Gnu Privacy Guard relies on one underfunded person (2015)
propublica.org
propublica.org
An idea (not a serious one, but a point for discussion): in civil society we have a government that collects taxes that are used to fund the vital infrastructure that allows the society to function. How about if all ISPs were to charge a very small levy to customers? This levy would go to an independent and neutral body to be used to pay for the salaries of those who are creating the internet infrastructure we all rely upon.
Obviously there would be many problems with trying to implement such a system across the entire world. Worth discussion though?
P.S. I have no doubt that this idea has probably already been thought of and discussed before. There is nothing new under the sun :-)
[edit: fixed fat finger typo.]
At least in the US, we know we can't trust the ISPs to "do the right thing". Maybe things are different elsewhere but I cannot support this idea in the US. Sorry.
You're talking about possibly the scummiest, least moral companies in the global tech industry.
How about levying such a tax on ISPs themselves? They're the ones making a profit off of the infrastructure you're talking about.
Now, everybody is doing his share, most of us are a bit altruist and a bit gifted in a way or in another. It's a question of scale.
It is wild to me that US intelligence is sincerely scared of their sources "going dark". I've never gotten over just how asymmetric the conflict is, and how much first-class privacy software gets written for little or no money.
We have a national PKI for doctors that could have been, but isn't, used for S/MIME. Missed opportunity.
I asked a ca about s/mime pricing - on its own they have a 50x3yr minimum purchase. They offered to waive the minimums if I combined with a regular server cert purchase.
After their shitbird response to LetsEncrypt, I'd rather pay someone else than use their "free" option.
Edit: for those who didn't follow it at the time, this sums it up: https://arstechnica.com/tech-policy/2016/06/800-pound-comodo...
https://www.youtube.com/watch?v=Z7Wl2FW2TcA&feature=youtu.be...
I feel like a fool for not being hip to this.
I'm not aware of any other pgp implementations besides the original.
https://www.fordfoundation.org/library/reports-and-studies/r...
Another reminder that selling goods and services in exchange for money still works better than giving things away and hoping somebody gives you a donation.
$60,000 from Linux Foundation's Core Infrastructure Initiative (one-time)
$137,000 in donations (one-time)
$50,000 a year from Facebook (recurring)
$50,000 a year from Stripe (recurring)
I think he got more than one year's salary in one-time funding alone, plus he's got a "salary" of $100,000/yr from Facebook and Stripe together.
At least he won't be starving now. But it would not be a bad thing if someone threw some more money at it, or someone assembled a small team to help out, or something.
Edit: saw in comment below there is a team on it. Good stuff.
We need to urgently find a sustainable way for individuals to support open source developers or accountability and relationship with end users will continue to diminish.
There must also be ways to gently encourage successful startups to contribute as now it seems they use a whole bunch of open source software and simply forget about it once successful, which is not a sutainable model.
The problem is, had he tried to sell GPG, I doubt many people would be using it now...
In contrast to say openssh which everyone uses.