Live data from Hacker News

Email Encryption Software Relies on One Guy, Who Is Going Broke

propublica.org

411–420 of 469 posts

Re: Email Encryption Software Relies on One Guy, Who Is Going Broke

#411
post #326

I would like to repost a comment from reddit[1] that makes some good points: "That title is pretty laughable. Enterprise E-Mail Encryption solutions do NOT use gnupg, and most enterprise customers do not even use openpgp, they use X.509/SMIME. I know the world top 10 server side enterprise e-mail encryption solutions and the majority uses java with either bouncycastle or ajak encryption, for PGP or openssl/bouncycast…

I tried to submit a patch for GnuPG that would enable it to use "proprietary" PKCS#11 smart-cards instead of "open" OpenPGP smart-cards. Line of though being, users may already have S/MIME generated keys on their smart-cards, so why not use the same keys with PGP too? In the end, a key is just a number.

The request was refused [1] with ridiculous arguments [1] about PKCS#11 not being "needed in free software world".

After that, I started playing with S/MIME and found out it was much more user-friendly than GPG. (After the initial setup.)

[1] Here you can find links to relevant threads: http://zvrba.net/software/gpg_pkcs11.html

Re: Email Encryption Software Relies on One Guy, Who Is Going Broke

#413
post #71

Earlier quoted context omitted.

I freely confess to being flabbergasted by these displays of less-than-rigorous thought processes. How would a free software project 'pay it forward'? They are in a very similar position, aren't they? Edit: For some reason, I can't reply to child comments (probably a cool-off time-out at work?). Just a short note here, then: $1.25e6 for the FSF translates to 10 developers like Koch being paid (the donation page quote…

There are many free software projects that are decently or well funded. They have no problem meeting their donation requests, and having a good budget year over year. These projects are usually end user facing, in a way that their dependencies aren't. It seems reasonable that these projects should consider adding items to their budget to redistribute funds to projects that they depend on. Some probably do this, howev…

Name a few. I know very very few and the funding goals are very very modest most of the time (they don't really convey the idea of full time devs)

Re: Email Encryption Software Relies on One Guy, Who Is Going Broke

#414

I've been complaining about this on HN before; lot's of startups built chat apps on top of GPG during the whole Snowden thing and Werner can't raise $120,000. I'm really glad Pro Publica picked it up, but I also think we need to change to way we think about critical software like GPG. The GPG Tools team (GPG for Apple Mail) recently stated they need to charge for the tool in the future because they simply can't handl…

>I also think we need to change to way we think about critical software like GPG Maybe the lesson here is not to license important software under such permissive licenses. Make it open source and free for non-commercial, require a donation if it is used in a commercial product. I don't really see how you can give something away for free and then expect companies to volunteer to pay for it.

It's nice in theory, but then the defintiion of "commerical" can mess it up, and can be subject to how judges (anywhere in the world interpret it). A german court ruled that "non-commerical" (in a CC licence) meant only for personal use, and non-personal entities had to pay. https://www.techdirt.com/articles/20140326/11405526695/germa...

Re: Email Encryption Software Relies on One Guy, Who Is Going Broke

#415

Here are Felix ("fefe") von Leitner's comments http://translate.google.com/translate?js=n&sl=de&tl=en&u=htt... Not that I would share his views, but he is a relatively well known German security expert and free software activist (dietlibc). He knows GnuPG pretty well and basically says: Werner, you don't deserve our donations, stop crying, get a day job and maintain GnuPG in your spare time.

[deleted]

Re: Email Encryption Software Relies on One Guy, Who Is Going Broke

#416
post #42

Earlier quoted context omitted.

> I wonder sometimes if this is the legacy that RMS was thinking about. No. Free software was never about no money being involved. In fact, RMS himself used to get a lot of money by selling free software. Back in the day when Emacs was too big for the internet, RMS used to sell Emacs tapes at 100 USD each (with documentation and source code, of course). In fact, he still thinks that you should be charging money for d…

> I have really hoped that the current app store model would turn out to be a great way to sell free software. A convenient way to pay, and you can download and install whatever you want. Optionally, you can have a link to the source code. > Sadly, it doesn't seem to be happening this way. I don't understand why not. Perhaps I too am being too idealistic. As an indie app developer, I already struggle with people ripp…

You can still retain trademark rights and copyright to art assets, which for most apps should be as effective as copyright to prevent ripoffs. (Which isn't saying much. Copyright doesn't seem to be very effective to prevent ripoffs, unfortunately.)

Re: Email Encryption Software Relies on One Guy, Who Is Going Broke

#417
The whole commercial industry is relying on open-source components, arbitraging what should cost money in the first place to build a business, then assuming that people do it for the fun primarily (which is not completely untrue), maintenance though costs money, but to give edits back should be the role of the earning community, not the original founder. Licensing might help here, just too many people are offering their works for free (read there will always be somebody with a free alternative). It's kinda weird to expect something else and proclaim free software..

Re: Email Encryption Software Relies on One Guy, Who Is Going Broke

#418
post #4

Calling GnuPG "email encryption software" really understates its importance. It's also used in countless applications to encrypt data at rest, and GPG signatures are used to secure the distribution of software. For instance, GPG is an essential part of the package managers of Debian, Ubuntu, and RedHat. Here is a link to the donation page: https://gnupg.org/donate/index.html

Seems odd that the MANY projects dependent on GPG don't donate enough to GPG to employ one guy. Do Free Software project with funding 'pay it forward' to the volunteers on other projects they heavily depend on? (I don't really know) If not, they deserve to suffer the consequences.

Open Source = The kindness of strangers.

Re: Email Encryption Software Relies on One Guy, Who Is Going Broke

#419

GNU is awesome in the way that 'Citizen Kane' is awesome. It is awesome because of what it accomplished given the context in which it was created. The context has changed but GNU, by and large, has not. "Free Software" gave us BSD and Linux, but it is also partially responsible for the privacy issues of Google and Facebook (neither of which would be as competitive if they had to pay licensing fees to Microsoft and Or…

Thought experiment: if there was no GPLv2, only GPLv3, would the same concerns apply?

Have you come across promising alternative models? These would need to exhibit some properties of GNU-style free software and some properties of cash-cow commercial software. Thus, technical run-time mechanisms for software composition will play a key role in the new legal framework, just as linking (e.g. GPL vs LGPL) did in the GNU ecosystem.

Today we have microservices, containers, etc - which allow composition of software with different licenses, T&C and biz models.

Re: Email Encryption Software Relies on One Guy, Who Is Going Broke

#420
post #340

Earlier quoted context omitted.

> There are many free software projects that are decently or well funded. They have no problem meeting their donation requests, and having a good budget year over year. Too bad OpenSSL wasn't one of them until after the big "heartbleed" incident. The core infrastructure projects don't seem to get as much funding as they ought to, especially given almost everyone relies on them (even if they don't realize it). Prior t…

Over the next three years, the Linux Foundation will receive a combined total of $3.9 million from Google, Intel, Amazon and others to fund core infrastructure projects such as OpenSSL. Sounds good until you take a step back... > Intel will invest "$300 million to help improve the pipeline for women and minorities, actively support the hiring and retention of diverse candidates, and fund programs that support the pos…

It's interesting with the Outreach programme in GNOME (I think that's what it's called), because if you periodically look at planet.gnome.org, there are interesting things going on with developers within that outreach programme.

But there are also justified backlashes to the programme, given that there is a perceived priority given to the programme in some areas instead of writing software. The argument is that not everyone and their dog needs to be involved with writing software, so why should we encourage them to? You don't see such pushes in dentistry, the car industry or anything like that; "Are you a WOMAN? Then join the car industry!".

Strangely we do in IT though, where it is the belief that we should make EVERYONE code!

The "I will fight you and I will win" response from Emmanuelle Bassi is a particularly horrible/strange/passionate reaction from one of the guys involved with the programme: see http://blogs.gnome.org/tvb/2014/09/12/im-looking-at-you/comm...

Post reply on HN