Slashdot Mirror


Command-Line Crypto From Phil Zimmermann, Again

A few months ago, PGP creator Phil Zimmermann became a reseller for the current graphical version of the software he originally spawned, produced by PGP Corporation. Now, Zimmermann has just started selling through his own website a modern command-line encryption product called FileCrypt, which has its roots in an older version of PGP. Confusingly enough, this software is produced by a company called (Veridis), and doesn't say PGP on the box, because legally it can't. Network Associates, which acquired PGP Inc. in 1997, still holds the rights to that name; when NAI spun off PGP to PGP Corporation in 2002, they held onto the command-line version. PGP Corporation, for whom Zimmermann serves as a technical advisor (as well as a reseller), is contractually unable to sell a command-line version. (He is on the board of Veridis as well.) But why introduce a text-only version of utility software, anyway, when the GUI-fied desktop version has been maturing for years and costs less? Update: 02/07 23:07 GMT by T : Here are three instant clarifications: PGP Corporation was misrendered as "Open PGP" in this paragraph; Veridis' command line product was inspired by PGP but independently created; its codebase is separate from NAI's version of PGP; and the rights holder to the PGP name is PGP Corporation, not NAI.

They aren't paying for a pretty logo. The real reason is that the GUI version of PGP (along with other graphical encryption software, like the GNU Privacy Guard) aren't even in the same market.

Casual computer users have never laid out much money for encryption. The widespread use of PGP in its original incarnation (during the era of Zimmermann's prosecution for allowing it to be exported) can be attributed as much to its zero-dollars price as to a generalized interest in privacy. Home and hobby users are not cut out from buying Veridis's software -- for about a hundred dollars, you can buy a personal use version of the command-line version. The real money isn't in individuals keeping their tax records private, though -- Zimmermann and Veridis, like NAI (whose PGP-based product is called E-Business Server) are really aiming at commercial and governmental datacenters, and for customers willing to accept a much higher pricetag.

Insurance companies, banks, credit card processing centers, state records -- anywhere financial or otherwise confidential records are exchanged or stored en masse -- these all need encryption which works at the command-line. More precisely, they need crypto software which can work without direct human intervention at all. Instead, massive data centers need tools which can be called by scripts and other programs, so servers, or server farms, can spend their time crunching numbers rather than drawing pictures.

The name is familiar ... The commercial competition FileCrypt faces is familial -- it's the same product from NAI (sold from their McAffee division) that prevents Zimmermann and Veridis from calling their software PGP, even though NAI now labels their product E-Business Server. And though many companies have homegrown cryptographic solutions, Zimmermann says he knows of no other packaged software offering the high-volume encryption that the products from NAI or Veridis do.

And, he emphasizes, what they do is very similar. He says of the Veridis command-line product compared to NAI's, "It's drop-in compatible, identical in operation ... you could run the same perl scripts, the same command-line arguments."

If you want to buy Veridis' encryption software licensed for electronic commerce (not one-person use), hold onto your wallet: the price jumps about 50 times, to a shade under $5000, which Zimmermann describes as a bargain -- at least compared to the competition.

(Prices on the McAfee website show a one-year subscription-based license for E-Business Server starting at $6,875; $14,375 buys a perpetual license, with no included support.)

Both sides of that fence. And of competing in this case with a product that originated from his own crypto software (and his own company, PGP Inc.), Zimmermann says "I just don't really think of that as my product any more. It's in the hands of NAI, all the engineers have been fired. I just don't feel psychologically connected to that product." To look and not to sell. Especially when it comes to cryptographic software, code openness is considered not just a virtue but a near necessity. Peer-review and independent auditing, after all, are about the only ways you can tell that software isn't shuttling credit card numbers to the wrong person.

The business model of selling high-priced crypto software at thousands of dollars per processor doesn't mesh well with gratis software, though. To that end, Zimmermann says the FileCrypt code will be soon be available for download and inspection under terms which he says will be similar to those under which users can download the code for PGP Corporation's version of the PGP-based desktop software. (PGP Corporation's terms are available though their source code page).

9 of 165 comments (clear)

  1. ASCII pr0n by SUB7IME · · Score: 0, Funny

    Does this mean that I can now encrypt my ASCII pr0n?

  2. $^^#@#$@34fds#@$23$@# by mrtroy · · Score: 1, Funny

    im outside of the us and i just used it to encrypt "hah".( as per subject )

    --
    [I can picture a world without war, without hate. I can picture us attacking that world, because they'd never expect it]
  3. HOW COME AMERICA SLASHDOT NOT IMPORTANT THIS STORY by Anonymous Coward · · Score: 0, Funny


    Game " grapple superhuman
    " for Xbox in inadequate expression from entire world collection


    Contribution
    of the Saturday February 08, @03:44AM with the Oliver,
    Whether or not
    excessive reaction from section.



    It has been said the Sakura Avalon, " according
    to the GAME SPOT
    JAPAN NEWS article of the ZDNet Japan it became that Microsoft collects the
    game software " grapple superhuman " for the xbox at entire world levels so is.
    As for the reason thing because the inadequate expression for part religion is
    included.
    With the similar case, the weapon of front the Matsumoto zero
    loyal retainer of the original author offers the TV televising discontinuance
    from the fact that you have drawn in star type of the f_frff which is symbol of the
    judaism in the past captain * Ha - in the new work animation of the lock, there
    was also a kind of thing where after all the work becomes recreating. (
    Particular article )
    In addition conversely in category of fCf`ffff", it is
    used and in the fgfOEfJ of the f|fPff" as the sign of the temple and the temple it
    is symbol of little forest temple fist method, when " (TM)Â " it has been
    similar especially or the Hakenkreuz which probably will be, at the point where
    the American Judean human group makes a noise, if originally there was also a
    case, where the place where it is attached on smile even as for that fgfOEfJ becomes
    revision politely and old house exultaion. Furthermore as for the fgfOEfJ which has
    protest in Japanese edition, in America only those which the trader imports
    selfishly in parallel the fIf}fP being attached, it is not.
    Because especially
    it is not announced, being well not to understand, it does, the concrete primary
    factor of the latest grapple superhuman collection, but collecting, whether
    considerably from the fact that they are massive rock forcing ones which do not
    ship later, the core it is problem in the part, the êÜñ. Private the
    development company of the " To val No.1 "? The hand stopping at the Á Ä place,
    it was not bought, it is is, but even weekend per old house the combining which
    you will try searching -. "


  4. Smug by $$$$$exyGal · · Score: 3, Funny
    Pic of Zimmerman

    The look on his face is so smug, like, ha ha, "I have no such non-compete agreement with NAI", so I'm gonna screm 'em!

    --naked

    --
    Very popular slashdot journal for adul
  5. Drifting, drifting.... by airrage · · Score: 2, Funny

    "Confusingly enough, this software is produced by a company called (Veridis), and doesn't say PGP on the box, because legally it can't. Network Associates, which acquired PGP Inc. in 1997, still holds the rights to that name..."

    I'm sure PGP is important, but I can't remember what the acronym stands for --don't drift, don't drift off, focus buddy you can hang in there...

    "...when NAI spun off PGP to PGP Corporation in 2002, they held onto the command-line version. OpenPGP, for whom Zimmermann serves as a technical advisor (as well as a reseller),..."

    Almost five, it's about time to pack up and leave here, I wonder what's on TV tonight, probably nothing, Friday night blows. Need to get Road to Rome, but the flunky at Best Buy, who doesn't know his ass from a hole in the ground, said they're getting another shipment today, so probably need to go by there after work...maybe pick up mgs2 for xbox while I'm at it. mmmm xbox....

    "...is contractually unable to sell a command-line version. (He is on the board of Veridis as well.) But why introduce a text-only version of utility software, anyway, when the GUI-fied desktop version has been maturing for years and costs less?

    "actually, if I send Bill Lumberg my tps reports now .. maybe I can sneak out past Milton...

    --
    "This isn't a study in computer science, its a study in human behavior"
  6. Re:Advantage of command line... by Malc · · Score: 2, Funny

    Command line? This is Windows damnit! What we need first is a COM object interface distributed in a DLL. Then any application will have access to it with minimal fuss and piddling around ensuring the utitlity is on the commandline. For those who want a command line version, it will then be simple to add a console-based facade to the COM DLL.

  7. Re:Story, or advertisement? by hughk · · Score: 2, Funny
    Sounds like a publicity stunt to me, unfortunately they've tried it on the wrong crowd
    it got past the /. editors though didn't it!!!!!!
    --
    See my journal, I write things there
  8. Non-ssl-secured purchase form...??? by giantsquidmarks · · Score: 2, Funny

    The web form to purchase the product does not appear to be an ssl secured form...

    http://www.veridis.com/openpgp/en/buy2.asp

  9. Re:Automated jobs by Linux_ho · · Score: 2, Funny
    Like what?
    Exactly.
    --
    include $sig;
    1;