[104622] in Cypherpunks
Re: ITAR and Codebreaking
daemon@ATHENA.MIT.EDU (Greg Broiles)
Sat Oct 24 23:32:15 1998
Date: Sat, 24 Oct 1998 20:21:47 -0700 (PDT)
From: Greg Broiles <gbroiles@netbox.com>
To: Eric Cordian <emc@wire.insync.net>
cc: cypherpunks@cyberpass.net
In-Reply-To: <199810232323.SAA02700@wire.insync.net>
Reply-To: Greg Broiles <gbroiles@netbox.com>
On Fri, 23 Oct 1998, Eric Cordian wrote:
> Does anyone know how ITAR applies to cryptographic source code which can
> not directly be used to encrypt or decrypt files?
>
> Specifically, do we need to do some horrible export-controlled thing for
> source code which contains a very straightforward reference implementation
> of DES, and whose output is a file of integers defining a satisfiability
> problem instantated for a specific plaintext/ciphertext pair?
It's not ITAR any more, it's the EARs, and they apply to all crypto
software, or technical assistance/data related thereto. You should
consider your work product export controlled if it's produced in
electronic format.
If you don't want to be bothered with paper publication, I'll put together
a paper version of your output and make it available - for free if it's
small, or on a cost recovery basis. Print publication of the PGP source
code has proven to be very valuable to the amateur/enthusiast crypto
community.
--
Greg Broiles
gbroiles@netbox.com