The Key to Everything: How RSA, GCHQ, and a Colorado Programmer Built — and Nearly Lost — the Right to Private Conversation
Prologue
For nearly all of human history, secrecy had one immovable rule: to talk privately with someone, you first had to meet them and agree on a shared secret. That single constraint — the key distribution problem — shaped cryptography from Caesar’s shift ciphers through Enigma. Then, across roughly a decade in the 1970s, three separate groups of people broke that rule independently, in three completely different settings: a classified British intelligence agency that told no one, a pair of restless American academics who published everything, and a trio of MIT professors who turned an all-night dorm-room insight into a global company. What happened next involved a federal grand jury, a gagged professor threatened with prison for describing his own invention, T-shirts deemed illegal munitions, and a program written by a broke Colorado consultant that the United States government seriously investigated as an act of international arms trafficking.
This is the full story — the mathematics, the money, the patents, and the price several of the people involved personally paid for it.
The Problem: A Padlock With No Way to Share the Key
Every cipher before the 1970s was symmetric: one key both locked and unlocked a message. That’s manageable between people who can meet in person. It collapses the moment you want to email a stranger, buy something from a merchant you’ve never met, or run a banking network spanning continents — because somebody still has to transmit that one shared key across a channel that, by definition, isn’t secure yet.
By the late 1960s this looked less like an inconvenience and more like a hard ceiling on what computers could ever do safely. The people who broke through it did so almost simultaneously and in near-total isolation from one another — which is exactly why this story has three separate beginnings.
Act One (Secret): GCHQ, Cheltenham, 1969–1974
At Britain’s Government Communications Headquarters, a mathematician named James Ellis had spent years turning over an old, wartime-era Bell Labs paper on protecting the secrecy of voice communications. In 1969, he sketched a genuinely strange theoretical idea he called “non-secret encryption”: it should be mathematically possible to encrypt a message using information that never needed to be kept secret at all, as long as decrypting it required a separate, private piece of information that only the recipient held. Ellis could prove this was mathematically consistent. He had no idea how to actually build it, and the problem sat unsolved at GCHQ for four years.
In 1973, a 22-year-old, Cambridge-trained mathematician named Clifford Cocks joined GCHQ’s cryptography section. In his very first week, a colleague mentioned Ellis’s dormant puzzle to him — reportedly as a kind of warm-up exercise for the new hire. Cocks, who had a strong background in number theory, went away and, within roughly half an hour, worked out a scheme built on the difficulty of factoring the product of two large prime numbers. Mathematically, it is the same idea the world would come to know, four years later, as RSA.
Shortly afterward, a second GCHQ mathematician, Malcolm Williamson, independently worked out a method for two parties to agree on a shared secret over a channel anyone could be listening to — mathematically equivalent to what the public world would eventually call Diffie–Hellman key exchange.
None of it went anywhere. GCHQ judged the computing hardware of the day too weak to make the idea practical, and — more importantly — an intelligence agency does not advertise a capability like this. Ellis, Cocks, and Williamson received no patents, no public credit, and no announcement. Their work stayed classified for 24 years, unknown even to the American researchers about to reinvent it in full public view.
Act Two (Public): Diffie, Hellman, and “New Directions in Cryptography”
Three thousand miles away and with no knowledge of GCHQ’s buried discovery, a restless, itinerant computer scientist named Whitfield Diffie had become fixated on the same key-distribution problem — driven partly by a broader conviction that privacy was a civil liberty worth defending in the computer age. He partnered with Martin Hellman, a Stanford electrical engineering professor, and the two of them — building on parallel, independent work by Hellman’s graduate student Ralph Merkle on public key distribution — worked out that a key could be split into two mathematically linked halves: one public, one private.
They presented the idea at the International Symposium on Information Theory in June 1976 and published it that November as “New Directions in Cryptography” in IEEE Transactions on Information Theory, opening with a line that has outlived almost everything else written about cryptography that decade: “We stand today on the brink of a revolution in cryptography.” The paper didn’t hand the world a complete cipher — it described the concept of public-key cryptography and the specific mechanism now known as Diffie–Hellman key exchange, letting two strangers agree on a shared secret in full view of any eavesdropper.
It detonated inside the small world of academic cryptography. It was also, unbeknownst to nearly everyone reading it, the second time in seven years this basic idea had been discovered.
Act Three: A Passover Seder and the Birth of RSA
Diffie and Hellman had described what public-key cryptography should do, but not a complete, general-purpose cipher to actually do it. Three researchers at MIT set out to build one: Ron Rivest and Adi Shamir, both computer scientists, and Leonard Adleman, a mathematician. Their working method had an almost comic division of labor — Rivest and Shamir proposed candidate one-way functions, and Adleman’s entire job was to try to break them. Accounts of exactly how many failed schemes they burned through vary — most say somewhere in the high 30s to low 40s, with 42 the figure most often cited.
The breakthrough arrived, as the best origin stories tend to, almost by accident. After a Passover Seder in April 1977, and having had a fair amount of wine, Rivest couldn’t sleep. He lay on his couch with a math textbook and started turning the problem over in his head; by daybreak he had worked out the essential mechanism of what became RSA — a system whose entire security rests on a simple asymmetry: multiplying two enormous prime numbers together is computationally trivial, while factoring the resulting product back into those two primes is, as far as anyone has ever proven, brutally hard.
How it actually works, in brief: pick two large primes, p and q, and multiply them to get a modulus n. Choose a public exponent e; derive a private exponent d such that e·d ≡ 1 (mod φ(n)), where φ is Euler’s totient function. The pair (n, e) becomes the public key; (n, d) stays private. Encryption is just modular exponentiation — c = mᵉ mod n — and decryption reverses it — m = cᵈ mod n. Anyone can encrypt with the public key; only someone holding d can invert it. Break the system by factoring n back into p and q, and the whole scheme falls apart — which is why key length matters so much in practice. Early RSA implementations used moduli in the low hundreds of bits; modern practice uses 2,048- to 4,096-bit keys, and the eventual advent of large-scale quantum computers running Shor’s algorithm is the one theoretical threat that could break the underlying factoring assumption entirely.
The trio published the result in 1977–78, taking the algorithm’s name from their initials: Rivest–Shamir–Adleman. True to academic instinct, they gave the idea away freely — Martin Gardner even wrote it up for a general audience in his Scientific American column that August, and a fuller technical paper, “A Method for Obtaining Digital Signatures and Public-Key Cryptosystems,” followed in Communications of the ACM in February 1978. It was MIT’s own patent office, not the three researchers, that decided the work should be patented under the terms of the university’s federal research funding. The application was filed on December 14, 1977, and U.S. Patent 4,405,829 — “Cryptographic Communications System and Method” — was granted on September 20, 1983.
None of the three had any idea that Clifford Cocks had already found essentially the same mathematics inside GCHQ, four years earlier, in half an hour, as an onboarding exercise.
Act Four: The Government Fights Back (1977–1978)
Here is the part of the story that rarely survives the short version: almost the instant public-key cryptography escaped into the open academic literature, the American national-security apparatus tried to force it back into the vault — and came close to treating its inventors as criminals for the act of describing their own research out loud.
The Meyer letter. In July 1977, as Hellman and his students prepared to present follow-up work at that October’s International Symposium on Information Theory, a letter reached the Institute of Electrical and Electronics Engineers (IEEE) from a man identified only as J. A. Meyer. It warned that publishing cryptography papers without prior government clearance might violate the Arms Export Control Act and the International Traffic in Arms Regulations (ITAR) — the same legal regime that controls the export of tanks, missiles, and nuclear technology. The letter didn’t name Hellman outright, but it specifically cited the exact issues of IEEE Transactions on Information Theory and Computer magazine that carried his papers, and it warned darkly that “these modern weapons technologies, uncontrollably disseminated, could have more than academic effect.” Reporters at Science magazine soon discovered that Meyer was not simply a concerned member of the public — he was an employee of the National Security Agency.
The effect was immediate and personal. On the advice of Stanford’s general counsel, it was Hellman himself — not his graduate students Ralph Merkle and Steve Pohlig, who had done much of the actual work — who stood up to deliver the conference talk, specifically to shield the more legally vulnerable younger researchers. Hellman later summed up the period bluntly: “there was a time there when it was pretty dicey.” NSA director Bobby Inman publicly denied the agency had directed Meyer to write the letter, calling it a personal initiative — yet internal NSA records later released under FOIA showed the agency actively debating, at exactly this time, whether to push for legislation requiring government pre-clearance of academic cryptography papers. Inman’s eventual compromise was a “voluntary” prepublication review system for crypto research; distrusted by the very community it targeted, it reportedly never attracted enough participants to function and quietly collapsed.
The Davida gag order. The same year produced an even starker case a few states away. George Davida, a cryptography researcher at the University of Wisconsin–Milwaukee, filed a patent application in October 1977 (through a university-affiliated foundation) for a stream-cipher device built with National Science Foundation funding. On April 21, 1978, the U.S. Patent Office — acting on the NSA’s recommendation — issued a formal secrecy order against Davida’s application under the Invention Secrecy Act of 1951. Its language was blunt: Davida was “hereby notified” that his application contained material whose “unauthorized disclosure… might be detrimental to the national security,” and he was ordered “in nowise to publish or disclose the invention” to anyone not already aware of it — on pain of a $10,000 fine and up to two years in prison. No justification was offered. No appeal process existed. The order didn’t even identify which agency had made the classification decision.
Davida refused to comply quietly. He took the story to the press, and his university’s chancellor, Werner Baum, publicly denounced the order as a violation of academic freedom. Facing sustained media coverage and pressure from Davida’s congressional representative, the NSA backed down: the order on his patent was rescinded around June 1978, with the agency’s internal rationale amounting to little more than “the dangers of harm to the national security were less severe than originally perceived.” A nearly identical secrecy order, slapped that same month on an unrelated voice-scrambler patent (the “Phasorphone,” invented by four other engineers), was lifted on October 11, 1978, after those inventors ran the identical media playbook. Davida spent much of the rest of his career as an outspoken critic of NSA policy, and the episode became a kind of founding parable inside the early cypherpunk community: the agency’s leverage over researchers depended entirely on secrecy and quiet compliance, and it evaporated the instant someone made noise.
Rivest, Shamir, and Adleman were never personally hit with a secrecy order over the RSA patent — but they filed it into an environment where, within the previous year, the same agency had informally tried to intimidate one group of public-key researchers into silence and had formally gagged another under criminal penalty. It’s a meaningful part of why RSA’s inventors moved to publish as widely and quickly as they did, rather than sit on the result.
The Business of Secrets: RSA Data Security, Inc.
In 1982, Rivest, Shamir, and Adleman started a company — reportedly out of Adleman’s apartment — to commercialize their patent: RSA Data Security, Inc. For years it barely survived; RSA’s arithmetic was too computationally heavy for the personal computers of the era, and the company came close to folding entirely.
According to the company’s own later accounts, government resistance to RSA started almost immediately. The Commerce Department had shown early interest in adopting RSA as an official U.S. encryption standard — until, RSA said, the NSA quietly persuaded Commerce to sever the relationship, wary of ceding ground on a cryptosystem it didn’t control. Jim Bidzos joined the company on February 1, 1986, and soon took over as CEO of a firm he later described as having “no products, no customers, and no revenue,” and turned it into a genuinely combative commercial and political operator — licensing the algorithm to companies like Lotus and taking the fight to Washington directly.
That fight reached its peak in April 1993, when the Clinton administration unveiled the Clipper Chip: a government-designed encryption chip for telephones with a built-in back door, so that a “key escrow” mechanism would let law enforcement decrypt any conversation on demand. Bidzos treated it as an existential threat to the entire idea of unescrowed cryptography, and was quoted at the time — via contemporaneous secondhand accounts rather than a single verifiable on-the-record interview — describing Clipper as “an arrow aimed at the heart of my company.” He led an industry campaign warning businesses to reject any product shipping with government-mandated key escrow, using the phrase “Big Brother inside” — language that cypherpunk activists ran with independently, producing stickers and lapel buttons that mimicked Intel’s “Intel Inside” logo and circulated through Silicon Valley by the thousands.
Separately, and just as consequentially, U.S. export-control law — enforced under the identical ITAR framework that would soon be turned on Phil Zimmermann — capped the strength of cryptography American companies were legally permitted to sell overseas. RSA and its licensees were forced to ship deliberately weakened, shorter-key “export-grade” versions of their own software abroad. Decades later, some of those same artificially crippled ciphers came back to haunt the modern internet in the form of vulnerabilities like FREAK and Logjam — security holes that existed only because 1990s-era export law had mandated that certain products be built breakable by design.
RSA Data Security’s own patent-enforcement reflexes, meanwhile, were about to collide head-on with an idealistic programmer trying to give the algorithm away for free.
Enter Phil Zimmermann: Pretty Good Privacy
Philip Zimmermann was a software engineer and longtime anti-nuclear activist based in Boulder, Colorado, who had spent years thinking hard about what everyday digital life would look like if every email and file could be swept up and stored by governments indefinitely. His answer — developed on his own time, with no company and no institutional funding behind him — was Pretty Good Privacy (PGP), released for free on the internet in June 1991. It gave ordinary people access to the same strength of encryption previously available mainly to governments, militaries, and large corporations.
The financial toll started before the government ever showed up. By Zimmermann’s own account, he missed five mortgage payments in the first half of 1991 just to finish the software, and his independent consulting business — his actual income — suffered while he spent months buried in roughly 11,000 lines of code. He then released the finished product for nothing.
PGP used RSA for its public-key operations. Zimmermann had not licensed the patent. He later explained that he rushed the release partly because a U.S. Senate bill under discussion at the time appeared to threaten mandatory government back doors in encryption products — he wanted strong cryptography in the public’s hands before that window closed. Within months, volunteers around the world had mirrored, translated, and improved it. Zimmermann had, in effect, distributed a piece of software the U.S. government classified as a weapon.
The Collision: Patents, Munitions, and a Federal Grand Jury
Two separate legal problems now converged on one small, free program.
First, patent infringement. RSA Data Security considered PGP’s unlicensed use of its algorithm a straightforward violation, and publicly branded the program “banditware” — a reputational shot aimed at recasting a privacy advocate as a common thief. The licensing dispute simmered for years.
Second, and far more serious: export control. Under the Arms Export Control Act and ITAR, the U.S. government treated sufficiently strong cryptographic software as a literal munition, legally comparable to exporting tanks or missiles. Once PGP had spread overseas via the internet, U.S. Customs opened a criminal investigation into Zimmermann personally, on the theory that he had illegally exported munitions.
In February 1993, two U.S. Customs agents arrived at Zimmermann’s home in Boulder to question him — initially, by his account, without confirming he was the actual target of the inquiry. He was. A federal grand jury was empaneled in San Jose, California, under the U.S. Attorney’s Office for the Northern District of California, to weigh charges under the Arms Export Control Act, on the theory that posting PGP to a domestic Usenet newsgroup made Zimmermann responsible for its subsequent, unauthorized spread abroad by people he’d never met. He faced a maximum penalty of five years in prison and a $1 million fine — for a program he had given away.
The investigation dragged on for three years, with no charges ever filed and no resolution offered — an open-ended legal threat Zimmermann simply had to live under. He assembled a defense team of six lawyers (Phil Dubois, Ken Bass, Eben Moglen, Curt Karnow, Tom Nolan, and Bob Corn-Revere), and — lacking any corporate backing — relied on a public Zimmermann Legal Defense Fund, funded by donations from the same global community of PGP users who now had a direct stake in whether the software’s author went to prison. The Electronic Frontier Foundation and other civil-liberties groups treated the case as a bellwether for a much larger question: could writing and publishing software be prosecuted as arms dealing?
The era produced some of the strangest artifacts in the history of computing. Cryptographers protested the export rules by printing tiny RSA implementations — in some cases just a few lines of Perl — on T-shirts, since printed text only qualified as a controlled “defense article” if it was in “machine-readable form”; a few activists pointedly added scannable barcodes just to press the point. Zimmermann and MIT Press went further still: in 1995 they published the entire PGP source code as a printed, 600-page book, betting that the First Amendment protected the printing of text — including source code — even though exporting the identical bits on a floppy disk was illegal. The implicit argument was elegant: if Zimmermann was an unlicensed arms exporter, so was one of the country’s leading research universities, for the act of publishing a book.
The Personal Toll: What Three Years Under Investigation Actually Cost Zimmermann
The dry legal summary — “a three-year investigation, eventually dropped” — badly understates what this actually did to one person’s life.
He was attacked on two fronts simultaneously. The same season that Customs agents showed up at his front door, RSA Data Security’s “banditware” label was doing its own damage, trying to convert a privacy advocate into a reputational villain. Zimmermann had to fight a patent-infringement narrative and a federal criminal investigation at the same time, with no company standing behind him on either front.
The legal bills nearly broke him. With no employer and no institutional backing, Zimmermann personally had to fund a defense that stretched to six attorneys over three years. By multiple accounts the costs ran into the hundreds of thousands of dollars — money he didn’t have, which is precisely why total strangers who simply used his software had to crowdfund his defense. That a private citizen needed public donations to avoid prison for writing and freely publishing a piece of software was, to the civil-liberties organizations that rallied around him, the actual story.
He had to muzzle his own explanation of his own motives. One of the more corrosive effects of a live criminal investigation is what it does to your ability to explain yourself honestly. Zimmermann later said he had genuinely wanted PGP to reach dissidents, journalists, and human-rights workers living under repressive governments around the world — but he couldn’t say so publicly while under investigation, because expressing a wish for the software to cross borders would have handed prosecutors direct evidence of the “intent to export” they needed to build a case. For three years, the actual author of PGP had to stay quiet about his own reasons for writing it, precisely because honesty would have been used against him.
The absurdity peaked in October 1993, when Zimmermann was invited to testify before a House subcommittee on cryptography export-control policy — meaning he spent an afternoon formally advising Congress on the exact rules a federal grand jury was, at that same moment, actively weighing whether he had broken.
And when it finally ended, there was no vindication — only silence. In mid-January 1996, his lead attorney received a one-paragraph fax: the U.S. Attorney’s Office for the Northern District of California had decided Zimmermann “will not be prosecuted… The investigation is closed.” The office added only that “no further comment will be made… on the reasons for declination.” No apology. No explanation. Three years of financial strain, reputational attack, and constrained speech ended with the government simply walking away and saying nothing further, leaving Zimmermann to rebuild his finances and, months later, found a company from scratch. If there was a silver lining, it was a bitterly ironic one: the publicity from being investigated as a suspected arms trafficker only made more people around the world curious about the software he had written — the persecution likely accelerated PGP’s fame, and the broader cause of civilian cryptography, faster than quiet obscurity ever would have.
Resolution: A License, a Near-Bankruptcy, and a Sale
The two disputes untangled on different timelines, in different ways.
The patent dispute was resolved when Zimmermann’s team shipped PGP 2.6 in 1994, rebuilt against RSAREF — a reference implementation of RSA that RSA Data Security licensed for free, noncommercial use, legitimizing the algorithm’s use domestically. (International versions of PGP, where the U.S. patent held no force, simply used other RSA-compatible code and were never part of the licensing dispute.)
The criminal investigation ended, as described above, in mid-January 1996. Zimmermann founded PGP Inc. shortly afterward to sell a commercial version of the software — a company that, by some accounts, then burned through roughly $17 million in venture funding in its first year alone and came within about three weeks of declaring bankruptcy before Network Associates (the security company later renamed McAfee) acquired it on December 9, 1997, for an aggregate consideration of approximately $36 million in cash, assumed liabilities, and warrants. Separate patent-licensing litigation between RSA and Network Associates over the PGP business continued to rumble on for a few more years after that.
The Twist Nobody Knew About Until 1997
For the entirety of the public saga above — Diffie and Hellman’s paper, the MIT trio’s Passover epiphany, the RSA patent fight, Zimmermann’s prosecution — almost nobody outside a narrow circle inside British intelligence knew that Ellis, Cocks, and Williamson had already worked out the underlying mathematics at GCHQ years earlier. GCHQ finally declassified their work in December 1997, just months after James Ellis died without ever having received public credit in his lifetime. Malcolm Williamson lived until 2015. Clifford Cocks was made a Companion of the Order of the Bath in 2008 and elected a Fellow of the Royal Society in 2015; in 2010, the GCHQ trio’s discovery was formally recognized as an IEEE Milestone, a distinct honor from the 2002 ACM A.M. Turing Award given to Rivest, Shamir, and Adleman, and the 2015 Turing Award given to Diffie and Hellman for their own independent contributions.
Legacy
The RSA patent expired on September 20, 2000, and the algorithm — by then already embedded inside HTTPS, SSH, and effectively all of internet infrastructure — passed permanently into the public domain. PGP changed hands several more times in the years that followed and evolved into the open OpenPGP standard, still in active use today for encrypted email and code-signing. RSA the company went on to spin out VeriSign as a separate business in April 1995, was itself acquired by Security Dynamics Technologies in July 1996, and remains, under various owners, a major name in enterprise authentication and encryption to this day.
What’s genuinely remarkable, looking back, is how the entire conceptual foundation of modern digital security was produced three separate times in the same narrow window of years — roughly 1969 to 1978 — in three radically different environments: a classified government laboratory that told absolutely no one; a public academic paper that reshaped a field overnight; and a fevered, wine-soaked night of scratch-paper mathematics that became a household acronym. And it took a broke, idealistic programmer in Colorado, a decade later, funded by strangers and threatened with federal prison, to force the actual argument about who gets to use it.
By the Numbers
- 24 years — how long GCHQ’s discovery of public-key cryptography stayed classified (1973–1997)
- ~40–42 — failed candidate schemes Rivest, Shamir, and Adleman reportedly tried before landing on RSA
- $10,000 fine / 2 years in prison — the maximum penalty George Davida faced merely for discussing his own gagged invention
- 5 years / $1,000,000 — the maximum penalty Phil Zimmermann faced for posting free software to Usenet
- 3 years — the length of the U.S. government’s criminal investigation into Zimmermann
- 6 — the number of attorneys on Zimmermann’s defense team
- 600 pages — the length of the printed book MIT Press used to legally export PGP’s source code
- 17 years — the term of the RSA patent (granted 1983, expired 2000)
- $17 million — reportedly burned through by PGP Inc. in its first year of operation
- ~$36 million — the price Network Associates paid to acquire PGP Inc. in December 1997, roughly three weeks before it was reportedly set to declare bankruptcy
- 2,048–4,096 bits — typical RSA key length in modern use, versus the low hundreds of bits common in the algorithm’s earliest implementations
Timeline Synopsis
| Year | Event |
|---|---|
| 1969 | James Ellis (GCHQ) conceives the theoretical concept of “non-secret encryption.” |
| 1973 | Clifford Cocks (GCHQ), in his first week on the job, works out a practical implementation mathematically equivalent to RSA. Classified. |
| 1974 | Malcolm Williamson (GCHQ) works out an equivalent to Diffie–Hellman key exchange. Also classified. |
| 1976 (Jun–Nov) | Whitfield Diffie, Martin Hellman, and Ralph Merkle present and then publish “New Directions in Cryptography,” publicly introducing public-key cryptography. |
| 1977 (Apr) | Ron Rivest, Adi Shamir, and Leonard Adleman devise the RSA algorithm at MIT after a Passover gathering. |
| 1977 (Jul) | NSA employee J. A. Meyer sends the IEEE a letter warning that publishing cryptography research may violate ITAR arms-export law, chilling academic publication. |
| 1977 (Aug) | RSA is described publicly via Martin Gardner’s Scientific American column. |
| 1977 (Oct) | George Davida (Univ. of Wisconsin–Milwaukee) files a patent on a stream-cipher device. |
| 1977 (Dec) | MIT files the RSA patent application. |
| 1978 (Feb) | Rivest, Shamir, and Adleman publish the full technical paper in Communications of the ACM. |
| 1978 (Apr) | On the NSA’s recommendation, the U.S. Patent Office issues a secrecy order gagging Davida from discussing his own invention, under threat of fine and imprisonment. |
| 1978 (Jun) | The Davida secrecy order is rescinded after public and media pressure. |
| 1978 (Oct) | A near-identical secrecy order on the unrelated “Phasorphone” voice-scrambler patent is also lifted. |
| 1982 | Rivest, Shamir, and Adleman found RSA Data Security, Inc. |
| 1983 (Sep) | U.S. Patent 4,405,829 (“Cryptographic Communications System and Method”) is granted to MIT. |
| 1986 (Feb) | Jim Bidzos joins RSA Data Security and soon becomes CEO, driving its commercial and political strategy. |
| 1991 (H1) | Zimmermann misses five mortgage payments self-funding PGP’s development; his consulting business suffers. |
| 1991 (Jun) | Phil Zimmermann releases PGP 1.0 for free on the internet. |
| 1992 (Sep) | PGP 2.0 is released with international volunteer contributions and improved cryptography. |
| 1993 (Feb) | U.S. Customs agents visit Zimmermann’s Colorado home; a grand jury investigation opens. RSA Data Security publicly labels PGP “banditware.” |
| 1993 (Apr) | The Clinton administration unveils the Clipper Chip; Bidzos and RSA lead industry opposition. |
| 1993 (Oct) | While under active criminal investigation, Zimmermann testifies before a House subcommittee on cryptography export-control policy. |
| 1994 | PGP 2.6, built on the licensed RSAREF library, resolves the domestic patent conflict. |
| 1995 | Zimmermann and MIT Press publish the full PGP source code as a printed book to route around export restrictions. |
| 1996 (Jan) | The U.S. Attorney’s Office closes the investigation without filing charges. |
| 1996 | Zimmermann founds PGP Inc. |
| 1997 (Dec) | GCHQ declassifies Ellis, Cocks, and Williamson’s earlier discovery of public-key cryptography. |
| 1997 (Dec 9) | PGP Inc. is acquired by Network Associates for roughly $36 million, weeks before a reported bankruptcy filing. |
| 2000 (Sep) | The RSA patent expires; the algorithm enters the public domain. |
| 2002 | Rivest, Shamir, and Adleman receive the ACM A.M. Turing Award. |
| 2010 | The GCHQ trio’s work is recognized as an IEEE Milestone. |
| 2015 | Diffie and Hellman receive the ACM A.M. Turing Award. |
Further Reading
- Steven Levy, Crypto: How the Code Rebels Beat the Government—Saving Privacy in the Digital Age — the definitive account of the Meyer letter, the Davida secrecy order, and the broader “crypto wars”
- Diffie, W. & Hellman, M. — New Directions in Cryptography, IEEE Transactions on Information Theory, 1976
- Rivest, R., Shamir, A., & Adleman, L. — A Method for Obtaining Digital Signatures and Public-Key Cryptosystems, Communications of the ACM, 1978
- GCHQ’s public pages on James Ellis, Clifford Cocks, and Malcolm Williamson (gchq.gov.uk)
- Zimmermann, P. — PGP: Source Code and Internals, MIT Press, 1995
- Simon Singh, The Code Book — a strong general-audience account of this whole saga
- National Research Council, Scientific Communication and National Security (1982), Appendix E — the contemporary official record of the 1975–1982 disputes between academic cryptographers and the NSA
- Zimmermann’s own account of the case’s end, and his 1993 and 1996 congressional testimony, archived at philzimmermann.com