The Gold Economy wrote: > Part II of the article rating digital currencies on their payment interfaces > is now posted on The Gold Economy: > > http://www.goldeconomy.com/ct/t.php?l=12 >
Hello Ken, Thanks for an excellent summary of the different systems and features... As the pioneer of automation in the gold currencies,and as the designer of the Pecunix system, I have a few comments. <aside content="some history"> Some of you will remember that I was the first person ever (back in 1998) to automate e-gold spends. There was no e-gold automation interface, I designed a clever script that actually "spoofed" the e-gold forms and logged in to complete the spends as if it were a person. I remember Jim Ray telling me it "could" not be done and Jay telling me it "should" not be done :). Soon after I did it, JP may did it for thegoldcasino.com. Once automation was a reality the e-gold system started to grow... </aside> Your assessment of the e-gold and GoldMoney systems seems accurate, but there are a few places I disagree on the e-bullion and Pecunix assessments. First, e-bullion: You mention "The e-Bullion Automated Transaction Interface Program (ATIP) uses PGP/GPG keys to allow users to authenticate themselves to the e-Bullion system" This is unfortunately not true. The e-bullion system is absolutely NOT compatible with PGP as it is currently implemented. The keys generated by the e-bullion system are not PGP compatible. Furthermore, you mention the fact that e-bullion generates the keys as an "imperfection". This is a massive understatement! The fact that the e-bullion system generates the keys goes against everything that public key cryptography stands for. It reveals a lack of understanding by the designers of the system and leaves the e-bullion system open to insider attacks. There are many other clues in the way the e-bullion GPG is implemented that illustrate that the designers of the system didn't really know what they were doing. You also make mention of the e-bullion documentation. I disagree with your assessment. The e-bullion documentation is poorly presented and until I implemented the e-bullion interface a few weeks ago, contained errors. Compare the Pecunix documentation at http://pecunix.com/money.refined...ref.developer and the merchant tools in the full access level of your Pecunix account. One MAJOR shortcoming in the e-bullion merchant interface (not manifested in any of the other currencies) is that there is no way to ensure verification of a "shopping cart" payment. If the user does not click through to the merchant site after completing the e-bullion payment, the merchant system is never notified of the payment. All the other systems use a "status_url" system that notifies the merchant system as soon as the payment is completed, no matter what the customer does. Pecunix: You mention "The User has a passphrase as well as two "Private Identification Keys" (PIK)..." There are actually 3. One gives full access to the account, the second gives limited access, allowing payments up to a daily payment limit (set under full access) and no changes to the account details, and the third level gives read only access to the account. This could be useful for a bookkeeper or auditor to have access to account records etc. Pecunix is fully compatible with PGP *and* GPG :) The Pecunix "shopping cart" interface is the only one that implements an "input hash". This means that the merchant can ensure that the exact amount required is submitted for payment to his account. All the other systems require that the merchant check the amount received is correct, or an attacker could easily submit a payment that verifies correctly but is not the correct amount. Again, thanks for the excellent assessment. Sidd. --- You are currently subscribed to e-gold-list as: [EMAIL PROTECTED] To unsubscribe send a blank email to [EMAIL PROTECTED] Use e-gold's Secure Randomized Keyboard (SRK) when accessing your e-gold account(s) via the web and shopping cart interfaces to help thwart keystroke loggers and common viruses.
