Slashdot Mirror


Network Associates Gives Up Search for PGP Buyer

nakhla writes: "I came across this article which states that Network Associates has given up the search for a buyer for its PGP division. The company has laid off 18 workers, and plans to continue to maintain the product for one year. It's a good thing that there are still products like GnuPG and others out there for people who need cheap, reliable encryption."

31 of 180 comments (clear)

  1. Sad.. by dj28 · · Score: 4, Interesting

    I actually bought a version of PGP Personal Security 7.0.3 from these guys. It comes with some nice extras such as a very nice firewall. It's a shame that not enough people contributed to the development. Hopefully they will open source the latest version so that development can continue for long after one year.

    1. Re:Sad.. by kerrbear · · Score: 3, Interesting
      I actually bought a version of PGP Personal Security 7.0.3 from these guys.

      Er, what happens to all the files people encrypted with PGP ten years from now when their personal versions no longer run on the new OSs? If PGP Personal Security is rendered obsolete, will there be a way to retrieve those files, or should they be unencrypted now and re-encrypted with something that is going to stick around?

      I've got some pretty important .pgp files lying around. Should I switch to something else or am I not understanding something here?

  2. Mixed feelings by rknop · · Score: 5, Informative

    I've got mixed feelings about this. On the one hand, PGP was revolutionary and is probably one of the main reasons encryption is as free and available today as it is. If Phil hadn't released that (at the expense of considerable suffering), I suspect that the governments of the world would have been able to clamp down on encryption big time, and all of us law abiding types would take it as an axiom that none of us really need anything like that, only terrorists do. It's sad to see the company that was carrying that torch give up on it. I fear this is just one more indication that personal encryption of e-mail and such isn't really going to catch on with the masses.

    On the other hand, NAI's not been a perfect angel. Phil left them because of differences about releasing (if memory serves) source code-- not because Phil is an open source advocate per se, so much as for reasons of being able to verify the security. And, myself, I'm an open source geek and have been using GnuPG for quite some time as my encryption software of choice. There still is hope that GnuPG will be turned into something that can catch on with the masses (just like there's hope, however faint, that things like GNOME and KDE will catch on with the masses).

    -Rob

    1. Re:Mixed feelings by smnolde · · Score: 3, Informative
      See winpt.org.

      I use it quite a bit to sign emails and the interface is pretty clean, too.

  3. It's a shame by WinterSolstice · · Score: 3, Interesting

    That a product as great as PGP is going under. I personally think that if it had stayed the way it was before the buyout, it would still be around. I wonder if something like this could eventually happen to /. or Gnome.

    This is the reason I am always concerned when a major company snatches up some cool new technology; they see it in major use by techs/geeks/etc, and think, "hey, with some good marketing...". They fail to understand what features matter to the original audience, fail to capture a new audience, and then drop the product.

    In the meantime, it strands people who used to like the product. I was a major PGP user since its inception. Now, I can't stand the darned thing. I tried the Palm and Pocket PC versions, I tried the Windows versions. They added too many toys and widgets to a small, light application.

    Oh well. I hope the Gnu PGP clone keeps up.

    -WS

    --
    An operating system should be like a light switch... simple, effective, easy to use, and designed for everyone.
  4. High Profile Use Case by SirSlud · · Score: 3, Insightful

    PGP encryption could use a nice high profile use case where its use saved the ass of someone the average joe could relate to.

    I really dont think that the average consumer is concerned about having their private messages intercepted. (The logic is usually: "I dont do anything bad. Hey, waitaminute. Why are /you/ so interested ... ?")

    That being said, I'm not surprised that it was difficult to find a buyer for them. The market really hasn't encountered the high profile case that justifies wide spread deployment of PGP use. I think .. ?

    --
    "Old man yells at systemd"
    1. Re:High Profile Use Case by sammy+baby · · Score: 3, Informative

      A good use case would be a major bennie, but I think you're coming at it from the wrong end. PGP isn't just used to encrypt/decrypt messages. The canonical four tasks:

        • Encryption/Decryption (Shh! Don't tell anyone this!)
        • Tamper Detection (Dude. Did someone mess with this message?)
        • Authentication (Hey - who really wrote this?)
        • Nonrepudiation (Fess up. I know you wrote this.)

      Rather than looking for situations where PGP prevented someone from intercepting a communictation - often very difficult to know ever happened - I'd be looking for case studies in which someone tried to tamper with a message and was foiled because of the PGP signature, or tried to forge a message... you get the idea.

  5. PGP is a joke by Dwonis · · Score: 3, Insightful

    Who cares? I stopped taking PGP seriously when NAI decided to stop releasing source code and expected me to 'just trust them' instead. Any crypto company that does that obviously knows nothing about security.

  6. What difference will it make? by maelstrom · · Score: 5, Funny
    It's not like there is highspread usage of PGP/GPG anyway. I have been trying to use PGP ever since Phil Zimmerman was still coding on it himself, but I've never been able to convince any of my friends to use it often enough to make it useful.

    I'm glad the option is there, and I know it's done a lot of good in a lot of places, but even using e-mail encryption automatically draws attention to yourself. It would be far better if everyone used it for every e-mail they sent. It would be great if keysigning and verification was a normal event in meatspace, but it just isn't to be. How is it that SSH and OpenSSH became so widespread but PGP and GPG haven't?

    I think it's because PGP and GPG have such a sucky interface. It takes me forever to read the manual every time, and the integration with current mail programs sucks! Evolution seems to be fixing this and I know mutt and pine can support it, but it's just too much work to setup if no one else you e-mail can do it too!

    Is there any hope? I'd like to think so, but only if it becomes the default in hotmail and MS Outlook will it become widespread, and what are the odds of that? *sigh*

    --
    The more you know, the less you understand.
    1. Re:What difference will it make? by Boiling_point_ · · Score: 5, Insightful
      Is there any hope? I'd like to think so, but only if it becomes the default in hotmail and MS Outlook will it become widespread, and what are the odds of that?

      That's the trouble with encryption, and security in general. It takes effort to be secure. You can trust an algorithm with your life, but do you trust the piece of software you installed on the computer you assembled out of parts you bought off the shelf? Sadly, strong encryption built as a default into something like Outlook might cause more trouble than its worth, in misplaced trust.

      Most Outlook users wouldn't know how to tell if their private key had been compromised by some email malware. If they're using email for tasks that SHOULD be kept private because they trust that Outlook will make it safe, then where will we be?

      --
      "If you create user accounts, by default, they will have an account type of Administrator with no password." KB Q293834
    2. Re:What difference will it make? by Foxman98 · · Score: 3, Insightful

      Can't agree with you more. I setup PGP/GPG for myself at one point in the past. Fact of the matter is, hardly anyone uses it. The reason for this? Simple - the average e-mail user is not aware of how open their e-mail really is. I remember eplaining to a co-worker that their e-mail was readable to anyone in the world who really wanted to. After explaining this fact (the whole "don't write anything you wouldn't write on a postcard" theory) they still didn't seem to "get it". So I decided to show them. I had them send a message to another co-worker while dsniff was watching their machine. Should've seen the look on their face when they say the e-mail displayed on my terminal. Point is - average user hears about, and knows that e-mail isn't entirely secure, but I don't think they realize just a) how insecure it is and b) how easy (and illegal) it can be to sniff it.

      --
      S.t.e.v.e.
    3. Re:What difference will it make? by Dr_Claw · · Score: 3, Interesting
      That's the trouble with encryption, and security in general. It takes effort to be secure.

      Absolutely. There are two huge problems. Firstly, it's easy to use things like PGP and set things up so that it's easily crackable. That requires knowledge (at all levels, from something as simple like making sure your private keys are only accessable by you, to the code using decent random generators).

      Secondly, you have to care about being secure all the time. One lapse and you're wide open. This is an even bigger sticking point for the masses. Just the other day I was ranting about certain programs (I won't go into which ones here), and for each one of my main reasons for not using them was security or privacy concerns. The person I was trying to convince noticed that and basically asked why that was a big deal. This kind of took me by suprise, and so I did a quick poll of other reasonably computer literate friends (they would all know about PGP for example). Sure enough, most of them do not care if files on their computer can be read, so long as damage isn't done to the PC, etc, etc. I don't understand it, but it appears people are like that.

      One random thought is that really email could do with a big overhaul. SMTP, email format, all kinds of aspects. Building encryption and authentication into that from the start would make things a hell of a lot cleaner and help make the above problems less of an issue. But sadly I think I'm dreaming that that will happen any time soon.

  7. Encryption Crackdown? by flipflapflopflup · · Score: 4, Interesting

    Maybe a smells a bit of conspiracy-theory, but this article at The Register opens the floor to the idea that NIA's decision isn't entirely due to commercial factors, and in fact looks a bit "fishy".

    Quite an interesting point - why would they give up on such a good product like this? And who could gain from them giving up a product like this?

  8. PGP app user interface by throwaway18 · · Score: 3, Interesting

    I'v been an ocassional user of PGP for year, first the DOS client then GPG on linux.

    A friend of mine tried to use the freeware NA windows version. Hes a typical windows user and won't read instructions. After giving him a five minute talk saying "Other people use you public key to write messages to you, only you can read the message with your private key etc". Days later I call in at his house and he had not managed to use it. The user interface was horrible. Despite having used command line PGP for user and having a quick look at the help I couldn't find his keyring or work out how to use it from a quick look at the menus.

    I can't imagine what the staff working on PGP were doing, certainly not useability

    There were three background processes running on his already unstable win98 machine poping up box's demanding he type in his details and register. I think he reinstalled windows in the end. People who use PGP are gneerally a bit paranoid, annoying them by trying to make tem register seems pointless.

  9. Email Integration with GnuPG by Dimwit · · Score: 5, Informative

    First, some kudos to the GnuPG team. I think this is one example of free software really taking over a given market. I only know of one person who uses the commercial version of PGP, and that's because his job requires it. Everyone else I know uses GPG.

    Now:

    For those of you lucky enough to be using MacOS X (go ahead a flame me - I've been using Unix for ten years, and MacOS X rox my sox), just grab a copy of GnuPG from Fink and install GnuPG.

    After that, grab a copy of PGPMail from Sente, and use the easy, one-drag install. It's still in beta, but it's damn nice integration.

    For reference, I'm running MacOS X 10.1.3. When I send an email to someone whose public key is in my keyring, I just click the button "Encrypt" before I click send. Voila. When I receive something encrypted, I have the option of having it automatically decrypt, or I just click "decrypt" in the toolbar. Very nice.

    --
    ...but it's being eaten...by some...Linux or something...
    1. Re:Email Integration with GnuPG by Random+Walk · · Score: 3, Interesting
      Sylpheed has good support for GnuPG, and is my favourite MUA on Linux.

      The drawback is: I would like very much like to use the same e-mail client on Linux and Windows, but sylpheed is only theoretically cross-platform. On ftp.gnupg.org, there is a w32 build of sylpheed 0.4.60 which is buggy like hell, and I have no idea how it was compiled (otherwise I would rebuild a newer version).

  10. Fatal Mistakes.... by CDWert · · Score: 3, Interesting

    Network Associates made a fatal mistake in my opinion, that singularly was to belive people are smart enough to ACTUALLY KNOW they need encryption.

    People in general, Im not talking slashot techno geeks. Have NO clue WHATSOEVER that information can be snatched from the net. I have told people they have mail bouncing only to see hen freak and become accusitory , HOW do You KNOW ?? You mean You could READ IT ? Blah Blah Blah, I look at em and say yeah but to bwe honest I could give a crap less what you write and to who. hat usually tones em down a notch.

    BUT Back to the point, If someone dosent KNOW there is a NEED then there is NO market for the product , If people dont buy it because they dont know there is a need can you blame em ? If someone tried to sell you say a under the desk testicle shield for radiological effects from monitor transmission would you buy it ? a few would , but most no , WHY ? Becaues if here is no problem, the product COMPLETLEY loses its percieved value.

    Now, that said they are in a bad market to try and pitch the inherent Insecurity of networks, being Network Associates and all...

    --
    Sig went tro...aahemmm.....fishing........
  11. Encryption and open source by pinkUZI · · Score: 5, Interesting

    Encryption is one of those things that goes really well with open source. PGP started out as Philip Zimmermann's free and open project which he released with a written warning against software that locked away its source code and algorithms. This makes it a little difficult to go back to closed source and proprietary encryption methods. The internet community's love affair with PGP was broken when Phil quit working with Network Associates. The trust wasn't with PGP alone, it was with Phil heading up PGP's development that drew the trust of us all.
    So, its not too surprising that Network Associates is having a little trouble trying to pawn off a product that has no market.

    Exit PGP, enter GnuPG.

    --
    You are receiving this message because your browser supports Slashdot Sigs and you have Slashdot Sigs enabled.
  12. Smartcard support by nakhla · · Score: 4, Informative

    One of the coolest things about the latest version of PGP (Corporate Desktop, I believe) is its support for smartcards. I have a Rainbow iKey, but it's pretty much useless for personal use because I don't have a certificate compatible with the device. With the newest version of PGP I could store PGP certs/keys on my iKey. It would be great if this kind of support was built into GnuPG. I'd LOVE to be able to use my iKey for PGP on Linux or for token-based authentication

  13. Encryption and the masses by EschewObfuscation · · Score: 5, Insightful

    There are, IMHO, two things that keep the average email user from using encryption:

    First, it has to be absolutely transparent. It can't put more of an overhead on a standard email send-and-receive than already exists. Key management would have to become at least as easy as address book management (say, having addresses and keys automatically integrated into your keyring). While this would present a security hole, most users aren't going to want to go and verify keys. They're also not going to want to type their password every time they send an email. Most users of apps like Outlook just store their passwords on their PCs anyway, because they can't be bothered logging in once per session (ever deal with someone who didn't remember their password because they never type it in anymore?). IIRC, PGP had several of these features, but with some apps you still had to encrypt to the clipboard and then paste the encrypted message back into your document.

    Second, to even get people to do this minimum, and to demand it in products, they have to see the need for it. Phil put it best, I think, when he drew an analogy in the docs for PGP. I can't remember the exact wording, but it was something along the lines of "So you're not saying anything illegal. What would you think if the government outlawed envelopes, and all mail had to be sent on postcards?

    Most people don't believe how easy it is to read email, because they have no idea how to go about it. Instead, they shrug and say that they don't care. If instead you ask them how they'd feel about having all of their corporate correspondence and private letters going out on postcards, they'd think twice, and (hopefully) bite the bullet and start using something like PGP. There can be a huge market for applications like PGP, but it has to be sold to people with the right message, and it has to, even at the expense of some security (and yes, I realize the implications of that, and know the argument that no security is better than flawed security), be easy to use.

    --

    (email addr is at acm, not mca)
    We are Number One. All others are Number Two, or lower.
    --The Sphinx
    1. Re:Encryption and the masses by Xofer+D · · Score: 3, Insightful
      I know I've been looking for a mail app with just these features that runs on Windows (and hopefully Linux too). I'm a competent Linux and Windows user, and I have no trouble using PGP on Windows with my Mozilla mailer. On Linux, it takes me significant time to copy and paste together an encrypted - or even just signed - message.

      I don't think that there's a good reason to think that making PGP easier to apply to email would make it less secure:

      • Taking the PGP model as an example, we could simply bind a hotkey to the copy-EncryptClipBoard-paste operation.
      • Alternately, we could modify our mailers to include "encrypt" and "sign" buttons right next to the "send" button.
      • The problem with authentication could be solved by an icon displaying the level of trust the user may place in the key - highest if the user has typed it in manually and has explicitly indicated trust, lower for implicit trust, and very low for automatically found keys
      • There are already public key databases (which the NAI PGP client hooks into, I might add) which could be queried to decrypt or check signatures (see above re: trust levels) automatically. Making this transparent would significantly aid the spread of PGP use.
      As you can probably tell, I feel kind of strongly about this - I even convinced my mother to use the PGP suite (although it turned out that the old version I gave her crashes her Win2k machine). I'd seriously consider working on the project, but I know I couldn't do it alone, and there are limited numbers of free choices for Windows (which I think it's crucial to get this working on). This is something I'd love to see integrated into the Mozilla mailer, but I don't want to suggest it while they're bug-hunting for 1.0!

      I'd love to hear advice as to how I can help this to happen, or find it already sitting around.

      --
      The Signal/Noise ratio can be improved in two ways. Remaining silent is the OTHER way.
    2. Re:Encryption and the masses by stapedium · · Score: 3, Interesting

      The problem with Phil's analogy to e-mail being like a postcard is that 99% of the time I use e-mail I would have no problem putting on a post card. And for the 1% of stuff I wouldn't normally put on a postcard...well, I'm just to lazy to set it up on every machine I use to send e-mail and convince all my contacts to use it and manage keys for everyone send e-mail to, and end up revoking and re-exchanging keys every time someone on a Win9X lets another person have physical access to their machine. This was the whole problem with the web of trust concept in the first place. The complexity of managing your trusted contacts (revoking certs, multiple certs for a contact, keeping your cert with you at all times) grows exonentially (or maybe worse).

      Besides, if 99.9% of the mail coming into my mailbox at home was postcards, I would probably send more postcards and not worry about it. The whole reason the postcard argument works is not real concern for privacy, but comfort with cultural customs. This is also why secure e-mail will never catch on for unior sending a message to grandma. Where it will and has caught on is in security concious businesses such as medical records where encryption of electronic correspondence with patients it is now required by law (do a earch of HIPPA to see all the headaches this is causing).

    3. Re:Encryption and the masses by DrXym · · Score: 4, Informative
      Actually there are several straightforward ways to get encryption to the masses without requiring them to think about whether they need it much.
      1. Use Plain English to describe encryption. Make analogies to envelopes and stuff. Don't blabber on about S/MIME or other gibberish.
      2. Integrate encryption into the mail program. Seamlessly and visibily. S/MIME support in most email programs is too complicated.
      3. Make generating a key easy, a question while setting up an account. None of the current rigmarole of having to give your life history to Verisign or whoever for some worthless uncertified key which expires in 6 months.
      4. Make key exchange on by default. Automatically insert a X-pgp-key-id header or somesuch into each mail sent out. Scan for this header in received mail and add to the address book entry by default.
      5. Make encryption the default behaviour when you have the key for someone you're sending to.
      6. Encourage e-tailers such as Amazon to put a "Encrypt your order details" checkbox on their order screens.

      Most people would happily use encryption if it happened automatically and painlessly. The current problems arise because PGP is not integrated and S/Mime frankly sucks, having an overly complicated UI, difficulty getting a key and is dog slow to boot.
  14. pgp and key lengths by cluge · · Score: 3, Interesting

    Maybe CAI didn't want to keep improving the product. DJB's crypto paper and methodology shows that any key less than 1024 can be "easily" cracked. CAI would have had some more work to do on their product (just as I'm sure the GNUPG team is reconsidering the approaches they are using).

    Finding the people to verify PGP is secure and proving that any new method of encryption is secure takes money, and since many people still consider zipping a file up with a password as "strong encryption" there was no market for it.

    To think, not to long ago the US govt. was complaining that the world would end if we all had encryption. As it turns out, few cared enough to use it.

    --
    "Science is about ego as much as it is about discovery and truth " - I said it, so sue me.
  15. Biometrics are not revocable by petej · · Score: 3, Informative

    Suppose someone finds an exploit in the device that does your retinal scan. Your admins must now deny your retinal scan credentials, and you have to switch to the other eye (presuming you have a spare). If that credential is compromised as well, you're completely out-of-luck.

    With a passphrase-based system, by contrast, you can just change your passphrase as needed.

  16. NAI didn't sell all of PGP by Rahtok · · Score: 5, Informative

    Guys, everybody here is missing what really happened here. About a year and a half ago, NAI separated the command line product from the GUI desktop product. NAI discovered that people will pay a large chunk of change for scriptable, command line stuff, and that they almost had to give away the GUI version. When they dissolved the business unit last October, they decided to KEEP the command line version [the McAfee biz unit sells it now, for the same large chunk of $$$] but were trying to sell off the GUI version. Now, riddle me this, riddle me that, how do you sell the GUI version to another company when the command line version you're keeping USES THE SAME CODE?! That's why NAI couldn't sell it -- no company wanted to pick up a product that NAI was going to keep the core product to. I know because I worked for NAI in the PGP division.

    It all is a big shame too. The last version, 7.1, was cool. It was stable, had an IPSEC client that could talk to pretty much any VPN gateway out there in addition to creating peer to peer IPSEC tunnels with other PGP clients as well. A mini firewall / IDS rounded it out. Frankly, companies just aren't paranoid enough to require that level of encryption yet. And until that happens, no commercial product is likely to succeed in this arena.

  17. NA made PGP into bloatware! by SomethingOrOther · · Score: 4, Informative

    it comes with some nice extras such as a very nice firewall

    And that is partly the reason nobody bought it.
    PGP evolved into a nice e-mail encryption program. NA added so much crap to this (VPN that hardly worked, Firewall, hard drive encyption) they forgot there core market..... secure E-MAIL and convincing people that it was nessisary!
    (In a corperate enviroment, people alredy have firewalls etc... NA just made PGP more complex)

    I actually bought a version of PGP Personal Security 7.0.3
    YTC !!!
    NA never published the source code for version 7. That was the reason Phil Zimmerman left NA.
    Version 6.5.8 could be downloaded as freeware and is every bit as compatable!

    --
    Anyone quoted by a reporter knows how little they understand
    Don't believe what you read is the truth.
  18. Bollocks! PGP has option for corperate key escrow! by SomethingOrOther · · Score: 3, Insightful

    you can't deploy it in a corporate environment.

    You ARE wrong! Read this about which PGP version to use.

    Here is a cut 'n' paste of the intersting bit....

    The Business versions allow you to set up how PGP will be used throughout an organization, and also allow for use of an Additional Decryption Key (ADK); but do not really include anything of additional value to an individual user. The ADK is just a master key used by an organization that all of its email/files is also encrypted to, so that if someone leaves the organization, there will still be access to his/her encrypted files - It has absolutely nothing to do with concepts such as government key recovery.

    --
    Anyone quoted by a reporter knows how little they understand
    Don't believe what you read is the truth.
  19. Marketing blunder! by dcavanaugh · · Score: 3, Insightful

    PGP is a nifty little package for encrypting files & e-mail. If it had been sold as a nifty little package at a low price, NAI would not be looking to dump it.

    I played with PGP when it was freeware. In a pilot project, I exchanged office gossip with a co-worker to see if ordinary people could use it effectively for secure e-mail communications. It worked quite well, but we didn't have a pressing need for the technology so deployment went nowhere.

    Years later, I'm at a different company and now I have a use for it. I visit NAI to see if I can buy just the basic file & e-mail encryption. I discover all they really want to sell is the entire PGP Desktop bundle, for a price that IMHO far exceeds what basic encrypted e-mail should be worth. Eventually, I managed to buy the basic package, but only after making phone calls and finding a reseller who could do such a thing. The licensing complexities of the whole process was as if I was buying an nuclear reactor! Had this been an easier process, I might have deployed it on hundreds of PCs, instead it's only a handful.

    I am the customer; I am always right. I want an easy-to-buy, easy-to-use, cheap-to-deploy package that encrypts the 5% of my users' e-mail & files that are worthy of encryption. NAI could have marketed PGP successfully to a high percentage of business and home PC owners, but for whatever reason they chose to go after the ultra-paranoid, encrypt-everything, price-is-no-object crowd instead. PGP is a great product; better management could have made it profitable. Maybe someone will buy the product and figure out how to broaden its appeal.

  20. Use PGP CKT by Constrain_Me · · Score: 4, Informative

    I don't believe someone hasn't posted this. I use PGP CKT and am VERY happy with it. It is built off of the last version of PGP that came with the source (6.5.8 Desktop Security, if i'm not mistaken), and they are currently on their 6th build (Build 07, which will fix XP problems is in Beta).

    PGP CKT, comes fully loaded with PGPDisk, and PGP4ICQ, and the plugins for Outlook/Outlook Express, I'm not sure about PGPNet, I don't use it.

  21. NAI Privacy Policy by AntiNorm · · Score: 3, Informative

    I was just about to download the freeware version of PGP last night when, in response to the mandatory registration, I read their privacy policy. Things like "We may also carefully select other companies to send you information about their products and services." caught my attention. Basically, they sell your information and require you to contact them to prevent this from happening. No, there isn't a 'please do not share this information' checkbox.

    That doesn't look like much of a privacy policy to me. Hence the reason I didn't proceed.

    --

    I pledge allegiance to the flag...
    of the Corporate States of America...