Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Matthew Green, who sits on the CII's advisory board, tweeted:

"CII does what's beneficial to its members. Privacy tools aren't" [https://twitter.com/matthew_d_green/status/56338899320386764...]

...which indicates to me that GnuPG wasn't sold properly. It's not just a "privacy tool" -- it's one of the ways that software (including OpenSSL) is securely distributed. I would guess that quite a few of the CII's members benefit from GnuPG and don't even realize it.



In what world are privacy tools not beneficial to the CII? And how does OpenSSL not fall under "privacy tool"??


GPG's goal is about privacy, while OpenSSL is more of a toolbox with most of the tools you need for anything crypto-related.

I imagine those people need to control integrity of the software, to make sure it is deployed correctly on their servers and distributed securely to their clients and users, and OpenSSL has all they need for that. Privacy, OTOH, is unneeded because they are not (or rather much less) after their own or their users' privacy.


CII is a consortium of consumers of free software, not publishers. If openSSL meds gpg, openssl should spend its funding on gpg.

Perhaps via a "Free Core Infrastructure Initiative"




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: