(keitai-l) Re: Amazon Japan Payment Security

From: Gerhard Fasol <fasol_at_eurotechnology.com>
Date: 06/18/04
Message-ID: <40D2989F.3020408@eurotechnology.com>
Andrew:

There is probably around US$ 5 billion in i-mode mcommerce
in a similar way as Amazon.com. Amazon is just the tip of
the iceberg.

I do not know the percentage, but I guess it's around 10% of
all Tokyo-Osaka Shinkansen tickets are sold through imode,
that is also not an official site.

I find outside Japan the role of official sites is often
totally misunderstood. It's great to have an official
site if you sell cartoons or games. But if you are the
Tokyo-Osaka Shinkansen Railway company, you don't need an
official site to sell your train tickets.

The payment systems for these sites have nothing
to do with DoCoMo.

Regarding Amazon: don't forget that there is an inbuilt
security in the system. After all they sell books, which
only have value if you have them. So these books need to
be delivered somewhere. I have not checked, but my guess
is that they only deliver to the address where your credit
card is registered. So if someone orders books fraudulently,
then they have a record where the books where delivered to.

It's a bit different but related story: back in Europe there
was a true story where a guy stole a handbag, and the only
items of value inside turned out to be concert tickets.
The thief made the mistake of actually using these tickets
and the police arrested the thief when he sat down on the
concert seats. Similar with the books.

Gerhard
http://www.eurotechnology.com/

Andrew Shuttleworth wrote:
> I'm interested in how Amazon Japan is implementing security and log-in
> on it's mobile site. I would like to implement a payment system on a
> non-official (at the moment) mobile site.
> 
> If I visit http://www.amazon.co.jp/i  I can register at the site
> including entering my credit card details. I'm not going through the
> official menu and there is nothing pops up to suggest that the site is
> secure. So question 1 is is this secure and does this security rely on
> being an official site?
> 
> Second question would be how they recognise that I am a return user so
> that I don't have to input my details again. I presume that they can
> do this because they on the official menu. Even if I go to the URL,
> the URL of the page I see is something like:
> http://www.amazon.co.jp/exec/obidos/dt/i/flex-sign-in/000-0000000-0000000?uid?=NULLGWDOCOMO&page=aa/xml/h/h.html&response=subst/aa/xml/h/h.html
>   (I changed the actual digit string to all zeros. I'm using a DoCoMo
> P504iS)

[ excessive quoting removed by moderator ]

-- 
---------------------------------------------------------------------
Gerhard Fasol, PhD                         Eurotechnology Japan K. K.
fasol_at_eurotechnology.com               http://www.eurotechnology.com/
---------------------------------------------------------------------
Find us in "IBM developerWorks" and in "Chemical & Engineering News":
http://www-106.ibm.com/developerworks/wireless/library/wi-elite8.html
http://pubs.acs.org/cen/topstory/8049/8049bus1.html
---------------------------------------------------------------------
Received on Fri Jun 18 10:28:30 2004