Showing posts with label paypal. Show all posts
Showing posts with label paypal. Show all posts

Tuesday, 29 October 2013

Droidcon 2013: Authentication for Droids

Tim Messerschmidt, PayPal @SeraAndroid

Presentation available on slideshare

OAuth2 client libs

Identity

OpenID
  • developed 2005
  • 2012: discovered you can hijack it
  • considered dead :-(
BrowserID & Persona
  • from Mozilla
  • great idea, but nobody really uses it apart from them…
OpenID Connect
  • layer on top of OAuth2
  • http://openid.net/connect
  • still a draft but looks really good
  • has a whole section on session management (i.e. stop allowing that app)

Providers

  • 80-90% via Google, Facebook & Twitter
  • all have their own SDKs that handle the OAuth for you
  • PayPal added a new identity provider
    • provides verified information
  • needs to be best practice to show which information will be shared at each time
  • Blue Inc 2011: Consumer Perceptions of Online Registration and Social Sign-In
    • 45% admit to leaving a website instead of resetting their password or answering security questions
    • 66% think that social sign-in is desirable alternative

Q&A

  • on mobile, app can fake a web view and capture identity
    • this is why facebook goes via app
  • think about different social providers for different countries
    • e.g. baidu for China, yandex for Russia
  • see also Google Authenticator libraries for two factor auth

Thursday, 5 July 2012

MomoLondon: Mobile Payments

I arrived a few minutes late and missed the beginning of Dave Birch’s introduction, but I gather it involved Star Trek and early Visa commercials…

Dave has posted his own summary of his introduction which was all about needing a better story to tell about mobile payments. He reckons we don’t have a really good narrative to get people excited about the subject, and that makes it harder to get the future technologies more widespread.

Some other points he raised were:

  • Keuffel & Esser (world’s largest manufacturer of slide rules) commissioned a report about the future in 1967. It was amazingly accurate apart for the bit where they went out of business 5 years later due to the invention of the calculator…
  • Facebook have money transmitter licenses in 38 out of 50 states — a good start, but not really useful if you need to pay someone and they go on holiday to a state that’s not covered…
  • In EU there was a regulatory barrier and now there isn’t — arrival of non-banks will be a big game change
  • UK Universal Credit system — payments won’t be by cheque any more
    • going for prepaid accounts
    • £2bn per month will be going through the new system
    • a big opportunity…

He then challenged the panel to come up with some good narratives for digital, mobile money. My usual summarised notes are below. Dave did a good job of making the evening interesting to listen to, but we didn’t really come away with any new stories to tell. As Margaret Gold tweeted later, the most we talked about was buying coffee…

Panel

Nathan Cushnie: O2’s Mobile Money

  • what is the user case?
  • just payment as utility is not very exciting
  • discovering deals, then paying directly
  • consolidating payments with other financial things — the rest of the wallet

Iain Herd: PayPal

  • what is the value for the merchants?

Russell Sheffield: paythru

  • has to be seamless, global & ubiquitous
  • fit the nuances of different cultures
  • Turkey have 10-12 merchant accounts for each merchant — they choose which to use
    • in Turkey, terminals are provided by the banks for free so this is possible

Jennifer Payne: Ponti’s (retailer)

  • not enough benefits for the retailer
  • want the experience to be user friendly, social, tie in to marketing
  • want a little hub and want it to be handed to us

Masabi - train tickets

  • merchants are terrified that they’ll install the wrong hardware (betamax)
  • masabi trying to provide several different versions all the time
  • what about a platform that will support multiple systems?

Are we just waiting to clear the logjams before Apple tells us what to do?

  • RS: it is complex - have to make sure it’s secure and keeps customer confidence
    • better not to let the consumer decide
  • IH: most players not looking at the whole journey
    • Apple good at making things work end to end
    • good at simplicity
  • JP: so many people creating different wallets
    • do I wait for them? do I make my own app?
  • NC: don’t want the consumer to have to choose technology

Audience experiences of purchasing on a phone?

  • used an SMS to buy using a local currency (Brixton pounds)
    • strong community narrative which was nothing to do with payment
  • starbucks app — did what it needed to do
    • very simple
  • been in a shop and got pissed off: used Amazon to buy direct
  • IH: used Pizza Express payment app
    • audience: fairly simple
    • retailer had no difficulty using it
  • audience: bought something in Macy’s
    • frustrated that had to take the phone out of his pocket
  • audience: paid with NFC on iPhone at Starbucks
  • RS: all down to the customer — the moment they have to think about the transaction, the interruption can stop the payment
  • DGW: the goal with the phone is to make things better
  • DGW: no good experiences involved PayPal, Barclays, etc
  • IH: need big companies involved to get reach — all previous mentions were small scale

Wandering through the building and paying

Do we even need to get our phone out of our pocket? Is it better just to walk around and have things credited to our account automatically?

  • Ben Whitaker, Masabi: femto cells on trains/buses… could just pick up people on the journey by being there
    • what about people on the bus stop?
    • track people across the journey…
  • PayPal Here/Square: check in to a merchant
    • next time you’re in the shop, the POS terminal shows your face
    • you can pay just by walking up to the till and talking
    • loyalty scheme — offers targeted at retail customers
    • POS machine shows how many times you’ve been in the store, what your last purchase was…
  • what does the mobile channel deliver?
  • is just leaving your wallet behind enough of a change?
  • JP: people go to a restaurant for the customer experience
    • just ordering on your phone is a lonely experience…
    • want engagement as opposed to payment
    • if it comes to payment later then that’s good

mobile should do more

  • payments going through to expenses automatically?
  • want someone to help me budget & track my spending…
  • NC: narrative needs to be bigger than just a transaction
    • accounts departments won’t accept electronic receipts at the moment…
  • RS: NatWest doing moneyless accounts in last couple of months
    • been that way for 15 years in South Africa because banks & mobile operators working together
  • DGW: Orange & NatWest did a trial in 1996… unfortunately not much has happened since then

Is it really just a squabble about who owns the customer?

  • IH: when working at a mobile operator, looking far too much at the commercial model than at what the consumer actually wanted

Risk - mobile payments should be more secure, and therefore cheaper?

  • IH: very large percentage of PayPal is risk management
    • when talking with partners, that’s one of the main things they bring to the table
  • however, PayPal’s risk management seems to involve offloading a load of risk onto the merchant — see the various articles about PayPal seizing and freezing accounts

What about identity on mobile?

  • RS: single sign-on
  • NC: not really looked at identity
  • IH: PayPal has less accounts than Facebook, but they’re all verified
  • DGW: if you figure out identity, then payment falls out in the wash…

What about payment with non-currency, e.g. selling personal information?

  • despite the promise of a new idea, this question didn’t get much of an answer…

Why can’t I take the phone round a supermarket and scan products as I go myself?

  • NC: O2 Wallet does include a bar-code scanner
    • can scan a virtual/digital barcode poster shop
    • next step would be paying for real things

Don’t want Starbucks & McDonalds — I want independent merchants

  • Not just taking the payment utility, want community and local interest

Replicating existing stories hasn’t worked - successes are those that create new markets

  • “What frustrates me is that those electronic, mobile transactions don’t appear any different in my bank statement”

Working backwards from the future

  • NC: consumer makes a gesture; consolidate offer & loyalty points; merchant gathers data

Payment of medium sized amounts between people (e.g. £600 for doing something)

  • PayPal is not legal tender — cannot force someone to be paid by PayPal…
  • the revolution is on the customer acquisition side, never on the usage
  • IH: PayPal focused on getting to Facebook size
  • it’s only a matter of time until you can send money via Facebook
  • audience: if you get a parking ticket, pay it by PayPal — it totally confuses them!
  • want to pay a builder, who pays his contractors, who use the money immediately to go down to the pub — cash is the only accepted mechanism right now
  • DGW: refuses to pay cash as he refuses to take part in the black economy!
    • part of the story could be that you’ll pay less tax if you pay by mobile :-)
  • IH: can give people prepaid PayPal credit cards — they can withdraw cash from an ATM

What about beggars? Small transactions to unknown people

  • DGW: contactless terminals by busker pitches in the underground set at £1
  • DGW: Not a problem he’s trying to solve…

Should I have the right to make an anonymous payment?

  • IH: that’s where PayPal came from
  • Data that goes with the payment that seems to the root of the business models we were talking about earlier…

Would it be good for Ponti’s to get rid of cash?

  • JP: it’s not on our radar — all that matters is that we get paid and the customer is happy

What is the market asking PayPal for?

  • in UK fashion group pay by barcode
  • all German shops close on a Sunday, but can put panels (with QR codes) in windows so people can shop online when you’re closed

Is showrooming a problem for retail (comparison shop and then buy online)?

  • JP: Not particularly true in a restaurant…

Wrap up:

  • need to look bigger than just replicating credit cards
  • In 1967 the USA banks thought it would take at least until the 1980s to get rid of cheques… Money changes very slowly

Announcements

  • Samsung Smart App Challenge - $4m worth of prizes
  • 19th July — Smart Accessibility Workshop: 4-7pm
    • what to think about when designing apps on mobile
    • already a third full
  • 24th July — Mobile Apps Marketing

Tuesday, 10 May 2011

Londroid: Payment and monetization

The first of two Android blog posts — this one’s from the Londroid Meetup on April 21st themed on Payments.

There were three presentations from three competing payment platforms, and they presented in roughly the order I’d prefer to use them (in their current state): Paypal is very much sorted for Android — they make it easy and it looks impressive and secure; Google’s in-app billing is still new and feels unfinished; and Paythru is simply a browser-based system that’s designed for mobile, but no way near as slick as the other two.

However, talking to the Paythru rep later, they have some interesting tricks up their sleeve — like being able to take payment but not actually charge it to the card for several days (useful for synchronising multiple payments, or buying Olympics tickets). Google will also be beefing up their billing system over the next few months, so Paypal won’t have an easy ride.

Integrating Paypal In-App and Mobile Browser Payments on Android

Anthony Hicks anthony@x.comPaypal

  • paypal in EU biggest in UK, then DE, then FR
    • small numbers in scandinavia, spain & italy
  • now have a bank license in Europe
  • iPhone, iPad, Android mobile payment library
    • all in-app (no browser)
  • adaptive payments
    • split payments between multiple parties
    • make chains of payments
    • make a billing agreement and charge them later
    • pre-approval — can request payments without taking people to paypal
    • customer agrees to pay up to £X per month
    • take commissions on payments
  • mobile express checkout also available (browser based)
    • optimised for webkit
    • can login with mobile number and pin (as well as with email/password)

Development

  • payment button & pages have to be consistent
    • paypal won’t let you change them
  • language only affects the login page
    • paypal then switch to user’s language
  • process to approve:
    • get sandbox ID
    • submit test app to paypal
    • get live app ID
    • rebuild app (and don’t change it too much!)

Android In-App Billing

Richard Hyndman @geekyouupAndroid Developer Advocate, Google

  • available on 1.6 and above (since handled by Android Market app)
    • have to have opened the Market app
  • two kinds of purchase:
    • Managed: once per account
    • can query market to find out if the purchase has been made
    • Unmanaged: unlimited per account
  • get the Google Market Billing package from the ADK
  • usage:
    • bind to service
    • check billing supported (requires network) — can then ask for upgrade
    • send billing request and put up billing page activity
    • set up billing receiver
    • purchase notify tells you something has changed, but you have to ask what…
    • quite a few back and forths…
  • security
    • recommend that you put validation on server (urban airship?)
  • use android.test.purchased as your SKU then it won’t get billed!
  • use test accounts for testing…
  • apparently the dungeons example has two or three classes you don’t actually need

Q&A

  • subscriptions not in API yet…
  • shared preferences can now be synced to the cloud
  • to prevent copying to another phone, would have to check market when app launches
  • currency tied to the google account, not to the IP location
  • can only buy digital content/services

Paythru - Money on the Move

http://www.paythru.com/

  • paythruMONEY — allows people to manage a card from their mobile
  • can move money with a single-use QR code
  • provides digital cash (user is logged in but retailer sees no identification)
  • a few lines of code:
    • launch a browser to a specific URL
    • get the app to launch with a return URL when the paythru mobile web checkout has completed

Wednesday, 4 November 2009

O2 Litmus: Palm Pre Mobile Web Developer Event

Tonight was a really impressive event organised by O2 Litmus. The two guys from Palm did a very good job presenting WebOS and Palm’s plans for the future. The food and drink was excellent. And they even gave us a Palm Pre each to take home! Certainly makes me want to at least try out making an app.

As usual, here’s my notes for the evening in a vaguely coherent manner…

  • webkit appearing all over the place on mobile
  • as well as opera (there were a couple of people from Opera at the event)
  • HTML 5 is providing standardisation for web applications in the same way that HTML provided standardisation for web documents
  • web applications are escaping the browser:
  • why not flash, javafx or silverlight?
  • because:
  • “When you improve things by an order of magnitude, you haven't made something better — you've made something new” — Stephen Levy
  • Palm Pre uses V8 javascript engine, just like Chrome
  • WebWorkers provide background threads
    • came from Gears worker pool
    • invented to stop database access causing hangs
  • Chrome uses WebWorkers for extensions
  • Firefox hasn’t implemented SQLite, but may go for a JSON-based database, like CouchDB
  • CSS Transforms
  • “it’s not javascript people don’t like, it’s dealing with cross-browser issues”
    • anyone mention IE…?
  • “it’s not just going to be developing apps for Palm — it’s making things for the web”

some detail

  • Mojo Framework is open-source
  • Mojo uses prototype.js at the moment, but will be made nicer to use other alternatives later
  • dashboard items and popups are just DOM items
  • want to integrate apps into system — background apps

security

  • web browser provides normal web sandbox
  • applications get access to native services
  • certain APIs still need permissions granted
    • e.g. location
    • can get app to ask when API is used
  • would like to push local APIs to browser windows
  • apps are packaged and signed
    • working with developers to encrypt apps in different ways
    • would anticipate that developers would be able to opt-in to encrypt their app
    • protect against people uploading a copy of an app as their own
    • balanced against the benefit of view source on the web

app store

  • Palm would like a “web app store” to emerge
  • Palm doesn’t feel that it’s the right company to make this move
  • creating a Palm catalogue & developer program for mid-December
    • charging $50 for each app to be in the catalogue — as a spam filter
    • money goes to funding developing programme & catalogue service
    • interested in finding other “friction points”
  • can get an immediate acceptance into the web distribution of the Palm app catalogue
    • submit and get a URL straight away
    • can email/tweet other people
    • no review process
  • opening up the backend too — feeds of all the apps and charts
  • would like digg-style rating
  • a developer can choose to make an app available for specific markets
  • also aiming to provide metrics for developers, so they can see how users are choosing or not choosing their apps
  • payment:
    • right now they have PayPal
    • would like to support several options
    • want to decrease the friction

BONDI & others

  • palm works with them
  • including W3C widgets & geo
  • Palm way will be there originally, but will be switched out when
  • order depending on developer requests
  • native-accelerated CSS transforms are higher at the moment
  • “Palm pays us, but they didn’t pay us enough to sell out”

supporting open source

  • waiving cost for anyone working open source
  • $99 for developer

testing

  • O2 Litmus will be recruiting Palm Pre users for testing availability
  • DeviceAnywhere will feature Palm Pre in O2 VDL

feedback

  • devrel@palm.com
  • they already use Jira and want to open it something to the public soon
  • homebrew community will patch things before Palm do it themselves
  • there are differing viewpoints internally…

personal usage

  • like multi-tasking
  • don’t like UI latency
    • hardware is roughly equivalent to the iPhone 3GS
    • don’t have access to hardware GPU — so CSS Transforms is really important
    • will happen with a over-the-air software upgrade

multiple devices

  • Palm Pixi seems a lot nicer
  • different screen size (80 pixels shorter)
  • should design liquid layouts…
  • the future is devices in all kinds of form factors

tooling

  • there are tools for Flash — what about tools for WebGL, etc?
  • mozilla is making tools
  • e.g. Atlas from 280North
  • this week there may be something new released…
  • should flash be a native platform for apps on Palm Pre?
    • nearly supported for web pages — Adobe has shown something working already

Monday, 26 October 2009

BarCampLondon7: Social Manipulation on the web and in person

Tim Nash

Social Engineering is still just as valid as ever…

  • If asked for photo ID, people will give it up willingly
  • given a photo ID with details, you can call up somewhere and say you’ve forgotten your ID
  • often the front desk will give you a new ID…
  • people are more likely to buy when there’s an official badge…
    • doesn’t really matter what the badge is
    • virtually no-one who clicks on the badge actually purchases
    • but buy rate will increase anyway
  • paypal did an experiment about a year ago
    • to see if it made a difference to not use the word PayPal on their “paypal verified” badges
    • made no difference to sales conversions
    • click-through rate to paypal went down
  • certain colours affect buying moods
    • brain doesn’t like bright colours
    • big red “buy now” button does not attract people — your eyes will avoid it
    • instead have a big grey “buy now” button with two red arrows on either side
    • eye tracking study shows people look for price and “buy now” button
    • sales rates go up when the price is just above the buy now button
  • best place for comments on a blog:
    • new comment box just under post
    • other comments can be down the side
  • use the word “reply” rather than “submit” comment
  • scienceforseo blog
    • highlight a part of the text and the comment will appear alongside