The Role of User-Agent Interactions on Mobile Money Practices in Kenya and Tanzania

Karen Sowon, Edith Luhanga, Lorrie Cranor, Giulia Fanti, Conrad Tucker, Assane Gueye

IEEE Symposium on Security and Privacy 2024 · Day 1 · Continental Ballroom 4

Overview

This talk, presented by Karen Sowon and a team of researchers from Carnegie Mellon University, delves into the often-overlooked security and privacy implications of user-agent interactions within the mobile money (Momo) ecosystem in Kenya and Tanzania. While the adoption of mobile money and its impact on financial inclusion have been extensively studied, the specific dynamics and vulnerabilities arising from how users engage with mobile money agents have received considerably less attention. The research highlights a critical gap in understanding how everyday practices, driven by both convenience and perceived security, inadvertently introduce new risks.

Watch on YouTube

Visual summary for The Role of User-Agent Interactions on Mobile Money Practices in Kenya and Tanzania by Karen Sowon, Edith Luhanga, Lorrie Cranor, Giulia Fanti, Conrad Tucker, Assane Gueye
Visual summary for The Role of User-Agent Interactions on Mobile Money Practices in Kenya and Tanzania by Karen Sowon, Edith Luhanga, Lorrie Cranor, Giulia Fanti, Conrad Tucker, Assane Gueye

Key moments

  1. 0:00 Introduction to mobile money and its financial inclusion impact
  2. 2:00 Highlighting the overlooked user-agent interaction in mobile money
  3. 4:15 Explaining cash-in, cash-out, and P2P mobile money transactions
  4. 6:00 Overview of three key findings: workarounds, agent choice, long-term risks
  5. 6:50 Detailing user and agent workarounds for transactions and KYC
  6. 8:00 Motivations for workarounds and their serious privacy/security implications
  7. 9:00 Varied perceptions and concerns about data privacy and ID misuse

The Role of User-Agent Interactions on Mobile Money Practices in Kenya and Tanzania

Speakers: Karen Sowon; Edith Luhanga; Lorrie Cranor; Giulia Fanti; Conrad Tucker; Assane Gueye

Conference: IEEE S&P

YouTube: https://www.youtube.com/watch?v=jaZ2olvsFyY

Overview

This talk, presented by Karen Sowon and a team of researchers from Carnegie Mellon University, delves into the often-overlooked security and privacy implications of user-agent interactions within the mobile money (Momo) ecosystem in Kenya and Tanzania. While the adoption of mobile money and its impact on financial inclusion have been extensively studied, the specific dynamics and vulnerabilities arising from how users engage with mobile money agents have received considerably less attention. The research highlights a critical gap in understanding how everyday practices, driven by both convenience and perceived security, inadvertently introduce new risks.

The study uncovers a complex interplay of user-designed workarounds and agent-facilitated modifications to standard mobile money procedures, particularly concerning Know Your Customer (KYC) requirements. These adaptations, initially conceived to navigate system challenges or mitigate existing risks, are shown to inadvertently undermine the very security mechanisms they aim to circumvent or enhance. The findings underscore the urgent need for a more nuanced approach to designing privacy and security features that account for the real-world behaviors and constraints of mobile money users and agents, especially in regions where mobile money is a cornerstone of financial access for the unbanked.

The work is significant because mobile money has revolutionized financial access for millions in emerging economies, particularly in Africa. Agents act as the crucial last-mile link, providing services far beyond the reach of traditional banks. Understanding the security posture of these agent-mediated interactions is paramount to ensuring the continued trustworthiness and resilience of a system that digitizes a substantial portion of national GDPs and serves as a primary financial conduit for vast populations.

Background

▶ Watch: Introduction to mobile money and its financial inclusion impact (0:00)

Mobile money (Momo) has emerged as a transformative financial service, predominantly offered by telecommunication companies (Telcos) in regions where traditional banking infrastructure is scarce or inaccessible. It has been instrumental in bridging the financial inclusion gap for millions of unbanked individuals, particularly across Africa. Unlike conventional banking, Momo leverages existing Telco infrastructure, relying on SMS and USSD protocols, making it accessible even on feature phones, which remain prevalent in many communities. A user's phone number effectively serves as their bank account, simplifying access to digital payments and various banking services.

A cornerstone of the Momo ecosystem is the network of authorized third-party agents. These agents, typically small businesses or shops within local communities, facilitate the "last-mile" access to mobile money services. They provide essential functions such as cashing in (depositing physical cash into a mobile money account) and cashing out (withdrawing physical cash from a mobile money account). Agents earn commissions for these services, incentivizing their participation and significantly extending the reach of financial services. In 2022, for instance, agents in Kenya digitized an amount equivalent to a third of the nation's GDP in just six months, highlighting their immense economic impact and reach, which is estimated to be at least 55 times greater than that of traditional banks.

The research distinguishes between two primary categories of interactions within the mobile money landscape: user-Momo interactions (pertaining to the adoption and direct use of the service) and user-agent interactions. While user-Momo interactions and adoption have been extensively studied, the privacy and security aspects of user-agent interactions have remained largely underexplored. This oversight is critical given the multifaceted roles agents play beyond simple transaction facilitation. Agents are often responsible for onboarding new users, which involves registering SIM cards and linking them to identification documents, typically national IDs. They also educate users on how to utilize Momo services and ensure compliance with Know Your Customer (KYC) regulations. KYC is a vital identity-proofing requirement designed to give mobile money providers a clear picture of their customers, essential for combating money laundering and anti-terrorism financing. Furthermore, agents frequently provide frontline customer support, addressing user queries and issues.

To understand the intricacies of privacy and security in user-agent interactions, the researchers conducted qualitative studies in Kenya and Tanzania, two pioneering countries in mobile money adoption. They interviewed a total of 72 mobile money users, 36 from each country.

The fundamental operation of mobile money involves three main transaction types:

  1. Cashing in (depositing): A user hands physical cash to an agent. If the agent has sufficient "float" (their mobile money balance), they accept the cash and transfer the equivalent mobile money to the user's phone via SMS.
  2. Cashing out (withdrawing): A user transfers mobile money from their phone to the agent's account. If the agent has sufficient physical cash, they accept the transfer and provide the user with the equivalent physical cash.
  3. Person-to-Person (P2P): Users directly transfer money from their phone to another user's phone via SMS or USSD, using the recipient's phone number as the account. Agent mediation is typically not required for P2P transactions.

Crucially, for agent-mediated transactions (cashing in and cashing out), users are mandated to present their physical ID to comply with KYC regulations. The agent is supposed to authenticate the customer by comparing the details on the physical ID with information returned by the Momo system after initiating the transaction. This foundational process is where many of the identified privacy and security challenges begin to manifest.

Key Findings

▶ Watch: Explaining cash-in, cash-out, and P2P mobile money transactions (4:15)

The study yielded three overarching key findings that collectively paint a comprehensive picture of the security and privacy landscape in user-agent mobile money interactions:

  1. Users and Agents Design Workarounds in Response to Ecosystem Challenges: The research observed that both mobile money users and agents frequently devise and employ informal "workarounds" to navigate various difficulties within the mobile money ecosystem. These challenges range from practical issues like network downtime, insufficient agent float, and high transaction costs to more direct security and data privacy concerns. These workarounds are not isolated incidents but rather systemic adaptations observed across all phases of a transaction, including execution and KYC compliance.
  1. Agent Choice is Driven by Convenience and Risk Mitigation: While convenience remains a significant factor in a user's choice of a mobile money agent, the study revealed that a key motivating factor is also the conscious desire to mitigate perceived privacy and security risks. Users often make deliberate choices about which agents to frequent, or how to structure their transactions, based on their assessment of the trustworthiness and security practices of specific agents or locations. This highlights an underlying awareness of potential vulnerabilities, even if the mitigation strategies employed can sometimes be counterproductive.
  1. Workarounds Introduce New Privacy and Security Challenges: Paradoxically, the very workarounds designed to overcome existing challenges or mitigate risks often create new, and sometimes more severe, privacy and security vulnerabilities in the long run. These informal adaptations frequently undermine the official security measures and protocols, such as KYC, that are meant to protect users and the integrity of the mobile money system. This finding underscores a critical tension between user-driven problem-solving and the overarching security framework.

These findings collectively illustrate a complex ecosystem where practical necessities, perceived risks, and informal adaptations interact to shape the actual security and privacy posture of mobile money transactions.

Technical Deep Dive

▶ Watch: Overview of three key findings: workarounds, agent choice, long-term risks (6:00)

The core of the study's technical insights lies in the detailed examination of the workarounds observed in Kenya and Tanzania, and the motivations behind them. These workarounds are not merely minor deviations but represent significant departures from established protocols, particularly impacting transaction execution and KYC procedures.

In the transaction execution phase, workarounds involved:

  • Changing the transaction process: This included involving proxies, where someone other than the account holder conducts the transaction. For example, K18 noted that the proxy had to be known by the agent to facilitate the process. This introduces risks related to delegation of trust and potential for fraud if the proxy is compromised or untrustworthy.
  • Modifying the agent's role: Users sometimes left physical cash and their details (phone number, transaction amount) with agents during network downtime, trusting the agent to complete the transaction later (K01). This bypasses real-time confirmation and places significant trust in the agent, creating a window for potential manipulation or loss.
  • Modification of transaction characteristics: Users might alter the size or location of their transactions for security purposes. K08, for instance, described dividing a large transaction into two or three smaller ones, conducted at different agents, to reduce the risk associated with a single large sum. TZ33 similarly changed transaction locations for security. While seemingly proactive, this fragmentation can complicate tracking and dispute resolution.

The motivators for these transaction-phase workarounds were diverse, including:

  • Navigating transaction costs: Users might seek agents with lower perceived fees or structure transactions to minimize costs.
  • Seeking more convenience: The desire for a quicker, less cumbersome process, especially if official procedures are perceived as slow or bureaucratic.
  • Network downtime: A frequent and significant driver, forcing users to improvise to complete urgent transactions.
  • Insufficient float: Agents might not have enough mobile money or physical cash, leading users to seek alternatives or leave funds with agents.
  • Security concerns: Users expressed fears about agents knowing their transaction details, which could be used to perpetrate fraud (TZ32: "I don't feel good because one can't know the agents intentions they know your transaction details they can tell someone else and then you end up being robbed").
  • Data privacy: Varied perceptions on sharing data with agents. While some users (TZ6) trusted agents to keep information safe, others (K25) reported agents misusing IDs to register additional SIM cards, which were then sold to individuals without proper identification. This practice directly undermines identity verification and can facilitate illicit activities.

Workarounds were also extensively observed in the KYC phase, where users and agents collaboratively modified how KYC was completed and what was provided for identity proofing. While many users acknowledged KYC's importance for security (K20, K21), ensuring individuals weren't feigning identity, they also expressed significant dissatisfaction with its practical implementation. Challenges included:

  • Denial of service: If a user forgot their ID, they couldn't transact, leading to frustration and potential financial exclusion at a critical moment.
  • Impracticality for agents: Agents facilitate numerous transactions daily, making a thorough ID check for every customer seem impractical and time-consuming.

These challenges led to several critical KYC workarounds:

  • Using someone else's ID: K15 reported using a cousin's ID because their SIM card was registered under that ID. This is analogous to using someone else's Social Security Number and account, completely breaking the link between the user and their financial identity, and enabling identity fraud.
  • Providing only the ID number: Many participants, like K20, reported simply giving the agent their ID number instead of the physical document. This removes the visual authentication step, making it easier for imposters to provide a false number.
  • Agents memorizing ID numbers: K31 mentioned that their regular agents had memorized their ID numbers, negating the need for repeated presentation. While convenient, this creates a single point of failure and makes it trivial for an agent to impersonate the user or facilitate transactions for others under that user's identity.

These workarounds, driven by a mix of necessity, convenience, and perceived security, collectively degrade the integrity of the mobile money system. They render KYC protocols ineffective, making it difficult to link transactions to legitimate individuals. This breakdown of identity verification creates a fertile ground for repudiation, where a user (or someone using their SIM) can deny having received money (TZ17), complicating P2P transactions and dispute resolution. Furthermore, the "data-rich environment" created by these informal practices, combined with broken KYC, makes mobile money users highly vulnerable to fraud and potential loss of funds (K17).

The study highlights a critical disconnect: users perceive certain actions as mitigating risk (e.g., dividing transactions) or increasing convenience (e.g., agents memorizing IDs), but these actions often introduce systemic vulnerabilities that undermine the overall security architecture. This technical deep dive reveals how human factors, operational constraints, and informal social dynamics interact to create significant security challenges in a vital financial ecosystem.

Demo / Proof of Concept

▶ Watch: Motivations for workarounds and their serious privacy/security implications (8:00)

This technical article is based on a qualitative study that focused on understanding user and agent behaviors, motivations, and observed workarounds within the mobile money ecosystem. The talk describes the methodology, findings, and implications of this research. As such, the presentation did not include a live demonstration or a proof of concept of a specific exploit or technical vulnerability in the traditional sense. Instead, the "proof" is derived from the empirical data collected through interviews and observations, illustrating how real-world practices introduce security and privacy risks.

Defensive Implications

▶ Watch: Varied perceptions and concerns about data privacy and ID misuse (9:00)

The findings of this study carry significant defensive implications for mobile money providers, regulators, and security practitioners operating in similar ecosystems. The pervasive nature of user and agent workarounds means that existing security mechanisms, particularly KYC, are often circumvented or rendered ineffective in practice. This necessitates a re-evaluation of current security strategies and a shift towards more adaptive and user-centric defensive postures.

Firstly, there is an urgent need to design for privacy and security at the interface between agents and users. This goes beyond merely enforcing policies; it requires understanding the practical constraints and motivations that drive workarounds. Security features should be intuitive, minimize friction, and integrate seamlessly into existing workflows. For instance, if network downtime prompts users to leave details with agents, solutions could include offline transaction capabilities with secure deferred processing, or more robust real-time network status indicators and alternative channels. The critical role of agents in financial inclusion means they cannot be bypassed; instead, their interactions need to be fortified with robust, yet usable, security protocols. Training for agents should not only cover official procedures but also address common workarounds and their associated risks, empowering agents to guide users towards secure practices.

Secondly, the challenges with identity proofing for individuals who lack formal identification or consistently forget their IDs highlight a systemic flaw in registration and authentication mechanisms. The current reliance on physical IDs, while crucial for KYC, creates a barrier to access and incentivizes risky workarounds like using someone else's ID or providing only an ID number. Defenders must explore alternative, robust, and inclusive identity verification methods. This could involve biometric authentication (e.g., fingerprint or facial recognition linked to a secure digital identity), digital identity solutions that are easier to carry and verify than physical cards, or reputation-based systems within trusted community networks, carefully designed to prevent abuse. The goal must be to maintain the integrity of KYC without excluding the very population mobile money aims to serve.

Finally, a fundamental defensive strategy involves improving the overall usability of mobile money services to address the underlying motivations for workarounds. If transaction costs are high, providers should explore more equitable pricing structures. If procedures are cumbersome, simplifying them through better UI/UX design on feature phones or agent terminals can reduce friction. For example, implementing clear, multi-language prompts for transaction details and confirmations can prevent errors and reduce reliance on agent-led data entry. The study highlights that user workarounds are often inconsistent with their own security preferences, likely due to the burdensome nature of official processes. By making the secure path the easiest path, providers can naturally guide users away from risky behaviors. This involves continuous feedback loops with users and agents to identify pain points and iteratively improve the system.

In summary, defensive measures must move beyond theoretical security policies to address the practical realities of mobile money usage. This involves a multi-pronged approach encompassing user-centric design, innovative identity solutions, and continuous usability improvements, all while recognizing the indispensable role of agents in the ecosystem.

Key Takeaways

  • Workarounds are Systemic and Risk-Driven: Mobile money users and agents frequently employ informal workarounds, not just for convenience, but also to mitigate perceived risks (e.g., network downtime, insufficient float, security concerns) or overcome challenges within the ecosystem.
  • Workarounds Undermine Security Measures: These ad-hoc solutions, particularly those related to Know Your Customer (KYC) procedures, often inadvertently break down existing privacy and security protocols, creating new vulnerabilities rather than solving old ones.
  • Broken KYC Leads to Severe Risks: The circumvention of KYC, such as using proxies, sharing ID numbers, or agents memorizing IDs, directly enables identity fraud, increases the risk of repudiation (denying transactions), and makes users more susceptible to financial loss.
  • Agent Choice Reflects Security Concerns: Users' decisions regarding which agents to patronize are significantly influenced by their desire to mitigate privacy and security risks, indicating an underlying awareness of the ecosystem's vulnerabilities.
  • Usability is Key to Security Compliance: The friction and perceived burdens of official mobile money processes, especially KYC, often drive users to adopt risky workarounds. Improving the usability and accessibility of secure procedures is crucial for encouraging compliance.
  • Design for the Agent-User Interface: Given the critical role of agents in financial inclusion, security and privacy measures must be thoughtfully designed for the specific dynamics of the agent-user interaction, including robust alternative identity proofing mechanisms for the unbanked or those without consistent ID access.

About the Speaker(s)

The lead presenter for this talk was Karen Sowon, a researcher affiliated with Carnegie Mellon University. The study was a collaborative effort involving a team of researchers from Carnegie Mellon University, including Edith Luhanga, Lorrie Cranor, Giulia Fanti, Conrad Tucker, and Assane Gueye. Their collective expertise spans various domains relevant to this research, including human-computer interaction, privacy engineering, computer security, and emerging economies, contributing to the comprehensive analysis of mobile money practices.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

This research meticulously uncovers how user and agent workarounds in mobile money ecosystems, driven by convenience and perceived risk, inadvertently shatter fundamental security protocols like KYC. It exposes critical systemic vulnerabilities in a vital financial infrastructure, demonstrating that human factors are often the weakest link, demanding urgent re-evaluation of current defensive strategies.

Heather Calloway (CISO) — STRONG ACCEPT

This research exposes a critical failure in designing security that aligns with operational realities, directly undermining KYC and exposing mobile money ecosystems to significant business risk. Providers and regulators are accountable to implement practical, user-centric controls that work in the field, protecting financial integrity and inclusion.

→ Top-rated talks at IEEE Symposium on Security and Privacy 2024

All talks from IEEE Symposium on Security and Privacy 2024