Showing posts with label boku. Show all posts
Showing posts with label boku. Show all posts

Monday, June 7, 2010

How not to sell your product, or: is there really a "Silver Bullet" for Mobile Payments security?



Engineers tend to frown at marketing and BD, but creating leads or closing a deal is never easy. No matter where you are you want to be able to clearly articulate what is the customer’s pain point that you are solving. And you want your solution to be as straight forward as possible, too. If you resort to detailed tables and text you’re bound to lose most of your potential customers along the way. One thing I like about mobile payment companies’ pitch is that it’s pretty straight forward; both Boku and Zong articulate very clearly that yes, they have higher fees, but overall their much higher conversion rates increase revenue. Simple and straightforward; I like that. Other mobile payments vendors follow suit with similar pitches.

Why some Mobile Payments vendors are missing the point

Some of these vendors are veteran companies rebranding for the digital goods space and as such talk the “new” mobile payments talk but do not walk the walk. You can’t, for example, claim you’re providing a seamless experience when you require a three page signup process on first payment; your product must support your value proposition. Still, I have encountered companies that claim exactly that – and fail to understand why a cumbersome sign up process is an issue. I can imagine how some of these products evolved: starting in technologically limiting environments, with little to no data sources available and nothing but premium SMS billing. Faced with these difficulties, the ability to create any sign up flow or get an integration agreement with an operator looked like a huge achievement. And it was. But as depressing as it is to see your market changing, empowering payments in a card-not-present environment is today almost a commodity and operator integration is a limited, narrowing edge. He who wants to survive adjusts, or continues to try to sell payments triggered via, let’s say, IVR call to a landline. I’m sure there’s a need for first-generation payments somewhere on the globe; in most developed markets these look displaced.

Commodities and risk management 

I find this obvious since commoditization also creates pitch and product distortions in my own back yard, risk and fraud management. How did that happen? 5 years ago it was harder to compete with internal risk departments. With the eCommerce boom, however, came the proliferation of fraud as fraudsters (and the average Joes of the world) realized how easy it was. With this came a demand for risk management tools and methods. Many companies emerged in response, and each had to evolve quickly to gain market share and capitalize on an almost vacant market. Since the business was so nascent (and, I would argue, still is far from full potential), little technology innovation was required to reach stellar improvements in any point in the funnel; and since all of these companies provided indicators to help support the retailer’s decision (rather than the decision itself), the sales tactic was geared toward convincing the customer to add your score to the variety of scores they were already using. And it worked: merchants are using on average between 4 to 5 different decision supporting tools and indicators. But the cost was commoditization and an ever degrading technological edge. This has already started to come into effect and change the way risk and fraud are discussed.

Scaring them used to work

Sometimes finding a pain point is complicated since the customer is either unaware of a problem or aware of it but does not think it merits attention. When pitched FraudSciences’ product, even though we offered an insured decision to merchants to expand their business to new markets, often times the initial response was negative. Getting merchants to understand “why now” is always a challenge, and with the growth we see in Digital and Virtual Goods publishers sometimes don’t even have the time to consider (as I noted in the past, zero cost of goods produced is both a blessing and a curse). But it seemed as though for some of the companies the approach changed into forcing customers to realize they have a problem, even when they don’t necessarily have one. This is the “scare pitch”; I recently spent some time with a content publisher that told me about a similar conversation with another payments provider. A good part of the talk was aimed at explaining why fraud is so dangerous while fact of the matter is that currently, content providers aren’t immediate targets (since content is not as easily monetized as other goods). Why try to scare customers into buying your service when they have no actual need? Because most tools and services provide negligible incremental value and this is the only way to get customers to add another one to the pile – like any premium-hungry insurance company, scare them with hell and make sure they sign the policy. The alternative is, of course, enabling an experience that unlocks more revenue rather than catches all the “bad guys”. And that’s exactly where the product is lacking.

Is there really a new silver bullet?

Since the pioneers of risk management in eCommerce were mostly web-security geeks, a fraudulent transaction was (and still is) viewed as a transaction made from a “bad machine” (rather than “by a bad user”, a very important distinction). If we could only map all the bad boxes in the world, says this logic, we can stop fraud. This is what “machine fingerprinting” is about. Most leading companies hence focused on black-list type systems geared at collecting as much anonymous information as possible to be able to identify machines without necessarily identifying its owners. The story repeated itself with IPs, cookies, browser profile and now the latest addition – mobile device ID. As with its predecessors in the role of silver bullet or even better than some of them, mobile device ID is not easily spoof-able, is relatively easy to retrieve and is (supposedly) unique. Problem solved, right? Not so. With so many phones manufactured, stolen and exchanged in a year, it’s easy to see that simply keeping a list of “bad devices” won’t cut it – same as with other devices and boxes, if you base you classification on a “device bad history”, you fail every time you see a new device; and you fail every time good and bad users share a device since one bad user “contaminates” the device for all others. A hacked phone is, like a hacked machine with a proxy set up in it, simply a relay. The real “badness” of a device should always be viewed as probabilistic, in the current context of the actions made on it, and compared to other details we may have on the user allegedly using it. That is why a system without Personal Identifier Information is nothing more than a mildly sophisticated black-list.

This is not a subtle point but it might be lost if all we're looking to gain is that small edge. In dealing with mobile devices I find that creating a pattern to recognize still encounters major issues: geolocation reliability, network topology and new patterns of user usage are just three considerations that make mobile payments more than just an extension of desktop purchases. Focusing on adding device IDs to a device fingerprint, without creating a viable solution to initial encounters or devices being transferred between users is similar to looking at a problem space through a keyhole. It just won't cut it. 

Why this is important

Turning eCommerce into virtual commerce and the mobile phone into a wallet will require a high level of trust between participants, since virtual communities and f2f proximity payments are new ideas and new experiences. Enabling that exchange is one of the best outcomes of effective risk management and user identity and intent assertions, but the current trend isn’t necessarily heading at that direction. I believe it should, but that would require profound pitch, product and point of view change. 

Monday, February 22, 2010

New York under zero: some thoughts on the Engage! Expo

"If there are any Mattel engineers in the audience, the astronaut Barby's space suit is not crash proof" (loose paraphrasing on Will Wright's keynote)

Yep, the keynote was entertaining and Engage brought a lot of vendors to snowy New York's Javits center. The two day event, though a bit low on developers, had a few interesting sessions and some interesting chances to share opinions. So what did I pick up from these two full days?

Payments and mobile

This Engage was heavy on payments companies, and by payments I mean mostly - if not exclusively - mobile payments focusing on SMS billing through carriers (obviously Paypal was there - a few of my colleagues and me - and additional sponsors). While the value of mobile payments for a streamlined, high conversion purchasing experience is clear (on the verge of overstated), the abundance of these companies over such a small space only served to emphasize how not-that-different these companies are from one another. Better coverage, low fraud and a promise for lower fees in 2011 were the value propositions.

Now, while I think mobile payments are clearly an avenue the industry must pursue, it was clear to me that until operators make a big leap of faith to embrace mobile payments, this field will not move much unless the companies themselves move to a Zong+ like, account based system that allows users to add a financial instrument and for the mobile payments company to charge it directly. And, as you are soon to find out, account based systems are a whole new world of pain - while with direct billing you charge a prepaid or underwritten balance an operator is liable for, accounts are a much more complicated structure. Plainly put, you start writing big fat checks directly to fraudsters' pockets. Looking at chargebacks in hindsight, as at least two of the participants suggested, just doesn't cut it. So mobile payments are looking for the next big breakthrough, and if fees don't drop soon (and they probably won't), I'm expecting some M&A work as competition heats up.

Offers and tasks

I'm a long time advocate of offers. Yes, offers have their "dark side", when misused, however they have a huge potential for creating incremental volume - something I personally love. When at the conference I heard that Offerpal are integrating tasks from Amazon's Mechanical Turk, and have been hearing assertions that competitors are going to follow suit (also heard it on stage from IMVU.com's CEO). Why is this good? I think that using social gaming to crowdsource simple but human intensive tasks is good for user education - do something good instead of just signing up for Netflix (nothing bad about Netflix, though); plus, it's good for the potential work providers - ideally, research institutes, advanced OCR services and others. In short, tasks are the new "green". Two caveats in this optimistic view, though: the first is that there is a serious chance of shortage of tasks, at least until this market picks up; the second is that abusing this model is still doable, maybe even easier than standard offers - if I were a fraudster, I'd immediately outsource my CAPTCHA operation to Amazon. Oops! Better read previous posts and do some risk analytics, guys, or you'll find you're breeding an ecosystem of thieves.

Zero cost of goods

I had this feeling in the past, but the conference reassured me: the "zero cost of goods produced" concept is both a blessing and a curse. Why a blessing? Because developers, bathing in the sensational bliss of high margins, were keen on trying new things - new business models, new payment options (30% take for mobile payments? come on) and various experiments in user interaction (offers, vanity items and many other really cool stuff). Why a curse? Because the notion has outgrown its proper boundaries, actually harming some of the developers. Assuming that if you just auto-refund your zero-cost virtual good, the problem of chargebacks goes away is a mistake, and not checking operational costs related to this "zero cost" work will make your bottom line look pretty bad eventually. Additionally, zero cost of goods got many developers focused on solely growing their user base and ARPU - both important but, as a few speakers noted, shifted attention from a few other very important stuff. Like fraud, like going international, but also like pricing - when the third pretty senior person suggested to developers that going all-in on a freemium model just isn't a good idea, I started to understand that the problem transcends risk management and controls; it's starting to detach companies from sound business judgment. So this is probably time to reconsider - it's all a part of growing up as an industry.

P.S. One last thing

I was delighted to meet a few young and talented entrepreneurs working exactly on the things I find exciting - namely p2p trade and new, great ways to engage users. It's fun to see how ideas evolve, and I'm looking forward to hearing more about them and others like them. Well done, guys!

Monday, November 30, 2009

Mobile payments part 2 - a tale of princes, laws and treasures

In the previous post we've looked at mobile payments in a glance, why there's a huge chance today and what are the biggest challenges. In this post I will start diving deeper into them, and suggest a few ideas.





There's a group of very talented guys I know, who used to work at this IT Company in Israel that was a part of the mobile industry. They basically made some peripherals, a few applications and other mobile related products. One of these products was a relay to transfer contacts from one cell phone to another, in case the owner wanted to upgrade or downgrade (yes, there are people who do not have smart phones and Outlook sync). When, at some point, they started their own company to manufacture and sell a similar relay, they found a very interesting (well, in a sense) thing: a huge chunk of their dev and QA time was not spent on improving the product; instead, it was spent on porting - making sure that the software matched all cell phones out there.

This is the time when industry experts read and think: "what else is new?" (And also: “we don’t have this problem now with the iPhone!” Yes, you do. But that’s for the next post).

Saturday, November 21, 2009

Why you should love (and fear) mobile payments [part 1]

A month and a half ago I discussed the mobile payments opportunity in India, a country where the mobile phone is often the consumer's sole financial entity (no banks, credit cards or anything else but cash). Boku's press release is a good opportunity to take a closer look at the US mobile payments market (see a previous post), and tell you why I think that it has great potential, but should also look out for a few obvious challenges.




You're all busy people, so I'll save you the time reading through my first paragraph and give you the bottom line: mobile payments are here, are growing, and have the potential to kill all other payment services. BUT it won't happen the way you'd imagine, and there are many pitfalls along the way, yet there are many chances for success.

Phew! Now that I got this off my chest, I can start explaining.