At 19:38 4/20/2001, Nick Andriash wrote:
>On April 20, 2001, at 3:31:17 PM, Sean Rooney wrote:
>
> > simple, have an independent 3rd party audit/code review done. use three
> > teams, take a 2/3rds majority vote on everything.
>
>Alright... but who is going to organize that? Is that what is presently in
>place? If so, I have never seen any reviews for either PGP or GPG...
>unless I am not looking in the right place, and that is entirely possible.

I never said it was EASY did I?  I suspect that a better modification is to 
make sure that all reviewers are triple blind.... logistically, it can be 
done.  but if someone is sufficiently paranoid about these things, and has 
sufficient cash to fund such an operation, its certainly achievable.  I do 
know a number of people in that particular catagory professionally...  When 
PGP 6.5x command line for Linux was written by a tiny little company nobody 
ever heard of a long time ago, it was done under contract with NAI, and 
this company is rumoured to have done some very impressive things with code 
management and review and all that development stuff that goes way over my 
head most days. I'm just a single security geek with some knowledge and 
experiences that have perhaps helped me be better at my job but however 
make no claim to expertise in all things.  I am told that the programming 
team on the pgp commandline thing were remarkably Brilliant and achieved 
great results under difficult conditions.

SWAG [scientific wild ass guess] however is something I do engage in from 
time to time.

>Point is, I have to trust someone/something if I am to continue using
>encryption software, so I am more likely to lend a measure of trust toward
>a well known Development Team/Company than I am individuals whom I do not
>know nor trust. Another example is Imad's CKT versions of PGP? Is there a
>published review of his source code, and if so by whom and how trustworthy
>are they?
>
>I am just one of the many confused PGP/GPG Users who are fence sitting in
>relation to who we should trust, trying hard not to get caught up in all
>this apparent paranoia. :o(




=====================================================================

Sean Rooney;
President and Chief Technical Officer
ColdStream Associates Ltd.
"Just when you learned that IT wasn't safe;"
www.coldstream.ca
416-516-8998
416-374-8823

======================================================================


Reply via email to