When I read the first few paragraphs, I thought it was interesting, but as I got to the details, I was quickly disappointed. Serial number based cash with *no* authentication? I could have hacked this protocol up with perl in less than 24 hours. The mailing list already has a sort of "e-cash" built in keyed by e-mail address and password instead of serial number. No encryption ready yet? They should have waited. If this system were to go into large scale use, I'd be tempted to try and forge their ecash and eavesdrop on other people's mail. This system is an accident waiting to happen and if it got subverted, it would just provide evidence to bureaucrats that we need laws protecting us in cyberspace and the government should start its own ecash on the net. Somebody point these guys to the IMP list. -Ray
participants (1)
-
rjc@gnu.ai.mit.edu