Live data from Hacker News

Email Encryption Software Relies on One Guy, Who Is Going Broke

propublica.org

1–10 of 469 posts

Re: Email Encryption Software Relies on One Guy, Who Is Going Broke

#3
Can someone explain why GPG in the person of Werner Koch isn't substantially funded under FSFE?

My first thought was the Software Freedom Conservancy. The only reasons I see for them not to take GPG under their wing are lack of will (but why?), sense of funding priorities (but why?), or the possibility that some GPG constituents would be concerned about associating GPG strongly with a US-based organization.

Re: Email Encryption Software Relies on One Guy, Who Is Going Broke

#4
Calling GnuPG "email encryption software" really understates its importance. It's also used in countless applications to encrypt data at rest, and GPG signatures are used to secure the distribution of software. For instance, GPG is an essential part of the package managers of Debian, Ubuntu, and RedHat.

Here is a link to the donation page: https://gnupg.org/donate/index.html

Re: Email Encryption Software Relies on One Guy, Who Is Going Broke

#5
post #2

There does seem to be a need for an "Internet fund". Pick 100 of the core free technologies that everyone relies on and pay people to maintain them.

I agree more would be better, but aren't there several now, such as the Free Software Foundation, the Software Freedom Conservancy, and the Apache Software Foundation?

Re: Email Encryption Software Relies on One Guy, Who Is Going Broke

#6
I've been complaining about this on HN before; lot's of startups built chat apps on top of GPG during the whole Snowden thing and Werner can't raise $120,000.

I'm really glad Pro Publica picked it up, but I also think we need to change to way we think about critical software like GPG. The GPG Tools team (GPG for Apple Mail) recently stated they need to charge for the tool in the future because they simply can't handle to amount of work anymore (it's still GPL) — the response from us was nothing but outrage.

// I just realized all of this is mentioned in the article. My bad.

Re: Email Encryption Software Relies on One Guy, Who Is Going Broke

#7
This is sad but not super surprising. Historically, if you had money and wanted a reasonable UI and cleaner integrations, you bought PGP (now from Symantec). GPG was always for people unwilling to pay.

For the record I donated. I'm just pointing out that writing something that's bundled and distributed as part of something else means nobody thinks about your project, or in many cases even realizes they're using it.

Re: Email Encryption Software Relies on One Guy, Who Is Going Broke

#8
I think the biggest problem is visibility for these projects. They need to be louder. In the case of openssl, I had no idea that they were severly underfunded (until heartbleed).

Same for GPG until now. I didn't hear they asked for donations.

And I doubt I'm the only one. So I quickly checked if maybe this was big on HN at a point and I just missed it.

https://hn.algolia.com/?query=GPG%20donation&sort=byPopulari... https://hn.algolia.com/?query=GPG%20fund&sort=byPopularity&p... https://hn.algolia.com/?query=GPG%20money&sort=byPopularity&...

Nope. It's not just me.

If not even the most technical people (that actually know what GPG and openssl are without looking it up) don't hear about this, how are regular people going to find out where to throw their donations at?

I think people would donate if they knew about it. I'm going to send this guy $100 and consider it a license fee, because he deserves it.

Re: Email Encryption Software Relies on One Guy, Who Is Going Broke

#10
post #5
post #2

There does seem to be a need for an "Internet fund". Pick 100 of the core free technologies that everyone relies on and pay people to maintain them.

I agree more would be better, but aren't there several now, such as the Free Software Foundation, the Software Freedom Conservancy, and the Apache Software Foundation?

If people like this are still falling through the cracks, clearly there aren't enough.
Post reply on HN