"Patent-pending technology guarantees the integrity of your loyalty program. GPS triangulation, velocity analysis, and statistical variation keep things secure."
Velocity analysis. Sounds complicated. Wonder how well it actually works.
"Patent-pending technology guarantees the integrity of your loyalty program. GPS triangulation, velocity analysis, and statistical variation keep things secure."
Velocity analysis. Sounds complicated. Wonder how well it actually works.
As far as I can tell we started at around the same time but from London, UK. And we have our own patent applications (that I was unhappy about submitting because I don't agree that they were non-obvious, and that punchd did the same thing elsewhere at the same time is evidence of that).
Anyhow... how do we, with what appears to be exactly the same solution, handle security?
Signals, lots of them. What sensors does the phone have? Great, grab it all and start comparing for deviations and against thresholds. When you have enough data start machine learning against it.
With velocity, look at the X,Y,Z of the gravity sensor and see if the numbers since the last QR scan indicate that you're moving at beyond a certain G... clearly scanning a QR code shouldn't require speed.
Then you've got things like, if you scanned in London, could you scan in Birmingham 5 minutes later? What's the likely speed between places.
Did a scan happen at 2am? The rest of the data suggests that they're closed at that hour.
And more subtle ones: If all of the compass readings for a specific branch point within a 15 degree range... you can actually know that they have a single cashpoint and the customer is on the South side of it.
As for whether they work, they're very effective against obviously fake stuff, and then together with other signals create a reasonably high confidence of finding the extremely doubtful stuff. You really want to handle this delicately as the thing you don't want to do is make it really uncomfortable for the small business owner if he suspects someone of fraud... so you want to catch them and deduct the fake points before they enter the shop, but confidently enough that you don't hurt a genuine customer at all.
It's really easy to sit down and create a whole load of tests against a new scan just by looking at a wealth of data from old scans.
I hope they haven't patented that aspect, it's pretty damn obvious.
You're right, it is a very delicate line between catching as many cheaters as possible while avoiding false-positives. We like to err on the side of false-negatives as much as possible.
And I'm sure you've also looked into whether the QR code could be generated per transaction (they could be, but does this place too high a cost-burden on the merchant and if a new device is used to display the generated codes is that going to meet local food hygiene standards for food outlets - and if existing devices are used such as printing on the receipts of their EPOS, is that accommodated by EPOS software).
We also looked into watermarking some signal from a sensor to prove that they were there, then we discovered Shopkick doing this with their noise emitter (a novel approach). We're unsure whether this is the best approach (requires another power point in the merchant, a mount point, installation, and if the emitted signal is dynamic then it requires a connection).
It's an interesting thing for sure... the best thing we've done to date is launch in a student bar with an alcohol deal, there is nothing that generates great data for security like letting compsci students hammer it with the reward of free beer. It's effectively our bug bounty... defeat our system and get a beer (or several) and strongly incentivises us to not have them defeat it.
Keys work very well here ;)