// COMPLETE THREAD

Internet Privacy Guaranteed ad (POTP Jr.)

18 expanded posts ยท every known parent and child

NODE c8fc2719Internet Privacy Guaranteed ad (POTP Jr.)
This culled from comp.security.firewalls.  I've edited out the blathering ad
copy and just left the "technical details".  Sounds like POTP Jr. to me; I'm
certainly not interested in the "buy our company" schtick.	-- Wink

         Wichita Falls, Texas
         February 16, 1996
         For immediate Release:
         Internet.Privacy.Guaranteed

	 [Long blathering sales prose elided.]

            If You Break our System, You've Bought our Company!

         Internet.Privacy.Guaranteed, IPG, today announced a new
         product line that guarantees privacy for 2, or privacy
         networks of 20,000 or more people on Internet. We back up our
         Guarantee with the Corporate motto, 'If You Break our System,
         You Have Bought our Company.'

         IPG Guarantees Absolute Privacy on Internet. Using the
         trademark CRE transform, the IPG PCX Nvelopes system
         translates any intelligible digitized information into
         utterly random gibberish. Only one other user, or more in
         certain instances where there is a need to know,  will have
         the Nvelopener required to transform the random gibberish
         back into intelligible digitized information. CRE Transforms,
         trademark IPG, are the only acknowledged unbreakable method
         of so transforming digitized information. There are no
         passwords, encryption keys, or anything like that to conjure
         up, remember, and perhaps forget. PCX Nvelopes usage is
         automatic, similar to PKZIP and PKUNZIP.   Easy to install,
         use, add to, and administer.

                        It is Unbreakable

         If an individual, or any group of individuals, break the IPG
         Privacy System, IPG will sell them the company for $1.00, and
         even give them the dollar to buy it with. If you think you
         can, just try and you find out that it is impossible. There
         may be rumors that someone has broken the system, but that is
         not possible, it will never happen.

                     Don't Waste your time !

         How dare IPG have the unmitigated gall? When you are certain,
         then you are certain, and IPG is certain! Others dare not
         make such a brazen boast because they cannot possibly back it
         up, but IPG most certainly can.  Every informed expert of the
         technology will confirm, without reservation, that the IPG
         system is not breakable, as many already have!  There, we
         have thrown down that gauntlet, dare you pick it up?

                               CRE Transforms

         The system uses CRE transforms, metaphorically called
         Nvelopes, to translate any meaningful digitized information
         into absolutely random gibberish.  In order to convert that
         random gibberish back into intelligible usable form, a
         Nvelopener is required, and only the rightful recipient(s)
         has the required Nvelopener.

                          Nvelopes and Nvelopeners

         Every Nvelope and Nvelopener pair is absolutely and totally
         unique - they bear no resemblance whatsoever to any other
         Nvelope - Nvelopener pair in existence, anywhere ay anytime.
         Every time a user wants to transmit information to another
         user, they utilize a new unique Nvelope.

                      No Passwords or Keys or the Like

         As an added bonus, there are NO MESSY, INTRUSIVE PASSWORDS or
         ENCRYPTION KEYS to conjure up, remember, fool around with,
         and perhaps forget. None of that sort of thing to bother with
         at all. Nothing to get in your way of using the system.

           Transforms Internet from Least Private to Most Private

         The System, called PCX Nvelopes, for Private Communications
         eXchange, transforms Internet from being the least private,
         utterly without any privacy at all, system for conducting
         communications, into the most private system possible, an
         elegant fast system that unequivocally insures privacy.

                         Privacy Network

         PCX Nvelopes serves 2 individuals who want to communicate
         with each other in private, as it serves equally well a
         corporate organization, or any other organization, privacy
         network, of 9 or 90,000 or more people, who want to keep
         customer, trade secret, strategy and plans, financial, and
         other confidential information privy to those with the need
         to know. For both in house and external usage.

                   Guaranteed Easy to Install, Use and Upgrade

         Potential users beset by a paranoia that the PCX Nvelopes
         system must be complex, difficult to configure, laborious to
         install, administratively burdensome, arduous to upgrade and
         add users, are in for a computer cultural shock.  As you will
         find, PCX is the exact antithesis of all of those things.  It
         is so simple to install, use, upgrade and add users to, that
         it will completely blow your mind away. There is nothing to
         do, installation and adding users are totally load and go
         operations - if you can operate a computer, you can install
         and use PCX Nvelopes within minutes, it is absolutely duck
         soup to any computer literate, even marginal ones.

                               Prices

         Prices are $19.96, including shipping and handling,
         for a full blown 12 user Demonstration system, unconditional
         moneyback guarantee and may be applied to your first order -
         the Demo system can be used by 2 people, or all the way up to
         12 users in a privacy network. For $39.95, two users can set
         up a two user privacy system with 500 Nvelopes.  A fully
         operational integrated multi-user system costs approximately
         $140.00 per user, ready to load and go, with thousands, or
         millions of Nvelopes and Nvelopeners. IPG also offers full
         turnkey leases at $15.00 per user, per network, per
         month, which includes all software, upgrades, administration,
         and unlimited Nvelopes and Nvelopeners.

         As a reference to its unbreakability, we refer you to an
         article by Paul Leyland on Internet at:

             http://dcs.ex.ac.uk/~aba/otp.html

         For more information visit our Web Site at:

             http://www.netprivacy.com/ipg

         or E-Mail at ipgsales@cyberstation.net,

         or by phone at 817-691-1081


                  Trademarks & Copyrights

         Nvelopes, Nvelopeners, CPX and CRE Transforms are trademarks
         of Internet.Privacy.Guaranteed, IPG.   Copyrighted 1995,1996
         by: Internet.Privacy.Guaranteed.  All rights reserved.
NODE 51a4bd3cRe: Internet Privacy Guaranteed ad (POTP Jr.)
-----BEGIN PGP SIGNED MESSAGE-----

- From the node of Wink Junior:
: 
:          IPG Guarantees Absolute Privacy on Internet. Using the
:          trademark CRE transform, the IPG PCX Nvelopes system
:          translates any intelligible digitized information into
:          utterly random gibberish.

Which makes one wonder what this ad actually said BEFORE they passed
it through the "CRE transform".

- -- 
    Mark Rogaski     | wendigo@gti.net | wendigo@pobox.com |  I use PGP, so
System Administrator |   http://www.pobox.com/~wendigo/    |    should you!
Global Telecom, Inc. | Why read when you can just sit and  | finger for pubkey
  http://w3.gti.net/ |          stare at things?           | wendigo@pobox.com

-----BEGIN PGP SIGNATURE-----
Version: 2.6.2

iQCVAwUBMSf9JMajO20pqAytAQF8GQP/ducu8Gf1Y91LecmRbEng9Hl9qjI70nsR
7xL9jKE72A2zifolwsYuzyifmrhNnjxVYnRzGCCKX/qvY3bWvLTpH2S9i9oDx2/2
89rfkvMsyo+P9QqIjqvPpN59BlVOFAcOtnRyJjJWrpkGVmCh5wYi+dLzptqtaRwp
gj/73ZiisVo=
=qdMW
-----END PGP SIGNATURE-----
NODE f064e858Re: Internet Privacy Guaranteed ad (POTP Jr.)
"Internet.Privacy.Guaranteed (IPG)" writes:
>	   CRE Transforms,
>          trademark IPG, are the only acknowledged unbreakable method
>          of so transforming digitized information. There are no
>          passwords, encryption keys, or anything like that to conjure
>          up, remember, and perhaps forget. 

Neat trick, unless they're using biometrics, which doesn't appear to be the
case :}

[...]
>                      Don't Waste your time !

I think they just said it best themselves, but I'll comment a bit more....

[...]
>          Every informed expert of the
>          technology will confirm, without reservation, that the IPG
>          system is not breakable, as many already have!  

All under NDA, I suppose. Note that they don't even name an "informed expert of
the technology"; at least the POTP people gave some names.

[...]
>          A fully
>          operational integrated multi-user system costs approximately
>          $140.00 per user, ready to load and go, with thousands, or
>          millions of Nvelopes and Nvelopeners. IPG also offers full
>          turnkey leases at $15.00 per user, per network, per
>          month, which includes all software, upgrades, administration,
>          and unlimited Nvelopes and Nvelopeners.
>
>          As a reference to its unbreakability, we refer you to an
>          article by Paul Leyland on Internet at:
> 
>              http://dcs.ex.ac.uk/~aba/otp.html

Clearly they (claim to) offer some sort of system using One Time Pads.
Notice the price quote of "$15.00 per user, per network, per month" including
"unlimited Nvelopes and Nvelopeners". I suspect this means that they're
basically selling chunks of (pseudo- ?)random data for as much as $15/person 
each month !  I guess it's nice work if you can get it. At that price, one
would hope that they're at least generating truly random bits from a hardware
source. But their skimpy details on their proprietary processes don't
inspire confidence....

>          For more information visit our Web Site at:
> 
>              http://www.netprivacy.com/ipg

In case you didn't get enough hyperbole from the press release, they have
extra helpings on the Web. This site has numerous pages containing precious
little real information. I found a few tidbits in unlikely places, though:

In http://www.netprivacy.com/ipg/mlmplan.html, which incidentally promises
that they "can help you to make some big bucks through the PCX Nvelopes
Multi - Level - Marketing Plan", it says:

> With our manufacturing process it is relatively easy for us
> to manufacture a ready to go system, for 25 users, or for
> 2,500 users.  All the user has to do is to prepare a
> DIR.LST, a Directory Listing of the users. We use that as
> the template and manufacture the system. 

This is actually a little scary. According to one of their other web pages, 
the DIR.LST file is a numbered list of user names and email addresses. So it
appears that a customer hands over a list of names and addresses, and IPG
assigns a set of one-time pads (or something) to each pair of users on the 
list. (Holy combinatorial explosion.) And now IPG knows the one-time pads that
will be used between any pair of email addresses on the list it has !  
The EES is starting to look attractive by comparison. 

> It becomes a load
> and go installation at each of the user sites. 

Gee, why are we all so worried about key management ?  It's just a load and
go installation at each of the user sites !  ;)

> We will even prepare, or help prepare, the DIR.LST for users.
>
> While we have the software and manufacturing facility to do
> that quickly, it is not easily transportable, to say the
> least, and certain aspects of it, we consider highly proprietary.

"not easily transportable, to say the least" ???  
Any ideas to what this might refer ?

OK, I saved (IMHO) the best for last. I suppose this could be taken as a claim
about their proprietary, immobile RNG methods:
(from http://www.netprivacy.com/ipg/comp.html)

>         How do we Achieve such High Standards?
>                  First Class Quality Control!
>
> We achieve unusually high standards of excellence because
> of the manufacturing process. Over 30%, sometimes as high as 
> 50% or more of our Nvelopes, Nvelopeners, are discarded 
> because they cannot meet our rigid standards. Also our 
> Nvelopes and Nvelopeners are subjected to a battery of 
> performance tests to insure that when used, they will meet the 
> high standards that you would expect.

<sigh> It's a jungle out there....

-Lewis	"You're always disappointed, nothing seems to keep you high -- drive 
	your bargains, push your papers, win your medals, fuck your strangers;
	don't it leave you on the empty side ?"  (Joni Mitchell, 1972)
NODE 8a58e7dcRe: Internet Privacy Guaranteed ad (POTP Jr.)
Mon Mar 19,1996

Obviously you want to criticise without investigation. He who knows all, 
   knows little, or nothing accoring to Einstein.

On Mon, 19 Feb 1996 lmccarth@cs.umass.edu wrote:

> "Internet.Privacy.Guaranteed (IPG)" writes:
> >	   CRE Transforms,
> >          trademark IPG, are the only acknowledged unbreakable method
> >          of so transforming digitized information. There are no
> >          passwords, encryption keys, or anything like that to conjure
> >          up, remember, and perhaps forget. 
> 
> Neat trick, unless they're using biometrics, which doesn't appear to be the
> case :}
It uses one time pads - yes - but true OTPs, not random number generators 
with a key like the POTP people. The mere fact that POTP sells the entire 
package, should tell you something. For long Messages, the basic kernel 
of our system is also a random number generator, but the source key, 5600 bits,
is a true random one time pad generated from a hardware source. 

>From that 5600 bits, a combination of a prime number numbers, picked from 
a large random table, by 512 of the random bits, ie 64 large prime 
numbers, and the other random bits are used to generate the random numbers 
used. This in effect creates a humoungous cycled encryption wheel 
system, with over 10 to the 2300th power possibilities before repeats, 
similar to engima but more like the most secured electronic encryption 
systems used prior to the advent of computers.
> 
> [...]
> >                      Don't Waste your time !
> 
> I think they just said it best themselves, but I'll comment a bit more....
> 
You obviously are too informed - since you already know everything, 
perhaps there is nothing more for you to learn so you are right, don't 
waste you time, since you already know, But others, less informed, might 
discover that they do nnot know everything
> [...]
> >          Every informed expert of the
> >          technology will confirm, without reservation, that the IPG
> >          system is not breakable, as many already have!  
> 
> All under NDA, I suppose. Note that they don't even name an "informed expert of
> the technology"; at least the POTP people gave some names.
We did refer people to Paul Leyland as you note in your next paragrapgh - 
Unlike PGP, and other RSA systems, DES, and even POTP, the PCX Nvelopes 
system is mathematically unbreakable - if you labor uner the delusion 
that the PGP protects your privacy be our guest. Ask yourself " Why are 
Freeh, Gore and all the others not screaming more than they are about 
RSA systems, DES systems and so forth? They are talking about 
interceting 1 in 100 messages n urban areas, are they doing it 
because they want to waste their time?
> [...]
> >          A fully
> >          operational integrated multi-user system costs approximately
> >          $140.00 per user, ready to load and go, with thousands, or
> >          millions of Nvelopes and Nvelopeners. IPG also offers full
> >          turnkey leases at $15.00 per user, per network, per
> >          month, which includes all software, upgrades, administration,
> >          and unlimited Nvelopes and Nvelopeners.
> >
> >          As a reference to its unbreakability, we refer you to an
> >          article by Paul Leyland on Internet at:
> > 
> >              http://dcs.ex.ac.uk/~aba/otp.html
> 
> Clearly they (claim to) offer some sort of system using One Time Pads.
> Notice the price quote of "$15.00 per user, per network, per month" including
> "unlimited Nvelopes and Nvelopeners". I suspect this means that they're
> basically selling chunks of (pseudo- ?)random data for as much as $15/person 
> each month!  I guess it's nice work if you can get it. At that price, one
> would hope that they're at least generating truly random bits from a hardware
> source. But their skimpy details on their proprietary processes don't
> inspire confidence....
Every message is encrypted with a separate Nvelope, and as indicated in 
our site, nver repeated. If the message is less than 5600 bits, it is a 
true random one time pad, from hardware sources - if longer, the one time 
pad becomes a random number generator as partially explained previously.
Each nvelope, hardware one time pad, an ADC LOB system,  is used once and 
only once, the system absolutely precludes reuse.  The $15.00 per moth 
keeps all users supplied with the necessary one time pads, which in the 
case of high volume business users might be a few hundred a day, a stock 
broker, anb accountant, auditor, an attorney or the like.
 > >          For more information visit our Web Site at:
> > 
> >              http://www.netprivacy.com/ipg
> 
> In case you didn't get enough hyperbole from the press release, they have
> extra helpings on the Web. This site has numerous pages containing precious
> little real information. I found a few tidbits in unlikely places, though:
> 
> In http://www.netprivacy.com/ipg/mlmplan.html, which incidentally promises
> that they "can help you to make some big bucks through the PCX Nvelopes
> Multi - Level - Marketing Plan", it says:
> 
> > With our manufacturing process it is relatively easy for us
> > to manufacture a ready to go system, for 25 users, or for
> > 2,500 users.  All the user has to do is to prepare a
> > DIR.LST, a Directory Listing of the users. We use that as
> > the template and manufacture the system. 
> 
> This is actually a little scary. According to one of their other web pages, 
> the DIR.LST file is a numbered list of user names and email addresses. So it
> appears that a customer hands over a list of names and addresses, and IPG
> assigns a set of one-time pads (or something) to each pair of users on the 
> list. (Holy combinatorial explosion.) And now IPG knows the one-time pads that
> will be used between any pair of email addresses on the list it has !  
> The EES is starting to look attractive by comparison. 
> 

Obviously you again already know everything, so there is no need to 
try to explain it to you, but others might be interested. As to 
combinatorial explosion, it really ius not as ad as people might think!
A user does not jave to keep all the combinations, only the ones paired 
with, thus in a thousand user system, there is only a need for 999 paired 
Nvelope and Nvelopeners, and some of those will little usage. We keep 10 
Nvelopes/Nvelopeners for each pair, 20 in duplex, and each is 700 bytes.
Thus in a 1000 user system, about 7.2 MB would be required to handle all 
the one taime pads, a lot os space but not unmageable, As Nvelopes are 
used, they are replensihed accordingly to a heuristic algorithm built 
into the system. 
  
> > It becomes a load
> > and go installation at each of the user sites. 
> 
> Gee, why are we all so worried about key management ?  It's just a load and
> go installation at each of the user sites !  ;)
> 

That is precisely why PCX Nvelopes is such an extraordinary system. 
That is the beauty of PCX Nvelopes, it lifts that  burden from the 
user, eliminates it entirely. You may have worried about key 
management, but with our system, you will not have to do so in the 
future. The system itself, manages all the OTPs, you do not have to do 
anything but use the system. Key management is the problem with all existing 
systems, but it is no problem at all with the PCX Nvelopes system, as you would 
see if you looked at the system, instead, of talking about something 
when you have no idea at all of what it is about. The first set of keys 
must be sent by a secure source, US mail, FED EX, or whatever, but
thereafter, all updates can be accomodated over Internet. 


 > > We will even prepare, or help prepare, the DIR.LST for 
users. > >
> > While we have the software and manufacturing facility to do
> > that quickly, it is not easily transportable, to say the
> > least, and certain aspects of it, we consider highly proprietary.
> 
> "not easily transportable, to say the least" ???  
> Any ideas to what this might refer ?
The combinatorial problem that you referred to previously, would indeed 
generate almost 500,000 pair sets, which we call packets. What is the 
best way to generate those 499,500 sets? 999 We can automatically generate 
them, and all the software that goes with them on 1000 sets of 6 diskettes
each, each of which goes through a separte verification process, and certification 
process, larger systems are delivered in parts, two diskettes 
direct, and the others over internet. 

> 
> OK, I saved (IMHO) the best for last. I suppose this could be taken as a claim
> about their proprietary, immobile RNG methods:
> (from http://www.netprivacy.com/ipg/comp.html)
> 
> >         How do we Achieve such High Standards?
> >                  First Class Quality Control!
> >
> > We achieve unusually high standards of excellence because
> > of the manufacturing process. Over 30%, sometimes as high as 
> > 50% or more of our Nvelopes, Nvelopeners, are discarded 
> > because they cannot meet our rigid standards. Also our 
> > Nvelopes and Nvelopeners are subjected to a battery of 
> > performance tests to insure that when used, they will meet the 
> > high standards that you would expect.
Every onetime pad is subjected to analysis at the bit level, character 
level, couplet level, triplet level, and set level, 5600 bits. As you 
might, but probably do not know, all hardware generation of OTP's are 
irregular, otherwise they are not random. Thus at times, a hardware 
source, such as ADC LOB system, can generate nonrandom data, unless 
this is checked, it can destroyed the integrity of your system. At all 
levels, we check standard deviation, chi Square, Delta IC, and other 
statistical tests. Moreover, we check sets of packet, at the 2, 4, 8, 
16, 32, 64, 128, 256, 512, 1024, 2048, 4096, 8192, 16384 etal. Our 
packets are random, and you can take that to the bank.   

> 
> <sigh> It's a jungle out there....
> 
> -Lewis	"You're always disappointed, nothing seems to keep you high -- drive 
> 	your bargains, push your papers, win your medals, fuck your strangers;
> 	don't it leave you on the empty side ?"  (Joni Mitchell, 1972)
> 
 <sigh> - Einstein - He who thinks that he knows everything, knows 
                     nothing.
NODE a6389028Re: Internet Privacy Guaranteed ad (POTP Jr.)
Since you're convinced that your system can stand scrutiny, why not
post a URL for a paper describing the algorithims, key management,
etc, of your system.  What you've posted here is unparseable, with the
exception of some nonsense, which parses to `We know enough to be
dangerous.'

Adam


IPG Sales wrote:

| >From that 5600 bits, a combination of a prime number numbers, picked from 
| a large random table, by 512 of the random bits, ie 64 large prime 
| numbers, and the other random bits are used to generate the random numbers 
| used. This in effect creates a humoungous cycled encryption wheel 
| system, with over 10 to the 2300th power possibilities before repeats, 
| similar to engima but more like the most secured electronic encryption 
| systems used prior to the advent of computers.

|  <sigh> - Einstein - He who thinks that he knows everything, knows 
|                      nothing.
| 


-- 
"It is seldom that liberty of any kind is lost all at once."
					               -Hume
NODE 7493995dRe: Internet Privacy Guaranteed ad (POTP Jr.)
On Mon, 19 Feb 1996, Adam Shostack wrote:

> Since you're convinced that your system can stand scrutiny, why not
> post a URL for a paper describing the algorithims, key management,
> etc, of your system.  What you've posted here is unparseable, with the
> exception of some nonsense, which parses to `We know enough to be
> dangerous.'
> 
> Adam
> 
> 
> IPG Sales wrote:
> 
> | >From that 5600 bits, a combination of a prime number numbers, picked from 
> | a large random table, by 512 of the random bits, ie 64 large prime 
> | numbers, and the other random bits are used to generate the random numbers 
> | used. This in effect creates a humoungous cycled encryption wheel 
> | system, with over 10 to the 2300th power possibilities before repeats, 
> | similar to engima but more like the most secured electronic encryption 
> | systems used prior to the advent of computers.
> 
> |  <sigh> - Einstein - He who thinks that he knows everything, knows 
> |                      nothing.
> | 
> 
> 
> -- 
> "It is seldom that liberty of any kind is lost all at once."
> 					               -Hume
> 
> 
> 
> 
> 
We are not currently revealing all the details of our system because of 
patents in process, and other relat6ed matters. We are offering the 
software. You should be able to readily decompile it and determine the 
algorithms used andf how they are used to generate random number sequences 
for very long files.  For short messages, a true OTP is used directly. 

If you are aware of encrtypting technology, you recognize that hardware 
prime number cycle wheels for the basis of some of the most secured 
hardware systems employed for encryption. We simply expand that technogy 
using software to set an intial setting, an adder, and a limit for 64 
such wheels, using large random prime numbers for each of those settings. 
The total number of possibilities is over 10 to the 1690th power and can 
be much larger. 

Thus we can eliminate the need to have the length of the OTP to be equal 
to the length of the file - if you do not belive that it works, try it 
and see - it takes inly a few hours to set such a trial up. We generated 
over 790 gigabytes of charcaters, on multiple backups, and tested. Our 
standard deviations, chi squares, Delta ICs for bits, characters, sets, 
and the entire set were random. The sets are random, and you can take 
that to the bank. 

Someone, will decompile it and discover that it is truly random, at least 
from the practical usage basis. But we need that time to file patents, 
cvopyrights and the like. 

The IPG system solves the key management problem and produces a truly 
unbreakabkle system. We make no apologies for not currently revealing all 
of the methodologies andf algorithms, but they will be revealed with 
time, by us or others, and you will discover that it is indeed a simple, 
easy to use, easy to install, truly unbreakable system.

"Unless we know, we do not experience by talking," Plato
NODE 68a37a85Re: Internet Privacy Guaranteed ad (POTP Jr.)
IPG Sales writes:
> We are not currently revealing all the details of our system because of 
> patents in process,

Bull. Once you have applied for the patent you no longer need be
secret -- indeed, you can still apply for a patent up to one year
after full publication.

> We are offering the software. You should be able to readily
> decompile it and determine the algorithms used andf how they are
> used to generate random number sequences for very long files.

Something tells me it wouldn't be worth my while. Until you guys get a
clue, none of my clients on Wall Street or elsewhere are coming within
a mile of your products. I won't even waste my time looking at them.

> If you are aware of encrtypting technology, you recognize that hardware 
> prime number cycle wheels for the basis of some of the most secured 
> hardware systems employed for encryption.

The cypherpunks mailing list is composed of some of the most
knowledgeable people in the field of cryptography in the
world. Therefore, you will pardon my noting that the phrase "prime
number cycle wheels" isn't a term any of us are familiar with. I don't
find the term anywhere in any of the literature, I don't recall it,
and if it was anything more than marketingese I would have. You do
seem to know enough to know that prime numbers play a bit of a role in
modern cryptography, but that seems to be it. They play very little
role in non-public key systems like yours.

> We simply expand that technogy 
> using software to set an intial setting, an adder, and a limit for 64 
> such wheels, using large random prime numbers for each of those settings. 
> The total number of possibilities is over 10 to the 1690th power and can 
> be much larger. 

Spare us the bull. You don't get security in a crypto system from
having impressive combinatorial explosions. A simple monoalphabetic
substitution can claim to have 403291461126605635584000000 possible
keys and you wouldn't trust your six year old cousin not to crack
it. (the number would be far, far more impressive if I'd taken all
ASCII characters instead of just the alphabet of 26 letters in to
account).

> Someone, will decompile it and discover that it is truly random, at least 
> from the practical usage basis.

"Truly random" and "for practical purposes" don't mix. If it isn't
truly random, then the question is whether or not the thing is, in
fact, a strong encryption system.

Time and time again, snake oil salesmen come up and delude themselves
and others into thinking that they have some sort of great encryption
system and time and time again it cracks open like an egg. You guys
have all the stigmata.

> The IPG system solves the key management problem

Public key cryptography did that 20 years ago. Where have you been?

> and produces a truly unbreakabkle system.

The only system that is truly unbreakable is a true one time pad, not
a fake one.

> We make no apologies for not currently revealing all 
> of the methodologies andf algorithms,

Too bad. You should be embarassed to even open your mouths.

Perry
NODE 3629ff6cRe: Internet Privacy Guaranteed ad (POTP Jr.)
On Mon, 19 Feb 1996, Perry E. Metzger wrote:

> 
> IPG Sales writes:
> > We are not currently revealing all the details of our system because of 
> > patents in process,
> 
> Bull. Once you have applied for the patent you no longer need be
> secret -- indeed, you can still apply for a patent up to one year
> after full publication.
True, but we are not sure what is going to be covered by patents, 
obviously you must know that wemay have to treat some of the information, 
maybe all of the really iomportant stuff as trad secret material and try 
our best to protect it inm that manner - we cannot depend upon the 
paatents until we know what is going to be covered, if anything - so bull
back to you.

> 
> > We are offering the software. You should be able to readily
> > decompile it and determine the algorithms used andf how they are
> > used to generate random number sequences for very long files.
> 
> Something tells me it wouldn't be worth my while. Until you guys get a
> clue, none of my clients on Wall Street or elsewhere are coming within
> a mile of your products. I won't even waste my time looking at them.
> 
In time they will, because keymanagem,ent makes RSA systems unmanageable 
for large organizations - offer such a suystem to Merrill Lynch and be 
laughed out of the office - only a syustem such as ours resolve that 
problem!


> > If you are aware of encrtypting technology, you recognize that hardware 
> > prime number cycle wheels for the basis of some of the most secured 
> > hardware systems employed for encryption.

Please refer to Dorthy Dennings excellent work on mathematical 
crytanalysis of wheeeled cryptosystems, and then imagine that every 
Nvelope, or suych wheeled system, was based on randomly selecting the 
prime number wheels, they do not have to be, but ours are - imagine that 
every message ever sent was sent using such an unique wheel system. 

> 
> The cypherpunks mailing list is composed of some of the most
> knowledgeable people in the field of cryptography in the
> world. Therefore, you will pardon my noting that the phrase "prime
> number cycle wheels" isn't a term any of us are familiar with. I don't
> find the term anywhere in any of the literature, I don't recall it,
> and if it was anything more than marketingese I would have. You do
> seem to know enough to know that prime numbers play a bit of a role in
> modern cryptography, but that seems to be it. They play very little
> role in non-public key systems like yours.

Are you sure that none of you are familiar with it? I have received many 
replies indicating that a large number of you are familiar with it, 
I refer you again to Denning's. Maybe you are not, but many are, 
apparently most from the replies that I am getting. Such systems are 
used at the highest level of government because they are the most secure 
systems available, excepting OTP's of course. 


> > We simply expand that technogy 
> > using software to set an intial setting, an adder, and a limit for 64 
> > such wheels, using large random prime numbers for each of those settings. 
> > The total number of possibilities is over 10 to the 1690th power and can 
> > be much larger. 
> 
> Spare us the bull. You don't get security in a crypto system from
> having impressive combinatorial explosions. A simple monoalphabetic
> substitution can claim to have 403291461126605635584000000 possible
> keys and you wouldn't trust your six year old cousin not to crack
> it. (the number would be far, far more impressive if I'd taken all
> ASCII characters instead of just the alphabet of 26 letters in to
> account).
Who in the world said it was monalpabetic substitution -  we are talking 
about the random sequences for a single message - A random prime number 
wheel system, provides a far more secure system that RSA based systesms, 
- check it out, and do some investigating instead of talking. > 
> > Someone, will decompile it and discover that it is truly random, at least 
> > from the practical usage basis.
> 
> "Truly random" and "for practical purposes" don't mix. If it isn't
> truly random, then the question is whether or not the thing is, in
> fact, a strong encryption system.
> 
> Time and time again, snake oil salesmen come up and delude themselves
> and others into thinking that they have some sort of great encryption
> system and time and time again it cracks open like an egg. You guys
> have all the stigmata.
> 
> > The IPG system solves the key management problem
> 
> Public key cryptography did that 20 years ago. Where have you been?
> 
> > and produces a truly unbreakabkle system.
> 
> The only system that is truly unbreakable is a true one time pad, not
> a fake one.
> 
> > We make no apologies for not currently revealing all 
> > of the methodologies and algorithms,
> 
> Too bad. You should be embarassed to even open your mouths. 

Not until we know what patent coverage is going to do and not to do.

> 
> Perry
>
NODE 1a5f89a6Re: Internet Privacy Guaranteed ad (POTP Jr.)
IPG Sales writes:
> > Once you have applied for the patent you no longer need be
> > secret -- indeed, you can still apply for a patent up to one year
> > after full publication.

>True, but we are not sure what is going to be covered by patents,
>obviously you must know that wemay have to treat some of the
>information, maybe all of the really iomportant stuff as trad secret
>material

If you make any of your work at all trade secrets your entire system
is totally unacceptable to any real client with real security
needs. No rational security person is willing to accept the words of
snake oil salesmen -- like yourselves -- on faith.

> In time they will, because keymanagem,ent makes RSA systems unmanageable
> for large organizations - offer such a suystem to Merrill Lynch and be
> laughed out of the office - only a syustem such as ours resolve that
> problem!

You are the ones that are going to get laughed out of places, except
for the offices of the ignorant and gullible, whom you might prey
on. You should be ashamed to even dare to put it on the market. You
are committing nothing less than fraud, in all likelyhood.

You system resolves no key management problems because at this point
-- sight unseen -- I'm almost sure it is a piece of junk. You are
putting out too many "this is crap" keywords for me to think
otherwise. However, let me point out that you guys also don't know
what you are talking about. There is no key management problem per
se. RSA based systems are quite easy to use.

Even private key systems are quite workable. I actually work with
these firms -- its what I do for a living. They have existing systems
based on KDCs (do you even know what a KDC is?) and they function just
fine. As for public key technologies, they are in many cases
implementing technologies based on public key system. The only people
that are going to be laughed out are you guys. You are obviously the
worst kind of snake oil salesmen.

> > > If you are aware of encrtypting technology, you recognize that hardware
> > > prime number cycle wheels for the basis of some of the most secured
> > > hardware systems employed for encryption.
> 
> Please refer to Dorthy Dennings excellent work on mathematical
> crytanalysis of wheeeled cryptosystems,

Are you refering to rotors, by any chance? Rotors are World War II era
technology. Of course, who can even guess what you are talking
about. You make about as much sense as the people handing out xeroxed
pamphlets on the street corner informing all comers about the fact
that they are being controlled by aliens.

> > > The total number of possibilities is over 10 to the 1690th power and can
> > > be much larger.=
> >
> > Spare us the bull. You don't get security in a crypto system from
> > having impressive combinatorial explosions. A simple monoalphabetic
> > substitution can claim to have 403291461126605635584000000 possible
> > keys and you wouldn't trust your six year old cousin not to crack
> > it. (the number would be far, far more impressive if I'd taken all
> > ASCII characters instead of just the alphabet of 26 letters in to
> > account).

> Who in the world said it was monalpabetic substitution -

I didn't. I just said that impressive numbers are meaningless. A
simple repeating Vigenere cipher's key can easily have more than
10^1690 possible keys and yet be crackable with no trouble at
all. Sheer number of combinations is meaningless. Big numbers are
meaningless. If you understood cryptography, my point would have been
obvious. You don't understand technology.

> we are talking
> about the random sequences for a single message - A random prime number
> wheel system, provides a far more secure system that RSA based systesms,

The first part of your comment is meaningless. The second part implies
that you know how to break RSA public key cryptography. Please
enlighten us as to how.

> - check it out, and do some investigating instead of talking.

You won't allow anyone to do any investigating on your methods since
you keep them secret.

You should be ashamed. Luckily, no one is going to buy your products,
especially not once the crypto community is finished with you.

Perry
NODE 630c589dRe: Internet Privacy Guaranteed ad (POTP Jr.)
Perry, 

I will not waste anymore of your time, or mine -
Since you seem to know everything about everything, 
there is no need in talking in circles - You may think that you know 
everything there is to know about encryption, but believe me, there is 
a lot more for you to learn - I do not now what KDC's are, I presume 
some sort o Key Delivery Codes. or Systems, but? I would like to find out 
though - send us some literature and we will send you a free demo system- that 
is the differece between you and us - we know very little and want to 
know more you know everythinh there is to know - and do not need to 
know anymore - 

Incidentally crypto wheel systems are stillemployed in 1996 at some of 
the highest levels of usage - some called then rotors at one time - they 
are still used because the produce non repeatable sequeces - the fact 
that ROMs are userd insteaed of rotors does not change the basic nature 
of such systems, they depend upon the generation of random, nonrepeatable 
sequences, which they can do, much faster and much more securely ythan 
RSA systems, I like RSA systems, they have application - but they are not 
the begin all and end all of encryption technology - good luck
NODE c5db1cadRe: Internet Privacy Guaranteed ad (POTP Jr.)
IPG Sales writes:
> there is no need in talking in circles - You may think that you know
> everything there is to know about encryption, but believe me, there is
> a lot more for you to learn - I do not now what KDC's are,

Key Distribution Centers, the center of Needham-Schroeder and similar
key management protocols, like the Kerberos protocols. If you don't
know what these are, you have no business talking about the "problems
of key management" because you know nothing about the field of key
management.

> that is the differece between you and us - we know very little and
> want to know more you know everythinh there is to know - and do not
> need to know anymore

The difference between us is that you are pretending to be a doctor
even though you have no medical training and are about to go out and
butcher live patients, pretending that this is just business as
usual. Some of the rest of us have devoted many years to the study of
this field, which actually does have a substantial literature and lots
of skilled professionals. Anyone who says "We know very little" has no
business writing code and selling it to the public. You are doing
nothing less than putting your customers businesses at risk, and in
some cases their lives. You deserve the worst.

> I will not waste anymore of your time, or mine -

Don't worry. Whether we waste any of your time or not, I assure you
that people like me *will* lay waste to your company and its sales if
you are indeed peddling junk, which is the most obvious assumption to
make here. I personally am sick of companies such as yours pulling the
big con on ignorant customers. You have not heard the last of any of
this -- believe me. If the lot of you end up convicted of fraud it
will not surprise me. I repeat -- you have NOT heard the last of
this. As I said, I'm a libertarian. I believe it is up to the
community, not the government, to track down and stop the activities
of glorified con men such as yourselves. You *will* be stopped.

Perry
NODE 4219f67cRe: Internet Privacy Guaranteed ad (POTP Jr.)
Perry

Yes you are quite right - time will tell and it is you that is wrong - as 
time will prove - it will be my pleasure to have you eventually choke on 
your castigating words - to castigate be sure that you are right, and in 
this case, you are wrong as time will tell - wait and see -!!!!!!
NODE 4727d8f9Re: Internet Privacy Guaranteed ad (POTP Jr.)
On Mon, 19 Feb 1996, IPG Sales wrote:

> Perry
> 
> Yes you are quite right - time will tell and it is you that is wrong - as 
> time will prove - it will be my pleasure to have you eventually choke on 
> your castigating words - to castigate be sure that you are right, and in 
> this case, you are wrong as time will tell - wait and see -!!!!!!

As much as I dislike Perry's strutting on CP, I dislike even more folks
who dream up some hair-brained scheme, then claim it's the greatest thing
since sliced bread, without so much as anything approaching peer review,
and are obviously out to make a quick buck when they take the company
public.  I hate to say it in public, but Perry's 100% correct.

Especially ones who end their rants with multiple exclamation marks.  The
more exclamation marks I see, the faster the message gets thrown in the
trash. 
--
Ed Carp, N7EKG    			Ed.Carp@linux.org, ecarp@netcom.com
					214/993-3935 voicemail/digital pager
					800/558-3408 SkyPager
Finger ecarp@netcom.com for PGP 2.5 public key		an88744@anon.penet.fi

"Past the wounds of childhood, past the fallen dreams and the broken families,
through the hurt and the loss and the agony only the night ever hears, is a
waiting soul.  Patient, permanent, abundant, it opens its infinite heart and
asks only one thing of you ... 'Remember who it is you really are.'"

                    -- "Losing Your Mind", Karen Alexander and Rick Boyes

The mark of a good conspiracy theory is its untestability.
		    -- Andrew Spring
NODE 98586ed1Re: Internet Privacy Guaranteed ad (POTP Jr.)
IPG Sales writes:
 > For short messages, a true OTP is used directly. 

Quick question: does anybody at IPG know what the "O" in "OTP" stands
for?

______c_____________________________________________________________________
Mike M Nally * Tiv^H^H^H IBM * Austin TX    * I want more, I want more,
       m5@tivoli.com * m101@io.com          * I want more, I want more ...
      <URL:http://www.io.com/~m101>         *_______________________________
NODE 30244978Re: Internet Privacy Guaranteed ad (POTP Jr.)
IPG Sales writes:
> Obviously you want to criticise without investigation. He who knows all, 
>    knows little, or nothing accoring to Einstein.

That's a rather disingenuous statement. I read your press release, and then
I spent a while browsing through everything that seemed germane on your
web pages. But my investigation of all the material you had presented to the
world yielded very little in the way of hard facts about the security of the 
IPG system. I responded to what I'd been able to find.

Future technical investigations of IPG would be greatly aided if you placed
on your web pages some of the technical details you have at last revealed
here. I just checked your web pages again, and they still don't explain the
actual workings of the system at all.

-Lewis	"You're always disappointed, nothing seems to keep you high -- drive 
	your bargains, push your papers, win your medals, fuck your strangers;
	don't it leave you on the empty side ?"  (Joni Mitchell, 1972)
NODE a1f19a9dRe: Internet Privacy Guaranteed ad (POTP Jr.)
On Tue, 20 Feb 1996 lmccarth@cs.umass.edu wrote:

> IPG Sales writes:
> > Obviously you want to criticise without investigation. He who knows all, 
> >    knows little, or nothing accoring to Einstein.
> 

I apologize but I do believe that you prejudged it without bothering to 
inquire of us, or inquire further. We are now anxious to cooperate with 
cypherpunks and let them show us how silly the system is. We will cooperate
fully, with minor but we believe accpeptableimitations and subject 
to reciprocation. 


> That's a rather disingenuous statement. I read your press release, and then
> I spent a while browsing through everything that seemed germane on your
> web pages. But my investigation of all the material you had presented to the
> world yielded very little in the way of hard facts about the security of the 
> IPG system. I responded to what I'd been able to find.
> 
> Future technical investigations of IPG would be greatly aided if you placed
> on your web pages some of the technical details you have at last revealed
> here. I just checked your web pages again, and they still don't explain the
> actual workings of the system at all.
> 
> -Lewis	"You're always disappointed, nothing seems to keep you high -- drive 
> 	your bargains, push your papers, win your medals, fuck your strangers;
> 	don't it leave you on the empty side ?"  (Joni Mitchell, 1972)
> 
We will not post it to Internet, but we will provide it to the 
Cipherpunks, a large selected set choisen by Derek Atkins or 
his designee. 

Some men are as sure of their opinions as they are of what they know - 
Shakespeare.
NODE 1cf7870bRe: Internet Privacy Guaranteed ad (POTP Jr.)
I wrote:
# Gee, why are we all so worried about key management ?  It's just a load and
# go installation at each of the user sites !  ;)

("That was sarcasm, son")

IPG Sales writes:
> That is precisely why PCX Nvelopes is such an extraordinary system. 
> That is the beauty of PCX Nvelopes, it lifts that  burden from the 
> user, eliminates it entirely. You may have worried about key 
> management, but with our system, you will not have to do so in the 
> future. The system itself, manages all the OTPs, you do not have to do 
> anything but use the system. Key management is the problem with all existing 
> systems, but it is no problem at all with the PCX Nvelopes system, 

What protects each user's one time pads ("PCX Nvelopes", or whatever) ?  

Are they protected by an eight-character Unix account password ?  (This would 
be harder for implementations on traditionally single-user platforms like the
Macintosh and most of the Microsoft OSes, presumably.) 

Are they protected by a policy that says all users must lock away their IPG
disks or CDs when not in use ?  

Also, how are they protected from the people who generate the one-time pads
at IPG (and their friends and families) ? 

> as you 
> would see if you looked at the system, instead, of talking about something 
> when you have no idea at all of what it is about. 

As I said earlier, I read all your material and still had almost no idea
at all about what it is. If you don't tell people about the system, it's
extremely hard for them to do more than speculate.

> The first set of keys 
> must be sent by a secure source, US mail, FED EX, or whatever, but
> thereafter, all updates can be accomodated over Internet. 

Keys ?  Wait a minute, #2 of the "Dozen Reasons why PCX Nvelopes is
absolutely the finest Communication Security and Privacy system available",
according to http://www.netprivacy.com/ipg/dozbest.html, is:

"2. No Messy, Intrusive Passwords/Encryption Keys to get in your way and
worry about, forget about those troublemakers"

[...]
> all hardware generation of OTP's are irregular, otherwise they are not 
> random. 

I'm not sure what you mean by "irregular" in this context.

> Thus at times, a hardware source, such as ADC LOB system, can generate 
> nonrandom data, unless this is checked, it can destroyed the integrity of 
> your system. 

This doesn't quite jibe with my understanding of the typical use of a hardware
RNG. From what I have read, one starts with an unpredictable bit source with
some known bias, so that each original bit has somewhat less than one bit of
real entropy. The bias is "corrected" by combining the original bits to get
fewer bits with enough real entropy, and then repeating the process enough to
get enough final bits of real entropy. 

Could you explain what the acronyms "ADC" and "LOB" mean here ?  I
just tried a web search for the two together, and all I got was a page of
UFO acronyms, and some astronomical acronyms (LOB = Lick Observatory 
Bulletin). Schneier discusses hardware RNG at length in Applied Cryptography,
but he doesn't mention either acronym. I might guess that LOB = Low Order
Bits.

-Lewis	"You're always disappointed, nothing seems to keep you high -- drive 
	your bargains, push your papers, win your medals, fuck your strangers;
	don't it leave you on the empty side ?"  (Joni Mitchell, 1972)
NODE 219c02b8Re: Internet Privacy Guaranteed ad (POTP Jr.)
-----BEGIN PGP SIGNED MESSAGE-----

In article <199602200851.DAA02057@thor.cs.umass.edu>,
lmccarth@cs.umass.edu wrote:

> IPG Sales writes:

> > Thus at times, a hardware source, such as ADC LOB system, can generate 
> > nonrandom data, unless this is checked, it can destroyed the integrity of 
> > your system. 
> 

> Could you explain what the acronyms "ADC" and "LOB" mean here ?  I
> just tried a web search for the two together, and all I got was a page of
> UFO acronyms, and some astronomical acronyms (LOB = Lick Observatory 
> Bulletin). Schneier discusses hardware RNG at length in Applied Cryptography,
> but he doesn't mention either acronym. I might guess that LOB = Low Order
> Bits.

I'd say that you're right, and I'd also guess myself that ADC stands for
Analog-to-Digital Converter, so that an "ADC LOB system" is a hardware
random number generator that looks at the lowest order (and therefore
presumed noisy) bit of an analog-to-digital converter.

ObCrypto:  Would four years experience interpreting cryptic vanity
plates while commuting on the Nimitz Freeway be a good qualification for
an NSA cryptanalyst?  Would that experience also qualify me as a traffic
analyst? 

- -- 
   Alan Bostick             | "If I am to be held in contempt of court,
Seeking opportunity to      | your honor, it can only be because the court
develop multimedia content. | has acted contemptibly!"
Finger abostick@netcom.com for more info and PGP public key

-----BEGIN PGP SIGNATURE-----
Version: 2.6.2

iQB1AwUBMSn/a+VevBgtmhnpAQG14QMAmzKee6JNV+R5so+xsGN/bPtzmIdAUqES
KB3CJaIEWvKD6PWUQ7/L+j+f8Ugr9ZrXHOscjjIge1zLdwtMnRmzNO/vpO6kI/aq
loVXVhPvPwnlniO6FGF5QqddQ7fUn5gI
=kfQZ
-----END PGP SIGNATURE-----