cypherpunks-legacy
Threads by month
- ----- 2026 -----
- July
- June
- May
- April
- March
- February
- January
- ----- 2025 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2017 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2016 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2015 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2014 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2013 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2012 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2011 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2010 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2009 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2008 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2007 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2006 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2005 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2004 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2003 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2002 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2001 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2000 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1999 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1998 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1997 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1996 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1995 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1994 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1993 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1992 -----
- December
- November
- October
- September
December 2003
- 8635 participants
- 56359 discussions
The Deviant <deviant(a)pooh-corner.com> writes:
> On Mon, 25 Nov 1996, Dana W. Albrecht wrote:
> > Rigorous proofs of the non-existence of an algorithm are not new.
> > Neither are rigorous proofs that any algorithm which can solve a given
> > problem requires a minimal running time. Or, in an even stronger sense,
>
> Hrmmm... I seem to see a problem (namely Moore's first law) in assigning
> anything a "minimal running time". Perhaps "minimal instruction count"
> would be more suited to your example. Because if you're talking about
> time, it essentially boils down to "the longer something takes the less
> time it takes".
>
> > that a particular known algorithm for a given problem is indeed a
> > (provably) optimal algorithm for that problem.
>
> Never happen. It just won't. As a rule, there's _always_ a faster way.
This is just simply not true. In fact, since you seem to have gracefully
failed to quote the section of my prior post which demonstrates otherwise,
let me re-iterate it:
> > For a (non-cryptographic) example of a proof of the first sort --- that
> > is, that "there exists no algorithm" --- consider the famous "Halting
> > Problem" for Turing machines. (I believe someone else has also
> > mentioned this.) There are many proofs such as this one, often related,
> > though the Halting Problem itself is perhaps the most famous example.
> >
> > For an (again, non-cryptographic) example of a proof of the second sort
> > --- that is, that "any algorithm that solves a given problem requires a
> > minimal running time" --- consider the proof that the "minimal" number
> > of key comparisons in the worst case required to sort a random list of
> > elements for which only an ordering relationship is known is O(nlog(n)).
> > See Knuth, Volume 3, section 5.3. For a simpler example, a standard
> > "binary" search which requires O(log(n)) comparisons to find a given
> > element in the worst case is provably the optimal algorithm for this
> > task.
Which part of this have you failed to understand? Look in section 5.3.1
of Volume 3 of "The Art of Computer Programming" by Knuth. You will find
there a rigorous proof that the "information theoretic lower bound" of
an algorithm which sorts by comparison of keys is O(nlg(n)).
Alternatively, refer to section 6.2.1 of the same book where it is
demonstrated that a binary search by comparison of keys on a sorted list
where no other information is available is an "optimum" algorithm.
If you wish to discuss this further, then you're going to have to directly
address what's widely known and beautifully articulated in Knuth.
> > Turning once again to cryptography, there is presumably an "optimal"
> > algorithm for factoring a "general" number in the "worst" case. Of
>
> Ok, now I have to pose a question: If cryptographers actually beleive
> this, why continue to search for a faster one.
That's easy. That an "optimum" factorization algorithm exists does not
mean it is _known_. Similarly, while one might demonstrate a mathematical
lower bound on the worst-case running times of all possible (known and
unknown) factorization algorithms, this does not mean that an actual
algorithm which runs in this time is known, nor does it even mean that
an actual algorithm which runs in this time even exists.
If you want a completely useless (but easy to prove) lower bound on the
number of operations a factorization algorithm must necessarily have,
I submit to you a trivial one: 1. Proof of this is left to the reader. :)
Proofs of more interesting lower bounds left to experienced mathematicians.
> > Turning once again to cryptography, there is presumably an "optimal"
> > algorithm for factoring a "general" number in the "worst" case. Of
> > course, known algorithms for factorization seem to regularly improve and
> > no one has even suggested that any current algorithm is (provably) the
> > "optimal" algorithm. Worse case bounds on running time for currently
> > known algorithms can certainly be produced, but no one currently knows
> > if these are the best algorithms.
>
> Again I say, there's _always_ a faster way.
No, there's not. While no proofs of useful lower bounds on factorization
algorithms are presently known, this does NOT mean that they do not exist.
That such proofs exist for other, simpler algorithms (see above) just
simply refutes this statement.
> > Obviously, discussion on this topic is unrelated to such security
> > problems as implementation mistakes, fault analysis, outright theft of
> > keys, etc. I hope that I've been careful to explain what I mean by
> > "provably secure" and that it's not interpreted to include these types
> > of attacks.
>
> Yes, I must commend you on your amazing tact in asking this incredebly
> irrevelant question.
You're welcome to think it's irrelevant. I, for one, am glad that people
like Matt Blaze took the trouble to do some work in this area. I'm also
grateful that this has been pointed out to me in response to my previous
post. (Thanks to "Mark M." <markm(a)voicenet.com>)
Dana W. Albrecht
dwa(a)corsair.com
1
0
At 05:34 AM 11/26/96 +0000, Tim Tartaglia wrote:
>
>Check out the following:
>http://www-tradoc.army.mil/dcsim/browser.htm
>
>Here's an excerpt:
>
>> ...Netscape has been working with NSA...Their proposed solution is based
>> on the use of Fortezza card technology. In November NSA expects to
>> certify Netscape Navigator 3.0 for "unclassified but sensitive" use...
The NSA has two main tasks: gathering [foreign] signals intelligence
("SIGINT") and making it difficult/impossible for other parties to get
signal intelligence from the US ("INFOSEC").
Given the context of the information you found, it looks like they're
negotiating with Netscape and Microsoft to evaluate the strength of their
browsers to that the browsers can be used for "unclassified but sensitive"
tasks; that is to say, NSA is operating in their "protect domestic data"
mode, not their "wiretap everything" mode.
Certifying the browsers (or other domestic privacy tools) as safe if
they're not (or if they've got designed-in weaknesses) would play a very
dangerous game - the NSA would gain little and risk a lot. They could (and
probably do, or will soon) mandate the use of GAK crypto for official
"sensitive" applications; so adding hidden weaknesses (which are
essentially stealth GAK) doesn't give them much they don't have already,
but it does create the potential that a third party will learn of the
hidden weakness (through careful study or exploiting a traitor or whatever)
and then have access to information the gov't would like to keep private
for an unknown period of time - followed by a sudden expensive & disruptive
switch of crypto tools when the discovery of the weakness became known.
So it seems unlikely that there's anything bad going on here; it doesn't
make much sense for the NSA (or other TLA) to intentionally weaken a crypto
app and then certify it as secure for government use. They want to keep the
good stuff for themselves, and make us use the weak software. They don't
seem to be especially shy about telling us when they want to spy on us.
I suppose it's possible to see government contracts as a foot in the door
to economic "incentivization", e.g., if Netscape and Microsoft want the
govt's money/approval badly enough, they'll switch over to the dark side.
But this danger is pretty much unavoidable; and the government's got enough
ways to coerce folks (cf. Jim Bidzos and the guys who want to run him over
in the parking lot) that this seems mild by comparison. If the government
chooses to apply some pressure to incentivize a corporation, they'll find a
way.
So far, it appears that they played fair when they certified DES as secure
- and folks on the outside have been banging away on DES for almost 20
years, without finding any trapdoors. The balance of risks suggests that
they'll probably keep playing fair when certifying privacy tools; not
because they're nice guys, but because it's in their best interests to do so.
--
Greg Broiles | US crypto export control policy in a nutshell:
gbroiles(a)netbox.com |
http://www.io.com/~gbroiles | Export jobs, not crypto.
|
1
0
I have started drafting a proposal statement for the Bounty server.
This is where I am at right now. I need as many comments on this
as to the way it will work as possible.
I am posting this from petro(a)smoke.suba.com because that is my
primary account rather than snow, which is only for cypherpunks. Sorry
for any killfiles this sneaks by.
Please reply to snow(a)smoke.suba.com or the list. Thanks.
Bounty Server, The proposal:
Version 0.1
Abstract:
This proposal is an attempt to outline a system for awarding cash
payments for the creation of new technologies without the overhead
or ownership associated with conventional systems such as contract
or work-for-hire, or employee-employer systems.
The objective is to actually bring this system online.
Background:
There is a lot of software floating around. It basically falls into
5 catagories: Commercial, Shareware, Freeware, Gnu (and other
"Copyleft" schemes) and Public Domain.
<Need to fill this in, but at this point we all know what the 5 types
are>
It is the "Copylefted" software that interests me at this point. There
is quite a bit of high quality "Gnu" software, and at least one
operating system based on the GNU mentality (linux) however there
is a dearth of _enduser_ tools such as mail and news readers for
the more popular end user operating systems, word processors and
graphics editing software, easy to use Graphic Design Software (TeX
is NOT easy to use) and easy to use Cryptographic software.
In order to get these kinds of tools, especially the Cryptographic
tools widely deployed, there needs to be a reason for someone to
invest the time and effort into polishing the user interfaces and
designing them for the average internet user to operate. Figuring
out new algorythms is fun. Being on the cutting edge, or flipping
the bird at Governments is fun. Doing something that has already
been done isn't nearly as sexy, yet to deploy the kinds of tools
we want _today_ and promote the development of the kings of tools
we will want tomorrow, there needs to be some sort of mechanism
in place to pay programmers to make these tools.
This mechanism (IMO) should be "market" driven, it should allow the
community of users to decide which projects should have priority,
and which shouldn't.
This mechanism should be as flexible as possible.
This mechanism should be as simple as possible, and as easy to use as
possible.
Originally I proposed this to apply to software, but I don't see why
it should stop at software. Initally the server will be restricted
to software, but I hope that this will work out, and be expanded
further.
The proposal:
What I am going to attempt to do is to set up a "Bounty Server" where
someone can iniate a "bounty" on a peice of technology. The initator
will write up a set of specifications for the technology, and an initial
award to be paid to the developer. They then post it on the server and
send their initial "bid" to the organization.
This is the "bounty". Other people can add to this bounty, allowing the
totals to add until someone claims that bounty by providing proof of
development to the initiator of the bounty. In software terms they would
upload the software to the server and notify the originator of the bounty,
and the server operators. Other technology will be figured out as it
becomes necessary.
Originally I was going to put the stipulation in that the software written
must be Copylefted. I decided that that wasn't really necessary, but
rather simply desired. To aid in that desire, I am going to build in
an initative to releaseing the software "copylefted".
To get more specific:
A bounty is considered to be posted when the initial payment is cleared
by the bank, and the specifications (discussed later are considered clear
enough to avoid interpretation problems.
The initial bounty contract gets posted to the WWW server, (possibly) to
a "developers list" of interested people, and (possibly) to an
appropriate UseNet Newsgroup.
Once the bounty is posted, other people can "bid up" or add to the bounty,
and their contribution will be added to the total bounty as well as their
"name" (email address) added to a list of contributors (unless they
request not to). The amount they gave will not be listed. It isn't
important. At this point contributions and initial bids will be
accepted by credit card, check, money order, and possibly ecash
(e-cash will be taken at some point, but it really isn't important
at this point since almost no one uses it.)
The first developer to upload a _working_ package to the server will
be awarded the total bounty, minus "brokerage" fees (discussed later)
"First" will be soley determined by the time stamp of the server. As soon
as the package is uploaded, the initiator and the server adminstrator
will be notifed, and the bounty marked "claimed". If the package is
accepted by the initiator, the bounty will be marked "closed", the
package moved to an FTP site for distribution (if Copylefted) or
moved offline if not (archived copies will be kept for legal reasons--
more on that later). At that point a check for the developer will
be cut (or ecash mailed if that works out).
The Server Adminstrator will also do an cursory check to make sure that
there are no obvious copyright violations.
In the event that there is a conflict between the initiator and the
developer, the claim will go into adjudication. The server adminstrators
decesion is final, and he will make every effort to settle the claim
fairly. Adjudication will incur an additional fee (see the fees section).
Writing the bounty:
The bounty specifications should include the following:
1) Target Operating Enviroment (i.e. Operating System for Software, and
whatever for other technology)
2) What the desired technology is intended to be used for (i.e. a
Word Processor, a Hardware RNG etc, whatever)
3) Desired Characteristics of the technology--specific features
of the technology. It isn't enough to say that you want a
word processor, you must specify minimum features you wish this
technology to contain (i.e. WYSIWYG, Postscript output, Outliner etc.)
4) Desired "quality" level: Proof of Concept, Alpha, Beta, Release etc.
5) Copyright status desired--whether the software will be owned by the
initiator of the bounty (in which case it is unlikely that anyone
else will contribute), owned by the programmer (well someone might
be that magnanomous), or "copylefted".
6) Where the initiators money is to go if the bounty is not claimed:
I will provide a short (8 or 10) list of charities that the money
will go to if the bounty is not met. This is to keep the initiator
honest, as well as the server. Each contributor will also get this
choice.
I am sure that I am missing something here, and I will need some
assistance in fleshing this out, as well as a couple of people to write
different specs as examples.
Adding to the bounty:
The bounty will be considered added to when the deposit clears and
is credited by the bank.
A person adding to the bounty will also be allowed to choose from the
list as to where they would like their money to go if the bounty
expires.
Fees:
The Organization will get 2% of any bounty where the software or
Technology that is copylefted. 20% of any other scheme.
Adjudication will incur an additional fee of 2 to 5% depending on the
difficulty in judging the claim.
All interest that acrues belongs to the Organization, and will be used
to defray any costs, or to provide for additional bounties should there
be an apprecialble excess.
Status:
At this point in time I am (obviously) still in the process of developing
the procedures. I have registered a Domain Name (bounty.org) and I have
a couple promises off assistance in certain areas. As well, I have
a server to start off with.
Where I need help at this point:
Legal issues. Any lawyers want to talk to me about this?
Comments.
I will be working on this, revising it, and soon I will be putting it up on
www.bounty.org.
Postmodernism is the refusal to think--Ron Carrier petro(a)suba.com
Deconstruction is the refusal to believe that anyone else can either.
Revolution and War are not murder unless you lose. This is a basic tenet
of civilization.--Jim Choate on the cpunks list.
1
0
Okay granted,i am virtually sure Deeyenda does not exhist,but i asked a simple question.
Altavista is a cute idea though ;)
Who posted this shit then,someone care to get back to him????
>The internet community has again been plagued by another virus.This message is being spread
>throughout the internet,including USENET posting,EMAIL and other inherent activities...The
>reason for all the attention is because of the nature of this virus and the potential security risks
>it makes.Instead of a destructive trojan virus (most viruses!),this virus,referred to as Deeyenda
>Maddick,performs a comprehensive search on your computer,looking for valuable information
>such as email and login,passwords,credit cards,personal info,etc. The Deeyenda virus also has
>the capability to stay memory resident whil running a host of applications and operating systems,
>such as Windows 3.11 and Windows 95.What this means to internet users is that when a login and
>PASSWORD are sent to the server,this virus can COPY this information and SEND IT OUT TO AN
>UNKNOWN ADDRESS (varies).
>The reson for this warning is because the Deeyenda virus is virtually undetectable.Once attacked
>your computer will be unsecure.Although it can attack any O/S,this virus is most likely to attack >those users viewing Java enhanced Web Pages (Netscape 2.0 + Microsoft Internet Explorer 3.0 +
>which are running on Windows 95) . Researchers at Princeton University have found this on a >number of world wide web pages and fear its spread.
> Please pass this on,for we must alert the general public at the security risks
>Steven K. Johnson
>Computer Center
>Carnegie Mellon University
>(412) 455-3756
>e-mail : SJohnson14(a)cmu.edu
Sounds like a pretty amazing virus to me??? More a crock of shit than anything else,but...
Hey maybe it'll run for president as well....
Sorry to inconvenience anybody,ridicule should have a purpose ;)
J a m e s
"Lead.Follow. Or get out of the way"
--------------------------------------------------------------------------------------------
Type Bits/KeyID Date User ID
pub 1024/9E318AA5 1996/09/24 Cracker <cracker(a)icon.co.za>
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: 2.6.3ia
mQCNAzJHdKwAAAEEALl3A6auLG0JLdtgEzl6KfPNqbTTSDX4L4To2b7PLqGDVV5r
BezC9dD/ITrCK9M64juiQ2p/DNjIihnXlEsJCy2btypStypQgU1fvAei3AnZ1cQ8
NiAnHNS+ImUAJgZjSHEQSevGE53IUovmWQ7YHUz9VpTTCtoJoUKxYuqeMYqlAAUR
tBxDcmFja2VyIDxjcmFja2VyQGljb24uY28uemE+iQCVAwUQMkd0rkKxYuqeMYql
AQEjagP/cYgGLAkWZJLeRcM4URwBX3J/0R54DadVnsvvoxDkzilv7U02IXZGZGnA
CvXsu2sThS7qDBiHFop/OZs3WmlQbQ4BAZ/hiCs5tSU2e7fkk0EKxsGAD1pTbw/J
rRU4WePLc++vv+6CBKw5NCSR5kMh8H3X4qtZZ9dYX9zsuzWKdpk=
=YGH8
-----END PGP PUBLIC KEY BLOCK-----
1
0
Okay granted,i am virtually sure Deeyenda does not exhist,but i asked a simple question.
Altavista is a cute idea though ;)
Who posted this shit then,someone care to get back to him????
>The internet community has again been plagued by another virus.This message is being spread
>throughout the internet,including USENET posting,EMAIL and other inherent activities...The
>reason for all the attention is because of the nature of this virus and the potential security risks
>it makes.Instead of a destructive trojan virus (most viruses!),this virus,referred to as Deeyenda
>Maddick,performs a comprehensive search on your computer,looking for valuable information
>such as email and login,passwords,credit cards,personal info,etc. The Deeyenda virus also has
>the capability to stay memory resident whil running a host of applications and operating systems,
>such as Windows 3.11 and Windows 95.What this means to internet users is that when a login and
>PASSWORD are sent to the server,this virus can COPY this information and SEND IT OUT TO AN
>UNKNOWN ADDRESS (varies).
>The reson for this warning is because the Deeyenda virus is virtually undetectable.Once attacked
>your computer will be unsecure.Although it can attack any O/S,this virus is most likely to attack >those users viewing Java enhanced Web Pages (Netscape 2.0 + Microsoft Internet Explorer 3.0 +
>which are running on Windows 95) . Researchers at Princeton University have found this on a >number of world wide web pages and fear its spread.
> Please pass this on,for we must alert the general public at the security risks
>Steven K. Johnson
>Computer Center
>Carnegie Mellon University
>(412) 455-3756
>e-mail : SJohnson14(a)cmu.edu
Sounds like a pretty amazing virus to me??? More a crock of shit than anything else,but...
Hey maybe it'll run for president as well....
Sorry to inconvenience anybody,ridicule should have a purpose ;)
J a m e s
"Lead.Follow. Or get out of the way"
--------------------------------------------------------------------------------------------
Type Bits/KeyID Date User ID
pub 1024/9E318AA5 1996/09/24 Cracker <cracker(a)icon.co.za>
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: 2.6.3ia
mQCNAzJHdKwAAAEEALl3A6auLG0JLdtgEzl6KfPNqbTTSDX4L4To2b7PLqGDVV5r
BezC9dD/ITrCK9M64juiQ2p/DNjIihnXlEsJCy2btypStypQgU1fvAei3AnZ1cQ8
NiAnHNS+ImUAJgZjSHEQSevGE53IUovmWQ7YHUz9VpTTCtoJoUKxYuqeMYqlAAUR
tBxDcmFja2VyIDxjcmFja2VyQGljb24uY28uemE+iQCVAwUQMkd0rkKxYuqeMYql
AQEjagP/cYgGLAkWZJLeRcM4URwBX3J/0R54DadVnsvvoxDkzilv7U02IXZGZGnA
CvXsu2sThS7qDBiHFop/OZs3WmlQbQ4BAZ/hiCs5tSU2e7fkk0EKxsGAD1pTbw/J
rRU4WePLc++vv+6CBKw5NCSR5kMh8H3X4qtZZ9dYX9zsuzWKdpk=
=YGH8
-----END PGP PUBLIC KEY BLOCK-----
1
0
> Steven Garman wrote:
> > Once method of combatting the spammers is to use disinformation. For example
> > we use new addresses for their "remove" lists to check on their honesty.
> >
> > What about attacking the lists themselves with false data? Say you run a site.
(snip)
Igor Chudov wrote:
> Another nutty idea: to create a database of people who do NOT want to
> receive unsolicited advertisements, and make it widely available.
Of course. But this does not address the issue of "unscrupulous
spammers" which is what Steven was commenting upon.
> The obvious problem is that some very uncsrupulous spammers would want
> to grab this database and use it as a source of email addresses.
>
> This problem has a solution, however: instead of distributing people's
> email addresses, distribute MD5 checksums of their addresses. For
> example, an entry for ichudov(a)algebra.com would be
>
> b51175dae78f25427351d5e3ff43de30
>
> There is no way to guess the original text from an MD5 checksum.
>
> Spammers should be advised to exclude all addresses with MD5 checksums from
> that database from the recipient list, and include instructions on how
> to get one added to the database into their spams.
Okay fine. The spammer is "advised" but if he is unscrupulous in the
first place, he'll simply ignore the advice and continue bulk-mailing
to every address he can grab.
> Database maintainers could even provide a email filter-bot that would
> accept recipient lists by email and send back the same lists, but
> WITHOUT addresses that wish not to receive spam. This way stupid
> low-tech spammers (who make up the majority) will be able to process
> their email lists quickly and easily.
Indeed, stupid low-tech spammers would benefit from such a service if
they wish to honor "do not send" requests.
> This database may be maintained centrally. Users may be able to sign up
> for inclusion into that database by email or by filling out a Web-based
> form. Identity verifications may be done by using cookie protocol.
I like the idea and if I had the resources, I would do it personally.
Optimistically, many bulk e-mailers would sign on to the plan.
(Ironically, one would probably have to solicit bulk e-mailers to
sign up). However, many, being unscrupulous, ignorant, etc. will not
be involved.
The only way I see to get bulk e-mailers to utilize this service is
to offer a positive and/or negative incentive for usage of the
service. ie. "What do I gain by elminating people from my bulk
mail-outs? What can be done if I don't follow this protocol?"
Ideas? Comments?
me
--------------------------------------------------------------
Omegaman <mailto:omega@bigeasy.com>
PGP Key fingerprint = 6D 31 C3 00 77 8C D1 C2
59 0A 01 E3 AF 81 94 63
Send a message with the text "get key" in the
"Subject:" field to get a copy of my public key.
--------------------------------------------------------------
3
3
Dana W. Albrecht originally wrote:
> Rigorous proofs of the non-existence of an algorithm are not new.
> Neither are rigorous proofs that any algorithm which can solve a given
> problem requires a minimal running time. Or, in an even stronger sense,
> For a (non-cryptographic) example of a proof of the first sort --- that
> is, that "there exists no algorithm" --- consider the famous "Halting
> Problem" for Turing machines. (I believe someone else has also
> mentioned this.) There are many proofs such as this one, often related,
> though the Halting Problem itself is perhaps the most famous example.
>
> For an (again, non-cryptographic) example of a proof of the second sort
> --- that is, that "any algorithm that solves a given problem requires a
> minimal running time" --- consider the proof that the "minimal" number
> of key comparisons in the worst case required to sort a random list of
> elements for which only an ordering relationship is known is O(nlog(n)).
> See Knuth, Volume 3, section 5.3. For a simpler example, a standard
> "binary" search which requires O(log(n)) comparisons to find a given
> element in the worst case is provably the optimal algorithm for this
> task.
Dana W. Albrecht (dwa(a)corsair.com) replies to
The Deviant <deviant(a)pooh-corner.com> like this:
> Which part of this have you failed to understand? Look in section 5.3.1
> of Volume 3 of "The Art of Computer Programming" by Knuth. You will find
> there a rigorous proof that the "information theoretic lower bound" of
> an algorithm which sorts by comparison of keys is O(nlg(n)).
That is a bound on a _reliable_ algorithm. A faster one is to shuffle
the elements and present it as sorted. Lightning fast, but only with
low probability of correctness. That is what we are up against in a key
search attack. The other guy just might guess my 100 bit key first time,
millionth time or whatever - early enough anyway.
So to get a lower bound you have to show that a lucky guess cannot be
distinguished from an unlucky one - and if you do that without a one
time pad I take my hat off.
-- Peter Allan peter.allan(a)aeat.co.uk
1
0
oh mindless aga,
>> This betrays your ignorance. I.Q. is scaled according to age. One does
>> not "improve."
Certainly not in your case.
>
>I have no ignorance, except for being ignorant of stupid people
>who call themselves "punks."
If you are ignorant of them, then how do you know that they are "stupid"?
>Look asshole; it says "LAW DOCTOR" -- that is what "Juris Doctor"
>means, stupid. And I am about to stick the motherfucking Laws
>right up your cocksucking ASS!
How is this possible? It seems that you are possible of rather contemptible contortions!
>"Juris" means Law. So Juris Doctor means "Law Doctor."
Clinging to technicalities here, aren't we?
>that is irrelevant, and you are off-topic.
Oooh! Oooh! Point the finger here, aga, at YOURSELF!
>Europe is also irrelevant, and you keep missing the point here.
>You have added the cypherpunks list again, and that was forbidden.
What a wonderful statement: Europe is irrelevant!!! A truly educated mind here.
>look asshole, you really want that list killed, do you not?
>I have no bounds, as you will soon learn.
When one is clapped in irons and thrown into prison for whatever it is that your acts can be classified under, then I am pretty sure they have _some_ bounds.
>> > > Be careful who you threaten. It might get you in trouble.
One wonders if you ever pay attention to what you actually write, aga?
>WRONG! There is NO crime which covers anything that one does
>internationally! And mailbombing is NOT "Unauthorized access,"
>regardless of where it occurs!
Uhm...oops, aga, you're wrong here, there are plenty of crimes that are international crimes. War crimes for example, which o against the Geneva convention. Child abduction crimes, which go against the Hague convention. But I am sure they will give you a slight slap on the wrist, after all, you are only a stupid hillbilly with no idea of the law.
>Pitt-1975; Dissertation was in 1983 actions. I practiced for
>six years, and then became perfect. I currently do not practice for
>any parties other than myself, family, corporation or Institutes,
>and I need no license for that. And since I do not carry any
>license from any State, there is NOTHING that you can do to stop me.
Assassination comes to mind...
>The State disciplinary board has no jurisdiction, nor does any
>Law. A Criminal Lawyer is a specialist in ripping new assholes
>on the witness stand, and that must now also be practiced on the net,
>it seems. Remember, you are the one who asked for this, "Sadam."
You seem to have this absolute _fascination_ with asses, faggots, cocks, and ripping _new_ assholes (as if you weren't a big enough one already. This is obviously some sort of concious repression: you just can't face the truth, can you, aga?
>This is a world-wide internet problem that you are about to get
>taken care of. You will be among the first locations to be
>eliminated. And just remember that your termination is your own
>doing. You had your chance to keep the fucking cypherpunks list
>OFF of your e-mail to me, and blew it.
Do we run and hide now, mommy?
>> I suggest a hobby which entails more physical activity.
>>
>
>I pump iron and run three times a week. And as a Tae Kwon Do
>black belt holder, I get lots of physical activity. I am in
>better physical shape than any other man that you know.
He/she/it pumps iron, does he/she/it? Whilst running? No mean feat for a thing without a brain. Assuming that you are better than anyone else you have probably never met, someone who probably has no desire to meet a thing like yourself, is yet another example of your sheer assonance!
>And just understand, as far as the internet is concerned, Europe does
>not mean SHIT!
Of course not...I am sure the European Internet thinks the same as you. After all, an inanimate object seems to think just as much as you!
--The Edge
1
0
Forbes: December 2, 1996
Cyberpower
By Peter Huber
James Carville once wisecracked that he wanted to be reincarnated as the
bond market. What did he mean by that? He meant that modern,
electronically connected markets are more powerful than any politician.
To
put it another way: The modem is redefining democracy.
British Telecom timed its announcement perfectly--on the eve of the
election.
Think of BT's $20 billion merger with MCI as an antidote to bad
government. By providing efficient, integrated global data connections,
telecommunication companies now offer voters the ultimate shopping
experience: shopping for better government.
Travel the wires and see what I mean. To a degree that may astound you,
your computer and your telephone enable you to choose what you like in
the
way of Federal Reserve, FDIC, SEC, FDA, OSHA, EEOC, NLRB or
other cans in the alphabet soup aisles of modern regulation.
The idea of choosing government is not, of course, new. If you don't like
California law on the subject, you drive to Reno for marriage, divorce or
gambling. To Mexico to buy cut-rate medicines unapproved in the U.S. To
Florida to go bankrupt or to die. The urge to take a political hike has
been
there all along. What has changed is the ease and convenience.
In the past you had to vote with your feet. Now you can vote with your
modem, too. The Web supplies an instant global storefront. While the U.S.
market still dominates the Internet, 36% of servers are now outside this
country. Virtual establishments on the Web already offer incorporation in
Belize, bank accounts in Switzerland, currency trading in Germany,
brokerage accounts in New Zealand. International 800 numbers are
proliferating.
Money, the most liquid of assets, has become the hardest to regulate.
Rich
people have always parked their money abroad when they didn't trust the
political climate at home. Today millions of ordinary investors can move
their
wealth between currencies and countries as fast as they can click icons
on a
screen.
For some this is just an opportunity to cheat on their taxes. A Hamburg
currency trader promises "tax-free profits." A Swiss on-line banker
emphasizes "banking secrecy" and "protecting the privacy of bank
clients."
Swiss safe deposit boxes, the bank assures you, "cannot be sealed by
foreign
authorities in case of civil offenses." Other on-line offshore entities
brazenly
tout "tax-free" advantages for U.S. depositors.
But evading tax collectors remains a sideshow in the vast business of
international, wired finance. The center of the action involves the
completely
legal evasion of inept central bankers. More than $1 trillion in foreign
exchange changes hands each day around the world. (By comparison,
turnover of all stocks on the New York Stock Exchange for an entire year
is
only around $4 trillion.) One in seven equity trades in today's world
involves
a foreigner as a counterparty. And even illiquid assets--real estate, for
example--are increasingly being securitized and then traded on global
markets.
As Walter Wriston, former Citicorp chief executive and author of The
Twilight of Sovereignty (Charles Scribner's Sons, 1992), says:
"Governments
have lost control of the international value of their currency." A single
integrated world market for tradable financial assets is taking shape.
Lowell
Bryan and Diana Farrell of McKinsey & Co. describe this evolution in
Market Unbound: Unleashing Global Capitalism (John Wiley & Sons, 1996).
The upshot? The prudent investor can now select investments based on the
central bankers standing behind them, just as he now chooses a stock
based
on his appraisal of the chief executive officer. Do you think the German
central bank is wavering? Try Alan Greenspan. If you think he is on the
wrong track, try New Zealand. Global mutual funds have limitless ability
to
move capital among local, state, national and international
portfolios--equity,
debt, currencies, futures, the lot. By far the most effective way to vote
against
new government spending is to buy some other government's bonds. This
kind of balloting is in fact conducted continually--by banks, pension
funds
and mutual funds. These are the new, private treasuries.
By dispatching its capital elsewhere, the electorate can almost instantly
depress the economy and thus the government's tax revenues. For any
government that's seriously in debt, the globalization of financial
markets puts
a double squeeze on new discretionary spending. If global capitalists
lose
faith and drive up interest rates, it isn't just new spending that costs
more,
it's
also the refinancing of old debt. The modemization of finance explains
the
federal government's mass conversion to more balanced budgets.
As Bryan and Farrell discuss in their book, the tremendous new mobility
of
private capital sharply curtails government power over macroeconomic
policy. Budget planners and central bankers become little more than fancy
bookkeepers. They don't orchestrate economic forces, they react to them.
Whether they talk left or right, governments worldwide have little choice
but
to abandon fiscally suicidal policies, most notably the practice of
issuing
long-term debt to finance current entitlements. Improvident governments
that
don't believe this end up like Mexico in 1995, with a collapsing peso and
an
overnight flight of capital. Even Washington's wisest understand the new
reality. "I used to think if there was reincarnation I wanted to come
back as
the President, the Pope or a .400 baseball hitter," Clinton adviser James
Carville quipped two years ago. "But now I want to come back as the bond
market. You can intimidate everybody."
Including, of course, government regulators. Wires are imposing a strict
new
discipline on the regulators of private banks, too. At a recent Cato
Institute
conference on the future of money, University of Georgia economist
Lawrence H. White described how new payment technologies have lowered
the cost of wiring money from $20 to 2 cents per transaction. This opens
up
the world of offshore banking to small investors--and it's all perfectly
legal,
so
long as you keep paying your income taxes. Offshore banks pay higher
interest on deposits and charge lower rates on loans because they aren't
subject to the wide array of bank taxes, mandatory insurance premiums and
antiredlining decrees imposed by U.S. regulators. For the first time,
small
depositors can decide for themselves whether the Federal Deposit
Insurance
Corp. is really worth the price they pay in less favorable interest
rates.
Securities regulation can now easily be circumvented in much the same
way.
With stock exchanges and brokerage accounts moving on-line, you can hold
and trade U.S. equities completely outside U.S. jurisdiction. If the
Securities
& Exchange Commission goes over the edge of the regulatory Laffer
Curve--by passing rules that stifle rather than protect--investors will
easily
be
able to move to a Swiss broker, a London exchange or a Canadian
commodities trader. The value of regulation, positive or negative,
becomes
something you shop around for, just as you shop for a trusty broker or
low
trading fees.
Labor will never be as fluid as capital, but does follow it. The 1980s
taught
us that manufacturing jobs could escape U.S. unions, labor laws, tort
lawyers
and environmental regulators much more easily than we had realized. The
aluminum still comes from an Alcoa mill in the U.S., but some 20% of the
Boeing 777 airframe structure is built by Japanese workers at a
Kawasaki/Mitsubishi/Fuji consortium. The wings and the cockpit of
McDonnell Douglas' MD-95 are being built in South Korea.
To be sure, most U.S. jobs, particularly the services that account for
54% of
the U.S. economy, are still in nontradable sectors. If you live in
Fresno, you
can't easily get a haircut from a coiffeur in France. But services do
already
make up over 20% of global trade, and they represent the fastest-growing
component of both trade and foreign direct investment worldwide. American
companies outsource data entry to countries in the Caribbean.
Manufacturers
outsource product design, logistics management, R&D and customer service
across national borders, too. U.S. insurance, tax consulting and
accounting
companies send claims and forms overseas for processing. Software, films,
music, finance, advertising, and even health care and education all move
as
well. Haircuts? Not yet, but there's already serious talk of
telemedicine.
The Boeing way of choosing labor is now embedded in the structure of some
39,000 large, transnational corporations, which collectively hold over
$2.7
trillion of assets outside their home-base countries. New foreign direct
investment in the 26 nations in the Organization for Economic Cooperation
&
Development rose by 53% in 1995, while outflows from these countries
increased by 42%. (For cross-border holdings of tradable securities, see
chart, p. 146.) "The very phrase `international trade' has begun to sound
obsolete," Wriston says in an interview.
Again, information and communications technologies are the critical new
lubricant. Many services, especially financial and anything involving
software,
consist of nothing but information and can be moved by wire alone. Moving
solid goods still requires cheap transportation, too, but the cost of
hauling
things around keeps dropping, energy costs notwithstanding. And many of
the products being hauled--everything from cameras to cars--keep getting
smaller and lighter as they get electronically smarter.
Once a manager in Detroit learns how to use the telecosm to outsource to
Toledo, Ohio, she can outsource to Toledo, Spain; with cyber power all
physical distances are roughly the same. And with this kind of global
production system in place, a manufacturing company can move jobs and
capital around like pieces on a chessboard, shopping continually for the
best-priced labor--and the best labor laws. As Norman Macrae, former
deputy editor of the Economist, foresaw some years ago, corporations of
the
future are not going to be nationally based, and they "aren't going to
have
long-lasting lines of production in settled places." Their managers will
be able
to move jobs almost as fast as governments can rewrite employment laws.
At
the margin, the managers of these transnational companies will adjust
their
portfolios of labor in much the same way as the manager of the Templeton
Growth Fund trades stocks.
So where does the globalization of labor markets leave the countless
national
regulators of employment and work? Whatever they address-- parental
leave, handicaps or the minimum wage--laws that deny economic reality
cannot be enforced if the jobs can pick up and leave. Much as they hate
the
fact, government bureaucrats are beginning to accept it. Yes, Washington
did
recently raise the minimum wage, but the real story there was how little
and
how late. The long-term global political trend is away from all such
dictates,
not toward them.
When she thinks of herself as "labor" the average American citizen may
not
like this at all. But as a consumer she's collaborating enthusiastically.
She
buys Nikes and Nintendos made in Asian factories. She demands profit from
her mutual fund and pension plan, not patriotic loss. Before long, she'll
shop
for life insurance in London and health insurance in Geneva, and the
offshore
actuaries will discriminate fiercely in favor of the healthy. In the
1980s the
chief executive of Chrysler might have decided to buy a few million car
engines from Korea. Today millions of individual Americans are gaining
the
power to shop anywhere they please. No longer can consumers, any more
than investors or corporate managers, be economically quarantined.
This means that consumer protection regulators face serious competition.
An
abortion now comes in a pill; there's little to stop you from buying that
from
an on-line pharmacy in Monaco if you have to. For years the FDA blocked
sales of kits that allowed home testing for the AIDS virus. So a South
African
company peddled a $100 kit on the Internet, with delivery by mail. And
the
owner boasted openly that he was in business to thwart the regulators
overseas.
The daughter of a magazine editor I know needed a special asthma drug
that
the Food & Drug Administration hasn't yet seen fit to approve. Her dad
E-mailed a contact in Paris, and the medicine arrived by air several days
later. He would not have bought a drug from China or Belize, but he was
willing to trust France. The world's drug regulators, in short, compete
for his
custom. A wide range of routine diagnostic services could easily be
offered
to U.S. citizens from laboratories in Bermuda. The Web would handle
marketing and payment. Federal Express would deliver.
What holds for lab tests holds for morals and culture, too. Nevada can
dispatch strip shows and blackjack tables to any computer in Utah. If we
shut down Nevada, gaming houses farther afield will quickly fill the
electronic
void. A two-minute Web search turns up the Aruba Palms, off the coast of
Venezuela. Download free software and link into the hotel's casino for
real-time blackjack, poker and slots, as well as full sports-book action.
Or
try out any of a dozen on-line gambling alternatives in Argentina,
Belize,
Antigua or the U.K. Or play the national lottery of Liechtenstein. Use
your
credit card, or use E-cash if you want to make both gains and losses
completely anonymous.
When it comes to pure content regulation--pornography the most vivid
example--government authorities have lost their grip completely. If you
don't
like Utah's censors, three clicks of a mouse will put you under the
unbuttoned
authority of Utrecht. Canada has instructed its citizens not to watch too
much
U.S. television. But it's laughably easy now for Canadians to buy a small
satellite dish and get subscription fees billed to a nominally U.S.
address.
Technology has rendered completely obsolete the very idea that government
authorities can control morality and culture. Politicians may still give
speeches
about these things, but everyone knows the talk is just reactionary
twaddle.
All of this should be very reassuring. Most of us won't leave the
country, not
in person and not by wire. We won't have to. Competition improves the
quality of everything else; it will improve the quality of government,
too. Most
politicians are pragmatists. They'll grasp that they have to deliver a
good
service at an attractive price--or lose market share to the competition.
Bill
Clinton understands this. Like James Carville, he learned that the bond
market runs the most powerful polls of all. Clinton ran as a budget
conservative.
The trend is already clear in monetary and fiscal matters, where the
competition for good government is the fiercest. Many of the abrupt
currency
swings of yesteryear--overnight devaluations, for example--just don't
happen
as much anymore. Wired financial markets are less volatile and much more
honest. Nearly all industrial countries have brought their annual
inflation
rates
under 3%. In The Death of Inflation: Surviving & Thriving in the Zero Era
(Nicholas Brealey Publishing, 1996), Roger Bootle argues that the
globalization of financial and labor markets left them no choice.
Within this country, large states like California seem to be learning the
same
lesson. They have to stay in line on tax rates, investment climate and so
forth--or lose jobs, investment and residents to their better-governed
neighbors. And while rigorous comparisons are difficult, it does appear
that
industrialized nations are gradually converging toward quite similar
regulatory
structures in monetary policy, banking, insurance and securities trading.
The
overall price that competing governments charge citizens for service--the
tax
rate--seems to be converging, too. Take away health insurance, which some
countries book as "private" rather than "public," and you find that the
tax
rates in industrialized countries are all quite close--much more so than
they
were in the 1960s.
Governments that don't keep up with the competition can lose market share
fast. Years ago Delaware developed a well-designed service called
corporate law. Most big U.S. companies are Delaware corporations now.
Other states tried to protect their consumers from high interest rates.
So
Citibank set up operations in South Dakota to issue credit cards
nationally. In
June the Supreme Court ruled that California residents may not challenge
Citibank's late-payment fees as usurious under California law: The fees
on
Citibank cards are South Dakota's legal responsibility. The usury police
in
other states can all take a permanent vacation.
We, the people, are all shipping tycoons now, with mobile wealth and
mobile
labor. We can choose Liberia's flag, for its unmeddlesome bureaucracy, or
London's insurance, for its trustworthy courts. As managers, workers and
consumers, we buy government in much the same way we buy shoes. Not
through bribes or political action committees or anything like that--we
buy it
by paying taxes and complying with the laws. But when shopping in one
government's mall gets too expensive or inconvenient, we shop in
another's.
So the old political carnival, filled as it was with freaks and geeks, is
over.
The old game of big promises on election day, soon forgotten in the
enjoyment of power, is over. Citizens now vote continually, with London,
Bonn and Tokyo on the ballot, too.
1
0
American Banker: Friday, November 22, 1996
MasterCard Raps Visa Security After Theft
By JEREMY QUITTNER
The theft of a personal computer with several hundred thousand credit
card
accounts stored in its memory has led MasterCard to suggest the security
procedures of rival Visa are inadequate. The computer, stolen from Visa's
San Mateo, Calif., data processing center early this month, contained
information transmitted from point of sale machines for 314,000 active
credit
card accounts -- from Visa, MasterCard, American Express, Discover, and
Citicorp's Diners Club.
Visa has offered to pay $20 per account, potentially $6.3 million, to
replace
the cards.
Although the five brands reacted quickly to the crime, and there has been
no
loss due to fraud, the incident shows how account information is
vulnerable to
fraud and theft from many directions.
Michael Stenger, special agent, financial crimes division for the U.S.
Secret
Service, said criminals will go after account information wherever they
can
find it.
"The computer is seen as a facilitator and a storage point," he said.
"The main
thing is (the thieves) need the information."
Account information from the different credit card networks is commonly
routed through MasterCard and Visa processing systems from point of sale
machines, and sent to the appropriate party.
"The question is, why was the information downloaded?" asked MasterCard
spokesman Sean Healy. "We don't do that type of downloading."
He said MasterCard stores point of sale information on cartridges in high
security locations in its St. Louis processing facility, where it would
be
"virtually impossible to replicate" the Visa theft.
However, David Melancon, a Visa International spokesman, contended,
"Any card company that processes transactions" downloads account
information.
Jerome Svigals, a smart-card and security consultant in Redwood City,
Calif., said Visa would have downloaded this information only if it was
working in the capacity of Vital Processing Services, its merchant
processing
arm.
He added the computer probably contained magnetic stripe information,
such
as account numbers, expiration dates, and encrypted verification codes.
"There is little or no protection against this problem," he said.
Visa said it may have been an inside job, although no one has been
arrested.
The thief or thieves were probably more interested in the computer
hardware
than the account information, Visa said.
"We have had rigorous plant security, but obviously not secure enough,"
Mr.
Melancon added.
Visa, which said the vast majority of affected accounts were its own,
said it
immediately contacted all the parties involved and recommended they get
in
touch with cardholders.
Mr. Healy said the stolen computer contained information on accounts at
500
of MasterCard's member banks.
"We are recommending they close the affected accounts and issue new
cards," Mr. Healy said. "We are monitoring authorizations very closely
and
have issued a worldwide security alert."
American Express, on the other hand, has chosen to monitor its own
accounts without informing cardholders. It would not specify how many of
its
accounts were involved.
"The accounts are being monitored for fraud, but we have not found any,"
said Gail Wasserman, an American Express spokeswoman.
Diners Club and Dean Witter, Discover & Co. said they were taking
measures to protect their cardholders.
American Banker: Friday, November 22, 1996
Bank Group Issues Guidelines for Protecting Consumer
Privacy
By Barbara A. Rehm
Retail bankers on Thursday unveiled a nine-point plan to safeguard
financial
information about their customers.
The Consumer Bankers Association is providing the privacy blueprint to
its
members, 900 financial institutions with more than $2.5 trillion in
assets.
"We are confident that these guidelines will enable our members to
continue
delivering top-quality service and choice while maintaining the trust of
consumers," said Pam Flaherty, Citibank senior vice president and a
member of trade group's board.
The guidelines, in the works for two years, are designed to help banks
maintain customer confidentiality standards even as new technologies
speed
information processing.
For example, under the plan, banks "will limit the use and collection of
information about our customers to what is necessary to administer our
business, provide superior service, and offer opportunities that we think
will
be of interest to them."
The blueprint also notes that banks will provide data about their
customers
only to "reputable information reporting agencies."
The Consumer Bankers issued the privacy guidelines to show the federal
government that the banking industry is policing itself and no new
regulations
are needed.
American Banker: Friday, November 22, 1996
Get On-Line Quickly or Get Left Behind
By JENNIFER KINGSON BLOOM and JEFFREY KUTLER
Almost 600 people paid a quick visit this week to a future in which most
consumers carry smart cards, do most of their banking and shopping on the
Internet, and rest assured that their financial institutions have taken
all
necessary steps to ensure payment security and personal privacy.
By now the bankers among the 600 have returned to a reality in which most
chief executive officers don't know much about personal computers, pay
more attention to commercial loan spreads and credit card profitability
than
to information technology, and still need convincing to pour a lot of
investment capital into creating the aforementioned future.
The vision of the possible appeared at American Banker's second annual
conference on financial services in cyberspace. After three days of
almost
boundless enthusiasm for electronic cash and virtual banking, these
concepts
didn't sound futuristic at all.
Stirring up a revival-meeting atmosphere, Mondex USA chairman Dudley
Nigg referred to Internet banking as "the Holy Grail." But no longer does
he
consider it beyond bankers' grasp. Giving the opening speech Monday, the
Wells Fargo Bank executive vice president decried the industry's past sin
of
"giving away the branch channel for free and charging for on-line service
...
How ludicrous!"
After Wells saw the light and dropped its fees for PC users, on-line
customers jumped from 20,000 in early 1995 to 270,000 today -- 110,000
of them via the Internet. Mr. Nigg expects two million Internet customers
in
five years.
It provides an unusual opening, he said, to "satisfy customer needs
(while) we
lower our costs ... That's the kind of economics that chairmen in our
industry
love to hear about, and is rare in banking. Rare is the channel where
costs
can be driven down."
Mr. Nigg, speaking the same day MasterCard announced its acquisition of
51% of Mondex International, a smart card program he fervently supports,
lived up to his keynote billing with the conference's most quotable
quote: "If
we don't get aboard this train early, we will miss it."
He said technology is advancing so quickly and decisively that bankers no
longer have the luxury of waiting for lower prices or more definitive
outcomes
before making a move.
"If we regard this as purely hype, we will forfeit this opportunity to
others
who are waiting in the wings," Mr. Nigg said. "We have traditionally been
slow to step up. In the past, second-movers had an opportunity to meet
the
train. Today, people are waiting for us to act. If we don't do so,
somebody
else will step in and take our place."
"Don't do nothing, waiting to see if Internet commerce is real," said
Verifone
Inc. vice president Roger Bertman, picking up the theme two days later
when
discussing bank-merchant relationships. "It is absolutely clear you will
miss an
opportunity and risk losing pieces of your merchant portfolios."
The Internet and personal financial management software like Intuit
Inc.'s
Quicken are "wedges driving financial services into the home," said Adam
Schoenfeld, vice president of publishing at Jupiter Communications in New
York.
Though many attempts at electronic financial services were "poorly
conceived
and executed," he said, banks are serving two million customers by PC,
and
more than three times that number express interest in the medium,
according
to a recent Jupiter-Find/SVP study.
Veterans of earlier, unsuccessful attempts at revolutionizing banking
behavior
like to bat around ideas on why the 1990s are different.
One obvious reason is the breakneck spread of personal computers into
consumers' homes. Huntington Bancshares senior vice president William
Randle, a conference co-chairman, cited an October survey that said 19
million U.S. households now use home computers for some aspect of
financial management.
He also showed a commercial that touted the home banking capabilities of
Packard Bell's products. "When manufacturers of computers start
advertising
banking as an application, times are moving fast," he concluded.
There were other ideas as well. Gaurang Desai, a vice president at
Montgomery Securities, said vendors and bankers are growing more
comfortable with one another and are working together more productively.
Henry Lichstein, a vice president and technology strategist at Citibank,
said
banks are learning how to market on-line services so they are attractive
to
consumers.
Pointing out that Citibank has offered home banking for a decade, he said
the
program began "in earnest" last year when the bank stopped charging for
it.
In 1996, Mr. Lichstein said, "the big change was the Internet."
And David Frankel, banking business manager at the Prodigy on-line
service,
recalled that when his company introduced on-line banking in 1988, it
fell flat.
Prodigy has spent the last eight months reconstructing its service for
the
Internet. "People are moving to the Internet directly at almost alarming
speed," Mr. Frankel said. "We have recognized the future of the Internet
and
the ultimate demise of proprietary on-line services."
Several speakers predicted that the introduction this year of television
sets
with Web browsers will jump-start home banking for the mass of consumers.
In the Jupiter Communications survey, 25% of households with personal
computers said they "would prefer to get their electronic financial
services
through the television," said Mr. Schoenfeld.
Mr. Lichstein defined the task at hand -- "the process of anticipating
change
and aligning oneself to it" -- as "finding the strategic groove."
Something is in a strategic groove, he said, when "if we do not step up
to the
challenge, someone else will." By that definition, Mr. Nigg was
describing
strategic grooves for the Internet and smart cards, particularly Mondex,
which can operate as both a real-world cash substitute and a
virtual-world
payment transmission device.
Mr. Lichstein put smart cards and consumer electronic banking in that
very
context. "The strategic groove in home banking," he said, "is in full
swing."
Critical or dissenting voices were pretty much drowned out. Charlotte
Wingfield, a KPMG Peat Marwick partner, said she got a respectful
reception to what she called the only presentation covering the biggest
mode
of banking distribution -- the branch.
Citing a consumer survey KPMG commissioned from Yankelovich Partners,
Ms. Wingfield concluded that "the branch's demise is greatly
exaggerated."
Her data indicated that even frequent PC users put "banking in person"
ahead
of software-based services on their list of preferences.
Agreeing with Ms. Wingfield, a member of the audience who works for a
technology company grumbled about the pro-virtual majority. "They make it
sound like everybody has to be on the Internet by next Tuesday, or
they're
toast. That just isn't the case."
Even a bank executive from the Northeast who is well versed in the
Internet
and intranets said, "I think it's all hype."
In one session that devolved into a small-scale cat fight among software
vendors, a Microsoft Corp. executive was trying to take the high road:
Other
purveyors of personal financial management software divulged the number
of
users they had doing on-line banking, but he wasn't going to play the
numbers
game.
A representative of Intuit said 400,000 people were banking on-line
through
Quicken and BankNow. The chief executive of Meca Software said he had
200,000 active users.
When Microsoft's turn came, Richard Bray, a product manager, kept
insisting that 10% of Microsoft Money users were doing on-line banking.
When pressed for specific numbers, he would go no further.
Unluckily for Mr. Bray, he was also scheduled to speak again later in the
day
about the Microsoft Network for the Internet. It was in that speech that
he
casually said: "Two and a half million people use Microsoft Money."
And 10% of 2.5 million would be ... William N. Melton, founder and
president of Cybercash Inc., was torn within himself. He took a break
from
the American Banker conference to fly to the giant Comdex computer trade
show in Las Vegas and returned with what he termed a "manic-depressive
problem."
When he first arrived in Scottsdale, he became "manic" when he learned
that
the bankers there had apparently gotten religion on the subject of the
Internet.
"We've been trying to talk to bankers for a long time, and said, 'The
Internet
is really here,"' he said. "I didn't think they were really getting it."
After jetting off to Comdex, though, he became "depressed" that while the
250,000 people attending the show were "all doing nothing but thinking
about
the Internet," they didn't seem to be moving quickly enough toward
on-line
commerce.
"We've been working on SET (the Secure Electronic Transactions protocol)
for one to one and a half years, and hopefully within six months we'll
have
interoperability tests," Mr. Melton said with some disdain.
After returning to Arizona, Mr. Melton swung back to manic mode. Hearing
details about MasterCard's buy into Mondex persuaded him that "maybe it's
going to happen."
Mr. Melton was emphatic about what was needed to help make "it" happen:
he called on banks to "unilaterally issue digital certificates" to get
customers
accustomed to on-line commerce and comfortable with evolving privacy and
security measures.
Mr. Melton and Mr. Bertman, general manager of the Internet commerce
division at Verifone (another company Mr. Melton founded), acknowledged
some other impediments or potential obstacles.
"By 2000, the privacy issue will have really hit," Mr. Melton predicted.
He
said the negative consequences of such an explosive political issue could
be
mitigated by banks' convincing the public they have addressed it. But he
warned of "a huge public debate."
Mr. Bertman said the industry must help consumers and merchants make
sense of a dizzying array of payment methods and options. Verifone and
Cybercash, among others, have proposed "virtual wallets" as a solution.
"Technologists tend to oversimplify the payments world," he said, "but
there
are some very complex issues" that financial institutions are best placed
to
resolve.
Mr. Bertman added that while most discussions have focused on the on-
line
consumer, bank-merchant relationships are at least as critical and have
been
"underestimated and under-understood."
"There is a question of how many banks do you need on the Internet," Mr.
Melton said. "This is not a polite question, but it's going to become
very
competitive - more so than in the physical world where you are protected
by
the walls of geography."
Mr. Melton was ready to declare victory on the security issue, saying,
"It's
essentially done."
Given the availability of data encryption techniques and specifications
like
SET, which is being developed by MasterCard and Visa, he said: "Tell your
customers, 'Don't worry. We'll take care of it'."
Mr. Bertman said the SET development process will take well into next
year,
but the card industry should move ahead with Internet payments." Sholom
Rosen, a vice president at Citibank who has invented a computer-
to-computer electronic money system, raised a red flag.
He said electronic currencies like those being promoted for the Internet
--
Citibank's is not among them -- raise security issues different from
those in
conventional commerce, and they are not fully addressed by "strong
encryption and protocols."
For example, Mr. Rosen said, counterfeit losses are conventionally borne
by
the party who is discovered passing fake currency. In on-line commerce,
the
issuer of money -- likely a bank -- is the victim, with consequences for
solvency and systemic risk that Mr. Rosen said haven't been thought
through.
Mr. Rosen stated in an interview that Mr. Melton and others are in an
"entrepreneurial mode" and understandably eager to embrace exciting new
things.
"Comdex is fine, but banks are in the business of having to manage
risks,"
Mr. Rosen said.
ABA Banking Journal: November, 1996
Are You "Toast"?
By William W. Streeter
Has anyone walked up to you recently and said, "You're toast"? As you
might surmise, the question has nothing to do with sun or food. It has to
do
with history, as in, "You're history, pal."
And that's how author Don Tapscott meant it when he used the expression
in
his presentation at the ABA Annual Convention last month.
He was speaking about the digital revolution, and with the single word
"toast," he likely captured the collective angst of most people in the
room.
As author of the best-selling book, The Digital Economy, Tapscott is a
prophet of the new order resulting from the digitizing of information.
Like
many of his ilk, his presentation was both mesmerizing and unsettling. He
spoke of the likely disappearance of entire industries under the
onslaught of
the Internet, specifically referencing travel agents and food
wholesalers.
He didn't foretell that fate for banking, but he did speak of the
"disintermediation" of the middleman.
"If you're in the middleman business, start looking for a job," he said.
It shouldn't take long to realize that banking falls under that heading.
Consider
that traditional banking is deposit intermediation, while the more recent
additions to the business have largely been brokerage. Sounds like a
"middleman" business to us.
Tapscott urged bankers to "reintermediate." We haven't a clue what that
means, but he did cite examples of several banks that have embraced the
Internet -- Security First Network Bank being one (look for an update on
it
next month); Wells Fargo and The Bank of Montreal being two others.
There's no denying that certain business have been displaced by
electronics.
The advent of desktop publishing software, for example, radically altered
the
"pre-press" and typesetting business that thrived pretty much since
Gutenberg. Typesetting in particular was wiped out by computers in the
space of about ten years. The function of putting words into type didn't
disappear, it was simply transferred to publications' staffs, at a
considerable
savings.
Those publications themselves face a challenge with the emergence of the
Internet as a radically different means of disseminating information.
Is banking similarly challenged? The answer without a doubt is "yes."
Will the
industry disappear like the typesetters? There are two considerations in
answering that question. First, the typesetting business disappeared
because
electronics gave publishers greater flexibility at less cost. The same
case is
made by proponents of banking via the Internet, but it's not clear yet
whether
a majority of people and businesses are ready to do banking that way.
Second, "banking" and "industry" are labels. The functions performed
under
those labels will of course continue as long as there is money, or more
broadly, exchange of value.
If by being "digitized" a product or service or process becomes more
convenient, more flexible, or less expensive, the marketplace will
embrace it.
And it will probably do so pretty quickly.
None of this says that there won't be a need for people to meet with
people.
Maybe many "face-to-face" meetings will occur by high-quality video
connection. But all of them won't. There will still be a need to be
reassured
about something in person; to shake hands on a deal; or to look someone
in
the eye -- a live eye.
As a proxy for this, consider that e-mail hasn't eliminated the need to
speak
by phone, any more than telephones eliminated the need to write or to see
someone in person.
Changes in fundamental technology have always caused business casualties
-- as with the proverbial buggy whip example.
Part of top management's job is to stay abreast of changing technology,
and
to hire and train people who can communicate in, and deal with, whatever
medium is appropriate. The difference now is that the change to a digital
age
will bring more far-reaching changes than anything seen recently, and is
occurring at dizzying speed.
For sure, money isn't likely to go away soon, and neither, therefore, is
financial services. That should ease some of the angst you may feel under
the
relentless barrage of "The Digital Age." But don't get comfortable
either, or
you will be toast.
Retail Delivery Systems News: November 22, 1996
Mondex Deal Changes MasterCard Strategy
Expect some turmoil in the smart card market as MasterCard International,
of New York, readjusts its strategy in the wake of buying a majority
interest
in Mondex, of London, a bank partnership formed to pilot smart cards in
England.
The long-time rumored acquisition represents one of the largest
investments
of a U.S. company in smart card technology.
Estimates are that MasterCard paid between $100 million and $150 million
for the majority interest.
MasterCard will adopt Mondex's technology as its strategic chip platform,
the companies say.
This raises questions for the future of pilots, such as the one planned
in New
York City's West Side by Citibank and Chase Manhattan and for the
validity of vendor hardware and software created to work with MasterCash,
analysts say. The New York pilot, which is meant to prove
interoperability of
the MasterCard and Visa systems, already has been delayed until the
second
quarter of 1997.
Additionally, MasterCard has lost several of its key officers in the
MasterCash division, raising questions about who is leading the venture,
RDSN has learned.
"A number of companies would like to see a crystallization of
MasterCard's
strategy with smart cards," says Dave Lott, an analyst with Dove
Associates
in Atlanta. "The deal raises a lot of questions in terms of what are they
going
to do with the product (MasterCash) that they've developed up to this
time."
Washington Post: Sunday, November 24, 1996
The Uncertain Value of 'Smart Cards'
By Jane Bryant Quinn
The next piece of plastic the banks think you ought to keep in your
wallet is a
"smart card." These cards come in several varieties and most aren't ready
for
mass distribution. But pilot projects are forging ahead in Atlanta and
New
York City early next year, and in Canada and several countries abroad.
There's no obvious consumer need for smart cards today. But the bankers
believe that you're going to love them anyway. You may even be mailed one
and urged to try it.
Smart card promoters make the assumption that you hate to carry cash. You
hate fishing for bills and coins to buy a newspaper or a soda. You'd put
down plastic, instead.
This plastic card has money on it, embedded in a computer chip. A $ 20
card, for example, will give you $ 20 in spending power.
If you buy a 75-cent newspaper, the seller will put your card in a
special
terminal and drain off 75 cents. No identification or signature is
required.
You now have a card with $ 19.25 left on it. After spending $ 1 on a
soda,
the value of your card goes down to $ 18.25. If you forget the amount,
you
can check it with a little portable card reader. Some readers also might
list
the last five things you bought.
Don't confuse a smart card with a debit card. When you pay by debit card,
money is moved automatically from your bank account into the merchant's
bank account. With a smart card, however, you first move money from your
bank account onto the card's computer chip. When you buy something, the
money moves from your card to the merchant's terminal and then,
electronically, to the merchant's bank.
If every merchant, street vendor, taxi driver and bus accepted smart
cards,
you wouldn't have to carry cash. To some, that would be a huge
convenience; to others, it's a shrug. But as long as some merchants took
smart cards and others didn't, you'd have to carry both.
Smart cards come in three varieties, some of them more flexible than
others:
* A prepaid, disposable single-purpose card. Telephone cards are a good
example. You pay $ 10 or $ 20 for a card, dial an 800-number, give the
number of your card and then make your telephone call. Minute by minute,
the cost of the call is deducted from the value of the card. When you've
spent
all the money on the card, you throw it out.
* A prepaid, disposable bank card. You buy the card at a bank and can use
it at any store that has a terminal.
* A reloadable card. When your money runs out, you can take it to a bank,
an automated teller machine or a special kiosk and load it up again.
Visa,
MasterCard, Citibank and the Chase Manhattan bank will jointly test a
reloadable card in a section of New York City next year. A reloadable
card
also could serve as your credit card, debit card or ATM card.
What's in it for the banks? Eventually (although not at first), the banks
probably would charge you for the card. There might be a fee when you
used
an ATM to load it up. The merchant also would pay a fee, in return for
getting what is presumably a more secure transaction.
What's in it for consumers? A very little bit of convenience. Putting
down a
card is a tad quicker than fishing out cash. You always have the
equivalent of
exact change. You wouldn't have to count your change, but you'd have to
use the card reader to be sure the merchant's terminal deducted the right
amount. You may or may not pay more for the card than it costs to get
cash
from an ATM.
For a while, the smart cards probably won't have any more than $ 100 on
them and the limit might be lower. So they're strictly for walking-around
money. You'd still need your credit card, debit card or checkbook for
more
serious shopping.
If the card malfunctions -- say, it registers $ 14 when you're sure you
were
carrying $ 36 -- a bank can check the balance on the computer chip, says
Ron Braco, a senior vice president at Chase Manhattan. But if you lose
the
card, it's just like losing cash. You're out the money.
Promoters of smart cards promise a lot of national and international uses
that
aren't yet anywhere in sight. I'll probably wait for them. Banks have a
sales
job to do on people like me who don't find it a nuisance to carry cash.
Forbes: December 2, 1996
Banks are pushing new ATM cards that doubleas a Visa or a MasterCard.
Avoid 'em.
Carte Blanche For Crooks
By Alexandra Alger
Chances are that yet another chunk of unsolicited plastic has popped up
in
your mailbox. It is not just another credit card. It's a combination new
ATM
card and charge card. You can use it to withdraw cash from automated
teller
machines, as you do with your current ATM card. Or you can use it to
charge purchases, without having to use your PIN (personal identification
number). "It's as convenient as a credit card, but it's not credit! The
amount
of your purchase is immediately deducted from the balance in your
checking
account," says the brochure sent out by one major bank. And therein lies
the
danger--it's a debit card. We don't like it for three reasons:
* It could give a thief carte blanche to your checking account. In case
of
fraudulent use of your debit card, you are the one who is instantly
out-of-pocket, not the bank. You may have to fight the bank to recover
your
money, and you could lose it completely if you don't report the loss
right
away. Meanwhile, your bank balance and credit line could be depleted, and
your checks could be bouncing all over town.
* You lose the credit float, of 30 days or so, that you get with a
zero-balance
credit card.
* You lose the option of withholding payments--important leverage in case
of
disputed charges.
Banks are flooding the mails with these new cards. Visa has launched a
multimillion-dollar national TV campaign to promote its debit cards,
starring
football superstar Deion Sanders. Some 4,000 U.S. banks, S&Ls and credit
unions are issuing MasterCard- and Visa-affiliated debit cards--double
the
number of a year ago. Most of the nation's biggest banks have already
joined
the party, including California's Bank of America and New York's Chase
Manhattan Corp. (to its new Chemical Bank customers). Citibank is
planning its blitz next year.
For banks, what's not to like? Merchants pay card issuers an
"interchange"
fee--typically 1% to 2% of the transaction value. Some banks even charge
customers $1 to $1.50 a month just to have the card.
Debit cards also help wean bank customers from costly check-writing. It
costs banks $1.10 or so to process every check, but only 27 cents to
handle
a debit card transaction, says Edward Neumann, director of Dove
Associates, a bank consulting firm in Washington, D.C.
Bankers insist that the cards are good for customers, too. "The key is
convenience--that's what we're selling," says John Russell, a spokesman
for
Banc One in Columbus, Ohio, the first bank to offer a debit card and now
the largest issuer of them (over 4 million).
But we think this convenience comes at too high a risk. Some debit- card
crooks are subtle. They'll use swiped debit cards occasionally, charging
up
relatively small amounts. As long as the account holders overlook the
charges
on their bank statements, the party continues. The thief has a kind of
annuity.
Roy Funderburk Jr. learned about this the hard way. The 53-year-old mail
carrier from Alexandria, Va. was going over his bank statement when he
noticed two debit-card charges in one day at an Exxon station he
occasionally used in Washington, D.C. That sent him back to statements
for
previous months. What he found were $1,000 in bogus gas station charges
made over a nine-month period. No charge was more than $20. He hadn't
lost his Visa debit card, so was baffled about the misuse.
Funderburk's branch manager at American Security Bank (now
NationsBank) told him not to worry, he would be reimbursed for his
losses.
But a month later Funderburk got word that he'd only be recompensed for
the fraudulent charges made within the previous 60 days-- $247. He was
out
$761. Funderburk was furious. He went to the Washington Police
Department, the Secret Service--even the FBI. The latter two told him
they
only looked into cases involving at least $5,000.
Finally, on the advice of a lawyer, he took the bank to small-claims
court. He
struck out there, too; the judge shook his head and told Funderburk the
bank
didn't owe him anything under federal bank rules, and there was nothing
he
could do.
The story has a happy ending. Out of the blue, an American Security
lawyer
called Funderburk about settling. Funderburk said he just wanted his
money
back, without interest. Fine, the attorney said. Within hours the money
was
back in his checking account. But what an ordeal!
How had the thief pulled off the thefts? All he needed to get started was
the
number on Funderburk's debit card, perhaps from a discarded receipt. A
phony card could be made, using that number.
Still, Funderburk was lucky. Banks will normally assume liability for
fraudulent use only if you notify them within two days after you miss
your
card. In that case your loss is limited to $50--often, you won't be
charged at
all. But wait any longer, and you could be liable for as much as $500 of
your
own checking account losses. If you fail to report the fraud within 60
days,
the bank doesn't have to give you a cent.
Your chances of getting hit are uncomfortably high. Last year Visa and
MasterCard issuers shouldered $19 million in fraud-related losses on
their
debit cards, says the Nilson Report, an industry newsletter in Oxnard,
Calif.
PIN-related ATM fraud accounts for $100 million to $200 million in annual
losses.
That is small potatoes compared with the estimated $3 billion in annual
credit-card fraud losses (FORBES, Aug. 26). But, says John Wisniewski, a
postal inspector in Pittsburgh:"The bad guys are just starting to figure
out how
to misuse them."
One of the more ingenious ATM scams involved a bogus telephone. At an
ATM in Miami, Fla. crooks put plastic sleeves into the card slots. When
customers saw their cards were swallowed by the machine, they picked up
the telephone provided to dial the posted customer service number.
But the phone was provided by the thieves, and the posted number put
customers in touch with a thief, not a bank employee. The thief then
asked
customers for their PIN as identification and promised that replacement
cards
would be mailed out in a matter of days.
The crooks then plucked out the stuck ATM cards with tweezers and were
off to the races.
Our advice is to avoid the ATM-debit card. When your ATM card expires,
request a simple replacement instead of the new combo card you'll be
mailed. In our view, the risks of the combo far outweigh the potential
rewards.
1
0