In 2004, three researchers published a paper with a pointed subtitle: "Why Not To Use PGP." Their argument was that encrypting instant messages with PGP gets the security properties backwards, and their replacement protocol, Off-the-Record Messaging, introduced ideas that every serious messenger now treats as mandatory. OTR itself is nearly gone. Its ideas run inside billions of phones.

The paper was "Off-the-Record Communication, or, Why Not To Use PGP," by Nikita Borisov, Ian Goldberg, and Eric Brewer, presented at the Workshop on Privacy in the Electronic Society in 2004. Its core observation: a private conversation in person has two properties that PGP-encrypted email destroys.

First, once the conversation is over, it is over. Nobody can later produce a transcript and prove what was said. Second, if someone steals your house keys tomorrow, they cannot retroactively hear what you said in your kitchen yesterday. PGP fails both tests. A signed message is durable, transferable proof that you wrote those exact words. And a message encrypted to a long-term key stays decryptable for as long as that key exists, so a key stolen years later unlocks years of archived ciphertext.

Borisov, Goldberg, and Brewer wanted digital conversations to behave like spoken ones. That requirement produced two properties with names that are now standard vocabulary: forward secrecy and deniability.