[12810] in Commercialization & Privatization of the Internet

home help back first fref pref prev next nref lref last post

Re: Failings of credit cards

daemon@ATHENA.MIT.EDU (Bruce Gingery)
Sun May 29 20:34:58 1994

Date: Sun, 29 May 1994 06:34:53 -0600 (MDT)
From: Bruce Gingery <lcbginge@antelope.wcc.edu>
To: John Curran <jcurran@nic.near.net>
Cc: Nick Szabo <szabo@netcom.com>, com-priv@psi.com
In-Reply-To: <9405282357.aa24401@nic.near.net>


  With the recent release of PGP v2.4 (commercial) and PGP v2.5 (freeware)
what is to prevent in-person exchange of public keys with a
financial institution for validation purposes.  This exchange would either
be in conjunction with a DDA or credit account, or a "pass-thru" arrangement.

In use:
	Amount, timestamp, and sequential transaction number
	is entered encrypted under purchaser's private key
	then financial institutions public key.  External to this
	SOME bank "routing" information is appended.  Also internal
	to this "credit block" is the debit-card or credit-card
	equivalent account identification.

	Order is entered with attached encrypted block and encrypted
	using vendor's public key.

	Order is sent to vendor.

	Vendor decrypts and forwards encrypted "credit block" to
	financial institution for "deposit", with an identifying
	transaction number. Financial institution does whatever
	processing it wishes to validate the balance for debit
	or credit availability, and either "bounces" or validates
	the deposit, and confirms the amount.

	Vendor ships "goods" or "bounces" the transaction using
	vendor's public key.
End of validated or bounced transaction.

  So it leaves portions of the whole thing in the hands of financial
institutions... everything today seems to be in their hands anyways, so
it's not a worsening of the situation.

	Bruce Gingery

---
	bruce@TotSysSoft.com
	lcbginge@antelope.wcc.edu

	NeXT-mail and MIME-mail welcome


home help back first fref pref prev next nref lref last post