from the archive · Contemporary era
Phil Zimmermann
b. February 12, 1954 · cryptographer · mathematician · programmer · human rights defender
By The Keeper · Published
AI-assisted writing, automatically checked. Editorial process
Phil Zimmermann is an American cryptographer, mathematician, and programmer who in 1991 released Pretty Good Privacy, the first strong encryption software made freely available to ordinary computer users. His decision to publish PGP triggered a three-year federal criminal investigation that became a defining episode in the debate over privacy and government control of cryptography. The case ended without charges in 1996, and the software he wrote went on to shape the standards that still protect email and digital communications today. Any Phil Zimmermann biography is, in large part, the story of how encryption moved from the domain of governments into the hands of the public.
Early Life
Philip R. Zimmermann Jr. was born on February 12, 1954, in Camden, New Jersey [1]. He grew up in Florida, where an early fascination with codes and secret writing took hold long before he had access to a computer. As a boy he borrowed a copy of Herbert Zim's book Codes and Secret Writing from the library, a chance encounter that he later credited with setting the direction of his working life [2].
Zimmermann studied at Florida Atlantic University in Boca Raton, earning a bachelor's degree in computer science in 1978 [1]. Cryptography remained a hobby during these years rather than a profession. The academic field itself was only beginning to open up: the publication of public key cryptography by Whitfield Diffie and Martin Hellman in 1976, followed by the RSA algorithm in 1977, arrived while Zimmermann was still an undergraduate, and he followed these developments closely [3].
After graduating he worked as a software engineer, eventually settling in Boulder, Colorado. During the early 1980s he was also active in the anti-nuclear movement, serving as a military policy analyst for the Nuclear Weapons Freeze Campaign and taking part in protests, including one at the Nevada nuclear test site where he was arrested alongside other demonstrators [2]. That political engagement mattered later: his belief that activists and dissidents needed private communication became a stated motive for the software that made him famous.
Path to Prominence
Through the 1980s Zimmermann worked on the problem of bringing public key cryptography to personal computers, machines far less powerful than the systems academic cryptographers used. He wanted a tool that would let two people who had never met exchange confidential messages without any government or corporation being able to read them [3].
The project gained urgency in 1991. That year, a provision in a draft of United States Senate Bill 266 proposed that makers of secure communications equipment ensure the government could obtain the plain text contents of communications when legally authorized. The provision was eventually dropped, but Zimmermann saw it as a warning that strong cryptography for citizens might soon be foreclosed [4]. He raced to finish his program, working intensively for months and, by his own account, missing mortgage payments in the process [2].
In June 1991 he released Pretty Good Privacy, or PGP, as free software, and a friend uploaded it to the Internet [4]. The name was a wry nod to Ralph's Pretty Good Grocery, a fictional store in Garrison Keillor's radio program A Prairie Home Companion [2]. PGP combined the RSA public key algorithm with a symmetric cipher and a system of digital signatures, packaged so that a home computer user could encrypt email without understanding the mathematics underneath. Within days copies had spread far beyond the United States, carried across borders by the network itself.
The Criminal Investigation
The worldwide spread of PGP collided with American law. At the time, cryptographic software was classified as a munition under the Arms Export Control Act and the International Traffic in Arms Regulations, and exporting strong encryption without a license was a felony [5]. In February 1993, Zimmermann learned that he was the target of a federal grand jury investigation run by the United States Customs Service and the United States Attorney's office in San Jose, California, examining whether the appearance of PGP abroad amounted to illegal arms export [5].
The investigation lasted three years and turned Zimmermann into an international symbol of the fight over encryption policy. Civil liberties groups rallied to his defense, supporters contributed to a legal defense fund, and the case sharpened the broader 1990s conflict known as the crypto wars, which also included the Clinton administration's Clipper Chip proposal for government-accessible encryption [3]. Zimmermann testified before Congress on encryption export policy during this period, arguing that the controls harmed American industry and did little to keep cryptography out of foreign hands [2].
Supporters found inventive ways to challenge the export rules. MIT Press published the complete PGP source code as a printed book in 1995, on the theory that books enjoyed First Amendment protection even where software did not; anyone abroad could scan the pages and compile the program [3]. In January 1996 the government closed the investigation without filing charges [5]. No official explanation was given, and the export regulations themselves were substantially relaxed by the end of the decade.
Major Achievements
Anyone asking who was behind the mainstreaming of email encryption arrives quickly at Zimmermann, and the list of Phil Zimmermann achievements begins with PGP itself. Beyond the original program, his lasting technical contribution was the web of trust, a decentralized model in which users vouch for one another's public keys instead of relying on a central certificate authority [3]. The message format he pioneered was later standardized by the Internet Engineering Task Force as OpenPGP, which remains a widely used open standard for encrypted email and file protection, with free implementations such as GNU Privacy Guard descending directly from his design [4].
In 1996, after the investigation ended, Zimmermann founded PGP Inc. to develop the software commercially. Network Associates acquired the company in December 1997, and Zimmermann stayed on for several years as a senior fellow [1]. The product line changed hands again when PGP Corporation was formed in 2002, with Zimmermann serving as a special advisor, and Symantec bought PGP Corporation in 2010 [1].
His later work moved from email to voice. In the mid 2000s he developed Zfone and the underlying ZRTP protocol, which lets two parties on an Internet phone call negotiate encryption keys directly, without depending on servers that could be compelled to hand over keys [6]. ZRTP was published as RFC 6189 in 2011. In 2012 he co-founded Silent Circle, a company offering encrypted voice, video, and messaging services, together with former Navy SEAL Mike Janke and PGP collaborator Jon Callas [6]. Silent Circle later helped launch Blackphone, a privacy-focused smartphone.
Recognition followed the work. Zimmermann received the Chrysler Award for Innovation in Design in 1995 and the Norbert Wiener Award from Computer Professionals for Social Responsibility in 1996 [1]. The Electronic Frontier Foundation gave him its Pioneer Award in 1995, Newsweek named him among the most influential people on the Internet, and in 2012 the Internet Society inducted him into the inaugural class of the Internet Hall of Fame [7]. In 2001 he was inducted into the CRN Industry Hall of Fame, and Simon Fraser University later awarded him an honorary doctorate [2].
Ideas and Advocacy
Zimmermann has always presented his software as a political act as much as an engineering one. In the essay Why I Wrote PGP, distributed with the original documentation, he argued that privacy in the digital age would vanish unless ordinary people encrypted routinely, and that cryptography served human rights workers, journalists, and dissidents living under surveillance [2]. Among the Phil Zimmermann facts most often repeated is his report that human rights groups abroad, including activists documenting abuses, wrote to thank him for PGP, letters he cited when defending the program during the export investigation [5].
He remained a public voice through the policy battles that followed. After the Snowden disclosures of 2013 renewed global attention on surveillance, Zimmermann spoke frequently about the need for end to end encryption and criticized proposals for government backdoors, drawing on the lesson of the 1990s that weakened cryptography protects no one [6]. In interviews he has been careful to acknowledge the tension in his work: encryption shields the innocent and the guilty alike, and he has said he accepts that trade because the alternative, a world without private communication, is worse [3].
His advocacy also took institutional form. Zimmermann served on the boards and advisory panels of technology and civil liberties organizations, and from 2016 he held a position at Delft University of Technology in the Netherlands, joining its cybersecurity group while continuing his work with Silent Circle [6].
Personal Life and Later Years
Zimmermann lived for many years in Boulder, Colorado, before moving to the San Francisco Bay Area during his commercial PGP years [2]. Consistent with his own advice on writing about living people, he has kept his family life largely out of public view, and he is known primarily through his work, his essays, and his frequent conference appearances rather than through personal publicity.
In the 2010s he relocated to the Netherlands for his role at Delft University of Technology, an arrangement that also reflected Silent Circle's decision to base operations in Europe, partly in response to the American surveillance controversies of the period [6]. He has continued to speak at security and privacy conferences worldwide, often reflecting on the unfinished nature of the fight he helped start: encryption is now built into billions of devices, yet legislative proposals to mandate exceptional access keep returning in new forms.
Now in his seventies, Zimmermann still identifies publicly as a cryptographer and human rights advocate. The through line of his career, from the anti-nuclear campaigns of the 1980s to the encrypted phones of the 2010s, has been the conviction that technical people bear responsibility for the political consequences of what they build [2].
Legacy
PGP's influence outlived every company that owned its trademark. The OpenPGP standard it inspired secures software distribution signatures, protects files and email for journalists and lawyers, and remains a reference point whenever engineers design systems that must work without trusting a central authority [4]. The web of trust idea prefigured later decentralized approaches to identity, and ZRTP's design influenced how modern secure calling systems handle keys [6].
The legal legacy is just as significant. The investigation of Zimmermann, together with related court cases of the 1990s, helped push the United States government to liberalize encryption export rules in 1999 and 2000, a shift that made today's routinely encrypted web commerce and messaging possible [3]. Historians of the Internet treat the PGP episode as the moment when strong cryptography escaped state control for good, which is why Zimmermann appears in the first class of the Internet Hall of Fame alongside the network's founding engineers [7].
For readers coming to a Phil Zimmermann biography for the first time, the essential point is simple: one programmer, working alone and at real legal risk, changed the default assumptions about who is entitled to privacy. The tools have evolved, but the argument he forced into the open in 1991, about whether citizens may keep secrets from their governments, remains the central privacy question of the digital era [5].
Questions & Answers
- When was Phil Zimmermann born?
- Phil Zimmermann was born on February 12, 1954, in Camden, New Jersey. He grew up in Florida and studied computer science at Florida Atlantic University, graduating in 1978.
- What is Phil Zimmermann famous for?
- He is best known as the creator of Pretty Good Privacy (PGP), released in 1991 as the first strong encryption program freely available to the general public. PGP became the basis of the OpenPGP standard that still protects email and files today.
- Why was Phil Zimmermann investigated by the US government?
- After PGP spread outside the United States, federal prosecutors opened a grand jury investigation in 1993 into whether he had illegally exported munitions, since encryption software was then classified as a weapon under export law. The investigation was dropped in January 1996 without any charges being filed.
- Is Phil Zimmermann still alive?
- Yes, Phil Zimmermann is living. He has remained active in cryptography and privacy advocacy, co-founding the secure communications company Silent Circle in 2012 and later joining Delft University of Technology in the Netherlands.
- What companies did Phil Zimmermann found?
- He founded PGP Inc. in 1996 to commercialize his encryption software, which Network Associates acquired in 1997. In 2012 he co-founded Silent Circle, which offers encrypted voice, video, and messaging services and helped launch the privacy-focused Blackphone.
- What awards has Phil Zimmermann received?
- His honors include the Electronic Frontier Foundation Pioneer Award in 1995, the Norbert Wiener Award in 1996, and the Chrysler Award for Innovation in Design in 1995. In 2012 he was inducted into the inaugural class of the Internet Hall of Fame.
References
Every record in this archive is kept against verifiable sources.
- [1]Philip Zimmermann, Internet Hall of Fame Innovator profile. Internet Society, Internet Hall of Fame, 2012. https://www.internethalloffame.org/inductee/philip-zimmermann/Web
- [2]Philip Zimmermann. Background: Philip Zimmermann. philzimmermann.com. https://philzimmermann.com/EN/background/index.htmlPrimary source
- [3]Steven Levy. Crypto: How the Code Rebels Beat the Government, Saving Privacy in the Digital Age. Viking Penguin, 2001. Book
- [4]Philip Zimmermann. Why I Wrote PGP. philzimmermann.com, 1991, updated 1999. https://philzimmermann.com/EN/essays/WhyIWrotePGP.htmlPrimary source
- [5]John Markoff. Data-Secrecy Export Case Dropped by U.S.. The New York Times, January 12, 1996. News
- [6]Somini Sengupta. Silent Circle and the story of Phil Zimmermann's encrypted communications work. The New York Times, 2013. News
- [7]2012 Inductees, Internet Hall of Fame. Internet Society, 2012. https://www.internethalloffame.org/inductees/Web

preserved for ever
Sealed on the blockchain. Tap the seal to verify.
preserved for ever
Sealed on the blockchain. Tap the seal to verify.
This record is inscribed on the Arweave blockchain, a permanent public ledger replicated across hundreds of independent machines. The copy there cannot be edited, withdrawn, or lost. It will outlast this website, its server, and its keeper.
help the keeper
Spotted an error, or hold a source the archive lacks? Every record can be corrected. Submissions are reviewed against authentic references before any change is made.

entered into the archive
kept by The Keeper