1997-08-11 - Re: Getting ecash without an MTB account

Header Data

From: Jeremey Barrett <jeremey@bluemoney.com>
To: Mike <cypherpunks@toad.com
Message Hash: 1307c2e3078efeec319102f0d06a7cfb95b523da0c2217afae81aa73fb2fd406
Message ID: <3.0.2.32.19970811010802.007f77f0@descartes.bluemoney.com>
Reply To: <3.0.3.32.19970811092630.009d5950@localhost>
UTC Datetime: 1997-08-11 08:19:01 UTC
Raw Date: Mon, 11 Aug 1997 16:19:01 +0800

Raw message

From: Jeremey Barrett <jeremey@bluemoney.com>
Date: Mon, 11 Aug 1997 16:19:01 +0800
To: Mike <cypherpunks@toad.com
Subject: Re: Getting ecash without an MTB account
In-Reply-To: <3.0.3.32.19970811092630.009d5950@localhost>
Message-ID: <3.0.2.32.19970811010802.007f77f0@descartes.bluemoney.com>
MIME-Version: 1.0
Content-Type: text/plain



-----BEGIN PGP SIGNED MESSAGE-----

At 09:26 AM 8/11/97 +0200, Mike wrote:
>
>I would have two accounts at MTB, one for savings and one for transactions.
>I want to give away a million bucks, so I deposit that amount in the
>transactions account. Then I give the account password to the receiver, he
>withdraws the money, and I change the password so he can't get any more
>money from me. I trust the receiver not to change my password, but if he
>does change it, then I can simply ask MTB to change it back, explaining
>that I lost my password.
>
>Would this work?
>

Should work just dandy, with this note: You must destroy your wallet
on disk for the transactions account and recreate after every
"transfer" is complete. This is because the sequence numbers on mint 
messages will not match and the MTB client will complain about it and 
reject the messages. However, you can re-create your wallet with
no problems at all. 

(Note to Digicash developers, if you're reading, please allow any
sequence number greater than or equal to the expected value in future
wallets. There is a really obscure and damned difficult attack that
can be mounted against this, but the alternative is a non-portable
wallet. Not being able to have an arbitrary number of wallets for 
the same account is mucho annoying).

BTW, there are better solutions to operating without a mint account,
but they are not widely available yet.

Regards,
Jeremey.



-----BEGIN PGP SIGNATURE-----
Version: PGP for Personal Privacy 5.0
Charset: noconv

iQCVAwUBM+7IYS/fy+vkqMxNAQHKHQP/WMtgWY5rswZjpNRvk56f0LY/DVe078xC
09Z8DG1dmIZbBCWlTqO5fujZlH83B2S7covw8K3YtVeCF74IlOI5TeOEVVgVZHnp
0/iLafMjEWQBy8/PHxy6IOJeWy0LX2kgJozWTztu6AlcCGvRJx3gRUK14UxMz1mJ
HY3wiupNPfg=
=Laum
-----END PGP SIGNATURE-----

--
Jeremey Barrett                                BlueMoney Software Corp.
Crypto, Ecash, Commerce Systems               http://www.bluemoney.com/
PGP key fingerprint =  3B 42 1E D4 4B 17 0D 80  DC 59 6F 59 04 C3 83 64






Thread