Live data from Hacker News

Why I Wrote PGP (1999)

philzimmermann.com

71–80 of 194 posts

Re: Why I Wrote PGP (1999)

#71

There’s something… different about how people (techie people are most of my sample) would write before the 00’s. I’m not sure if it has to do with the medium, or the constraints of the time, but reading it always fills me with something I can best describe as peace/nostalgia. The belief that technology honestly can change the world for the better and that the most influential people driving it have good motives inste…

To me, there was something to say vs people posting shit just to meet a quota. There seems to be much less thought/research/editing of content now. It wasn't so gamefied before HTML2.0 and social.

Re: Why I Wrote PGP (1999)

#72
post #64
post #3

PGP felt so subversive back in the day. Key signing parties[1] and porting the "international" version[2] to run on the Amiga. And the very real threat that the Clipper Chip[3] would lead to the outlawing of all other encryption methods. [1] https://en.wikipedia.org/wiki/Key_signing_party [2] https://www.unix-ag.uni-kl.de/~conrad/krypto/pgp263.features... [3] https://en.wikipedia.org/wiki/Clipper_chip

Yes, the only munition available on a t-shirt!

Did PGP did that too? I know DeCSS did this. Did they borrow the idea from PGP?

Re: Why I Wrote PGP (1999)

#73
post #70

According to the legend, they weren't allowed to publish PGP on the internet because US laws forbade exporting of cryptographic tools, so they made a book with the entire source code and shipped that overseas.

Yes, export regulations were heavy back then. To have proper SSL in your Netscape, you had to import this patch file from Australia. And then we had this whole Crypto Wars thing going on. Look at Steven Levy's excellent book on the subject, or search on the Wired archives.

Re: Why I Wrote PGP (1999)

#74
post #70

According to the legend, they weren't allowed to publish PGP on the internet because US laws forbade exporting of cryptographic tools, so they made a book with the entire source code and shipped that overseas.

I wouldn't call it legend, it was released via MIT press. See: https://en.m.wikipedia.org/wiki/Pretty_Good_Privacy

Re: Why I Wrote PGP (1999)

#75
From an old comment of mine on the topic:

https://youtu.be/sKOk4Y4inVY?t=518 [1]

1. "In 1995, there was a debate at Harvard Law School – four of us discussing the future of public key encryption and its control. I was on the side, I suppose, of freedom. It’s where I try to be. With me at that debate was a man called Daniel Weitzner who now works in the White House making Internet policy for the Obama administration.

On the other side was the then Deputy Attorney General of the United States and a lawyer in private practice named Stewart Baker who had been chief council to the National Security Agency, our listeners, and who was then in private life helping businesses to deal with the listeners. He then became, later on, the deputy for policy planning in the Department of Homeland Security in the United States and has much to do with what happened in our network after 2001.

At any rate, the four of us spent two pleasant hours debating the right to encrypt and at the end there was a little dinner party at the Harvard faculty club, and at the end, after all the food had been taken away and just the port and the walnuts were left on the table, Stuart said, “All right, among us now that we are all in private, just us girls, I’ll let our hair down.”

He didn’t have much hair even then, but he let it down.

“We are not going to prosecute your client, Mr. Zimmermann," he said. “Public key encryption will become available. We fought a long, losing battle against it, but it was just a delaying tactic.” And then he looked around the room and he said, ”But nobody cares about anonymity, do they?"

And a cold chill went up my spine and I thought, all right, Stuart, and now I know you’re going to spend the next twenty years trying to eliminate anonymity in human society and I am going to try to stop you and we’ll see how it goes.

And it’s going badly. We didn’t build the net with anonymity built in. That was a mistake. Now we are paying for it." -Eben Moglen

Re: Why I Wrote PGP (1999)

#76
post #63
post #14

Matthew Green does a pretty good job picking apart PGP's issues, although he completely fails at suggesting alternatives and also completely ignores non-email use cases. https://blog.cryptographyengineering.com/2014/08/13/whats-ma...

I am so tired of crypto experts criticizing PGP without suggesting an alternative. So much has been written, so many soapboxes have been climbed on, and yet there seems to be no good replacement. I deeply respect Philip Zimmermann for creating "pretty good privacy" rather than trying for "perfect privacy". PGP is exactly that: pretty good. Not great, not perfect, but pretty good indeed. And it's there. And it works.…

This article present some alternatives to PGP. https://latacora.micro.blog/2019/07/16/the-pgp-problem.html

Re: Why I Wrote PGP (1999)

#77

Is there a good websites listing the ways being spied on can affect you personally? Would be great every time a "I don't care if the NSA watch my dick picks, bro" naive person bring this to my face again.

Well my main reasons outside them are:

A) Abuse. The assumption that only true, evil crimes mean surveilance technology will be used is wrong. It will be used to harass partners, exes, famous people, activists, journalists, people with the wrong skin tone etc. In fact all of this happened already.

B) Power. Giving a government global surveilance capabilities also increases it's power into a realm where the government's nature will change. It will declare things being its business that were formely none of its business. It will go good for a while because our aystems change slowly, but at one point authotarians will take power and then you provided them with the perfect tool to target, assassinate, control and enforce.

C) Vulnerable groups. There are certain professions and groups that enjoy protection from government spying for a good reason. If you accept surveilance for yourself, you are also accepting it for them. And the next time you might really need your client-attorny-priviledge or your doctor-patient communication to stay private, it might be too late.

These are mostly "systemical" perspectives, but they are much stronger for me than "It is gross, they should not watch it".

Re: Why I Wrote PGP (1999)

#78

There’s something… different about how people (techie people are most of my sample) would write before the 00’s. I’m not sure if it has to do with the medium, or the constraints of the time, but reading it always fills me with something I can best describe as peace/nostalgia. The belief that technology honestly can change the world for the better and that the most influential people driving it have good motives inste…

I think FOSS didn't predict that work done by volunteers will be appropriated repackaged and sold by big corporations without sharing profits with contributors nor sharing any patches. This caused people to develop defensively - contribute as little as possible and only for their own benefits. Developers no longer wanted to be taken as fools.

Re: Why I Wrote PGP (1999)

#80

There’s something… different about how people (techie people are most of my sample) would write before the 00’s. I’m not sure if it has to do with the medium, or the constraints of the time, but reading it always fills me with something I can best describe as peace/nostalgia. The belief that technology honestly can change the world for the better and that the most influential people driving it have good motives inste…

One difference (in this article at least) is that there are no jokes or unnecessary cultural references. Another might be called moral clarity. Unfortunately, it's usually an illusion. We have much more experience with technologies invented under optimistic assumptions turning out to be a moral gray area at best, when you look at how they're used. I found this paper interesting: The Moral Character of Cryptographic W…

> One difference (in this article at least) is that there are no jokes or unnecessary cultural references. As someone who started his professional career in the mid 90s, working in what we now call cyber security, and having written both then and after a long gap… now. I was initially baffled and then somewhat put-off by the way style has changed between say 2000 and 2010. First I put it down to just being older. Then I wondered if authors were encouraged to “put more of you” into writing (which I am not a fan of unless you are explicitly writing autobiographically). Part of “bring your whole self to work”? Then I wondered if it was just an attempt to add colour to what may be a rather dry subject for anyone other than those working in our niche. Finally I thought that perhaps it was something a little more profound. A desire by the author to connect at some deeper level than the dry content, with an audience, a tribe if you will.
Post reply on HN