skiewiel meldde ons dat op de nederlandse security website staat dat de broncode van PGP wordt vrijgegeven. Het gaat hier om de laatste versie van het programma dat door Network Associates wordt ontwikkeld.
"PGP Security strongly believes that it is critical for the cryptographic community to be able to evaluate the cryptographic implementation behind our security products", said Mark McArdle, vice president of Engineering for PGP Security. "This release of the PGPsdk source code delivers on our commitment to provide access to the most sensitive components of our security products, which is key to maintaining the strong reputation PGP Security has world-wide." [break] Opvallend is, dat deze stap genomen wordt vlak na de publicatie (op 5 september) van de resolutie van de Europese Commissie met betrekking tot Echelon: [/break]
30. Calls on the Commission and Member States to promote software projects whose source text is made public (open-source software), as this is the only way of guaranteeing that no backdoors are built into programmes;
31. Calls on the Commission to lay down a standard for the level of security of e-mail software packages, placing those packages whose source code has not been made public in the "least reliable" category;
32. Calls on the European institutions and the public administrations of the Member States systematically to encrypt e-mails, so that ultimately encryption becomes the norm; [break] Voordat de broncode ingezien mag worden moet wel eerst een licentieovereenkomst geaccepteerd worden, en deze is behoorlijk strikt: zo mogen gevonden bugs niet bekend worden gemaakt zonder toestemming van Network Associates: [/break] 2. Restrictions. Except as otherwise provided herein, you may not, without prior written permission from NAI:
[...](vi) Provide, or otherwise disclose information regarding any discovered bugs, errors, architecture issues or problems with the Source Code or Compiled Code to any party other than Network Associates, or disclose the results of any benchmark test any third parties without Network Associates' prior written consent.
Het vrijgeven van broncode wordt de laatste tijd steeds populairder, het mechanisme dat door Network Associates wordt gebruikt lijkt sterk op de shared-source filosofie van Microsoft.