Slashdot Mirror


DMCA Attacks: NAI Tells Sites To Remove PGP (Updated)

daecabhir writes: "I am on Declan McCullough's excellent policy and technology mailing list, and received this article on Declan's Politech web site. Basically, Network Associates now appears to be using the DMCA to force sites that provide access to the "free" versions of PGP to cease and desist, if this is any indication. Unfortunately, I think that Network Associates may well be within their rights with regards to 'their' intellectual property, even if I disagree with the manner in which they are going about things." Update: 05/22 13:55 GMT by T : Looks like this wasn't the whole story, and in fact NAI was only objecting to a site with the commercial version of its software -- read below for more. Grant Bayley writes: "The hype being generated by the "NAI pulls out the DMCA stick" postings and the spectre of PGP being "removed from the Internet" is entirely bogus, and provably so with a little bit of fact checking.

Looking through the Google cache, it becomes very clear very quickly that crypto.radiusnet.net was hosting a copy of the commercial version of the software - not a copy of the PGPi (aka freeware) version of the PGP product. Given that this is the case, NAI is well within their rights to demand the removal of the files.

You can confirm this in the Google Cache.

254 comments

  1. quick!! by jeffy124 · · Score: 1

    get those copies to an offshore server!!

    --
    The One Rule Of Chess You'll Ever Need: Don't play someone who carries a kit in their bookbag.
    1. Re:quick!! by paganizer · · Score: 2, Interesting

      How exactly do they think they are going to profit from this? more like a Nail in the Coffin than anything else, free PGP from MIT is considered a sacred inalienable right, right?

      --
      Why, yes, I AM a Pagan Libertarian.
    2. Re:quick!! by delta407 · · Score: 1

      Quick, post it to Freenet; you don't know where it's stored!

    3. Re:quick!! by Anonymous Coward · · Score: 0

      Why not even binhex it and throw it on a newsgroup for Google to catch and permanently archive?

  2. wait.. by Beatbyte · · Score: 1

    isn't pgp a free application? whats the big deal here? just being stingy?

    1. Re:wait.. by Anonymous Coward · · Score: 2, Insightful

      There is a lot of people who would just love for PGP to just "go away". Like your local friendly FBI, CIA, and other 3 letter agencies one can only just guess at.

      Now they can't snoop on people anymore. And that includes all the other "nasties" out there that want to do harm to us that use it extensively.

      So they have put pressure on all the sites that link to copies of PGP to pull them, so eventually, nobody will know were to find their copy of PGP.

    2. Re:wait.. by spectral · · Score: 1

      but NAI (Network Associated Inc. I assume, I dunno what the I stands for) at least used to own PGP. I guess they don't like the free versions being around, cuz then they can't sell it.

    3. Re:wait.. by ragnarok · · Score: 1

      That was a troll, right?

      If it wasn't, are you aware that there are free alternatives to PGP available?

      --
      Search first, ask questions later.
    4. Re:wait.. by corebreech · · Score: 3, Interesting

      That's the thing. NAI ain't selling PGP anymore.

      Makes you wonder who's running NAI.

    5. Re:wait.. by thogard · · Score: 0, Troll

      Network solutions was founded by ex CIA and NSA guys and then sold to SAIC which who's sr mangment are all exspooks.

    6. Re:wait.. by BrookHarty · · Score: 4, Interesting

      We tried to buy a site license at work. We needed something that would plug into Outlook Exchange and work with everyone inside and outside the company. But after NAI killed PGP, we tried GPG but there was no plugin for Outlook Exchange (client).

      Good product, lots of people wanting to buy it, and no alternative program. If someone came out with a windows office plugin, maybe they could make/start a software company.

    7. Re:wait.. by Anonymous Coward · · Score: 0

      everyone knows gpg doesn't really encrypt anything.

    8. Re:wait.. by Anonymous Coward · · Score: 0

      It's "Network Associates" hehe...

    9. Re:wait.. by Anonymous Coward · · Score: 0

      There is a free outlook plugin though it doesn't appear to have been maintained for some time. I have it installed at home (Outlook XP) and it works OK.

    10. Re:wait.. by Guttata · · Score: 1

      Try gpgoe (plugin for Outlook Express), if that is good enough for your needs:

      http://www.winpt.org/gpgoe.html

  3. Are older versions theirs? by edisk1353 · · Score: 2, Interesting

    What is the DMCA's policy on older software?

    Does this mean that older versions of PGP now belong to Network Associates and are subject to the company's will? Even if they were free?

    1. Re:Are older versions theirs? by homer_ca · · Score: 5, Informative

      PGP versions 6 and 7 had both Freeware (free beer, for noncommercial use only) and Professional versions. If NA is trying to shut down PGP Freeware downloads, it's bogus. This is sections 1 and 3 from the PGP Freeware 6.5.8 license. Section 1.b grants the right to distribute unmodified copies. Section 3 states the term of the agreement, forever as long as the user violates the license. I was half expecting to find it, but they do NOT say "We reserve the right to change these licensing terms at any time without notice".

      1. License Grant. Subject to the terms and conditions of this Agreement, Network Associates hereby grants to you a non-exclusive, non-transferable right to use, copy and distribute solely for Non-Commercial Purposes (as defined below) the specified version of the Software and the accompanying documentation (the "Documentation").
      a. For purposes of the foregoing, "non-commercial purposes" means non-commercial, non-governmental use, including, without limitation, home use for personal correspondence, student or academic use, or use by non-profit human rights organizations. The Software is "in use" when it is loaded into the temporary memory (i.e., RAM) or installed into the permanent memory (e.g., hard disk, CD ROM, or other storage device) of a computer for the purpose of being accessible in client-mode by an end user.
      b. You may make exact, unmodified copies of the Software and distribute such copies solely (i) by electronic means; (ii) for Non-Commercial Purposes; and (iii) with all proprietary notices (including without limitation all copyright notices and this End User License Agreement) intact and unmodified or obscured.
      3. Term. This Agreement is effective unless and until earlier terminated as set forth herein. This Agreement will terminate automatically if you fail to comply with any of the limitations or other requirements described herein. Upon any termination or expiration of this Agreement, you must destroy all copies of the Software and the Documentation.

    2. Re:Are older versions theirs? by homer_ca · · Score: 1

      "term of the agreement, forever as long as the user violates the license"

      oops that should read, "forever as long as the user does not violate the license"

    3. Re:Are older versions theirs? by Anonymous Coward · · Score: 0

      LOL, that typo reminded me of the bible version they had to quickly confiscate back in the middle ages. One typo had one of the ten commandments read "thou shalt commit adultery", with the (perhaps careful) omission of the word not glaringly apparant to those reading it. Once the clergy realised the mistake, they were fairly serious about rounding all the copies up and burning the adulterous edition. I'm sure some people still have one around, if only to prove that God told them to.

    4. Re:Are older versions theirs? by Anonymous Coward · · Score: 0

      Aren't trolls supposed to make some kind of sense?
      In thus case the company stopped selling it and started GIVING it away, saying you can distribute it freely. As long as you were not using it for commercial means.

  4. Hm. by Wakko+Warner · · Score: 4, Informative

    Good thing there's GPG...

    - A.P.

    --
    "Remember when the U.S. had a drug problem, and then we declared a War On Drugs, and now you can't buy drugs anymore?"
    1. Re:Hm. by InSaNiAcK · · Score: 0

      Amen brother! GPG Is my free PGP jesus ;)

    2. Re:Hm. by redcliffe · · Score: 1

      Just need a version for windows, with outlook/oe plugins.

      David

    3. Re:Hm. by Clue4All · · Score: 4, Informative

      The problem with GPG is that it lacks an easy-to-use interface and Windows plugins. This was the selling point of NAI's PGP: it was easy point-and-click encryption for the common person. It's a shame they're ditching it, it really had a good chance for encouraging the widespread use of encryption.

      --

      Is your browser retarded?
    4. Re:Hm. by Anonymous Coward · · Score: 2, Funny

      You profess to be worried about security .. and you admit to using Outlook?

      I'm not snickering, it's the guy beside me, honest.

    5. Re:Hm. by malice95 · · Score: 2

      I just investigated this as well for my company. While GPG seems to be technically superior from a command line point of view it sucks from a gui point of view on windows. The NAI version has a very good gui config tool, and great integration into outlook. I found this site http://www3.gdata.de/gpg/ which offers similar gui integration into outlook and a gui config tool, but the NAI version works and looks better IMHO.

    6. Re:Hm. by ergo98 · · Score: 3, Informative

      Though because NAI hadn't been keeping it up, with each iteration of Outlook it fell further behind. For it to work with current versions of Outlook you have to specially configure PGP 7.0.3 to have a workable scenario, and even then quirks abound.

      I agree entirely with what you said, however I should point out that it is not so much the common person, or a "lowest common denominator" set of skills, but rather the security versus the convenience ration : I like using encrypted emails simply because it's no one elses business, but if it wasn't as convenient, and if I had to copy/paste between apps in a big time consuming process, I likely wouldn't bother except for messages which have to remain private (and one of the tenets of strong encryption is that encryption shouldn't be limited to only the highly confidential because it gives a very directed target, and can imply guilt to some screwed up types).

    7. Re:Hm. by _Sprocket_ · · Score: 3, Informative


      The problem with GPG is that it lacks an easy-to-use interface and Windows plugins.


      Open Source works by scratching itches. NAI has done a lot to generate an itch for GUI plugins/frontends for GnuPG on Windows. Poke around and you can easily find some good starts.


      This pageprovides a fairly nice listing of some of them. Check them out, kick the tires, see if they work for you. YMMV.


      One thing to note - WinPT is shaping up nicely as a general GnuPG interface (although it doesn't provide a selection of MUA-specific plugins, they do also offer GPGOE, a plugin for Outlook Express). WinPT is Open Source under the GPL license. And unlike other frontends, WinPT is more tightly integrated by using GPGME, GnuPG's new API.

    8. Re:Hm. by triptolemeus · · Score: 1

      There is pretty good stuff around:
      german privacy site sponsored by the German government. And also this one which features an M$ Outlook plugin.

      They are easy to install and there is a great introduction to GPG in the pdfs provided on the first link (German only).

      --
      The site where: "I'm right, as long as you ignore the things that prove me wrong", became a valid method of debate.
  5. Clarification needed by ergo98 · · Score: 2, Interesting

    So which version was being hosted that led to NAI sending out the copyright violation notice? Was this a commercial version that truly was a `pirate' copy, or was it the same version hosted at pgpi.com? (http://www.pgpi.org/products/pgp/versions/freewar e/) The pgpi site doesn't seem to have any information regarding this, and you would think they would given the impact of it to them.

  6. Huh? Wait a second... by rainmanjag · · Score: 1

    So that article included a link to infinging material. What was at that link? Was it illegal copies of NAI software? Or does this meen NAI is trying to crackdown on open source implementations of PGP?

    -jag

    --
    http://starboard.flowtheory.net/
  7. What does PZ think? by Anonymous Coward · · Score: 0

    Phil Zimmerman, what's your stance on this?

  8. mit distro center is still up by jnana · · Score: 4, Informative

    at http://web.mit.edu/network/pgp.html, but you can bet that i'm gonna download it again right now and burn the installer onto a CD.

    1. Re:mit distro center is still up by Lord+Squirrel · · Score: 3, Informative

      well, I just tried to download it...no dice. The site is up, but you can't download.

      --

      Lord of the Squirrels, Ambassador to the Moles, Minister of Rodential Information

    2. Re:mit distro center is still up by jnana · · Score: 1
      i just downloaded from it less than 15 minutes ago. You're right though. I just tried again and got the following error message:
      Internal Server Error

      The server encountered an internal error or misconfiguration and was unable to complete your request.

      Please contact the server administrator, jis@MIT.EDU and inform them of the time the error occurred, and anything you might have done that may have caused the error.

      More information about this error may be available in the server error log.

      Apache/1.3.20 Server at PGPDIST.MIT.EDU Port 80
      Let's hope this is just them getting slashdotted.
    3. Re:mit distro center is still up by jumpingfred · · Score: 1

      It is working for me fine.

    4. Re:mit distro center is still up by Dimensio · · Score: 2

      Just downloaded both the Win32 and Linux versions at 00:59EST.

    5. Re:mit distro center is still up by Ghost+in+the+Machine · · Score: 1

      It just worked for me.

    6. Re:mit distro center is still up by sulli · · Score: 1

      worked for me

      --

      sulli
      RTFJ.
    7. Re:mit distro center is still up by Anonymous Coward · · Score: 0

      HEHEH... Thanks... Licenses? We don't need no stinkin' licenses. YOINK!

    8. Re:mit distro center is still up by peddrenth · · Score: 1

      How does this announcement affect PGPi ?

  9. Not a good Idea by Anonymous Coward · · Score: 0

    When will corps learn that if they act like M$ no one will buy their products

    Money is not everything...

    This world, So sad :(

  10. I am not a lawyer by w.p.richardson · · Score: 2
    Can someone else who is not a lawyer explain how the DMCA applies?

    TIA!

    --

    Curb CO2 emissions: Kill yourself today!

    1. Re:I am not a lawyer by Cardhore · · Score: 3, Insightful

      It doesn't, except they included the letters DMCA in the title of their e-mail. This is probably just ordinary copyright law.

    2. Re:I am not a lawyer by Anonymous Coward · · Score: 0

      Can someone else who is a lawyer explain how the DMCA applies?
      (Score:2, Funny)

    3. Re:I am not a lawyer by Anonymous Coward · · Score: 4, Funny

      Sure:

      Wealthy Client: I want that stuff down.
      Lawyer: Okay.
      [to host] Take that down. Or else.
      Host: F*ck that. I've got First Amendment rights.
      Lawyer: Ha. [sends obscure legalese email] Here's a ridiculously vague DMCA notice.
      Host: I don't understand this crap.
      Lawyer: Good. You're not supposed to. But I'll be generous and tell you anyway. It says that if you take this stuff down, you won't be liable for [insert Carl Sagan voice] billions and billions of dollars for copyright infringement.
      Host: Oh. Okay.... I guess. [deletes information]
      Lawyer: Muahahaha.

    4. Re:I am not a lawyer by Anonymous Coward · · Score: 0

      If they threatened to sue for DMCA violations, but had no actual intention of using the DMCA to sue, doesn't that mean they are guilty of Barratry, a crime?

    5. Re:I am not a lawyer by norton_I · · Score: 2

      By invokin the DMCA, they use the safe harbor clause as leverage against the ISP. The ISP is guaranteed no legal liability if the act promptly to remove or block access to the alleged illegal material. If they try and stand up for the rights of their client, they are liable as accomplices to theft.

      I don't know what the particular situation is here, there are dozens of version of PGP and PGP-like programs, and no indication of what the actual supposedly infringing material was. If it was the actual no longer for sale commercial version of PGP, they are regrettably well within their rights to ask it to be removed, otherwise this is nonsense.

    6. Re:I am not a lawyer by Anonymous Coward · · Score: 0

      If every lawyer guilty of barratry was prosecuted, there'd be no lawyers left....hmm, now that's an idea!

    7. Re:I am not a lawyer by Anonymous Coward · · Score: 0

      Insert lawyer joke here. Of course, the way all these lawyers are throwing the initials "DMCA" around, one of these days(hopefully soon) they will attempt to scare the wrong person and get their asses burned.

    8. Re:I am not a lawyer by Anonymous Coward · · Score: 0

      And the flipside ? If a DMCA takedown notice is itself falsely or misleadingly issued, then the company that issued the notice is guilty of perjury ; the standard DMCA form has a clause to the effect of "I swear under penalty of perjury that all the above is correct".

      Interestingly, Blizzard has not been sued/FBI raided/kneecapped for perjury in issuing a DMCA notice against the bnetd project that was later found to be completely spurious....

  11. Freeware PGP versions remain available here... by wherley · · Score: 1

    Many versions for many platforms available here: PGPi.
    Information wants to be free.

    1. Re:Freeware PGP versions remain available here... by Excarnate · · Score: 0, Flamebait

      "Information wants to be free."

      Bullshit! Information does not want anything. That statement struck me as silly the first time I heard it and the more time goes by the more silly it seems.

      You have a weak mind if you buy that quote. If you want information to free (whatever free may mean to you) it takes effort to make it so. Sit on your ass and it won't happen.

      --
      .signature: No such file or directory
    2. Re:Freeware PGP versions remain available here... by kpansky · · Score: 1

      Bullshit! Information does not want anything

      Well, you are completely correct except for one simple fact: humans are required for information/knowledge to exist. Without humans there is no knowledge. Now because "knowledge" is defined in terms of humanity, it shares certain human characteristics. Humans at the most basic level want to share almost all information. While not _all_ humans want to share _all_ information, similarly not _all_ information "wants" to be free.

      Universal affirmatives can only be partially converted... so in conclusion sex is more fun than logic.

      --

      --Kevin
    3. Re:Freeware PGP versions remain available here... by hviezda14 · · Score: 1

      You are not right - information is independent from humang beeing, light (with any kind of information) is the same if you look at it or you don't.

    4. Re:Freeware PGP versions remain available here... by killeroonie · · Score: 1

      Actually, information doesn't exist until a human examines it. The light wave/photon is just a probability wave until a human observes it. Without a human, there might be *something* there, but you can't call it light, or information.

    5. Re:Freeware PGP versions remain available here... by cicho · · Score: 1
      Bullshit! Information does not want anything


      It's a catchy slogan. It's a metaphor. You're not supposed to take metaphors literally. What it means is that information, by its very nature, proliferates easily and is hard to lock down. It's called anthropomorphization. It's a figure of speech, look it up.


      But you already knew all that.

      --
      "Only the small secrets need to be protected. The big ones are kept secret by public incredulity." - Marshall McLuhan
    6. Re:Freeware PGP versions remain available here... by kpansky · · Score: 1

      Ever hear of Schroedinger's Cat?

      --

      --Kevin
  12. NAI - Graduates of the Verisign School of Business by zentec · · Score: 5, Interesting


    I purchased several copies of NAI's PGP for Unix version 5. The CD had a standard license agreement with it. Two years later, I receive a letter from NAI telling me that my license was revoked and I could no longer use the software.

    Somehow, I do not think I received my $1500 worth.

    I should have known, I asked NAI's sales department for a price quote on NAI virus protection products for the "enterprise" and I never did receive a straight answer.

    Thank God for GPG! Works with NAI's PGP plug-ins and it's truly free.

  13. Conspiracy! by Devil's+BSD · · Score: 2, Funny

    I find it interesting how Network Associates bought out PGP, then killed it, and is now trying to shut it down. Although it may be a long shot, could it be that the government is behind this? The government did not want PGP to be released in the first place because they thought it would threaten security...
    and for those still looking for PGP and unwilling to use GPG, there's still KaZaA.

    --
    I'm the Devil the Windows users warned you about.
    1. Re:Conspiracy! by Soko · · Score: 2

      and for those still looking for PGP and unwilling to use GPG, there's still KaZaA.

      OK - do we use that to make sure we have no privacy left and make using any encryption redundant, or do we use it to make sure we get a copy before they all dissapear?

      grokster, bud, grokster. 8-)

      Soko

      --
      "Depression is merely anger without enthusiasm." - Anonymous
    2. Re:Conspiracy! by Anonymous Coward · · Score: 0

      Of course it is... A pretty sneakey one I must admit.

    3. Re:Conspiracy! by Anonymous Coward · · Score: 0

      OK - do we use that to make sure we have no privacy left [slashdot.org] and make using any encryption redundant, or do we use it to make sure we get a copy before they all dissapear?

      grokster, bud, grokster. 8-)


      You're kidding right? I just downloaded Grokster to try it, unselected all the bullshit spyware plugins and it STILL installed cydoor. If I remove it with ad-aware it refuses to run. Grokster is no better than Kazaa in silently attempting to violate my privacy.

    4. Re:Conspiracy! by thogard · · Score: 1

      Has anyone else noticed that the ex-spook founded compaines are doing very very well right now?

      We all know that George Sr was a spook and look at how well his buddies companies ('cept Enron) are doing. There are many net references that indicate that George Jr used to for on projects for Daddy.

      There may not be a new wolrd order yet, but there are lots of happy and wealthy ex-spooks.

  14. Google cache by ergo98 · · Score: 5, Informative

    The google cache of the directory in question (that incited NAI to send the cease and desist) can be found at http://www.google.ca/search?q=cache:2PdJtPM6n0QC:c rypto.radiusnet.net/archive/pgp/+&hl=en. Immediately I see products that were in the NAI distribution of PGP (commercial) but aren't in the freeware version (such as PGP Disk). Is this just a case of a copyright violation (and possible outright piracy to the tune of "warez" sites) being defended as something else? I could be very much mistaken, but not all of PGP was made freeware, and even no longer sold products maintain intellectual property that the company has every right to maintain control of for future use.

    1. Re:Google cache by Anonymous Coward · · Score: 0

      http://www.google.CA/search?q=cache:2PdJtPM6n0QC:c rypto.radiusnet.net/archive/pgp/+&hl=en

      Ha your a silly english Kuniguhut

  15. The DMCA implements anti-circumventon clauses by Anonymous Coward · · Score: 0

    Disclaimer: I am not a lawyer

    Maybe I've had too many beers, but I dont think the DMCA has anything to do with this sort of "piracy". It covers anti-circumvention clauses covered by WIPO treaty and "original designs" meaning look 'n feel type stuff.

    Existing law should cover stuff like piracy and ownership of code, algorithms etc. not the DMCA. Again I'm not an IP lawyer, maybe someone would like to explain.

    http://www.eff.org/IP/DMCA/hr2281_dmca_law_19981 02 0_pl105-304.html

  16. Phil Zimmerman? by sludgely · · Score: 2, Interesting

    Has Phil made a comment yet regarding this? PGP is his child and it seems like if anyone has anything useful regarding this to say, he does. Where are you, Phil?

    1. Re:Phil Zimmerman? by PeterClark · · Score: 2

      It's probably too soon for him to have made a comment; all the same, a little Googling turned up some insightful stuff: apparently, Zimmerman dissed GPG. But that was a couple of years ago. I wonder what he thinks of it now, considering that GPG is about the only PGP replacement worth considering.

      :Peter

    2. Re:Phil Zimmerman? by Slashamatic · · Score: 5, Informative
      I am not Phil but I worked on PGP 1.x through 2.x or so, mostly on one of the ports. First a bit of history.

      Theoretically PGP in the early days could use RSAREF from RSA Labs but it needed some calls that were not in the published interface and thus broke RSA Labs non-commercial licence.

      The thing is that Phil requested that none of our software was GPLed as he wanted to try to use parts of it commercially. Fair enough, he would keep the non-commercial version as open as he could. Actually it was pretty open by then because contributors were working in France, Germany, even, I think, Russia.

      When the program was first passed to Viacrypt. They had there own licensed RSA engine and could drop it into PGP. However PGP still used another patented algorithm, IDEA. This had to be licensed (about $15) for commercial users.

      Viacrypt then got swallowed by NAI or at least PGP was transferred with it together with Phil Zimmerman. PGP moved away from algorithms like RSA and IDEA so didn't have so many patent issues. We ended up through Phil's efforts with a version of PGP free for non-commercial use an a licensed version for the corporates. However, many of the platforms were dropped.

      The source code of PGP was printed by MIT in an OCR freindly font and the whole thing was exported legally to Norway, scanned nd put up on the pgpi server. Later, NAI did something similar to get the code to their office in Switzerland and with the availability of commercial PGP in Europe, the free version went non-commercial only.

      NAI stopped publishing source code after 6.5.8 so a lot of people stopped there with that release. Strangely, a commercially licensed user was not allowed to recompile from the free source.

      Ok, history lesson over. PGP always has had a bit of a chequered past because some people don't like it one little bit. It was a difficult product to sell but NAI seemed to have had a steady business with it. That they dropped it after 9/11 came as no suprise to anyone (it may have been making money but not enough to want to compromise sales of other s/w to the US government). However, in the background we have the OpenPGP standard (well, RFC) being developed that gave a chance for other interoperable programs like GnuPG to be developed. This project has the backing of the German government, who seem to believe in strong encryption for the masses. The software is currently far from perfect (try recompiling the Windows version), but it works and without the patented algorithms. There are some front-ends that make it reasonably user friendly. It isn't there yet, but it will be.

      In the mean time, I have seen PGP in use in Central Asia, not by terrorists, but by a Central Bank for interbank money transfers. That terrorists and criminals have used PGP is certain, but so do people like Amnesty and the Red-Cross. The use of PGP to co-ordinate attacks against the US is a massive red-herring to cover up incompetence by the FBI and INS.

  17. This is just a ruse . . . by Anonymous Coward · · Score: 0
    . . . to detract attention from the high probability that the most recent closed-source version was backdoored, anyway. They're only trying to appear to attempt to remove it--NAI can't be stupid enough to actually think they can.</tinfoil hat>

    ~~~

  18. careful if you use wget for your websurfing needs by Cardhore · · Score: 3, Interesting

    If your user agent happens to include "wget", watch out! "Any IP/Host seen using wget or any other mirror tool will be banned!

  19. DMCA or plain copyright? by Anonymous Coward · · Score: 1, Interesting

    Why isn't this just a "plain copyright" case? Like the Church of Scientology attacking Google with the DMCA, I don't see why they need the part about circumventing access controls to copyrighted material. It would make more sense to invoke plain old copyright law. Are the letters "DMCA" more scary or something?

    1. Re:DMCA or plain copyright? by Anonymous Coward · · Score: 0

      Are the letters "DMCA" more scary or something?

      Yes

    2. Re:DMCA or plain copyright? by Anonymous Coward · · Score: 0

      Ever since DMCA was passed, it has extended and superseded "plain copyright." In other words, DMCA is now part of "plain copyright."

    3. Re:DMCA or plain copyright? by gilroy · · Score: 3, Insightful
      Blockquoth the poster:

      Are the letters "DMCA" more scary or something?

      That's it, exactly. Copyright law (pre-DMCA) has a long, detailed history in the courts. There are lots of precedents, including relatively wide fair-use harbors. The DMCA, while paying lip service to fair use, actually narrows its applicability a lot. But more importantly, no one knows how courts will interpret the DMCA, as few cases have percolated through the system. It's that element of uncertainty that serves as a bludgeon ... many companies would be unwilling to fight tooth-and-nail against a lawsuit if they aren't relatively sure of how the underlying law is going to be interpreted.
  20. This is a good thing! by bfree · · Score: 2

    Network Associates are quite within their rights to stop people distributing their software unless they had specifically given those rights in an unrevocable way. Why is this a good thing?

    • Even more development should move to GPG as alternative options are required.
    • More people should become aware of the fragile basis of all proprietry software.
    • Network Associates will lose this business forever (they are killing PGP and that's fine by me).
    --

    Never underestimate the dark side of the Source

    1. Re:This is a good thing! by Wintersmute · · Score: 3, Insightful

      Yeah - but can anyone explain why Network Associates wants to orphan their privacy software at a time when online privacy concerns are really coming into focus? Seems like this is a time to be getting into the market, rather than out.

      Any chance they're worried about the implications of widely available privacy software for "bad guys"?

      --
      It may be cold, but at least it's clear.
    2. Re:This is a good thing! by acceleriter · · Score: 1

      I bet there's a good chance they got some nice phat contracts from the federal government in return for making PGP go away as a product. They don't need to eradicate it; just to make it look like a tool of fringe weirdos and/or terrorists. That'll keep encryption from becoming sufficiently ubiquitous to forestall a surveillance society.

      --

      CEE5210S The signal SIGHUP was received.

    3. Re:This is a good thing! by twiztidlojik · · Score: 1

      Nah, it was Doubleclick! Doubleclick, I tell you! DOUBLECLICK!
      (you know, privacy, violation of privacy, haha, funny. Nevermind.)

      --
      I will now redundantly add my name to the end of my post. You know, in case you forgot me or something.
    4. Re:This is a good thing! by Anonymous Coward · · Score: 0

      Duh. Read the old license...it is not revocable. They have no fucking standing here except lack of legal knowledge and well-paid legal whores to perform obfuscatory blather functions.

      Honestly, it's enough to make one become a lawyer in order to be able to perform some STFU to these kinda companies and the firms that work for them.

      IANALY (I am not a lawyer _yet_)

    5. Re:This is a good thing! by ImaLamer · · Score: 2

      they are killing PGP and that's fine by me

      Fine by you yes, but what about us that use PGP to securly e-mail friends and family on Windows machines? If they can't get copies (legally) then it will die and then I've got to go about maintaining not only a copy of my secret key but now PGP as well.

      There is more to PGP than sending and getting secure e-mails. E-mail signing and even secure data backup.

      The problem is that the freeware version of the license says that anyone can distribute it forever.

  21. Call off your search by Anonymous Coward · · Score: 0

    It's pointless

  22. It's worth mentioning... by reparteeist · · Score: 3, Informative

    Since GnuPG does not use the patented IDEA algorithm, it is in no danger from NAI.

    --
    If Bill Gates had a nickel for every time Windows crashed... Oh wait, he does.
    1. Re:It's worth mentioning... by _Sprocket_ · · Score: 2


      Since GnuPG does not use the patented IDEA algorithm, it is in no danger from NAI.


      Just to clarify...


      I don't believe the issue is use of the IDEA algorithm - that patent is held by MediaCrypt. However, PGP is owned by NAI. GnuPG is safe from NAI because it does not contain any PGP code. GnuPG is (mostly) compatible with PGP because it implements the OpenPGP standard which was based on PGP.

    2. Re:It's worth mentioning... by grahammm · · Score: 1

      I thought that Ascom owned the IDEA patent. So did they sell it to mediacrypt or was it part of some company takeover or re-organisation?

    3. Re:It's worth mentioning... by _Sprocket_ · · Score: 2

      Ascom is MediaCrypt or something to that effect.

  23. I knew it would come to this... by Anonymous Coward · · Score: 0

    Time to start collecting all the copies of PGP while they last. I was wondering how they (ANTI_PGP Gestaopo) were going to eradicate the use of PGP. Now we know.

  24. Re:NAI - Graduates of the Verisign School of Busin by malice95 · · Score: 2

    How do you get gpg to work with nai's plugins? I love the outlook plugin from nai but I would love to use gpg on the backend.

  25. GPG frontends by PeterClark · · Score: 5, Informative

    I could be mistaken, but I think that GPG plays just fine with NAI's plug-ins. And as for frontends, I don't think you have looked hard enough. Also, Kmail has effortless integration with GPG, and I hear that Evolution does too, although I've heard that there were a couple of bugs in it. Perhaps they've been fixed by now.

    :Peter

    1. Re:GPG frontends by Anonymous Coward · · Score: 1

      I think he means nice easy integration with programs like Eudora under Windows. There seems to be one but it is no longer supported. We bought PGP specifically because it tied in with our Eudora mail clients easily.

    2. Re:GPG frontends by psychosis · · Score: 3, Interesting

      I use GPG with Evolution daily, and have had no problems in the 1.0.3 release.
      It even handles different keys for different accounts without user intervention (after telling it the key number for a given account, of course).
      It has the handy features like "remember pass phrase for this session" (it's an option for the paranoid), sign-every-message, and verification of a signed message sent to you with a mouse click.
      Check it out - it's the only mail client I use now!

    3. Re:GPG frontends by GdoL · · Score: 1

      I'm usung GPG with evolution for sometume now and it is great. I just forgot about it. It works great. I would like to know how to use it with mozilla, though.

      --

      ------I can please only one person per day. Today is not your day. Tomorrow isn't looking good either.------
    4. Re:GPG frontends by Anonymous Coward · · Score: 0

      Indeed - and it's command line driven nature means it was a doddle for me to insert GPG into existing back office tasks on both Unix and NT servers such as ftp jobs to external destinations etc, with one shared key database.

    5. Re:GPG frontends by Anonymous Coward · · Score: 0

      I use GPG with Evolution daily, and have had no problems in the 1.0.3 release

      Really? I think it sucks. From Evolution .98 or so it's been completely broken. Well, not completely. But it OFTEN tells me that signed messages have a bad signature, but a) verifying the signature using PGP and Outlook tells me it's good, and b) it's signed messages from places like SANS - newsletters that you can verify in more ways than one what the contents were, and there is nothing wrong with them I assure you. So it has to be the GPG/Evolution combo, and I blame Evolution, since I can save the message separately and check the sig and its fine.

  26. Re:NAI - Graduates of the Verisign School of Busin by acceleriter · · Score: 2, Interesting

    How about a link to a scan of that letter (with your details blanked out, of course)? It'd also be educational to see the original license agreement, to determine if it even contained an out like that for NAI (providing that it's enforcable to begin with, which is probably a stretch in a non-UCITA state anyway). IANAL, etc.

    --

    CEE5210S The signal SIGHUP was received.

  27. rotlol! by Anonymous Coward · · Score: 0

    that's funny. What license are distributing that joke under?

  28. Re:Encryption is for terrorists by Anonymous Coward · · Score: 0

    Yes, as only The Mighty U.S. Of A can develop encryption techniques. No other backwards little country could think of such a thing!

    (even thou. the brits did it first...)

  29. GNU Privacy Guard Anyone? by npsimons · · Score: 2, Informative
    Looks like it's time to switch to GNU Privacy Guard if you haven't already. Does anyone know if it will be immune to this attack?


    And for those that haven't found it yet, enigmail should allow you to use GNU Privacy Guard with Mozilla, even under Windows. Haven't tried it myself yet.

    1. Re:GNU Privacy Guard Anyone? by /dev/trash · · Score: 1
      Looks like it's time to switch to GNU Privacy Guard [gnupg.org] if you haven't already. Does anyone know if it will be immune to this attack?

      They are two separate things, why would and how could NAI stop GPG?

    2. Re:GNU Privacy Guard Anyone? by pagan26 · · Score: 1

      Well, they could just throw the same four letters that started this discussion......

      --
      Open Source: Every now and then, you get what you don't pay for.
    3. Re:GNU Privacy Guard Anyone? by _Sprocket_ · · Score: 3, Informative


      Looks like it's time to switch to GNU Privacy Guard [gnupg.org] if you haven't already. Does anyone know if it will be immune to this attack?


      You might want to poke around the link you provided. GnuPG is an implementation of RFC2440 (OpenPGP). Since OpenPGP is based on PGP, there is a certain degree of compatability between PGP and GnuPG, however, GnuPG is not based on PGP code. In short, NAI has no ownership over GnuPG in any form. Any attempts to block GnuPG with DMCA claims would be completely outlandish.


      It might be worth noting that GnuPG is also being developed with funding from the German government. Even if NAI were to try and block GnuPG with such a DMCA claim, I suspect it would be entirely futile and wouldn't even cause a hiccup in GnuPG distribution and development.

    4. Re:GNU Privacy Guard Anyone? by /dev/trash · · Score: 1
      Well, they could just throw the same four letters that started this discussion......

      Yeah that'd be effective.

  30. Re:Encryption is for terrorists by Anonymous Coward · · Score: 0, Flamebait

    Your right. Here, let me just go ahead and publish my credit card information, social security number, address, birthday, bank account info, access to stocks portfolios and what the hell, let me throw in the same of my wifes. And gee whiz, why not just go ahead and publish my username and password list to all my online accounts. Yeah, to hell with encryption, we can all trust each other, right. We all know each other that know that no one would think of misusing that info, right?

    Okay, in case you're a complete moron, that was sarcasm. You just go on believing that crap you just preached. No skin off my back when you get totally hosed...

  31. Re:Encryption is for terrorists by ObviousGuy · · Score: 0, Troll

    We tell other countries what to do, they do it.

    It's called Pax Americana and it's been the international order since 1990.

    --
    I have been pwned because my /. password was too easy to guess.
  32. Re:careful if you use wget for your websurfing nee by Anonymous Coward · · Score: 0

    wget -m -U "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)" http://www.foobar.com/quux/

    happy mirroring :)

  33. Other DMCA provision by Anonymous Coward · · Score: 1, Insightful

    Sec. 1201 and 1202 deal with circumvention. Sec. 512 - a different provision - deals with service provider liability and entails the notice-and-take-down liability sections. These provisions limit service providers' liability for hosting copyrighted content. Thus, when Declan talks about the DMCA "nastystick", he's talking about Sec. 512 of the DMCA. Same with the Co$ incident. Sec 512 there too. Other than that, it is just 'plain old' copyright law.

  34. DMCA... by jmv · · Score: 3, Funny

    Under the DMCA, I ask you to keep your dog from sh... on my lawn!!!

    Has the word DMCA been recently accepted as a synonym for "generic laswuit"?

  35. Comparison of Game 4 losers and dot-com companies by ChazeFroy · · Score: 2

    Seems to me that Network Associates, with their backs to the wall, are playing the part of a losing hockey team facing elimination in Game 4 of a best-of-seven series.

    Play dirty to survive.

  36. Good News by Anonymous Coward · · Score: 1, Informative

    If they are defending their rights to a product they no longer market, it means they're trying to retain its value in order to sell it to someone else.

    Rock on PGP, free or otherwise.

  37. it's dead, Jim by g4dget · · Score: 3, Insightful

    What's the point? If it's not open source and if it's not commercially supported, it's dead. Oh, you may still be able to use it for a little while but then operating systems and libraries will drift away.

    1. Re:it's dead, Jim by Anonymous Coward · · Score: 0

      OS backward compatibility usually takes care of this, especially for such simple command line utilities. I have tools last compiled a decade ago.

      Oops, Linux don't do that.

  38. you know... by kevin+lyda · · Score: 4, Interesting

    it's too bad that people don't pay more attention to rms when he talks about freedom.

    and it's also too bad that people kept doing dev on possibly not free pgp versions instead on truly free implementations of pgp (ie gnupg).
    how many times are we going to learn this lesson?

    --
    US Citizen living abroad? Register to vote!
    1. Re:you know... by bentini · · Score: 2
      how many times are we going to learn this lesson?

      I think we'll only learn it once. The question is when that one time is finally going to happen.
    2. Re:you know... by mccalli · · Score: 2
      and it's also too bad that people kept doing dev on possibly not free pgp versions instead on truly free implementations of pgp

      It's terrible, yes. So...are you going to pay the people a salary to work on the free versions or shall I?

      What? You're not prepared to pay for it? Then how are these coders going to earn their living?

      It's good that free alternatives can be developed by those with the interest and time. However, don't knock the people working on the closed stuff - they're just earning their living like any other coder.

      Cheers,
      Ian

    3. Re:you know... by kevin+lyda · · Score: 2

      uh, moron, i was referring to people contributing code to the non-free versions. not the people paid to do it, just the ones who were contributing code thinking it was free software when it was actually just "free beer" software.

      --
      US Citizen living abroad? Register to vote!
  39. My PGP EULA by SignalFreq · · Score: 5, Informative


    A quick look at the documentation that came with my version of PGP Freeware:

    Network Associates Freeware End User License Agreement
    (Non-Commercial Use and Distribution Only)

    1. License Grant. Subject to the terms and conditions of this Agreement, Network Associates hereby grants to you a non-exclusive, non-transferable right to use, copy and distribute solely for Non-Commercial Purposes (as defined below) the specified version of the Software and the accompanying documentation (the "Documentation").

    a. For purposes of the foregoing, "non-commercial purposes" means non-commercial, non-governmental use, including, without limitation, home use for personal correspondence, student or academic use, or use by non-profit human rights organizations. The Software is "in use" when it is loaded into the temporary memory (i.e., RAM) or installed into the permanent memory (e.g., hard disk, CD ROM, or other storage device) of a computer for the purpose of being accessible in client-mode by an end user.

    b. You may make exact, unmodified copies of the Software and distribute such copies solely (i) by electronic means; (ii) for Non-Commercial Purposes; and (iii) with all proprietary notices (including without limitation all copyright notices and this End User License Agreement) intact and unmodified or obscured.

    ... blah, blah, blah...

    3. Term. This Agreement is effective unless and until earlier terminated as set forth herein. This Agreement will terminate automatically if you fail to comply with any of the limitations or other requirements described herein. Upon any termination or expiration of this Agreement, you must destroy all copies of the Software and the Documentation.

    11. Miscellaneous. This Agreement is governed by the laws of the United States and the State of California, without reference to conflict of laws principles. The application of the United Nations Convention of Contracts for the International Sale of Goods is expressly excluded. This Agreement sets forth all rights for the user of the Software and is the entire agreement between the parties. This Agreement supersedes any other communications with respect to the Software and Documentation. This Agreement may not be modified except by a written addendum issued by a duly authorized representative of Network Associates. No provision hereof shall be deemed waived unless such waiver shall be in writing and signed by Network Associates or a duly authorized representative of Network Associates. If any provision of this Agreement is held invalid, the remainder of this Agreement shall continue in full force and effect. The parties confirm that it is their wish that this Agreement has been written in the English language only.

    Quick overview of the sections not included:
    2. Restictions: no renting/leasing/loading/reselling.
    4. Updates: No tech support.
    5. Ownership Rights: They still own all the copyrights.
    6. Warrant Disclaimer: "As is" software.
    7. Limitation of Liability: I can't hold them liable.
    8. US Government:
    9. Export Controls: Don't let it cross a border! oh no!
    10. High Risk Activities: Don't use this inconjunction with life-support, etc.

    So, section 1 grants me the right to use, copy and distribute PGP. Section 3, there is no expressed limit on the amount of time I can use it. The only limiting factor is section 11, which gives them the right to modify by a written addendum.

    Damn. Guess I'll just have to switch to GPG.

    - SignalFreq

    1. Re:My PGP EULA by Anonymous Coward · · Score: 1, Informative

      I believe that is fairly standard boilerplate. It means that nobody, even an employee of the company, can say or do anything to change that agreement.

      For example, some salesperson can tell a client "Oh, forget that #4 "no tech support thing", we'll always provide support to good customers like you." But, it wouldn't be binding.

      It is, I believe, without exception, impossible to write a binding contract that allows either party to unilaterally change the rules later. By any means.

      To try is to never gain a "meeting of the minds", an absolute pre-requisite to contracts. Such an adendum might just claim your first born, or something. You can't possibly know, so you can't possibly have agreed. (Well, at least in the pre-UCTIA world. Before the Government finally stole the birth right of citizens for Corporate greed).

    2. Re:My PGP EULA by mindstrm · · Score: 2

      Not binding? Sure it would be. Something the company told you verbally is just a separate contract.

      The EULA does not provide tech support, no, but if the company TELLS you it will, that's another story altogether.

  40. crypto.radiusnet.net is a joke by Anonymous Coward · · Score: 4, Insightful
    Hi all,

    I think we'll all find that this ends up being less of a problem than it seems to be, and certainly one unworthy of Declan's attention. The first thing to consider is that of the couple of security/crypto archives out there (Wiretapped, munitions.vipul.net, the old zedz.net site, Packetstorm), the crypto.radiusnet.net one is the only one of the group that is out of date, disorganised and discourages mirroring. Look over the site, and you'll see what I mean. The second thing to consider is that (as another poster has already mentioned) PGPi.org has the explicitly freeware versions of the software available on a number of mirrors worldwide, and does not appear to have been made a target here.

    Conspiracy theories aside, if they were mirroring commercial versions of the product, NAI is well within their rights to pursue them, and I'm sure the other legitimate crypto/security archive sites will be glad to see crypto.radiusnet.net stop sullying their good names by association.

    1. Re:crypto.radiusnet.net is a joke by Erris · · Score: 2
      GPi.org has the explicitly freeware versions of the software available on a number of mirrors worldwide, and does not appear to have been made a target here.

      It's kind of hard to enforce the DCMA outside the US, isn't it?

      NA is no longer selling PGP, right? It's a cost cutting measure, right? Sure, it's much cheaper to not defy your government and remain in business.

      I've seen a lot of posts here accusing radius of being a Warez site. Sounds like big bullshit to me. That letter would have been sent bye the "anti-piracy" division long ago if this were true. Are these posters telling me that radius really does not know what NA has asked them to remove?

      NA is within their legal rights in anycase. Their goofey EULA explicity alowed this kind of behavior, and US laws back them up. You never really owned it, you just used it. It's unatural, it's wasteful and it's stupid. That's why there is free software.. Drink all the free beer you want, but don't complain about the hangover or the night you spent sobering up in jail, or the little girl you ran over under the influence. The rest of us will tell you how obnoxious you were later.

      --
      DMCA, Hollings, Palladium. What might have sounded like paranoia is now common sense.
  41. That's point by famazza · · Score: 2, Insightful

    That's exactly the point. That's the way it should be. The application does exactly one thing, cryptography, and nothing else. This is the unix way.

    All applications should be responsible for a single task, we have wonderful examples to show us that this modularity is very positive, powerful applications, few bugs, easy customizations.

    OTOH we have only few examples of stable applications that have lots of functionalities, usually hard to customize, adapt to new paradigms and maintaince.

    The idea is keep all development teams independent of each other, by following few, but well defined, standards. That's the way X works, we must choose a window manager, X developers don't need to worry about user interface.

    IMHO this is the way it should be, of course, a tarball/rpm/deb/whatever that packs the application and GUI is a great idea, but much more important then this is the quality of the application

    --

    -=-=-=-=
    I know life isn't fair, but why can't it ever be un-fair in MY favor!?
    1. Re:That's point by Anonymous Coward · · Score: 1

      Tell that to the average user though. Your type of attitude is commonplace among the Linux users and that is why it will never become more than a niche OS for "power" users. Grandma doesn't want to have to learn to use cdda2wav, lame, and cdrecord on the command line to "rip, mix, and burn". She'll just buy a Mac or use Windows.

    2. Re:That's point by Dwonis · · Score: 3, Insightful
      It's still a good philosophy. The problem here is not that the frontend is separate, but that there are few (if any?) frontends.

      That said, using PGP-style crypto properly requires some background knowledge, and I won't be recommending it to the masses until that is addressed (by an interface or otherwise).

    3. Re:That's point by _Sprocket_ · · Score: 3, Insightful


      Grandma doesn't want to have to learn to use cdda2wav, lame, and cdrecord on the command line to "rip, mix, and burn".


      Actually... if Grandma wants to RIP CDs, she uses something like GRIP. This actually continues with the "unix way". GRIP is a GUI frontend that focuses on the interface. It takes advantage of strong components in the background that handle each step well. And Grandma has no idea. She just goes clicky-clicky and everything works. Well.
    4. Re:That's point by Anonymous Coward · · Score: 0

      "...that is why [Linux] it will never become more than a niche OS for "power" users"

      So what?

      "It's so complex, that's why cardiac surgery will never become more than a niche proffesion for proffesional surgeons"

      All well and good: I need powerfulness, I want simplyness if possible, but I don't want to sacrify powerfulness on behalf of simplyness (Keep it as simply as possible, but not simpler)

    5. Re:That's point by Anonymous Coward · · Score: 0

      Unix: when you want powerfulness without the simplyness. Perhaps I should reduce the previous posters illiteracyness and tell him that he's making things too complexityness. Or increase his vocabulary so it won't have so much scarcityness.

      The previous post should read: All well and good: I need power. I want simplicity if possible, but I don't want to sacrifice power to gain simplicty (Keep it as simple as possible, but no simpler).

    6. Re:That's point by ncc74656 · · Score: 2
      Grandma doesn't want to have to learn to use cdda2wav, lame, and cdrecord on the command line to "rip, mix, and burn". She'll just buy a Mac or use Windows.

      She could use EAC and drop a copy of the LAME DLL into the EAC directory. Tweak a few (relatively simple) settings and you have the best Windows-based ripping/encoding setup—and it's dirt-simple to operate. It'd take no more than a page to describe the installation and setup.

      --
      20 January 2017: the End of an Error.
  42. NOT FREE by Anonymous Coward · · Score: 5, Informative

    The version hosted on radiusnet was not a freeware version nor public domain, or whatever. It was PGP corporate desktop and other various COPYRIGHTED materials. I visited that sight every month or so for updated versions. Of course, now I use gpgp ;)

    1. Re:NOT FREE by walkern · · Score: 1

      Indeed

      PGPCorpDesktop_7.1.1.. 08-Jan-2002 11:25 11.8M

      (google cache - the site is not responding for me - presumed dead)

    2. Re:NOT FREE by ivan256 · · Score: 1

      other various COPYRIGHTED materials

      Please, it was UNLICENSED. Of cource it was copyrighted, as everything is by default, but that's irrelevent. copyrighted doesn't mean non-free with the proper licensing.

  43. Extra stuff removed by SpaceLifeForm · · Score: 1
    It's interesting that the entire directory contents (except index.html)
    and sub-directories appear to also be missing,
    even though not all of them were PGP related.

    For example http://crypto.radiusnet.net/archive/pgp/gnupg is not available.

    --
    You are being MICROattacked, from various angles, in a SOFT manner.
  44. AND... by Anonymous Coward · · Score: 0

    after a quick look around at the other crypto 'mirrors' of supposedly linux software, I found the same NAI PGP Corp. Desktop 7.1.1 still available for download for Win32

  45. Haiku! by Haiku_troll · · Score: 0

    PGP downloads
    Violate DMCA
    So says NAI

    1. Re:Haiku! by corebreech · · Score: 2, Funny

      nsa retards
      are fucking with my freedom
      and i pay these guys!

  46. Re:careful if you use wget for your websurfing nee by kubrick · · Score: 3, Interesting
    It's unethical. but it's possible to change this. And even if it weren't included in the options, being open source it would be easy enough to change:


    `-U AGENT-STRING'
    `--user-agent=AGENT-STRING'
    Identify as AGENT-STRING to the HTTP server.


    The HTTP protocol allows the clients to identify themselves using a `User-Agent' header field. This enables distinguishing the WWW software, usually for statistical purposes or for tracing of protocol violations. Wget normally identifies as `Wget/VERSION', VERSION being the current version number of Wget.

    However, some sites have been known to impose the policy of tailoring the output according to the `User-Agent'-supplied information. While conceptually this is not such a bad idea, it has been abused by servers denying information to clients other than `Mozilla' or Microsoft `Internet Explorer'. This option allows you to change the `User-Agent' line issued by Wget. Use of this option is discouraged, unless you really know what you are doing.


    --
    deus does not exist but if he does
  47. Excuse me but by Anonymous Coward · · Score: 0

    I thought Eudora was dead. Yes, some people still use it but there isn't anymore active by QCalm or whoever it was.

    1. Re:Excuse me but by Anonymous Coward · · Score: 0

      Depends on what you call "dead". The last version was released, oh, a couple of weeks ago.

      - Rob

  48. I've got it by Apreche · · Score: 2

    I've still got the installer for the newest version of free PGP for windows. If anyone wants it.

    --
    The GeekNights podcast is going strong. Listen!
  49. Re:NAI - Graduates of the Verisign School of Busin by Citizen+of+Earth · · Score: 1

    Somehow, I do not think I received my $1500 worth.

    You should know better than to use commerical software. The purpose of a corporation is to maximize profits. Period.

  50. Ugly reality of proprietary software by Ogerman · · Score: 2

    Well, first off, this really isn't a problem seeing as how the superior (and open) GnuPG is available to all. (And yes, there are GUIs available.)

    On the other hand, it's a scary look at how copyright with regards to software has apparently evolved into 'information control' instead of right to have a copy. How many proprietary software EULA's include a clause that XYZ company may terminate the license at any time? If I'm not mistaken, that means that someone like M$ or Adobe can walk into any office in the US that uses their software and shut them down at their own whim. And is there even a legal framework for forcing a refund? So lawyers or law experts, what you say about this?

    If this is all true, you RMS bashing folks in the crowd ought to give the 'all proprietary is evil' ideology another mental run-around before something else like this comes around and bites you. How long before we need a "War on Proprietary Software"? (-:

    1. Re:Ugly reality of proprietary software by josh+crawley · · Score: 2

      Well, technically, GNU software is proprietary. All that means is someone owns it. Company software (like MSWindows) is Trade secret, proprietary, and liscensed software. GPL stuff is STILL OWNED. By whom, you ask? Anybody who contributes to the code base.

      Say, a company goes to Linus and offers to buy an exclusive linux kernel for X dollars to him for unlimited liscense. OK. All he has to do is get an UNANIMOUS vote from EVERY DEVELOPER(lest that be thousands of lines of code, or a simple 1 liner) a YES to allow that liscense.

      Effectively, GPL locks out companies from using thier code directly.

    2. Re:Ugly reality of proprietary software by MAXOMENOS · · Score: 2

      Effectively, GPL locks out companies from using thier code directly.

      On the contrary: the GPL allows any company to use the licensed code. They just can't re-release it under a non-GPL license.

      As an interesting twist, this means that IBM has a say in whether LInux goes proprietary. I leave as an exercise for the reader to determine whether this could pose a problem later.

  51. To do list by corebreech · · Score: 2, Interesting

    I know gnupg has made some very big strides in this area, but clearly, now is the time to devise a framework upon which popular encryption is allowed to survive PGP.

    The point isn't whether the geeks can do it. The point is whether some poor, persecuted soul in some totalitarian country, like -- um, you know -- can click a button and send an email out of the country or to his best friend, securely.

    Clearly we would like to see front-ends developed for all the popular email applications that can accept code implementing any kind of encryption scheme whatsoever, and encryption algorithms that can fit into any popular email application available.

    If somebody comes up with a new encryption algorithm, they shouldn't have to write code to support Evolution, Eudora, Outlook Express, so forth and so on.

    Likewise, somebody should be able to write a front-end for a email application according to a specific API and expect to see every available encryption algorithm thus far implemented available from within that email application.

    And of course, it all needs to be open source. If anything needs to be open source, it is this.

    gnupg is great, but it presumes a single algorithm, doesn't it? Wouldn't it be much better to make it easier to introduce new algorithms into the mix? Put yourself in the position of the GS-7 analyst sitting in Virginia who has to run all these decipher jobs. If he gets to *assume* that the encryption being used is pgp-style, his workload is modest, he just needs to feed the file to the program.

    But if he first has to figure out what algorithm is being used, suddenly his job becomes many orders of magnitude harder. Especially if there are hundreds if not thousands of algorithms out there, each and every one available to the common man for his use.

    I know we're not supposed to rely on obscurity for encryption, but that presumes your only interest is in protecting a single channel of communication. If your interest is in protecting *all* channels of communication, obscurity becomes viable. Something as trivial as taking the output of gnupg and exclusive-or'ing with a Erica Rose Campbell jpeg would add another - if - statement to the NSA's decryption code. Add another 100 jpegs every day and very quickly the NSA's job becomes very, very hard.

    I never liked PGP. They zip before encrypting, and I could never get an answer from Zimmermann as to whether or not the checksum survived the zip. If the checksum survives, all the NSA has to do is unzip every try at an encrypted file and see if the checksums match. Strip out the checksum, and their job becomes much harder. The checksum needs to go.

    1. Re:To do list by dvdeug · · Score: 2

      gnupg is great, but it presumes a single algorithm, doesn't it?

      No. Everything's done by pluggable modules, and there are several choices of algorithm.

      But if he first has to figure out what algorithm is being used, suddenly his job becomes many orders of magnitude harder.

      It becomes n times harder, where n is the number of algorithms. Assuming, of course, that each of those algorithms is equally secure. In practice, there are a handful of algorithms that have been pounded hard enough to believe secure. Many other algorithms, especially those done by an untrained amature, will fall apart under the hands of a decent cryptoanalyist. It's much better to double your key length then to try and make choice of algorithm part of the encryption. (GPG includes the algorithm choice in plain text due to this principle.)

    2. Re:To do list by corebreech · · Score: 2

      I'll take your word for gnupg's pluggability, since no mention seems to be made of it in the documentation... but I'll read it again.

      However...

      I think you miss the point regarding the value of increasing the number of algorithms. The complexity increase is not n times but rather n factorial. Algorithms can be applied in daisy-chain fashion upon other algorithms. Even a trivial algorithm works here.

      Yes, a decent cryptoanalyst will tear apart a trivial algorithm, but how many decent cryptoanalysts are there? More than the number of people who can choose any combination of installed algorithms via point-and-click?

      No.

      Again, we've been trained to think about this as a problem of protecting a single channel. All of that is still valid, for that one specific problem. The problem of how to get the NSA to give up this travesty of a cause is quite another, and it is realizable only by demonstrating to them the impossibility of the problem they are attempting to solve.

      For instance, does gnupg allow me to plug in a one-time pad as an encryption algorithm? I don't think so. The gui I'm envisioning would. Yes, there are practical considerations in the use of the one-time pad, but once those are met, the resulting communication is impervious to cryptoanalysis, regardless of the technology the NSA is wielding.

      For instance, two friends at graduation who are going their separate ways, agree to rip a CD using /dev/random, make a copy, and use those 680MB to encrypt the emails they send to one another... for life. Very cool, very doable... very unbreakable.

      Get enough people doing that, along with people using the encoder rings they got in their box of Cap't Crunch, and rot13, and all the trivial extensions of all the serious encryption algorithms and the NSA will be swimming in complexity... a kind of complexity they can't easily leverage their hardware to tame.

    3. Re:To do list by dvdeug · · Score: 2

      The complexity increase is not n times but rather n factorial

      A complexity increase that can disappear in an instant, and comes at the cost of using a good algorithm.

      Algorithms can be applied in daisy-chain fashion upon other algorithms.

      Which, in some cases, will render them worthless as they counteract each other.

      Yes, a decent cryptoanalyst will tear apart a trivial algorithm, but how many decent cryptoanalysts are there?

      If you don't want to keep it from a decent cryptoanalyst, why bother using serious encryption in the first case?

      For instance, two friends at graduation who are going their separate ways, agree to rip a CD using /dev/random, make a copy, and use those 680MB to encrypt the emails they send to one another... for life. Very cool, very doable... very unbreakable.

      I don't know how many years it would take to get 680MB from /dev/random, but it isn't going to be quick. In any case, who cares? Add a patch to GPG to do this, but don't think there will be many users.

      the NSA will be swimming in complexity... a kind of complexity they can't easily leverage their hardware to tame.

      I would be surprised. One good algorithm used by the people they want to watch would give them trouble. A thousand lousy ones will merely make their jobs more interesting - "hey, look, here's another idiot using MD4. Haven't seen that in a while."

    4. Re:To do list by MikeBabcock · · Score: 2

      Your basic problem, pointed out many times, is that you're applying the _wrong_ math to the problem.

      Cryptanalysis isn't random probabilities from discrete 101 ... its large number theory (in most cases) and usually uses direct analysis, not trial and error.

      --
      - Michael T. Babcock (Yes, I blog)
  52. wow by Anonymous Coward · · Score: 0

    Why let commercial interests rob the public of essential tools?

    Talk about making a case for GPL open source!

    Shacof

  53. Whats funny... by f0rtytw0 · · Score: 2, Insightful

    Whats funny is originally PGP was released for free on the internet at a time when encryption software had heavy export restrictions. Being released for free on the internet was what made it so popular.

    --
    this is the most important sig ever! In your face 446154!
  54. The nicer looking response... by Dogcow · · Score: 5, Informative

    ---------- Forwarded message ----------
    Date: Wed, 22 May 2002 14:41:59 +1000 (EST)
    From: Grant Bayley
    To: Declan McCullagh , R. A. Hettinga ,
    Meyer Wolfsheim , peter_beruk@nai.com
    Subject: Re: NAI pulls out the DMCA stick.

    Hi Declan, others.

    The hype being generated by the "NAI pulls out the DMCA stick" postings and the spectre of PGP being "removed from the Internet" is entirely bogus, and provably so with a little bit of fact checking.

    Looking through the Google cache, it becomes very clear very quickly that crypto.radiusnet.net was hosting a copy of the commercial version of the software - not a copy of the PGPi (aka freeware) version of the PGP product. Given that this is the case, NAI is well within their rights to demand the removal of the files.

    You can confirm this in the Google Cache, here:

    http://216.239.33.100/search?q=cache:QA-H5VtPvP4 C: crypto.radiusnet.net/archive/pgp/+&hl=en

    Keep in mind that of the couple of crypto/security archives out there, the radiusnet one is basically the "abortion" of the bunch. It's disorganised and out of date in so many places as to be dangerous.

    By "crypto/security archives", I'm referring to Wiretapped (www.wiretapped.net, which I operate), munitions.vipul.net, the zedz.net archives (ftp://ftp.zedz.net/) and Packetstorm (www.packetstormsecurity.org).

    If this is the straw that breaks the radiusnet camel's back, I for one won't be complaining, if only because of the old and out of date material
    on the site. In the case of tools that perform a security function using crypto (IPSec, ssh etc), being updated is critical, as a number of the older versions of the software have contained serious security problems.

    Grant

  55. FUD, Disinformation, Scare Tactics, Misleading by Anonymous Coward · · Score: 0

    Albeit there probably was something that shouldn't have been on the server.

    But I can not stop laughing everytime I see this whole PGP flap.

    What is going on is your all being scared to look for a warezed version, somehow it will be better than a older free version. Like somehow it is going to disappear.(sic)

    Ah but perhaps your getting a backdoored version? Can you tell the difference? Could you tell the difference even if you have the source?

    I wouldn't trust a damn thing that comes from NAI. Just check who they have been sleeping with.

    I wouldn't trust a damn person that use's their product. Since they can't be very intelligent if they knowing use bad wares.

    The right kind / and version of crypto, and the knowledge of the users is the key. Even then I bet that if "someone" who has lots of money wanted to crack your little measly key they could.

    screw all the hype. save your bandwidth. who knows, you may even be tracked by "someone" for attempting to get specific filenames, off specific sites. Wanna be on that "list?"

    I feel sorry for the clueless. They haven't been around long enough to know the difference. And that wisdom they probably never will get.

  56. Uh, use Kazaa and grokster for privacy? huh? by Cecil · · Score: 2, Informative

    Have none of you heard of gnucleus? gnutella, free, spyware-free, open source?

    Uh, unless you like spyware while you're installing encryption software. riiight.

    1. Re:Uh, use Kazaa and grokster for privacy? huh? by Anonymous Coward · · Score: 0

      Anyway I think it's a typo.. should have been "use Kazaa and grokster for piracy"!

  57. Exactly why they're ditching it by Anonymous Coward · · Score: 0

    They are _not_ encouraging the widespread use of encryption.

  58. Ho Hum Lunix Lunix Lunix by Anonymous Coward · · Score: 3, Insightful

    The subject line here should be: Free Software Advocates shoot their mouth off without checking the facts.

    Over 100 posts, and only one or maybe two have hit the nail on the head - the site was posting commercial, proprietary software. Not free software in whatever sense you like to use the term. Not open source either.

    Please guys, get your facts right before posting.

    Whoops - I forgot - this is Slashdot.

    Home of irresponsible adhocratic journalism...

  59. Re:Encryption is for terrorists by Anonymous Coward · · Score: 0

    in case *you* are a moron, **you have been trolled!**

  60. Another proof for how right RMS is by Baki · · Score: 5, Insightful

    Richard Stallman was (once again) criticized by some of the slashdot crowd today in this article, about being pedantic, purist, impracticle etc. PGP/GPG is an excellent example of RMS being pedantic and purist, and rightly so.

    RMS and the FSF have always been refusing to use PGP, because of its license. They have been critiziced along the same lines for this, since PGP was "free in a practical sense" i.e. free as in free beer, even though it had been written by "good guy" Phil Zimmermann. Today we may be glad that the FSF refused to use PGP, started to write GPG as soon as the RSA patent expired (i.e. as it was legally possible to write a clone without infringing on patents).

    1. Re:Another proof for how right RMS is by MAXOMENOS · · Score: 4, Informative

      Work on GnuPG was proceeding well before the patent on RSA expired; GnuPG uses a completely different algorithm (ElGamal, which uses discrete logs) for public-key encryption. ElGamal was technically covered by the Diffie-Hellman, but that expired in 1997. Click here for a brief description of ElGamal.

      That having been said, I agree with you whole-heartedly that RMS's hard-headedness about PGP is our saving grace. Thankfully, we now have a PGP replacement that is just as effective, if slightly less user-friendly right now, as the original; and which is also useful for commercial enterprises (unlike the "free" version of PGP).

    2. Re:Another proof for how right RMS is by Daffy+Duck · · Score: 1

      Just to be pedantic, GPG was written long before the RSA patent expired. Because of the patent, it didn't have "official" RSA support, but you could get it separately as a module. This is still the case for IDEA, whose patent hasn't expired.

  61. Haven't I Seen This Somewhere Before? Oh well... by krmt · · Score: 3, Interesting

    First they came for the Amiga, and I did not speak out because I was not an Amiga user.

    Then they came for Be, and I did not speak out because I was not a Be user.

    Then they came for Blender and I did not speak out because I was not a Blender user.

    Then they came for PGP, and I was thankful that someone had spoken for me.


    Many thanks to the GnuPG developers.

    --

    "I may not have morals, but I have standards."

  62. Are you trolling? by rjh · · Score: 5, Informative
    Really. You're painfully uninformed.

    If somebody comes up with a new encryption algorithm, they shouldn't have to write code to support Evolution, Eudora, Outlook Express, so forth and so on.

    They don't. RFC2440 (plus RFC2015, 3156, etc.) are extensible; they support a broad variety of algorithms and are designed to support future algorithms. RTFFAQ.

    Likewise, somebody should be able to write a front-end for a email application according to a specific API and expect to see every available encryption algorithm thus far implemented available from within that email application.

    Microsoft CAPI provides just this. GPG Made Easy (GPGME) also makes it almost trivial to incorporate crypto support into your application. (ObDisclosure: I'm working on C++ bindings for GPGME, so I'm biased.)

    gnupg is great, but it presumes a single algorithm, doesn't it?

    RTFFAQ. OpenPGP supports more algorithms than you can shake a stick at. For instance:
    • IDEA
    • 3DES
    • CAST5-128
    • Blowfish
    • Rijndael/AES-128, -192, -256
    • Twofish
    • RSA
    • El Gamal
    • DSA


    Wouldn't it be much better to make it easier to introduce new algorithms into the mix?

    No. In fact, I personally dislike the fact that most PGP implementations (including GnuPG) support so many algorithms. Every implementation must support 3DES, and y'know, 3DES has a twenty-five year track record of turning brilliant cryptanalysts into burned-out alcoholic wrecks. Anyone who wishes to use AES256 for "security" is missing the point--the most trusted algorithms aren't the latest sexy things. The most trusted algorithms are the ones which are older than God and uglier than a Soviet worker's housing bloc.

    If he gets to *assume* that the encryption being used is pgp-style, his workload is modest, he just needs to feed the file to the program.

    The analyst is already going to know what algorithms you're using. The way you plan these things is to assume the analyst has access to tens of thousands of times more computing power than exists in the world, tens of thousands of times more memory than exists in the world, knows you better than your wife does, and knows every last detail of your cryptosystem except what your key is.

    Assuming anything else is absolute folly.

    And yes, I am a cryptographer.

    Especially if there are hundreds if not thousands of algorithms out there, each and every one available to the common man for his use.

    There are three symmetric algorithms I would trust my deepest secrets to. IDEA, 3DES and Blowfish. AES isn't on that list (won't be for another couple of years while peer review shakes out). If I'm a professional in this field, and out of the literally thousands of different symmetric block ciphers proposed over the years I can only find three which I recommend without hesitation, and the other 997+ range somewhere between interesting-but-flawed and fatally stupid, I really doubt that you--a layman with no experience whatsoever--will be able to intelligently choose the three good ciphers out of a field which consists, mostly, of spectacularly bad ones.

    Something as trivial as taking the output of gnupg and exclusive-or'ing with a Erica Rose Campbell jpeg would add another - if - statement to the NSA's decryption code

    Please go read this book: Codebreaking, by Rudolf Kippenhahn. You have a critical misunderstanding of how cryptanalysis works. It doesn't work by a series of "try this, then try that, then try..." It works by looking for redundancies, patterns, in data and then creating a mathematical model which can recreate those same redundancies and patterns. If you're XORing with a JPEG, you're not going to be making it appreciably harder to break. There's a lot of mathematical order in a JPEG.

    I would bother responding to your last comment about why PGP is "weak", but really, it's clear that you're talking through your hat. I can believe that you're utterly clueless, or I can believe that you're trolling. If the latter, then HAND, IABT. If the former, then please go off and read up on the subject.

    I'd suggest starting with David Kahn's The Codebreakers, from there Rudolf Kippenhahn's Codebreaking, then Schneier's Secrets and Lies. Only then start to work on Applied Cryptography and the Handbook of Applied Cryptography.
    1. Re:Are you trolling? by MAXOMENOS · · Score: 1

      Every implementation must support 3DES, and y'know, 3DES has a twenty-five year track record of turning brilliant cryptanalysts into burned-out alcoholic wrecks.

      If I had a mod point, I'd mod you up +1 Funny just for that image. Then again, I'm one sick dude.

    2. Re:Are you trolling? by corebreech · · Score: 1, Troll

      Really. You're painfully uninformed.

      That could very well be. Reading your reply shows I'm in good company.

      RFC2440 (plus RFC2015, 3156, etc.) are extensible...

      Um, no, they aren't. They're good for public-key and symmetric encryption, but, despite what you learned at the university, public-key and symmetric aren't the only choices available.

      I'd like to plug in a one-time pad, if that's OK with you. Utterly unbreakable. I like that. OpenPGP doesn't seem to easily support that.

      I'd also like to support trivial encryption methods, like replacing 'a' with 'c', etc. Yes, any three-year-old would be able to break it. But if you make it easy for people -- including novice users -- to pick and choose from these trivial algorithms any number of same and apply them to their message it would require some fantastic coding on the part of the NSA to automatically decipher it all.

      Yes, if they want to devote GS-7's to the task of decrypting a specific message they'll be able to do it. But they won't be able to automate the decryption of all our messages. They'll have to assign each to a GS-7.

      There are more of us than there are GS-7's. It's not a subtle point I'm making here, is it?

      Microsoft CAPI provides just this. GPG Made Easy (GPGME) also makes it almost trivial to incorporate crypto support into your application. (ObDisclosure: I'm working on C++ bindings for GPGME, so I'm biased.)

      I wouldn't say your biased. Just defensive. For what it's worth, I think you're doing us all a great service by focusing on exactly what you're doing.

      I just think you're missing my point. For instance, you've only listed two API's up there, for two families of email products. There are dozens more applications that are candidates for this. And all the work is being done to support formally correct algorithms. What I'm saying is that there is a value to worthless algorithms (as well as uncrackable algorithms like one-time pads) that deserve to be put in the mix too.

      RTFFAQ. OpenPGP supports more algorithms than you can shake a stick at. For instance...

      Yes, I've read the FAQ. I don't see one-time pads listed there. The one algorithm that is provably undecipherable and it's not available to me. Maybe some of you guys need to read the Frequently Asked Requests list?

      No. In fact, I personally dislike the fact that most PGP implementations (including GnuPG) support so many algorithms...

      Please try to look at this from the point of what goes on at the NSA. Have you ever heard of the expression, "low-hanging fruit"? Most of what the NSA is called on to decipher is "low-hanging fruit." It is stuff that they can easily decipher by simply inputing the file into some program running on some supercomputer somewhere.

      What we should want to do is make it hard for them to guess what program to feed a encrypted file to. If you have 10,000 stupid and trivial encryption algorithms that can be broken by three-year-olds you'll still need 10,000 three-year-olds to sit down and figure them out if you want to crack them. If you have people out there encoding their messages using any combination of those 10,000 trivial encryption algorithms you have 10,000 factorial problems to work out.

      I'm repeating myself, but the point can't be stressed strong enough. If the NSA wants to decrypt any one of these, they can. But if everyone were to adopt this kind of approach, the NSA would not be able to routinely decrypt our messages. They wouldn't be able to simply feed them all to a computer, they'd have to assign GS-7's to the task, and it would take time... lots of it. The scenario I'm envisioning would see the agency demoralized within a year, and their masters dissatisfied with their work product within another five years.

      The analyst is already going to know what algorithms you're using. The way you plan these things is to assume the analyst has access to tens of thousands of times more computing power than exists in the world, tens of thousands of times more memory than exists in the world, knows you better than your wife does, and knows every last detail of your cryptosystem except what your key is.

      WRONG!!! If we make it easy for users to come up with weak, but utterly wacky, algorithms, how will they know??? How do they know I'm exclusive-or'ing with a Erica Campell jpeg? Hmmm? Did you tell them?

      If we give users an interface that lets them improvise their own ridiculous encryption algorithms, and layer them atop the more secure algorithms you're talking about, the analysts will no longer be able to assume what algorithm is being used. And that's my whole point.

      That's what we need to change. We can't let them simply assume anymore. We need to make them really work for our data.

      And yes, I am a cryptographer.

      No offense, but that's your problem. I'm not taking about the art of cryptography, per se. You can't see the forest for the trees. Please think about what I'm saying. Don't think about the math of it, think about what the GS-7 at the NSA has to do to deal with what I'm talking about.

      Please go read this book: Codebreaking, by Rudolf Kippenhahn. You have a critical misunderstanding of how cryptanalysis works. It doesn't work by a series of "try this, then try that, then try...

      You're talking about cryptoanalysis that focuses on a single encrypted file. I'm talking about cryptoanalysis as it occurs in a data shop, where there are umpteen candidate files that need to be decrypted, and some GS-7 who's pushing all the buttons to see that the right files go to the right programs.

      I concede that what I'm talking about is crackable. Actually, I personally don't mind that the NSA is able to target a specific communication and decrypt it. What I object to is their being able to summarily decrypt all our communications simply because they can.

      You should be familiar with the use of chaff in encryption. What I'm suggesting isn't too different from that, except here it would be introduced to the system at a macroscopic scale.

      I would bother responding to your last comment about why PGP is "weak", but really, it's c

      This comment was cut short. If you know that PGP doesn't save the checksum, please say so. Or are you defending its inclusion?

    3. Re:Are you trolling? by rjh · · Score: 3, Informative

      It's absolutely clear that you're on crack. Sorry, but I don't have time to waste getting trolled. Look at my prior response. The answers you want are in there.

      Barring that, you could do something daring (gasp!) like, oh, reading the published literature. Somehow, though, I don't expect you've done any of that.

    4. Re:Are you trolling? by corebreech · · Score: 1, Redundant

      Dude, I've read through all of Schneier's "Applied Cryptography", First Edition, and spent many an hour comparing his Second Edition with his first.

      Read "Secrets and Lies" too.

      I've implemented in C any number of encryption algorithms, have invented a few of my own too actually (yes I know, LOL.) I got OpenSSL to compile and work the way I wanted in both Linux and Windows environments, um, OpenSSH too. PAM. Etc.

      I'm no super-duper-math-genius or anything, but then, clearly, neither are you.

      I think you're just having a bad day. A lot of people here don't get the pussy they need, and I'm thinking we should elect you as our leader... you've got all the symptoms and you don't seem to mind showing it. I salute you.

      But if anybody is trolling here, it is you.

    5. Re:Are you trolling? by corebreech · · Score: 2

      OK, I see /. truncates messages, it's happened to my reply (first time I've seen it happen to me) and it happened to your message. I'm particularly interested in how you were going to finish the following sentence:

      I would bother responding to your last comment about why PGP is "weak", but really, it's c

      Again, I was making a big deal about the checksum appearing in the zip file that PGP creates before encrypting.

      You don't think that's a problem?

    6. Re:Are you trolling? by dvdeug · · Score: 2

      I don't see one-time pads listed there. The one algorithm that is provably undecipherable and it's not available to me.

      You're a programmer; that's a program for a first-year student. There's so many possible formats for a one-time pad - I can't imagine a generic program that would support your CD-ROM idea. Given how insecure one-time pads are, if not used carefully, and how much a PIA they are to use, if used carefully, I really don't see the point in such an addition to GPG.

      If the NSA wants to decrypt any one of these, they can.

      There's no evidence they can break 3DES or Blowfish.

      But if everyone were to adopt this kind of approach, the NSA would not be able to routinely decrypt our messages.

      They would be able to decrypt any message they wanted to; half the time they would just feed them to a computer, the computer would run the top 50 trivial algorithms, and spit out the answer.

    7. Re:Are you trolling? by timerider · · Score: 1

      ever tried to click a link?
      especially the 'read the rest of this comment' link?

    8. Re:Are you trolling? by Anonymous Coward · · Score: 0

      I am sorry for interupting this great piece of discusion or trolling....whatever.
      corebreech argues that if every joe six-pack gets his own rotl13 eqevalent intergrated into outbreak the nsa and every other group sniffing on every bit ever put on a line or on the air while having a beowulf of automated decryption proceses is gonna have an big task getting the e-mails to the right automated decrypt-where-posible systems. He is scared about groups getting just the amount of computing power to decrypt a percentage of everything they intercept, a percentage that scales relative with the amount of previously cracked keys they have (they have to have some passphrase storage, afterall they would want to try the passes they gathered trough human inteligence on every mail they see, same passphrase, same terrorist organisation)(also for crypto systems where a cracked message does not reveal the passphrase(like pgp??) when they find the plain text is full of the word bomb, they will ofcourse go after the pass to make sure they get future (and past?) mails). This percentage would also scale with the amount of money they get from whoever funds them(adding beowulf nodes)

      rjh thinks that most of the things corebreech claims are not based on the traditional way cryptoanalysis on a specific message works which does not matter that much becouse what the nsa does to thousands of poor inocent private e-mails is hardly traditional analysis.

      And now my idea, isn`t the whole idea behind a multiple cipher system (pgp)or a system where everyone can plug the crypto they please into outbreak only posible if there is a plaintext indication of the cipher used? This would make the "evil" nsa`s job to stay on top of new crypto plugins rather then finding ways to distinguish between them.

    9. Re:Are you trolling? by ZanshinWedge · · Score: 2
      Um, no, they aren't. They're good for public-key and symmetric encryption, but, despite what you learned at the university, public-key and symmetric aren't the only choices available.

      I'd like to plug in a one-time pad, if that's OK with you. Utterly unbreakable. I like that. OpenPGP doesn't seem to easily support that.

      Umm, call me crazy but I think that one-time-pads are a form of secret-key symmetric cipher. I'm fairly sure the RFC is sufficiently flexible to allow such a thing.

      Otherwise, the rest of your post is just garbage. Weak but "unknown" algorithms do not provide security, even millions of them. Only strong algorithms provide security. If you really want to make the NSA fume then use RSA with an 8192-bit key, yeah they ain't gonna bust that one for a good long while if they don't have the private key.

    10. Re:Are you trolling? by cowbutt · · Score: 2
      I can't imagine a generic program that would support your CD-ROM idea.

      You could always run your data through cdencrypt before you PGP/GPG it. ;-)

    11. Re:Are you trolling? by Coolfish · · Score: 2

      you're complaining that PGP doesn't implement one time pads. This is all one needs to see that you're completely full of crap.

    12. Re:Are you trolling? by corebreech · · Score: 2

      No, not at all.

    13. Re:Are you trolling? by corebreech · · Score: 2

      You're a programmer; that's a program for a first-year student.

      Actually, a small child flipping a coin can implement the algorithm, but that isn't my point. The one-time pad is the only algorithm that can be said to be absolutely secure provided the pad can be exchanged reliably. That makes it ideal for certain applications.

      There's so many possible formats for a one-time pad - I can't imagine a generic program that would support your CD-ROM idea.

      Are you kidding? All you would need to do is save an index value somewhere. When encrypting a message, exclusive-or the message with the random data on the CD at that index value, then increment the index value by the amount of data encrypted for the next use. Vice versa when decrypting. Very simple.

      Given how insecure one-time pads are, if not used carefully, and how much a PIA they are to use, if used carefully, I really don't see the point in such an addition to GPG.

      You're grossly exaggerating the insecurity here. Unless you have every password you use memorized, you have some written down somewhere or stored in some device. The risk of using a one-time pad is the same, provided you've securely exchanged the pad in the first place (no big deal.)

      There's no evidence they can break 3DES or Blowfish.

      Yes, of course the NSA will announce when they've broken 3DES or Blowfish.

      They would be able to decrypt any message they wanted to; half the time they would just feed them to a computer, the computer would run the top 50 trivial algorithms, and spit out the answer.

      Yes, that works for 50 trivial algorithms. What I'm talking about is allowing novice users to create any number of trivial algoritms, and to combine any number of same together with stronger algorithms to create a truly impossible job for the NSA. It wouldn't be 50 tries they'd have to do, it'd be more like 10,000 factorial.

    14. Re:Are you trolling? by lithron · · Score: 1

      And that, everyone, is a good troll. Only problem is that the other poster was too smart to fall for it :-)

      There is always next time.

    15. Re:Are you trolling? by corebreech · · Score: 2

      Umm, call me crazy but I think that one-time-pads are a form of secret-key symmetric cipher.

      You're right of course, I've gotten in the habit of regarding one-time pads as being in a class of their own. Something about their being the only kind of crypto that will survive quantum computing.

      But I guess it doesn't say that in the textbook.

      Otherwise, the rest of your post is just garbage. Weak but "unknown" algorithms do not provide security, even millions of them.

      Clearly, you haven't read anything I've written. Either that or you're a idiot. Don't feel bad, there are lots of idiots here, you're in good company.

      The point to the trivial encryption algorithms isn't that they'd pose a challenge individually to the NSA, but rather, when taken together, they'd pose an enormous logistical problem for them... one that would probably be insurmountable.

      The trivial algorithm could always be applied on top of a more robust one.

      The trivial algorithm would have to be something that could easily be created by a novice, by being able to select from a list of thousands of prepackaged trivial algorithms perhaps, and then chaining them together so that the number of tries required by the NSA computer would be on the order of 10,000 factorial, say.

      Think of it as insurance. The NSA may not be able to crack some of these more robust algorithms, but then again, they just might. All of you are looking at this from the point of view of cryptographers. I'm looking at it from the point of view of somebody who is running thousands of jobs a day trying to decrypt a steady stream of traffic assigned to them.

      Whatever. If you don't get it by now, there's no use. You'll just have to wait for the textbook.

    16. Re:Are you trolling? by john_cfa · · Score: 1

      The problem with trivial algorithms is that you don't need to know the algorithm to crack them. You just look for patterns, and whether you have 1000, or 1000000 poor algorithms it takes exactly the same amount of time to crack, you just ignore the encription method, and look for the key, exactly the way you crack a one time pad, all it takes is a long enough message, and out pops your answer, just like cryptanalysis used to work before being put on the formal basis that brought about strong algorithmic encryption.

      What you're proposing would simply massively decrease the amount of time that MOST messages would take to decrypt, whilst slightly increasing the time that strongly encrypted messages take. Or to put into the political context, those of us who think the NSA are bad people, but generally are of no interest to them, would have our mail read, but our obfuscation would ever so slightly help the nasty terrorist types who would not be foolish enough to use trivial encryption.

    17. Re:Are you trolling? by dvdeug · · Score: 2

      That makes it ideal for certain applications.

      Not many. Virtually invincible and practical beats the heck out of invicible and clumsy for most.

      You're grossly exaggerating the insecurity here.

      Not really. If you loop over, breaking the code is trivial. If your noise algorithm really wasn't that great after the first few bytes (and /dev/random quite possibly isn't), breaking the code is trivial.

      Yes, of course the NSA will announce when they've broken 3DES or Blowfish.

      Civilian cyrtographers been working on block-algorithms like DES and Blowfish for many years now; even with the advance in knowledge and technology since DES was created, we still can't easily break DES. The only way we can think of to break it would take very expensive hardware that no civilian has. Given what we know about DES and DES-like algorithms, Blowfish or 3DES, given a secure password, can't be broke by any means known to man; all cracking algorithms would take longer than the expected lifetime of mankind. And if there were a shortcut, then the NSA would be moving the government away from DES and Blowfish-like cyphers; but they aren't.

      Unless you're completely paranoid, the only reasonable guess is that they haven't cracked 3DES or Blowfish. And if you are, then I'd worry about the orbital mind-control lasers first.

      What I'm talking about is allowing novice users to create any number of trivial algoritms,

      95% of those algorithms aren't going to make cracking it any harder. Ceasar cyphers and the like don't change the enthropy of the message. Furthermore, they don't stack; they merge, meaning two of the algorthms make just another trivial algorthim of the same type. Worse yet, if you let novice users create encryption algorithms, some of them will mangle their data beyond recovery.

      You can't just stack a bunch of trivial algorithms on top of each other and get a good algorithm. What you get is a trivial algorithm, and likely a trivial algorithm that is known and simple. And if you let novices at it, quite likely a trivial algorithm that doesn't work.

    18. Re:Are you trolling? by Coolfish · · Score: 2

      and how sir are you going to DISTRIBUTE the one time pads? Encrypt them with something else and then send them? Lemme guess, you'd encrypt them with ROT12 instead of ROT13. and how would you tell the person that you've encrypted them with that? You'd probably say "I've encrypted with this ROT13............. (-1 !! - please don't look at this bad guys!) "

      you have no idea what a one time pad is, how it works, and the major problems associated with it. it's no wonder it's not in PGP because implementing it securily and efficiently would be next to impossible.

  63. Re:careful if you use wget for your websurfing nee by Anonymous Coward · · Score: 1, Insightful

    Maybe it's unethical for you, but you're not authorative of ethics. Nobody is.

  64. Re:NAI - Graduates of the Verisign School of Busin by Anonymous Coward · · Score: 0

    fuck off

  65. Re:Encryption is for terrorists by ObviousGuy · · Score: 0, Troll

    you make funnel cakes from sperm

    I used to and your mom loved them, but I had to give it up. The boiling oil splashing out wasn't good for my foreskin.

    --
    I have been pwned because my /. password was too easy to guess.
  66. Misleading headline by Simon+Garlick · · Score: 3, Informative

    So NAI wants to stop warez distribution of its full commercial (unbuyable or not) registered PGP suite. Perfectly reasonable.

    Good to see the Slashdot editorial team is on the job! Nice work, Timothy!

    1. Re:Misleading headline by Anonymous Coward · · Score: 0

      Everyone in the world has a right to find, download and use warez! I call it the "right to steal and load software".

  67. PGP For UNIX 5.0.2 Retail License Agreement (long) by Wanker · · Score: 3, Informative

    For your reading pleasure:

    -----
    PGP for Unix, Version 5.0.2
    LICENSE COPY OF NETWORK ASSOCIATES PRODUCTS

    (Commercial, Executable Version)

    Copyright (c) 1990-1998 Network Associates Inc., and its Affiliated Companies.
    All Rights Reserved.

    End User License Agreement for PGP for Unix

    IMPORTANT-READ CAREFULLY: This Network Associates End-User License Agreement
    ("Agreement") is a legal agreement between you (either an individual or a single
    entity) and Network Associates, Inc. (or "Network Associates") for the Network
    Associates software product identified above, which includes computer software
    and may include associated media, printed materials, and "online" or electronic
    documentation ("Software Product"). By installing, copying, or otherwise using
    the Software Product, you agree to be bound by the terms of this Agreement. If
    you do not agree to the terms of this Agreement, you may not install or use the
    Software Product; you may, however, return it to your place of purchase for a
    full refund.

    The Software Product is owned by Network Associates, Inc. and is protected by
    copyright laws and international copyright treaties, as well as other
    intellectual property laws and treaties.

    1. GRANT OF LICENSE. Network Associates grants you (the original end-user,
    except as permitted under 1 (g)) a non-transferable non-exclusive license to put
    in use by a person or organization that agrees to be bound by the terms of this
    Agreement, one copy or node of the Software Product. If you purchased this
    Software Product from a retail store or directly from Network Associates as a
    retail product for individual users, this license is effective until terminated.
    If this Software Product was purchased in some other manner than as a retail
    product, the license may have a term commencing on the Delivery Date of a
    Product and continuing for an extended period of time as otherwise indicated in
    your purchase order or as set forth in a separate and complementing Software
    License Agreement to which this End User License Agreement is subject to.

    a. Installation. You may install one copy or node of the Software Product on
    one Client Device (defined as, any computer, workstation, personal digital
    assistant, pager, "smart phone" or other digital electronic device for which the
    software was designed and on which software may be used by an end user in
    client-mode).

    b. Use. You may use one copy or node of the Software Product on one Client
    Device or Server (except as may be specifically provided below). The Software
    Product is "in use" when it is loaded into the temporary memory (i.e., RAM) or
    installed into the permanent memory (e.g., hard disk, CD ROM, or other storage
    device) of a Client Device for the purpose of being accessible in client-mode by
    one end user. Though the Server may be connected at any point in time to an
    unlimited number of workstations or computers operating on one or more networks,
    you must acquire a separate License for each end user who accesses or otherwise
    utilizes the services of the Software Product. Any computer, workstation,
    personal digital assistant, pager, "smart phone" or other digital electronic
    device on which software may be used by an end user in client-mode shall be
    referred to as a "Client Device." An end user who uses software on a Client
    Device that accesses or otherwise uses the Software Product shall be referred to
    as a "Seat." Each License must be dedicated to one unique Client Device or Seat.
    It permits that Client Device or Seat to access or utilize the services of any
    Server running a copy of the Software Product. The services of the Software are
    considered to be accessed when there is a direct or indirect connection between
    a Client Device or Seat and a Server. Use of software or hardware that reduces
    the number of Client Devices or Seats directly accessing or utilizing the
    Software Products (sometimes called "multiplexing" or "pooling" software or
    hardware) does not reduce the number of Licenses required (e.g., the required
    number of Client Access Licenses would equal the number of distinct inputs to
    the multiplexing or pooling software or hardware "front end"). If the number of
    Seats or Client Devices that can access or use the Software Product can exceed
    the number of Licenses you have obtained, then you must have a reasonable
    mechanism or process in place to ensure that the number of Client Devices or
    Seats accessing or using the Software Product does not exceed the number of
    Licenses you have obtained.

    c. Volume Licenses. If this package is a volume license package (such as a
    "corporate license" or a "corporate bundle"), you may make and use additional
    copies or nodes of the Software Product up to the number authorized in this
    package or in your corporate license agreement, or otherwise indicated at the
    time of purchase. If the anticipated number of users of the Software Product
    will exceed the number of applicable licenses, then you must have a reasonable
    mechanism or process in place to ensure that the number of persons using the
    Software Product does not exceed the number of licenses you have obtained.

    d. Upgrades. If this Software Product is labeled as an upgrade or trade-up
    from a prior version of a Network Associates product that you were properly
    licensed to use, Network Associates grants you the right to put in use either
    the current or prior version of the Software Product, and any prior version
    license is replaced by this Agreement.

    e. Support. Subject to U.S. export control laws and regulations, Network
    Associates may provide you with technical support services relating to the
    Software Product according to Network Associates' standard support policies and
    procedures, which may be described in the user manual, in "on line"
    documentation and/or other materials provided by Network Associates or posted on
    Network Associate's web site ("Support Services"). Any supplemental software
    code provided to you as part of the Support Services shall be considered part of
    the Software Product and subject to the terms and conditions of this Agreement.
    With respect to technical information you provide to Network Associates as part
    of the Support Services, Network Associates may use such information for its
    business purposes, including for product support and development. Network
    Associates will not utilize such technical information in a form that personally
    identifies you.

    f. Dual Media Software and Multiple Platform Versions. If the package from
    which you obtained this Software Product contains more than one medium (e.g.,
    both 3 1/2" disks and a CD), you may use only the medium appropriate to your
    computer. You may not use the other disk(s) on another computer or loan, rent,
    lease, or transfer them to another user except as permitted under this Agreement
    or as part of the permanent transfer (as provided above) of all the Software
    Product and related materials. If the CD or disk(s) on which the Software
    Product resides contains several copies of the Software Product, each of which
    is compatible with a different operating system or platform architecture (such
    as Windows95/NT, Macintosh, one or more versions of Unix, the x86 architecture,
    or various RISC architectures), then you may install the Software Product for
    use with any of those architectures up to the number of copies or nodes
    purchased but in no event may you use any version(s) on another computer or
    loan, rent, lease, or transfer them to another user except as permitted under
    this Agreement or as part of a permanent transfer (as provided above).

    g. Restrictions.

    i) Transfer. The original of this Agreement is your proof of license
    to exercise the rights granted herein and must be retained by you.
    You may not rent or lease the Software Product, including all
    accompanying printed materials.

    ii) Other Restrictions. You may not reverse engineer, decompile,
    disassemble or otherwise translate the Software Product, except and
    only to the extent that such activity is expressly permitted by
    applicable law notwithstanding this limitation. If this Software
    Product is labeled "Evaluation Copy," "Not For Resale," "NFR" or to
    any of those effects, this license only permits use for
    demonstration, test, or evaluation purposes.

    2. COPYRIGHT. The Software Product is licensed, not sold. All right, title
    and interest in the Software Product (including any images, "applets,"
    photographs, animations, video, audio, music, and text incorporated into the
    Software Product), accompanying printed materials, and any copies you are
    permitted to make herein, are owned by Network Associates, Inc. and its
    affiliated companies or its suppliers, and the Software Product is protected by
    United States copyright laws and international treaty provisions. Therefore,
    you must treat the Software Product like any other copyrighted material (e.g., a
    book or musical recording) except that you may either (a) make one copy of the
    Software Product solely for backup or archival purposes or (b) transfer the
    Software Product to a single hard disk, provided you keep the original solely
    for backup or archival purposes. Such copy shall include Network Associates'
    copyright and other proprietary notices. You may not copy the printed materials
    accompanying the Software Product.

    3. U.S. GOVERNMENT RESTRICTED RIGHTS LEGEND. The Software Product and
    documentation are provided to the U.S. Government with RESTRICTED RIGHTS. The
    U.S. Government acknowledges Network Associates' representation that the
    Software is "commercial computer software" as that term is defined in 48 C.F.R.
    12.212 of the Federal Acquisition Regulations ("FAR") and is "Commercial
    Computer Software" as that term is defined in 48 C.F.R. 227.7014 (a)(i) of the
    Department of Defense Federal Acquisition Regulation Supplement ("DFARS"). Use,
    duplication or disclosure by the U.S. Government is subject to restrictions set
    forth in subparagraphs (a) through (d) of the Commercial Computer-Restricted
    Rights clause at FAR 52.227-19 when applicable, or in subparagraph (c)(1)(ii) of
    the Rights in Technical Data and Computer Software clause at DFARS 252.227-7013,
    or at 252.211-7015, or to this commercial license, as applicable, and in similar
    clauses in the NASA FAR Supplement, as applicable. Contractor/manufacturer is
    Network Associates, Inc. 2805 Bowers Avenue, Santa Clara, CA 95051-0963.

    4. EXPORT LAW. Export of the Software Product may be subject to compliance
    with the rules and regulations promulgated from time to time by the Bureau of
    Export Administration, United States Department of Commerce, which restrict the
    export and re-export of certain products and technical data. If the export of
    the Software Product is controlled under such rules and regulations, then the
    Software shall not be exported or re-exported, directly or indirectly, (a)
    without all export or re-export licenses and governmental approvals required by
    any applicable laws, or (b) in violation of any applicable prohibition against
    the export or re-export of any part of the Software.

    5. TERMINATION. This Agreement will immediately and automatically terminate
    without notice if you fail to comply with any term or condition of this
    Agreement. You agree upon termination to promptly destroy the Software Product
    together with all of its component parts, prior and replacement versions, and
    all copies, modifications and merged portions thereof in any form.

    6. LIMITED WARRANTY.

    a. Limited Warranty. Network Associates warrants that the Software Product
    will perform substantially in accordance with the accompanying written materials
    for a period of sixty (60) days from the date of original purchase. To the
    extent allowed by applicable law, implied warranties on the Software Product, if
    any, are limited to such sixty (60) day period. Some jurisdictions do not allow
    limitations on duration of an implied warranty, so the above limitation may not
    apply to you.

    b. Customer Remedies. Network Associates' and its suppliers' entire
    liability and your exclusive remedy shall be, at Network Associates' option,
    either (a) return of the purchase price paid for the license, if any or (b)
    repair or replacement of the Software Product that does not meet Network
    Associates' limited warranty and which is returned at your expense to Network
    Associates with a copy of your receipt. This limited warranty is void if
    failure of the Software Product has resulted from accident, abuse, or
    misapplication. Any repaired or replacement Software Product will be warranted
    for the remainder of the original warranty period or thirty (30) days, whichever
    is longer. Outside the United States, neither these remedies nor any product
    support services offered by Network Associates are available without proof of
    purchase from an authorized international source and may not be available from
    Network Associates to the extent they are subject to restrictions under U.S. export
    control laws and regulations.

    c. NO OTHER WARRANTIES. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW,
    AND EXCEPT FOR THE LIMITED WARRANTIES SET FORTH HEREIN, THE SOFTWARE AND
    DOCUMENTATION ARE PROVIDED "AS IS" AND NETWORK ASSOCIATES AND ITS SUPPLIERS
    DISCLAIM ALL OTHER WARRANTIES AND CONDITIONS, EITHER EXPRESS OR IMPLIED,
    INCLUDING, BUT NOT LIMITED TO, IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS
    FOR A PARTICULAR PURPOSE, CONFORMANCE WITH DESCRIPTION, TITLE AND NON-
    INFRINGEMENT OF THIRD PARTY RIGHTS, AND THE PROVISION OF OR FAILURE TO PROVIDE
    SUPPORT SERVICES. THIS LIMITED WARRANTY GIVES YOU SPECIFIC LEGAL RIGHTS. YOU
    MAY HAVE OTHERS, WHICH VARY FROM JURISDICTION TO JURISDICTION.

    d. LIMITATION OF LIABILITY. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE
    LAW, IN NO EVENT SHALL NETWORK ASSOCIATES OR ITS SUPPLIERS BE LIABLE FOR ANY
    INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL OR EXEMPLARY DAMAGES OR LOST
    PROFITS WHATSOEVER (INCLUDING, WITHOUT LIMITATION, DAMAGES FOR LOSS OF BUSINESS
    PROFITS, BUSINESS INTERRUPTION, LOSS OF BUSINESS INFORMATION, OR ANY OTHER
    PECUNIARY LOSS) ARISING OUT OF THE USE OR INABILITY TO USE THE SOFTWARE PRODUCT
    OR THE FAILURE TO PROVIDE SUPPORT SERVICES, EVEN IF NETWORK ASSOCIATES HAS BEEN
    ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. IN ANY CASE, NETWORK ASSOCIATES'
    CUMULATIVE AND ENTIRE LIABILITY TO YOU OR ANY OTHER PARTY FOR ANY LOSS OR
    DAMAGES RESULTING FROM ANY CLAIMS, DEMANDS OR ACTIONS ARISING OUT OF OR RELATING
    TO THIS AGREEMENT SHALL NOT EXCEED THE PURCHASE PRICE PAID FOR THIS LICENSE.
    BECAUSE SOME JURISDICTIONS DO NOT ALLOW THE EXCLUSION OR LIMITATION OF
    LIABILITY, THE ABOVE LIMITATIONS MAY NOT APPLY TO YOU.

    7. GENERAL . These terms and conditions may not be modified, amended,
    canceled or in any way altered, nor may they be modified by custom and usage of
    trade or course of dealing, except by an instrument in writing and signed by a
    duly authorized officer of Network Associates. THESE TERMS AND CONDITIONS SHALL
    BE CONSTRUED AND ENFORCED IN ACCORDANCE WITH THE LAWS OF THE STATE OF
    CALIFORNIA, UNITED STATES OF AMERICA. Any action or proceeding brought by anyone
    arising out of or related to these terms and conditions shall be brought only in
    a state or federal court of competent jurisdiction located in the county of
    Santa Clara, California, and the parties hereby consent to the jurisdiction and
    venue of said courts. Should any term of these terms and conditions be declared
    void or unenforceable by any court of competent jurisdiction, such declaration
    shall have no effect on the remaining terms hereof. These terms and conditions
    are in the English language, and only the English language version hereof,
    regardless of the existence of other language translations of these terms and
    conditions, shall be controlling in all respects. The failure of either party to
    enforce any rights granted hereunder or to take action against the other party
    in the event of any breach hereunder shall not be deemed a waiver by that party
    as to subsequent enforcement of rights or subsequent actions in the event of
    future breaches. Network Associates reserves the right at any time without
    liability or prior notice to change the features or characteristics of this
    Software Product, or its documentation and related materials, or future versions
    thereof. These terms and conditions constitute the complete and exclusive
    statement of the agreement between us which supersedes any proposal or prior
    agreement, oral or written, and any other communication between us relating to
    the subject matter of these terms and conditions.

    Copyright (c) 1990-1998 Network Associates, Inc. and its affiliated companies. All
    rights reserved. PGP and Pretty Good Privacy are registered trademarks of
    Network Associates, Inc. and its affiliated companies. The Software Product may
    use public key algorithms described in U.S. patent numbers 4,200,770, 4,218,582,
    4,405,829, and 4,424,414, licensed exclusively by Public Key Partners; the
    IDEA(tm) cryptographic cipher described in U.S. patent number 5,214,703,
    licensed from Ascom Tech AG; and the Northern Telecom Ltd., CAST Encryption
    Algorithm, licensed from Northern Telecom, Ltd. IDEA is a trademark of Ascom
    Tech AG. The Software Product may also include any of the following; compression
    code which is provided by Mark Adler and Jean-loup Gailly, used with permission
    from the free Info-ZIP implementation; LDAP software which is provided courtesy
    University of Michigan at Ann Arbor, Copyright (c) 1992-1996 Regents of the
    University of Michigan, All rights reserved; DB 2.0 software which is Copyright
    (c) 1990, 1993, 1994, 1995, 1996, 1997 Sleepycat Software, Inc., All rights
    reserved; software developed by the Apache Group for use in the Apache HTTP
    server project (http://www.apache.org/), Copyright (c) 1995-1997 The Apache
    Group, All rights reserved. Network Associates, Inc. and its affiliated
    companies may have patents and/or pending patent applications covering subject
    matter in this software or its documentation; the furnishing of this software or
    documentation does not give you any license to these patents. Note: Some
    countries have laws and regulations regarding the use and export of cryptography
    products; please consult your local government authority for details. Should you
    have any questions concerning these terms and conditions, or if you desire to
    contact Network Associates, Inc. for any reason, please write: Network
    Associates, Inc. Customer Service, 2805 Bowers Avenue, Santa Clara, CA 95051-
    0963. http://www.nai.com.

  68. Re:It's the same with toothpaste by Anonymous Coward · · Score: 1, Insightful

    I found that by relying on proprietary toothpaste products I'm becoming too relient on Procter and Gamble proprietary Crest brand toothpaste. If they and their IP lawyers decide not to provide the proprietary tooth polishing product to me or the population at large, we might have to switch to another product. It's a vicious cycle.

    So many people like you focus on the 'problem' of proprietary software. It's bullshit. The problem is corporate behavior and governmental collusion. Individuals are now officially meaningless. The choice has become anarchy or communism. The GNU generation has choosen communism. I'm hoping for a little anarchy.

  69. Must have been Slashdotted, fine now... by aquarian · · Score: 2

    I just downloaded now, no problem...

  70. it's about time by Anonymous Coward · · Score: 0

    we gave PGP up anyway... and embraced GPG! one of the problems with commercial software is that it can be taken away... try that with GPG.

  71. Licensed to terminat by Slashamatic · · Score: 1

    It is an interesting issue because if licensed software can be terminated so easily, how can it be treated as an asset on the balance sheet? It is always a risk that support could be withdrawn, but if the right to use can also be be taken away, it kind of makes a good argument for Open Source software, particularly those licenses which are irrevokable.

  72. Bwaaahahahaha! That's a good one! by NFW · · Score: 1
    But, just in case it wasn't entirely rhetorical:

    Corporations will learn that leasson when huge numbers of people stop forking over huge amounts of money for Microsoft's products.

    The Peru situation is pretty cool, but I'm still not holding my breath.

    --
    Build stuff. Stuff that walks, stuff that rolls, whatever.
  73. Yeeee-haaaa! by Anonymous Coward · · Score: 0

    Good old fashioned flamewar!

  74. /.'ed no, DMCA'd yes by ImaLamer · · Score: 2
    http://crypto.radiusnet.net/archive/pgp/
    Date: Thu, 9 May 2002 13:01:40 -0500
    From: Peter_Beruk@NAI.com
    To: root@radiusnet.net, webmaster@radiusnet.net
    Subject: Network Associates, Inc. DMCA Notice

    [ The following text is in the "iso-8859-1" character set. ]
    [ Your display is set for the "US-ASCII" character set. ]
    [ Some characters may be displayed incorrectly. ]

    DMCA NOTICE OF INFRINGING MATERIAL

    Via Email: root@radiusnet.net; webmaster@radiusnet.net;
    Re: Digital Millennium Copyright Act Notice
    Dear Radiusnet.net
    I am writing on behalf of Networks Associates, Inc. and its affiliated
    companies (collectively, "Network Associates"). As you may know, Network
    Associates is a leading provider of computer software for network security
    and management. Among its business units are such well-known names as
    McAfee, PGP Security, Sniffer Technologies, and Magic Solutions.
    We have learned that Radiusnet.Net is providing access on its system or
    network to material that infringes the copyrighted work of Network
    Associates. In particular, I refer you to the web pages located at
    http://crypto.radiusnet.net/archive/pgp which contains links from your site
    that provide unauthorized copies of NAI proprietary materials, including
    software. The material on this web site infringes Network Associates'
    valuable copyrights.
    Accordingly, Network Associates requests that Radiusnet.Net immediately
    remove or disable access to this infringing material. You should know that
    Network Associates takes its intellectual property rights seriously. By
    bringing this matter to your attention, we hope that Radiusnet.Net will act
    promptly to remedy this problem.
    We have a good faith belief that use of the material described above is not
    authorized by Network Associates, any of its agents, or the law. To the
    best of our knowledge, the information contained in this notification is
    accurate.
    Under penalty of perjury, I am authorized to act on behalf of Network
    Associates. If you have any questions or concerns, please contact me at the
    address listed above. You can also reach me by e-mail at
    peter_beruk@nai.com or by phone at +1 301-947-7150.
    Thank you for your anticipated cooperation.
    Sincerely,

    Peter Beruk
    Director, Anti-Piracy Programs

    Peter Beruk
    Director, Anti-Piracy Programs
    Network Associates, Inc.
    Phone: +1.301.947.7150
    Fax: +1.301.527.0482
  75. Sylpheed has gpg support also by Anonymous Coward · · Score: 0

    Sylpheed is the most underrated mail client.

  76. symptoms my friends, symptoms ! by Anonymous Coward · · Score: 0

    boys and girls, ladies and gents,

    watch closely... as your freedom to exercise your freedoms is taken away from you, without your consent, by inadequately prepared and well-compensated legislators.

    Slashdotters are here discussing the symptoms and offering an opinion regarding the symptoms...lets talk about the CAUSE !

    The DMCA is legislation that effectively strikes out at the creative foundations of our country. Like so much legislation preceeding it, the DMCA's creators have kneeled before the corporate dollar.

    Who benefits from killing off curiosity ?
    Who benefits from killing off free speech ?
    Why the hell is a guy in jail for talking about some lousy EBook encryption, that is just really sad and morally wrong.
    Books ARE meant to be read, right ?

    I ask you these simple questions?

    I offer you one explanation,
    follow the almighty buck.

    (its right about now that we will all be arrested for removing the tab from our mattress)

  77. Re:PGP For UNIX 5.0.2 Retail License Agreement (lo by grahamm · · Score: 1

    I note that under termination the only criteria is breaking the agreement. It does not say that NAI have the right to unilaterally revoke the licence without "just cause".

  78. Re:It's the same with toothpaste by Anonymous Coward · · Score: 0

    I'm hoping for a little anarchy.

    Kid, go sit with the l337 w4rez d00d5 and script kiddies over there, quit annoying me.
    There's your bloody anarchy.

  79. Re: Hm by rutherford · · Score: 2, Informative

    There are already many good Windows programs for GnuPG. Look at the fine WinPT program which let you encrypt texts with every mail program available. Not as comfortable as a build in program but still easy to use. For key management you can use GPA. In Germany there is already a project which combines all these programs in one windows installable program with a very good documentation: GnuPP. There is also a plugin for Outlook available (not Express).

  80. PGP 6.5.8 CKT is still up with Source by tandoor · · Score: 3, Informative

    Imad's PGP Page

    He's been updating the latest source release of PGP (6.5.8), adding features, and fixing bugs. The latest solid release if Build 08

    Imad is based in Lebanon (so you can guess what he thinks of US IP Lawyers' threats)

    1. Re:PGP 6.5.8 CKT is still up with Source by Anonymous Coward · · Score: 0

      Is he a terrorist? Sure sounds like it!

    2. Re:PGP 6.5.8 CKT is still up with Source by tandoor · · Score: 1


      1. Encourages use hacked PGP which supports longer key lengths making it even harder for NSA to listen in.

      2. Based in Lebanon, one of those axis of terror countries if I ever heard of one.

      Yee-Haw - Sure sounds like one of those terrorist rag heads to me!

  81. NAI employee thoughts by Anonymous Coward · · Score: 0
    I work at NAI and this sort of thing pisses me right off. In the unlikely event that anyone from management reads this, ARGGGHHHHH!!!!!!

    It's largely irrelevant what's actually happened (although on first pass the story looks accurate) - the perception is terrible. It's alienating customers (tomorrow's potential customers in particular) and pissing of those of us with clue - you know, the technical people who actually develop products rather than powerpoint slides. It's going to make it harder to recruit good tech people, and may well push people into leaving (especially now the stock has tanked thanks to the revelations from the SEC investigation.) The product is not even being developed internally any more, and the PHBs seem to have given up looking for a buyer. Would it have killed you to open source it, or even put it in the public domain? No, it would have lead to a lot of goodwill and appreciation in the user community and the type of people who hang on slashdot WHO - of course - are OUR CUSTOMERS .


    *sigh*. Management. Can't live with 'em: pass the beer nuts.

    1. Re:NAI employee thoughts by Anonymous Coward · · Score: 0

      so that means you are gonna post the public IP of the NAI FTP server, all ISO files right ?

      * begins laughing in a menacing tone *

  82. Not their intelectual property by Senjaz · · Score: 1

    How can Network Associates enforce this? Public key cryptograph was discovered/invented at Bletchley Park, UK for our government use before it was independantly proposed in the US.

    Isn't there something about prior art with these things?

    --
    Don't blame me - this .sig had steal me written all over it.
  83. gpg by Anonymous Coward · · Score: 0

    I've never used PGP myself. Just use GNU Privacy Guard and you'll not have not handle with these sorts of problems.

  84. backward OS by Erris · · Score: 2
    OS backward compatibility usually takes care of this, especially for such simple command line utilities. I have tools last compiled a decade ago.

    Oops, Linux don't do that.

    It's very difficult to maintain compatibility with a backward OS, just ask the folks at Wine. =:>

    The original poster is correct about things shifting under PGP. If you have not noticed, M$ is killing netscape style pulgins. This is only one example, many other things shift under M$. Have you seen M$?s new ASCII? Ever been frustrated when a print method shifted, forcing you to cut and paste your old program's output to some new piece of shit to print? Ever had a Printman that did not include ASCII box characters so that text art was broken? These are subtle ways of breaking old tools. You should expect more overt measures in the future from a company who's web sites refuse entry based on user-agent not Internet Exploder.

    Also, you are a troll about old aplications not running. Debian has a an old libraries package that prommises to take care of problems. I would not know, because I've never had a problem like that.

    Most "simple" utilities can be written as scripts that conform to standards for shells much older than 10 year old Linux. Awk, sed, cp, mv, how long have these names been around doing what they always do? Why bother to compile something that just calls reasonable tools for you? I suppose you could compile simple utilities like that if you 1)Don't have many tools so you can remember exaclty what they do without looking at the source, 2)Don't care to ever change what that utility does or how. Strangly enough, the only place that might be true is in an environment that lacks useful utilities to begin with, forcing you to compile substitutes of your own that can't be ported. Backward Compatible is right on target there.

    --
    DMCA, Hollings, Palladium. What might have sounded like paranoia is now common sense.
  85. Easy-to-use interface is already here: GnuPP by Cyberstar · · Score: 1

    If you miss an easy-to-use interface, you haven't tried the Gnu Privacy Project.

    It is an easy to use bundle which consists of GnuPG, GPA and WinPT all installed with one exe.

    Project homepage: http://www.gnupp.org/
    Download: http://www.gnupp.de/download/gnupp-1.1-en-installe r.exe

    - Cyberstar

  86. Is it possible... by ms-schadenfreude · · Score: 1

    for the open-source movement to use the DMCA against some of these corporations that currently use it for evil? Fight fire with fire!

    1. Re:Is it possible... by Anonymous Coward · · Score: 0

      Only if they violate the terms of the license under which the software is distributed. There are really only two obvious ways to violate the GPL. One is to distribute a modified version in binary form and refuse to GPL your changes or provide the source. If you redistribute in binary form without changes, you can point people to where you got the source from. The other is to attempt to redistribute under another license.

  87. Encryption as a Basic Right by raahul_da_man · · Score: 2, Insightful

    It's about time that encryption was recognised as a tool to keep governments from spying on private citizens. The idea is that Goverment should have the power to spy on its citizens, but not that is should spend all of its time and resources doing so.

    1. Re:Encryption as a Basic Right by meringuoid · · Score: 1

      It's about time that encryption was recognised as a tool to keep governments from spying on private citizens.

      Well, how about this...

      1) Phil Zimmermann releases PGP.
      2) US Government tries to stop him on the grounds that this counts as exporting weapons.

      Therefore

      3) The US Government says that PGP is classed as a weapon.

      Now

      4) US citizens have a right under the Constitution to bear arms

      So

      5) US citizens have a right under the Constitution to use strong encryption

      --
      Real Daleks don't climb stairs - they level the building.
  88. It depends......... by Anonymous Coward · · Score: 0

    Did the dog circumvent your fence?

  89. anyone check out Network Assoc.'s site?! by Drunken_Jackass · · Score: 1

    'Cause i did.

    "Network Associates recently announced the closure of PGP Security business unit"

    From pgp.com

    Yeah, their poised to take over the PGP world.

    --
    There are 01 types of people in this world. Those that understand binary, and me.
  90. Commercial Customer like Lockheed by Anonymous Coward · · Score: 0

    I'm a former Lockheed Martin Employee, and well we used PGP when dealing with secure mail, in fact there is an entire infrastructure, I know they we're switching to PKI, I guess that pushes it up. Any Comments?

  91. Don't buy anything by Anonymous Coward · · Score: 0

    "You have a weak mind if you buy that quote"

    He didn't. He got it for free. Just as was intended.

    Although you seem to like going along with the crowd, eh, herr doktur?

  92. /dev/random isn't where you get it. by dmaxwell · · Score: 2

    I don't have anything to say at the moment about the larger issues being debated in this thread but I do have something to say about random number sources. If I wanted to fill a CD with good random numbers /dev/urandom is not how I would go about it. The quality of /dev/urandom is reasonable as uses bits of fluff like the delay between keypresses and chatter from the device drivers to create an "entropy pool" to seed a pseudorandom algorithm with. The problem is that it is slooooowwww. Most goings on in a normal desktop PC are very very ordered and deterministic. The few that aren't represent a very small amount of entropy.

    All of this means that the process that is generating your iso is going to see short bursts of data inbetween long periods of entropy gathering. That CD will probably take hours at least to generate. Also I said the quality of the data is "reasonable". If one means to keep the government or a well heeled corporate attacker out of the cyphertext it may not be good enough. Even the non-deterministic processes in a PC likely have a fair amount of order in them. In other words, that entropy pool is probably good enough to make a 2048 bit assymetric key. It probably wouldn't do for a 650MB iso. The longer the string of numbers, the more likely hidden order can be found.

    The way I would is to sample the output of a white noise generator. The output of the ADC is then used to seed a good pseudorandom algorithm. The reason why we use the white noise as a seed is to obliterate any bias in the data caused by such factors as the slew rate, bandpass of the analog circuitry making the white noise or any subtle imperfection that may exist in the ADC. A reverse biased transistor is one source of analog noise. This would be a high speed generator of quality random numbers. The speed would only be limited by the clock rate of the ADC or rate at which the PC can process the output.

  93. DMCA explained by Anonymous Coward · · Score: 0

    The DMCA is simple really... it means: "Do your Mom's Cunt and Ass"

  94. 2.6.3i by Anonymous Coward · · Score: 0

    I don't know if it has any of the vulnerabilities of later versions, but I don't think it does, and it is a source distribution.

    More people should mirror this source distribution, or just start using, and developing GnuPG.

    If you say there aren't any good plug-ins or gui's for windows, well, develop them. Most people here don't use windows, and even those that do probably don't find it to hard to integrate what is already there with GnuPG.

    This is a short coming of Open Source development that maybe you can address. The technically minded people that develop open source tend to find work arounds, and leave it at that, or know and understand the *nix mentality of small tools linked together, and use that philosophy.

    This isn't good enough for the average user, and if you think you know what the average user really wants, then take a swing, make a following for yourself.

  95. NAI doesn't own the full rights to PGP by Anonymous Coward · · Score: 0
    Since everyone seems to have forgotten, I'll put in the reminder here. Last I heard, NAI didn't own the full rights to PGP.

    Phil Z. split the rights to PGP with the guy who was responsible for putting the PGP effort together, and for releasing the code. That guy never relinquished his rights, last I heard.

    So at the most, NAI owns Phil's half of the code, and doesn't have full authority to limit the publication of PGP.

  96. Nonsense by Anonymous Coward · · Score: 0

    Here is a GPG plug-in for Outlook. This plugin is so good and so easy, you will actually consider using Outlook as your mail client.

    It will even install GPG for you if you don't already have it.

  97. They have an English version, as well by Anonymous Coward · · Score: 0

    gnupp.com is the same site in English.

  98. MIT? by Anonymous Coward · · Score: 0

    Will linux run on PGP from MIT or is it too old?

  99. Re:PGP For UNIX 5.0.2 Retail License Agreement (lo by Anonymous Coward · · Score: 0

    Oh, but it does...

    "7. GENERAL . These terms and conditions may not be modified, amended, canceled or in any way altered, nor may they be modified by custom and usage of trade or course of dealing, except by an instrument in writing and signed by a duly authorized officer of Network Associates. "

  100. Read you PO by MountainLogic · · Score: 2
    1. GRANT OF LICENSE. [snip]... If this Software Product was purchased in some other manner than as a retail product, the license may have a term commencing on the Delivery Date of a Product and continuing for an extended period of time as otherwise ndicated in your purchase order or as set forth in a separate and complementing Software License Agreement to which this End User License agreement is subject to. [emphasis mine]

    If you write a PO that says you want only a three year license you get what you pay for.

  101. A better reason to switch to GnuPG by return+42 · · Score: 2

    NAI no longer publishes their source code. Backdoors? "Trust us", they say. "Fuck that", I say.

  102. Not quite. by mindstrm · · Score: 2

    NAI killed the PGP line of their products because it wasn't making any money.

    The government did not object to PGP being released; they objected to PGP being exported, and zimmerman got shit for it, and although it's unfortunate, he WAS in violation of federal export control laws regarding munitions. Yes, those laws were rediculous and unenforceable, but they pre-dated pgp by quite a number of years.

    NAI's pgp for windows is excellent. The eudora plugin works almost perfectly (automatic decryption seems to not work at all for me.. anyone know about this?). It has good keyserver and key management functions, and supports x.509 certificates as well.

  103. Re:NAI - Graduates of the Verisign School of Busin by Marcos+the+Jackle · · Score: 0

    That's exactly right, asshole! I guess you have a problem with some people making a living. Seems like you subscribe to the RMS/Karl Marx school of thought...

    Kill yourself.

  104. Re:careful if you use wget for your websurfing nee by Anonymous Coward · · Score: 0
    > Maybe it's unethical for you, but you're not authorative of ethics. Nobody is.

    Postulate that there is a God, who created the universe. Would he be ``authorative of ethics''? Can you prove that there is no such God?

  105. Re:It's the same with toothpaste by Anonymous Coward · · Score: 0

    Proprietary software is a problem because there is so much room for abuse ALONG with the technical disadvantage of not being able to modify the software if needed. Corporate behavior is not going to go away any time soon so don't think you'll solve the problem there. Get rid of M$ and another will take their place.

    btw, GNU has absolutely nothing to do with communism. If you believe that, you either have no idea what communism is or are confused on the nature of the GPL license. Communist economies have centralized dictatorial control. GNU is decentralized and uncontrolled. You may disagree with RMS all you like, but the fact is, he has no power whatsoever.

  106. How does your ultra-obscurity go with usability? by smcv · · Score: 1

    > > Umm, call me crazy but I think that one-time-pads are a form of secret-key symmetric cipher.

    > You're right of course, I've gotten in the habit of regarding one-time pads as being in a class of their own. Something about their being the only kind of crypto that will survive quantum computing.

    Alice takes some plain text and a key (which happens to be as long as the plain text and taken from the next however many bytes of her one-time pad), feeds the key and the text to some agreed algorithm (which happens to be XOR), and sends the resulting ciphertext to Bob.
    Bob takes the same key Alice used (which happens to be the same number of bytes from a matching one-time pad) and Alice's ciphertext, feeds the key and the ciphertext to some other agreed algorithm (which happens to be XOR), and gets Alice's plain text out.

    Sounds suspiciously symmetric to me; you just happen to be using the next however many digits of your one-time pad rather than picking a key yourself.

    -=-=-=-=-=-

    In OpenPGP, the hypothetical cryptoanalyst trying to read your message does know which algorithm you used. How? Because you told them in the header.

    If the message doesn't, in some way, include the algorithm, your recipient will have to specify which algorithm you used.

    Now: Click on e-mail, enter passphrase, wait, read decrypted message

    Your idea: Click on e-mail, get a window asking you for the algorithm, select 3DES with some key followed by ROT13 followed by XOR with some key followed by cyclic shift left by 47 bits followed by ElGamal followed by XOR with DeCSS source code followed by RSA, enter 3DES, XOR, ElGamal and RSA keys, wait quite a while, read decrypted message. I think collecting the encrypted mail and feeding it to GnuPG/Ciphersabre/<your one-time-pad program here> manually is probably easier.

    Not happy with that sort of usability? OK, how about entering a key, and waiting for your computer to run through all the available algorithms trying to decrypt the message with that algorithm/key pair? I don't want to have to (partially) brute-force crack my own mail :-)

    Taking your idea to its logical conclusion, I can construct an unbreakable encrypted message using a simple algorithm involving "dd if=/dev/random" (or rand() for entropy-impaired OSs). It's a pity the recipient can't decrypt it either.

    It's not as if you're necessarily gaining anything - chaining together multiple encryption steps doesn't necessarily make anything more secure (triple ROT-13 is only as secure as ROT-13, quadruple ROT-13 is less secure :-)

    Come to think of it, how are you going to get people using your arbitrarily complex encryption if they know "the enemy" can decrypt their messages? You seem to be relying on weight of data to make it unlikely that "the enemy" decrypt your particular message, but if your scheme isn't popular, it'll be quite likely. Even if it is popular, from how you seem to want it to work, anyone who's specifically out to get you can get at your particular messages pretty easily; so in fact, your idea would only work against an organisation that wanted to spy on everyone ::cough.govcough::, and would be pretty useless against someone who knew who you were and that you were their target.

  107. Godwin's Law! by Anonymous Coward · · Score: 0

    You LOSE!

  108. Re:How does your ultra-obscurity go with usability by corebreech · · Score: 2

    Yes, the recipient would have to know how you've encrypted the message, and if that information is included in the header it makes the scheme worthless. The encryption being used would have to be agreed upon out-of-band. I don't see that as being as onerous as everybody thinks it will be. It's nice that there is a way to encrypt messages to people you've never met, but I have no need to communicate securely with people I don't know.

    When I want to send information securely, it is to somebody I know, who've I've met, who I talk to over the phone, etc. Maybe it's source code, contract negotiations, sweet nothings in her ear.

    It seems to me that we are losing a lot by buying into only a few algorithms. We're putting all our eggs in one basket, so to speak. If these ciphers are breakable, then we're allowing the NSA to automate all of their cryptoanalysis!

    I disagree that this would have to be popular in order to be effective. Or, maybe it depends on what you mean by popular. If the ability is widespread and some number -- even if it is only in the hundreds say -- are using the software, then the NSA has to code for it, right?

    A lot of things have to be done right. The software has to have a very easy-to-use interface that generates the algorithm. This algorithm then has to be representable as a number that can then be communicated to the desired addressee who then can enter that number into her system and associate it with email coming from you.

    Again, the algorithm being used here can sit atop something more robust, like triple-DES, so it wouldn't be easy to crack at all, or at least, no easier than cracking triple-DES, so there is a security factor that can be advertised here... noone need shy away from this approach because it isn't strong.

    What we're doing now is giving the NSA a very focused point of attack. By getting everybody to use as many different encryption standards as possible, we promote the demise of Echelon-like activities.

    Think of obscurity as something that sucks for an individual application, but which scales really really well. After a certain point, it becomes overwhelming. Yes, the NSA will still be able to target specific messages, but this business with sweeping through everybody's traffic in due course is effectively finished.

  109. Re:careful if you use wget for your websurfing nee by kubrick · · Score: 1

    No, ethics are an individual thing. Morals are ethics imposed on others. :)

    But if people are spending money to provide a resource to me, I feel that it's only ethical to repsect their wishes about how I would access it.

    I don't expect all other people to feel that way, but I wanted to flag that I did.

    --
    deus does not exist but if he does
  110. Lawyer: NO!!! by hawk · · Score: 2
    I am a lawyer, but this is not legal advice. If you need that, then go pay for it!



    > To try is to never gain a "meeting of the minds", an absolute pre-requisite to contracts.


    NO! The "meeting of the minds" is frequently repeated by many, including some lawyers and some textbooks, but it's just plain WRONG.


    The standard is objective, not subjective. The validity of the contract is determined *entirely* from the provable circumstances, not what anyone thought they were doing.


    Also, as long as I'm at it, boilerplate statements that the boilerplate can't be changed, and written contracts that prohibit oral modifications, range from tricky to flat out invalid. The oral change to the contract changes and sets aside the no oral changes rule . . . "no unauthorized person may change" isn't overrriden by a purported change by an unauthorized person, but there might not be an offer and acceptance (the actual rule), or the contract may be other than intended . . .


    hawk, esq

  111. No PGPi after version 5. by someone247356 · · Score: 1

    Since the ITAR (or is it the commerce department now) regs changed so that people didn't have to scan in the source code to PGP overseas there hasn't been an "i" version. PGP Freeware is available globally as PGP 6.5.3, PGP 6.5.8, PGP 7.0.3. (http://www.pgpi.org/products/pgp/versions/freewar e/win2k/)

    Since NAI stopped publishing the complete source code for the latest versions, and then Phil left, I'm not sure how far I would trust the later versions.

    Now I'm not saying that he wasn't distributing the non-free versions, but just because someone is posting a late non-"i" version doesn't necessarily mean that it's not the free version.

    --
    Just my $0.02 (Canadian, before taxes)