Threat Picture
Latest Cybersecurity News

Phil Zimmermann: Giving Away PGP and Facing an Export Probe

He released encryption software so ordinary people could protect their messages. Its spread overseas brought a federal investigation.
By Charles Joseph · Updated
Share
Share
Copy URL

In June 1991, Phil Zimmermann gave away a piece of software, and it made him the target of a three-year federal criminal investigation.

The software was Pretty Good Privacy, the program that put strong public-key encryption in the hands of anyone with a PC and a modem. The government treated it like a weapon, because under the export rules of the day it was one.

Customs investigated him for trafficking in munitions. The NSA, by one retired insider's account, worried that his source code would teach the world how to build strong crypto. Both were right about what PGP would do, and neither could stop it.

Phil Zimmermann at a Glance

  • Zimmermann earned a computer science degree from Florida Atlantic University in 1978 and spent two decades as a software engineer, with a side interest in military policy that turned him into a privacy activist.
  • Alarmed by a 1991 anticrime bill that'd have required back doors in communications equipment, he finished PGP in a hurry and had friends upload it to the internet on June 6, 1991.
  • PGP 2.0 followed in September 1992 in ten languages, with the web-of-trust model that helped make it the most widely used email encryption in the world.
  • Because PGP spread overseas, US Customs opened a criminal investigation into him for violating arms-export law; MIT Press printed the source code as a book in 1995.
  • On January 11, 1996, the US Attorney's office in San Jose closed the case without charges; Zimmermann founded PGP Inc. and testified to the Senate that June.
  • Network Associates bought PGP Inc. in December 1997; he stayed three years as a senior fellow and left in February 2001, publicly vouching that PGP had no back doors.
  • Since 2004 he's worked on encrypted phone calls, creating the ZRTP protocol and Zfone and co-founding Silent Circle, maker of Silent Phone.
  • Inducted into the Internet Hall of Fame in 2012, he's now associate professor emeritus at Delft University of Technology in the Netherlands.
Sponsored

The Life of Phil Zimmermann

Before PGP

Zimmermann took his bachelor's degree in computer science from Florida Atlantic University in 1978 and went to work as a software engineer. Over the next two decades he specialized in cryptography, data security, data communications and real-time embedded systems.

What set him apart from other engineers was politics. By his own account, his interest in the political side of cryptography grew out of a background in military policy issues, and by the end of the 1980s he'd come to see strong encryption as a tool for ordinary people against governments, not the other way round.

Senate Bill 266

In 1991 the US Senate took up an omnibus anticrime bill, S. 266, with a clause that'd have required makers of secure communications equipment to build in "trap doors" so the government could read encrypted messages. Civil libertarians and industry protested, and the provision died.

Zimmermann didn't wait to find out. He finished PGP, sent it to a couple of friends for distribution, and on June 6, 1991, Pretty Good Privacy 1.0 was uploaded to the internet, free for anyone to use.

His essay "Why I Wrote PGP" laid out the argument in one line: "If privacy is outlawed, only outlaws will have privacy." If enough ordinary citizens used strong crypto, he reasoned, it'd be much harder for any government to make it illegal.

Volunteers piled in. In September 1992, PGP 2.0 shipped in ten languages on several platforms, with much stronger cryptography and the distributed "web of trust" model that let strangers vouch for each other's keys. It became the most widely used email encryption software in the world, with no company, no staff and no budget behind it.

Sponsored

The Munitions Case

PGP spread around the world within days, and the United States classified cryptographic software as a munition. In 1993 the US Customs Service opened a criminal investigation into Zimmermann for violating the Arms Export Control Act.

For three years he lived under the threat of indictment. He wanted PGP used for human rights work in places where people needed protection from their own governments, but he couldn't say so out loud, because it'd have helped a prosecutor prove intent.

Supporters found a loophole. In 1995 MIT Press published PGP Source Code and Internals, the complete program printed as a book, because paper was protected by the First Amendment in ways floppy disks weren't.

On January 11, 1996, Assistant US Attorney William Keane in San Jose wrote to Zimmermann's lawyer that his client "will not be prosecuted in connection with the posting to USENET in June 1991 of the encryption program Pretty Good Privacy. The investigation is closed." NPR carried the news the next morning.

PGP Inc. and the Senate

Zimmermann founded PGP Inc. the same year, and on June 26, 1996, he appeared before a Senate subcommittee as the chairman and chief technology officer of a "newly-formed company" to argue for loosening export controls.

The investigation had only helped, he told the senators: PGP had "spread organically all over the world" and become the de facto standard for email encryption, winning industry awards along the way.

In December 1997, Network Associates acquired PGP Inc. Zimmermann stayed on for three years as a senior fellow to guard PGP's cryptographic integrity, but when new management decided in late 2000 to publish less of the source code, he left. His farewell note of February 19, 2001 assured users that every version through PGP 7.0.3 was free of back doors.

A new PGP Corporation bought the product back from Network Associates in August 2002, with Zimmermann as special advisor, and held it until Symantec acquired the company in 2010. By then the war was over: the US export restrictions had collapsed in 2000.

Zfone and Silent Circle

In 2004 Zimmermann turned to a new problem: phone calls over the internet. He designed ZRTP, a protocol that lets two phones agree on an encryption key without any server holding a copy, and built Zfone to prove it worked.

He unveiled the project at DEF CON in 2005, and ZRTP went on to power Silent Phone, the encrypted calling and messaging app from Silent Circle, the secure communications company he co-founded. The company also put its name on Blackphone, a handset built for privacy.

By 2014 he was back at DEF CON with a talk titled "How to Get Phone Companies to Just Say No to Wiretapping," which is about as subtle as Zimmermann gets.

Sponsored

Stories From the Field

The stories Zimmermann likes best come from outside the United States. PGP helped enable the safe evacuation of 8,000 civilians during the Kosovo conflict, and human rights groups used it to document war crimes in Guatemala and to protect witnesses from reprisals.

At the 2014 National Cyber Security Hall of Fame ceremony, a man from the human intelligence community approached him to say that colleagues of his were alive because of PGP.

And in 2004 Robert Morris Sr., retired from the NSA, told him what the agency had actually feared in 1991: not PGP itself, but its source code, which would show a lot of people how to write strong public-key crypto, and the skills would proliferate.

Awards and the Netherlands

The awards came early and kept coming: the EFF Pioneer Award and the Chrysler Award for Innovation in Design in 1995, the Norbert Wiener Award in 1996, Privacy International's Louis Brandeis Award in 1999.

The Internet Society put him in the inaugural class of its Internet Hall of Fame in 2012, the National Cyber Security Hall of Fame inducted him in 2014, Foreign Policy named him a leading global thinker the same year, and the Université Libre de Bruxelles gave him an honorary doctorate in 2016.

Along the way he moved his academic life to the Netherlands, where he's associate professor emeritus of cybersecurity at Delft University of Technology.

Zimmermann Today

On June 6, 2021, Zimmermann marked PGP's 30th anniversary with an essay on his site. "Here we are, three decades later, and strong crypto is everywhere," he wrote. "What was glamorous in the 1990s is now mundane."

His own work has shifted to end-to-end secure telephony and text messaging, and he still consults, as his site puts it, "on matters cryptographic." The email address at the bottom of his biography still ends in mit.edu.

Sponsored

Phil Zimmermann: Pretty Good, As It Turned Out

Zimmermann called his program Pretty Good Privacy because he didn't want to oversell it. It turned out to be good enough to change the law.

The decade of crypto wars that PGP started ended with every Western democracy dropping its restrictions on strong encryption, and today the browser, the banking app and the messaging app all do what PGP did, without anyone noticing.

He never got his day in court. Instead, the idea behind his 1991 release became ordinary: people could protect their own private conversations.

QUOTE:

"Amateurs hack systems, professionals hack people."