Tuesday, June 16, 2009
So your mobile phone is your new wallet?
Payment services are fighting to increase share of wallet, and remove as many boundaries as possible between the merchant and the customers' money. Obviously, the mobile phone is always there, available to use, it's really a gadget, you know, it's not really as serious as a credit card. We all know credit cards are dangerous to use on the web. But taking a closer look reveals that a mobile phone isn't a step closer to the customer's money, it's actually the same distance. You don't own the "stash", only another funnel for getting some of it.
This, by the way, doesn't mean that mobile payments isn't a good idea or that it's going to fail (it might, though, but not because it's not the biggest funnel), and I wish Boku and friends all the luck; but fact of the matter is that your phone is pretty much the same as your bank account, debit card, credit or any other payment method - it's a key to the treasure chest. Get a hold of the chest (in other words - become the bank) - and you've REALLY got an advantage. Until then, I'll continue buying my Mafia dollars the same way, be my proxy what it may.
Tuesday, April 7, 2009
The single source of truth
Awaken now at last
And tell us how to save us from ourselves
and how to survive our own rulers
who would make a plutocracy of our democracy
in the Great Divide
between the rich and the poor
in whom Walt Whitman heard America singing"
(Lawrence Ferlinghetti, "To the Oracle at Delphi")
Ok, no politics. Here's the first rule of proper engagement with complex decisions: know the truth. It's so simple yet one of the hardest tasks ever in a large organization, especially one that deals with transactions every day. Because the Knowledge Boom hits hardest where you actually need to make sense of it. This isn't just going through your Google reader and finding the 5 interesting posts to read between the dozens you got last night from TechCrunch and Slashdot. It is (first and foremost) about finding those pieces that really matter, and using them to make money, or prevent from losing it; it is about finding what's the most important piece of data you aren't logging or don't have, and getting it; and finally, it is about making it all connect. Because without all of these, you're left with a blur called your payment system, and your best chance is third party vendors and Chargeback representment, and you know my opinion - it's not the best place to be in.
So, you say, what's the problem? I'll hire someone who understands Risk and I'm good.
Not quite. Here's an interesting dynamic: since many merchants either relate risk management to CS or demand a clear ROI for any headcount they're hiring, the risk or fraud management department often ends up as an underdeveloped group with CS responsibilities. Yes, this means that they'll start calling a lot of people. On the other hand, when the organization grows, in comes the industry veterans with their zest for business intelligence, segmentations and graphs. So you end up with a group of "factory" workers on one hand - who feel the "field" but do not know what to do with this knowledge (little to say generalize on it), and on the other hand you have the top squad, segmenting the world but never actually meeting the real fraud cases on a non-aggregate level. When the second group need to find what is happening exactly, they cannot rely on the first group, and they end up reverse-engineering the answer to "what really happened?" by digging deeper into your already-huge data warehouse, always reaching something that is just that-much better than a random variable, but never the actual answer. I know this is industry standard, I know it works well to a certain extent, I also know it loses flexibility and degrades after a while. In addition, I can tell you that this is the reason to not only fraudsters having a ball, but also (and much worse!) for legitimate people not making it through the grid of filters. So my advice to you is: get an oracle.
Who's or what's an oracle? You can think of this position as, at the very least, the missing link between your field agents and the BI experts. The "oracle" knows what's a good transaction and what's a bad one; they can rationalize the case and furthermore, they can generalize. Because proper usage of rationalization and generalization are key for an efficient decision making process: they lay the foundations for understanding why bad things happen, how do you spot them on time (and not in restrospect analysis of business performance or when the processor is already knocking on your door with chargeback fines), and what should you check. They have the ability to dive into the material and resurface with additional insight, and the ability to test your systems while you develop them. This is much more than a field agent becoming the newest member of the BI team - the oracle is not only a person with a specific talent, but also has the right system to enable their way of thinking that has nothing to do with Customer Support - as important as CS might be in your organization.
What's the talent profile, and what's the right system? Allow me to call this my little trade secret. But you have an important tip now - find an oracle. Find two. Have your own source of truth, that isn't just your most experienced field agent, and make sure they are all in sync (which is a challenge in its own). Then, finally, you'll be able to start planning automated systems that actually do the work your way.
Tuesday, March 31, 2009
Here comes the scary part
Oh, is it really?
I didn't go to the MRC conference this year. Somehow, boogieman stories from interested third parties (over early morning session, in Vegas!) sounded less appealing for someone who needed to fly 18 hours for the experience. I did, however, read excerpts and ideas. Boy, I have to admit that the set up was a lot more successful than a Tel-Aviv cafe. Because here's the thing with 3rd party vendors - they are looking to sell, and if you're looking for the real gap in your system (rather than the perceived one), you probably shouldn't be looking at that direction. Let's see what's hot this year: it sppears that Malware and Botnets are attacking everyone, and that Machine ID and phone verification might be the only way of stopping this.
Now's probably the right moment to wonder what's my case. True. Here's my case: buying flashy new technologies when you haven't exploited the old ones is pricy, redundant, plain dumb sometimes. Most of the merchants that will purchase anti-malware and machine id solutions do not, I bet, have a decent user-location system in place, and are instead declining multiple good buyers who live in a set of black-listed locations; most of the merchants that will purchase phone verification products will double their fraud operation costs before they realize that calling alarge percentage of the transaction volume only slows them down instead of bringing that solution to loss mitigation. My case is - proper analysis of what you're dealing with, rather than going with the nifty, trendy new fraud filter, will bring you much higher ROI and a method for solving your own problem. It does, however, require some extra effort that cannot be bought off the shelf: training the right kind of people to do the right kind of work. More on that in future posts.
Thursday, December 13, 2007
Black men can't shop?
Your working late hours, late enough to reach the time when you have to go and get yourself a strong one from the coffee house downstairs to wake everyone up. Only after you volunteer to be the ones who'll go get it you find that you forgot your card at home. No problem, what could be simpler? You just borrow your friend's card.
After choosing exactly what you need, with a list you made earlier at the office, come the time to pay. You reach into your wallet and hand the cashier your firend's card. It's ok, your friend gave you the card. Even when the slip needs to be signed you sign it, it doesn't matter what signature you use (btw, do you sign your own or "invent" one for the friend?), no one will notice anyway, right?
Wait.
You've just committed the basic scenario in "card present" C2B (consumer-to-business) frauds, ones in which there's a real plastic that's being put through the POS (point-of-sale) terminal.
True, you're no thief (or "carder", as one may be called). You did this all very honestly and there's no suspicion of a crime. The cashier came out clean - indeed he didn't use a very simple identity verification method (forinstance - asking for a driver's license, like other "stung" merchants already do) yet the liability is on the issuer, as long as the buyer signs the slip.
You are not thieves maybe but Gregory K, for instance, is. His method was a combination of the very simple and the somewhat sophisticated: He scanned trash cans and looked for copies of credit card slips. Sometimes he did great and hacked computers over eMule and other file sharing platforms to copy credit details. He used those details to buy online - in this kind of shopping it's much easier to pretend you're someone else, you can be Barbara from Australia for all we know, all you need is her card details and some other details people usually keep together with their card, when they are gullable and unsuspecting. Gregory had it easy, he lives in the states, and it will cost him a few years behind bars now, carried away by the (justified) fear of identity theft.
So why can't black men shop? Well, the legitimate ones can, but the thieves among them, those who orchestrate scams from third world countries, find that going into a store with a just-stolen card and claiming to be George Costanza the third will be a bit hard, but stealing on the net is so much easier and profitable. In addition, when shopping over the net the purchases are under the merchants' resposibility and those - lacking substantial knowledge in preventing fraud - turn into easy victim to sophisticated Nigerian, Vietnamese and Russian carder exploiting many stations en route to the desired loot of watches, jewelry and electronics for thousands of dollars.
How do the merchants protect themselves? Well, they just don't sell, or ask for riculously frustrating actions (you can't imagine how many times a year does an Israeli need to send their passport's or credit report's scan, little to mention not even being able to ship to Israel). Next time, when you get rejected over a simple order online, remember Greg K. and his Nigerian friends, that cost the eCommerce business billions of dollars a year, and turn online shopping into a much more complicated procedure.