PayPal is probably the most inspired half hour's work anyone has ever done on the internet. Of course, without its older sibling, eBay, it would never have happened, or if it had it would have been in serious competition. But it grew out of a need to service the burgeoning eBay as it grew from a niche website into a global phenomenon and the users needed a safe way to pay each other. What the PayPal team come up with is what is called an escrow account, a neutral place where the buyer can lodge a sum of money pending receipt of goods bought. The seller only gets his or her money once the transaction is complete.
It grew quickly because nobody else thought to build a system like it at the time. The big banks were making lots of money on dodgy deals that eventually turned sour and they had to be bailed out by their local governments, or you and me as I like to think of them. Not all banks needed bailing out - quite a few managed to limp through the credit crunch and some just rolled over. I don't think I ever heard any suggestion that the bank that calls itself PayPal had to rattle a cap near a government.
Of course PayPal doesn't have conventional current accounts although you can lodge money in there earning zero interest if you want. If that sounds familiar, it's probably because your present current account pays pretty much the same as PayPal. However your current account probably provides you with a cheque book to make payments from and I'm not sure PayPal does that. I'm not sure they'd want to either, given that it's an antiquated payment method put into shadow by PayPal's instant payment methods. You can pay bills and automate regular payments through your normal bank account and this is probably an area PayPal doesn't compete in - yet.
Because they're solvent, international, uninhibited by national boundaries and have a branch on every laptop, mobile phone and iPad I suspect that many of us find ourselves using PayPal for more than paying for bargains we've won on eBay. Many do so already as many on-line traders already accept PayPal for what could be considered normal transactions without an eBay presence and I've noticed a plethora of local shops that accept PayPal payments so that kids can convert their paper round wages into internet trading vouchers without the need of involving a national bank. In fact I wouldn't be surprised to find that some people had their weekly wage paid into PayPal right now and in fact, for those who would struggle to open a conventional bank account, PayPal is probably a good option as it doesn't allow you to overdraw, a reason why some people can't obtain a conventional bank account.
In fact, some of us do have a portion of our wages paid into PayPal already. Many international authors using Smashwords, which funnels all the payments made into Apple, Sony, Barnes & Noble, Kobo and so on pays us authors via PayPal, or at least most of us.
Now there is a rule that suggests you can't have a Coca Cola without a Pepsi; it's a rule that market forces insist on eventually but one that PayPal have managed to avoid for some time. It looks like the challenge is on its way, though. Obviously the mainstream banks are still a bit tarnished with the credit crunch and will struggle to persuade consumers to move from PayPal and into their arms, but of course the new giants aren't from the financial sector but are the tech companies.
Google, a company that does appear to have the requisite solvency to challenge PayPal, is having a go. In fact they've been doing this in the US for a while, but they are moving into the UK now with a service called Checkout. It works much like PayPal - why try to fix something the isn't broke? - and it's for on-line payments. There's an uphill battle in store for Google - most of us have a PayPal account because we've dabbled in eBay in the past and these accounts already exist. As PayPal has rolled out more usability then we've moved with them. We're going to need a compelling reason to sign up for Checkout, and I guess eBay won't be nudging us towards them.
But competition is usually a good thing, so it will be interesting to watch what happens with Google Checkout. I can't see how they can make the process cheaper or easier, and of course forcing people using Google Play to use their service is commercial suicide, so the only way is up. Perhaps we can look forward to getting some interest on money lodged in these accounts or maybe they'll move into the mortgage business? Whatever they do, it's likely to benefit the consumer.
------------------------------------------------------------------------------------
Visit my Book Website here
Visit Project: Evil Website here Visit DLF Website here
Follow me on Twitter - @RayASullivan
Join me on Facebook - use raysullivan.novels@yahoo.com to find me
Ray Sullivan publishes fiction adventures and comedic novellas on Amazon. He also muses on technology, posts books in serial format and discusses the world of self publishing.
Showing posts with label PayPal. Show all posts
Showing posts with label PayPal. Show all posts
Friday, 24 May 2013
Thursday, 16 May 2013
Passwords Are Barking Up The Wrong Tree
There's an organisation called FIDO - yes, I know, it featured in at least one Scooby Doo episode and a couple of Tom and Jerry cartoons too - that wants to change the way we shop and interact generally with the internet.
You see, most on-line transactions are only relatively secure. Sure, the retailers you use will have a secure server, there's encrypted messages and of course, your password. I say password because most normal people have just the one, maybe two. Because remembering Aunt Mabel's wedding anniversary and the title of the first film you ever saw in the cinema are difficult enough to remember. Add another couple of random facts and your mind is going to meltdown.
In fact the industry would be rather pleased if everyone used passwords as complex as the one I've suggested - and if any wannabe hacker is looking up my family tree, I don't think I've ever had an Aunt Mabel. I'd hate to waste your precious if illegally spent time.
But the reality is that remembering truly complex passwords - you know, random combinations of letters, numbers and punctuation marks - is hard work, especially if you have a lot of accounts out in cyberspace. And it's not as though the holders of the secure servers have been immune to successful attacks over the last year or so. Sony was hacked - that we know because they owned up. There have been other high profile hacks recently, too. My guess is not all organisations, when hacked, tell us.
This is where Michael Barratt, PayPal's Chief Information Officer comes in. Not content with working tirelessly at managing PayPal's information, he's also the president of the Fast Identity Online (FIDO) Alliance.
FIDO is keen to migrate us away from secure passwords because basically they're not really secure. They note that while we may have a few very secure passwords we do have a habit of using them in a number of locations and therefore the password is only as secure as the least secure location. They also realise that being mostly human, we'll continue to do this until we're all compromised.
So, what's better than a secure password? No password, reckon FIDO. They make the observation that most of us carry out our transactions on a limited number of devices - sure, you may hop onto a mate's iPad to bid for something on eBay once in a blue moon, but most of your online transactions will be on a finite and auditable number of computers.
They want us to migrate to FIDO enabled devices that use a combination of fingerprint matching, hardware tokens and USB memory sticks plus some trick software. They've developed the standard and hope that FIDO enabled equipment will start shipping this year.
OK, details are necessarily scant, but for me I'm not wholly on-board. I agree that passwords are an imperfect solution to the problem but I'm not convinced about the FIDO approach, either. Fingerprints, while largely unique, are reproducible, hardware tokens sound like they will work until they won't, and that day will be the day I want to access my bank account, USB memory sticks are becoming persona non grata in many ways and software - don't talk to me about software.
There will be a way to solve this problem and biometrics will probably be part of it - as the FIDO fingerprint standard suggests - and I suspect that the solution will be simpler than the proposal. I think FIDO do have a point about us using a finite number of devices and that insight is probably pure genius - maybe we will need a super password to access our stuff when away from any of our normal devices, but if a way of carrying out our transactions using our regular devices can be devised then that will make hacking harder. After that it probably boils down to finding a sensible biometric we can use. It may even be staring us in the face.
Visit my Book Website here
Visit Project: Evil Website here Visit DLF Website here
Follow me on Twitter - @RayASullivan
Join me on Facebook - use raysullivan.novels@yahoo.com to find me
You see, most on-line transactions are only relatively secure. Sure, the retailers you use will have a secure server, there's encrypted messages and of course, your password. I say password because most normal people have just the one, maybe two. Because remembering Aunt Mabel's wedding anniversary and the title of the first film you ever saw in the cinema are difficult enough to remember. Add another couple of random facts and your mind is going to meltdown.
In fact the industry would be rather pleased if everyone used passwords as complex as the one I've suggested - and if any wannabe hacker is looking up my family tree, I don't think I've ever had an Aunt Mabel. I'd hate to waste your precious if illegally spent time.
But the reality is that remembering truly complex passwords - you know, random combinations of letters, numbers and punctuation marks - is hard work, especially if you have a lot of accounts out in cyberspace. And it's not as though the holders of the secure servers have been immune to successful attacks over the last year or so. Sony was hacked - that we know because they owned up. There have been other high profile hacks recently, too. My guess is not all organisations, when hacked, tell us.
This is where Michael Barratt, PayPal's Chief Information Officer comes in. Not content with working tirelessly at managing PayPal's information, he's also the president of the Fast Identity Online (FIDO) Alliance.
FIDO is keen to migrate us away from secure passwords because basically they're not really secure. They note that while we may have a few very secure passwords we do have a habit of using them in a number of locations and therefore the password is only as secure as the least secure location. They also realise that being mostly human, we'll continue to do this until we're all compromised.
So, what's better than a secure password? No password, reckon FIDO. They make the observation that most of us carry out our transactions on a limited number of devices - sure, you may hop onto a mate's iPad to bid for something on eBay once in a blue moon, but most of your online transactions will be on a finite and auditable number of computers.
They want us to migrate to FIDO enabled devices that use a combination of fingerprint matching, hardware tokens and USB memory sticks plus some trick software. They've developed the standard and hope that FIDO enabled equipment will start shipping this year.
OK, details are necessarily scant, but for me I'm not wholly on-board. I agree that passwords are an imperfect solution to the problem but I'm not convinced about the FIDO approach, either. Fingerprints, while largely unique, are reproducible, hardware tokens sound like they will work until they won't, and that day will be the day I want to access my bank account, USB memory sticks are becoming persona non grata in many ways and software - don't talk to me about software.
There will be a way to solve this problem and biometrics will probably be part of it - as the FIDO fingerprint standard suggests - and I suspect that the solution will be simpler than the proposal. I think FIDO do have a point about us using a finite number of devices and that insight is probably pure genius - maybe we will need a super password to access our stuff when away from any of our normal devices, but if a way of carrying out our transactions using our regular devices can be devised then that will make hacking harder. After that it probably boils down to finding a sensible biometric we can use. It may even be staring us in the face.
------------------------------------------------------------------------------------
Visit my Book Website here
Visit Project: Evil Website here Visit DLF Website here
Follow me on Twitter - @RayASullivan
Join me on Facebook - use raysullivan.novels@yahoo.com to find me
Wednesday, 15 May 2013
How Would You Like To Pay, Pal?
I've been a vocal supporter of the cashless society for years. As a junior member of the RAF I think I joined it for a while, having taken a massive pay drop to follow a career in the military. But long before Transport for London introduced the Oyster card I was boring the pants of every landlord in any pub I found myself in that a cashless payment system was what we need in this country. To be fair, I was most vocal as my real cash reserves diminished and the alcohol levels increased.
Basically my views were, and remain, that taking a wallet out for a night in the pub is a foolhardy exercise. Until recently most UK pubs only took cash for normal beer tinged transactions, only taking credit and debit cards for larger deals, usually where meals or bottles of champagne (for Hooray Henrys and other Rodney types - not the Sullivan household please note) were involved. Of course we all stop off at the ATM, withdraw a sensible amount based on what we expect to pay for the night with a small amount of contingency. This is our first mistake - we should withdraw enough to keep ourselves drinking until the pub closes or dawn, whichever is likeliest - but the optimist in us always assumes we'll stop at a sensible time.
We also tend not to sanitise our wallets before leaving, so they are full of credit cards, debit cards, driving licences and loyalty cards. If a thief takes the wallet they have access to all the Tesco loyalty points we own.
In my world I'd like to take a single card out with me, stop off at the ATM and charge the card up with my estimate of what I expect to spend, with enough contingency for a takeaway meal afterwards. I'm not a big fan of over-complicated passwords but in this case I would support a sixteen digit PIN - if I run out of cash and am too drunk to remember a simple sequence of sixteen numbers, some in scientific notation of course, then I really need to go home. In the pub, and the takeaway later, I use the plastic card to pay for all my purchases. If I lose the card then I've lost no more than if I'd lost the wallet I no longer need to carry, but still have my credit and debit cards safely at home. Maybe I'll also keep a back-up card with enough money on to buy me a final beer and a taxi home in my sock, just in case. The payments would be contactless and in an ideal world wouldn't cost the retailer any fees either.
Bonkers? Probably to a banker because they like to make money every which way, but look at it from another perspective. Thousands, possibly millions of people loading up such cards for specific and emergency needs, leaving cash on them all the time. That's a lot of cash tied up in escrow for banks to play with, so they win with this system anyway. At the moment no bank is offering this because they want to charge the retailers a fee for processing the deal, but what if just one bank saw the opportunity and decided to offer the facility? Well, I reckon they would find retailers would sign up pretty quickly as there would be no reason not to and a majority of customers, the ones with cash, would migrate to their bank in droves. Obviously the other banks would then be forced to offer the same deal, but they would have been wrong-footed by the bank that decided to implement this idea (and hopefully promote the smart banker who read my blog). One bank would gain a lot, the other banks would be playing catch up, the retailers will see a boost to their sales and the consumer wins hands down.
And I get to keep my wallet for when I'm sober.
In the meantime PayPal are trying something similar but ultimately much more techy. They are looking at introducing a similar point of sale process using PayPal, although I suspect they'll be looking at charging retailers for the service, but it does have some interesting features. The main feature is that the customer registers with stores that sign up for their 'Check In' system by 'swiping a PIN on the retailer's web page', according to the article I've read. Unfortunately the article doesn't explain exactly what this means, so I'm guessing you access the web-page and register with a PIN you've agreed with PayPal. It may mean something else, so don't blame me if it's wrong - I've just given you a template for world beating e-commerce already and I think I made that plain enough. I get the impression that you register with the retailer when you enter their premises, using the PayPal concept.
Anyway, once registered for the PayPal system, you tell the retailer that you want to pay by PayPal and they book all your bills to your account. You don't sign anything, you don't pop in a PIN and you don't need a card. You don't even need to get your phone out to swipe across a device as they will have your photo on electronic file. And that means they can tell if it's you, even if you're so drunk you can't tell if it's you.
And that's why I think I prefer my method.
Visit my Book Website here
Visit Project: Evil Website here Visit DLF Website here
Follow me on Twitter - @RayASullivan
Join me on Facebook - use raysullivan.novels@yahoo.com to find me
Basically my views were, and remain, that taking a wallet out for a night in the pub is a foolhardy exercise. Until recently most UK pubs only took cash for normal beer tinged transactions, only taking credit and debit cards for larger deals, usually where meals or bottles of champagne (for Hooray Henrys and other Rodney types - not the Sullivan household please note) were involved. Of course we all stop off at the ATM, withdraw a sensible amount based on what we expect to pay for the night with a small amount of contingency. This is our first mistake - we should withdraw enough to keep ourselves drinking until the pub closes or dawn, whichever is likeliest - but the optimist in us always assumes we'll stop at a sensible time.
We also tend not to sanitise our wallets before leaving, so they are full of credit cards, debit cards, driving licences and loyalty cards. If a thief takes the wallet they have access to all the Tesco loyalty points we own.
In my world I'd like to take a single card out with me, stop off at the ATM and charge the card up with my estimate of what I expect to spend, with enough contingency for a takeaway meal afterwards. I'm not a big fan of over-complicated passwords but in this case I would support a sixteen digit PIN - if I run out of cash and am too drunk to remember a simple sequence of sixteen numbers, some in scientific notation of course, then I really need to go home. In the pub, and the takeaway later, I use the plastic card to pay for all my purchases. If I lose the card then I've lost no more than if I'd lost the wallet I no longer need to carry, but still have my credit and debit cards safely at home. Maybe I'll also keep a back-up card with enough money on to buy me a final beer and a taxi home in my sock, just in case. The payments would be contactless and in an ideal world wouldn't cost the retailer any fees either.
Bonkers? Probably to a banker because they like to make money every which way, but look at it from another perspective. Thousands, possibly millions of people loading up such cards for specific and emergency needs, leaving cash on them all the time. That's a lot of cash tied up in escrow for banks to play with, so they win with this system anyway. At the moment no bank is offering this because they want to charge the retailers a fee for processing the deal, but what if just one bank saw the opportunity and decided to offer the facility? Well, I reckon they would find retailers would sign up pretty quickly as there would be no reason not to and a majority of customers, the ones with cash, would migrate to their bank in droves. Obviously the other banks would then be forced to offer the same deal, but they would have been wrong-footed by the bank that decided to implement this idea (and hopefully promote the smart banker who read my blog). One bank would gain a lot, the other banks would be playing catch up, the retailers will see a boost to their sales and the consumer wins hands down.
And I get to keep my wallet for when I'm sober.
In the meantime PayPal are trying something similar but ultimately much more techy. They are looking at introducing a similar point of sale process using PayPal, although I suspect they'll be looking at charging retailers for the service, but it does have some interesting features. The main feature is that the customer registers with stores that sign up for their 'Check In' system by 'swiping a PIN on the retailer's web page', according to the article I've read. Unfortunately the article doesn't explain exactly what this means, so I'm guessing you access the web-page and register with a PIN you've agreed with PayPal. It may mean something else, so don't blame me if it's wrong - I've just given you a template for world beating e-commerce already and I think I made that plain enough. I get the impression that you register with the retailer when you enter their premises, using the PayPal concept.
Anyway, once registered for the PayPal system, you tell the retailer that you want to pay by PayPal and they book all your bills to your account. You don't sign anything, you don't pop in a PIN and you don't need a card. You don't even need to get your phone out to swipe across a device as they will have your photo on electronic file. And that means they can tell if it's you, even if you're so drunk you can't tell if it's you.
And that's why I think I prefer my method.
------------------------------------------------------------------------------------
Visit my Book Website here
Visit Project: Evil Website here Visit DLF Website here
Follow me on Twitter - @RayASullivan
Join me on Facebook - use raysullivan.novels@yahoo.com to find me
Subscribe to:
Posts (Atom)