Monday, September 13, 2010

The Snowflake Complex: behavioral modeling and you

“You are not special. You are not a beautiful or unique snowflake. You're the same decaying organic matter as everything else.”

 Fight Club, 1999

Whenever a highly improbable event occurs, I’m immediately inclined to find that one missing detail that may explain it as part of a pattern; maybe a rare permutation of indicators and events but a pattern still. It’s not due to a firm belief in determinism, but rather a fascination with the observation that human experience is diverse while at the same time we all go through the same (culture- and geography-dictated) crossroads in life; these crossroads also provide us with the common grounds on which communities are formed. Examples to such patterns are manifold but let’s just call out two: Joseph Campbell’s The Hero’s Journey is the canonical textbook of myths, while Malcolm Gladwell’s Outliers is a recent, nicely written example.

Recently I had this conversation all over again while describing my new project to a few folks. Every time I talk about modeling human behavior, I get asked how I can generalize on human beings – we’re such unique creatures, and the spectrum of our reactions is immensely broad. True and untrue; while we’re all unique individuals (well, you are. I’m not), we’re limited by two degrees of constraints that make it easier to understand who we are and why we do what we do.

One is our immediate and general social environment forcing us into behavioral patterns – forget the fact that people end up succumbing to the way they were brought up, let’s talk about the present – the only difficulty here is deciding on the right frame to compare to when trying to make a prediction. Sure, you’re very smart, and you dropped out of college to join a startup. Quite a unique move in your small town, maybe, but can’t say you’d stand out in a crowd in San Francisco. Being part of a startup that was successfully sold, then relocating to the US is something that happens to – I’d say – 1 in every 10,000 people in specific areas; put otherwise, there are thousands of people with a similar experience running around.

The other constraint is much more mundane – when you try to model behavior on the web, people are just limited by the interface. Trying to create complex interaction models or make arbitrary decisions usually fails because there’s no button for that (if you ever played Sierra quests, you know what “I can’t do that” means). Even when examining seemingly more complex MMOs like World of Warcraft, you see how simple the actual interaction model is.

We want to be a unique snowflake. I hope we are. But those who want to track and understand human behavior shouldn’t let the snowflake complex hinder their efforts. Ask the guys at Hunch.

Wednesday, September 1, 2010

Why don't you become a payment provider? A disambiguation.

Every once in a while there comes a question about why doesn't company X become a payment provider, or what would it take for them to become one. Lately, I have seen this come up in Quora regarding Skype. Parts of what I want to say about this matter were brought in this Quora question but there are a few other issues and a couple other basic assumptions to sort out.

I'm a big proponent for competition in payments; rates are too high, systems are archaic and self-imposed limitations by incumbents are just crazy sometimes. Even Paypal can use the competition to shake up some of its ways of doing business as the 8000 pound gorilla. But before you dive right in, you have to sort for yourself where in the food chain are you going to compete. I covered this a little bit in my previous posts about mobile payments, but I see 4 links in the payments chain you need to mind: engagement drivers, networks, methods, and wallets. Of course you can play in all of them, and many companies do so in more than one, but it's important to understand them since they have different implications to your product. Once we understand those, we can really look at why providing value in payments is not as easy as it sounds; we can also understand where most people choose to compete and where other opportunities might be waiting.

"Engagement drivers" is the model for many companies in the gaming market. You're competing in driving engagement when all you do from the payments perspective is resell someone else's ability to provide a method of payments (and therefore, build on top of the second group's systems). Note - not some other company's ability to acquire payments, as the companies whose services you'll use are not banks or V and MC. As I noted in my post, I see the mobile payment providers of the world in this category, and to a large extent offer wall providers as well. Players in this category don't own the customer service liability with the customer but at the same time don't own the relationship either; their product is a promise for improved conversion and hassle free UX, and at times they act as "aggregators", presenting end users with multiple payment methods. Quite a few companies have been pushed to this part of the chain or chose to go here because Methods incumbents are too strong and the barriers to playing there are high, while the gaming industry was and still is very supportive of pricey added services as long as you can drive engagement.

Networks is where most of the big players are playing or intend on playing; this is where Paypal, Facebook credits, Google checkout, mobile operators, the future Apple product etc are in the food chain. Players in this area have a direct relationship with the buyer and the seller, and discover the joy of customer service for payments. They emerge because they either identified a new merchant and customer relation that was needed and not catered for (examples: Paypal rules in online payments and P2P/U2U, Facebook is solving virtual currency fatigue and small WePay is looking at group payments). At this level customers already have stored value accounts that are sensitive to fraud as well as may default on some type of credit you've given them. This is the true battlefield of payments to many people - and many people, in my honest opinion, are missing the point - but when question askers think about payments this is what they have in mind. And for a good reason - owning this type of a relationship, as well as identity details, is important value add that can and should be leveraged by current payment companies.

Payment Methods and Wallet is where I find things to be extremely interesting - try to draw a graph of Visa, Mastercard, Amex and banking through the world and you can realize why - how small and fragmented is the online payments world compared to this opportunity, and what opportunity lurks there. But first I must make a point about differentiating methods and wallets, since some companies might claim to be both. Here's a simple test: when your customers get their paycheck, where do they put their money? If it's in your system you're the wallet. If it's not, you're not.

I am very interested in Methods since they are the rails that enable payments, while getting a piece of the pie in a (relatively) lower risk environment. Methods connect wallets with networks and they do this, ideally, in a seamless integration. Yes, they're in the back unless they have great brand strategy, and that's a challenge for any player to solve, but the reward is huge. It's a high-volume-low-margin market, but a profitable one, and is one that is ready for competition, as long as you can bring more value than just another credit card. I can say I know at least two companies that are working in this area and will provide what I perceive as immense value, and I'm following them closely.

Lastly, Wallets are where you put your money when you get it. For regulatory and other reasons mostly this place is a bank, that then uses various other services to allow you to spend your money. While quite a few companies developed as means for helping you spend or creatively save your money (Mint would be one example), not many are trying to provide an actual wallet. While there are many barriers here as well, this is a unique type of relationship with a customer, one that has much more upside once established but a rough way until it is established.

If you're thinking about payments, you're probably thinking about one of the first two in terms of fighting for market share in a crowded space while disregarding the third. Now that we have them defined, we can look at the perils of trying to establish yourself as any.

In a future post: what are the challenges of becoming an engagement driver and a network 

Monday, June 7, 2010

How not to sell your product, or: is there really a "Silver Bullet" for Mobile Payments security?



Engineers tend to frown at marketing and BD, but creating leads or closing a deal is never easy. No matter where you are you want to be able to clearly articulate what is the customer’s pain point that you are solving. And you want your solution to be as straight forward as possible, too. If you resort to detailed tables and text you’re bound to lose most of your potential customers along the way. One thing I like about mobile payment companies’ pitch is that it’s pretty straight forward; both Boku and Zong articulate very clearly that yes, they have higher fees, but overall their much higher conversion rates increase revenue. Simple and straightforward; I like that. Other mobile payments vendors follow suit with similar pitches.

Why some Mobile Payments vendors are missing the point

Some of these vendors are veteran companies rebranding for the digital goods space and as such talk the “new” mobile payments talk but do not walk the walk. You can’t, for example, claim you’re providing a seamless experience when you require a three page signup process on first payment; your product must support your value proposition. Still, I have encountered companies that claim exactly that – and fail to understand why a cumbersome sign up process is an issue. I can imagine how some of these products evolved: starting in technologically limiting environments, with little to no data sources available and nothing but premium SMS billing. Faced with these difficulties, the ability to create any sign up flow or get an integration agreement with an operator looked like a huge achievement. And it was. But as depressing as it is to see your market changing, empowering payments in a card-not-present environment is today almost a commodity and operator integration is a limited, narrowing edge. He who wants to survive adjusts, or continues to try to sell payments triggered via, let’s say, IVR call to a landline. I’m sure there’s a need for first-generation payments somewhere on the globe; in most developed markets these look displaced.

Commodities and risk management 

I find this obvious since commoditization also creates pitch and product distortions in my own back yard, risk and fraud management. How did that happen? 5 years ago it was harder to compete with internal risk departments. With the eCommerce boom, however, came the proliferation of fraud as fraudsters (and the average Joes of the world) realized how easy it was. With this came a demand for risk management tools and methods. Many companies emerged in response, and each had to evolve quickly to gain market share and capitalize on an almost vacant market. Since the business was so nascent (and, I would argue, still is far from full potential), little technology innovation was required to reach stellar improvements in any point in the funnel; and since all of these companies provided indicators to help support the retailer’s decision (rather than the decision itself), the sales tactic was geared toward convincing the customer to add your score to the variety of scores they were already using. And it worked: merchants are using on average between 4 to 5 different decision supporting tools and indicators. But the cost was commoditization and an ever degrading technological edge. This has already started to come into effect and change the way risk and fraud are discussed.

Scaring them used to work

Sometimes finding a pain point is complicated since the customer is either unaware of a problem or aware of it but does not think it merits attention. When pitched FraudSciences’ product, even though we offered an insured decision to merchants to expand their business to new markets, often times the initial response was negative. Getting merchants to understand “why now” is always a challenge, and with the growth we see in Digital and Virtual Goods publishers sometimes don’t even have the time to consider (as I noted in the past, zero cost of goods produced is both a blessing and a curse). But it seemed as though for some of the companies the approach changed into forcing customers to realize they have a problem, even when they don’t necessarily have one. This is the “scare pitch”; I recently spent some time with a content publisher that told me about a similar conversation with another payments provider. A good part of the talk was aimed at explaining why fraud is so dangerous while fact of the matter is that currently, content providers aren’t immediate targets (since content is not as easily monetized as other goods). Why try to scare customers into buying your service when they have no actual need? Because most tools and services provide negligible incremental value and this is the only way to get customers to add another one to the pile – like any premium-hungry insurance company, scare them with hell and make sure they sign the policy. The alternative is, of course, enabling an experience that unlocks more revenue rather than catches all the “bad guys”. And that’s exactly where the product is lacking.

Is there really a new silver bullet?

Since the pioneers of risk management in eCommerce were mostly web-security geeks, a fraudulent transaction was (and still is) viewed as a transaction made from a “bad machine” (rather than “by a bad user”, a very important distinction). If we could only map all the bad boxes in the world, says this logic, we can stop fraud. This is what “machine fingerprinting” is about. Most leading companies hence focused on black-list type systems geared at collecting as much anonymous information as possible to be able to identify machines without necessarily identifying its owners. The story repeated itself with IPs, cookies, browser profile and now the latest addition – mobile device ID. As with its predecessors in the role of silver bullet or even better than some of them, mobile device ID is not easily spoof-able, is relatively easy to retrieve and is (supposedly) unique. Problem solved, right? Not so. With so many phones manufactured, stolen and exchanged in a year, it’s easy to see that simply keeping a list of “bad devices” won’t cut it – same as with other devices and boxes, if you base you classification on a “device bad history”, you fail every time you see a new device; and you fail every time good and bad users share a device since one bad user “contaminates” the device for all others. A hacked phone is, like a hacked machine with a proxy set up in it, simply a relay. The real “badness” of a device should always be viewed as probabilistic, in the current context of the actions made on it, and compared to other details we may have on the user allegedly using it. That is why a system without Personal Identifier Information is nothing more than a mildly sophisticated black-list.

This is not a subtle point but it might be lost if all we're looking to gain is that small edge. In dealing with mobile devices I find that creating a pattern to recognize still encounters major issues: geolocation reliability, network topology and new patterns of user usage are just three considerations that make mobile payments more than just an extension of desktop purchases. Focusing on adding device IDs to a device fingerprint, without creating a viable solution to initial encounters or devices being transferred between users is similar to looking at a problem space through a keyhole. It just won't cut it. 

Why this is important

Turning eCommerce into virtual commerce and the mobile phone into a wallet will require a high level of trust between participants, since virtual communities and f2f proximity payments are new ideas and new experiences. Enabling that exchange is one of the best outcomes of effective risk management and user identity and intent assertions, but the current trend isn’t necessarily heading at that direction. I believe it should, but that would require profound pitch, product and point of view change. 

Tuesday, May 18, 2010

Facebook showing Traces of Crowd Sourcing in Risk Management (?)



Picture by Matthew Filed/Creative Commons

If you're following the blog, you know I'm a big advocate of using the "wisdom of the masses" (well... at least their accumulated computational ability) to crowd-source complex tasks that cannot be easily automated. The way I see it, it's not that users merely "don't mind", they actually expect that to happen. This is the reason I'm pro offer walls (well, at least some of them) and like the concept of “jobs” or “tasks” incorporated into these walls. There's a lot to be done in the area of engaging users around various complex decisions, risk management being one of them (see other ideas on gwap). Now, I don't think that we cracked the code of making financials and risk interesting – whether it’s because financials are less “sexy” or because or more elusive reasons - but I do enjoy seeing interesting attempts.

That's why I liked the feature I discovered in a TC post: 


Yeah, I know, you’re wondering what I am so excited about. Well, for me it goes back to the dynamics that help establish and nurture communities. Online communities are here to stay, from Habbo hotel to SL to social networks. Communities like Facebook are growing by mere network effect; every day, people are pouring into the platform to interact, share, play. And at the same time, you can’t help but hear the murmur: Facebook did this, Facebook did that, I don’t like the new layout, I hate the privacy policy. This might means that we have (potentially) passed the docile stage of throwing sheep at other users, to the involvement period. What’s that? Basically, creating a real, lasting online community requires more than a news feed and a constant unedited stream of brain farts (dad, I actually like yours. Really). It requires users’ engagement, their involvement in regulating their environment, in setting its rules and in actively helping to make it better. It requires some kind of ownership, a sense of responsibility. This is what creates a healthy community that can be actually leveraged as more than a collection of unrelated, though somewhat connected, individuals. And that’s the reason why I like the potential of this nascent form of crowd-sourcing risk management: from my point of view, it’s a fair attempt at starting to enable users to assume that kind of responsibility. It’s a call to action where Facebook’s Risk team, effectively the police in a network that’s around 1.5X the size of US population, is asking you to join the neighborhood guard. If it’s really your neighborhood, won’t you act to keep it peaceful?

That’s why I like it. Or, at least, that’s the potential I’m loading on one poor notification feature… The other reason is, of course, the poetic justice of using the same type of resources fraudsters are using to overcome standard risk controls to actually deter fraud. Gotta love that.

What is your take on crowd sourcing risk-related process in your system?



PS
In case you’ve never seen it, catch this remarkable piece of the performing arts.
Lyrics are here.

Saturday, April 24, 2010

Blizzard, secondary markets and the gaming industry

Phew... after two months of work, I can take a step back and go back to blogging.

Who won the "Pirate bay" trial?

The simplistic answer is obvious: though currently in appeal (scheduled to open September of this year) the site's operators were convicted on April 17th, 2009 in accessory to crime against copyright law, and were sentenced to a year in jail and over $3.5M for fines and other damages. I would call this a pretty decisive decision.

So the publishers win, right? I don't think so.

The trial itself is a cornerstone in the fight against piracy, but focusing on that misses the point. Don't get me wrong, I'm not pro any illegal activity, however some illegal activities stem from a need that's not met by what the industry has to offer; something people are willing to pay for. It's not that people didn't want to pay for music and movies - they just didn't want to pay for them in the way they were bundled by the publishers. And from this perspective, the publishers lost. They lost their old business model to the vast end-user-driven movement that spun piracy: iTunes (paying for single songs), Netflix (subscription based streaming), Spotify (free music discovery) and Hulu (ad based streaming) are examples to models that evolved since publishers had to change. Who won the pirate bay trial? Irrelevant in the long term. The important thing is that users get more of what they want.

The same rule applies to secondary markets in online games.

I spoke to a few publishers over the last few months, and especially at GDC. I asked a simple question - why don't you support p2p trade and secondary markets? The answers varied, but most of them responded just like a music publisher in the pre-iTunes era: it just doesn't fit their business model.

Most games provide their players with progression - along skill levels, story lines, levels, goods. When stripping them off fancy mechanics, in essence Farmville and WoW are similar in the sense that you have "stuff" you accumulate (be those points, ranks or cows) and you have a series of actions you can do you get them. In some of the cases, you also go through an internal narrative that adds another layer of "stuff" to achieve, this time story progression. Players get rewarded by the game, and invest in challenges that the game provides them with - and so gameplay, long hours of engagement and investment of time and money against game-initiated calls for action are what drive profitability. Secondary markets undermine this dynamic - players are supposed to buy content, currency and items from the publisher only, and buying them from other players ruins gameplay and works against the game's planning.

Sounds familiar, doesn't it?

The way I see it secondary markets represent something the player community needs and wants, and a necessary change to the way games are played. Allowing players to create value themselves and trade it with other players will only increase engagement with the game, not decrease it - provided that there is really an option for open ended play. Of course it creates additional challenges - farming, scams, fraud in p2p trade - but most of those are current issues for most online games and worlds, and instead of seeing its value churned by piracy and chasing down pirates, the gaming industry needs to make a decision to take this activity into the games. With the digitization of commerce, there's no reason why actual entrepreneurs cannot work in the virtual space as much as they would in the real world, and virtual worlds can be direct beneficiaries from sophisticated ecosystems. You only need to look at the numbers from Blizzard's latest launch of the "pets" on WoW to understand that reselling, and later turning these now-commodities into high value collectibles, is just around the corner - and gaming companies cannot allow themselves to not participate in one way or another.

It does seem, however, that gaming companies have identified this need and are working to accommodate it in future publications. Going back to the opening of this post, this is another place where "piracy" showed the industry where it needs to go; choosing to fight such a clear message from users doesn't really make sense. I, for one, am looking forward to in-game, open marketplaces booming.

Monday, March 8, 2010

Looking for candidates: Paypal New Ventures Risk

Over the past months I’ve been telling you about my take on risk management, automated decisions, digital goods and various other areas. I am now starting to look for candidates for my team to deal with these exact areas within Paypal – so if you’re one or think you know one, please let me know. Find the formal JD in the eBay site with req number 38550BR. But read on before that - the description in this post is much more important).

The team is Paypal's New Ventures Risk team, in charge of risk management for Paypal's newest, most innovative ventures, leading Paypal's growth in new markets and with new technologies. The role is for a leader of the seller risk aspect of new ventures, dealing with sellers and developers using our most innovative products. Note: though the position is titled "manager", this is not a people management position.

What I’m looking for is results driven, quick thinking do-it-alls who want to be involved with new products, markets and risk challenges within Paypal. You should have the passion for consuming a lot of data and information, be able to learn quickly and identify and define trends in concise terms. You should be analytical and with a quantitative approach but not a data cruncher without any understanding of the big picture – we are playing at all fronts. Know or be able to learn how to drive processes through other people and organizations; working in ambiguous situations and coping with change is a must, as well as an ever changing operating rhythm. This is not your classic 9 to 5 and I’m not your classic 9 to 5 manager.

Experience is not a must (=graduates are also encouraged to apply), definitely not previous experience in risk management. However, please be an avid internet user, preferably a gamer in your past or present. Some security experience or tech savvy is a big plus – don’t get intimidated by developers, architects and tech talk. Impress me by having interesting hobbies out of work that you maintain although you are an aggressive achiever, and by having vast general knowledge (as in: you shout answers at “who wants to be a millionaire” while watching it on TV).

Read the blog. Process. Understand. Talk to me.

Monday, March 1, 2010

Dealing with International Fraud - a Few Basics

When we started looking for customers in the first payments startup I worked for, low hanging fruit were obvious. All you had to do to find them was look for a merchant's international shipping policy - or lack thereof - and continue from there. The value proposition we offered, where we would make final accept/decline decisions and insure them, was just good enough to be true and be worth a lot of money for those who wanted to expand internationally. Still, it wasn't easy to convince these guys to expand, I'll tell you that - for every one who was willing to check us out, at least ten were pretty happy selling internally in the US. Who thought of the international market at that time? Looking back at it, this was around the dawn of managed fraud and risk services, and though we spearheaded the offering for the more dangerous segments we most definitely weren't the only ones.

Now, however, of all the questions I am asked, the ones I hear the most - and with the most urgency in them - are the ones regarding international purchases. Unlike a few years ago, when merchants let themselves brutally limit international buyers and focused on domestic markets, it's clear today that global expansion is a key for sustained success. Every beginning publisher wants to talk localization. And they should: this is way more general than digital goods and content. While US eCommerce is forecasted to grow to 8% of all retail purchases in 2012, according to Gartner, European b2c sales are forecasted to outgrow US sales, and grow 20% in 2010, according to eMarketer. This is an amazing opportunity – and it means that a lot of real goods need to be shipped around the world. However, when you get to actually approving these transactions, often you find that you just don't get the tools you're used to outside of the biggest eCommerce markets and some don't even exist outside of the US.

So how do you deal with those tricky international purchases?

• Remember what international fraudsters aren’t – they’re not the people they are stealing from. Sounds very basic, but it will serve you well – most fraudsters are young, computer savvy males from 3rd world countries trying to use Western world cards and bank accounts. Note obvious mismatches in details: if details given for the customer (phone number, card bin country, address) just don’t match, come from distant parts of a country or look invented, beware.

• Purchasing history from other merchants, through a 3rd party vendor, serves you mostly when you delay shipment (either because it’s standard practice or you’re suspicious). For all other cases, you need to have velocity checks and an ability to identify returning fraudsters alternating details. There are some good machine-ID companies out there, but you also have to complement with rules that identify purchasing behavior that is different than what you are used to in your industry and shop.

• Contacting users makes sense – but only when you understand what contacting them tells you. Calling a VoIP phone does no good, same as emailing someone whose email domain ranges from the ridiculous @legit.com to the less obvious @army.com; some seemingly fine domains host sites that are nothing but a blank page, so checking occasionally makes sense.

• IP intelligence can teach you a lot – you wouldn’t be surprised to hear that there are more fraudsters and more exploited, Trojan infested computers in big cities with high speed internet. It’s always good to know more about your user’s connection, especially if they are risky – if someone is initiating a payment to your site from within Microsoft’s Azure cloud, you may be up for some trouble.

• Find alternative data sources. No other country has such extensive public data sources of its citizens as the US, but free and paid data bases exist outside of the US too. A good address and name resource like 192.com helps you know more about your customer, and social networks span world wide. Too bad fraudsters can use this too…

• And, last but not least – know that there are legitimate people out there acting very ordinarily, but in a way that might strike you initially as dangerous. Where people relocate between states in the US, in the EU they do so between countries. Belgium and France share a language, and exactly as an Austrian might have a German bank account, so can someone from the Turkish minority. Time to polish your skills in geography, and read some Wikipedia pages!

Applying the above should take you a few additional steps in your way to open up your site to international commerce. And one additional thing to remember: deploying a great set of filters in place is close to useless without having a team reiterate on it and improve it as user behavior changes - the alternative is reactive risk management, slowly closing down itself using black lists and limitations until you resort back to the good ol’ US domestic shipping. Don’t let that happen to you, the international opportunity is too big to miss on.