[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: A2-DES 1.0 DES encryption for the Apple II (1/1)



In article <1994Mar28.221618.1337@seas.smu.edu> volk@seas.smu.edu (Andrew R. Volk) writes:
>In article <1994Mar28.201727.25324@uts.amdahl.com> fadden@uts.amdahl.com (Andy McFadden) writes:
>>NSA export restrictions prevent this sort of thing from being exported
>>to other countries from the United States.  Unfortunately, this applies
>>to things that were imported in the first place.
>>
>>As a result, FTP sites in the USA probably shouldn't archive this.
>
>That hasn't been an issue for almost every site on the planet, you'll find
>DES encryption programs for every platform everywhere in the world. When
>someone downloads the program off the site, that's the user's problem. Let's
>please not kill an Apple // encryption program!

You managed to miss the point completely.  Let's try this again.

It is illegal to export encryption software from the United States.
Contrary to popular belief, there are people with computer skills outside
the country, and as a result there are a number of DES packages that
originated from outside the country.

Also, since the CIA's mind-scanner doesn't work just yet, it's highly
probably that copies of DES have managed to leak across the border.

What the NSA says is that encryption algorithms are equivalent to
munitions (guns, bullets, nuclear bombs), and as such you aren't allowed
to transmit them FROM the United States TO another country.

What this means is, you can grab all the stuff you want from outside the
USA, and it's not a problem.  If somebody from Canada wants to distribute
DES all over the world, that's fine, the NSA can't do anything about it.

However, if an FTP site in the USA makes it available to people in other
countries, they are breaking the law.  I've seen a number of FTP sites with
a notice like this:

    If you are connecting from outside the USA, please find these files
    on a mirror site in a different country.  Export restrictions
    prevent us from making these files to you.  If you don't follow
    these rules, we may be forced to remove the restricted files.

If a user downloads the file, it is *NOT* the user's problem, it's the
problem of whoever made that file available for download.  Since DES was
decertified, the NSA probably won't care, but I for one don't feel like
messing with an organization that scans Usenet postings (hi guys!)

As Jawaid mentioned, it's okay to distribute binaries of algorithms
used only for authentication, such as for passwords.  Since this program
does data encryption, it's not exempt.

I rather doubt that not archiving it on FTP sites within the USA will
kill it.  If you want to be picky, a Usenet node that propagates the
comp.binaries.apple2 newsfeed from inside the USA to a site outside the
USA is in violation of the law.

An interesting side note: you'd be hardpressed to find a copy of AutoArk
outside the country with the encryption feature in it.  They found out
right before they were due to ship that they had to ship a different
version internationally.  I don't know how careful they were about it,
but there were a bunch of posts in the Econ category on GEnie discussion
this.

>Andrew R. Volk                | 'finger -l' for PGP 2.3 Public Key

And, of course, RSA has a patent on the algorithm used in PGP, so
technically it's illegal to use PGP *inside* the United States for
other than educational purposes.  But, software patents are stupid, so
who cares?  (The Compton multimedia patent was overturned!  Yay!!)

-- 
fadden@uts.amdahl.com (Andy McFadden)

"Our UNIX is bigger than your UNIX"
[ These are my opinions, not Amdahl policies. ]