NODE 6e52995dPGP bastardization (fwd)
Philip Zimmermann <prz@acm.org>Wed, 13 Jul 94 16:44:44 PDT
Forwarded message:
From prz Wed Jul 13 17:36:39 1994
Message-Id: <m0qODqw-000305C@maalox.ppgs.com>
Subject: PGP bastardization
To: trollins@debbie.telos.com
Date: Wed, 13 Jul 1994 17:36:38 -0700 (MDT)
Cc: karnow@cup.portal.com (Curt Karnow)
From: Philip Zimmermann <prz@acm.org>
Reply-To: Philip Zimmermann <prz@acm.org>
X-Mailer: ELM [version 2.4 PL22]
Content-Type: text
Content-Length: 1863
Tom, I hear that you are distributing a modified version of PGP that
uses a different customized encryption algorithm of your own design.
If you read the "Snake Oil" section of the PGP User's Guide, then you
know how I feel about amateur cryptographer's encryption algorithms
that have not been subjected to extensive peer review.
PGP's reputation, and my repuitation (which is tied to PGP), depends
of people trusting the quality of encryption algorithms and protocols
that I have carefully selected for PGP, using all of my knowledge and
experience. If someone were to put a new encryption algorithm into
PGP without my permission, it could serve to tarnish the reputation
that PGP has earned over the years.
Accordingly, I do not approve of anyone modifying the cryptographic
characteristics of PGP. PGP and Pretty Good Privacy are my trademarks,
and their good name is trusted the world over because of the care that
I have exercised in selecting its algorithms.
If you'd like to write your own cryptographic utility, using your own
algorithms and protocols, I have no problem with that. But I do not
want my program, my documentation, my name, and my trademarks, to be
used for products that may have flawed algorithms.
I also have no problem with you modifying PGP for your own private
use, if you like to experiment with new algorithms of your own design.
But I do not want you to distribute such a program to others, if it uses
my code, my manuals, my name, and my trademarks. It could hurt my
reputation and PGP's reputation.
If I am misinformed on this subject, please let me know and accept
my apology for assuming too much. Otherwise, I'd like you to remedy
the situation. Please let me know what has happened and what we can
do about it.
Sincerely,
Philip Zimmermann
prz@acm.org
cc: Curtis Karnow
Landels, Ripley, and Diamond
NODE acafce3eRe: PGP bastardization (fwd)
Berzerk <berzerk@xmission.xmission.com>Wed, 13 Jul 94 18:51:36 PDT
On Wed, 13 Jul 1994, Philip Zimmermann wrote:
> Accordingly, I do not approve of anyone modifying the cryptographic
> characteristics of PGP. PGP and Pretty Good Privacy are my trademarks,
> and their good name is trusted the world over because of the care that
> I have exercised in selecting its algorithms.
Do you think you might supply a version in the future supporting
1) more session key bits, for user suplied algorithims.
2) larger public keys, with no arbitrary limits.
I would be likely to *BUY* such a program, but will not buy the current
version of pgp especially with the restriction on key size.
Don't follow this up with "but it would take a gazilion universes twenty
gogelplex years to solve this" as I am fully aware of the numbers, and
disagree with 1024 as a reasonable number.
If you don't plan to relax this restriction, then you can expect people
in areas where patents are not enforced to hack your algorithim. Not a
threat, or saying it is right, just a fact of life.
Also, as a legal issue, anyone could legaly and without fear of any
sanction produce a "modification kit" in printed form that detailed the
changes to be made to your code to become "snake oil" and such a
modification kit would be protected under the 1st amendment, and totally
outside the reach of you or any law enforcement agency. This might not
be "respectfull" to you, but it is totally acceptable, as long as they
don't distribute the code for pgp2.6 with it. Use could be another
thing.
I would say the only way to accomidate this is to make a biger mousetrap
for the parinoid.
Perhaps it should be called MGPD for Mega Good Privacy Dudez.:-).
Roger.