// COMPLETE THREAD

Re: PGP, Inc.--What were they thinking?

4 expanded posts ยท every known parent and child

NODE fd4162c8Re: PGP, Inc.--What were they thinking?
I should point out before starting that I now work for Verisign. This
following personal opinion however and may not reflect any corporate policy
that may or may not exist.


I can understand the pressures on PGP to support key escrow. When I designed
the Shen trust system for the Web I allowed for an escrow facility for much
the same reasons that have been cited.

If it was not for the unrelenting pressure from the US government to support
GAK I am sure that commercial escrow would be a checkbox item. The problem
is that as long as the pressure is there any step towards commercial escrow
is also a step towards GAK.

The problem with PGP's move is that it is the first significant break by the
Internet software provider community. This will make it much easier for
Netscape or Microsoft to cave in. It will also build the pressure on them.
I wonder what would happen to Bills problem with the DoJ if he had a sudden
change of heart. Somehow I don't see Netscape and Microsoft holding the line
on GAK if PGP are happily exporting their product and grabbing market share.

I really did not expect Phil Zimmerman to be the first to blink.

I also don't understand it from the corporate perspective. PGP may be
picking up some business in the corporate market but at the cost of
alienating a significant part of the hacker community which has been his
best supporter up till now. I would think his best strategy would have been
to build on this customer base rather than sell it out at the first
opportunity.

If Phil Z. wants to get into the Enterprise market he is going to have to
start speaking their language. Most companies today are looking for open
standards. PGP may have been the de facto security solution three years ago
but the reality today is several million copies of Comminicator and Explorer
with S/MIME built in. If you are prepared to load certs manually for each
person you communicate with you can even use the Web of trust model with
S/MIME. Its easier if you can rely on a CA. I probably don't have to remind
many people on this list that few people make security a priority although
they are prepared to do so if it has little impact on them personally.

I really don't want to get into a standards flamewar, the point I'm making
is that this is a bigger issue in the Enterprise market than key escrow at
this point. Phil claims to have an RSA license, if he wants to go after the
enterprise market he can support S/MIME.


        Phill
NODE d148af98Re: PGP, Inc.--What were they thinking?
Phillip Hallam-Baker <hallam@ai.mit.edu> writes:
> I can understand the pressures on PGP to support key escrow. 

There is reasonable justification for key escrow, or recovery features
for _stored_ encrypted information.  The rate at which people forget
passwords alone suggests that this would be a good idea.

However the PGP design does much more than that: it allows third and
fourth parties to decrypt messages in transit.

> The problem with PGP's move is that it is the first significant
> break by the Internet software provider community. This will make it
> much easier for Netscape or Microsoft to cave in.

I think they could have implemented recovery of stored encrypted
files, and of saved email archives more easily without including
recovery information over the wire.  It's a security risk to send
recovery encrypted info over the wire encrypted to long term public
keys.

> It will also build the pressure on them.
> I wonder what would happen to Bills problem with the DoJ if he had a sudden
> change of heart. Somehow I don't see Netscape and Microsoft holding the line
> on GAK if PGP are happily exporting their product and grabbing market share.
> 
> I really did not expect Phil Zimmerman to be the first to blink.

Me either.

> I also don't understand it from the corporate perspective. PGP may be
> picking up some business in the corporate market but at the cost of
> alienating a significant part of the hacker community which has been his
> best supporter up till now. I would think his best strategy would have been
> to build on this customer base rather than sell it out at the first
> opportunity.

He could have built storage escrow with much less argument; almost no
argument in comparison I would expect.

> If Phil Z. wants to get into the Enterprise market he is going to have to
> start speaking their language. Most companies today are looking for open
> standards. PGP may have been the de facto security solution three years ago
> but the reality today is several million copies of Comminicator and Explorer
> with S/MIME built in. 

The obvious thing I think is for pgp to build systems which can
automatically interoperate with either.

Adam
-- 
Now officially an EAR violation...
Have *you* exported RSA today? --> http://www.dcs.ex.ac.uk/~aba/rsa/

print pack"C*",split/\D+/,`echo "16iII*o\U@{$/=$z;[(pop,pop,unpack"H*",<>
)]}\EsMsKsN0[lN*1lK[d2%Sa2/d0<X+d*lMLa^*lN%0]dsXx++lMlN/dsM0<J]dsJxp"|dc`
NODE d3ec8693Re: PGP, Inc.--What were they thinking?
In <01bcdf5a$4a2d3a60$06060606@russell>, on 10/22/97 
   at 10:20 PM, "Phillip M. Hallam-Baker" <hallam@ai.mit.edu> said:

>I really don't want to get into a standards flamewar, the point I'm
>making is that this is a bigger issue in the Enterprise market than key
>escrow at this point. Phil claims to have an RSA license, if he wants to
>go after the enterprise market he can support S/MIME.

Nothing personal Phil but that is the most brain dead sugestion I have
seen on this list in a long time. Well I can see that getting a paycheck
from Verisign hasn't tanted your viwes in favor of an inferior standard.

-- 
---------------------------------------------------------------
William H. Geiger III  http://www.amaranth.com/~whgiii
Geiger Consulting    Cooking With Warp 4.0

Author of E-Secure - PGP Front End for MR/2 Ice
PGP & MR/2 the only way for secure e-mail.
OS/2 PGP 2.6.3a at: http://www.amaranth.com/~whgiii/pgpmr2.html                        
---------------------------------------------------------------
NODE e2963114Re: PGP, Inc.--What were they thinking?
Phillip M. Hallam-Baker wrote:
>
> I should point out before starting that I now work for Verisign. This
> following personal opinion however and may not reflect any corporate policy
> that may or may not exist.

Knowing who is pulling Verisign's strings, I sincerely doubt that
a thinly-veiled character assassination of Phil Zimmermann is out
of line with their corporate policy.

It's a little early to start cumming in your pants over PGP's loss
of reputation capital, P[s]hill.
When the dust is finished settling in the battle deciding whether we
will live in a total surveillance state, or not, Verisign is likely to
end up at the bottom of the dust-bin (unless, of course, you accomplish
your aims at the company very, very quickly--which is highly unlikely).

Phill Half-Baked
"Stick a knife in me, I'm half-done."