Live data from Hacker News

Why I Wrote PGP (1999)

philzimmermann.com

191–194 of 194 posts

Re: Why I Wrote PGP (1999)

#191
post #189

Earlier quoted context omitted.

> but about whether someone else could... Why would they be able to? I haven't heard of any such exploits for Signal, and their crypto as well as their app-related code is open, well-documented, and repeatedly audited.

You're focusing on signal for some reason, ignoring the larger point being made Also: > their crypto as well as their app-related code is open, well-documented, and repeatedly audited. And since nobody builds their executable from source, it doesn't at all guarantee anything about the version I have on my phone right now, unless I do a lot of extra check that virtually no one will do on every update. If whatever enti…

> And since nobody builds their executable from source

How many people build gnupg or gpg-agent from source?

> Whatever entity

Seems like something your local apt/pacman repository mirror host could do too.

It's a fair concern. I'm not trying to be disingenuous, sorry if it comes off that way. I'm just focusing on Signal because you wrote "modern IM software".

Re: Why I Wrote PGP (1999)

#192

Earlier quoted context omitted.

Or alternatively, then came Internet for the masses. Before that a lid was kept on a huge part of the population, the dream of raw global information sharing turned out to be a nightmare our societies/species is no ready for.

It's the "Eternal September" or "September that Never Ended" for the internet in general. With mass use came mass marketing and a switch from authentic information dissemination Internet to pure and absolute profiteering of everything you see on the internet. Do a random search in Google (DDG, or Bing) of ANY term at all, and you will see that the full first page links to pages that wrote whatever content for a profi…

Wikipedia and community wikis also centralized (drained?) a lot of knowledge that might have otherwise existed on separately hosted sites linked through webrings.

Re: Why I Wrote PGP (1999)

#193
post #189

Earlier quoted context omitted.

You're focusing on signal for some reason, ignoring the larger point being made Also: > their crypto as well as their app-related code is open, well-documented, and repeatedly audited. And since nobody builds their executable from source, it doesn't at all guarantee anything about the version I have on my phone right now, unless I do a lot of extra check that virtually no one will do on every update. If whatever enti…

> And since nobody builds their executable from source How many people build gnupg or gpg-agent from source? > Whatever entity Seems like something your local apt/pacman repository mirror host could do too. It's a fair concern. I'm not trying to be disingenuous, sorry if it comes off that way. I'm just focusing on Signal because you wrote "modern IM software".

> How many people build gnupg or gpg-agent from source?

More people than those build signal from source

> Seems like something your local apt/pacman repository mirror host could do too.

Which is why I focus on build from source, and more people fo it for pgp than any im software out there.

Re: Why I Wrote PGP (1999)

#194

From an old comment of mine on the topic: https://youtu.be/sKOk4Y4inVY?t=518 [1] 1. "In 1995, there was a debate at Harvard Law School – four of us discussing the future of public key encryption and its control. I was on the side, I suppose, of freedom. It’s where I try to be. With me at that debate was a man called Daniel Weitzner who now works in the White House making Internet policy for the Obama administration.…

Thank you for posting this partial transcription. The whole speech is well worth listening to.

The loss of freedom has only accelerated since 2012, when Moglen gave this speech. I wish he would give them more often. He’s truly a voice for freedom, and there are not that many.

Post reply on HN