12 ms·
Why I Wrote PGP (1999)
- rsyring 5y agoCreated 1991, updated 1999
- forgotmypw17 5y agoI think one of the best arguments for using PGP is how long it's been around and is still in use, for two reasons: The encryption mechanisms have been tested many times by many people. And the tooling exists for just about platform and language.
- tptacek 5y agoThe encryption mechanisms were tested, found wanting, and replaced in subsequent systems. PGP's installed base prevented them from keeping up. As a result, the constructions used in PGP today are essentially reviled by cryptography engineers.
- paulryanrogers 5y agoReally? The fundamentals or the implementation?
- tptacek 5y agoThe fundamentals. I mean, very much both! But the fundamentals are the more important part.
- forgotmypw17 5y agoWhat do you mean by "constructions"?
- tptacek 5y agoCryptographic constructions.
- forgotmypw17 5y agoCan you recommend a text about this? As a layperson, I'm still having trouble understanding what you mean by that.
- zahllos 5y agoHere's a quick overview: We have what we call primitives that achieve a certain goal. For example AES on its own does a pretty good job of being a block cipher. However it doesn't fulfil all our expectations for actual secure communication alone and for this we need to use it as part of a slightly larger scheme. These are the constructions tptacek refers to. How we put together the bits we have in a way that meets our expectations, which we refer to as semantic security. This doesn't just apply to AES but also to public key crypto as well. This might seem quite abstract, so let me put it this way: AES alone doesn't know if the ciphertext you feed it has been modified by an attacker. It will simply process that data with a given key. The decrypting software might notice and report an error (the message will look garbled), and there are circimstances where this can actually be exploited to reveal information. This is not what we expected to happen. We've learned a lot about this since the early 90s. Many modern primitives actually come with all the parts we would call a construction built in, to avoid potential misuse (although these schemes are for the most part academic right now). Almost all modern systems combine primitives like AES in such a way as to meet our expectations. Except perhaps Telegram but nobody knows what they're smoking. If you want an actual textbook, Introduction to Modern Cryptography by Katz and Lindell, or Cryptography Made Simple by Nigel Smart will cover this in plenty of detail, and are also good all round introductions to most areas of cryptography by leading experts. I learn towards the book by Smart, but either will be perfectly fine.
- breput 5y agoThis is pure snark and should be downvoted into oblivion, but by 2015 even Phil Zimmerman couldn't figure out the tooling: "Sorry, but I cannot decrypt this message. I don't have a version of PGP that runs on any of my devices" https://twitter.com/josephbonneau/status/638772283713060864 https://twitter.com/josephbonneau/status/638772283713060864
- forgotmypw17 5y agoStrange, I've found it for all major platforms. I don't do much encryption, but keygen and message signing works for me on Android, iOS, GNU+Linux, FreeBSD, Mac, and Windows.
- breput 5y agoPGP felt so subversive back in the day. Key signing parties[1] and porting the "international" version[2] to run on the Amiga. And the very real threat that the Clipper Chip[3] would lead to the outlawing of all other encryption methods. [1] https://en.wikipedia.org/wiki/Key_signing_party https://en.wikipedia.org/wiki/Key_signing_party [2] https://www.unix-ag.uni-kl.de/~conrad/krypto/pgp263.features.html https://www.unix-ag.uni-kl.de/~conrad/krypto/pgp263.features... [3] https://en.wikipedia.org/wiki/Clipper_chip https://en.wikipedia.org/wiki/Clipper_chip
- alfiedotwtf 5y agoThe government thinks it still is.
- breput 5y agoPGP's biggest weakness was that it was too early. There was no normal user accessible software available. No regular person was going to establish the web of trust or use command line utilities. So now we have easy, strong encryption and the keys are controlled by...someone. Definitely not the user, though. Funny story - even Phil Zimmerman can't use PGP: https://twitter.com/josephbonneau/status/638772283713060864 https://twitter.com/josephbonneau/status/638772283713060864 So maybe it is just a hard problem.
- jandrese 5y agoNo, PGP's weakness is that the Web of Trust is an unworkable solution for the general population for key exchange. It works fine for a you and your circle of crypto nerds, but as a general solution it's impossible. IMHO this is a case where perfect was the enemy of good. Many possible solutions were rejected because there was a possibility that someone could MITM your first contact, even though in the real world this is unlikely. The key registries were almost a solution but none of them ever gained enough traction to be a default solution and mail clients were strangely hesitant to incorporate them even when they did implement PGP. PGP was always half of the solution. Sadly they never figured out the other half. Microsoft almost got it working with Exchange, but even then you usually it only works on a single domain at a time. You can't use encrypt an email to someone at a different company even if they are using Exchange.
- cowmix 5y agoI have sooooo many lost emails due to lost pgp configurations. Encrypted blobs in my mail spools.
- nolok 5y agoThe fact that you couldn't restore no matter what without the key speaks for pgp rather than against, in my book. By comparison I have very little trust in modern IM software.
- approxim8ion 5y agoDo you think I could restore an encrypted signal backup without the key?
- nolok 5y agoYou missed my point which was not about whether you could, but about whether someone else could, either from your backup or from a entirely different copy they could have acquired during the original transmission. Same way I wouldn't trust a gmail/outlook/whatever-apple-named-theirs automatic mail encryption the way I can trust a bulky weird to use pgp one.
- approxim8ion 5y ago> but about whether someone else could... Why would they be able to? I haven't heard of any such exploits for Signal, and their crypto as well as their app-related code is open, well-documented, and repeatedly audited.
- nolok 5y agoYou're focusing on signal for some reason, ignoring the larger point being made Also: > their crypto as well as their app-related code is open, well-documented, and repeatedly audited. And since nobody builds their executable from source, it doesn't at all guarantee anything about the version I have on my phone right now, unless I do a lot of extra check that virtually no one will do on every update. If whatever entity* aiming for me chose to target a specific update at me on the store that did a clear copy send on the side, I would never know. * Say, China aiming for a chinese user on whatever chinese app store is popular at the moment, to take the most obvious (but clearly not only) exemple
- deleted 5y ago[deleted]
- j0e1 5y ago> But while technology infrastructures can persist for generations, laws and policies can change overnight. Once a communications infrastructure optimized for surveillance becomes entrenched, a shift in political conditions may lead to abuse of this new-found power. Political conditions may shift with the election of a new government, or perhaps more abruptly from the bombing of a federal building. Prescient.
- tptacek 5y agoI guess. Pretty much everyone was saying that back then.
- forcry 5y agoVaccine mandates comes to mind. Imagine Hitler had mandatory vaccines at his disposal, set in place by some benevolent administration for a seemingly good cause. He wouldn't have needed gas chambers that just does not scale as much.
- dang 5y agoWe've banned this account for posting the same things over and over. Single-purpose accounts are not allowed here, and using the site primarily for political/ideological battle is also not allowed here. Please don't create accounts to break HN's rules with. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- forcry 5y agoSo I posted a response to your comment that got instantly flagged and hidden. Wonder if HN employs automatic scanning and flagging for keywords.
- b0rsuk 5y agoThe technotronic era involves the gradual appearance of a more controlled society. Such a society would be dominated by an elite, unrestrained by traditional values. Soon it will be possible to assert almost continuous surveillance over every citizen and maintain up-to-date complete files containing even the most personal information about the citizen. These files will be subject to instantaneous retrieval by the authorities. (Zbigniew Brzezinski, Between Two Ages, 1971)
- breput 5y agoMatthew Green does a pretty good job picking apart PGP's issues, although he completely fails at suggesting alternatives and also completely ignores non-email use cases. https://blog.cryptographyengineering.com/2014/08/13/whats-matter-with-pgp/ https://blog.cryptographyengineering.com/2014/08/13/whats-ma...
- aborsy 5y agoWith attacks on encryption and privacy by governments and big companies, we need more tools such as PGP. The user should hold the keys, not a government or company. Technical aspects are generally secondary, and should improve, but we shouldn’t dismiss good approaches due to implementation details.
- breput 5y agoYou're absolutely correct. But unless the tools are designed so the average user can easily manage their own keys, it's basically PGP again. I think U2F/WebAuthn dongles actually could solve this problem but there are all sorts of new problems now like "how do I use this with my iPhone and also with my PC" or "what happens when lose my (physical) keychain with my dongle".
- toastal 5y agoNot necessarily an endorsement (although I do own one), OnlyKey lets you store and use PGP keys in this way as well as U2F, OTP, etc.
- tptacek 5y agoThis is an especially funny thing to say when you compare the number of daily users Signal --- itself a niche cryptosystem --- has to PGP.
- breput 5y agoThe Signal protocol is very well designed but the implementation requires a telephone number (I know it is coming). That's a step removed from PGP which can be completely offline.
- uncomputation 5y agoThere’s something… different about how people (techie people are most of my sample) would write before the 00’s. I’m not sure if it has to do with the medium, or the constraints of the time, but reading it always fills me with something I can best describe as peace/nostalgia. The belief that technology honestly can change the world for the better and that the most influential people driving it have good motives instead of profit motives. And they were real visionaries most of the time. By contrast, anything seemingly after the dot com boom (I can’t draw a clear line, this is just throwing a dart) seems, I don’t know how to describe it. Too self-aware, too clever? It’s similar to the contrast between HN and other forums/social media out there. I’m not sure, but whenever an older article or something shows up, I usually enjoy it. Perhaps it’s that only the best have survived till now.
- deleted 5y ago[deleted]
- baby 5y agoVery similar to the cryptocurrency field. Lots of noise nowadays.
- dannyw 5y agoBitcoin was born in the aftermath of the global financial crisis and the occupy wall street movement.[1] Events where, giant banks and institutions received trillions of dollars in unprecedented bail outs while 'main street' suffered with record unemployment, foreclosures, and destruction of small businesses. People rightfully realised that perhaps government should not have absolute and total control of the monetary supply and financial system. That a 'Plan B' may be in order. Unfortunately, today it's 90% people trying to get rich quick. [1]: https://en.bitcoin.it/wiki/Genesis_block https://en.bitcoin.it/wiki/Genesis_block
- cinquemb 5y ago> Unfortunately, today it's 90% people trying to get rich quick. And that is, unsurprisingly (and quite banally), used by many detractors to dismiss it all while handwaving away: > Bitcoin was born in the aftermath of the global financial crisis and the occupy wall street movement.[1] Events where, giant banks and institutions received trillions of dollars in unprecedented bail outs while 'main street' suffered with record unemployment, foreclosures, and destruction of small businesses. > People rightfully realised that perhaps government should not have absolute and total control of the monetary supply and financial system. Like people still hand wave away all the metadata and other work-arounds to compromising popular crypto systems that are highly touted because they are popular/convenient/etc or all the "get rich quick" mentality/motivations that exist outside of cryptocurrencies and have always existed…
- jonathankoren 5y agoMy undergrad university library has (had?) a bound copy of PGP source code on the stacks for checkout. If I remember correctly, digital copies of the binaries and source code were prohibited for export as a munition, but publishing the source code in a book, made it a book, and thus eligible for export.
- bariswheel 5y ago'The only way to hold the line on privacy in the information age is strong cryptography.'
- IanClarke 5y agoEverything is hackable. Connect a computer to the internet and you basically have lost. We know that today, encryption isn't the final solution when there are hackers and social engineering.
- Gradient-Ascent 5y agoEverything is hackable. Connect a computer to the internet and you basically have lost. We know that today, encryption isn't the final solution when there are hackers and social engineering.
- TeeMassive 5y agoIs there a good websites listing the ways being spied on can affect you personally? Would be great every time a "I don't care if the NSA watch my dick picks, bro" naive person bring this to my face again.
- imiric 5y agoNot really a website, but this paper[1] breaks down and refutes the "I've got nothing to hide" argument quite well. [1]: https://papers.ssrn.com/sol3/papers.cfm?abstract_id=998565 https://papers.ssrn.com/sol3/papers.cfm?abstract_id=998565
- atoav 5y agoWell my main reasons outside them are: A) Abuse. The assumption that only true, evil crimes mean surveilance technology will be used is wrong. It will be used to harass partners, exes, famous people, activists, journalists, people with the wrong skin tone etc. In fact all of this happened already. B) Power. Giving a government global surveilance capabilities also increases it's power into a realm where the government's nature will change. It will declare things being its business that were formely none of its business. It will go good for a while because our aystems change slowly, but at one point authotarians will take power and then you provided them with the perfect tool to target, assassinate, control and enforce. C) Vulnerable groups. There are certain professions and groups that enjoy protection from government spying for a good reason. If you accept surveilance for yourself, you are also accepting it for them. And the next time you might really need your client-attorny-priviledge or your doctor-patient communication to stay private, it might be too late. These are mostly "systemical" perspectives, but they are much stronger for me than "It is gross, they should not watch it".
- deleted 5y ago[deleted]
- pdkl95 5y agoIn addition to the reason already mentioned, one of the most important reasons privacy is necessary is how people - especially children - discover new aspects of their own identity, personality, and interests. Children will experiment when they think their parents aren't watching. Freedom to experiment and explore their interaction with the world is obviously very important for children, but this use of privacy never really goes away. Consider if you wanted to learn an instrument but have never played music before (or any other difficult skill). You probably want the freedom to practice badly for a while. If you had to practice knowing people were watching you, would you feel as free to experiment learning this type of skill? Problems of abuse and power are obviously very important concerns. However, I believe the chilling effect surveillance has on people will cause a major shift away from people experimenting with learning new things and exploring their hobbies will become an insidious, system damage to culture and social liberty.
- deleted 5y ago[deleted]
- dang 5y agoSome past threads: Why I Wrote PGP (1999) - https://news.ycombinator.com/item?id=10581971 https://news.ycombinator.com/item?id=10581971 - Nov 2015 (47 comments) Why I Wrote PGP (1999) - https://news.ycombinator.com/item?id=6823668 https://news.ycombinator.com/item?id=6823668 - Nov 2013 (109 comments)
- lottin 5y agoAccording to the legend, they weren't allowed to publish PGP on the internet because US laws forbade exporting of cryptographic tools, so they made a book with the entire source code and shipped that overseas.
- pawal 5y agoYes, export regulations were heavy back then. To have proper SSL in your Netscape, you had to import this patch file from Australia. And then we had this whole Crypto Wars thing going on. Look at Steven Levy's excellent book on the subject, or search on the Wired archives.
- atoav 5y agoI wouldn't call it legend, it was released via MIT press. See: https://en.m.wikipedia.org/wiki/Pretty_Good_Privacy https://en.m.wikipedia.org/wiki/Pretty_Good_Privacy
- caf 5y agoAs I heard it at the time, they had to actually physically carry the book overseas.
- jrochkind1 5y agoIt's not a legend, it's easy enough to confirm. https://philzimmermann.com/EN/essays/BookPreface.html https://philzimmermann.com/EN/essays/BookPreface.html
- arminiusreturns 5y agoFrom an old comment of mine on the topic: https://youtu.be/sKOk4Y4inVY?t=518 https://youtu.be/sKOk4Y4inVY?t=518 [1] 1. "In 1995, there was a debate at Harvard Law School – four of us discussing the future of public key encryption and its control. I was on the side, I suppose, of freedom. It’s where I try to be. With me at that debate was a man called Daniel Weitzner who now works in the White House making Internet policy for the Obama administration. On the other side was the then Deputy Attorney General of the United States and a lawyer in private practice named Stewart Baker who had been chief council to the National Security Agency, our listeners, and who was then in private life helping businesses to deal with the listeners. He then became, later on, the deputy for policy planning in the Department of Homeland Security in the United States and has much to do with what happened in our network after 2001. At any rate, the four of us spent two pleasant hours debating the right to encrypt and at the end there was a little dinner party at the Harvard faculty club, and at the end, after all the food had been taken away and just the port and the walnuts were left on the table, Stuart said, “All right, among us now that we are all in private, just us girls, I’ll let our hair down.” He didn’t have much hair even then, but he let it down. “We are not going to prosecute your client, Mr. Zimmermann," he said. “Public key encryption will become available. We fought a long, losing battle against it, but it was just a delaying tactic.” And then he looked around the room and he said, ”But nobody cares about anonymity, do they?" And a cold chill went up my spine and I thought, all right, Stuart, and now I know you’re going to spend the next twenty years trying to eliminate anonymity in human society and I am going to try to stop you and we’ll see how it goes. And it’s going badly. We didn’t build the net with anonymity built in. That was a mistake. Now we are paying for it." -Eben Moglen
- vbezhenar 5y agoTor is the anonymous net. It might be not perfect against targeting state-level attackers, but generally it works and delivers its promise.
- user3939382 5y ago> it works Does it? Dragnet surveillance might not easily inspect all Tor traffic, but it can easily see who is using it, flag those identities, and put them on a list for increased scrutiny. Unless a major web browser has it enabled by default, I don’t see it delivering on its promise.
- jtsuken 5y agoMy favourite conspiracy theory is that the whole Trevor Martin/George Zimmerman affair (https://en.wikipedia.org/wiki/Killing_of_Trayvon_Martin https://en.wikipedia.org/wiki/Killing_of_Trayvon_Martin) was pushed so hard by US media mainly to suppress any reference to George Zimmerman and PGP after the publication of Snowden's papers.
- schwartzworld 5y agoCouldn't be genuine outrage about a child getting murdered in cold blood
- stavros 5y agoDid you mean Phil Zimmermann? The two last names aren't spelled the same (and it peeves Phil when people forget the second n).
- greggyb 5y agoYou've got at least two incorrect names in your post, and possibly three. Trayvon (not Trevor) Martin was killed by George Zimmerman. Phil Zimmermann (different last name than George 'nn' vs 'n') wrote PGP.
- upofadown 5y agoI think that sometimes we forget that PGP is primarily a political statement. It makes the world a better place simply by existing.
- DrStartup 5y agoPGP key server on a eth dapp?