Sunday, March 06, 2011

On payments

Ohad Sammet, writing for TechCrunch:

“We hear a lot of chatter about new payment services, and who’s competing in the space, and obviously who’ll win the space or own a big piece of it. Lately we’ve seen some movement when both Apple and Google announced new payment options for digital publishers and exchanged a few blows. So are the giants going to displace PayPal soon?”

The current chatter about new payment services is usually triggered by extrapolations of the promises of NFC technology that is getting built into newish mobile hardware. There's a lot of valid discussion that can be had about this topic, but Apple's (or Google's) recent announcements of their terms for subscriptions have very little to do with it.


The subscription services launched by Apple and Google have to do with the cost structure of publishing content on their platforms, and what is the cut that is retained before paying the publishers. This is completely unrelated to the underlying payment infrastructure that is used to make these transactions.1

“The bottom line is that it is much harder to compete in payments using the same path PayPal took 10 years ago. Creating yet another network based on existing methods is a “me too” strategy that doesn’t provide real incentive for merchants to switch [...]. This is not real disruption. What is, then? I’m betting on two trends—payroll (becoming the wallet, getting people to keep their money with you) and short term credit (built from the ground up to be a robust system). This warrants a whole different discussion. Right now, however, it seems that Google and Apple are not going down those paths or presenting an alternative; and until they do so I believe they won’t be serious players in core payments.”

I don't see anything that would indicate that Google and Apple are not going down those paths, because as mentioned above, the subscription announcement have got nothing to do with this. (Neither do I see, by the way, anything that would indicate they are going down those paths, beyond rumors.)


What is clear however is that real disruption is exactly what is needed ; most of the complexities of payment systems today have to do with the existing cost structures and current infrastructure capabilities, and neither of these are immune to changes.


As Ohad mentions, using bank payments today has massive implications in terms of taking on risk for short-term credit. But in a connected world, I struggle to see any technological reason why a transaction between a payer and payee cannot be instantiated, validated and confirmed in a matter of seconds. This would eliminate the need for any payment processor to take on that short term credit risk.


And credit card payments are saddled with overly complex cost structures and terms, which — besides the fact that they are a golden goose for the likes of VISA and Mastercard — are obstacles to massive-scale acceptance as a peer-to-peer payment system — even with the beautiful work of companies like Square. The fees for merchants are variable depending on the terms of their contracts, on the physical presence of the card (swipe) and they are a confusing combination of both fixed costs (percentage of transaction) and variable costs (flat fee) ; although here again, Square must be applauded for taking this on and doing away with the confusing flat fee.


These constraints are based on antiquated systems and therefore heightened risk, and there is much potential for disruption here. There is also no reason whatsoever that a rectangular piece of plastic be required for effecting a payment. That is I think the last ball and chain of companies like Square, and while the ubiquity of the plastic card is what enables them to get the initial penetration and acceptance required for success, I also hope that they are already preparing for a future where these anachronistic artifacts are happily forgotten.



1. In Apple's case, the user pays 100% of the cost of the transaction using their iTunes account, which is backed by a credit card. Apple then distributes 70% of that to the publisher, usually via once-a-month bank transfers. None of that is changing.

Labels: , , , , , , ,

Friday, August 13, 2010

Open letter to Google on net neutrality

Dear Google,
Dear Mr. Brin and Mr. Page,
Dear Mr. Schmidt,

Until this week, Google had been maybe *the* foremost advocate and supporter of Net Neutrality since its inception. I remember first reading about the term and learning what the stakes were on the official Google blog several years ago. One post after another, Google was clearly taking the very strong position of defending the consumers' interests against that of a few corporations, and I was in admiration of that. Vint Cerf was even brought to Google as a spokesperson for Google's net neutrality lobbying efforts, because of the founding figure that he was with regard to the internet. In your eyes, he therefore represented the best person to make the case that the internet deserved to be preserved exactly like it was meant to be.

Your recent "joint legislative framework proposal" with Verizon is deeply hypocritical in this regard, and it has shattered the trust that I had in your organization. Crafting special language for "additional online services" that would not fall under net neutrality provisions is a shamefully sneaky way to insert a massive loophole in the text and completely undermine the principles at the core of net neutrality.
And the idea that wireless access to the internet should be considered separately from wired access to the internet, and therefore should be excluded from any of the critical net neutrality provisions is certainly the most egregious thing I have read in a long time. This amounts to taking people for fools. Wireless access to the internet is to the next decade and beyond what wired access to the internet was to the last two. And even if it were to always remain a marginal mean of accessing the internet, it should still be covered. Access to the internet regardless of the mean and transport of data through all of the internet is what should be protected, and not one bit of all this should be exempted.

It's also lost on no one that you now have with Android a vested corporate interest in shaping how internet regulations can work in your favor in the realm of wireless broadband. And to see such a quick and bold reversal from Google on something that was hailed as a core principle and value for your company is appalling and offensive. This is nothing short of a shameful sell-out to greed and power. I sincerely hope you reconsider your stance.

Sincerely,
Hugues de Saint Salvy

Labels: , , , , , ,

Friday, January 26, 2007

Suggestion for increased security in Google Docs & Spreadsheets

At some point last year Google launched "Google Docs & Spreadsheets", offering their users the opportunity to store, edit and share documents online. I love this product and I use it very frequently, for sharing documents, but also to keep a golden copy of important documents online so that I can access them wherever I am on the planet, with nothing more than a web connection.
However, as I started to add more personal documents I also became increasingly concerned about the potential for loss or abuse of my data. I am not so much worried about some Google employee being able to view my data stored on their servers. I know Google is very keen on protecting the data and privacy of its users, although I agree with John Battelle that we shouldn't become complacent and ignore the dangers of all our data being so vulnerable, within reach of one ill-intentioned but well-connected individual.
I am not so worried either about the lack of SSL encryption in Google Docs & Spreadsheets, which means that my data is being transmitted unencrypted from my computer to Google's server, available to be snatched by anybody watching Internet packets go by on my wireless network. I am worried about it of course, but it is possible to force Google Docs & Spreadsheets to work in SSL by using a Firefox extension such as CustomizeGoogle. (* see update below)
What I became concerned about was the potential for somebody from my inner circle of acquaintances (colleagues, friends, passing visitors, etc...) to be granted access to my personal documents without my knowledge or desire. It is well-known that identity theft crimes are often committed by a person in the inner circle of the victim, and by the same token I think this is how my data is the most vulnerable.

Google Docs & Spreadsheets is restricting access to your documents through your Google account and password, which are certainly secure in terms of their encryption ; however I find that many people are now logged almost constantly in their Google account, be it through the Google personalized homepage, Gmail, or any other Google service. This is good for Google of course, who benefits from the knowledge of your surfing habits, however it can open a breach in your own security. The "secure" protection that you thought your Google password provided is not going to be much of a barrier. For this reason, I posted a message on the Google Group for Google Docs & Spreadsheets, with a suggestion to improve the security for those few sensitive documents that you may have stored. The idea is inspired by the method that Google themselves (itself?) put in place to restrict access to your Search History: add a new layer of security, even though you are already logged into your Google account. Here is how Google explains it:
To help protect your privacy, we'll sometimes ask you to verify your password even though you're already signed in. This may happen more frequently for services like Personalized Search which involves your personal information.
My suggestion for Google Docs & Spreadsheet is very similar. Here is how the main page currently looks like:
Let's say you have two documents, "Sensitive Info Spreadsheet" and "Top Secret Document", that you would really like to keep private. The idea is to be able to lock (meaning: to encrypt) those documents and to ensure that they cannot be decrypted and read without first entering a password. My suggested implementation would be to add, next to the document title, a little lock that you could click/un-click, not unlike how the "star" function works. This could look something like this:
Clicking (activating) the little lock would do just that. The document would become instantly encrypted and protected, using your Google password (the same as your Google account). In order to read or unlock the document, you would have to enter your password in a little pop-up input field, like this:
I think this would be simple and efficient, however I welcome your comments and feedback. If you like this idea, I would recommend that you go to my post in the "Ideas & Suggestions" Google group and either rate my post and/or add a message to the thread. Hopefully if enough people express their interest in this, Google might pick up on it and implement it sooner.

Update (2007-07-26): Google upgraded their Docs & Spreadsheets about a month ago, and since around that time they also implemented SSL support for spreadsheets as well. This is a welcome improvement, unfortunately it does not address the other security and privacy issues mentioned above.

Labels: , , , ,