// COMPLETE THREAD

PGP bastardization (fwd)

2 expanded posts ยท every known parent and child

NODE 6e52995dPGP bastardization (fwd)
Forwarded message:
From prz Wed Jul 13 17:36:39 1994
Message-Id: <m0qODqw-000305C@maalox.ppgs.com>
Subject: PGP bastardization
To: trollins@debbie.telos.com
Date: Wed, 13 Jul 1994 17:36:38 -0700 (MDT)
Cc: karnow@cup.portal.com (Curt Karnow)
From: Philip Zimmermann <prz@acm.org>
Reply-To: Philip Zimmermann <prz@acm.org>
X-Mailer: ELM [version 2.4 PL22]
Content-Type: text
Content-Length: 1863      

Tom, I hear that you are distributing a modified version of PGP that 
uses a different customized encryption algorithm of your own design.

If you read the "Snake Oil" section of the PGP User's Guide, then you
know how I feel about amateur cryptographer's encryption algorithms
that have not been subjected to extensive peer review.

PGP's reputation, and my repuitation (which is tied to PGP), depends
of people trusting the quality of encryption algorithms and protocols
that I have carefully selected for PGP, using all of my knowledge and
experience.  If someone were to put a new encryption algorithm into
PGP without my permission, it could serve to tarnish the reputation
that PGP has earned over the years.

Accordingly, I do not approve of anyone modifying the cryptographic
characteristics of PGP.  PGP and Pretty Good Privacy are my trademarks,
and their good name is trusted the world over because of the care that 
I have exercised in selecting its algorithms.

If you'd like to write your own cryptographic utility, using your own
algorithms and protocols, I have no problem with that.  But I do not 
want my program, my documentation, my name, and my trademarks, to be
used for products that may have flawed algorithms.

I also have no problem with you modifying PGP for your own private
use, if you like to experiment with new algorithms of your own design.
But I do not want you to distribute such a program to others, if it uses
my code, my manuals, my name, and my trademarks.  It could hurt my
reputation and PGP's reputation.

If I am misinformed on this subject, please let me know and accept
my apology for assuming too much.  Otherwise, I'd like you to remedy
the situation.  Please let me know what has happened and what we can
do about it.

Sincerely,
Philip Zimmermann
prz@acm.org

cc:  Curtis Karnow
     Landels, Ripley, and Diamond
NODE acafce3eRe: PGP bastardization (fwd)
On Wed, 13 Jul 1994, Philip Zimmermann wrote:
> Accordingly, I do not approve of anyone modifying the cryptographic
> characteristics of PGP.  PGP and Pretty Good Privacy are my trademarks,
> and their good name is trusted the world over because of the care that 
> I have exercised in selecting its algorithms.

Do you think you might supply a version in the future supporting
1) more session key bits, for user suplied algorithims.
2) larger public keys, with no arbitrary limits.

I would be likely to *BUY* such a program, but will not buy the current 
version of pgp especially with the restriction on key size.

Don't follow this up with "but it would take a gazilion universes twenty 
gogelplex years to solve this" as I am fully aware of the numbers, and 
disagree with 1024 as a reasonable number.

If you don't plan to relax this restriction, then you can expect people 
in areas where patents are not enforced to hack your algorithim.  Not a 
threat, or saying it is right, just a fact of life.

Also, as a legal issue, anyone could legaly and without fear of any 
sanction produce a "modification kit" in printed form that detailed the 
changes to be made to your code to become "snake oil" and such a 
modification kit would be protected under the 1st amendment, and totally 
outside the reach of you or any law enforcement agency.  This might not 
be "respectfull" to you, but it is totally acceptable, as long as they 
don't distribute the code for pgp2.6 with it.  Use could be another 
thing.

I would say the only way to accomidate this is to make a biger mousetrap 
for the parinoid.

Perhaps it should be called MGPD for Mega Good Privacy Dudez.:-).

Roger.