On April 20, 2001, at 3:31:17 PM, Sean Rooney wrote:

> simple, have an independent 3rd party audit/code review done. use three
> teams, take a 2/3rds majority vote on everything.

Alright... but who is going to organize that? Is that what is presently in
place? If so, I have never seen any reviews for either PGP or GPG...
unless I am not looking in the right place, and that is entirely possible.

A question. If you take some of the GPG precompiled binaries for Win32
that are available (such as the one I use from time to time), has anyone
checked their source code and provided a review? A lot of Users say they
trust GnuPG because it is open source, yet I wonder how many have checked
the source code and published a review?

Point is, I have to trust someone/something if I am to continue using
encryption software, so I am more likely to lend a measure of trust toward
a well known Development Team/Company than I am individuals whom I do not
know nor trust. Another example is Imad's CKT versions of PGP? Is there a
published review of his source code, and if so by whom and how trustworthy
are they?

I am just one of the many confused PGP/GPG Users who are fence sitting in
relation to who we should trust, trying hard not to get caught up in all
this apparent paranoia. :o(


Nick

=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
    -=N.J. Andriash  |  Vancouver, B.C. Canada=-
 PGP-Basics List Moderator | PGP Key ID: 0x7BA3FDCE
GnuPG v1.0.4-2 (MingW32) | TB! v1.52 Beta 1 | Win98 SE             



Reply via email to