Feeds

PGP creator: Net is like 'downtown Bagdad'

The internet depends on strong crypto, Zimmerman says

Security for virtualized datacentres

Interview PGP (Pretty Good Privacy), the encryption software package created by privacy advocate Phil Zimmermann, celebrated its fifteenth birthday last week.

Developed to help human rights activists to communicate safely via the net, Zimmermann’s software is deployed by more than 35,000 businesses and millions of individuals. In the last 15 years encryption has grow from a product of questionable legal status to a government-mandated approach to protecting sensitive ecommerce transactions.

Strong encryption used to be viewed as something 'dodgy', prompting the question: "what are you trying to hide". Now firms are legally required to encrypt data or risk falling foul of information disclosure laws and corporate governance regulations,

Zimmermann says PGP has been "more successful than I first envisioned", even though email encryption technology is less commonplace than many pundits predicted in the late 1990s.

The internet has moved on a great deal in the last 15 years and not always been for the best, he says. "The internet has gone from been a gentleman's club for academics to something fiendishly hostile. It's changed from something like a university campus to downtown Bagdad," he told The Register.

The use of PGP remains politically-charged. "PGP is used by agents of major governments and has become a tool in the war on terror. Unfortunately, and I wish this wasn't true, it's also used by the bad guys. Like any computer technology, encryption can be used for both good or ill," Zimmermann said.

The original cypherpunk

Phil Zimmerman pictureZimmermann was the first developer to make public key encryption software easily available to the public. After he released PGP's source code - a step he took to make sure the code could be checked by independent experts for backdoors - the technology became available of the then fledgling internet through Usenet. Zimmermann said he had no part in distributing the software outside the US, but its availability overseas still brought the unwelcome attentions of the US government.

A licensing dispute over the use of the RSA algorithm in PGP escalated when the US Customs Service began a criminal investigation of Zimmermann in February 1993 over allegations of "munitions export without a license". At the time encryption products stronger than 40bits (PGP was a 128bit product) were considered a munition.

For three years, Zimmermann lived under the shadow of this investigation until the case was dropped in early 1996. Zimmermann said this difficult period brought some benefits.

"The criminal investigation alerted public to existence of PGP and increased its credibility. People like to root for the underdog," he said.

The closure of the case left Zimmermann free to establish a company (PGP Inc.) and to market updated versions of his software and related products. Unfortunately, Zimmermann, tells us this original firm was infected by the dotcom madness of the time and soon collapsed under debt. "This was the '90s and firms thought you had to spend quickly in order to make money. Unfortunately it didn't work," he said.

PGP Inc. was acquired by Network Associates (NAI) in December 1997, and Zimmermann stayed on for three years as a senior fellow despite his view, in retrospect, that PGP "languished" under the custody of NAI.

Network Associates dropped development of the software when it was faced by its own financial problems, four years or so ago. But the technology was revived after it was acquired by a new firm, PGP Corporation, in 2002. Zimmermann continues as a special advisor and consultant to PGP Corporation while working on a number of other projects.

Dial Z for Zfone

Chief among these is Zfone, a software package designed to encrypt VoIP calls, which is in beta test. Zimmermann said technology of this type guards against the possibility of organised criminals placing spyware on machines as a way to monitor conversations. The software adds encryption features to VoIP programs such as Gizmo and SIPphone. But it does not interoperate with Skype, which utilises a separate (and proprietary) encryption algorithm.

"Details on how Skype works haven't been publically released so I've been unable to accommodate it," Zimmermann explained.

The priorities for Zfone's future development include OEM deals with VoIP phone manufacturers and embedding the technology in VoIP clients, he added.

Zimmermann said he'd never experience government harassment over Zfone, in contrast to his experiences in developing PGP. "The world has changed. The internet depends on strong crypto. I hope governments understand that," he said. ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
NASTY SSL 3.0 vuln to be revealed soon – sources (Update: It's POODLE)
So nasty no one's even whispering until patch is out
Russian hackers exploit 'Sandworm' bug 'to spy on NATO, EU PCs'
Fix imminent from Microsoft for Vista, Server 2008, other stuff
Microsoft pulls another dodgy patch
Redmond makes a hash of hashing add-on
'LulzSec leader Aush0k' found to be naughty boy not worthy of jail
15 months home detention leaves egg on feds' faces as they grab for more power
Forget passwords, let's use SELFIES, says Obama's cyber tsar
Michael Daniel wants to kill passwords dead
FBI boss: We don't want a backdoor, we want the front door to phones
Claims it's what the Founding Fathers would have wanted – catching killers and pedos
Kill off SSL 3.0 NOW: HTTPS savaged by vicious POODLE
Pull it out ASAP, it is SWISS CHEESE
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Win a year’s supply of chocolate
There is no techie angle to this competition so we're not going to pretend there is, but everyone loves chocolate so who cares.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.