18 February 2018
Visit www.avoka.com

Selfie payments: Marketing stunt or the real deal?

25 May 2016  |  9568 views  |  0 Saccha Breite, SIX Payment Services

An increasing number of companies are working on new biometric procedures that quickly and conveniently prove the identity of users making payments. Sascha Breite, head future payments at the payment specialist SIX Payment Services, takes a closer look at 'Selfie Payments' and examines other European initiatives.

At the Mobile World Congress in Barcelona, MasterCard announced the launch of a new authentication solution: payment by ‘selfie’. This follows last summer’s announcement when, MasterCard stated that it wanted to make passwords and payment codes superfluous.

The rise of the selfie appears unstoppable. MasterCard is now counting on self-portraits for its payment procedures. Cardholders will soon be able to take a selfie at the supermarket cash register instead of entering a password in order to identify themselves as the genuine user. By the middle of 2016, MasterCard’s German customers should be able to prove their identity and authenticate payments using a ‘selfie’. Following this "Selfie Pay" is said to be launched in Austria in 2017. Ajay Bhalla, the head of MasterCard's security department is convinced that the "selfie generation" will welcome and use the new feature.

Blink to beat misuse

For the procedure to work, users must install the MasterCard app "Selfie Pay" on their smartphone, tablet or PC, and save a sample picture of themselves. A unique code is created using the image data. The selfie taken at the point of payment is then transmitted to MasterCard in an encrypted form and compared with the saved code. Alternatively, customers can prove their identity with their fingerprint, according to a BBC report. Once the user is successfully identified, all they need to do is confirm the transaction.

However, cardholders must not forget to blink in the selfie. The software uses this eye movement as a means of ensuring that a fraudster is not just holding up a photo to the camera. MasterCard seems to be aware that this security measure alone is insufficient. Yet to date, the company has only mentioned vaguely other security measures. A spokesman said that the system recognises attempts at fraud because it evaluates other data. However, security researcher Jan Krissler from the technical university of Berlin (TU Berlin) moved a pencil over the eyes of a photo - which a scanner interpreted as blinking and thus the software accepted the payment. There are more extensive means of face identification by way of 3D models which offer significantly better fraud prevention but these are still in the development phase.

Is the payments market moving to a password-free world?

Banks, financial institutions and payment service providers are working to create a world which functions without the need to input passwords. They are counting on unique biometric features, such as customers' fingerprints or voices, or even the blood flow in their fingertips to authenticate payments. "Consumers hate passwords," states Bhalla with conviction. Apparently the most-used password is 123456. This is in itself very insecure, but in addition many people also use the same password for multiple purposes. "If they are hacked, the intruder has access to almost all their data," explains Bhalla.

Payment by ‘selfie’ is only one of a number of authentication initiatives currently being developed. In 2015, at CeBIT, Alibaba boss Jack Ma demonstrated the payment procedure "Smile to Pay", an app that recognises and authenticates customers based on the shape of their face. Google is currently testing a "Hands Free" app and the UK's Atom Bank is planning to introduce face scanners. Barclays, a UK-based financial service provider, has developed an authentication procedure that measures the bloodflow in a customer's finger. Deutsche Bank is also planning to introduce biometric verification processes with a system that recognises whether the accountholder or a third party is holding the mobile phone being used for a payment. Payment transfers are already feasible via fingerprinting at Deutsche Bank.

New EU directive on payment services

MasterCard tested "Selfie Pay" in a pilot program with 500 participants in the United States and the Netherlands in 2015. According to a BBC report, it will be rolled out in 14 countries this summer, including the UK, France and Germany. The launch in Austria is scheduled for 2017. Yet in countries like Germany, where people are concerned about data protection, MasterCard will not find it easy to convince people to make even more of their personal data available.

It is likely that MasterCard will not reveal any details on security until the service is launched. But an EU directive passed in 2015 obliges providers of mobile payment services to use a strict client authentication procedure through “the use of two or more elements categorised as knowledge (something only the user knows), possession (something only the user possesses) and inherence (something the user is).”

Ultimately, the more data companies gather, the more money they can demand for it. The amount of data that MasterCard, Google & others collect depends on customers' habits - and whether they are prepared to change them. Time will tell whether users really prefer to constantly make photos of themselves rather than remembering a password. Some people therefore see MasterCard’s "Selfie Pay" app as a marketing stunt rather than a genuinely market changing development.

There is a school of thought that believes that fingerprint checks are simpler to implement and use in practice. It is clear however that MasterCard will attempt to persuade existing and new customers of the benefits of its new payment function. If it proves popular amongst the selfie generation, it may spread beyond this group to the wider population

KeywordsBIOMETRICS

Comments: (0)

Comment on this story (membership required)

Finextra news in your inbox

For Finextra's free daily newsletter, breaking news flashes and weekly jobs board: sign up now

Related stories

BMO introduces MasterCard selfie payments for corporate cardholders

BMO introduces MasterCard selfie payments for corporate cardholders

23 March 2016  |  13165 views  |  0 comments | 25 tweets | 24 linkedin
Following Dutch thumbs up, MasterCard preps major selfie payments roll out

Following Dutch thumbs up, MasterCard preps major selfie payments roll out

22 February 2016  |  13318 views  |  1 comments | 3 tweets | 2 linkedin
ABN Amro invites customers to sign up with a selfie

ABN Amro invites customers to sign up with a selfie

07 December 2015  |  10230 views  |  1 comments | 18 tweets | 34 linkedin
Lucova brings selfie payments to college campus

Lucova brings selfie payments to college campus

12 November 2015  |  6692 views  |  1 comments | 17 tweets | 12 linkedin
From biometrics to one-time passcodes, MasterCard preps Identity Check suite

From biometrics to one-time passcodes, MasterCard preps Identity Check suite

06 October 2015  |  10101 views  |  0 comments | 12 tweets | 18 linkedin
MasterCard trials selfie payments in the Netherlands and US

MasterCard trials selfie payments in the Netherlands and US

18 August 2015  |  23407 views  |  3 comments | 55 tweets | 46 linkedin
Alibaba unveils 'smile-to-pay' tech

Alibaba unveils 'smile-to-pay' tech

16 March 2015  |  17852 views  |  4 comments | 26 tweets | 23 linkedin

Related company news

 

Related blogs

Create a blog about this story (membership required)
Visit www.vasco.comvisit http://info.nice.comvisit www.ebaday.com

Who is commenting?

Top topics

Most viewed Most shared
Saudi central bank provides sandbox for banks to try out Ripple techSaudi central bank provides sandbox for ba...
10463 views comments | 16 tweets | 11 linkedin
Aussie real-time payments platform goes liveAussie real-time payments platform goes li...
8249 views comments | 15 tweets | 41 linkedin
ECB launches staunch defence of cashECB launches staunch defence of cash
7737 views 10 comments | 21 tweets | 26 linkedin
hands typing furiouslyHow can Blockchain Help with AML KYC
7613 views 3 | 9 tweets | 4 linkedin

Featured job

to £100K base, double OTE, benefits
London, UK

Find your next job