{"id":5353,"date":"2018-11-02T11:00:47","date_gmt":"2018-11-02T05:30:47","guid":{"rendered":"https:\/\/gtm360.com\/blog\/?p=5353"},"modified":"2022-02-21T13:58:48","modified_gmt":"2022-02-21T08:28:48","slug":"winners-dont-let-security-screw-up-user-experience","status":"publish","type":"post","link":"https:\/\/gtm360.com\/blog\/2018\/11\/02\/winners-dont-let-security-screw-up-user-experience\/","title":{"rendered":"Winners Don&#8217;t Let Security Screw Up User Experience"},"content":{"rendered":"<p>Like me, you may have come across people who appear obsessed with security but happily book cabs, send messages, order food, and even <a href=\"https:\/\/gtm360.com\/blog\/2018\/10\/05\/why-do-people-obsess-over-security-and-then-make-payments-without-a-password\/\" target=\"_blank\" rel=\"noopener\"><strong>make payments<\/strong><\/a> without entering a single password \/ PIN on their smartphones.<\/p>\n<p><a href=\"https:\/\/gtm360.com\/blog\/wp-content\/uploads\/2018\/10\/sales-funnel-buyer-2.0.jpg\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-5424\" src=\"https:\/\/gtm360.com\/blog\/wp-content\/uploads\/2018\/10\/sales-funnel-buyer-2.0.jpg\" alt=\"\" width=\"300\" height=\"269\" srcset=\"https:\/\/gtm360.com\/blog\/wp-content\/uploads\/2018\/10\/sales-funnel-buyer-2.0.jpg 1000w, https:\/\/gtm360.com\/blog\/wp-content\/uploads\/2018\/10\/sales-funnel-buyer-2.0-200x179.jpg 200w, https:\/\/gtm360.com\/blog\/wp-content\/uploads\/2018\/10\/sales-funnel-buyer-2.0-768x689.jpg 768w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>This is not as contradictory as it seems if you look at the end-to-end customer journey.<\/p>\n<p>For the uninitiated,\u00a0<em><strong>Customer Journey<\/strong><\/em>\u00a0can be defined as the path taken by customers while interacting with a company \/ brand.\u00a0A customer journey traverses multiple stages in a customer\u2019s relationship with a brand viz. awareness, interest, desire, action, repeat purchase and advocacy.<\/p>\n<p>The apparent headscratcher just means that people value security when they&#8217;re in the <em><strong>awareness<\/strong><\/em>\u00a0or TOFU (top of funnel) stage of the funnel but they want convenience after reaching the <em><strong>repeat purchase <\/strong><\/em>or BOFU\u00a0(bottom of funnel) stage of the funnel.<\/p>\n<p>In plain English:<\/p>\n<p>People will switch from cash to digital payments only if it&#8217;s secure but they will continue to use digital payments only if it&#8217;s easy to use.<\/p>\n<p>In payments (and in many other products and services), studies have shown that <strong>consumers have different considerations at different stages of their purchase journey <\/strong>and that<strong> all considerations are not created equal<\/strong>.<\/p>\n<p>Many payment service providers (PSP) don&#8217;t get this cardinal trait of consumer behavior and solve only for the TOFU driver, namely, security. Not surprisingly, they struggle to gain mainstream adoption.<\/p>\n<p>Take, for example, two factor authentication. When Reserve Bank of India mandated 2FA for all online payments in India, it presumably thought &#8220;people want security, 2FA provides security, ergo people will flock to online payments&#8221;.<\/p>\n<p>What happened was exactly the opposite. Although the central bank-cum-banking regulator&#8217;s move was well-intentioned, 2FA caused tremendous friction and resulted in an alarmingly high rate of failed payments for reasons explained in the following exhibit.<\/p>\n<figure id=\"attachment_5416\" aria-describedby=\"caption-attachment-5416\" style=\"width: 620px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/gtm360.com\/blog\/wp-content\/uploads\/2018\/10\/2FA-Friction-Failed-Payments-L-1jul2018.jpg\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-5416\" src=\"https:\/\/gtm360.com\/blog\/wp-content\/uploads\/2018\/10\/2FA-Friction-Failed-Payments-L-1jul2018.jpg\" alt=\"\" width=\"630\" height=\"281\" srcset=\"https:\/\/gtm360.com\/blog\/wp-content\/uploads\/2018\/10\/2FA-Friction-Failed-Payments-L-1jul2018.jpg 2477w, https:\/\/gtm360.com\/blog\/wp-content\/uploads\/2018\/10\/2FA-Friction-Failed-Payments-L-1jul2018-200x89.jpg 200w, https:\/\/gtm360.com\/blog\/wp-content\/uploads\/2018\/10\/2FA-Friction-Failed-Payments-L-1jul2018-768x342.jpg 768w, https:\/\/gtm360.com\/blog\/wp-content\/uploads\/2018\/10\/2FA-Friction-Failed-Payments-L-1jul2018-1024x456.jpg 1024w, https:\/\/gtm360.com\/blog\/wp-content\/uploads\/2018\/10\/2FA-Friction-Failed-Payments-L-1jul2018-630x280.jpg 630w\" sizes=\"auto, (max-width: 630px) 100vw, 630px\" \/><\/a><figcaption id=\"caption-attachment-5416\" class=\"wp-caption-text\">CLICK TO EXPAND<\/figcaption><\/figure>\n<p>People like me who were paying for online shopping with credit cards for years switched to cash on delivery. Many others never tried online payments for online shopping. Not surprisingly, <a title=\"Permanent Link to Why COD Still Rules Ecommerce In India\" href=\"https:\/\/gtm360.com\/blog\/2017\/04\/21\/why-cod-still-rules-ecommerce-in-india\/\" target=\"_blank\" rel=\"bookmark noopener\" data-slimstat=\"5\">COD Still Rules Ecommerce In India<\/a> with a 60% share.<\/p>\n<p>When there was a cash crunch in the wake of the de\/remonetization of high value currency notes in India in November 2016, people didn&#8217;t switch from COD to digital payments \u2013 they simply stopped shopping online because they didn\u2019t have enough cash to pay on delivery.<\/p>\n<p>PSPs that have required explicit 2FA for each and every payment \u2013 \u201caccording to RBI mandate\u201d \u2013 have flopped. On the other hand, fintechs like PayTM that cleverly circumvented 2FA \u2013 or at least make it implicit \u2013 became unicorns and household names.<\/p>\n<p>Let&#8217;s look at a few other markets.<\/p>\n<p>While many security technologies were invented in the USA, none of them has been implemented there. Let&#8217;s take 2FA and EMV as examples:<\/p>\n<ul>\n<li>The American regulator FFIEC mandated 2FA for online payments in 2005 and reissued its guidelines in 2012. But online payments don&#8217;t require 2FA in USA even today.\u00a0Stripe, the leading payment gateway company, at one time minced no words about its dislike for 3D Secure, the go-to method for implementing 2FA for online payments. Its website once\u00a0<a href=\"https:\/\/support.stripe.com\/questions\/does-stripe-support-3d-secure-verified-by-visa-mastercard-securecode\" target=\"_blank\" rel=\"noopener\"><strong>noted<\/strong><\/a>: &#8220;At Stripe we&#8217;ve so far opted not to support 3D Secure since we believe the costs outweigh the benefits.&#8221;<\/li>\n<li>The EMV migration deadline has come and gone over a year ago in USA, still fewer than one-third of US retailers have implemented Chip and PIN technologies.<\/li>\n<\/ul>\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">EMV for US Gas Stations.<br \/>Cost: $7B. <br \/>Savings: &lt;=$0.5B\/year (from potentially reduced fraud).<br \/>Ergo no ROI.<a href=\"https:\/\/t.co\/Twn0gpGzmw\">https:\/\/t.co\/Twn0gpGzmw<\/a><\/p>\n<p>&mdash; Ketharaman Swaminathan (@s_ketharaman) <a href=\"https:\/\/twitter.com\/s_ketharaman\/status\/795966887565938688?ref_src=twsrc%5Etfw\">November 8, 2016<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>The sky hasn&#8217;t fallen.<\/p>\n<p>Sure, there have been a number of data breaches in the US e.g. Experian, Target. But they have all happened on the server side. And it looks like the country is fighting back with overwhelming force. According to <em>New York Times<\/em>, banks and card networks are adopting\u00a0<a href=\"https:\/\/www.nytimes.com\/2018\/05\/20\/business\/banks-cyber-security-military.html\" target=\"_blank\" rel=\"noopener\"><strong>military-style tactics to fight cybercrime<\/strong><\/a>. If you&#8217;re an optimist, these measures will convince you that Wall Street would be immune to such breaches. If you&#8217;re a skeptic, then, fact is, these breaches on the server side can\u2019t be prevented, no matter how many additional security-enhancing steps are put on the consumer-side.<\/p>\n<p>The situation in Europe is a bit ambivalent. According to an article entitled\u00a0<a href=\"https:\/\/www.wsj.com\/articles\/retailersobjecttoeuplanforstricteronlinesecurity1487010226\" target=\"_blank\" rel=\"noopener\"><strong>EU Online-Security Plan Is Criticized<\/strong><\/a> in\u00a0<em>Wall Street Journal<\/em>, &#8220;business groups are slamming a European Union proposal that would require customers to enter extra security information for online purchases as part of Strong Customer Authentication. Credit-card companies and e-commerce associations worry that if online purchases become too cumbersome customers will abandon them.&#8221; <em>WSJ<\/em> goes on to add that consumer advocates, on the other hand, say &#8220;there is no trade-off between antifraud protections and promoting e-commerce&#8221;.<\/p>\n<hr style=\"width: 70%;\" \/>\n<p><strong><em>Security wins on intent. Convenience wins on action.<\/em><\/strong><\/p>\n<p>While PSPs must make all the right noises about security, it\u2019s futile to anchor a digital payment product around security &#8211; an average user won&#8217;t be able to jump through all the hoops required to make an app totally secure (no matter what s\/he says before using the app).<\/p>\n<p>I&#8217;m glad regulators and PSPs have learned this lesson.\u00a0To paraphrase a famous Steve Jobs quote, they&#8217;ve started taking the trouble to figure out what really appeals to customers instead of lazily giving consumers what they say they want. I also suspect they&#8217;ve been nudged in this direction after witnessing the runaway success enjoyed by products that have treated security as a go-to-market message than a core product feature.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Hypocritical of <a href=\"https:\/\/twitter.com\/Paytm?ref_src=twsrc%5Etfw\">@Paytm<\/a> to complain that WhatsApp Payments doesn&#39;t have a login. Its own Sign Out link is buried so deeply that 99% of PayTM users I know are permanently logged into the app and never enter password \/ PIN to make an individual payment.<a href=\"https:\/\/t.co\/hBaOIqVk4h\">https:\/\/t.co\/hBaOIqVk4h<\/a><\/p>\n<p>&mdash; Ketharaman Swaminathan (@s_ketharaman) <a href=\"https:\/\/twitter.com\/s_ketharaman\/status\/965564220552171521?ref_src=twsrc%5Etfw\">February 19, 2018<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>Here are the results of the approach change:<\/p>\n<ul>\n<li>The Indian banking regulator has emphasized convenience over security in all recently launched digital payment products and services such as UPI, Recurring Payments and Contactless Payments. (Considering that some of these apps directly touch bank accounts, I think the pendulum has swung a little too far to the other extreme, but that&#8217;s perhaps a post for another day.)<\/li>\n<\/ul>\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Kudos to RBI for prioritizing convenience over security in operating model of recurring payments. <a href=\"https:\/\/t.co\/HBvMxzsShW\">https:\/\/t.co\/HBvMxzsShW<\/a><\/p>\n<p>&mdash; Ketharaman Swaminathan (@s_ketharaman) <a href=\"https:\/\/twitter.com\/s_ketharaman\/status\/791618231169679360?ref_src=twsrc%5Etfw\">October 27, 2016<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<ul>\n<li><a href=\"https:\/\/gtm360.com\/blog\/wp-content\/uploads\/2018\/09\/PAYZAPP-LOGOUT.jpg\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-5342 size-medium\" src=\"https:\/\/gtm360.com\/blog\/wp-content\/uploads\/2018\/09\/PAYZAPP-LOGOUT-123x200.jpg\" alt=\"\" width=\"123\" height=\"200\" srcset=\"https:\/\/gtm360.com\/blog\/wp-content\/uploads\/2018\/09\/PAYZAPP-LOGOUT-123x200.jpg 123w, https:\/\/gtm360.com\/blog\/wp-content\/uploads\/2018\/09\/PAYZAPP-LOGOUT-768x1247.jpg 768w, https:\/\/gtm360.com\/blog\/wp-content\/uploads\/2018\/09\/PAYZAPP-LOGOUT-631x1024.jpg 631w, https:\/\/gtm360.com\/blog\/wp-content\/uploads\/2018\/09\/PAYZAPP-LOGOUT.jpg 1080w\" sizes=\"auto, (max-width: 123px) 100vw, 123px\" \/><\/a>In the past, my go-to mobile payment app\u00a0<a href=\"https:\/\/gtm360.com\/blog\/2015\/07\/03\/hdfc-banks-payzapp-ends-my-bill-payment-woes\/\" target=\"_blank\" rel=\"noopener\"><strong>HDFC Bank PayZapp<\/strong><\/a> would log me out automatically after a few minutes of inactivity. This meant I had to enter a PIN to make the next payment. This was obviously a hangover from the shared desktop web security mindset. Recognizing that this approach is overconservative for a personalized device like a smartphone, PayZapp has modified its logout procedure lately: I now need to tap the Logout button and confirm that I really want to log out of PayZapp. Looks like PayZapp has understood the advantage of letting the user remain logged in to its app at all times &#8211; the approach pioneered, AFAIK, by <a href=\"https:\/\/gtm360.com\/blog\/2017\/01\/20\/five-reasons-why-paytm-is-miles-ahead-of-its-competition\/\" target=\"_blank\" rel=\"noopener\"><strong>PayTM<\/strong><\/a>, India&#8217;s largest digital payment product.<\/li>\n<li>A business associate and franchising specialist <a href=\"https:\/\/www.linkedin.com\/in\/prashant-srivastava-96a82a11\/\" target=\"_blank\" rel=\"noopener\"><strong>Prashant Srivastava<\/strong><\/a> tells me that the workflow for NEFT, IMPS and RTGS payments on his bank&#8217;s NetBanking portal has changed lately. For nearly two decades, this Top 3 private sector bank in India used to gate A2A payments with a bingo card and mobile OTP. Lately, I believe, both of those challenges &#8211; and the associated friction &#8211; have gone away. Now, you select a payee, enter an amount, press the submit button. And, poof, your money gets transferred immediately!<\/li>\n<\/ul>\n<p>I&#8217;m sure these UX-enhancing features will give a big boost to digital payments in the years to come. I&#8217;m also optimistic that they won&#8217;t cause an alarming increase in fraud. (Go <strong><a href=\"https:\/\/twitter.com\/hashtag\/CashlessIndia\" target=\"_blank\" rel=\"noopener\" data-slimstat=\"5\">#CashlessIndia<\/a><\/strong>!)<\/p>\n<hr style=\"width: 70%;\" \/>\n<p>Some people have proposed\u00a0<a href=\"https:\/\/www.finextra.com\/blogposting\/15738\/biometrics-will-eliminate-friction-in-financial-services\" target=\"_blank\" rel=\"noopener\">Intelligent Friction<\/a>\u00a0as a tradeoff between security and convenience.<\/p>\n<p>3D Secure v2 is one way to implement intelligent friction. Stripe, which had earlier panned 3DS v1, has a <a href=\"https:\/\/stripe.com\/guides\/3d-secure-v2\" target=\"_blank\" rel=\"noopener\"><strong>favorable opinion of 3DS v2<\/strong><\/a>.<\/p>\n<figure id=\"attachment_5419\" aria-describedby=\"caption-attachment-5419\" style=\"width: 490px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/gtm360.com\/blog\/wp-content\/uploads\/2018\/10\/STRIPE-3DS-V2-V1.png\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-5419\" src=\"https:\/\/gtm360.com\/blog\/wp-content\/uploads\/2018\/10\/STRIPE-3DS-V2-V1.png\" alt=\"\" width=\"500\" height=\"294\" srcset=\"https:\/\/gtm360.com\/blog\/wp-content\/uploads\/2018\/10\/STRIPE-3DS-V2-V1.png 1890w, https:\/\/gtm360.com\/blog\/wp-content\/uploads\/2018\/10\/STRIPE-3DS-V2-V1-200x117.png 200w, https:\/\/gtm360.com\/blog\/wp-content\/uploads\/2018\/10\/STRIPE-3DS-V2-V1-768x451.png 768w, https:\/\/gtm360.com\/blog\/wp-content\/uploads\/2018\/10\/STRIPE-3DS-V2-V1-1024x601.png 1024w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/a><figcaption id=\"caption-attachment-5419\" class=\"wp-caption-text\">3D Secure v2 (Image courtesy: STRIPE)<\/figcaption><\/figure>\n<p>But, if I were a merchant or a bank &#8211; or even a payor or PSP &#8211; I&#8217;d be cautious about anything that has the word &#8220;friction&#8221; in its name, even if it&#8217;s prefixed with some cool-sounding term before it. The extra step(s) required to implement intelligent friction will inevitably delay the affected payments. Some of those payments may even fail if the extra moving part (e.g. mobile OTP) introduced in the &#8220;challenge path&#8221; is not reliable.<\/p>\n<p>While consumers may keep retrying a delayed or failed payment on that one occasion, the anxiety and inconsistent user experience they go through will not only threaten conversion rates on that occasion but turn people off that mode of payment on future occasions &#8211; if not, gasp, drive them back to cash and cheques.<\/p>\n<hr style=\"width: 70%;\" \/>\n<p>Buying and selling happens only when payments are successful. Business is lost when payments fail.<\/p>\n<p>Convenience trumps security.<\/p>\n<p>Winners know this and never let security screw up user experience.<\/p>\n<p><span style=\"font-family: Arial; font-size: xx-small;\">DISCLAIMER: If you&#8217;ve come this far, it should be obvious that this post is largely restricted to consumer-facing digital payment apps meant to be used by the average man on the street. By no means should security play second fiddle in the case of server-side applications and databases that store sensitive user and payments data and must be managed by trained professionals in such a way that they&#8217;re fully secured from internal and external threats.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Like me, you may have come across people who appear obsessed with security but happily book cabs, send messages, order food, and even make payments without entering a single password \/ PIN on their smartphones. This is not as contradictory as it seems if you look at the end-to-end customer journey. For the uninitiated,\u00a0Customer Journey\u00a0can &#8230; <a title=\"Winners Don&#8217;t Let Security Screw Up User Experience\" class=\"read-more\" href=\"https:\/\/gtm360.com\/blog\/2018\/11\/02\/winners-dont-let-security-screw-up-user-experience\/\" aria-label=\"Read more about Winners Don&#8217;t Let Security Screw Up User Experience\">Read more<\/a><\/p>\n","protected":false},"author":4,"featured_media":5415,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[18,6,14,4,8,13,1],"tags":[],"class_list":["post-5353","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-b2-product-v-services","category-bfsi","category-cx","category-digital-marketing","category-it-marketing","category-product","category-mandatory-category"],"_links":{"self":[{"href":"https:\/\/gtm360.com\/blog\/wp-json\/wp\/v2\/posts\/5353","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gtm360.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gtm360.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gtm360.com\/blog\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/gtm360.com\/blog\/wp-json\/wp\/v2\/comments?post=5353"}],"version-history":[{"count":21,"href":"https:\/\/gtm360.com\/blog\/wp-json\/wp\/v2\/posts\/5353\/revisions"}],"predecessor-version":[{"id":9204,"href":"https:\/\/gtm360.com\/blog\/wp-json\/wp\/v2\/posts\/5353\/revisions\/9204"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/gtm360.com\/blog\/wp-json\/wp\/v2\/media\/5415"}],"wp:attachment":[{"href":"https:\/\/gtm360.com\/blog\/wp-json\/wp\/v2\/media?parent=5353"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gtm360.com\/blog\/wp-json\/wp\/v2\/categories?post=5353"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gtm360.com\/blog\/wp-json\/wp\/v2\/tags?post=5353"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}