Smoke is rising from Apple’s Conclave

by Cherian Abraham 9 min read October 2, 2013

TL;DRRead within as to how Touch ID is made possible via ARM’s TrustZone/TEE, and why this matters in the context of the coming Apple’s identity framework. Also I explain why primary/co-processor combos are here to stay. I believe that eventually, Touch ID has a payments angle – but focusing on e-commerce before retail. Carriers will weep over a lost opportunity while through Touch ID, we have front row seats to Apple’s enterprise strategy, its payment strategy and beyond all – the future direction of its computing platform.

I hadshared my takeon a possible Apple Biometric solution during the Jan of this year based on its Authentec acquisition. I came pretty close, except for the suggestion that NFC is likely to be included. (Sigh.)

Its a bit early to play fast and loose with Apple predictions, but its Authentec acquisition should rear its head sometime in the near future (2013 – considering Apple’s manufacturing lead times), that a biometric solution packaged neatly with an NFC chip and secure element could address three factors that has held back customer adoption of biometrics: Ubiquity of readers, Issues around secure local storage and retrieval of biometric data, Standardization in accessing and communicating said data. An on-chip secure solution to store biometric data – in the phone’s secure element can address qualms around a central database of biometric data open to all sorts of malicious attacks. Standard methods to store and retrieve credentials stored in the SE will apply here as well.

Why didn’t Apple open up Touch ID to third party dev?

Apple expects a short bumpy climb ahead for Touch ID before it stabilizes, as early users begin to use it. By keeping its use limited to authenticating to the device, and to iTunes – it can tightly control the potential issues as they arise. If Touch ID launched with third party apps and were buggy, it’s likely that customers will be confused where to report issues and who to blame.

That’s not to say that it won’t open up Touch ID outside of Apple. I believe it will provide fettered access based on the type of app and the type of action that follows user authentication. Banking, Payment, Productivity, Social sharing and Shopping apps should come first. Your fart apps? Probably never.

Apple could also allow users to set their preferences (for app categories, based on user’s current location etc.) such that biometrics is how one authenticates for transactions with risk vs not requiring it. If you are at home and buying an app for a buck – don’t ask to authenticate. But if you were initiating a money transfer – then you would. Even better – pair biometrics with your pin for better security.Chip and Pin? So passé.

Digital Signatures, iPads and the DRM 2.0:

It won’t be long before an iPad shows up in the wild sporting Touch ID. And with Blackberry’s much awaited and celebrated demise in the enterprise, Apple will be waiting on the sidelines – now with capabilities that allowdigital signatures to become ubiquitous and simple – on email, contracts or anything worth putting a signature on. Apple has already made its iWork productivity apps(Pages, Numbers, Keynote), iMovie and iPhotofreefor new iOS devices activated w/ iOS7.

Apple, with a core fan base that includes photographers, designers and other creative types, can now further enable iPads and iPhones to become content creation devices, with the ability to attribute any digital content back to its creator by a set of biometric keys. Imagine a new way to digitally create and sign content, to freely share, without worrying about attribution.

Further Apple’s existing DRM frameworks are strengthened with the ability to tag digital content that you download with your own set of biometric keys. Forget disallowing sharing content –Apple now has a way to create a secondary marketplace for its customers to resell or loan digital content, and drive incremental revenue for itself and content owners.

Conclaves blowing smoke:

In a day and age where we forego the device for storing credentials – whether it be due to convenience or ease of implementation – Apple opted for an on-device answer for where to store user’s biometric keys. There is a reason why it opted to do so – other than the obvious brouhaha that would have resulted if it chose to store these keys on the cloud.

Keys inside the device. Signed content on the cloud. Best of both worlds.

Biometric keys need to be held locally, so that authentication requires no roundtrip and therefore imposes no latency. Apple would have chosen local storage (ARM’s SecurCore) as a matter of customer experience, and what would happen if the customer was out-of-pocket with no internet access. There is also the obvious question that a centralized biometric keystore will be on the crosshairs of every malicious entity. By decentralizing it, Apple made it infinitely more difficult to scale an attack or potential vulnerability.

More than the A7, the trojan in Apple’s announcement was the M7 chip – referred to as the motion co-processor. I believe the M7 chip does more than just measuring motion data.

M7 – A security co-processor?

I am positing that Apple is using ARM’sTrustZonefoundation and it may be using the A7 or the new M7 co-processor for storing these keys and handling the secure backend processing required.

Horace Dediu of Asymco hadcalled to questionwhy Apple had opted for M7 and suggested that it may have a yet un-stated use.I believe M7 is not just a motion co-processor, it is also a security co-processor. I am guessing M7 is based on the Cortex-M series processors and offloads much of this secure backend logic from the primary A7 processor and itmay bethat the keys themselves are likely to be stored here on M7. The Cortex-M4 chip has capabilities that sound very similar to what Apple announced around M7 – such as very low power chip, that is built to integrate sensor output and wake up only when something interesting happens. We should know soon.

This type of combo – splitting functions to be offloaded to different cores, allows each cores to focus on the function that it’s supposed to performed. I suspect Android will not be far behind in its adoption, where each core focuses on one or more specific layers of the Android software stack. Back at Google I/O 2013, it had announced 3 new APIs (the Fused location provider) that enables location tracking without the traditional heavy battery consumption. Looks to me that Android decoupled it so that we will see processor cores that focus on these functions specifically – soon.

ARMv8

I am fairly confident that Apple has opted for ARM’s Trustzone/TEE. Implementation details of the Trustzone are proprietary and therefore not public. Apple could have made revisions to the A7 chip spec and could have co-opted its own. But using the Trustzone/TEE and SecurCore allows Apple to adopt existing standards around accessing and communicating biometric data. Apple is fully aware of the need to mature iOS as a trusted enterprise computing platform – to address the lack of low-end x86 devices that has a hardware security platform tech. And this is a significant step towards that future.

What does Touch ID mean to Payments?

Apple plans for Touch ID kicks off with iTunes purchase authorizations. Beyond that, as iTunes continue to grow in to a media store behemoth – Touch ID has the potential to drive fraud risk down for Apple – and to further allow it to drive down risk as it batches up payment transactions to reduce interchange exposure. It’s quite likely that à la Walmart, Apple has negotiated rate reductions – but now they can assume more risk on the front-end because they are able to vouch for the authenticity of these transactions. As they say – customer can longer claim the fifth on those late-night weekend drunken purchase binges.

Along with payment aggregation, or via iTunes gift cards – Apple has now another mechanism to reduce its interchange and risk exposure. Now – imagine if Apple were to extend this capability beyond iTunes purchases – and allow app developers to process in-app purchases of physical goods or real-world experiences through iTunes in return for better blended rates? (instead of Paypal’s 4% + $0.30).Heck, Apple can opt for short-term lending if they are able to effectively answer the question of identity – as they can with Touch ID. It’s Paypal’s ‘Bill Me Later’ on steroids.

Effectively, a company like Apple who has seriously toyed with the idea of a Software-SIM and a “real-time wireless provider marketplace” where carriers bid against each other to provide you voice, messaging and data access for the day – and your phone picks the most optimal carrier, how far is that notion from picking the cheapest rate across networks for funneling your payment transactions? Based on the level of authentication provided or other known attributes – such as merchant type, location, fraud risk, customer payment history – iTunes can select across a variety of payment options to pick the one that is optimal for the app developer and for itself.

And finally, who had the most to lose with Apple’s Touch ID?

Carriers. Iwrote about this before as well, here’s what I wrote then (edited for brevity):

Does it mean that Carriers have no meaningful role to play in commerce? Au contraire. They do. But its around fraud and authentication. Its around Identity. … But they seem to be stuck imitating Google in figuring out a play at the front end of the purchase funnel, to become a consumer brand(Isis). The last thing they want to do is leave it to Apple to figure out the “Identity management” question, which the latter seems best equipped to answer by way of scale, the control it exerts in the ecosystem, its vertical integration strategy that allows it to fold in biometrics meaningfully in to its lineup, and to start with its own services to offer customer value.

So there had to have been much ‘weeping and moaning and gnashing of the teeth’ on the Carrier fronts with this launch. Carriers have been so focused on carving out a place in payments, that they lost track of what’s important – that once you have solved authentication, payments is nothing but accounting. I didn’t say that. Ross Anderson of Kansas City Fed did.

What about NFC?

I don’t have a bloody clue. Maybe iPhone6? iPhone

This is a re-post from Cherian'soriginal blog post"Smoke is rising from Apple's Conclave"

Related Posts

Expanding the Prescreen View with Alternative Credit Data

Start with a simple question Credit prescreen is an important tool in many lenders’ growth strategies. But the precision of any prescreen strategy depends on the data behind it. What financial behavior might traditional credit data alone not reveal? With Clarity data now available for Instant Prescreen decisioning, lenders can bring alternative credit insights into their targeting strategy, helping them identify prospects who may align with their established criteria, refine targeting strategies and explore additional acquisition opportunities while maintaining control over their risk thresholds. Additional insights alongside traditional credit data For many consumers, a traditional credit file tells a rich and reliable story. But it doesn't always tell the whole story. Consumers may also be using alternative financial products, such as small-dollar installment loans, single-payment loans, auto title loans or rent-to-own agreements and building payment histories that provide additional signals about their financial behavior. For lenders, those unseen signals can represent untapped opportunities. With more than 60 million unique subprime identities, Clarity's database helps lenders gain a more complete view of their applicant pool. Clarity data adds another dimension to that view, providing alternative credit insights that can help lenders better understand consumers whose financial behavior may not be fully represented by traditional credit data alone. How Clarity data sharpens instant prescreen decisioning Clarity provides specialty alternative credit data, with insights into subprime and near-prime consumer activity that may not appear in traditional credit files. And because Clarity is part of Experian, those insights can now be brought directly into Instant Prescreen decisioning. That means lenders can incorporate additional attributes and scores into their credit decisioning strategies without managing a separate data feed or stitching together disconnected sources. It has quickly become a visibility gap lenders can't ignore. Additional data may help support more granular segmentation and targeting strategies. Lenders remain in control of their criteria and risk thresholds while gaining additional information to inform their prescreen strategies. When considered alongside traditional credit data, alternative credit insights can support several aspects of prescreen decisioning: Identify more opportunities: Surface qualified prospects who may be harder to identify using traditional credit data alone. Refine targeting: Add alternative credit insights to help differentiate consumers with greater precision. Inform offer strategies: Use a broader view of financial behavior to help align consumers with appropriate offers. Expand intelligently: Explore incremental audience opportunities while maintaining control over your established risk criteria. Simplify execution: Access Experian and Clarity insights within a connected Instant Prescreen decisioning environment. See more opportunity in your prescreen strategy Growth doesn’t always require looking for an entirely new audience. Sometimes, it starts with seeing more in the audience already in front of you. By bringing Clarity data into Instant Prescreen, lenders can add another layer of insight to their decisioning, helping identify incremental opportunities, refine targeting and support acquisition decision processes across a broader range of consumers. Explore prescreen solutions

September 3, 2026 by Zohreen Ismail
Are Fraudsters Building Better Identities Than Your Customers?

Fraudsters are getting surprisingly good at onboarding. Sometimes, better than your customers. Legitimate customers treat onboarding like an errand. They start an application between other tasks, get distracted, forget a password, switch devices, upload a document or come back later to finish. Their digital lives aren’t always linear, because real life isn’t either. Fraudsters approach onboarding differently. For them, opening an account is the objective. Every interaction is designed to increase the odds of success. The difference raises an uncomfortable question hanging over onboarding: What exactly are we rewarding? When smooth becomes suspicious Digital onboarding has traditionally rewarded experiences that feel smooth, consistent and complete. The challenge is that legitimate customers rarely behave that way. Most people approach onboarding somewhere between mildly distracted and mildly annoyed. They pause halfway through because dinner is burning. They reopen an old account only to realize everything is attached to an email they made in college and, somehow, still use for airline receipts. Digital life accumulates history unevenly, because ordinary life does too. Fraudsters have every reason to eliminate those inconsistencies. Applications may be rehearsed. Identity attributes are assembled deliberately. Contact points are prepared in advance. Every interaction is optimized to make the application appear credible. Ironically, the qualities organizations often associate with confidence — clean submissions, steady progression and few corrections — can also describe applications that have been carefully engineered to pass inspection. The challenge isn't that smooth onboarding is meaningless. It's that smooth onboarding, by itself, doesn't tell the whole story. Context changes interpretation A smooth onboarding experience should be the beginning of the evaluation, not the end. Behavior provides important context. How someone moves through an application can reveal whether the experience feels naturally human or unusually orchestrated. Do they interact naturally? Do they hesitate, correct mistakes or navigate in ways that resemble ordinary human behavior? Or does the session appear unusually scripted, automated or repetitive? Identity verification adds another layer. Matching information across trusted sources, validating identity details and strengthening confidence in account creation remain important, particularly when onboarding decisions carry financial, fraud or customer experience consequences. But verification largely answers a point-in-time question: Does this information match right now? A third layer comes from digital history. An inbox attached to years of airline receipts, loyalty accounts, subscription renewals, account recovery, financial notifications and familiar digital routines introduces a different kind of confidence. Legitimate digital identities leave behind patterns of persistence and engagement that develop gradually over time. Fraudsters can assemble convincing identity attributes, but creating years of ordinary digital life is much harder. Building confidence in an identity requires more than verifying information submitted during a single onboarding session. It requires understanding whether the identity reflects a broader history that supports what the application suggests. A multilayered approach builds stronger identity confidence No single signal can provide a complete view of identity risk. Organizations need multiple sources of confidence that reinforce one another. That's the thinking behind our approach: combining behavioral intelligence, identity verification and digital identity continuity into a more complete view of risk. We bring these complementary layers together through: • NeuroID adds behavioral context during onboarding and account creation, helping identify interaction patterns that may indicate automation, manipulation or coordinated fraud. • Precise ID® strengthens identity verification and resolution by comparing applicant information with trusted identity data. • AtData, recently added to our portfolio, contributes email-centered intelligence based on persistence, engagement and long-term digital history. Together, these capabilities help organizations move beyond evaluating a single moment in time to understanding whether an identity is supported by consistent behavior, trusted identity data and an established digital history. The future of fraud prevention isn't about rewarding the smoothest application. It's about recognizing the most trustworthy identity. Fraudsters can rehearse an application. They can optimize an onboarding journey. They can even assemble convincing identity attributes. What they can't easily manufacture is years of ordinary digital life. That's why digital identity continuity has become an important layer of modern fraud prevention. Combined with identity verification and behavioral intelligence, it helps organizations distinguish between identities that simply look convincing and those supported by a history that is much harder to fake. Learn more Contact us

September 2, 2026 by Julie Lee
From Hybrids to Refinancing: Consumers are Finding New Roads to Vehicle Affordability

For today’s automotive consumers, considering a vehicle purchase isn’t just about the price they see on the window, it’s about finding the right combination of their vehicle preference and monthly payment. In fact, data from Experian Automotive’s State of the Automotive Finance Market Report: Q2 2026 highlighted how affordability continues to shape the automotive finance market. For instance, hybrids offered the lowest average new vehicle loan payment across all fuel types, coming in at $646 in Q2 2026, compared to electric vehicles (EVs) at $692, and gasoline-powered vehicles at $721. This led to considerable growth in new vehicle market share for hybrids this quarter, accounting for 16.80%, from 12.99% last year. While the automotive market continues to offer consumers an expanding mix of fuel types, the combination of growing hybrid share and comparatively lower monthly payments is something worth watching. Affordability isn’t just about what consumers drive, it’s how they finance it While hybrid vehicles are continuing to pave their way in the vehicle market, consumers who already have an auto loan are finding greater savings through refinancing. In the second quarter of 2026, automotive refinancing reached approximately 140,000 loans. More notably, the financial benefit associated with refinancing has grown. Consumers who refinanced this quarter reduced their average interest rate by more than 2.4%, with the average rate moving from 10.40% on the original loan to 7.97% on the refinanced loan. Those rate reductions translated into meaningful monthly savings, especially when refinancing through particular lenders. In Q2 2026, refinancing saved consumers an average of $83 per month, compared to an average monthly savings of $64 this time last year. However, credit unions delivered the largest average payment difference among lender types at $102 this quarter, followed by banks ($65), and finance companies ($38). It’s important for automotive professionals to acknowledge that affordability is not a single moment in the vehicle journey. It can influence the vehicle a consumer chooses, the financing they opt for during that transaction, and the decisions they make years after driving off the lot. Understanding and leveraging those different moments can help professionals identify opportunities to better serve consumers throughout the vehicle ownership lifecycle. To learn more about automotive finance trends, view the full State of the Automotive Finance Market Report: Q2 2026 presentation on demand.

August 27, 2026 by Melinda Zabritski

Subscribe to our Newsletter

Enter your name and email for the latest updates.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Subscribe to our Newsletter

Don't miss out on the latest industry trends and insights!
Subscribe