About
Community
Bad Ideas
Drugs
Ego
Erotica
Fringe
Society
Privacy
100 Ways to Disappear and Live Free
A Guide to Intelligence Collection Methods
A Study of Criminal History Records, as Maintained by the RCMP
A Theory of Information Warfare: Preparing for 2020
An Appraisal of the Technology of Political Control
Anonymity on the Web
Antisurveillance
Appeal Filed in Teenager vs. FBI Case
Beating The FBI
Big Brother's Little Helpers: Private Intelligence Networks
Biometric ID Cards
Bugs, Taps And Infiltrators: What To Do About Political Spying
Carnival Booth: Defeating Computer-Assisted Passenger Screening System
Carnivore FAQ
China's Golden Shield: Corporations and the Development of Surveillance Technology in China
Civil Liberties Under Threat
Cooperation of Telecommunications Providers with Law Enforcement
Cryptography: Policy and Technology Trends
Disabling CCTV / Video Cameras
Disabling Surveillence Video Cameras
EPIC Analysis of Draft Guidelines on Searching and Seizing Computers
EU Lawful Interception of Telecommunications
Eavesdropping On the Electromagnetic Emanations of Digital Equipment
Electronic Surveillance in a Digital Age
Email Privacy Law Review
European Union and FBI Launch Global Surveillance System
Executive Guide to the Protection of Information
Exposing The Global Surveillance System
Exposing the Global Surveillance System
FBI Investigates Domestic Activities to Identify Terrorists
Fingerprints
General Counterdrug Intelligence Plan
Gmail Bedfellows
Hiding Yourself
Homeless Tracking Fact Sheet
How COINTELPRO Helped Destroy the Movements of the 1960s
How Private Is My Credit Report?
How Tax Returns are Selected for Audit
How To Create A New Indentity
How To Get Lost
How to Get Anything on Anyone
IRS Cups It's Ear to Cordless Phones
IRS and Terrorist-Related Information Sharing
Identification, Anonymity and Pseudonymity in Consumer Transactions
Identification: A Move Towards the Future
Identity Cards: Frequently Asked Questions
Interception Capabilities 2000
Internet Security and Privacy for Activists and Citizens
Internet Security and Privacy for Activists and Citizens
Investigators Guide to Sources of Information
Is the NSA Sniffing Your Email?
Mail Surveillance
New Communications Technologies and Traditional Civil Liberties
Participating With Safety
Privacy Rights of BBS Users
Privacy or Service: Must We Be Forced to Choose?
Proof of Echelon?
Rebirth Methods In Post 9/11 USA
Recieve Your FBI File
Report of the Interception of Communications Commissioner for 2001
Schengen Information System: SIS II
Smart Cards: Opportunities for Public Sector Applications
Spook Words
Spy Secrets
Statements by the DCI and the NSA Director on Economic Spying
Surveillance Conference Overview
Testimony of Mark M. Ishikawa CEO BayTSP.com
The "Enemy Within": EU Plans the Surveillance of Protestors
The Group Trap
The Joy of Handles
The Libertarian Party Represents You
The Shocking Menace of Satellite Surveillance
The TEMPEST Method of Computer Data Interception!
The World of Surveillance
They Were Spying on Us: Detroit Police Red Squad
Touching Big Brother: How Biometric Technology will Fuse Flesh and Machine
U.S. Military Spying on Web Sites
UK ID Cards: Majority in Favor
UK National ID Cards - A Consultation
Using the Freedom of Information Act: Revised Edition
Watching the Watcher Watching You
Watching the Watchers: The Spanish Police
What To Do When They Ask For Your Social Security Number
Who's Afraid of Carnivore? Not Me!
Why Legal Action Should Be Taken for Installation of Surveillance Cameras in Public Places
Will We Be Under Total Surveillance?
Your Papers Please
Technology
register | bbs | search | rss | faq | about
meet up | add to del.icio.us | digg it

No Regrets About Developing PGP

by Philip Zimmermann

The Friday September 21st [2001] Washington Post carried an article by Ariana Cha that I feel misrepresents my views on the role of PGP encryption software in the September 11th terrorist attacks. She interviewed me on Monday September 17th, and we talked about how I felt about the possibility that the terrorists might have used PGP in planning their attack. The article states that as the inventor of PGP, I was "overwhelmed with feelings of guilt". I never implied that in the interview, and specifically went out of my way to emphasize to her that that was not the case, and made her repeat back to me this point so that she would not get it wrong in the article. This misrepresentation is serious, because it implies that under the duress of terrorism I have changed my principles on the importance of cryptography for protecting privacy and civil liberties in the information age.

Because of the political sensitivity of how my views were to be expressed, Ms. Cha read to me most of the article by phone before she submitted it to her editors, and the article had no such statement or implication when she read it to me. The article that appeared in the Post was significantly shorter than the original, and had the abovementioned crucial change in wording. I can only speculate that her editors must have taken some inappropriate liberties in abbreviating my feelings to such an inaccurate soundbite.

In the interview six days after the attack, we talked about the fact that I had cried over the heartbreaking tragedy, as everyone else did. But the tears were not because of guilt over the fact that I developed PGP, they were over the human tragedy of it all. I also told her about some hate mail I received that blamed me for developing a technology that could be used by terrorists. I told her that I felt bad about the possibility of terrorists using PGP, but that I also felt that this was outweighed by the fact that PGP was a tool for human rights around the world, which was my original intent in developing it ten years ago. It appears that this nuance of reasoning was lost on someone at the Washington Post. I imagine this may be caused by this newspaper's staff being stretched to their limits last week.

In these emotional times, we in the crypto community find ourselves having to defend our technology from well-intentioned but misguided efforts by politicians to impose new regulations on the use of strong cryptography. I do not want to give ammunition to these efforts by appearing to cave in on my principles. I think the article correctly showed that I'm not an ideologue when faced with a tragedy of this magnitude. Did I re-examine my principles in the wake of this tragedy? Of course I did. But the outcome of this re-examination was the same as it was during the years of public debate, that strong cryptography does more good for a democratic society than harm, even if it can be used by terrorists. Read my lips: I have no regrets about developing PGP.

The question of whether strong cryptography should be restricted by the government was debated all through the 1990's. This debate had the participation of the White House, the NSA, the FBI, the courts, the Congress, the computer industry, civilian academia, and the press. This debate fully took into account the question of terrorists using strong crypto, and in fact, that was one of the core issues of the debate. Nonetheless, society's collective decision (over the FBI's objections) was that on the whole, we would be better off with strong crypto, unencumbered with government back doors. The export controls were lifted and no domestic controls were imposed. I feel this was a good decision, because we took the time and had such broad expert participation. Under the present emotional pressure, if we make a rash decision to reverse such a careful decision, it will only lead to terrible mistakes that will not only hurt our democracy, but will also increase the vulnerability of our national information infrastructure.

PGP users should rest assured that I would still not acquiesce to any back doors in PGP.

It is noteworthy that I had only received a single piece of hate mail on this subject. Because of all the press interviews I was dealing with, I did not have time to quietly compose a carefully worded reply to the hate mail, so I did not send a reply at all. After the article appeared, I received hundreds of supportive emails, flooding in at two or three per minute on the day of the article.

I have always enjoyed good relations with the press over the past decade, especially with the Washington Post. I'm sure they will get it right next time.

The article in question appears at http://www.washingtonpost.com/wp-dyn/articles/A1234-2001Sep20.html

-Philip Zimmermann

24 September 2001

(This letter may be widely circulated)

 
To the best of our knowledge, the text on this page may be freely reproduced and distributed.
 

totse.com certificate signatures
 
 
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
Hot Topics