The Gold Economy wrote:

> Part II of the article rating digital currencies on their payment
interfaces
> is now posted on The Gold Economy:
>
> http://www.goldeconomy.com/ct/t.php?l=12
>

Hello Ken,

Thanks for an excellent summary of the different systems and features...

As the pioneer of automation in the gold currencies,and as the
designer of the Pecunix system, I have a few comments.

<aside content="some history"> Some of you will remember that I was
the first person ever (back in 1998) to automate e-gold spends. There
was no e-gold automation interface, I designed a clever script that
actually "spoofed" the e-gold forms and logged in to complete the
spends as if it were a person. I remember Jim Ray telling me it
"could" not be done  and Jay telling me it "should" not be done :).
Soon after I did it, JP may did it for thegoldcasino.com. Once
automation was a reality the e-gold system started to grow... </aside>

Your assessment of the e-gold and GoldMoney systems seems accurate,
but there are a few places I disagree on the e-bullion and Pecunix
assessments.

First, e-bullion:
You mention "The e-Bullion Automated Transaction Interface Program
(ATIP) uses PGP/GPG keys to allow users to authenticate themselves to
the e-Bullion system"

This is unfortunately not true. The e-bullion system is absolutely
NOT compatible with PGP as it is currently implemented. The keys
generated by the e-bullion system are not PGP compatible.

Furthermore, you mention the fact that e-bullion generates the keys
as an "imperfection". This is a massive understatement! The fact that
the e-bullion system generates the keys goes against everything that
 public key cryptography stands for. It reveals a lack of
understanding by the designers of the system and leaves the e-bullion
system open to insider attacks. There are many other clues in the way
the e-bullion GPG is implemented that illustrate that the designers
of the system didn't really know what they were doing.

You also make mention of the e-bullion documentation. I disagree with
your assessment. The e-bullion documentation is poorly presented and
until I implemented the e-bullion interface a few weeks ago,
contained errors. Compare the Pecunix documentation at
http://pecunix.com/money.refined...ref.developer and the merchant
tools in the full access level of your Pecunix account.

One MAJOR shortcoming in the e-bullion merchant interface (not
manifested in any of the other currencies) is that there is no way to
 ensure verification of a "shopping cart" payment. If the user does
not click through to the merchant site after completing the e-bullion
payment, the merchant system is never notified of the payment. All
the other systems use a "status_url" system that notifies the
merchant system as soon as the payment is completed, no matter what
the customer does.

Pecunix:
You mention "The User has a passphrase as well as two
"Private Identification Keys" (PIK)..."

There are actually 3. One gives full access to the account, the
second gives limited access, allowing payments up to a daily payment
limit (set under full access) and no changes to the account details,
and the third level gives read only access to the account. This could
be useful for a bookkeeper or auditor to have access to account
records etc.

Pecunix is fully compatible with PGP *and* GPG :)

The Pecunix "shopping cart" interface is the only one that implements
an "input hash". This means that the merchant can ensure that the
exact amount required is submitted for payment to his account. All
the other systems require that the merchant check the amount received
is correct, or an attacker could easily submit a payment that
verifies correctly but is not the correct amount.

Again, thanks for the excellent assessment.

Sidd.



---
You are currently subscribed to e-gold-list as: [EMAIL PROTECTED]
To unsubscribe send a blank email to [EMAIL PROTECTED]

Use e-gold's Secure Randomized Keyboard (SRK) when accessing your e-gold account(s) 
via the web and shopping cart interfaces to help thwart keystroke loggers and common 
viruses.

Reply via email to