Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

PGP went commercial to deal with lawsuits, but it is still open source.

I would like if someone with more understanding of the situation could outline the risks of allowing PGP to be the only implementation.



PGP is source-available with a proprietary license.[0] It was only ever free to use for non-commercial purposes.

[0]http://www.symantec.com/connect/downloads/symantec-pgp-deskt...


PGP is not open source.

Parts of its source code are viewable and reviewable, associated with key cryptographic functions. Much of what PGP builds is structure around that, and most of that isn't open in any sense of the word.

Phil Zimmerman (who's long since left the building) does understand the value of source review, and the team who supported PGP continued that legacy. But it was quite limited in scope.

That said, PGP also did work with other implementations, including GPG, to resolve compatibility issues -- I'm aware of a few of those personally myself.


Could the unreviewed code be a liability?


His point stands though. GPG never caught on as a commercial product or something that people would pay for. Both are Open Source, that's not the issue.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: