Re: [Eben Moglen <moglen@columbia.edu>] Re: US crypto export restrictionsand GNU (fwd)

From: Date: Wed, 15 Mar 2000 16:58:30 +0000
Subject: Re: [Eben Moglen <moglen@columbia.edu>] Re: US crypto export restrictionsand GNU (fwd)
References: 1 2 3 4  Groups: php.dev 
Request: Send a blank email to php-dev+get-16836@lists.php.net to get a copy of this message
Eben Moglen wrote: > > On Tue, 14 March 2000, Richard Stallman wrote: > > A concern that has been expressed to me several times is that the new > regs are infectious, i.e. code that incorporates US exported patches > becomes US export controlled, and hence may be affected by future > regulatory changes. > > Eben, what do you have to say about this issue? > > I think don't fully understand the bearing of the statement. US export > control regulations apply to code not because of its origin, but > solely because of its function. Code developed in the United States > is subject to export control if it performs functions listed in the > so-called Munitions List. Without entering into too many of the > endless unhappy technicalities, that means, roughly speaking, code > that performs encryption or decryption using non-trivial algorithms > and key lengths, or which performs key management activities, or code > which would provide such functions if encryption/decryption algorithms > were "dropped in" to "encryption-sized holes" in the code. It doesn't > matter whether the routines were assembled abroad and reimported to > the US, or whether any of the code is descended from code exported > from the US in the past. The questions are (not to suggest that any > of these are as simple as they look, or that NSA didn't play all sorts > of silly games through its mouthpiece agencies in defining each of > these criteria): [1] is the code "in" the US; [2] does it qualify as a > munition because it performs functions defined on the munitions list; > and [3] is it going "out" of the US? If and only if the answers are > yes, the regs apply. > > With this in mind, the "infectiousness" argument seems hard to > credit. If someone has heard it made in enough detail to clarify what > is being asserted I can try to analyze the matter further, but as > things stand I think the claim is likely to be based on a > misunderstanding. The claim is that should OpenSSL (a UK/German/ex-Australian project) accept legally exported patches from the US, then OpenSSL would become subject to US export regs. You appear to be saying that that is not the case, correct? > As to the possibility of future restrictive changes in regulations, it > is theoretically possible, but practically of vanishing likelihood. > The absurdity of prohibiting export from the US of that which is > pervasively available elsewhere already has been fully accepted by the > non-secret portions of the federal government, and industry's stake in > the new situation is profound. It would take circumstances capable of > overriding that consensus to bring about restrictive change. Such > circumstances are hard to define, let alone foresee. I've made much the same argument myself. Cheers, Ben. -- SECURE HOSTING AT THE BUNKER: http://www.thebunker.net/hosting.htm http://www.apache-ssl.org/ben.html Coming to ApacheCon Europe? http://ApacheCon.Com/

« previous php.dev (#16836) next »