NODE 83639e53Re: Fixing pgp 2.6
Hal <hfinney@shell.portal.com>Mon, 16 May 94 18:18:43 PDT
I think there are some things being overlooked in this discussion.
First, note the strong hint in Schiller's message about operators of
key servers who accept pre-2.6 keys being guilty of contributory
infringement of the RSA patent. I think we can expect strong legal
pressure from RSA to shut down the remaining U.S. key servers, even
those which don't use illegal versions of PGP. They succeeded once in
shutting down the key servers which used PGP; they will succeed again
in shutting down the others due to the contributory infringement threat.
For the same reason, hopes of getting a non-RSA-approved "2.6a" (hacked
to be backwards compatible with 2.3) widely available in the U.S. are
not well founded. FTP sites which hold programs or even patch files to
allow 2.6 to interoperate with 2.3 will be targetted by RSA as
contributory infringers. In short, the legal advantages PGP 2.6 will
have over unapproved versions will be strong enough that it will be
widely used in the U.S.
However, this does not mean the loss of international encrypted
communications. The solution is simple. PGP 2.3a will be patched to
be compatible with PGP 2.6. I don't know what we'll call it,
"PGP2.3e", perhaps, where "e" is for Europe. 2.3e will have the speed
advantages of 2.3a, no copyright problems with RSAREF use, be perfectly
legal outside the U.S., and will interoperate with 2.6. Converting
from 2.3a to 2.3e will be no more difficult than converting from 2.2 to
2.3 was.
Although I hate Jim Bidzos' guts for what he has done to Phil, he holds
the legal upper hand for the next few years. The present course does
allow for wider use of encryption by the public, which we can all support.
Look at it rationally, and 2.6 is a step in the right direction.
Hal
P.S. It's possible that pre-2.6 keys will not interoperate with 2.6,
in which case users of both 2.6 and what I am calling 2.3e will have to
generate new keys. This is no great problem; people should make new
keys and retire their old ones every year or two anyway, IMO.
NODE 5bfc8084Re: Fixing pgp 2.6
Black Unicorn <unicorn@access.digex.net>Mon, 16 May 94 19:07:07 PDT
>
> For the same reason, hopes of getting a non-RSA-approved "2.6a" (hacked
> to be backwards compatible with 2.3) widely available in the U.S. are
> not well founded. FTP sites which hold programs or even patch files to
> allow 2.6 to interoperate with 2.3 will be targetted by RSA as
> contributory infringers. In short, the legal advantages PGP 2.6 will
> have over unapproved versions will be strong enough that it will be
> widely used in the U.S.
I hadn't considered this. My question is answered.
>
> However, this does not mean the loss of international encrypted
> communications. The solution is simple. PGP 2.3a will be patched to
> be compatible with PGP 2.6. I don't know what we'll call it,
> "PGP2.3e", perhaps, where "e" is for Europe. 2.3e will have the speed
> advantages of 2.3a, no copyright problems with RSAREF use, be perfectly
> legal outside the U.S., and will interoperate with 2.6. Converting
> from 2.3a to 2.3e will be no more difficult than converting from 2.2 to
> 2.3 was.
Frankly, I am really not interested in using PGP2.6 IN the U.S.
I am reluctant to support the active restriction of capability in a
software product by dignifying its underhanded tactics in using it.
More serious efforts at a stealth PGP which makes identification of the
creator of cyphertext near impossible is badly needed.
I wonder if a Mac version will be available by September.
I wonder if a Mac version of StealthPGP will ever be available.
I wish I had the time/know-how to create one myself.
>
> Hal
>
-uni- (Dark)
--
073BB885A786F666 nemo repente fuit turpissimus - potestas scientiae in usu est
6E6D4506F6EDBC17 quaere verum ad infinitum, loquitur sub rosa - wichtig!