// COMPLETE THREAD

compatibility with future PGP

27 expanded posts ยท every known parent and child

NODE b5719265compatibility with future PGP
The only change the future post-September PGP 2.6 messages will have
is a change in the version number byte from 2 to 3.  PC's little hack
not to check version numbers will work, but as a patch it's not the
most robust.  It would be more robust if it checked for the range
[2..3].

Another thing a patched 2.3 release would have to do to be fully
indistinguishable is to generate new version numbers itself after the
given date.

Eric
NODE 4858ef8dRe: compatibility with future PGP
You wrote:

| Another thing a patched 2.3 release would have to do to be fully
| indistinguishable is to generate new version numbers itself after the
| given date.

	While I understand that people prefer the 2.3 code because of
its availablility outside of the US, and speed advantages, I think
that its important to remember PGP has not really caught on in the US
because of questions about its legality.  I'm trying to push for the
widespread use of PGP 2.5 here at the Brigham & Women's hospital where
I work.  I can't push for version 2.3 for legal reasons.

	There is a significant advantage to pacthing both the US-legal
and world legal versions of PGP.  Both are useful & neccessary to the
future of strong encryption.  I've heard that 2.5 is available outside
of the US.  If this is so, would it make sense to make 2.5 the version
which is patched and enhamced as the standard?

Adam

-- 
Adam Shostack 				       adam@bwh.harvard.edu

Politics.  From the greek "poly," meaning many, and ticks, a small,
annoying bloodsucker.
NODE 67be9ebdRe: compatibility with future PGP
Adam Shostack says:
> You wrote:
> | Another thing a patched 2.3 release would have to do to be fully
> | indistinguishable is to generate new version numbers itself after the
> | given date.
> 
> 	While I understand that people prefer the 2.3 code because of
> its availablility outside of the US, and speed advantages, I think
> that its important to remember PGP has not really caught on in the US
> because of questions about its legality.  I'm trying to push for the
> widespread use of PGP 2.5 here at the Brigham & Women's hospital where
> I work.  I can't push for version 2.3 for legal reasons.

People overseas want to be able to use this program, too. There are
250 million people in the U.S., which constitutes under 1/20th of the
Earth's population. Quit being provincial. This discussion is about
what the other 4.75 billion people have to do to interoperate with the
brain-damaged MIT stuff.

Perry
NODE 74e96116Re: compatibility with future PGP
Date: Tue, 24 May 1994 13:06:22 -0400
    From: "Perry E. Metzger" <perry@imsi.com>

    There are 250 million people in the U.S., which constitutes under
    1/20th of the Earth's population.

These statistics are somewhat misleading given that the vast majority
of users that are on the net are in the U. S.  I suspect that the same
is true for computer users in general, but I'm much less certain.

I agree that this legal silliness is unfortunate, but I don't think
that it's especially terrible that Adam would like to be able to
advocate PGP use at work without putting himself at risk.

I think it's great that patches are coming out to bridge the gaps
between 2.3 and 2.6 from either direction.  It's also nice that the
newer versions of PGP appear to have a propensity toward travel :-)

			Rick
NODE f168821eRe: compatibility with future PGP
Rick Busdiecker says:
>     There are 250 million people in the U.S., which constitutes under
>     1/20th of the Earth's population.
> 
> These statistics are somewhat misleading given that the vast majority
> of users that are on the net are in the U. S.  I suspect that the same
> is true for computer users in general, but I'm much less certain.
> 
> I agree that this legal silliness is unfortunate, but I don't think
> that it's especially terrible that Adam would like to be able to
> advocate PGP use at work without putting himself at risk.

You've misunderstood. The point is only that overseas users,
technically speaking, do not have access to 2.[56], and might want
patches. I didn't say anything about whether Adam should be running
2.[56] on his machine.

Perry
NODE 467d6c0fRe: compatibility with future PGP
> Rick Busdiecker says:
> >     There are 250 million people in the U.S., which constitutes under
> >     1/20th of the Earth's population.
> > 
> > These statistics are somewhat misleading given that the vast majority
> > of users that are on the net are in the U. S.  I suspect that the same
> > is true for computer users in general, but I'm much less certain.
> > 
> > I agree that this legal silliness is unfortunate, but I don't think
> > that it's especially terrible that Adam would like to be able to
> > advocate PGP use at work without putting himself at risk.
> 
> You've misunderstood. The point is only that overseas users,
> technically speaking, do not have access to 2.[56], and might want
> patches. I didn't say anything about whether Adam should be running
> 2.[56] on his machine.

That is a snotty answer to avoid answering the question, Perry.  Non-US/
Canadian users weren't supposed to have access to PGP in the first place,
so what's the problem?  If they want it, they can probably get it from the
place where they got PGP 2.X in the first place.
-- 
Ed Carp, N7EKG/VE3		ecarp@netcom.com		519/824-3307
Finger ecarp@netcom.com for PGP 2.3a public key		an88744@anon.penet.fi
If you want magic, let go of your armor.  Magic is so much stronger than
steel!        -- Richard Bach, "The Bridge Across Forever"
NODE 54973f50Re: compatibility with future PGP
Ed Carp says:
> > You've misunderstood. The point is only that overseas users,
> > technically speaking, do not have access to 2.[56], and might want
> > patches. I didn't say anything about whether Adam should be running
> > 2.[56] on his machine.
> 
> That is a snotty answer to avoid answering the question, Perry.

What question precisely is it that I'm not answering? I was unaware
that any question had even been asked.

Adam said that he didn't think patches were useful. I simply noted
that there are lots of people outside the U.S. who might want them.
Hell, there are lots of people inside the U.S. who might want them.
No one was implying by the distribution of such patches that Adam
should be running any software on his computer he doesn't feel
comfortable with.

Perry
NODE 31d41408Re: compatibility with future PGP
From: Adam Shostack <adam@bwh.harvard.edu>
    Date: Tue, 24 May 94 12:55:36 EDT

	    There is a significant advantage to pacthing both the US-legal
    and world legal versions of PGP.  Both are useful & neccessary to the
    future of strong encryption.



    Date: Tue, 24 May 1994 13:58:34 -0400
    From: "Perry E. Metzger" <perry@imsi.com>
    
    Adam said that he didn't think patches were useful.



Hmmmmm....

			Rick
NODE dac7c67fRe: compatibility with future PGP
Perry:

| > I agree that this legal silliness is unfortunate, but I don't think
| > that it's especially terrible that Adam would like to be able to
| > advocate PGP use at work without putting himself at risk.
| 
| You've misunderstood. The point is only that overseas users,
| technically speaking, do not have access to 2.[56], and might want
| patches. I didn't say anything about whether Adam should be running
| 2.[56] on his machine.

	Technically, they never had access to v1, either.  As I said
in my first message, I've heard 2.5 has already found its way out of
the US.  If that is the case, then the non-US users have access to
2.5.  If they do have access to 2.5, then could we discuss the
technical merits of patching 2.5 v. patching 2.3?

	Benefits of starting with 2.3:

	* widespread use
	* no RSA code
	* faster?


	2.5:
	
	* clearly legal in the USA
	* single code base for future modifications

	Its my opinion that the single code base, developed outside of
the US, based on 2.5, is the way to go.  Patching 2.3 is worthwhile,
but does not address all (potential) users of PGP.  Patching 2.5 does
(again, assuming that its been exported), and as such, I feel it is
a better way to go.

Adam
	

-- 
Adam Shostack 				       adam@bwh.harvard.edu

Politics.  From the greek "poly," meaning many, and ticks, a small,
annoying bloodsucker.
NODE 4dc36b95Re: compatibility with future PGP
Adam Shostack says:
> 	Technically, they never had access to v1, either.  As I said
> in my first message, I've heard 2.5 has already found its way out of
> the US.  If that is the case, then the non-US users have access to
> 2.5.

I wouldn't know where to find 2.5 outside the U.S.

Besides, there are other scenarios in which one would want such
patches. Here are just a couple.

1) You have a friend with an old PGP who wants to send you mail and
   who can't get a new PGP. Old PGP will read old PGP generated files,
   but new will not read old.
2) You have a friend eight months from now who only has old PGP and
   who you would like to send new PGP to. He knows your old-form
   signature but can't read the new one. The patch is simple enough
   that he can verify it himself. You can send it to him and then send
   him a signed copy of the new PGP.

In any case, I see no reason to oppose people posting patches.

This is the last time I'll post on this topic. Its getting old fast.

Perry
NODE f4795fa5Re: compatibility with future PGP
> 1) You have a friend with an old PGP who wants to send you mail and
>    who can't get a new PGP. Old PGP will read old PGP generated files,
>    but new will not read old.

Wrong, Perry.  Go read the announcement again.  2.6 will read old
messages, but after sept 1 it will start generating incompatible
messages that old versions cannot read. 

-derek
NODE c19d63b1Re: compatibility with future PGP
Derek Atkins says:
> > 1) You have a friend with an old PGP who wants to send you mail and
> >    who can't get a new PGP. Old PGP will read old PGP generated files,
> >    but new will not read old.
> 
> Wrong, Perry.  Go read the announcement again.  2.6 will read old
> messages, but after sept 1 it will start generating incompatible
> messages that old versions cannot read. 

Ahem. This is only true if the pkccompat mode was on. I have plenty of
text around that 2.5 will not read. This is not tragic, but the
situation might arise.

In any case, I don't understand why anyone would rationally oppose the
distribution of Pr0duct Cypher's patches -- you don't have to use them
if you don't like.

Perry
NODE d4cf430bRe: compatibility with future PGP
Perry writes:
| In any case, I don't understand why anyone would rationally oppose the
| distribution of Pr0duct Cypher's patches -- you don't have to use them
| if you don't like.

	I wasn't opposing them; I was suggesting that patching 2.5
would be more productive in the long run than patching 2.3

Adam


-- 
Adam Shostack 				       adam@bwh.harvard.edu

Politics.  From the greek "poly," meaning many, and ticks, a small,
annoying bloodsucker.
NODE d96d11edRe: compatibility with future PGP
Adam Shostack says:
> Perry writes:
> | In any case, I don't understand why anyone would rationally oppose the
> | distribution of Pr0duct Cypher's patches -- you don't have to use them
> | if you don't like.
> 
> 	I wasn't opposing them; I was suggesting that patching 2.5
> would be more productive in the long run than patching 2.3

Again, as I've noted, there are people who will need, for whatever
reason, to fix their old 2.3a (or pre-2.3a) system so that it will
interoperate.  Assuming that 2.5 finds its way overseas, it is not an
unreasonable code base for FUTURE development. However, what we are
talking about is not new development but retrofits.

Perry
NODE dba1ff70Graph isomorphism based PK cryptosystems?
I've been out of the literature for quite a while now so pardon me
if this is a dumb question.  Do any of you know of any public key
cryptosystems based on the graph isomorphism problem?  Last I heard
there weren't any.  But I think I've found one.

j'
NODE 6e19da6eRe: Graph isomorphism based PK cryptosystems?
Jay Prime Positive says:
>   I've been out of the literature for quite a while now so pardon me
> if this is a dumb question.  Do any of you know of any public key
> cryptosystems based on the graph isomorphism problem?  Last I heard
> there weren't any.  But I think I've found one.

There was a powerful result a while back concerning public key systems
based on NP complete problems -- in particular, I recall that there
was a large class of them that were flawed -- the original knapsack
problem based public key system suffered from the defect from the
limited amount my neurons will disgorge. Sadly, I can't remember the
details any longer. Anyone else have a vague recollection on this?

It would be cool to hear about your graph isomorphism based system in
any case. I have heard of zero knowledge systems based on graph
isomorphism, but never public key systems.

By the way, there is a neat paper circulating in samizdat form from
China about public key systems based on compositions of finite
automata. However, I'm more or less obligated not to spread it about
until the paper has been published (sigh). Its quite tantalizing,
though.

Perry
NODE 3b10da11Re: Graph isomorphism based PK cryptosystems?
Date: Tue, 24 May 1994 18:11:51 -0400
   From: "Perry E. Metzger" <perry@imsi.com>

   There was a powerful result a while back concerning public key systems
   based on NP complete problems

Hmm.  Was it the set of 'super increasing' knapsack problems?

   It would be cool to hear about your graph isomorphism based system in
   any case.

I only worry that if I publish, it could be patented.  And I don't
want the algorithm to end up in the hands of the software patent
folks.  Especially if they will be making money off it, and I wont.

Solutions?

   Perry
NODE e9dbc388Re: Graph isomorphism based PK cryptosystems?
Jay Prime Positive says:
> I only worry that if I publish, it could be patented.  And I don't
> want the algorithm to end up in the hands of the software patent
> folks.  Especially if they will be making money off it, and I wont.

If you publish, only you could patent it. There is only danger if you
don't publish, in which case others can independently make the same
discovery and patent it.

Perry
NODE 2aba2da3Re: Graph isomorphism based PK cryptosystems?
> 
> 
> Jay Prime Positive says:
> > I only worry that if I publish, it could be patented.  And I don't
> > want the algorithm to end up in the hands of the software patent
> > folks.  Especially if they will be making money off it, and I wont.
> 
> If you publish, only you could patent it. There is only danger if you
> don't publish, in which case others can independently make the same
> discovery and patent it.
> 
> Perry

    But you would then need to file within one year of the publication
    date I think.

    Bart
NODE 877a688bRe: Graph isomorphism based PK cryptosystems?
NODE 86329aaaGraph isomorphism based PK cryptosystems?
I only worry that if I publish, it could be patented.  And I don't
   want the algorithm to end up in the hands of the software patent
   folks.  Especially if they will be making money off it, and I wont.

If you publish, only you can patent.  One must be the 'true inventor'
(or some similar term of art) in order to file a patent on an
invention.  As someone pointed out, a system can be re-invented; then
that person is also a true inventor and can patent.

Publication is protection against patenting.  This is one of the main
reasons behind such publications as the IBM Technical Journal--the
publication of results not worth patenting themselves, but definitely
worth preventing others from patenting.  Publication of a result
precludes this.

Eric
NODE 73feae80Re: Graph isomorphism based PK cryptosystems?
> From: jpp@jpplap.markv.com (Jay Prime Positive)
> cryptosystems based on the graph isomorphism problem?  Last I heard
> there weren't any.  But I think I've found one.

Interesting.  Have you tested it against the known methods for the
isomorphism problem?  Van Leeuwen* references an O(n log n)
average-case algorithm, and ones that are pseudopolynomial w.r.t.
degree, genus, and treewidth.  There are also methods based on
"signatures" (hash functions on graphs, basically); there's an O(n^2)
expected-time perfect signature, and an O(n) (worst-case?) one with
exponentially small failure rate.  These might provide attacks,
though none solve the general problem.
	* (in Handbook of Theo. Comp. Sci., Vol. A)

BTW, the graph isomorphism problem is not known to be NP-complete,
and van Leeuwen comments that there is some theoretical basis
for expecting it not to be.  

Disclaimer: I don't know much about graph theory, I'm just getting
paid to do it.  :->

   Eli   ebrandt@hmc.edu
NODE e14430feRe: Graph isomorphism based PK cryptosystems?
> Date: Tue, 24 May 94 17:08:05 PDT
> From: Eli Brandt <ebrandt@jarthur.cs.hmc.edu>
>
> Interesting.  Have you tested it against the known methods for the
> isomorphism problem?  Van Leeuwen* references an O(n log n)
> average-case algorithm, and ones that are pseudopolynomial w.r.t.
> degree, genus, and treewidth.  There are also methods based on
> "signatures" (hash functions on graphs, basically); there's an O(n^2)
> expected-time perfect signature, and an O(n) (worst-case?) one with
> exponentially small failure rate.  These might provide attacks,
> though none solve the general problem.
>	   * (in Handbook of Theo. Comp. Sci., Vol. A)

   No I haven't tested it against any known GI algorithm.  Your
references are all very interesting and I will investigate them.  If
you had a publisher handy, along with the city the publisher is in, I
would happily phone them up and get a copy.  But if not, I can operate
a card catalog.

> BTW, the graph isomorphism problem is not known to be NP-complete,
> and van Leeuwen comments that there is some theoretical basis
> for expecting it not to be.  

  No, I didn't expect GI to be NP-complete at all.  I expect rather
that P < GI < NP.  That is one of the reasons that GI is an
interesting problem.  Especialy because (as you point out) GI is amost
always in P.

  In any case, my PK cryptosystem is not interesting except for the
new complexity point.  (Although, the general construction may be
interesting.)  I can prove that my cryptosystem has a level of
security which is reduceable to GI, and GI to it.  (The reduction is
only in polynomial time.  I will try to see about getting the slow
parts down to O(n) time.)

  PGP will almost certainly never include my PK system as an
alternative to RSA.  For one thing it needs a k^3 to 1 expantion in
communication costs for a security parameter of k.  For another the
'fast' decrypt routine requires O(n^3) in the number of nodes in the
graphs.  But there is no known GI algorithm which is O(n^3) in
general.  (And if there is one for *my* graphs, then I will give you a
polynomial time algorithm for all of GI.)

>    Eli   ebrandt@hmc.edu
NODE 9f5f6f2aRe: compatibility with future PGP
> 
> 	Technically, they never had access to v1, either.  As I said
> in my first message, I've heard 2.5 has already found its way out of
> the US.  If that is the case, then the non-US users have access to
> 2.5.  If they do have access to 2.5, then could we discuss the
> technical merits of patching 2.5 v. patching 2.3?
> 
> 	Benefits of starting with 2.3:
> 
> 	* widespread use
> 	* no RSA code
> 	* faster?
> 
> 
> 	2.5:
> 	
> 	* clearly legal in the USA
> 	* single code base for future modifications
> 
> 	Its my opinion that the single code base, developed outside of
> the US, based on 2.5, is the way to go.  Patching 2.3 is worthwhile,
> but does not address all (potential) users of PGP.  Patching 2.5 does
> (again, assuming that its been exported), and as such, I feel it is
> a better way to go.
>

Perhaps, but I think that many folks still do not have the answers
they are looking for -- primarily, can you use the secring generated
by 2.3 or below with the new (2.6) release, if you so desired?

- paul
NODE a0df5bccRe: compatibility with future PGP
> From: "Perry E. Metzger" <perry@imsi.com>
> People overseas want to be able to use this program, too. There are
> 250 million people in the U.S., which constitutes under 1/20th of the
> Earth's population.

You dropped the part of his message where he said that he believed
v2.5 was available abroad.  If it's not, I don't think it will take
long.  And once it's escaped from this little prison state of ours,
overseas users incur no risk in using it: they can't even be
Noriega'd, since they've broken no law in any country.

   Eli   ebrandt@hmc.edu
NODE 21f4d417patch to PGP 2.6
> The only change the future post-September PGP 2.6 messages will have
> is a change in the version number byte from 2 to 3.  PC's little hack
> not to check version numbers will work, but as a patch it's not the
> most robust.  It would be more robust if it checked for the range
> [2..3].

Agreed.

> Another thing a patched 2.3 release would have to do to be fully
> indistinguishable is to generate new version numbers itself after the
> given date.

Is "indistinguishability" the point or "interoperability"?

If the latter, then no change to generated version numbers should
be necessary/desired.  I believe that 2.6 plans to read previous
versions just fine.

Cort.
NODE 6f0ec93fpatch to PGP 2.6
> Another thing a patched 2.3 release would have to do to be fully
   > indistinguishable is to generate new version numbers itself after the
   > given date.

   Is "indistinguishability" the point or "interoperability"?

Reference is not advocacy.

I was speaking of what was necessary to ensure indistinguishability.
If that is your goal, then this is directly relevant.  If not, then it
may be beside the point.

The change in version numbers seems to have two effects, both of which
I addressed.  Use these statements as they are appropriate to your
goals.

Eric

P.S. The "you" is the general "you".