Live data from Hacker News

Why I Wrote PGP (1999)

philzimmermann.com

31–40 of 194 posts

Re: Why I Wrote PGP (1999)

#31
post #29
post #25

Earlier quoted context omitted.

The Signal protocol is very well designed but the implementation requires a telephone number (I know it is coming). That's a step removed from PGP which can be completely offline.

That's interesting and all, but my point is just that you'll have to stop and think about how many orders of magnitude separate the userbase sizes. A simpler way to make the same point would be that relative to modern cryptography, to a first approximation, nobody uses PGP.

Maybe only the right people use PGP.

Re: Why I Wrote PGP (1999)

#32

There’s something… different about how people (techie people are most of my sample) would write before the 00’s. I’m not sure if it has to do with the medium, or the constraints of the time, but reading it always fills me with something I can best describe as peace/nostalgia. The belief that technology honestly can change the world for the better and that the most influential people driving it have good motives inste…

[deleted]

Re: Why I Wrote PGP (1999)

#33
post #10

> But while technology infrastructures can persist for generations, laws and policies can change overnight. Once a communications infrastructure optimized for surveillance becomes entrenched, a shift in political conditions may lead to abuse of this new-found power. Political conditions may shift with the election of a new government, or perhaps more abruptly from the bombing of a federal building. Prescient.

So I posted a response to your comment that got instantly flagged and hidden. Wonder if HN employs automatic scanning and flagging for keywords.

Re: Why I Wrote PGP (1999)

#34
post #31
post #29

Earlier quoted context omitted.

That's interesting and all, but my point is just that you'll have to stop and think about how many orders of magnitude separate the userbase sizes. A simpler way to make the same point would be that relative to modern cryptography, to a first approximation, nobody uses PGP.

Maybe only the right people use PGP.

I honestly have no trouble believing that's what PGP's userbase believes about themselves, which is absolutely part of the problem.

Re: Why I Wrote PGP (1999)

#35
post #17

Earlier quoted context omitted.

I think one of the best arguments for using PGP is how long it's been around and is still in use, for two reasons: The encryption mechanisms have been tested many times by many people. And the tooling exists for just about platform and language.

This is pure snark and should be downvoted into oblivion, but by 2015 even Phil Zimmerman couldn't figure out the tooling: "Sorry, but I cannot decrypt this message. I don't have a version of PGP that runs on any of my devices" https://twitter.com/josephbonneau/status/638772283713060864

Strange, I've found it for all major platforms. I don't do much encryption, but keygen and message signing works for me on Android, iOS, GNU+Linux, FreeBSD, Mac, and Windows.

Re: Why I Wrote PGP (1999)

#36
post #6

Earlier quoted context omitted.

I think one of the best arguments for using PGP is how long it's been around and is still in use, for two reasons: The encryption mechanisms have been tested many times by many people. And the tooling exists for just about platform and language.

The encryption mechanisms were tested, found wanting, and replaced in subsequent systems. PGP's installed base prevented them from keeping up. As a result, the constructions used in PGP today are essentially reviled by cryptography engineers.

What do you mean by "constructions"?

Re: Why I Wrote PGP (1999)

#37
post #30
post #22

Earlier quoted context omitted.

There isn't "an" alternative to PGP, because the idea of a single tool like PGP that covers all the use cases PGP attempts to cover has been revealed to be bankrupt. PGP does a bad job at practically everything it's applied to, because different problem domains ask different things from their cryptography. Backup tools want deduplication. Secure messaging wants relentless forward secrecy. Package signing systems want…

it's a little like someone invented a bad balanced binary tree It's a little like that culturally but it's almost entirely unlike that technically - a suboptimal data structure or algo tend to be just suboptimal-but-functional whereas bad cryptography and bad cryptography engineering often fail catastrophically. I know you know this, of course! But for one thing, someone used an iffy analogy on the internet, etc. For…

I'd use the analogy of "someone came up with C and then people came up with high level languages and even low-level languages that provided memory safety and..." but then we'd just be in another debate about how mired in the 1980s we should remain. :)

Re: Why I Wrote PGP (1999)

#38
post #6

Earlier quoted context omitted.

The encryption mechanisms were tested, found wanting, and replaced in subsequent systems. PGP's installed base prevented them from keeping up. As a result, the constructions used in PGP today are essentially reviled by cryptography engineers.

What do you mean by "constructions"?

Cryptographic constructions.

Re: Why I Wrote PGP (1999)

#39
My undergrad university library has (had?) a bound copy of PGP source code on the stacks for checkout.

If I remember correctly, digital copies of the binaries and source code were prohibited for export as a munition, but publishing the source code in a book, made it a book, and thus eligible for export.

Re: Why I Wrote PGP (1999)

#40

There’s something… different about how people (techie people are most of my sample) would write before the 00’s. I’m not sure if it has to do with the medium, or the constraints of the time, but reading it always fills me with something I can best describe as peace/nostalgia. The belief that technology honestly can change the world for the better and that the most influential people driving it have good motives inste…

Very similar to the cryptocurrency field. Lots of noise nowadays.
Post reply on HN