Catch up on stories from the past week (and beyond) at the Slashdot story archive

 



Forgot your password?
typodupeerror
×

Feed Techdirt: The World's Email Encryption Software Relies On One Guy, Who Is Going Broke (google.com)

The man who built the free email encryption software used by whistleblower Edward Snowden, as well as hundreds of thousands of journalists, dissidents and security-minded people around the world, is running out of money to keep his project alive.

Werner Koch wrote the software, known as Gnu Privacy Guard, in 1997, and since then has been almost single-handedly keeping it alive with patches and updates from his home in Erkrath, Germany. Now 53, he is running out of money and patience with being underfunded.

"I'm too idealistic," he told me in an interview at a hacker convention in Germany in December. "In early 2013 I was really about to give it all up and take a straight job." But then the Snowden news broke, and "I realized this was not the time to cancel."

Like many people who build security software, Koch believes that offering the underlying software code for free is the best way to demonstrate that there are no hidden backdoors in it giving access to spy agencies or others. However, this means that many important computer security tools are built and maintained by volunteers.

Now, more than a year after Snowden's revelations, Koch is still struggling to raise enough money to pay himself and to fulfill his dream of hiring a full-time programmer. He says he's made about $25,000 per year since 2001 — a fraction of what he could earn in private industry. In December, he launched a fundraising campaign that has garnered about $43,000 to date — far short of his goal of $137,000 — which would allow him to pay himself a decent salary and hire a full-time developer.

The fact that so much of the Internet's security software is underfunded is becoming increasingly problematic. Last year, in the wake of the Heartbleed bug, I wrote that while the U.S. spends more than $50 billion per year on spying and intelligence, pennies go to Internet security. The bug revealed that an encryption program used by everybody from Amazon to Twitter was maintained by just four programmers, only one of whom called it his full-time job. A group of tech companies stepped in to fund it.

Koch's code powers most of the popular email encryption programs GPGTools, Enigmail, and GPG4Win. "If there is one nightmare that we fear, then it's the fact that Werner Koch is no longer available," said Enigmail developer Nicolai Josuttis. "It's a shame that he is alone and that he has such a bad financial situation."

The programs are also underfunded. Enigmail is maintained by two developers in their spare time. Both have other full-time jobs. Enigmail's lead developer, Patrick Brunschwig, told me that Enigmail receives about $1,000 a year in donations — just enough to keep the website online.

GPGTools, which allows users to encrypt email from Apple Mail, announced in October that it would start charging users a small fee. The other popular program, GPG4Win, is run by Koch himself.

Email encryption first became available to the public in 1991, when Phil Zimmermann released a free program called Pretty Good Privacy, or PGP, on the Internet. Prior to that, powerful computer-enabled encryption was only available to the government and large companies that could pay licensing fees. The U.S. government subsequently investigated Zimmermann for violating arms trafficking laws because high-powered encryption was subject to export restrictions.

In 1997, Koch attended a talk by free software evangelist Richard Stallman, who was visiting Germany. Stallman urged the crowd to write their own version of PGP. "We can't export it, but if you write it, we can import it," he said.

Inspired, Koch decided to try. "I figured I can do it," he recalled. He had some time between consulting projects. Within a few months, he released an initial version of the software he called Gnu Privacy Guard, a play on PGP and an homage to Stallman's free Gnu operating system.

Koch's software was a hit even though it only ran on the Unix operating system. It was free, the underlying software code was open for developers to inspect and improve, and it wasn't subject to U.S. export restrictions.

Koch continued to work on GPG in between consulting projects until 1999, when the German government gave him a grant to make GPG compatible with the Microsoft Windows operating system. The money allowed him to hire a programmer to maintain the software while also building the Windows version, which became GPG4Win. This remains the primary free encryption program for Windows machines.

In 2005, Koch won another contract from the German government to support the development of another email encryption method. But in 2010, the funding ran out.

For almost two years, Koch continued to pay his programmer in the hope that he could find more funding. "But nothing came," Koch recalled. So, in August 2012, he had to let the programmer go. By summer 2013, Koch was himself ready to quit.

But after the Snowden news broke, Koch decided to launch a fundraising campaign. He set up an appeal at a crowdsourcing website, made t-shirts and stickers to give to donors, and advertised it on his website. In the end, he earned just $21,000.

The campaign gave Koch, who has an 8-year-old daughter and a wife who isn't working, some breathing room. But when I asked him what he will do when the current batch of money runs out, he shrugged and said he prefers not to think about it. "I'm very glad that there is money for the next three months," Koch said. "Really I am better at programming than this business stuff."

Related stories: For more coverage, read our previous reporting on the Heartbleed bug, how to encrypt what you can and a ranking of the best encryption tools.

Republished from ProPublica. ProPublica is a Pulitzer Prize-winning investigative newsroom. Sign up for their newsletter .



Permalink | Comments | Email This Story








Submission + - 'Star Wars: Episode VII' has a title: 'The Force Awakens' (ew.com)

schwit1 writes: If you feel a disturbance in the Force, it’s millions of voices suddenly crying out the new title of Star Wars: Episode VII — The Force Awakens. The reveal comes as the movie finishes its final day of shooting (with many more months of post-production to come.)

Although there were still a few days left of shooting, the cast of the J.J. Abrams film already celebrated their wrap party last weekend, following a bumpy few months of principal photography thrown into crisis when Han Solo himself, Harrison Ford, broke his leg on set in an accident involving a falling door on the Millennium Falcon.

Submission + - Ubuntu to switch to systemd (markshuttleworth.com)

GuerillaRadio writes: Following the decision for Debian to switch to the systemd init system, Ubuntu founder and SABDFL Mark Shuttleworth has posted a blog entry indicating that Ubuntu will now follow in this decision. "Nevertheless, the decision is for systemd, and given that Ubuntu is quite centrally a member of the Debian family, that’s a decision we support. I will ask members of the Ubuntu community to help to implement this decision efficiently, bringing systemd into both Debian and Ubuntu safely and expeditiously."

Submission + - CmdrTaco: Anti-Beta Movement a "Vocal Minority" (washingtonpost.com) 30

Antipater writes: The furor over Slashdot Beta is loud enough that even outside media has begun to notice. The Washington Post's tech blog The Switch has written a piece on the issue, and the anti-Beta protesters aren't going to be happy about it. The Post questioned Slashdot founder Rob Malda, who believes the protests are the work of only a vocal minority or readers: "It's easy to forget that the vocal population of a community driven site like Slashdot might be the most important group, but they are typically also the smallest class of users." The current caretakers of Slashdot need to balance the needs of all users with their limited engineering resources, Malda argues — noting wryly, "It ain't easy."
Databases

Transgendered Folks Encountering Document/Database ID Hassles 814

An anonymous reader writes "Most of us hear the equivalent of 'let me bring up your record' several times a week or month when dealing with businesses and government agencies; sometimes there's a problem, but clerks are accustomed to dealing with changes in street address, phone numbers, company affiliation, and even personal names (after marriage). But what about gender? Transgendered folks are encountering embarrassing moments when they have to explain that their gender has changed from 'M' to 'F' or vice versa. While there are many issues involved in discrimination against transgendered individuals, I have to confess that the first thing that came to my mind was the impact on database design and maintenance."
Facebook

Facebook and Microsoft Disclose Government Requests For User Data 140

wiredmikey writes "Facebook and Microsoft say they received thousands of requests for information from U.S. authorities last year but are prohibited from listing a separate tally for security-related requests or secret court orders related to terror probes. The two companies have come under heightened scrutiny since reports leaked of a vast secret Internet surveillance program U.S. authorities insist targets only foreign terror suspects and is needed to prevent attacks. Facebook said Friday it had received between 9,000 and 10,000 requests for user data affecting 18,000 to 19,000 accounts during the second half of last year and Microsoft said it had received 6,000 to 7,000 requests affecting 31,000 to 32,000 accounts during the same period." Meanwhile, an article at the Guardian is suggesting the government may have better targets to pursue than Edward Snowden. "[U.S. director of national intelligence James Clapper] has come out vocally to condemn Snowden as a traitor to the public interest and the country, yet a review of Booz Allen's own history suggests that the government should be investigating his former employer, rather than the whistleblower."
DRM

Netflix Using HTML5 Video For ARM Chromebook 232

sfcrazy writes "Netflix is using HTML5 video streaming instead of using Microsoft's Silverlight on Chromebooks (which now supports DRM for HTML5). Recently Google enabled the much controversial DRM support for HTML5 in Chrome OS to bring services like Netflix to Chromebooks using HTML5." Still no word on general support for GNU/Linux, but x86 or ARM, what's the difference? (If you're ok with DRM at least.)
Android

Developer Drops Game Price To $0 Citing Android Piracy 433

hypnosec writes with news of a curious way of fighting piracy. From the article: "Android based devices are being activated at the rate of million a day and users are downloading apps and games at a rate never seen before. Despite these promising stats, developers of Android based games and apps are not really keen on porting games and apps that have been successful on iOS to Android. Why? Rampant piracy on Android! Madfinger Games has joined the long list of developers who have recently turned their paid Android based game, Dead Trigger, to a free one. Originally priced at $0.99 on Play Store, the first person shooter game is now available for free . The iOS version of the game still costs $0.99 and hasn't been made free." Zero-cost, but certainly not Free Software; one has to wonder whether Open Source games with a "donation" build in the store would do better than proprietary games with upfront costs.
PlayStation (Games)

US Air Force To Suffer From PS3 Update 349

tlhIngan writes "The US Air Force, having purchased PS3s for supercomputing research, is now the latest victim of Sony's removal of the Install Other OS feature. It turns out that while their PS3s don't need the firmware update, it will be impossible to replace PS3s that fail. PS3s with the Other OS feature are no longer produced since the Slim was introduced, so replacements will have to come from the existing stock of used PS3s. However, as most gamers have probably updated their PS3s, that used stock is no longer suitable for the USAF's research. In addition, smaller educational clusters using PS3s will share the same fate — unable to replace machines that die in their clusters." In related news, Sony has been hit with two more lawsuits over this issue.
Education

Exam Board Deletes C and PHP From CompSci A-Levels 663

VitaminB52 writes "A-level computer science students will no longer be taught C, C#, or PHP from next year following a decision to withdraw the languages by the largest UK exam board. Schools teaching the Assessment and Qualifications Alliance's (AQA) COMP1 syllabus have been asked to use one of its other approved languages — Java, Pascal/Delphi, Python 2.6, Python 3.1, Visual Basic 6, and VB.Net 2008. Pascal/Delphi is 'highly recommended' by the exam board because it is stable and was designed to teach programming and problem-solving."
United States

State Senator Caught Looking At Porn On Senate Floor 574

Everyone knows how boring a debate on a controversial abortion bill can get on the Senate floor. So it's no wonder that Florida State Sen. Mike Bennett took the time to look at a little porn and a video of a dog running out of the water and shaking itself off. From the article: "Ironically, as Bennett is viewing the material, you can hear a Senator Dan Gelber's voice in the background debating a controversial abortion bill. 'I'm against this bill,' said Gelber, 'because it disrespects too many women in the state of Florida.' Bennett defended his actions, telling Sunshine State News it was an email sent to him by a woman 'who happens to be a former court administrator.'"
Security

OpenSSL 1.0.0 Released 105

hardaker writes "After over 11 years of development since the start of the OpenSSL Project (1998-12-23), OpenSSL version 1.0.0 has finally hit the shelves of the free-for-all store."

Slashdot Top Deals

Love may laugh at locksmiths, but he has a profound respect for money bags. -- Sidney Paternoster, "The Folly of the Wise"

Working...