Live data from Hacker News

Why I Wrote PGP (1999)

philzimmermann.com

181–190 of 194 posts

Re: Why I Wrote PGP (1999)

#181
post #104

Earlier quoted context omitted.

The fact it is state built and state funded doesnt give me confidence that it protects you against state level adversary.

They built it for their spies, so they can exchange information without traces. And they popularize it, so metadata analysis becomes useless. It's unlikely to have vulnerabilities, because other states could find and use them.

If it was indeed built for spies as they claim then I would expect that they know how to track communications through it because you have to know when your spies are leaking materials or have gone rogue.

Re: Why I Wrote PGP (1999)

#183
post #142
post #114

Earlier quoted context omitted.

We had worse crises before that didn’t change societies so deeply. With 9/11 we started renouncing to the concept of freedom that we gained with illuminism and the French revolution. Then we started putting “safety” before everything else.

We had worse crises before that didn’t change societies so deeply During the Red Scare, loyalty review boards were instituted and civil servants insufficiently 'American' were sacked in the thousands.

[deleted]

Re: Why I Wrote PGP (1999)

#184
post #173

Earlier quoted context omitted.

> it works Does it? Dragnet surveillance might not easily inspect all Tor traffic, but it can easily see who is using it, flag those identities, and put them on a list for increased scrutiny. Unless a major web browser has it enabled by default, I don’t see it delivering on its promise.

Don't leave the onion network. It's the exit nodes where 1/3 are hostile.

Thats a really good point actually!

Re: Why I Wrote PGP (1999)

#185

Earlier quoted context omitted.

I am with you. But I think I know what it is, you touched on it and almost had it. It was indeed peace, we almost had it, world peace - feeling utopian and all loving in the 90s. Then came 9/11. It’s the single point in history where just about everything to do with American society can be defined to be before and after. Doesn’t matter what you think about the event and it’s authenticity as described, the fact of the…

Or alternatively, then came Internet for the masses. Before that a lid was kept on a huge part of the population, the dream of raw global information sharing turned out to be a nightmare our societies/species is no ready for.

It's the "Eternal September" or "September that Never Ended" for the internet in general. With mass use came mass marketing and a switch from authentic information dissemination Internet to pure and absolute profiteering of everything you see on the internet.

Do a random search in Google (DDG, or Bing) of ANY term at all, and you will see that the full first page links to pages that wrote whatever content for a profit (either by selling ads, or by a paywall, etc).

Long lost are sites like Xoom, Geocities or similar where people wrote about their knowledge just for the sake of it. Long gone are the "web rings" that took you into cliques of people wanting to share knowledge of some specific subject.

Nowadays the closest you can get to that sort of information is in forums like this or reddit (and this last is questionable). That's why adding "site:reddit.com" when searching for some opinion is becoming more useful compared to pure serach engine results.

Re: Why I Wrote PGP (1999)

#186
post #64

Earlier quoted context omitted.

Yes, the only munition available on a t-shirt!

Did PGP did that too? I know DeCSS did this. Did they borrow the idea from PGP?

And AACS as well.

I remember buying some FreeBSD disks from Walnut Creek CDROM in the 90s, these shipped to my home in Mexico. When they Arrived, apparently Kerberos was not included in the distribution because "it was not possible to export weapons outside of the USA". 12 year old me was completely puzzled at what that was about.

Re: Why I Wrote PGP (1999)

#187

Is there a good websites listing the ways being spied on can affect you personally? Would be great every time a "I don't care if the NSA watch my dick picks, bro" naive person bring this to my face again.

I met an American guy around 2005 who told me something that got me to think: He did not use any "public" email service (gmail, yahoo, hotmail, etc). When I asked him why, did he believe the government could do something to him? his answer was (heavily parphrased):

"It is not about what the government can to today with it, it is what the government will be able to do in the future"

You may believe that your dick picks are OK now and laugh at the thought of some FBI/NSA official having to comb those on a friday afternoon. But in 10/15 years time you may be in a situation where, said official will bring your dick-picks as evidence of how since so long ago you were a crazy sex maniac.

Re: Why I Wrote PGP (1999)

#188
post #151

Earlier quoted context omitted.

Do you think I could restore an encrypted signal backup without the key?

You missed my point which was not about whether you could, but about whether someone else could, either from your backup or from a entirely different copy they could have acquired during the original transmission. Same way I wouldn't trust a gmail/outlook/whatever-apple-named-theirs automatic mail encryption the way I can trust a bulky weird to use pgp one.

> but about whether someone else could...

Why would they be able to? I haven't heard of any such exploits for Signal, and their crypto as well as their app-related code is open, well-documented, and repeatedly audited.

Re: Why I Wrote PGP (1999)

#189
post #151

Earlier quoted context omitted.

You missed my point which was not about whether you could, but about whether someone else could, either from your backup or from a entirely different copy they could have acquired during the original transmission. Same way I wouldn't trust a gmail/outlook/whatever-apple-named-theirs automatic mail encryption the way I can trust a bulky weird to use pgp one.

> but about whether someone else could... Why would they be able to? I haven't heard of any such exploits for Signal, and their crypto as well as their app-related code is open, well-documented, and repeatedly audited.

You're focusing on signal for some reason, ignoring the larger point being made

Also:

> their crypto as well as their app-related code is open, well-documented, and repeatedly audited.

And since nobody builds their executable from source, it doesn't at all guarantee anything about the version I have on my phone right now, unless I do a lot of extra check that virtually no one will do on every update. If whatever entity* aiming for me chose to target a specific update at me on the store that did a clear copy send on the side, I would never know.

* Say, China aiming for a chinese user on whatever chinese app store is popular at the moment, to take the most obvious (but clearly not only) exemple

Re: Why I Wrote PGP (1999)

#190
post #90

My favourite conspiracy theory is that the whole Trevor Martin/George Zimmerman affair ( https://en.wikipedia.org/wiki/Killing_of_Trayvon_Martin ) was pushed so hard by US media mainly to suppress any reference to George Zimmerman and PGP after the publication of Snowden's papers.

You've got at least two incorrect names in your post, and possibly three.

Trayvon (not Trevor) Martin was killed by George Zimmerman. Phil Zimmermann (different last name than George 'nn' vs 'n') wrote PGP.

Post reply on HN