Thursday, September 24, 2009

What I learned about India [Part 1]












Preparing for a ceremony in Rishikesh







  • "Did you see they have 'Hello to the King' here?"
  • "What's 'Hello to the King'?"
  • "It's basically a 'Hello to the Queen', only with a Bhagsu cake"
  • "What's a Bhagsu cake?"
  • "It's basically a Banoffie pie, only without the bananas"
  • "I give up"
(Two Israeli backpackers, Dharamsala)

I'm not such a big traveler, but it seems to me that there is no single country you can capture in a blog post after less than a month of travel. That wouldn't be fair, but nonetheless, I have to say something other than "WOW". India is amazing, colorful, and extravagantly diverse; it is also noisy, dirty at times and completely frustrating when western perceptions of time and place collide with the Indian way of getting things done. But hey, you don't go on a backpacking trip to get five star treatments, do you?
India, at least the parts I visited, still seems very conservative. Sometimes it's obvious (you wouldn't believe how much of a standard Jason Biggs flick is censored in some Indian channels); sometimes it's subtle, though, like the highly sophisticated techie, sitting next to me in Barista coffee in Connaught place, holding an E71 but reading the caste-sorted "groom wanted" ads in the Hindustan times. It's there, and coming from a somewhat religious, symbolic country I appreciate the contradictions this creates. But the thing that amazed me the most is the fact that anything on the crust of this culture, ever so slow in its rituals and conventions, is by definition ever changing, at lightning fast pace. I'm not only talking about the highly western desserts those backpackers from my prelude discuss; what I'm actually thinking about is technology – and specifically, mobile phones.
They're everywhere. And not only are they everywhere (I had a 3G signal in the hills of Parvati valley! This actually beats some major US cities), it seems that they're actually used not as a luxury but indeed as THE major gadget. The taxi driver uses it instead of a radio; the young man on the bus to Kasol watched his favorite videos; and the old man, carrying a huge pack of firewood outside of Tosh, walks barefoot but talks on his mobile. And there's another part to it: I've explained in the past why using your mobile to pay isn't another steps towards the "stash", since the operators bill to a credit card or a bank account, not manage the user's money directly. But the case is different in India; many people do now have any financial entities in a financial institution, and a large chunk of the mobile market is prepaid. This means that other than cash, the mobile phone is the type of "currency" these people carry. Developing a mobile-phone-based, easy to use P2P payment solution is a must, the next step in payment evolution and something that will boost India's economy. This goes way beyond being able to send more ringtones and premium online content – this actually means gaining control over people's financial entities. If you can pay with a mobile phone, why not let it be your bank?



So why doesn't this happen? For various reasons (that can be overcome, but are still obstacles). One of them is the fact that a prepaid model prevents proper identification. This limits the ability to manage identities from afar, without any details from the user. It can be overcome (from installing a client, though models of incremental identification requirements when initiating payments, to rigorous vetting processes), but creates a major challenge. Another major problem is the fact that old phones have little processing power, and cannot sustain any type of payments application; if you don't install any type of software, you have a high unsecure medium, that can be easily breached and allow access to user credentials. These are the two major technical and risk related issues, and I'll discuss near-field communications and mobile authentication in future posts. The two other obstacles I learned about when I was in India are very interesting as well: one is consumer adoption, in a world of cash payments and little to no money; and the other, for which I would love to get comments from readers, is the fact that the Indian VC industry is smaller than needed, and geared towards American standards for business models and success. This is a very interesting reasons I would like to investigate, and will share my findings as soon as possible.

Bottom line, if you're looking for your next startup, maybe P2P mobile payments in India is your best guess. What's better than driving progress and technology into rural areas, while reaching amazing business success? And you get to taste "Hello to the King" as well. Next one's on me.

Sunday, August 30, 2009

Taking some time off

As I'm going on vacation, the blog will be inactive for a few weeks now.

See you on the other side of India!

Monday, August 24, 2009

There's a kind of hush

Yes, it's gaining momentum. TechCrunch posted today of an acquisition in the field of micropayments for gaming. We're at the verge of an explosion - the mass proliferation of startups and technology companies trying to get a share of this growing industry. They're goig to face a lot of challenges (beyond fraud - even managing a payments or dispute resoluion operation is costly), but I'm personally interested, obviously, in the rise of marketplaces.


Yes, buying virtual credit using a stolen credit card gets you... virtual credit. That you can later find a way to sell, that's true, but marketplaces are such an ever-green environment for fraudsters to operate, since they let you exit funds so much easier. And these guys, no doubt, are going to be a lot more creative and tech-savvy - in a non-tangible, rapid environement.

Why is this a problem? Because most risk controls today rely of the item being shipped (to a real address, that matces the billing address of the card, and also matches at the bank). They also rely on the ability to delay shipment when yuo suspect someting. Don't buy tales about sophisticated "dynamic risk scores", I tell you, it's all AVS and some additional blacklists. And at this point exactly, in these quick, electronic transactions with no account history, statistical models and standard risk controls are failing. Let the arms race begin.

Thursday, August 20, 2009

Heartland my love

So the security-related part of the web is stirring over the Heartland breach going to court, and having fun mocking Heartland for falling for the oldest trick in the SQL-injections book. Since Israel's IDF's chief of staff was also a victim of his credit card being stolen, newspapers in Israel feasted over this "hot news" item, to the extent that one blog even names Albert Gonzales (the "brain" behind the attack. I wonder who Pinky is) "The Al Capone of Cyber Thieves".

Geez.

A flurry of blog posts and articles followed, telling us that checking your credit report is important (really?) and pulling some chargeback stories from the attic. One even went as far as interviewing the manager of operations for one of Israel's issuers. Don't get me wrong, while I'm against trying to scare people, public education makes sense (though many time is useless, as I have claimed in the past [Hebrew]). But the part I'm much more interested in is not the fact that a breach happened, those happen all the time although some retailers just hide their negligence. What I’m interested in is the publication of such an indictment, and its effect of the psychological aspect of committing internet fraud.

You see, analysts profile people. We know who the average fraudster is: a young, tech-savvy male with a knack for gadgets and digital goods, who thinks he could get away with it pretty easily. The “getting away with it” part is the important one; be that the average fraudster or a desperate housewife looking to earn a few dollars defrauding buyers on eBay, the mental state needed to commit a felony on the web is much less delinquent in nature. Because the web is not “the real world”. Because doing it over the computer pushes it away from me. It’s not me; actually, it’s my avatar. And pressing charges in the real world against people who wronged in the virtual world makes it as real as it gets. This, in turn, makes people a lot more aware of what they’re doing when they’re stealing – and the heuristic of a self-aware fraudster are different than those of one that isn’t. A fraudster who isn’t afraid of getting caught looks a lot more like your average Joe, and this is something we want to prevent. This is not only because risk analytics become easier (and legit people’s lives become better, since we need less “tricky” controls), but because indicting fraudsters is the right thing to do. Security and trust are, I believe, the key foundations of a thriving online community, and I’d like to help keep it as such.

Saturday, August 15, 2009

O Master, where art thou?

As an Israeli, discovering Corporate America was a shock. Not that I never heard of the term; still, for someone who just joined "the industry" (as the hi-tech sector is usually referred to in Israel) a few years back, discovering that this kind of thing exists (and has many types of interesting positions, some are far from the usual computer-science-only cult of Israeli hi-tech) was mind boggling. I'm not sure how eBay strikes locals in California but in Israeli terms it's a pretty big international corporate - and now I'm relocating straight to HQ, to live in the belly of the beast with my wife and dog. What an adventure.

Tuesday, August 11, 2009

Fraud Fighting 2.0

“Wow, I've been a victim of fraud for 10 days and didn't even know it until now. Holy crap.” (A random Twitter user reporting)

During FraudSciences’ fraud operations days I was never keen on letting analysts and agents call people who were defrauded. Old school credit card users, who have had their details stolen, were never too happy hearing about it from someone they didn’t know, calling from another country and sounding like the fraudster himself - with a thick accent and all of their personal data at hand. It didn’t help that the company was called FraudSciences either, but that’s a completely different story. As time went on it became clear that most users we encountered preferred that fraud be dealt with out of their sight. They didn’t want to know about, or be involved in, any process regarding their identity being stolen. Sure, we’ve had the occasional angry customer calling back to understand whether we know the person’s name, who they were and their whereabouts to get even (and even had one person explaining that she always suspected her next-cube neighbor at the office), but generally speaking – no involvement. And we were completely fine continuing to work, undisturbed.

Tuesday, August 4, 2009

PayPal Israel is looking for Analysts!

Disclaimer: This blog is not intiated nor endorsed by Paypal.com. I am writing it not as an employee of the company and my opinions are strictly my own. I am, however, posting a publicly available job opening since I find it to be a very interesting position, to be our single source of truth.

Read more about the domain and the type of people.

PayPal Israel is looking for Risk Analysts

Responsibilities:

Analysts in PayPal are highly motivated team players, working within the Live Analytics group, specializing in understanding, creating and applying advanced proprietary fraud prevention models. The group members work in a variety of fraud related fields while using state of the art tools and methods (profiling, forensics, network analysis, machine learning and more). The ideal candidates have a passion for solving fraud "riddles" and strong analytic skills allowing them to analyze various kinds of data and information and come up with new understandings. The role encompasses acquisition and application of vast knowledge areas over a short period of time and requires a strong sense of personal responsibility. The position is shift based, in a hectic live environment, held in regular working hours. Role development includes increasing contact with cross-organization research groups, project and product management roles and various other positions inside the greater global risk organization inside PayPal.

Requirements:

- BA graduate or a final year student
- Full time position
- 1-2 years work experience
- Proven analytical skills - scoring more than 700 in the psychometric test or an equivalent is a must
- Quick-thinker, fast learner, wide general knowledge
- Team worker, responsible and trustworthy
- Strong deliverability within strict time frames
- Computer skills: experience with programming /scripting language, Excel, SQL - a plus
- General familiarity with Internet technologies and protocols - a plus
- Excellent English. Other languages - a plus