Quantcast StorefrontBacktalk » Blog Archive » Amazon, Facebook: Retailers Want IT Leaders That Don’t Lead
advertisement
advertisement

Amazon, Facebook: Retailers Want IT Leaders That Don’t Lead

Written by Evan Schuman
March 4th, 2009
Like this story? Share it
To share this story with people in your social network, please click on the network icons below.

Many major retailers have been criticized for being slow to adapt to industry—especially Web-based—changes. But it’s not hard to see why when we see how the industry treats e-tail pioneers such as Amazon and Facebook.

To be fair, both Amazon and Facebook got spanked for going too far in respectively testing copyright and privacy limits, and both firms likely merited it. And both firms quickly retreated. The specifics here do not indicate a major inappropriate reaction, but the pattern is discomforting.

For companies to lead the industry and stake out strong global positions–especially in a weak economy—requires bold action. That means being aggressive at times to see how far consumers and competitors will permit them to go. Standup comedians trying to become successes don’t get anywhere by sticking with safe material.

Let’s look at precisely what these two players did.

Amazon Gets Creative

On Friday (Feb. 27), Amazon issued a statement that it was reversing an experimental text-to-speech feature after quite a few people in the publishing industry screamed bloody murder. (“Holy Catastrophic Copyright Calamity!” shrieked sidekick Robin to publishing superhero Bookman. “Quick! To the BookMobile….”)

The Amazon statement literally opened with this classic line: “Kindle 2’s experimental text-to-speech feature is legal: no copy is made, no derivative work is created, and no performance is being given.” Yep, PR Rule 152 clearly states that if the first sentence of a media statement has to declare that a new service is technically not a felony, it’s probably going to be a long day.

Amazon’s statement said that the company was pushing text-to-speech for many titles, but would step back and limit it—for now—to those publishers and authors who want to cooperate. (A cooperative publisher? I thought those just existed in Aesop’s Fables or something.) Spoketh Amazon: “Nevertheless, we strongly believe many rightsholders will be more comfortable with the text-to-speech feature if they are in the driver’s seat.” Like they needed some consulting firm to tell them that.

But the serious point is that Amazon is trying to work with text-to-speech and see how it might take book sales to the next level. Arguably, when the recession smoke clears, Amazon may be one of the only major booksellers left. Book publishers, left to their own devices (most likely a World War I era Underwood typewriter and abacus), are not much more likely to embrace change than their newspaper cousins have been. It’s going to be up to booksellers such as Amazon to push publishers—dragging and red-lining all the way—into the new world order, which may be publishers’ only shot at long-term survival.

If we’re going to need retailers like Amazon to be creative and adventurous for the industry to survive, we need to cut them a bit of slack when they make mistakes. Fear not: They will make—and have made–plenty of mistakes. If they didn’t, they’d be stagnant and ineffective, but there’s no need to drag Borders and Starbucks into this.

On The Face Of It

Facebook’s situation is surprisingly similar. I say surprisingly because, despite Facebook and Amazon being radically different types of companies (social networking and retailer) dealing with remarkably different issues (copyright versus privacy), what they did and how they reacted—and how the industry then reacted—were quite similar. Both tried new tactics in relatively uncharted waters; both quickly realized the depth of the stupidity and insensitivity of the move; both publicly apologized and reversed the changes; and both were pummeled for it. If we don’t encourage experimentation, the industry is in serious trouble.

It could be argued that Facebook is almost as much of a pioneer in its space as Amazon is in its. Although Facebook arrived a lot later to the Web party, it has proven quite agile in the social media space, an area that retailers need to understand a lot better. And Amazon knows fully that it’s not much of a reach to envision what Facebook and its MySpace arch-rival could do retail-wise if either firm truly opted to master the data and relationships each already has in place. That is precisely what Facebook is trying to do.

The company is not trying it today, but it is trying to lay the foundation for such a move a couple years down the road. To do that will require privacy changes and a different kind of data collection, which brings us to Facebook’s “I’m so sorry that I promise to not do it ever again unless I’m confident you’re not looking” moment.

Facebook today still runs a very distant second to MySpace, but it’s catching up. As of January, according to Hitwise, MySpace had a 57 percent social networking share, compared with Facebook’s 31.1 percent. That’s a snapshot, and it looks good for MySpace. But put a little more context into that data and the picture is clearly trending to Facebook. That 57 percent from January 2009 is a huge drop from the 72.5 percent MySpace had just a year ago (January 2008), and it’s even a healthy (or, in this case, unhealthy) drop from the 60.6 percent it had just a month earlier (December 2008). At the same time, Facebook’s 31.1 percent marketshare is more than double the 15 percent it had in January 2008, and it also registered a substantial increase from the 27 percent it had in December 2008.

Add up all those numbers and it’s clear that Facebook is a social media player to watch. In the meantime, though, the company is plotting the future and realized that its privacy policies weren’t nearly as abusive as they could be. Nobody reads ‘em anyway, execs thought, so why not let the lawyers have a little fun?

Facebook Tries To Master Its Domain

The new rules said that Facebook owns all content on the site, even after a consumer removes it. Facebook heard the backlash and quickly reversed itself. That wasn’t the first time, either. But Facebook wasn’t done yet.

Last Thursday (Feb. 26), company CEO Mark Zuckerberg said he had learned a lesson and that new Facebook rules (officially called The Facebook Principles and the Statement of Rights and Responsibilities) would be “subject to a vote, which may include other alternatives. The vote will be open to all Facebook users active as of February 25, 2009. The results of the vote will be made public and will be binding.” Had he stopped there, it would have been perfect. Let the customers (who aren’t paying anything, but still) vote on this stuff. Then if something happens later, how angry can consumers get if their peers—and perhaps even themselves—had supported the move? Besides, it’s not that dangerous. How many Americans really read the referendums and questions they vote on at the polls?

But, of course, CEO Zuckerberg didn’t leave it at that. He said the results would be binding only “if more than 30 percent of all active registered users vote.” AP crunched the numbers: “If more than 7,000 users comment on any proposed change, it would go to a vote. It would be binding to Facebook if more than 30 percent of active users vote. Based on Facebook’s current size, that would be nearly 53 million people. By comparison, a group created to protest Facebook’s new terms has roughly 139,600 members as of Thursday.”

That’s not a bold move to empower consumers. It’s a cheap display of theatrics—and cheesy theatrics at that—to make it sound like you’ll accept the customer’s will when it really gives Facebook carte blanche to do anything it wants under the façade of being more open. Consumers are not that dumb (actually, they are, but let’s not go there). This scenario has got all of the makings of a massive backfire disaster.

Even worse, that sentence can be interpreted to mean that if 30 percent of active users do not vote, any changes would not only not be binding but they wouldn’t even have to be made public. You think 53 million people are going to even know about the vote, let alone make the effort to participate?

It wouldn’t be so galling if Zuckerberg hadn’t tried to make Facebook sound egalitarian when it was actually being Machiavellian.

“We’re honored that so many millions of people around the world have decided to bring Facebook into their lives to share information and experiences with friends and loved ones. We understand that gives us an important responsibility to our users,” Zuckerberg wrote. “History tells us that systems are most fairly governed when there is an open and transparent dialogue between the people who make decisions and those who are affected by them. We believe history will one day show that this principle holds true for companies as well, and we’re looking to move in this direction with you.”

Why is it that when CEOs use the word “principles,” it’s usually in a context that demonstrates that the principles they truly have are not ones they should be bragging about?


advertisement

3 Comments | Read Amazon, Facebook: Retailers Want IT Leaders That Don’t Lead

  1. Bob LeMay Says:

    When you make the statement “Consumers are not that dumb (actually, they are, but let’s not go there)” you should use “we” instead of “they”.

    Unless you manage to live a self-sufficient lifestyle on a farm somewhere.

    Just because we might be on the business side of retail in our professional lives doesn’t free us from our roles as consumers, too.

  2. Rob Martell Says:

    That was a great article. I’m glad I read it.

    I’d heard about the Kindle thing with Amazon, and although I had heard about the Facebook issue, I don’t use it.

    Now that I have read this, I wish all consumers also had a bunch of lawyers at their disposal!

    Consumers aren’t necessarily dumb, they just can’t devote the time to decipher what the army of lawyers have concocted. And even that would assume they were properly informed about it.

    Argh!

  3. John Schulte Says:

    Facebook has other troubles too, if you’re thinking of using the site for creating business groups, which as I learned the hard way not to, or you should think twice about putting much time into.

    Since they cannot monitor all their members actions personally, your actions are monitored by technology, and it’s not perfect. You can easily do something that triggers their system to deactivate your profile, which in turn leaves any groups you started open to be taken over by the next person that visits the group.

    Yes, a competitor could take over your group.

    This is not well known among business people yet, but if facebook ever expects to be a serious player with business, their system needs to be fixed.

Leave a Reply

Newsletter

Quickly catch-up on the latest in E-Commerce and Retail Tech with our free weekly newsletter, with urgent bulletins as news merits.
advertisement

Most Recent Comments

What’s The Rush For New PCI Call Center Requirements?

And I have not heard anyone mention the impact on companies who provide quality improvement services. Many merchants hire quality improvement companies to review their audio recordings to provide guidance on how to improve their sales staff’s effectiveness in customer service and sales retention. PCI Council needs to rethink this requirement until there is a widely available commercially viable solution. Read more...
Another ridiculous decision where regulators don't think critically enough about the unintended consequences of their decision. This will be a huge problem for the credit and collections industry. We have to keep all recorded calls for other reasons not related to cc information. We can't purge all of our calls and we don't have the technology to not record part of the conversation. Even if we did, I am not sure we could afford it. Read more...
This "clarification" is causing a lot of panic with large FS clients who now appear to be non-compliant after spending 7 figure sums on their compliance programs. The only alternative to call recording would now appear to be some sort of IVR/push button type interrupt to take card data away from the contact centre. The council is a position to force that sort of process and technology change and this may backfire on them and the vendors that lobbied hard for this clarification. Read more...
PCI council has made a one-sided decision; They should have done a much more in-depth research that could have provided more insight on what regards to the implications of such decision. Read more...

Will Old OS Cause PCI Violation? No, But Marketing Still Says So

This is an interesting issue, because there's more to it than what's apparent on the surface. PA-DSS requires supported and patched operating systems and other software components (e.g., databases, libraries, Java, etc.) per PA-DSS 7.1.b and 8.1, and the option for compensating controls simply isn't there. Merchants can make use of compensating controls for most PCI DSS requirements, but only when legitimate constraints exist and only in ways that meet the intent and rigor of the requirement and go above and beyond the other PCI DSS requirements. Read more...
Why would one automatically upgrade to a "new" OS -- some of the older versions of certain OS-es are more stable and more robust than the crap being peddled today. This is yet another clear example of PCI SSC being out of touch with reality. Rather than requiring a "current" OS, the requirement should be to demonstrate the OS in use is stable and robust, and is adequately hardened against threats. Read more...
There are compensating controls that encrypt the swipe at the driver level as it enter the PC, there are hardware encrypting card swipes so the cardholder data is already encrypted before it comes to the PC -- either of these, especially the second, would remove the OS entirely from a cardholder data risk profile. Read more...
In my opinion, the only thing the vendor did wrong was they didn’t know of that FAQ entry. Even if they did, it changes nothing about the need for merchants to update software that no longer receives updates. Read more...

MasterCard Blinks, Drops Dec. 31 Level 2 PCI Deadline

Reciprocity between MasterCard and Visa was always been a factor in Acquirer merchant level assignments. The brief removal of reciprocity generated a great deal of interest in being able to be classified at a lower level in MasterCard's world. Nevertheless the return of the reciprocity language in the December changes did not effectively create any new Level 2 merchants, but it DID dash the hopes of a lot of them.... :-( Read more...
Let's given them credit??? For being idiotic in the first place? Not on your life! Everyone has just had to scramble and include the costs of the previously announced M/C requirement in their 2010 budgets, and start negotiating with the QSAs for the additional services. All for naught! Read more...
"A bunch of Level 3 and Level 4 merchants just became Level 2s". Is this an accurate statement? MasterCard & Visa have historically included the caveat "or is a Level X in another brand" in their level setting criteria. MasterCard appeared to back way from this in the June pronouncement, and have simply returned to the status quo. Have Acquirers have been tracking and reporting merchants at separate levels by brand? Read more...
I stick by my comment (quoted in the column) about a bunch of L3 and L4 merchants becoming L2s and requiring an onsite. To me, what made MasterCard's original requirement for an onsite assessment for L2s palatable was that they took away their reciprocity provision. That is, they seemed to focus on larger merchants with over a million MasterCard trans/year. With reciprocity in place, a lot of smaller merchants are pulled into the onsite requirement. Rather than causing confusion, I think reciprocity will lead to additional work for processors and acquirers. Read more...

Retailers Sue POS Vendor, Questions Raised Where PCI Duties Stop

I would add a couple more questions: "did the breach involve the use of the default passwords?" (The story doesn't say.) And "were the default passwords used by Computer World to remotely administer the store systems?" "where is the PCI auditor in all this?" Did the restaurant group think they didn't need an audit because Radiant was (mis)representing Aloha as PCI compliant? How is a retailer or even a PCI auditor to know otherwise? A PCI auditor is not necessarily a qualified computer forensic investigator capable of finding the card data on the hard drives. They can only base a decision on information given to them by others. Read more...
There are so many holes in the process it will be difficult to pin blame on just one constituent. It is ridiculous that the technology exists to better secure these transactions (PIN, EMV, etc) yet banks won't use them. Only the banks or government can force this change, and retailers will suffer until then. Read more...
A major issue in this case will be if the restaurants had any support agreements in place with Computer World and if so what those agreements say. In my experience many single unit/small operators choose to skip the support agreements in favor of a "pay as you go" arrangement. In this scenario I can't imagine how the POS VAR can be held responsible for a system they don't own nor exclusively manage. Read more...
There is a big difference in having the POS installation guide say "make sure you set this password because the security of your CHD depends on this" vs. a POS application not storing the CHD in the first place. Traditionally only the merchant was liable for breaches and PCI related fees (fines). Maybe dragging some of the vendors into the liability mud fight will open the eyes of some of these vendors. Read more...

Should Credit Card Transactions Be Free? There May Be A Way

Here in the Netherlands, where the population is notoriously penny-pinching, credit card acceptance is amazingly low. It's both a result of the consumer not wanting to pay interest on everyday purchases as well as merchants not giving up a slice of the action. It is both legal and common to pass the processing fee onto the customer as a surcharge. Now things are moving to leave the credit cards behind: mobile phone payments are becoming more and more common here, and the transaction fees are minimal. Parking and entertainment (movie/concert tickets, nightclubs) have been amongst the first, and it's rapidly gaining momentum because the market has been hungry for the convenience at a price it is willing to pay. Read more...
"Free" is an illusion. Don't charge one person but charge double to someone else. I am very skeptical on anyone who says that advertising will create valid cashflow. Just look at the advertising struggles in a TiVo world. And if you sell your customers data, just be warned that the one group that might have issue with that are you customers (which to me is very important to cashflow. Read more...
Another factor not mentioned here is the impending costs that the processors and issuers are going to incur when someone decides on an end-to-end encryption method, and it then becomes government mandated. I can guarantee that this is a when question and not an if question. The back-end networks are pretty antiquated right now, and it's going to cost billions to replace everything. The cost of tech may be going down, but the cost of replacing millions of servers and hardware, and creating new, proprietary, software is still really expensive. Read more...
Accepting credit cards are not "risk-free" for merchants, contrary to Jim's comments above. Chargebacks are an expense - both in terms of actual transaction reversals and costs associated with managing the process. Chargeback rules and expenses can be everything from a thorny issue to an onerous expense for some merchants, especially for convenience stores that allow customers to pay for gasoline at the pump, or other retailers that allow in-store self-checkout options. Read more...
I've wondered for years why the price of transactions has been so high. Phone companies long ago started offering unlimited calling for flat rates because they understood that in many cases it cost more to report on the transactions (calls) than it did to fulfill them. Read more...
If a home-owner defaults on the mortgage, who is taking the risk? The bank making the loan to the consumer or the person selling the house? It is obviously the bank that takes this risk and is rewarded for that risk through interest rate charges. In my mind, we have mixed together two distinct and unrelated transactions. Read more...
The one big factor not mentioned in this article is who will take over the risk ? Taking credit cards is risk free to merchants and the issuing Banks take the risk if a customer defaults on the payments ! If you had a "interchange free" payment system will the merchants assume the risk ? Also, if there isn't enough profit for the issuing banks they will stop issuing credit cards which will in turn kill our economy. Read more...

The Dangerous Out-Of-Scope PCI Charade

If tokens are ever deemed in-scope, then where does the line stop? I ask this because it would mean that all timestamps, sequential number, random numbers or any other piece of information that may or may not be used to generate a token is within scope -- all data a POS uses and stores, not just payment data. Read more...
Having the ability to do both Tokenization and End to End Encryption (not mere point to point) can have tremendous scope and risk reduction benefits and agility to adapt to change in this fast moving compliance landscape. Being able to have both on tap from a single platform is a solid approach to avoiding the pitfalls. Read more...
But the consumer walks into a particular retail chain, gives their payment card to someone wearing that chain's uniform and the card is swiped. If, six months later, there's a breach and that card was misused, it's the retailer who will in the spotlight. They're the deep pocket and, therefore, the target. If the consumer is angry and wants to cut off business, it will hit the retailer. Therefore, if the retailer is going to end up being blamed no matter what, they have to stay involved. Read more...
True, that someone may be storing a token-to-PAN cross reference. But that would be the bank, not the retailer. If the bank is not sure they can keep their data secure, then there are bigger problems to be addressed than bringing tokens into scope. Read more...
Good general point, Steve, but for the record, not all tokenization is done the same way. Many tokens are associated with lookup lists that allow for them to re-matched to the card data if it's needed, such as for a chargeback. A token doesn't have to be decryptable (is that a word?) for there to be a way to access the original data. Read more...
The out-of-scope argument is very valid but in reference to tokens, the premise of temporarily out-of-scope or abruptly deemed in-scope is flawed. Conway was quoted “anything that could be made unreadable can, in various ways, be made readable again,” this statement is true when talking about encryption technologies (all encryption technologies) but not so with true tokens. True tokens are in no way related to the original data other than as a reference key. Read more...