Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror

Feed Techdirt: The World's Email Encryption Software Relies On One Guy, Who Is Going Broke (google.com)

The man who built the free email encryption software used by whistleblower Edward Snowden, as well as hundreds of thousands of journalists, dissidents and security-minded people around the world, is running out of money to keep his project alive.

Werner Koch wrote the software, known as Gnu Privacy Guard, in 1997, and since then has been almost single-handedly keeping it alive with patches and updates from his home in Erkrath, Germany. Now 53, he is running out of money and patience with being underfunded.

"I'm too idealistic," he told me in an interview at a hacker convention in Germany in December. "In early 2013 I was really about to give it all up and take a straight job." But then the Snowden news broke, and "I realized this was not the time to cancel."

Like many people who build security software, Koch believes that offering the underlying software code for free is the best way to demonstrate that there are no hidden backdoors in it giving access to spy agencies or others. However, this means that many important computer security tools are built and maintained by volunteers.

Now, more than a year after Snowden's revelations, Koch is still struggling to raise enough money to pay himself and to fulfill his dream of hiring a full-time programmer. He says he's made about $25,000 per year since 2001 — a fraction of what he could earn in private industry. In December, he launched a fundraising campaign that has garnered about $43,000 to date — far short of his goal of $137,000 — which would allow him to pay himself a decent salary and hire a full-time developer.

The fact that so much of the Internet's security software is underfunded is becoming increasingly problematic. Last year, in the wake of the Heartbleed bug, I wrote that while the U.S. spends more than $50 billion per year on spying and intelligence, pennies go to Internet security. The bug revealed that an encryption program used by everybody from Amazon to Twitter was maintained by just four programmers, only one of whom called it his full-time job. A group of tech companies stepped in to fund it.

Koch's code powers most of the popular email encryption programs GPGTools, Enigmail, and GPG4Win. "If there is one nightmare that we fear, then it's the fact that Werner Koch is no longer available," said Enigmail developer Nicolai Josuttis. "It's a shame that he is alone and that he has such a bad financial situation."

The programs are also underfunded. Enigmail is maintained by two developers in their spare time. Both have other full-time jobs. Enigmail's lead developer, Patrick Brunschwig, told me that Enigmail receives about $1,000 a year in donations — just enough to keep the website online.

GPGTools, which allows users to encrypt email from Apple Mail, announced in October that it would start charging users a small fee. The other popular program, GPG4Win, is run by Koch himself.

Email encryption first became available to the public in 1991, when Phil Zimmermann released a free program called Pretty Good Privacy, or PGP, on the Internet. Prior to that, powerful computer-enabled encryption was only available to the government and large companies that could pay licensing fees. The U.S. government subsequently investigated Zimmermann for violating arms trafficking laws because high-powered encryption was subject to export restrictions.

In 1997, Koch attended a talk by free software evangelist Richard Stallman, who was visiting Germany. Stallman urged the crowd to write their own version of PGP. "We can't export it, but if you write it, we can import it," he said.

Inspired, Koch decided to try. "I figured I can do it," he recalled. He had some time between consulting projects. Within a few months, he released an initial version of the software he called Gnu Privacy Guard, a play on PGP and an homage to Stallman's free Gnu operating system.

Koch's software was a hit even though it only ran on the Unix operating system. It was free, the underlying software code was open for developers to inspect and improve, and it wasn't subject to U.S. export restrictions.

Koch continued to work on GPG in between consulting projects until 1999, when the German government gave him a grant to make GPG compatible with the Microsoft Windows operating system. The money allowed him to hire a programmer to maintain the software while also building the Windows version, which became GPG4Win. This remains the primary free encryption program for Windows machines.

In 2005, Koch won another contract from the German government to support the development of another email encryption method. But in 2010, the funding ran out.

For almost two years, Koch continued to pay his programmer in the hope that he could find more funding. "But nothing came," Koch recalled. So, in August 2012, he had to let the programmer go. By summer 2013, Koch was himself ready to quit.

But after the Snowden news broke, Koch decided to launch a fundraising campaign. He set up an appeal at a crowdsourcing website, made t-shirts and stickers to give to donors, and advertised it on his website. In the end, he earned just $21,000.

The campaign gave Koch, who has an 8-year-old daughter and a wife who isn't working, some breathing room. But when I asked him what he will do when the current batch of money runs out, he shrugged and said he prefers not to think about it. "I'm very glad that there is money for the next three months," Koch said. "Really I am better at programming than this business stuff."

Related stories: For more coverage, read our previous reporting on the Heartbleed bug, how to encrypt what you can and a ranking of the best encryption tools.

Republished from ProPublica. ProPublica is a Pulitzer Prize-winning investigative newsroom. Sign up for their newsletter .



Permalink | Comments | Email This Story








Google

Google Adds To Mozilla's Push For 'Do Not Track' 128

AndyAndyAndyAndy writes "In a morning blog post, Google announced the release of a Chrome plug-in called 'Keep My Opt-Outs,' which hopes to block all tracking cookies. Interestingly, it is released as open-source with the hopes that it will gain quick deployment on non-Chrome browsers and find a robust foothold against ads. The story is also covered at Computerworld, which has broader insight into the issue, looking at Google, Mozilla and Firefox, and seems to indicate more rapid change is looming — potentially from the FCC itself."
Transportation

Heroic Engineer Crashes Own Vehicle To Save a Life 486

scottbomb sends in this feel-good story of an engineer-hero, calling it "one of the coolest stories I've read in a long time." "A manager of Boeing's F22 fighter-jet program, Innes dodged the truck, then looked back to see that the driver was slumped over the wheel. He knew a busy intersection was just ahead, and he had to act fast. Without consulting the passengers in his minivan — 'there was no time to take a vote' — Innes kicked into engineer mode. 'Basic physics: If I could get in front of him and let him hit me, the delta difference in speed would just be a few miles an hour, and we could slow down together,' Innes explained."
Microsoft

Xbox Live Pricing To Go Up To $60 Per Year 199

donniebaseball23 writes "Microsoft has raised the annual price of Xbox Live Gold to $60, which is a price hike of $10. The new price goes into effect on November 1, but gamers can lock in the current Xbox Live price by renewing now. EEDAR analyst Jesse Divnich is not surprised by the move, nor does he think it will really have much impact on the Xbox momentum."
Government

American Lung Association Pushes For Ban On Electronic Cigarettes 790

Anarki2004 writes "The American Lung Association is jumping on board the ban-E-cigs-train. From the article: 'So, while the ALA admitted that electronic cigarettes contain fewer chemicals than tobacco cigarettes, they refuse to acknowledge the obvious health benefit that lack of the most toxic chemicals provides to the smokers who switch. Are lives and lung health the real issue here or is nicotine addiction? The ALA must know that numerous studies show that, absent the tobacco smoke, nicotine is relatively harmless and comparable to caffeine. The American Heart Association acknowledges that nicotine is "safe" in other smoke-free forms such as patches or gum.' For those of you not in the know, electronic cigarettes (also called personal vaporizers) are a nicotine delivery device that resembles a cigarette in shape and size, but does not burn tobacco. It is less a expensive alternative to the traditional tobacco cigarette that is by all appearances (though not thoroughly researched) also healthier."
Security

Microsoft Refuses To Patch Rootkit-Compromised XP Machines 330

Barence writes "Microsoft has revealed that its latest round of patches won't install on XP machines if they're infected with a rootkit. In February, a security patch left some XP users complaining of endless reboots and Blue Screens of Death. An investigation followed and Microsoft discovered the problems occurred on machines infected with the Alureon rootkit, which interacted badly with patch KB977165 for the Windows kernel. Now Microsoft is blocking PCs with the rootkit from receiving its new patches. 'This security update includes package-detection logic that prevents the installation of the security update if certain abnormal conditions exist on 32-bit systems,' Microsoft cautions in the patch notes."
Media

Nvidia Announces 3D Blu-ray Format For 2010 178

Barence writes "Nvidia has announced that 3D Blu-ray movies will begin appearing in 2010. A spokesman confirmed that the Blu-ray Association — to which Nvidia is a contributor — had settled on the 'proper parameters [for] what constitutes a 3D Blu-ray' and claimed the first 3D Blu-ray films would hit the shelves 'towards the end of Summer 2010.' Nvidia will support the standard through its 3D Vision technology, using bit rates of around 60Mbits/second — twice that of a standard movie — although HDMI 1.3 'should have sufficient bandwidth' to ensure smooth playback. New files will be encoded using the MVC-AVC format, which is based on the AVC format currently used by Blu-ray movies.' Update: HotHardware has some additional details, including images of demo hardware.
Image

NASA Tests Flying Airbag 118

coondoggie writes "NASA is looking to reduce the deadly impact of helicopter crashes on their pilots and passengers with what the agency calls a high-tech honeycomb airbag known as a deployable energy absorber. So in order to test out its technology NASA dropped a small helicopter from a height of 35 feet to see whether its deployable energy absorber, made up of an expandable honeycomb cushion, could handle the stress. The test crash hit the ground at about 54MPH at a 33 degree angle, what NASA called a relatively severe helicopter crash."
The Courts

Sparc Sends SparkFun Electronics C&D Letter 219

moogied writes "SparkFun.com, a electronics component provider, has been sent a cease and desist letter by Sparc in response to the lengthy trademark process that SparkFun is participating in. The letter states 'Because the dominant portion of the SparkFun mark, namely, SPARK, is phonetically identical and nearly visually identical to SI's SPARC mark, and because it is used in connection with identical goods, we believe confusion is likely to occur among the relevant purchasing group.' SparkFun.com has provided the entire contents of the letter, with a breakdown of points it feels are most relevant."
Patents

Touchpad Patent Holder Tsera Sues Just About Everyone 168

eldavojohn writes "Okay, well, maybe not everyone but more than twenty companies (including Apple, Qualcomm, Motorola and Microsoft) are being sued for a generic patent that reads: 'Apparatus and methods for controlling a portable electronic device, such as an MP3 player; portable radio, voice recorder, or portable CD player are disclosed. A touchpad is mounted on the housing of the device, and a user enters commands by tracing patterns with his finger on a surface of the touchpad. No immediate visual feedback is provided as a command pattern is traced, and the user does not need to view the device to enter commands.' Sounds like their may be a few companies using that technology. The suit was filed on July 15th in the favoritest place ever to file patent claim lawsuits: Texas Eastern District Court. It's a pretty classic patent troll; they've been holding this patent since 2003 and they just noticed now that everyone and his dog are using touchpads to control portable electronic devices."
Image

Rotten Office Fridge Cleanup Sends 7 To Hospital 410

bokske writes "An office worker cleaning a fridge full of rotten food created a smell so noxious that it sent seven co-workers to the hospital and made many others ill. Firefighters had to evacuate the AT&T building in downtown San Jose on Tuesday, after the flagrant fumes prompted someone to call 911. A hazmat team was called in. Just another day at the office."
The Internet

Net Neutrality Blasted by MPAA Bosses 222

proudhawk writes "The LA Times is reporting that the MPAA's Dan Glickman has taken another swipe against net neutrality at his recent ShoWest appearance. 'Glickman argued in his speech that neutrality regulations would bar the use of emerging tools that ISPs can use to prevent piracy. That's what some studio lobbyists have been telling lawmakers, too, in their efforts to derail neutrality legislation. And depending on how the regulations are written, they could be right.'"
Technology

Vaporware - the Tech That Never Was 192

An anonymous reader writes "CNet has published an incredibly detailed look at the most critical examples of vaporware ever seen in the tech sector. We're familiar with Wired's yearly round-ups, but this decades-long retrospective look at the most promising of all technologies that never saw the light of day, holds some fascinating technology I've never even heard of, including the wonderfully-named three-dimensional atomic holographic optical data storage nanotechnology. 'Continual delays, setbacks and excuses are the calling cards of a product that becomes vapourware. Windows Vista ran the risk of joining the club, and the terrific multiplayer first-person shooter Team Fortress 2 was in production for almost a decade before it was released in 2007. Devoted TF fans feared it would become a distinguished entrant in the who's who of vapourware. You might say Google Mail is in the running, having been in beta since 2004.'"

Slashdot Top Deals

Trap full -- please empty.

Working...