XeroBank: Feature Requests

Discussion in 'privacy technology' started by Pleonasm, Jun 26, 2008.

Thread Status:
Not open for further replies.
  1. Pleonasm

    Pleonasm Registered Member

    Joined:
    Apr 9, 2007
    Posts:
    1,201
    The purpose of this thread is to provide a place for the customers of XeroBank to offer constructive feedback on — and recommend enhancements to — their products and services, and for prospects of XeroBank to more fully understand the strengths and weaknesses of this anonymity solution.

    * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *

    To get started, I am offering the following comments (in no particular order) for consideration by XeroBank.

    • Update, enhance and expand the set of FAQs on the XeroBank website, together with creating a searchable Knowledge Base of articles on XeroBank products and services.

    • Author white papers describing the XeroBank network and its unique attributes.

    • Keep the XeroBank website current (e.g., always the display the actual latest version number of XeroBank software available for download).

    • Post a “change log” on the XeroBank website for each new release of XeroBank software.

    • Improve the customer support ticket system, by providing a prompt acknowledgement to the user that a ticket has been received.

    • Create a public community forum in which XeroBank users may talk to one another.

    • Prepare a Knowledge Base article containing a comparative analysis of the strengths and weakness of the major commercial anonymity services.

    • Expand the set of exit nodes on the XeroBank network available to a user (i.e., beyond Canada and the Netherlands).

    • Vary the IP address of the exit node on the XeroBank network at least daily.

    • Vary the country of the “hop” in the XeroBank network (i.e., entry node -> hop -> exit node) frequently (e.g., hourly).

    • Allow the user to specify the default exit node when first launching xB VPN (e.g., perhaps through a command-line parameter such as “--connect Canada.ovpn”).

    • Author a Knowledge Base article containing links to allow a user to download all the source code used by the XeroBank client (e.g., xB VPN).

    • Commission and release the results of an audit by an independent and well-respected technology consultancy that verifies all anonymity, privacy and technology assertions made by XeroBank.

    • Achieve FIPS 140-2 certification.

    • During the new account signup process, allow the user to optionally indicate that s/he has a VeriSign Class 1 digital ID corresponding to the email address that has been provided. That ID may then be retrieved by XeroBank (see https://digitalid.verisign.com/services/client/index.html) and used to encrypt the “Welcome to XeroBank” email sent to the user that (may) contain the Access and Deposit account numbers. In this way, the contents of that introductory message are secured.

    • Alter the XeroBank Installer so that shortcuts to xB Browser and xB Config are not added to the “Start | All Programs | XeroBank” folder, when the xB Browser is not being installed.
     
  2. Genady Prishnikov

    Genady Prishnikov Registered Member

    Joined:
    Mar 9, 2006
    Posts:
    350
    Good suggestions. However, it would take more than one person to do it all and the last few weeks of postings from Steve have made it clear (to me at least) that XeroBank is a one-man-shop. Tickets? He just checked on them. Billing problem? He just checked and it's fixed now. Problems signing in? He'll check on it....a few hours later he reappears and it's "fixed." And on and on it goes.

    The website, the service (or lack thereof), the customer service lag times, so many things point to XeroBank being Steve Topletz and a few "advisors." Which would be fine - if there was a little honesty about it.
     
  3. SteveTX

    SteveTX Registered Member

    Joined:
    Mar 27, 2007
    Posts:
    1,641
    Location:
    TX
    I think most of these things are doable, but some will be significant hurdles, like the FIPS 140-2. That is going to require an entire rewrite of the xB Machine core, going back to formula. Kyle and I have already started working on laying the groundwork for it.

    As for the digital ID... you can just elect to write it down and not have it sent to you. If you start adding all those options, you make it a lot more difficult for the novice to understand. However, I'll toss it to Stefan and see what he says about it. One of the things we discussed for implementation is to have account email updates use a PGP key that you could upload. That way you could always recover your password assuming you had the private key, and we could send that info to any address.

    For hops, I think there is a Germany hop coming up, and we just added some more Canada servers.

    The changelog is easy enough, that is written in the updates latest.msg file on the server, and it is all written down in detail on the SVN.

    The rest shouldn't be too difficult. The smoothness of the UI is my focus right now. We're setting up a new forum and cerberus system but they can't move as fast as you normally would because they have to get stripped, locked down, and smoothed out before release. Otherwise, they would be ready in 30 minutes! Secure designs take a little time.
     
  4. Pleonasm

    Pleonasm Registered Member

    Joined:
    Apr 9, 2007
    Posts:
    1,201
    Based upon the comments of Genady Prishnikov (post #2), another request is:

    • Offer periodic scheduled tours of the XeroBank offices in Dallas, TX to the public, to allow individuals to verify the size and scope of the company.
     
  5. Pleonasm

    Pleonasm Registered Member

    Joined:
    Apr 9, 2007
    Posts:
    1,201
    And another . . .

    • Populate the “File version” and “Product version” metadata fields on all XeroBank files (e.g., “XeroBank Installer.exe” and “C:\Program Files\XeroBank\xBVPN.exe”), so that the user can easily retrieve version information by right-clicking the file name in Windows Explorer, choosing “Properties”, and viewing the “Details” tab.
     
  6. Pleonasm

    Pleonasm Registered Member

    Joined:
    Apr 9, 2007
    Posts:
    1,201
    Another idea…

    • Report on the XeroBank website the number of requests the company has received by governmental entities for customer information by country by status (e.g., "complied," "denied,", "in progress") by month (and by rolling 12-month year).
     
  7. caspian

    caspian Registered Member

    Joined:
    Jun 17, 2007
    Posts:
    2,301
    Location:
    Oz
    Yeah I would be curious to know what they want to see. I have read that they spied on Gay college students in several states, intercepting their emails, and that they spied on PETA and some peace groups. I think they are after anyone who believes in peace or who disagrees with the Bush Admin. But I just wonder if they would actually try to get info on people for these types of reasons.
     
  8. SteveTX

    SteveTX Registered Member

    Joined:
    Mar 27, 2007
    Posts:
    1,641
    Location:
    TX
    Done. You caught me while I was working on the installer. :)
     
  9. SteveTX

    SteveTX Registered Member

    Joined:
    Mar 27, 2007
    Posts:
    1,641
    Location:
    TX
    Done, changelog inside the installation directory.

    Done.

    Did some more major overhaul on xB VPN for extreme efficiency on x64 and Vista. That also means the startup/shutdown problem is fixed too.

    Installer is now versioned to date compiled. Latest version is 2.8.6.28, should be recompiled after we verify changelog and shortcuts link. To be released later today.
     
  10. Pleonasm

    Pleonasm Registered Member

    Joined:
    Apr 9, 2007
    Posts:
    1,201
    And another…

    • Author a Knowledge Base article that provides “how to” instructions describing procedures to allow a customer to independently verify all anonymity/privacy facets of the operation of xB VPN and the XeroBank network. For example, this thread begins a discussion of how to check that your Internet traffic is encrypted.
    P.S.: Steve, your prompt attention to these feature requests is appreciated by all, I am sure. :)
     
  11. Pleonasm

    Pleonasm Registered Member

    Joined:
    Apr 9, 2007
    Posts:
    1,201
    Steve, may I also recommend that a link to the change log be posted adjacent to the link for downloading the XeroBank Installer on the company’s website? In this way, a user can review the log and make an informed assessment of whether it is necessary to install the update on her or his system.

    Thank you.
     
  12. Pleonasm

    Pleonasm Registered Member

    Joined:
    Apr 9, 2007
    Posts:
    1,201
    And…

    • Offer the customer a choice of credit card processors for the Deposit account. At present, the Dalpay.is processor results in a foreign fee surcharge being added to the total fee paid by US customers, apparently because currency exchange is required. If US customers can use a US credit card processor, then this surcharge (3%) can be avoided.

    • Alert customers when they are enrolling in the XeroBank services that a credit card processing fee (3%) may be added to the total cost of the service, depending upon the customer’s bank that issued the credit card and her or his country.
     
Thread Status:
Not open for further replies.