At 19:38 4/20/2001, Nick Andriash wrote:
>On April 20, 2001, at 3:31:17 PM, Sean Rooney wrote:
>
> > simple, have an independent 3rd party audit/code review done. use three
> > teams, take a 2/3rds majority vote on everything.
>
>Alright... but who is going to organize that? Is that what is presently in
>place? If so, I have never seen any reviews for either PGP or GPG...
>unless I am not looking in the right place, and that is entirely possible.
I never said it was EASY did I? I suspect that a better modification is to
make sure that all reviewers are triple blind.... logistically, it can be
done. but if someone is sufficiently paranoid about these things, and has
sufficient cash to fund such an operation, its certainly achievable. I do
know a number of people in that particular catagory professionally... When
PGP 6.5x command line for Linux was written by a tiny little company nobody
ever heard of a long time ago, it was done under contract with NAI, and
this company is rumoured to have done some very impressive things with code
management and review and all that development stuff that goes way over my
head most days. I'm just a single security geek with some knowledge and
experiences that have perhaps helped me be better at my job but however
make no claim to expertise in all things. I am told that the programming
team on the pgp commandline thing were remarkably Brilliant and achieved
great results under difficult conditions.
SWAG [scientific wild ass guess] however is something I do engage in from
time to time.
>Point is, I have to trust someone/something if I am to continue using
>encryption software, so I am more likely to lend a measure of trust toward
>a well known Development Team/Company than I am individuals whom I do not
>know nor trust. Another example is Imad's CKT versions of PGP? Is there a
>published review of his source code, and if so by whom and how trustworthy
>are they?
>
>I am just one of the many confused PGP/GPG Users who are fence sitting in
>relation to who we should trust, trying hard not to get caught up in all
>this apparent paranoia. :o(
=====================================================================
Sean Rooney;
President and Chief Technical Officer
ColdStream Associates Ltd.
"Just when you learned that IT wasn't safe;"
www.coldstream.ca
416-516-8998
416-374-8823
======================================================================