Today, TechCrunch posted about Amazon PayPhrase going live. It appears that Amazon customers were notified of this feature, allowing them to set a phrase they can later use on 3rd party sites to check out quickly - just type in your payphrase and PIN and you're out. The TC post mentions a similarity to PayPal's student accounts, I am not sure I agree, but that's not the case. The interesting question (one also raised in the post) is - what new risks does a new feature introduce into the system?
There's a lot to be said about modeling the possible risks in a new payment feature, and I find it to be some science, some art. You have to weigh not only what users and fraudsters are doing now, but also what opportunities will they have once you introduce a feature, and understand how to design controls that mitigate the major issues without hurting functionality. That's why there's some art in it.
Friday, October 30, 2009
Saturday, October 24, 2009
The EU is less united than expected
This mystery research, widely advertised today by the EU union's research department, puts cross border shopping declines inside Europe at 60%. I once wrote a post about 3rd world shoppers unable to shop, but this situation is a much graver one. Unfortunately, the pros' call to invest in better, more intelligent risk management to open up to international purchases goes unnoticed, while merchant insist on making lives harder for legitimate buyers.
Hopefully SEPA will help solve at least part of the issues dealt with here, at least giving a head start for merchants and buyers on their mutual trust issue.
Hopefully SEPA will help solve at least part of the issues dealt with here, at least giving a head start for merchants and buyers on their mutual trust issue.
Thursday, October 22, 2009
Reconstructing Zynga: the industry's opinion on fraud in social games
My previous post about fraud in Social Games raised a few objections and spun a few sub-discussions. That's great, because it shows people are interested, and there's a LOT to be discussed in this field. I wanted to circle back to some of the main points that were raised in this discussion.
There's nothing new about fraud. Really. Ever since people walked this planet, I would assume, there has been fraud - more and more as time advances and human kind introduces additional currencies that replace tangible goods. It's beyond the limited availability of tangible goods; being able to control supply and demand through a symbol (call it cash, checks, virtual currency or repackaged subprime mortgages) is the basis for modern economy. But is the fact that fraud isn't new merely a reason for underestimating it? Definitely not; if it were, then why is the Spanish Prisoner scam, better known in its current days' reincarnation as the Nigerian Scam, still rampant on the web?
There's nothing new about fraud. Really. Ever since people walked this planet, I would assume, there has been fraud - more and more as time advances and human kind introduces additional currencies that replace tangible goods. It's beyond the limited availability of tangible goods; being able to control supply and demand through a symbol (call it cash, checks, virtual currency or repackaged subprime mortgages) is the basis for modern economy. But is the fact that fraud isn't new merely a reason for underestimating it? Definitely not; if it were, then why is the Spanish Prisoner scam, better known in its current days' reincarnation as the Nigerian Scam, still rampant on the web?
Sunday, October 18, 2009
And now for something completely (?) different
I'm diverting from Risk per se the deal with another decision-automation question I'm wondering about.
High-tech fluctuates. It boomed on the verge of the new millennium, and did so (albeit differently) before the latest downturn. And when booming, help is required. High-tech companies don't usually post a "help wanted" sign on their office wall (though some in Israel did), and getting to a good position requires some work beyond coming from a good school. In the days of the "bubble", just knowing a few people would secure you a position somewhere in the space, but nowadays it takes a lot more than that - employers demand good grades, subject matter expertise and experience - all of which are no mere feat for new graduates.
High-tech fluctuates. It boomed on the verge of the new millennium, and did so (albeit differently) before the latest downturn. And when booming, help is required. High-tech companies don't usually post a "help wanted" sign on their office wall (though some in Israel did), and getting to a good position requires some work beyond coming from a good school. In the days of the "bubble", just knowing a few people would secure you a position somewhere in the space, but nowadays it takes a lot more than that - employers demand good grades, subject matter expertise and experience - all of which are no mere feat for new graduates.
Tuesday, October 6, 2009
Jacob doesn't mind

Let's say there's a guy names Jacob. This guy, he's 23 years old, has somewhat of a steady job, largely sales and maintenance for a nice apartment complex in southern California. He uses PayPal, a lot more than he would like. He also has a Facebook account and a MySpace page; he follows friends on Twitter (and sometimes updates his own status messages there). He has an iPhone 3G; he's on top of things. If he was ever hit by fraud, he would probably tell his friends about it.
You know what? The industry is missing on many of Jacob's friends. Not because they don't have credit cards or because they don't shop online - it's because we haven't changed with them. Why? Because Jacob doesn't mind - he doesn't mind his information being out there on the web (as long as it's kept with a privacy policy). He doesn't mind some interaction with risk controls because web 2.0 and post 9/11 safety education taught many users that it's ok to be asked questions by those with authority. And in the land of risk management online, we are the authority. And we are limiting our business. Jacob and his friends don’t mind working with us to make their lives better – we simply won’t let them.
You know what? The industry is missing on many of Jacob's friends. Not because they don't have credit cards or because they don't shop online - it's because we haven't changed with them. Why? Because Jacob doesn't mind - he doesn't mind his information being out there on the web (as long as it's kept with a privacy policy). He doesn't mind some interaction with risk controls because web 2.0 and post 9/11 safety education taught many users that it's ok to be asked questions by those with authority. And in the land of risk management online, we are the authority. And we are limiting our business. Jacob and his friends don’t mind working with us to make their lives better – we simply won’t let them.
Sunday, September 27, 2009
Deconstructing Zynga: what's up in Social Gaming fraud
Talking to friends in a party I had to hold myself from becoming too smuggy-smug-smug. Yep, the lot of "I'm too good for Mafia Wars" geeks fell prey to the eggplant-growing rhythm of Farmville. Eggplants. My friends. I don’t even like eggplants, but still felt responsible in a way, though they’re only a drop in Zynga’s estimated 15M+ daily users (the numbers keep growing...). But things were only getting better for me that day.
“You know”, said one of the guys, “this social gaming stuff is really worth a lot of money. I know someone who made $100K off this thing”.
KACHING!!! Immediately he had my full attention. You don’t just MAKE $100K playing social games by the book, even if you break a finger playing Texas Hold’em. I had to know.
“You know”, said one of the guys, “this social gaming stuff is really worth a lot of money. I know someone who made $100K off this thing”.
KACHING!!! Immediately he had my full attention. You don’t just MAKE $100K playing social games by the book, even if you break a finger playing Texas Hold’em. I had to know.
Labels:
digital goods,
social gaming,
tips for risk management,
zynga
Thursday, September 24, 2009
What I learned about India [Part 1]

Preparing for a ceremony in Rishikesh
- "Did you see they have 'Hello to the King' here?"
- "What's 'Hello to the King'?"
- "It's basically a 'Hello to the Queen', only with a Bhagsu cake"
- "What's a Bhagsu cake?"
- "It's basically a Banoffie pie, only without the bananas"
- "I give up"
I'm not such a big traveler, but it seems to me that there is no single country you can capture in a blog post after less than a month of travel. That wouldn't be fair, but nonetheless, I have to say something other than "WOW". India is amazing, colorful, and extravagantly diverse; it is also noisy, dirty at times and completely frustrating when western perceptions of time and place collide with the Indian way of getting things done. But hey, you don't go on a backpacking trip to get five star treatments, do you?
India, at least the parts I visited, still seems very conservative. Sometimes it's obvious (you wouldn't believe how much of a standard Jason Biggs flick is censored in some Indian channels); sometimes it's subtle, though, like the highly sophisticated techie, sitting next to me in Barista coffee in Connaught place, holding an E71 but reading the caste-sorted "groom wanted" ads in the Hindustan times. It's there, and coming from a somewhat religious, symbolic country I appreciate the contradictions this creates. But the thing that amazed me the most is the fact that anything on the crust of this culture, ever so slow in its rituals and conventions, is by definition ever changing, at lightning fast pace. I'm not only talking about the highly western desserts those backpackers from my prelude discuss; what I'm actually thinking about is technology – and specifically, mobile phones.
They're everywhere. And not only are they everywhere (I had a 3G signal in the hills of Parvati valley! This actually beats some major US cities), it seems that they're actually used not as a luxury but indeed as THE major gadget. The taxi driver uses it instead of a radio; the young man on the bus to Kasol watched his favorite videos; and the old man, carrying a huge pack of firewood outside of Tosh, walks barefoot but talks on his mobile. And there's another part to it: I've explained in the past why using your mobile to pay isn't another steps towards the "stash", since the operators bill to a credit card or a bank account, not manage the user's money directly. But the case is different in India; many people do now have any financial entities in a financial institution, and a large chunk of the mobile market is prepaid. This means that other than cash, the mobile phone is the type of "currency" these people carry. Developing a mobile-phone-based, easy to use P2P payment solution is a must, the next step in payment evolution and something that will boost India's economy. This goes way beyond being able to send more ringtones and premium online content – this actually means gaining control over people's financial entities. If you can pay with a mobile phone, why not let it be your bank?
So why doesn't this happen? For various reasons (that can be overcome, but are still obstacles). One of them is the fact that a prepaid model prevents proper identification. This limits the ability to manage identities from afar, without any details from the user. It can be overcome (from installing a client, though models of incremental identification requirements when initiating payments, to rigorous vetting processes), but creates a major challenge. Another major problem is the fact that old phones have little processing power, and cannot sustain any type of payments application; if you don't install any type of software, you have a high unsecure medium, that can be easily breached and allow access to user credentials. These are the two major technical and risk related issues, and I'll discuss near-field communications and mobile authentication in future posts. The two other obstacles I learned about when I was in India are very interesting as well: one is consumer adoption, in a world of cash payments and little to no money; and the other, for which I would love to get comments from readers, is the fact that the Indian VC industry is smaller than needed, and geared towards American standards for business models and success. This is a very interesting reasons I would like to investigate, and will share my findings as soon as possible.
Bottom line, if you're looking for your next startup, maybe P2P mobile payments in India is your best guess. What's better than driving progress and technology into rural areas, while reaching amazing business success? And you get to taste "Hello to the King" as well. Next one's on me.
Subscribe to:
Posts (Atom)