// COMPLETE THREAD

Re: PGP Employee on MKR

5 expanded posts ยท every known parent and child

NODE 83e4eb97Re: PGP Employee on MKR
A PGP Employee wrote:
>> Unfortunately these people just don't get it. Corporations refused
>> to buy 5.0 because it did not have any way for the corps to get at
>> email encrypted to their employees. There are some very legitimate
>> uses of this, such as when an employee dies and someone else has
>> to take over for them.

No, PGP Inc 'just don't get it'. I'm sure that there are plenty of people
out there who disagree with the entire concept of CMR, and I'm not very
happy with it myself. But that's not the most important issue here.

Since this point just doesn't seem to get through to PGP Inc employees, I'm
going to shout.

FORCING ENCRYPTION TO MULTIPLE KEYS FOR ONE RECIPIENT IS ONE STEP AWAY FROM
GAK. FORCING ENCRYPTION TO MULTIPLE KEYS FOR ONE RECIPIENT IS ONE STEP AWAY 
FROM GAK! FORCING ENCRYPTION TO MULTIPLE KEYS FOR ONE RECIPIENT IS ONE STEP 
AWAY FROM GAK!! FORCING ENCRYPTION TO MULTIPLE KEYS FOR ONE RECIPIENT IS ONE 
STEP AWAY FROM GAK!! !!!*FORCING ENCRYPTION TO MULTIPLE KEYS FOR ONE RECIPIENT 
IS ONE STEP AWAY FROM GAK*!!!

Is that clear enough? Do you understand what I (and, apparently, Adam Back
and others) am saying now? The problem is not so much with the fact that
you're supporting company needs, but with the way you're doing so.

>> They also don't seem to realize that you always have the ability
>> to remove the MRK from your list of recipients.

Just as government-supported rating schemes are purely voluntary and will
be so for, oh, I don't know, a couple of years? Once the infrastructure is
there, we need only an executive order to make it mandatory. If this 
software ships in its current form and becomes the dominant player in the
market, in four or five years all keys will be GMR keys with the FBI or
NSA as one mandatory recipient. You 'privacy zealots' will have created the
government's surveillance infrastructure. I hope you'll feel proud.

>> Sometimes I really feel like screaming at these people. _All_ of
>> the developers at PGP are personal privacy zealots and no one
>> likes the idea of the MRK. 

Good. Then reimplement it to avoid giving the government a GAK/GMR
infrastructure. Yesterday I posted a modified version of PGP's CMR to
the cypherpunks list which can't be used for GAK because it only encrypts
to one key; Jon Callas just told me I'd 'redesigned PGP 5.5'. Cool. I've redesigned PGP 5.5 so that it can't support GAK; in that case, please 
implement it, or accept that you're deliberately choosing to support the 
thugs in governments around the world and have become part of the problem.

>> That is why we refuse to make them
>> required. 

Just 'mandatory voluntary' for companies which have your SMTP enforcer
enabled. What's the difference?

>> Most everyone at PGP has
>> internalized personal privacy as a cause (actually most had it
>> before they joined PGP).

So prove it. Stop working on creating a GMR/GAK infrastructure. The current
PGP CMR system has numerous problems which many people have pointed out on
the cypherpunks list, and you'd do better to solve those problems rather 
than see them in a major New York Times article about '101 Ways PGP 5.5 
Harms Company Security'. How long will PGP Inc last when it's reputation 
for providing secure products is in tatters, because it chose to release a product which deliberately reduced company security and opened them to new threats, rather than redesign their CMR to remove these problems?

The current CMR implementation is bad for us, bad for PGP Inc's commercial
customers, and bad for PGP Inc. Why is this so hard for you to accept? Why
ship a bad product when you can fix the problems?

    Mark
NODE 1399848bRe: PGP Employee on MKR
I have watched this silly debate for some time now. PGP pulled an awsome
hack on corporate America, bringing strong crypto to thousands of
corporate drones,  while Cypherpunks, the crypto elite, seems incapable of  
reponding with anything other than to engage in frenzied mutual
masturbation fueld by GAK fantasies.

This is sad. Very sad.

--Lucky

On Thu, 23 Oct 1997 mark@unicorn.com wrote:

> 
> 
> A PGP Employee wrote:
> >> Unfortunately these people just don't get it. Corporations refused
> >> to buy 5.0 because it did not have any way for the corps to get at
> >> email encrypted to their employees. There are some very legitimate
> >> uses of this, such as when an employee dies and someone else has
> >> to take over for them.
> 
> No, PGP Inc 'just don't get it'. I'm sure that there are plenty of people
> out there who disagree with the entire concept of CMR, and I'm not very
> happy with it myself. But that's not the most important issue here.
> 
> Since this point just doesn't seem to get through to PGP Inc employees, I'm
> going to shout.
> 
> FORCING ENCRYPTION TO MULTIPLE KEYS FOR ONE RECIPIENT IS ONE STEP AWAY FROM
> GAK. FORCING ENCRYPTION TO MULTIPLE KEYS FOR ONE RECIPIENT IS ONE STEP AWAY 
> FROM GAK! FORCING ENCRYPTION TO MULTIPLE KEYS FOR ONE RECIPIENT IS ONE STEP 
> AWAY FROM GAK!! FORCING ENCRYPTION TO MULTIPLE KEYS FOR ONE RECIPIENT IS ONE 
> STEP AWAY FROM GAK!! !!!*FORCING ENCRYPTION TO MULTIPLE KEYS FOR ONE RECIPIENT 
> IS ONE STEP AWAY FROM GAK*!!!
> 
> Is that clear enough? Do you understand what I (and, apparently, Adam Back
> and others) am saying now? The problem is not so much with the fact that
> you're supporting company needs, but with the way you're doing so.
> 
> >> They also don't seem to realize that you always have the ability
> >> to remove the MRK from your list of recipients.
> 
> Just as government-supported rating schemes are purely voluntary and will
> be so for, oh, I don't know, a couple of years? Once the infrastructure is
> there, we need only an executive order to make it mandatory. If this 
> software ships in its current form and becomes the dominant player in the
> market, in four or five years all keys will be GMR keys with the FBI or
> NSA as one mandatory recipient. You 'privacy zealots' will have created the
> government's surveillance infrastructure. I hope you'll feel proud.
> 
> >> Sometimes I really feel like screaming at these people. _All_ of
> >> the developers at PGP are personal privacy zealots and no one
> >> likes the idea of the MRK. 
> 
> Good. Then reimplement it to avoid giving the government a GAK/GMR
> infrastructure. Yesterday I posted a modified version of PGP's CMR to
> the cypherpunks list which can't be used for GAK because it only encrypts
> to one key; Jon Callas just told me I'd 'redesigned PGP 5.5'. Cool. I've redesigned PGP 5.5 so that it can't support GAK; in that case, please 
> implement it, or accept that you're deliberately choosing to support the 
> thugs in governments around the world and have become part of the problem.
> 
> >> That is why we refuse to make them
> >> required. 
> 
> Just 'mandatory voluntary' for companies which have your SMTP enforcer
> enabled. What's the difference?
> 
> >> Most everyone at PGP has
> >> internalized personal privacy as a cause (actually most had it
> >> before they joined PGP).
> 
> So prove it. Stop working on creating a GMR/GAK infrastructure. The current
> PGP CMR system has numerous problems which many people have pointed out on
> the cypherpunks list, and you'd do better to solve those problems rather 
> than see them in a major New York Times article about '101 Ways PGP 5.5 
> Harms Company Security'. How long will PGP Inc last when it's reputation 
> for providing secure products is in tatters, because it chose to release a product which deliberately reduced company security and opened them to new threats, rather than redesign their CMR to remove these problems?
> 
> The current CMR implementation is bad for us, bad for PGP Inc's commercial
> customers, and bad for PGP Inc. Why is this so hard for you to accept? Why
> ship a bad product when you can fix the problems?
> 
>     Mark
> 
> 


-- Lucky Green <shamrock@cypherpunks.to> PGP encrypted email preferred.
   "Tonga? Where the hell is Tonga? They have Cypherpunks there?"
NODE 6510bf8eRe: PGP Employee on MKR
* Lucky Green wrote:
>corporate drones,  while Cypherpunks, the crypto elite, seems incapable of  
>reponding with anything other than to engage in frenzied mutual
>masturbation fueld by GAK fantasies.
>
>This is sad. Very sad.

Look at Open PGP and shut up.
NODE bdbd008bRe: PGP Employee on MKR
Lucky Green <shamrock@cypherpunks.to> writes:
> I have watched this silly debate for some time now. PGP pulled an
> awsome hack on corporate America, bringing strong crypto to
> thousands of corporate drones, while Cypherpunks, the crypto elite,
> seems incapable of reponding with anything other than to engage in
> frenzied mutual masturbation fueld by GAK fantasies.

Lucky, all we're saying is that there are better ways to do it.  What
is so difficult with that?

We didn't say: "don't have disaster recovery for stored data."  (Well
I didn't and I don't think Mark did either).

We just said: "make it is diffcult as possible to abuse for GAK while
you're designing it".

> This is sad. Very sad.

If you want to get into the debate, at least start making some
specific points criticizing the obvious alternatives:

"corporate key escrow is better than commercial message recovery"

This is so because CKE requires access to the data.  CMR doesn't, the
recovery info goes over the wire.

You of all people I would have thought would see this one clearly, it
was only a few weeks ago you were arguing that the "key escrow"
argument of the Fed's was a fallacy becuase people wouldn't be using
their comms keys to encrypt stored data.  (Or something along those
lines).  Same thing here, just applied to corporate environments.

Adam
-- 
Now officially an EAR violation...
Have *you* exported RSA today? --> http://www.dcs.ex.ac.uk/~aba/rsa/

print pack"C*",split/\D+/,`echo "16iII*o\U@{$/=$z;[(pop,pop,unpack"H*",<>
)]}\EsMsKsN0[lN*1lK[d2%Sa2/d0<X+d*lMLa^*lN%0]dsXx++lMlN/dsM0<J]dsJxp"|dc`
NODE 44029fb9Re: PGP Employee on MKR
At 9:49 PM +0200 10/23/97, Lucky Green wrote:
>I have watched this silly debate for some time now. PGP pulled an awsome
>hack on corporate America, bringing strong crypto to thousands of
>corporate drones,  while Cypherpunks, the crypto elite, seems incapable of
>reponding with anything other than to engage in frenzied mutual
>masturbation fueld by GAK fantasies.

Well said, Lucky.

The next step to gaining the wide-spread and richly deserved acceptance
that should be PGP's fate is to certify it as a recognized, codified, and
testable method for using strong crypto.  That is what the IETF effort is
all about.

Remember the IETF is devoted to enabling anyone, anywhere who possess the
wit, perserverance and means to communicate over digital networks to do so.
As we are all aware, that means having the ability to do it privately and
securely.  That is way the standardization effort in the IETF is so
fundamentally important.  No other standards body has the world-wide
breadth nor the commitment to the individual's right to use and develop
computer technology than the IETF.  It is our best shot to make PGP a
standard.

We can't afford to blow it.

best,

john  w noerenberg, ii
jwn2@qualcomm.com
pager: jwn2@pager.qualcomm.com
 --------------------------------------------------------------------
  "A beautiful idea has a much greater chance of being a correct idea
   than an ugly one."
 -- Roger Penrose, "The Emperor's New Mind", 1989
 --------------------------------------------------------------------