Date: 2001-04-20 16:38 -0700
Nick Andriash:
>On April 20, 2001, at 3:31:17 PM, Sean Rooney wrote:
>
>> simple, have an independent 3rd party audit/code review done. use three
>> teams, take a 2/3rds majority vote on everything.
>
>Alright... but who is going to organize that? Is that what is presently in
>place? If so, I have never seen any reviews for either PGP or GPG...
>unless I am not looking in the right place, and that is entirely possible.
>
>A question. If you take some of the GPG precompiled binaries for Win32
>that are available (such as the one I use from time to time), has anyone
>checked their source code and provided a review? A lot of Users say they
>trust GnuPG because it is open source, yet I wonder how many have checked
>the source code and published a review?
>
>Point is, I have to trust someone/something if I am to continue using
>encryption software, so I am more likely to lend a measure of trust toward
>a well known Development Team/Company than I am individuals whom I do not
>know nor trust. Another example is Imad's CKT versions of PGP? Is there a
>published review of his source code, and if so by whom and how trustworthy
>are they?
>
>I am just one of the many confused PGP/GPG Users who are fence sitting in
>relation to who we should trust, trying hard not to get caught up in all
>this apparent paranoia. :o(
Nick,
You bring the basic points together very succinctly. I too ask myself who
to trust. May be this whole security thing and "trust " business if full of
holes and is daydreaming, smoke and mirrors. I wonder sometimes.
And now that Verisign has shown it does not investigate request for
certificates very thoroughly, and issued several bogus Microsoft
certificates which turned out to be completely phoney, who are we going to
trust there too?
Would I trust versions of PGP from 5 to 7 running on Windows if my life and
that of others depended on it? Not a chance!
How come NAI does not really think like that? They don't, otherwise there
would be much more focused on making PGP really solid (including fixing the
bugs that have been there for years), rather then forever adding bells and
whistles which have not been tested at large (a critical requirement
especially in the security area).
By definition the security area must protect its core. If bells and
whistles endanger that, then get rid of them at least in some well
identified high end versions of PGP. PGP 7 is most definitely not a high
end version, especially on Windows. People can do (and I am sure in many
case "are doing") all kinds of things to our machines, including recording
keystrokes, patching PGP, etc. without even coming close to our house, all
with off the shelf equipment that is dirt cheap.
The answer we get from NAI is "Trust us, we are the best"! And yet they do
not even regularly publish how they "fixed" the faults that seem to come up
more and more often. Have the fixes been widely tested? That cannot have
happened. They should have discussion forums of their own, and encourage
people to test these things.
They certainly don't, they always try to make the "holes" look
insignificant, academic, theoretical, even when they seem to be major
oversights on their part. That reflects a lack of vigilance, thoroughness
and continuity that is a must in the security area. It does not make me
more confident, the opposite is true.
And administratively NAI is so weak it is almost funny. They do not seem to
do anything right as a company, and that also brings down the credibility
of what is inside. How much control do they really have over what goes on
inside? It has to be very little as far as I can see.
I am lucky that my life does not depend on PGP, like it is the case for
many people who use the stuff. In fact PGP was initially focused on the
basic strength of its approach, and making sure it can stand up to the
strongest attacks. Not so anymore. We are not even worried about PGP being
coupled with an OS full of holes and not having PGP software that looks out
for these holes and protects itself.
I find myself in a quandary. I cannot and do not necessarily implicitly
"trust" the software coming out of NAI, not that I mistrust any one person
in particular on the inside.
However, it is quite obvious to me that software development at NAI is not
done in a truly professional manner. They don't even know how to organize
their distribution, and upgrades always bring new mostly undocumented
surprises, conflicts, etc. I find them very "in-grown", lacking a client
perspective. Some of the flaws in the first PGP 7 issue were caused by odd
(weird) assumptions by the designers, and nobody obviously had seen that
from a client perspective or had bothered to test the stuff before putting
it out.
This is a dark picture I am putting forward, however I cannot see anything
on the horizon that cheers me up about all this. Things in technology are
getting worse with respect to security, not better.
For a few years now, I have talked about the PGP users and security experts
getting organized in a sort of Association, with staff, annual fees, etc.
Why are we not doing this like most professional associations do it? When
people care enough, they become members, are wiling to put up a bit of
money. Then they know "someone" out there is minding the store, and they
get feedback. There are millions of users of PGP, we should be able to
quite easily raise enough to do something.
Until that happens, the PGP area will continue to be run the way it is now,
by software developers. That is crazy, especially now that PRZ is no longer
part of that picture at all.
I agree with the comments regarding the review of code. It has not happened
very much in the past (it generally mostly happens in the tech underground
and stays there). The review of code has to be organized (some have
suggested ways of doing that) and someone needs to overview the process on
an ongoing basis and ensure the results are published for all to see. An
Association is essential to make that happen.
We talk so much about the need to protect ourselves. However we have no
leaders at all who could get enough momentum going to get organized. I
doubt if PRZ still has the fire to make that type of stuff happen, perhaps?
Surely there must be some people out there ready to take on the job,
especially if we organize ourselves so they can get paid to do it. Then we
could have continuity and some form of unity and order.
Frustrated? Yes. Impatient?, Yes. Puzzled? Yes.
Hopeful? I suppose.
However, I am NOT looking forward to PGP 8 on Windows XP!
Cheers,
Jacques