Live data from Hacker News

Why I Wrote PGP (1999)

philzimmermann.com

61–70 of 194 posts

Re: Why I Wrote PGP (1999)

#61
post #26

Earlier quoted context omitted.

Would you want the same capability on the Internet? If not, what makes Internet communication different from POTS communication?

Internet connections have a more-or-less reliable source IP (spoofing does occasionally happen and we take measures to mitigate it), IP ranges have owners and if an address is consistently used for abuse (attacks, spam email, ...) then people do report this to the owner of that address?

> IP ranges have owners and if an address is consistently used for abuse (attacks, spam email, ...)

IP ranges have registrants. Servers usually are assigned IP addresses temporarily by the registrant, or by someone the registrant has assigned the block of addresses to by some other means. This means differs from region to region. In the US the responsible party is ARIN, and registrants can reassign addresses using a database called SWIP. In the EU both registrants and their partners use the same database called RIPE. I have never registered addresses in other regions.

> then people do report this to the owner of that address?

Yes. Registrant again, but yes. And if you don't get satisfaction, then you can (and should) escalate all the way to the region's authority.

Re: Why I Wrote PGP (1999)

#62
post #55

Earlier quoted context omitted.

> Unfortunately, today it's 90% people trying to get rich quick. And that is, unsurprisingly (and quite banally), used by many detractors to dismiss it all while handwaving away: > Bitcoin was born in the aftermath of the global financial crisis and the occupy wall street movement.[1] Events where, giant banks and institutions received trillions of dollars in unprecedented bail outs while 'main street' suffered with…

> And that is, unsurprisingly (and quite banally), used by many detractors to dismiss it all There is a stronger argument against crypto: the main use case (outside speculation) seems to be illegal activities. If what you are doing is legal, why not use government currency? If what you are doing is illegal, crypto is great. A currency outside the control of the government (police) is almost by definition made for ill…

1. Why does FedEx exist? If what you are doing is legal, shouldn't you use USPS?

2. There are plenty of things that are federally illegal but many consider to be morally legal. Examples include, for example, weed dispensaries operating in states that have legislated cannabis.

3. What happens if a future government makes funding of ETE encrypted software, without CSAM scanning, illegal?

Re: Why I Wrote PGP (1999)

#63
post #14

Matthew Green does a pretty good job picking apart PGP's issues, although he completely fails at suggesting alternatives and also completely ignores non-email use cases. https://blog.cryptographyengineering.com/2014/08/13/whats-ma...

I am so tired of crypto experts criticizing PGP without suggesting an alternative. So much has been written, so many soapboxes have been climbed on, and yet there seems to be no good replacement.

I deeply respect Philip Zimmermann for creating "pretty good privacy" rather than trying for "perfect privacy". PGP is exactly that: pretty good. Not great, not perfect, but pretty good indeed. And it's there. And it works. It's a compromise, which works well for many people's requirements. Oh, and did I mention that it EXISTS?

I use PGP every day. My private keys are stored on Yubikeys, which is supported. I have offline backups of those, which is supported, too. I can encrypt my backups for multiple keys, sign lists of hashes of files to verify integrity, and people can send me private E-mail.

None of this works perfectly, but it does work, and (not being a teenager anymore) I appreciate the fact that PGP has worked since 1991 or so, and I can reasonably expect it to work for the rest of my lifetime, unlike much modern software, which while being incredibly fashionable, seems to flare out a couple of years later.

Re: Why I Wrote PGP (1999)

#64
post #3

PGP felt so subversive back in the day. Key signing parties[1] and porting the "international" version[2] to run on the Amiga. And the very real threat that the Clipper Chip[3] would lead to the outlawing of all other encryption methods. [1] https://en.wikipedia.org/wiki/Key_signing_party [2] https://www.unix-ag.uni-kl.de/~conrad/krypto/pgp263.features... [3] https://en.wikipedia.org/wiki/Clipper_chip

Yes, the only munition available on a t-shirt!

Re: Why I Wrote PGP (1999)

#65

There’s something… different about how people (techie people are most of my sample) would write before the 00’s. I’m not sure if it has to do with the medium, or the constraints of the time, but reading it always fills me with something I can best describe as peace/nostalgia. The belief that technology honestly can change the world for the better and that the most influential people driving it have good motives inste…

One difference (in this article at least) is that there are no jokes or unnecessary cultural references. Another might be called moral clarity. Unfortunately, it's usually an illusion. We have much more experience with technologies invented under optimistic assumptions turning out to be a moral gray area at best, when you look at how they're used. I found this paper interesting: The Moral Character of Cryptographic W…

I'd put "jokes" and "cultural references" together under "tone". Recent articles often feel like they're trying to catch the attention of children. There are lots of "candies" to make you read: pictures, GIFs, jokes, an attention grabbing title, colors, emojis, a friendly tone, lots of exclamation marks. On the other hand, that article is mostly black on white text, that's plain in a good way.

Re: Why I Wrote PGP (1999)

#66
post #55

Earlier quoted context omitted.

> Unfortunately, today it's 90% people trying to get rich quick. And that is, unsurprisingly (and quite banally), used by many detractors to dismiss it all while handwaving away: > Bitcoin was born in the aftermath of the global financial crisis and the occupy wall street movement.[1] Events where, giant banks and institutions received trillions of dollars in unprecedented bail outs while 'main street' suffered with…

> And that is, unsurprisingly (and quite banally), used by many detractors to dismiss it all There is a stronger argument against crypto: the main use case (outside speculation) seems to be illegal activities. If what you are doing is legal, why not use government currency? If what you are doing is illegal, crypto is great. A currency outside the control of the government (police) is almost by definition made for ill…

If by trying to avoid aiding and abbeting the system described as:

> …giant banks and institutions received trillions of dollars in unprecedented bail outs [1] while 'main street' suffered with record unemployment, foreclosures, and destruction of small businesses.

> People rightfully realized that perhaps government should not have absolute and total control of the monetary supply and financial system.

Is defined as illegal in of itself by a government, then sure, there's no argument against dismissing it as illegal. Just like PGP falling under being illegal (from another comment) because it could exist as:

> digital copies of the binaries and source code were prohibited for export as a munition

There's no successful argument one can make against such illegality to said government. And I wouldn't bother, such people will never acquiesce if they haven't felt the lack of sufficient recourse to [1] (because they quite possibly may gain a lot of benefits by being indirectly or directly involved in [1])

Luckily, reality isn't so rigid as to what people (or even other traditional governments abroad) will actually accept (then and now) and have sovereignty over deciding what they want for themselves and side stepping based on what can actually be enforced in totality in practice regardless of what any given institutionalized jurisdiction may think of it.

Re: Why I Wrote PGP (1999)

#67
post #7

I have sooooo many lost emails due to lost pgp configurations. Encrypted blobs in my mail spools.

The fact that you couldn't restore no matter what without the key speaks for pgp rather than against, in my book.

By comparison I have very little trust in modern IM software.

Re: Why I Wrote PGP (1999)

#68

There’s something… different about how people (techie people are most of my sample) would write before the 00’s. I’m not sure if it has to do with the medium, or the constraints of the time, but reading it always fills me with something I can best describe as peace/nostalgia. The belief that technology honestly can change the world for the better and that the most influential people driving it have good motives inste…

I suspect it is that there are a lot less abstractions and the thinking is much more moored in the material. In this profoundly technical article there is barely even a mention of computers or algorithms, and the vision is of a more analogue world (of paper bills, phone companies, physical wiretaps, human agents).

The modern internet is almost entirely clashes of abstract concepts. It also shows up in the slight breakdown on the internet of basic, verifiable facts. Nobody is relying on real-world stimulus to form opinions. It is a bit draining to keep up with.

That and there is less optimism because it is clear how slowly the world changes. Consider the "The government has a track record that does not inspire confidence..." paragraph. Written 30 years ago, part of it could credibly be talking about Assange, have names swapped for Trump, etc. At some point intelligent people are going to get jaded pretending that this is new based on the overwhelming evidence that the internet gives us access to.

Re: Why I Wrote PGP (1999)

#69
post #24
post #18

Earlier quoted context omitted.

You're absolutely correct. But unless the tools are designed so the average user can easily manage their own keys, it's basically PGP again. I think U2F/WebAuthn dongles actually could solve this problem but there are all sorts of new problems now like "how do I use this with my iPhone and also with my PC" or "what happens when lose my (physical) keychain with my dongle".

This is an especially funny thing to say when you compare the number of daily users Signal --- itself a niche cryptosystem --- has to PGP.

Funny term, “niche cryptosystem”

It’s like a frog, which is about to beat a frog with a wand, frog says, come on, I am already a frog!

Re: Why I Wrote PGP (1999)

#70
According to the legend, they weren't allowed to publish PGP on the internet because US laws forbade exporting of cryptographic tools, so they made a book with the entire source code and shipped that overseas.
Post reply on HN