Please create an account to participate in the Slashdot moderation system

 



Forgot your password?
typodupeerror
×

Feed Techdirt: The World's Email Encryption Software Relies On One Guy, Who Is Going Broke (google.com)

The man who built the free email encryption software used by whistleblower Edward Snowden, as well as hundreds of thousands of journalists, dissidents and security-minded people around the world, is running out of money to keep his project alive.

Werner Koch wrote the software, known as Gnu Privacy Guard, in 1997, and since then has been almost single-handedly keeping it alive with patches and updates from his home in Erkrath, Germany. Now 53, he is running out of money and patience with being underfunded.

"I'm too idealistic," he told me in an interview at a hacker convention in Germany in December. "In early 2013 I was really about to give it all up and take a straight job." But then the Snowden news broke, and "I realized this was not the time to cancel."

Like many people who build security software, Koch believes that offering the underlying software code for free is the best way to demonstrate that there are no hidden backdoors in it giving access to spy agencies or others. However, this means that many important computer security tools are built and maintained by volunteers.

Now, more than a year after Snowden's revelations, Koch is still struggling to raise enough money to pay himself and to fulfill his dream of hiring a full-time programmer. He says he's made about $25,000 per year since 2001 — a fraction of what he could earn in private industry. In December, he launched a fundraising campaign that has garnered about $43,000 to date — far short of his goal of $137,000 — which would allow him to pay himself a decent salary and hire a full-time developer.

The fact that so much of the Internet's security software is underfunded is becoming increasingly problematic. Last year, in the wake of the Heartbleed bug, I wrote that while the U.S. spends more than $50 billion per year on spying and intelligence, pennies go to Internet security. The bug revealed that an encryption program used by everybody from Amazon to Twitter was maintained by just four programmers, only one of whom called it his full-time job. A group of tech companies stepped in to fund it.

Koch's code powers most of the popular email encryption programs GPGTools, Enigmail, and GPG4Win. "If there is one nightmare that we fear, then it's the fact that Werner Koch is no longer available," said Enigmail developer Nicolai Josuttis. "It's a shame that he is alone and that he has such a bad financial situation."

The programs are also underfunded. Enigmail is maintained by two developers in their spare time. Both have other full-time jobs. Enigmail's lead developer, Patrick Brunschwig, told me that Enigmail receives about $1,000 a year in donations — just enough to keep the website online.

GPGTools, which allows users to encrypt email from Apple Mail, announced in October that it would start charging users a small fee. The other popular program, GPG4Win, is run by Koch himself.

Email encryption first became available to the public in 1991, when Phil Zimmermann released a free program called Pretty Good Privacy, or PGP, on the Internet. Prior to that, powerful computer-enabled encryption was only available to the government and large companies that could pay licensing fees. The U.S. government subsequently investigated Zimmermann for violating arms trafficking laws because high-powered encryption was subject to export restrictions.

In 1997, Koch attended a talk by free software evangelist Richard Stallman, who was visiting Germany. Stallman urged the crowd to write their own version of PGP. "We can't export it, but if you write it, we can import it," he said.

Inspired, Koch decided to try. "I figured I can do it," he recalled. He had some time between consulting projects. Within a few months, he released an initial version of the software he called Gnu Privacy Guard, a play on PGP and an homage to Stallman's free Gnu operating system.

Koch's software was a hit even though it only ran on the Unix operating system. It was free, the underlying software code was open for developers to inspect and improve, and it wasn't subject to U.S. export restrictions.

Koch continued to work on GPG in between consulting projects until 1999, when the German government gave him a grant to make GPG compatible with the Microsoft Windows operating system. The money allowed him to hire a programmer to maintain the software while also building the Windows version, which became GPG4Win. This remains the primary free encryption program for Windows machines.

In 2005, Koch won another contract from the German government to support the development of another email encryption method. But in 2010, the funding ran out.

For almost two years, Koch continued to pay his programmer in the hope that he could find more funding. "But nothing came," Koch recalled. So, in August 2012, he had to let the programmer go. By summer 2013, Koch was himself ready to quit.

But after the Snowden news broke, Koch decided to launch a fundraising campaign. He set up an appeal at a crowdsourcing website, made t-shirts and stickers to give to donors, and advertised it on his website. In the end, he earned just $21,000.

The campaign gave Koch, who has an 8-year-old daughter and a wife who isn't working, some breathing room. But when I asked him what he will do when the current batch of money runs out, he shrugged and said he prefers not to think about it. "I'm very glad that there is money for the next three months," Koch said. "Really I am better at programming than this business stuff."

Related stories: For more coverage, read our previous reporting on the Heartbleed bug, how to encrypt what you can and a ranking of the best encryption tools.

Republished from ProPublica. ProPublica is a Pulitzer Prize-winning investigative newsroom. Sign up for their newsletter .



Permalink | Comments | Email This Story








Submission + - 'Star Wars: Episode VII' has a title: 'The Force Awakens' (ew.com)

schwit1 writes: If you feel a disturbance in the Force, it’s millions of voices suddenly crying out the new title of Star Wars: Episode VII — The Force Awakens. The reveal comes as the movie finishes its final day of shooting (with many more months of post-production to come.)

Although there were still a few days left of shooting, the cast of the J.J. Abrams film already celebrated their wrap party last weekend, following a bumpy few months of principal photography thrown into crisis when Han Solo himself, Harrison Ford, broke his leg on set in an accident involving a falling door on the Millennium Falcon.

Bug

The 69 Words GM Employees Can Never Say 373

bizwriter (1064470) writes "General Motors put together its take on a George Carlin list of words you can't say. Engineering employees were shown 69 words and phrases that were not to be used in emails, presentations, or memos. They include: defect, defective, safety, safety related, dangerous, bad, and critical. You know, words that the average person, in the context of the millions of cars that GM has recalled, might understand as indicative of underlying problems at the company. Oh, terribly sorry, 'problem' was on the list as well."

Comment Do a proper threat assessment there. (Score 1) 1374

Because any place that is designated as a "gun-free zone" thereby becomes a place of danger. Nowdays they are refered to as "Rob Me zones".

Generally speaking, bars are rather filled with people, so robbing people inside is impractical and a bit silly of an idea even when everyone is supposed to be disarmed.

Robbing them in the parking lot is a possibility -- bars seem to attract crime of all sorts -- but the typical target you want to mug is someone who can't defend themselves. For a bar, that most likely means drunk people, who would be in no condition to defend themselves if they did have a gun; you'd just end up with an escalation of the situation that would most likely work against the armed patron by encouraging the mugger to attack while the patron attempts to draw.

On the other hand, the threat of impulsive, alcohol-fueled murders in a flash of anger is massively increased when you let someone carry a weapon into a bar. 50% of all murders are committed under the influence of alcohol. Allowing guns into bars is a recipe for raising the local homicide rate.

Just look at what happened to the schools !

Over 99% of schools will never have a school shooting throughout their lifespan. There were 38 school shootings in 2000-2010 resulting in the deaths of 33 victims (not including the shooter). This number does not include colleges but does include a handful of non-public schools. There are just under 99,000 schools in America, meaning that around 4% of 1% of schools had a shooting, and of those most were single-target attacks or very short opportunistic attacks rather than the slow, deliberate Columbine or Virginia Tech style massacre that people hold up as an example of where a gun might help.

On the other hand, 606 people died of firearms accidents and 19,392 people died of suicide just in 2010 alone. So with that in mind, what exactly do you think would have been solved by bringing guns to a building filled with curious children and emotionally wrought teens other than a lot of opportunities for tragedy.

You have to do a fair threat evaluation. Guns in schools are a far bigger threat than they are a threat neutralizer.

Comment Re:Gun nuts (Score 1) 1374

On the other hand, I would exercise self-restraint and not go to bars full of guns.

Kind of like avoiding smoking in bars, you may find that the choice simply becomes "don't go to bars." On the other hand, you can tell a smoky bar upon stepping in the door, so those are easy enough to avoid. However, with concealed carry laws, you have no idea if anyone is carrying while drunk until it has become a situation unless the bar has a very clear sign on the door.

Comment Re:Gun nuts (Score 1) 1374

If you wish to live in community that heavily regulates firearms, then band together and do so - nothing restricts a locality/city/region from banning the things of their own initiative (see also Chicago, D.C, New York City, etc.) However, please do not try to impose such things across the whole nation. There is no "reasonable" restriction in the eyes of those who wish to promulgate these laws, save for complete abolition.

Due to a number of court challenges, there is no local governments that are allowed to practice such restrictions anymore, because "there is no 'reasonable' restriction in the eyes of those who wish to [oppose] these laws, save for complete [legalization]." See Heller vs. DC, et al.

Okay, maybe that's a bit too far. Most gun-enthusiasts support restrictions on felons and the mentally ill owning guns, but there are a good number of true gun-nuts that don't, and politics over the last decade has pushed further and further to the fringe on the right. Witness the latest law in right-leaning Georgia to allow concealed carry in bars where people will be intoxicated while armed.

I mean, why did anyone think that was a good idea?

United States

"Smart" Gun Seller Gets the Wrong Kind of Online Attention 1374

R3d M3rcury (871886) writes "How's this for a good idea? A gun that won't fire unless it's within 10 inches of a watch? That's the iP1 from Armatrix. Of course, don't try to sell it here in the United States." From the NY Times article linked: "[Armatrix employee] Belinda Padilla does not pick up unknown calls anymore, not since someone posted her cellphone number on an online forum for gun enthusiasts. Then someone snapped pictures of the address where she has a P.O. box and put those online, too. In a crude, cartoonish scrawl, this person drew an arrow to the blurred image of a woman passing through the photo frame. 'Belinda?" the person wrote. "Is that you?" ... "I have no qualms with the idea of personally and professionally leveling the life of someone who has attempted to profit from disarming me and my fellow Americans," one commenter wrote." The article paints a fairly rosy picture of the particular technology that Armatrix is pushing, but their ID-checking gun seems to default to an unfireable state, which might not always be an attractive feature. And given that at least one state — New Jersey — has hinged a gun law on the commercial availability of these ID-linked guns, it's not surprising that some gun owners dislike a company that advertises this kind of system as "the future of the firearm."

Comment Re:I can't do it; I've tried before. (Score 1) 466

Right, the no-meat version is better ;) If its cooked well, which the Chinese can do since they've been cooking this way for 1000's of years, then you get a very good result.

In your opinion, but you've already established that meat wasn't something you really cared for to begin with.

Don't get me wrong, there are a few Chinese vegetarian dishes I like and many more Indian dishes, but any good dish is a celebration of its ingredients. No dish should be able to taste the same if you add or remove any one ingredient, because if done properly, a dish enhances the flavors of all of its components. If it does taste the same, then there's probably just some component smothering the other flavors, and I can't imagine that any such dish treats its vegetables any better.

I think people mostly don't want to enjoy their non-meat meals, they COULD, but they'd feel like maybe they weren't eating well before. Its scary.

I think you should talk to people who have different life experiences from you rather than just imagine motives for them that cast them in a scary light. I've wanted to go lacto-ovo vegetarian for health and environmental reasons, but I've failed three times. It's not that I didn't want to like vegetarian dishes; it's that I just never stopped wanting the meat dishes too. It's far harder to give up something you enjoy than it is to find joy in other things, and when it comes to food, nothing is quite as tempting as the dish you can't have but want.

Just ask anyone on a diet.

Comment Think of carob & chocolate (Score 2) 466

Because people like meat, and you aren't going to get some people to switch until they can get the experience of meat. The problem is that the primary consumers of vegetarian meat substitutes are people who don't like meat.

Imagine if we were talking about giving up chocolate. People could tell you that there's all sorts of yummy, fruit flavored alternatives out there that have "great flavors and textures all their own" and "can satisfy the appetite." But none of them are chocolate. They don't compare at all when you've got that craving, even if they are nutritionally equivalent or better.

So then someone invents carob bars, and all the chocolate lovers look askance at it, while the non-chocolate people are split between those that embrace the new "tastes just like chocolate" treat (which it doesn't) and others are just so puzzled why anyone would want chocolate in the first place. Is it any wonder it fails to attract people who are okay with chocolate?

It's the same with meat substitutes and meat.

Comment I can't do it; I've tried before. (Score 4, Informative) 466

I find that not eating meat is pretty trivial ...

Good for you. I'm reminded of a quote from a comic I read when someone expressed shock and incredulity that another character had not seen Star Wars. Her response was simply, "Your life experiences are different from my own." What you are basically saying here is that you don't really like meat all that much and it was no big sacrifice to give it up. That's not the case for everyone.

I find the switch to a meatless diet extremely hard, and I become just absolutely ravenous when I go more than a few days without it. I've tried three times for all the good reasons that you mention, and I just get a craving that cannot be satisfied by anything else.

Almost any garden variety restaurant in China can make you a dish that usually can't be distinguished from a meat dish, and if I wish I can make several of them myself.

As someone who likes meat, I find that statement laughable. If the vegetables in the dish are the most interesting and delicious part to you, then that's probably true for you. However, while I do enjoy many vegetarian Chinese and Indian dishes, I will NEVER confuse them for those with meat. The taste of the meat is not found in the meat itself but also in the sauces.

Comment Re:Bank them (Score 1) 333

My thought upon reading this story was, "Oh, thank God!!"

I had been hoping there was a definite end that science could not trick. I was beginning to fear that the medical community was going to try to force any level of existence to continue without regard to quality. Death is a part of life. I'd rather live with that than trying to force a 100 year old body to keep it's heart beating just because some family member doesn't know how to cope any other way.

That is a view and a choice that I can respect, but why should you cheer the possibility that no one be able to choose any other way? That those who want more life be denied it?

Like a lot of the elderly people you mention, I think I too would choose death over prolonged suffering, helplessness, and a lack of ability to accomplish much more than running the bills up for my family. But I don't think I would choose death until that was all I had to look forward to, and I would be happy for any medical advancement that pushes that inevitable time back and that preserves health into those latter years.

And if the generation after me is able to live forever, I will not begrudge them that just because it was too late for me. (Okay, maybe I'll be a tad jealous.) However, I'd oppose any efforts to stop it with what's left of my life.

Slashdot Top Deals

Beware of Programmers who carry screwdrivers. -- Leonard Brandwein

Working...