June 26, 2009

Internet crimes to be proud of

Thanks to Pretty Good Privacy encryption creator Phil Zimmermann for software that undermines suppression -- and for keeping me out of jail

By 1994, even I recognized the importance of PGP to all freedom-loving peoples. In my youthful exuberance, I was enraged that Zimmermann, who I had personally e-mailed a few times, was being accused of being an American traitor. I came up with a scheme, that upon reflection, was either incredibly ballsy or can only be attributed to adolescent arrogance. My plan was to intentionally violate the U.S. federal statues against distributing encryption programs to foreign governments. This was a charge that Mr. Zimmermann had craftily and legally avoided for good reason.

I was going to create a Web site that would allow any visitor to easily send a copy of PGP to a random foreign e-mail address recipient with a carbon copy of the transfer automatically sent to the White House, along with a protest letter. My idea was to get millions of visitors to violate our "stupid" software encryption laws on purpose and see how the U.S. Justice Department could handle a million violations. My fantasy included the government realizing how ignorant it was, forcing it to change the laws, and to drop the charges against Zimmermann.

[ See what Roger Grimes thinks of President Obama's plan for Internet security | Learn how to secure your systems with Security Adviser newsletter. ]

Pretty bad protest
This wasn't just a silent fantasy. I had created the bare bones of the Web site and contacted Newsweek magazine. I had been profiled in a March 1992 issue regarding the popular Michelangelo virus and the newly emerging Dark Avenger's polymorphic virus mutation engine, and I'd established friendly inside contacts. The magazine's computer and science associate editor loved my idea and promised to give it coverage.

I even understood the potential legal consequences of my actions. I knew I could end up in jail or, at the very least, wasting a lot of money in my defense. I had told my new wife and mother of my first daughter of my idea and the possible consequences. As you can imagine, she was not very supportive of my risking my good job, our house, and our comfortable life. But I was that emotionally driven. At the time I was fond of quoting, "You can take my right to privacy out of my cold, dead hands!" This from a guy who's never held a gun.

Although the exact details are a bit hazy now, I remember nervously dialing Zimmermann for the first time, with the Newsweek editor listening in. I knew getting Zimmermann's support would lock in the magazine's commitment and get me the publicity I would need to get large numbers of visitors willing to join me in my privacy fight.

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »
balfson 26-Jun-09 9:03am
I don't disagree, but there are limits. When operators of a tor cite budgetary reasons for refusing to police advance-fee fraud, my impression of the gallantry of their efforts changes.
GreeneConsulting 26-Jun-09 5:16pm
Phil Zimmerman PgP program was the fist to show that encryption is so badly need the internet grew up. Now I can think of not having it running to secure a system . when I start using PGP it was on many system and we found some off shoots called PGP Stealth(no made by Phil) that program rocked but was only on the Amiga for short time you could dump a PGP file into another file and to re-call it with justuse PGP the key. It did show up for the PC for bit but its writer just stopped with updates. so Phil Zimmerman Thank you for making us see the need getting people make better security systems . with out your work many of us would not be working in computer today.
aaugh 3-Jul-09 10:30pm
Things are never quite so black-and-white. Crypto software, like any tool, can be used for good or bad. It can help the cause of freedom and legitimate business, but it can also be used conceal criminal and terrorist activities.

Sign up to receive InfoWorld Resource Alerts

Subscribe to the Today's Headlines: First Look Newsletter

Find out what will be news for the day, with our first-thing-in-the-morning briefing.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2009 Infoworld, Inc.