Live data from Hacker News

Email Encryption Software Relies on One Guy, Who Is Going Broke

propublica.org

201–210 of 469 posts

Re: Email Encryption Software Relies on One Guy, Who Is Going Broke

#201
post #4

Calling GnuPG "email encryption software" really understates its importance. It's also used in countless applications to encrypt data at rest, and GPG signatures are used to secure the distribution of software. For instance, GPG is an essential part of the package managers of Debian, Ubuntu, and RedHat. Here is a link to the donation page: https://gnupg.org/donate/index.html

Of course on the other hand, it is overstated here too.

Email Encryption Software Relies on One Guy

Err... did PGP recently go bankrupt?

Edit: Crap, it's worse, they seem to have been acquired by Symantec. Is it still any good?

Re: Email Encryption Software Relies on One Guy, Who Is Going Broke

#202
post #149

Earlier quoted context omitted.

> How would a free software project 'pay it forward'? As mentioned by the grandparent comment, GPG is in use by Debian, Ubuntu and RedHat package managers. Whether or not you count those three as free software they have plenty of money to pay forward to a piece of software that underpins their entire stacks.

The point isn't easily settled, it seems: I am having a hard time to find financial statements from Debian. Ubuntu, or rather Canonical, being a private company, doesn't seem to release financial information. The Ubuntu main page doesn't even provide a 'donate' link anymore. Which leaves RedHat, at last. A public company, of course[0]: Operating profit 2014: $ 1.3e9 Net total income 2014: $ 178.3e6 [0] http://investo…

Software in Public Interest handles debian's donations. The latest treasurer report from SPI can be found here: http://lists.spi-inc.org/pipermail/spi-general/2014-November...

For some reason SPI has not put out an annual report since 2012: http://www.spi-inc.org/corporate/annual-reports/2012.pdf

Re: Email Encryption Software Relies on One Guy, Who Is Going Broke

#203
post #8

I think the biggest problem is visibility for these projects. They need to be louder. In the case of openssl, I had no idea that they were severly underfunded (until heartbleed). Same for GPG until now. I didn't hear they asked for donations. And I doubt I'm the only one. So I quickly checked if maybe this was big on HN at a point and I just missed it. https://hn.algolia.com/?query=GPG%20donation&sort=byPopulari... h…

I'm wondering if there is a meta-donation page that lists a bunch of the most important open source projects, how you can donate to them and their yearly funding goals (and how many developers are being supported).

Freedom of the Press Foundation does this although they target projects and organizations that focus on issues related to the press and journalism.

Example: https://freedom.press/bundle/encryption-tools-journalists

Re: Email Encryption Software Relies on One Guy, Who Is Going Broke

#204
post #4

Calling GnuPG "email encryption software" really understates its importance. It's also used in countless applications to encrypt data at rest, and GPG signatures are used to secure the distribution of software. For instance, GPG is an essential part of the package managers of Debian, Ubuntu, and RedHat. Here is a link to the donation page: https://gnupg.org/donate/index.html

Thanks for the link, just donated!

(me too)

Interesting to see more people have donated so far in 2015 than the whole of 2014.

Re: Email Encryption Software Relies on One Guy, Who Is Going Broke

#205

For bitcoin donations, you can go to [1], which gives the address as 12LKeo24XCzgz6ASSxcUa8BvUfzkEyCpGq [2]. The address is not generated per user, and is dedicated to GnuPG. [1] https://www.wauland.de/en/donation.nojs.html [2] https://blockchain.info/address/12LKeo24XCzgz6ASSxcUa8BvUfzk...

Wow, check out today's donations. There are multiple 1+ BTC and one for 10 BTC. Over US$8000 donated today!

Re: Email Encryption Software Relies on One Guy, Who Is Going Broke

#206
post #99

Earlier quoted context omitted.

> You are using Ubuntu, I see from your profile. How much have you paid them? It's easier for businesses to write off these type donations (and make them for significant amounts) than for private individuals to do so.

If it's a registered non profit you can donate and 'write it off' too. The idea that a 'big company' should do the donating is short sighted. That big company is made up of individuals. If everyone reading this donated $100, the problem posed by the article would disappear.

My point is that it's probably easier to get a company that is turning a profit off of something to donate a single large sum, than to convince a million people to donate $1.

Re: Email Encryption Software Relies on One Guy, Who Is Going Broke

#207
post #71

Earlier quoted context omitted.

I freely confess to being flabbergasted by these displays of less-than-rigorous thought processes. How would a free software project 'pay it forward'? They are in a very similar position, aren't they? Edit: For some reason, I can't reply to child comments (probably a cool-off time-out at work?). Just a short note here, then: $1.25e6 for the FSF translates to 10 developers like Koch being paid (the donation page quote…

https://www.fsf.org/about/financial The FSF had revenue of 1.25 million in 2013. I'm not trying to comment on where it came from or where it went to. I'm only pointing out that they are not in a very similar position.

So… enough pay for about 20 developers?

Re: Email Encryption Software Relies on One Guy, Who Is Going Broke

#209

Earlier quoted context omitted.

Probably OpenBSD's signify. You are of course aware signatures don't solve the licensing problem however, which is a Trusted Client problem (i.e. unsolvable).

I'll check that out. Thank you!

By all means. Ed25519 (which underlies signify) is a pretty decent modern signature scheme. (tweetnacl.c also implements it, in less code.)

It also seems you want to expire things, so I do feel I have to warn you that signatures are a totally separate thing to a secure time source, which is a whole different bag of marbles.

However, since what you're designing sounds like a logic bomb/copy protection/DRM system, I must say what I've been saying for the last quarter-century or so: please do not design your software to deliberately fail. That is a bad call: trust me on this one. Any crypto that you do to support it, even if the crypto itself is sound, is just tapdancing around a failure state.

Re: Email Encryption Software Relies on One Guy, Who Is Going Broke

#210

Earlier quoted context omitted.

I don't see this happening with FFTW or Qt. Apparently selling exceptions is fine? I can imagine a market for selling GPG exceptions. Also, I know some free games are sold on app stores. Wesnoth comes to mind. Have people come to spite the Wesnoth developers and put the same game on the app store without a fee?

You only have to look at any thread here about copyright or piracy to see indignation at the very idea of charging money. People believe that software being free (for every definition of free) is a fundamental human right, and part of the justification made for piracy is that no one has the right to profit from software, and the for-profit distribution models need to be disrupted and undermined. You can list a couple…

You're arguing against a straw man. The free software community has stood by using free licenses and selling exceptions and dual licensing. The FSF explicitly sells its code and gives you the source along with it. The community holds that software should be free as-in libre, not free as-in beer. This is a distinction that has been made time and time again.

That is, you are always free to charge money, but you are not free to withhold source or prevent modifications/redistribution of those modifications, because this restricts the rights of other human beings. Or said another way, your freedom stops where my nose begins.

Post reply on HN