NODE 732736afRe: The future will be easy to use
"E. ALLEN SMITH" <EALLENSMITH@ocelot.Rutgers.EDU>Thu, 30 Nov 1995 13:43:08 +0800
From: IN%"jlasser@rwd.goucher.edu" "Jon Lasser" 29-NOV-1995 16:23:00.41
Not if you're encrypting a Credit Card transaction to ship physical
goods. In that case, I'm going to certainly want to link a key ID to a
physical body (or at least address) if I'm the seller, so as to limit
liability as best I can.
While this might not ultimately be important, early adopters of crypto on
the net seem in general to be financially interested with an eye to limiting
liability. They want linked keys.
There's a public-relations aspect to crypto which most systems not
linking name -> key id fail. This is the step necessary to get it out
the door.
Unfortunately, it also appears counter to CP philosophy.
However, if you have optional linking of ID and name, shippers will only
ship to keys with such attributes. Because just ID and address, it could
be a "hit and run" type attack shipped to a safe maildrop.
---------------------------------
If the transaction is via a Credit Card, it's the card issuer's
liability (and responsibility to determine creditworthiness), unless I'm badly
mistaken. If it's bank-issued ecash, then it's up to the bank to disgorge
physical dollars when ecash is presented to them. What's the risk in either
case?
-Allen
NODE b189144aRe: The future will be easy to use
Jon Lasser <jlasser@rwd.goucher.edu>Fri, 1 Dec 1995 02:23:17 +0800
On Thu, 30 Nov 1995, E. ALLEN SMITH wrote:
> However, if you have optional linking of ID and name, shippers will only
> ship to keys with such attributes. Because just ID and address, it could
> be a "hit and run" type attack shipped to a safe maildrop.
> ---------------------------------
> If the transaction is via a Credit Card, it's the card issuer's
> liability (and responsibility to determine creditworthiness), unless I'm badly
> mistaken. If it's bank-issued ecash, then it's up to the bank to disgorge
> physical dollars when ecash is presented to them. What's the risk in either
> case?
Credit card fraud -- ie I've snarfed someone's card number and they
haven't figured it out yet.
Cardholder's liability is $50 (I think). Depending on the situation (if
it's a card-is-physically-present transaction or a not-present) the
liability falls to either the bank or the merchant.
A "proof of address" is a darn good way to reduce (not prevent, reduce)
that sort of fraud.
Jon
------------------------------------------------------------------------------
Jon Lasser <jlasser@rwd.goucher.edu> (410)494-3072
Visit my home page at http://www.goucher.edu/~jlasser/
You have a friend at the NSA: Big Brother is watching. Finger for PGP key.