Monday, June 7, 2010

How not to sell your product, or: is there really a "Silver Bullet" for Mobile Payments security?



Engineers tend to frown at marketing and BD, but creating leads or closing a deal is never easy. No matter where you are you want to be able to clearly articulate what is the customer’s pain point that you are solving. And you want your solution to be as straight forward as possible, too. If you resort to detailed tables and text you’re bound to lose most of your potential customers along the way. One thing I like about mobile payment companies’ pitch is that it’s pretty straight forward; both Boku and Zong articulate very clearly that yes, they have higher fees, but overall their much higher conversion rates increase revenue. Simple and straightforward; I like that. Other mobile payments vendors follow suit with similar pitches.

Why some Mobile Payments vendors are missing the point

Some of these vendors are veteran companies rebranding for the digital goods space and as such talk the “new” mobile payments talk but do not walk the walk. You can’t, for example, claim you’re providing a seamless experience when you require a three page signup process on first payment; your product must support your value proposition. Still, I have encountered companies that claim exactly that – and fail to understand why a cumbersome sign up process is an issue. I can imagine how some of these products evolved: starting in technologically limiting environments, with little to no data sources available and nothing but premium SMS billing. Faced with these difficulties, the ability to create any sign up flow or get an integration agreement with an operator looked like a huge achievement. And it was. But as depressing as it is to see your market changing, empowering payments in a card-not-present environment is today almost a commodity and operator integration is a limited, narrowing edge. He who wants to survive adjusts, or continues to try to sell payments triggered via, let’s say, IVR call to a landline. I’m sure there’s a need for first-generation payments somewhere on the globe; in most developed markets these look displaced.

Commodities and risk management 

I find this obvious since commoditization also creates pitch and product distortions in my own back yard, risk and fraud management. How did that happen? 5 years ago it was harder to compete with internal risk departments. With the eCommerce boom, however, came the proliferation of fraud as fraudsters (and the average Joes of the world) realized how easy it was. With this came a demand for risk management tools and methods. Many companies emerged in response, and each had to evolve quickly to gain market share and capitalize on an almost vacant market. Since the business was so nascent (and, I would argue, still is far from full potential), little technology innovation was required to reach stellar improvements in any point in the funnel; and since all of these companies provided indicators to help support the retailer’s decision (rather than the decision itself), the sales tactic was geared toward convincing the customer to add your score to the variety of scores they were already using. And it worked: merchants are using on average between 4 to 5 different decision supporting tools and indicators. But the cost was commoditization and an ever degrading technological edge. This has already started to come into effect and change the way risk and fraud are discussed.

Scaring them used to work

Sometimes finding a pain point is complicated since the customer is either unaware of a problem or aware of it but does not think it merits attention. When pitched FraudSciences’ product, even though we offered an insured decision to merchants to expand their business to new markets, often times the initial response was negative. Getting merchants to understand “why now” is always a challenge, and with the growth we see in Digital and Virtual Goods publishers sometimes don’t even have the time to consider (as I noted in the past, zero cost of goods produced is both a blessing and a curse). But it seemed as though for some of the companies the approach changed into forcing customers to realize they have a problem, even when they don’t necessarily have one. This is the “scare pitch”; I recently spent some time with a content publisher that told me about a similar conversation with another payments provider. A good part of the talk was aimed at explaining why fraud is so dangerous while fact of the matter is that currently, content providers aren’t immediate targets (since content is not as easily monetized as other goods). Why try to scare customers into buying your service when they have no actual need? Because most tools and services provide negligible incremental value and this is the only way to get customers to add another one to the pile – like any premium-hungry insurance company, scare them with hell and make sure they sign the policy. The alternative is, of course, enabling an experience that unlocks more revenue rather than catches all the “bad guys”. And that’s exactly where the product is lacking.

Is there really a new silver bullet?

Since the pioneers of risk management in eCommerce were mostly web-security geeks, a fraudulent transaction was (and still is) viewed as a transaction made from a “bad machine” (rather than “by a bad user”, a very important distinction). If we could only map all the bad boxes in the world, says this logic, we can stop fraud. This is what “machine fingerprinting” is about. Most leading companies hence focused on black-list type systems geared at collecting as much anonymous information as possible to be able to identify machines without necessarily identifying its owners. The story repeated itself with IPs, cookies, browser profile and now the latest addition – mobile device ID. As with its predecessors in the role of silver bullet or even better than some of them, mobile device ID is not easily spoof-able, is relatively easy to retrieve and is (supposedly) unique. Problem solved, right? Not so. With so many phones manufactured, stolen and exchanged in a year, it’s easy to see that simply keeping a list of “bad devices” won’t cut it – same as with other devices and boxes, if you base you classification on a “device bad history”, you fail every time you see a new device; and you fail every time good and bad users share a device since one bad user “contaminates” the device for all others. A hacked phone is, like a hacked machine with a proxy set up in it, simply a relay. The real “badness” of a device should always be viewed as probabilistic, in the current context of the actions made on it, and compared to other details we may have on the user allegedly using it. That is why a system without Personal Identifier Information is nothing more than a mildly sophisticated black-list.

This is not a subtle point but it might be lost if all we're looking to gain is that small edge. In dealing with mobile devices I find that creating a pattern to recognize still encounters major issues: geolocation reliability, network topology and new patterns of user usage are just three considerations that make mobile payments more than just an extension of desktop purchases. Focusing on adding device IDs to a device fingerprint, without creating a viable solution to initial encounters or devices being transferred between users is similar to looking at a problem space through a keyhole. It just won't cut it. 

Why this is important

Turning eCommerce into virtual commerce and the mobile phone into a wallet will require a high level of trust between participants, since virtual communities and f2f proximity payments are new ideas and new experiences. Enabling that exchange is one of the best outcomes of effective risk management and user identity and intent assertions, but the current trend isn’t necessarily heading at that direction. I believe it should, but that would require profound pitch, product and point of view change. 

Tuesday, May 18, 2010

Facebook showing Traces of Crowd Sourcing in Risk Management (?)



Picture by Matthew Filed/Creative Commons

If you're following the blog, you know I'm a big advocate of using the "wisdom of the masses" (well... at least their accumulated computational ability) to crowd-source complex tasks that cannot be easily automated. The way I see it, it's not that users merely "don't mind", they actually expect that to happen. This is the reason I'm pro offer walls (well, at least some of them) and like the concept of “jobs” or “tasks” incorporated into these walls. There's a lot to be done in the area of engaging users around various complex decisions, risk management being one of them (see other ideas on gwap). Now, I don't think that we cracked the code of making financials and risk interesting – whether it’s because financials are less “sexy” or because or more elusive reasons - but I do enjoy seeing interesting attempts.

That's why I liked the feature I discovered in a TC post: 


Yeah, I know, you’re wondering what I am so excited about. Well, for me it goes back to the dynamics that help establish and nurture communities. Online communities are here to stay, from Habbo hotel to SL to social networks. Communities like Facebook are growing by mere network effect; every day, people are pouring into the platform to interact, share, play. And at the same time, you can’t help but hear the murmur: Facebook did this, Facebook did that, I don’t like the new layout, I hate the privacy policy. This might means that we have (potentially) passed the docile stage of throwing sheep at other users, to the involvement period. What’s that? Basically, creating a real, lasting online community requires more than a news feed and a constant unedited stream of brain farts (dad, I actually like yours. Really). It requires users’ engagement, their involvement in regulating their environment, in setting its rules and in actively helping to make it better. It requires some kind of ownership, a sense of responsibility. This is what creates a healthy community that can be actually leveraged as more than a collection of unrelated, though somewhat connected, individuals. And that’s the reason why I like the potential of this nascent form of crowd-sourcing risk management: from my point of view, it’s a fair attempt at starting to enable users to assume that kind of responsibility. It’s a call to action where Facebook’s Risk team, effectively the police in a network that’s around 1.5X the size of US population, is asking you to join the neighborhood guard. If it’s really your neighborhood, won’t you act to keep it peaceful?

That’s why I like it. Or, at least, that’s the potential I’m loading on one poor notification feature… The other reason is, of course, the poetic justice of using the same type of resources fraudsters are using to overcome standard risk controls to actually deter fraud. Gotta love that.

What is your take on crowd sourcing risk-related process in your system?



PS
In case you’ve never seen it, catch this remarkable piece of the performing arts.
Lyrics are here.

Saturday, April 24, 2010

Blizzard, secondary markets and the gaming industry

Phew... after two months of work, I can take a step back and go back to blogging.

Who won the "Pirate bay" trial?

The simplistic answer is obvious: though currently in appeal (scheduled to open September of this year) the site's operators were convicted on April 17th, 2009 in accessory to crime against copyright law, and were sentenced to a year in jail and over $3.5M for fines and other damages. I would call this a pretty decisive decision.

So the publishers win, right? I don't think so.

The trial itself is a cornerstone in the fight against piracy, but focusing on that misses the point. Don't get me wrong, I'm not pro any illegal activity, however some illegal activities stem from a need that's not met by what the industry has to offer; something people are willing to pay for. It's not that people didn't want to pay for music and movies - they just didn't want to pay for them in the way they were bundled by the publishers. And from this perspective, the publishers lost. They lost their old business model to the vast end-user-driven movement that spun piracy: iTunes (paying for single songs), Netflix (subscription based streaming), Spotify (free music discovery) and Hulu (ad based streaming) are examples to models that evolved since publishers had to change. Who won the pirate bay trial? Irrelevant in the long term. The important thing is that users get more of what they want.

The same rule applies to secondary markets in online games.

I spoke to a few publishers over the last few months, and especially at GDC. I asked a simple question - why don't you support p2p trade and secondary markets? The answers varied, but most of them responded just like a music publisher in the pre-iTunes era: it just doesn't fit their business model.

Most games provide their players with progression - along skill levels, story lines, levels, goods. When stripping them off fancy mechanics, in essence Farmville and WoW are similar in the sense that you have "stuff" you accumulate (be those points, ranks or cows) and you have a series of actions you can do you get them. In some of the cases, you also go through an internal narrative that adds another layer of "stuff" to achieve, this time story progression. Players get rewarded by the game, and invest in challenges that the game provides them with - and so gameplay, long hours of engagement and investment of time and money against game-initiated calls for action are what drive profitability. Secondary markets undermine this dynamic - players are supposed to buy content, currency and items from the publisher only, and buying them from other players ruins gameplay and works against the game's planning.

Sounds familiar, doesn't it?

The way I see it secondary markets represent something the player community needs and wants, and a necessary change to the way games are played. Allowing players to create value themselves and trade it with other players will only increase engagement with the game, not decrease it - provided that there is really an option for open ended play. Of course it creates additional challenges - farming, scams, fraud in p2p trade - but most of those are current issues for most online games and worlds, and instead of seeing its value churned by piracy and chasing down pirates, the gaming industry needs to make a decision to take this activity into the games. With the digitization of commerce, there's no reason why actual entrepreneurs cannot work in the virtual space as much as they would in the real world, and virtual worlds can be direct beneficiaries from sophisticated ecosystems. You only need to look at the numbers from Blizzard's latest launch of the "pets" on WoW to understand that reselling, and later turning these now-commodities into high value collectibles, is just around the corner - and gaming companies cannot allow themselves to not participate in one way or another.

It does seem, however, that gaming companies have identified this need and are working to accommodate it in future publications. Going back to the opening of this post, this is another place where "piracy" showed the industry where it needs to go; choosing to fight such a clear message from users doesn't really make sense. I, for one, am looking forward to in-game, open marketplaces booming.

Monday, March 8, 2010

Looking for candidates: Paypal New Ventures Risk

Over the past months I’ve been telling you about my take on risk management, automated decisions, digital goods and various other areas. I am now starting to look for candidates for my team to deal with these exact areas within Paypal – so if you’re one or think you know one, please let me know. Find the formal JD in the eBay site with req number 38550BR. But read on before that - the description in this post is much more important).

The team is Paypal's New Ventures Risk team, in charge of risk management for Paypal's newest, most innovative ventures, leading Paypal's growth in new markets and with new technologies. The role is for a leader of the seller risk aspect of new ventures, dealing with sellers and developers using our most innovative products. Note: though the position is titled "manager", this is not a people management position.

What I’m looking for is results driven, quick thinking do-it-alls who want to be involved with new products, markets and risk challenges within Paypal. You should have the passion for consuming a lot of data and information, be able to learn quickly and identify and define trends in concise terms. You should be analytical and with a quantitative approach but not a data cruncher without any understanding of the big picture – we are playing at all fronts. Know or be able to learn how to drive processes through other people and organizations; working in ambiguous situations and coping with change is a must, as well as an ever changing operating rhythm. This is not your classic 9 to 5 and I’m not your classic 9 to 5 manager.

Experience is not a must (=graduates are also encouraged to apply), definitely not previous experience in risk management. However, please be an avid internet user, preferably a gamer in your past or present. Some security experience or tech savvy is a big plus – don’t get intimidated by developers, architects and tech talk. Impress me by having interesting hobbies out of work that you maintain although you are an aggressive achiever, and by having vast general knowledge (as in: you shout answers at “who wants to be a millionaire” while watching it on TV).

Read the blog. Process. Understand. Talk to me.

Monday, March 1, 2010

Dealing with International Fraud - a Few Basics

When we started looking for customers in the first payments startup I worked for, low hanging fruit were obvious. All you had to do to find them was look for a merchant's international shipping policy - or lack thereof - and continue from there. The value proposition we offered, where we would make final accept/decline decisions and insure them, was just good enough to be true and be worth a lot of money for those who wanted to expand internationally. Still, it wasn't easy to convince these guys to expand, I'll tell you that - for every one who was willing to check us out, at least ten were pretty happy selling internally in the US. Who thought of the international market at that time? Looking back at it, this was around the dawn of managed fraud and risk services, and though we spearheaded the offering for the more dangerous segments we most definitely weren't the only ones.

Now, however, of all the questions I am asked, the ones I hear the most - and with the most urgency in them - are the ones regarding international purchases. Unlike a few years ago, when merchants let themselves brutally limit international buyers and focused on domestic markets, it's clear today that global expansion is a key for sustained success. Every beginning publisher wants to talk localization. And they should: this is way more general than digital goods and content. While US eCommerce is forecasted to grow to 8% of all retail purchases in 2012, according to Gartner, European b2c sales are forecasted to outgrow US sales, and grow 20% in 2010, according to eMarketer. This is an amazing opportunity – and it means that a lot of real goods need to be shipped around the world. However, when you get to actually approving these transactions, often you find that you just don't get the tools you're used to outside of the biggest eCommerce markets and some don't even exist outside of the US.

So how do you deal with those tricky international purchases?

• Remember what international fraudsters aren’t – they’re not the people they are stealing from. Sounds very basic, but it will serve you well – most fraudsters are young, computer savvy males from 3rd world countries trying to use Western world cards and bank accounts. Note obvious mismatches in details: if details given for the customer (phone number, card bin country, address) just don’t match, come from distant parts of a country or look invented, beware.

• Purchasing history from other merchants, through a 3rd party vendor, serves you mostly when you delay shipment (either because it’s standard practice or you’re suspicious). For all other cases, you need to have velocity checks and an ability to identify returning fraudsters alternating details. There are some good machine-ID companies out there, but you also have to complement with rules that identify purchasing behavior that is different than what you are used to in your industry and shop.

• Contacting users makes sense – but only when you understand what contacting them tells you. Calling a VoIP phone does no good, same as emailing someone whose email domain ranges from the ridiculous @legit.com to the less obvious @army.com; some seemingly fine domains host sites that are nothing but a blank page, so checking occasionally makes sense.

• IP intelligence can teach you a lot – you wouldn’t be surprised to hear that there are more fraudsters and more exploited, Trojan infested computers in big cities with high speed internet. It’s always good to know more about your user’s connection, especially if they are risky – if someone is initiating a payment to your site from within Microsoft’s Azure cloud, you may be up for some trouble.

• Find alternative data sources. No other country has such extensive public data sources of its citizens as the US, but free and paid data bases exist outside of the US too. A good address and name resource like 192.com helps you know more about your customer, and social networks span world wide. Too bad fraudsters can use this too…

• And, last but not least – know that there are legitimate people out there acting very ordinarily, but in a way that might strike you initially as dangerous. Where people relocate between states in the US, in the EU they do so between countries. Belgium and France share a language, and exactly as an Austrian might have a German bank account, so can someone from the Turkish minority. Time to polish your skills in geography, and read some Wikipedia pages!

Applying the above should take you a few additional steps in your way to open up your site to international commerce. And one additional thing to remember: deploying a great set of filters in place is close to useless without having a team reiterate on it and improve it as user behavior changes - the alternative is reactive risk management, slowly closing down itself using black lists and limitations until you resort back to the good ol’ US domestic shipping. Don’t let that happen to you, the international opportunity is too big to miss on.

Monday, February 22, 2010

New York under zero: some thoughts on the Engage! Expo

"If there are any Mattel engineers in the audience, the astronaut Barby's space suit is not crash proof" (loose paraphrasing on Will Wright's keynote)

Yep, the keynote was entertaining and Engage brought a lot of vendors to snowy New York's Javits center. The two day event, though a bit low on developers, had a few interesting sessions and some interesting chances to share opinions. So what did I pick up from these two full days?

Payments and mobile

This Engage was heavy on payments companies, and by payments I mean mostly - if not exclusively - mobile payments focusing on SMS billing through carriers (obviously Paypal was there - a few of my colleagues and me - and additional sponsors). While the value of mobile payments for a streamlined, high conversion purchasing experience is clear (on the verge of overstated), the abundance of these companies over such a small space only served to emphasize how not-that-different these companies are from one another. Better coverage, low fraud and a promise for lower fees in 2011 were the value propositions.

Now, while I think mobile payments are clearly an avenue the industry must pursue, it was clear to me that until operators make a big leap of faith to embrace mobile payments, this field will not move much unless the companies themselves move to a Zong+ like, account based system that allows users to add a financial instrument and for the mobile payments company to charge it directly. And, as you are soon to find out, account based systems are a whole new world of pain - while with direct billing you charge a prepaid or underwritten balance an operator is liable for, accounts are a much more complicated structure. Plainly put, you start writing big fat checks directly to fraudsters' pockets. Looking at chargebacks in hindsight, as at least two of the participants suggested, just doesn't cut it. So mobile payments are looking for the next big breakthrough, and if fees don't drop soon (and they probably won't), I'm expecting some M&A work as competition heats up.

Offers and tasks

I'm a long time advocate of offers. Yes, offers have their "dark side", when misused, however they have a huge potential for creating incremental volume - something I personally love. When at the conference I heard that Offerpal are integrating tasks from Amazon's Mechanical Turk, and have been hearing assertions that competitors are going to follow suit (also heard it on stage from IMVU.com's CEO). Why is this good? I think that using social gaming to crowdsource simple but human intensive tasks is good for user education - do something good instead of just signing up for Netflix (nothing bad about Netflix, though); plus, it's good for the potential work providers - ideally, research institutes, advanced OCR services and others. In short, tasks are the new "green". Two caveats in this optimistic view, though: the first is that there is a serious chance of shortage of tasks, at least until this market picks up; the second is that abusing this model is still doable, maybe even easier than standard offers - if I were a fraudster, I'd immediately outsource my CAPTCHA operation to Amazon. Oops! Better read previous posts and do some risk analytics, guys, or you'll find you're breeding an ecosystem of thieves.

Zero cost of goods

I had this feeling in the past, but the conference reassured me: the "zero cost of goods produced" concept is both a blessing and a curse. Why a blessing? Because developers, bathing in the sensational bliss of high margins, were keen on trying new things - new business models, new payment options (30% take for mobile payments? come on) and various experiments in user interaction (offers, vanity items and many other really cool stuff). Why a curse? Because the notion has outgrown its proper boundaries, actually harming some of the developers. Assuming that if you just auto-refund your zero-cost virtual good, the problem of chargebacks goes away is a mistake, and not checking operational costs related to this "zero cost" work will make your bottom line look pretty bad eventually. Additionally, zero cost of goods got many developers focused on solely growing their user base and ARPU - both important but, as a few speakers noted, shifted attention from a few other very important stuff. Like fraud, like going international, but also like pricing - when the third pretty senior person suggested to developers that going all-in on a freemium model just isn't a good idea, I started to understand that the problem transcends risk management and controls; it's starting to detach companies from sound business judgment. So this is probably time to reconsider - it's all a part of growing up as an industry.

P.S. One last thing

I was delighted to meet a few young and talented entrepreneurs working exactly on the things I find exciting - namely p2p trade and new, great ways to engage users. It's fun to see how ideas evolve, and I'm looking forward to hearing more about them and others like them. Well done, guys!

Sunday, February 14, 2010

Fraud detection and User Interaction: why are Millennials slower?

A scientist was conducting an experiment with a fly. He pulled off one of its legs and set it down to see if it could fly. Conclusion: a fly without one leg can still fly. He pared off a second leg and set it down, saying "Fly!" Conclusion: a fly without two legs can still fly. He removed all the legs and set the fly on the palm of his hand, shouting "Fly!" Conclusion: a fly without legs can still fly, briefly, before crashing to the floor. He pulled off all the fly's wings and set the fly on the palm of his hand, yelling "Fly!" Nothing. "Fly!" Nothing. Conclusion: a fly without wings is deaf.

This was an old, lousy and a bit vicious joke even when I was a kid. It does, however, effectively demonstrate a long lasting truth: it is not the collected data, but rather how we interpret it, that renders its effectiveness in decision making. Errors range from confusing cause and effect (is it that customers who experienced fraud are more active, on average, or that active customers are, in average, more prone to experience fraud?) to gross segmentation causing severe false positives; a lot of these cases are triggered by analysts sticking to high level, big numbers rather than complementing their analysis with case-by-case review and customer engagement. Business intelligence is a very important practice, and we must use our tools wisely to reach the best possible conclusions to guide our decisions.

One interesting case of interpretation I found was regarding Javelin's 2010 Identity Fraud Survey Report. Here's an excerpt from the link:

"18 to 24 Year Olds are Slowest to Detect Fraud – Millennials (consumers aged 18 to 24 years old) take nearly twice as many days to detect fraud, compared to other age groups, and thus are fraud victims for longer periods of time. Millennials were found to be the less likely to monitor accounts regularly and the least likely group to take advantage of monitoring programs offered by financial institutions. However, Millennials were the most likely group to take action such as switching primary banks or switching forms of payment."

Why is that? Well, looking for interesting opinions I came across this blog post. It suggests that Millennials are optimistic about the economy and feel invincible, being young, not imagining that fraud could happen to them. Interesting, but I don't buy into this kind of explanation, for two reasons: one, is that it's over simplistic in its description of Millennials' psych, but the second is that it puts a cap on our ability to engage with a group of users about their financials. It's just too important to let go: being able to engage with your user community to deter fraud will be a growing need for payment services in 2010 and beyond, and I claim that they expect this to happen. It just doesn't resonate with me that social networks and games can get you engaged but your bank or eWallet, the place where all your money is, can't. It's just a question of the right engagement model. What is the difference between those that work and those that fail? As a user myself, I don't feel like I have compelling interfaces that help me monitor my financials - and I log in to my online banking interface on a daily basis. There's just too much information, too many buttons and graphs to make sense. To add insult to injury, many monitoring programs (such as the lately advertized Chase debit card program) require users and parents to set their own monitoring rules. This reminds me of another area, online predator monitoring, which poses the same challenge to parents - you set the rules to monitor suspicious words in your child's IM. Seriously? We force the laymen to do our job for us? Can we really not provide a compelling, interactive, machine learning interface that provides an appealing user experience? I think we can. Especially if the alternative is accusing Millennials of being too optimistic.

Looping back to the beginning of the post, I'm just hypothesizing (or pulling the fly's leg, if you'd like). It's now a question of actually engaging with users and examining behavior to validate basic assumptions; something that we must do to make sure we understand the data we are getting. But this is my own hunch on Javelin's results. What do you think?

If you liked this post, please subscribe to my blog!