PaymentsJournal
No Result
View All Result
SIGN UP
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
PaymentsJournal
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
No Result
View All Result
PaymentsJournal
No Result
View All Result

The Federal Government’s Hard Case for the Identity Ecosystem

By George Peabody
January 30, 2011
in Mercator Insights
0
0
SHARES
0
VIEWS
Share on LinkedIn
American Express Introduces Enhanced Business Travel Account to Help Companies Manage the Reality of Business Travel - PaymentsJournal

Background from bank plastic cards. Figures on the card. Small depth of sharpness. Indoors. Horizontal format. Gray, green, yellow. Color. Photo.

The federal government’s idea for simplifyingour online lives, especially with respect to e-commerce, is gettingsome traction in the popular online press (see link below). Theattraction of a national single sign on scheme, operated by atrusted third party, is an intuitively compelling notion. I mean,isn’t it obvious? Just move the welter of passwords that plague ustoday to a service that trusts me and vouches for me to the onlinesites I visit. What could be more logical?
Unfortunately, that’s about as far as it goes. Beneath the firstlayer of simplicity lies a morass of complication and not justtechnical details. Contractual and liability concerns abound.Building online trust is hard. While the simplest use case ofanonymous access to a site or even subscriber access to a news siteseems simple enough (and it isn’t), e-commerce transactions requirea far higher level of surety and security.

Identity ecosystem proponents argue that consumer demand will drivemerchants to accept this new form of identity verification.Consumer convenience, as it so often does, is predicted tooverwhelm the reticence of merchants and other entities concernedwith online security. That’s a big assumption because these schemeshave to convince a very experienced and highly skeptical audience -the fraud and risk managers of online retailers who are, in fact, amajor target beneficiary of the NSTIC or any other federatedidentity plan. Based on Mercator’s research in collaboration withthe Merchant Risk Council, that will be a tall order (see ourreport Trekking to Find the Holy Grail: E-Commerce Identity andAuthentication).

Even the track record of simplifying assumptions in authenticationis not encouraging. OpenID, a single sign on scheme, has nottranslated into wide adoption. Indeed, for the site operator,OpenID implementation has proven difficult. Recently, 37signals (arespected Web 2.0 SaaS developer) announced it is phasing outOpenID support in favor of a proprietary scheme serving its ownonline properties. When the web cognoscenti turns up its nose at atechnology, that is not a good sign.

Given its ubiquity, some are saying Facebook will become the singlesign-on provider. Based on its track record with privacy controls,that should give everyone pause. Scares me to death.

This blog post is not a defense of the weak user ID and passwordschemes employed today. There are better ways. At Mercator, we areexamining online and mobile authentication schemes. An upcomingreport will look at the potential for smartphone-basedauthentication methods. For higher value use cases, that seems tobe a particularly compelling route.

http://www.businessweek.com/magazine/content/11_06/b4214036537462.htm
To read the Mercator and Merchant Risk Council report onthe NSTIC and Identity Ecosystem notion, here’s the link:http://www.mercatoradvisorygroup.com/images/MRC%20WHITEPAPER.pdf

0
SHARES
0
VIEWS
Share on LinkedIn
Tags: DebitMobile PaymentsPrepaid

    Get the Latest News and Insights Delivered Daily

    Subscribe to the PaymentsJournal Newsletter for exclusive insight and data from Javelin Strategy & Research analysts and industry professionals.

    Must Reads

    cross-border tokenized deposits

    Project Agorá Is Showing Banks Why Tokenized Deposits Matter

    August 28, 2026
    prepaid speed

    How Jumpstarting Gift Card Redemption Can Mitigate Breakage

    August 27, 2026
    ISO and ISV partnerships

    Building a Successful Payments Strategy: How ISOs and ISVs Can Drive Scalable Growth Together

    August 26, 2026
    ACH Network, credit-push fraud, ACH payments growth, ACH Network growth

    Despite Rapid Change, ACH Still Anchors the Payments Industry

    August 25, 2026
    virtual cards

    Virtual Cards Are Poised for a Banner Year in Commercial Payments

    August 24, 2026
    BNPL, BNPL for everyday expenses

    Hard Times, Easy Money: BNPL Now Finances Rent and Utilities

    August 21, 2026
    faster payments fraud prevention

    Beyond Compliance: Rewiring Fraud Prevention for Faster Payments

    August 20, 2026
    embedded finance for banks, instant payments

    Embedded Finance: Banks’ New Growth Channel

    August 19, 2026

    Linkedin-in X-twitter
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter

    ©2026 PaymentsJournal.com |  Terms of Use | Privacy Policy

    • Commercial Payments
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    No Result
    View All Result