>
> I have nothing to do with Windows computers, sorry!  Cant you just
> add a line or two of code so it works on the web?!

Hi,


I don't know how to make a VB program work on the web.
If you don't live on Antarctica a windows computer cannot be that far away...

Anyway, if I were to make a complete program to do automated tries on all e-gold
accounts, I would probably proceed to add a browser window to the program and let
it interact with the turingdecoder I made, to do the automated attack.
I don't see what could be the purpose of putting it in a web page, other than for
demonstration purposes.


Basically we have the situation (based on 500000 e-gold accounts, and 3 or 4
trials before an account locks), that I have about 2000000 free lottery tickets
every day , right there for the taking.
These are very low odds tickets of course, but you never know. Most lotteries have
low odds, yet there are winners every week.
Obviously, with more and more people having broadband access at low cost, this is
going to be a problem sooner or later.
Why not take these 2000000 free lottery tickets, somebody with programming skills
in a poor country will ask himself.
This could cause most e-gold accounts to be locked continuously.


The easiest way I see , to avoid these automated attacks on all e-gold accounts,
is to stop using the account # for login purposes, use login names instead (to be
choosen by the user).
The account # should remain in use as the account # to which you can pay, and the
# you show on your site.
The login name should be used by the account owner to login into his account and
do spends or whatever.
The login name can be easy to remember, or more difficult if you want some extra
security, but the purpose is that you don't share the login name on your website
or other...
This makes it much more difficult to run automated attacks on all e-gold accounts,
because now you cannot simply run through all the account # from 100000 to 999999.


It also solves a second problem.
Right now it is very easy to boycot my competitors if I am working in the e-gold
economy.
For example if I run an e-gold casino or e-gold exchange service, I can set up a
small program that runs automated attacks on my competitors' e-gold accounts ,
with the purpose to lock them up as much as possible (only 3 or 4 failed logins
are needed to lock an account for a certain amount of time).
With login names this problem dissappears because one doesn't know on which login
name to run, inorder to shut down somebody's account.



Danny

http://two-cents-worth.com/?102468&EG


---
You are currently subscribed to e-gold-list as: archive@jab.org
To unsubscribe send a blank email to [EMAIL PROTECTED]

Use e-gold's Secure Randomized Keyboard (SRK) when accessing your e-gold account(s) 
via the web and shopping cart interfaces to help thwart keystroke loggers and common 
viruses.

Reply via email to