Re: [Eben Moglen <moglen@columbia.edu>] Re: US crypto export restrictionsand GNU (fwd)
| From: | Ben Laurie | Date: | Wed, 15 Mar 2000 16:58:30 +0000 |
| Subject: | Re: [Eben Moglen <moglen@columbia.edu>] Re: US crypto export restrictionsand GNU (fwd) | ||
| References: | 1 2 3 4 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-16836@lists.php.net to get a copy of this message | ||
Eben Moglen wrote:
>
> On Tue, 14 March 2000, Richard Stallman wrote:
>
> A concern that has been expressed to me several times is that the new
> regs are infectious, i.e. code that incorporates US exported patches
> becomes US export controlled, and hence may be affected by future
> regulatory changes.
>
> Eben, what do you have to say about this issue?
>
> I think don't fully understand the bearing of the statement. US export
> control regulations apply to code not because of its origin, but
> solely because of its function. Code developed in the United States
> is subject to export control if it performs functions listed in the
> so-called Munitions List. Without entering into too many of the
> endless unhappy technicalities, that means, roughly speaking, code
> that performs encryption or decryption using non-trivial algorithms
> and key lengths, or which performs key management activities, or code
> which would provide such functions if encryption/decryption algorithms
> were "dropped in" to "encryption-sized holes" in the code. It doesn't
> matter whether the routines were assembled abroad and reimported to
> the US, or whether any of the code is descended from code exported
> from the US in the past. The questions are (not to suggest that any
> of these are as simple as they look, or that NSA didn't play all sorts
> of silly games through its mouthpiece agencies in defining each of
> these criteria): [1] is the code "in" the US; [2] does it qualify as a
> munition because it performs functions defined on the munitions list;
> and [3] is it going "out" of the US? If and only if the answers are
> yes, the regs apply.
>
> With this in mind, the "infectiousness" argument seems hard to
> credit. If someone has heard it made in enough detail to clarify what
> is being asserted I can try to analyze the matter further, but as
> things stand I think the claim is likely to be based on a
> misunderstanding.
The claim is that should OpenSSL (a UK/German/ex-Australian project)
accept legally exported patches from the US, then OpenSSL would become
subject to US export regs. You appear to be saying that that is not the
case, correct?
> As to the possibility of future restrictive changes in regulations, it
> is theoretically possible, but practically of vanishing likelihood.
> The absurdity of prohibiting export from the US of that which is
> pervasively available elsewhere already has been fully accepted by the
> non-secret portions of the federal government, and industry's stake in
> the new situation is profound. It would take circumstances capable of
> overriding that consensus to bring about restrictive change. Such
> circumstances are hard to define, let alone foresee.
I've made much the same argument myself.
Cheers,
Ben.
--
SECURE HOSTING AT THE BUNKER: http://www.thebunker.net/hosting.htm
http://www.apache-ssl.org/ben.html
Coming to ApacheCon Europe? http://ApacheCon.Com/