Please create an account to participate in the Slashdot moderation system

 



Forgot your password?
typodupeerror
×
Encryption Security

GnuPGP article on CNN 22

Ed Goodwin writes "CNN had an article about a 128 bit encryption program released under the Gnu license. Not alot of technical info but the developer comes across as a serious OpenSource advocate. "
This discussion has been archived. No new comments can be posted.

GnuPGP article on CNN

Comments Filter:
  • They use that phrase at least 3 times (I stopped reading when I read it the third time). How blatantly incorrect.
  • here's my opinion on that:

    -----BEGIN PGP MESSAGE-----
    Version: 2.6.2

    pgAAAC3X92V/VZV7hVVNY4TOUBuxVbh8IC3HnXJwuqndVtVZ 3GzaPUGdSEOPxLpE
    sMU=
    =NHcT
    -----END PGP MESSAGE-----

    ...the password is everyone's favorite metasyntactic syllable, three letters, lowercase. (nope, it's not 'bar'. :)
  • I'm currently using the latest release of GnuPG, and have been for a little while... surprised it's never been mentioned on Slashdot before. it seems to be very high quality, conforming to the OpenPGP spec, and can be broken to play nice with PGP 5 and 6, and somewhat with 2.x.

    Odd this should turn up... I posted to my local LUG list about it this morning, just on a whim.

    http://www.gnupg.org, if anyone needs a link.
  • This is the kind of technology that needs to be integrated somehow into GNOME/KDE so that a significant number of people are using strong encryption, so that the government's attack on privacy can be curtailed. With strong encryption, the government cannot eavesdrop, and that is something that you don't get with many technologies.

    How can GnuPG be integrated into GNOME without breaking certain laws. Is there any way to have GNOME/KDE-aware programs that can be downloaded and installed easily off of foreign sites?

    Is there any way to link the installation of these as part of the installation of GNOME/KDE on a desktop?

    I think this should be one area that should be explored, because stronger encryption means we get authenticated E-mail, etc., and this should all be an integral part of the user experience. This is something that Microsoft cannot offer and something that, if done right, could really be a selling point for OSS.

    Any comments?
  • "GnuPG could easily be adapted for Windows, Koch said, but 'I'm not going to do that for free. I'm not that interested in Windows,' he said.

    Classic.

  • Hey, it's just a beta.

    FreeBSD/OpenBSD are explicitly mentioned as ports with no comment about unavailable RNGs, and from what I've heard about these they have crypto in the kernel.

    Sure, GPG needs its own RNG. Someone will have to write one. Anyone?

    It is designed to be a drop-in replacement for PGP (identical command line switches for the basic operations) and to be compatible to PGP5 upwards (PGP2 is not difficult because of RSA and IDEA being patented and therefore not implemented in GPG).
  • umm, kill the "not" in "not difficult" in my above response. Changed wording and missed that.
  • Maybe you should read some of the infos on www.gnu.org [gnu.org].

    Hint: it's not what someone pays for something to be programmed, but what you can do with the resulting sources.

    Free software does not mean that programmers are slaves. They are also free, and if they don't program what you want/need, you can try to motivate them to program that for you.

    Also, this is nothing new. Happens all the time.
  • That's the way that it should be--you can make money off of causing progress in the workings, or off of distribution (selling to those who want to buy a CD-ROM just because it's easier than downloading the entire GNU system, or whatever), but taking money for the privilage of using (or even seeing) software? Ick.


    It's too bad that most misinterpret `free' as meaning 'gratis'....


    -Rozzin
  • I installed a Debian/Slink beta this week and GPG seems to be well integrated into the mail-user-agent "exmh".

    Packages are signed somehow, but I think the sig is only checked when the package-maintainers upload the software. (And I don't know if everyone uses GPG already.)

    Please note that GPG can't be an integral part of any free GNU/Linux-System, since US-Gov. doesn't permit reexporting.

    What other kind of "integration" might be needed in the near future?

He has not acquired a fortune; the fortune has acquired him. -- Bion

Working...