Feeds

PGP dies of neglect – your alternatives

A key for all seasons

  • alert
  • submit to reddit

Combat fraud and increase customer satisfaction

Letters Our stories PGP dies of neglect: NAI shrugsHow we can save PGP - Zimmerman drew the following responses:-


I'm saddened to hear NAI is trying to kill PGP (or at least failing to try to keep it alive).

Are you aware that free versions of PGP for non-commercial use can be found at: http://web.mit.edu/network/pgp.html?

Thank you for your article,

Ben Levy


Subject: PGP Personal Edition (?)
Date: Fri, 8 Mar 2002 14:49:08 -0700
-----BEGIN PGP SIGNED MESSAGE-----

Sir,

I read your article published at this web site
:(http://www.theregister.co.uk/content/54/24336.html)

You made reference that a desktop version of PGP is no longer available. While this may be true for the NAI versions, MIT is still distributing a desktop GUI version that has a lot of the same functions described in the package mentioned in your article. I am only writing to seek some clarification and inform you and potentially your viewers that they can still download a use a stable and functional version of PGP for personal use. The article confused me in stating that a GUI was no longer available, except in trial form.

Guess the article was not crystal clear to me (as a lot of things are) and wanted to make sure that this great product does not get washed up in NAI's foolish maneuvers.

Or, I could be completely wrong in all my statements, but last I checked you can still get it from MIT (http://web.mit.edu/network/pgp.html).

Lets hope that PGP lives forever!

Thanks,
Sean Gash
IS Administrator


Subject: Crypto Kong and other encryption stuff

Hi Andrew

Regarding your article about PGP or the lack thereof. There are some alternatives these days, none are as easy to use and not all are up to the
enterprise, but good enough for a technical home user.

Crypto Kong:

Crypto Kong uses Elliptic Curve Cryptography and only runs on Windows. Which is a pain for those of us who avoid Windows like the plague.

Elliptic Curve Cryptography is interesting in light of the latest advances in factoring technology because it provides an alternative to 'standard'
discrete logarithm and factoring based crypto.

I have spoken with James D via email about five years ago and he is certainly not going to sell out. He has continued to develop Crypto Kong
off (IIRC) his own back.

Hushmail:

I'm wary of any web based system, if only because its not under direct control of the user and hosts multiple users. But that said they apparantly provide an OK OpenPGP based service and it works with most standard browsers.

PGP International:

Not strictly for customers, but then not strictly for the US either.

Gnu Privacy Guard:

*nix users should head this way; command line, fast, lots of plugins and works with most *nix sytems and comes with a slew of plugins, including GPGME which provides a simple library for applications developers.

Developed with German government money and pretty quickly updated any time there has been a problem (There was a problem with split signatures that was rapidly solved, as with a lot of Free Software).

I am sure there are probably more out there but I cannot recommend them as I have never personally used them, I only emailed BTW because I think using cryptography is a major issue and it is better to say something than
say nothing ;-).

Regards

John B Everitt


Bugger Network Associates!

Let Zimmerman go back to 6.5.8 [which is what I still use] and start from there.

Privacy is IMO more about what your application can do or prevent others doing, more than what you look like while you're doing it, although deception no doubt, has its place in a good privacy solution :-)

As for Mac OSX and WinXP, that's a downside for Microsoft in selling new products, not for PGP per se AFAICS.

Michael O'Neill
O'Neill Quigley & Associates


I was interested to see that NAI had notified their customers. Only yesterday I was looking to find if one could buy the commercial PGP Desktop.
Of course, non-commercial users still have http://www.pgpi.org/.

As far as I can tell, the only real commercial alternative is the free GPG, which can be used with WinPT (Windows Privacy Tray) on all Windows systems.

The WinPT web site is http://www.winpt.org/ . The WinPT graphical installer includes GPG, and provides a very similar user interface to PGP. It's easy to install, but has the same naive user problems as PGP in understanding how to manage keys.

But then, the TLAs would not let you advertise that, would they?

Andrew Yeomans
Global IT Security Architecture and Strategy, Dresdner Kleinwort Wasserstein


Of course, given that Ashcroft wants his fingers in everything, and that PGP actually *works*, and given the prior treatment of Phil Zimmerman
re: PGP's crypto provisions, are you really surprised it's being left out to dry?

Bob Halloran
Jacksonville FL

Top three mobile application threats

More from The Register

next story
Och aye! It's the Loch Ness Monster – but only Apple fanbois can see it
Fondleslab-friendly beastie's wake spotted... OR WAS IT?
Japanese boffin EYES up big bucks with strap-on digi-glasses
AgencyGlass saddles user with creepy OLED display
Sleuths find nosy NORKS drones on the Chinternet
UAVs likely to have been made in the Middle Kingdom
Spanish village called 'Kill the Jews' mulls rebranding exercise
Not exactly attractive to the Israeli tourist demographic
Dorian Nakamoto gets $23,000 payout over Bitcoin invention saga
Maintains he didn't create cryptocurrency, but will join community
Pirate Bay's 10 millionth upload: Colour us shocked, a SMUT FLICK
P2P badboys show online piracy is alive and humping
Teen girl arrested with 70-year-old man's four inch weapon inside her
Charged with introducing .22 snubbie to penile facility. It wasn't firing blanks
Oz bank in comedy Heartbleed blog FAIL
Bank: 'We are now safely patched.' Customers: 'You were using OpenSSL?'
Forget the beach 'n' boardwalk, check out the Santa Cruz STEVE JOBS FOUNTAIN
Reg reader snaps shot of touching tribute to Apple icon
prev story

Whitepapers

Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mainstay ROI - Does application security pay?
In this whitepaper learn how you and your enterprise might benefit from better software security.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.