[6150] in cryptography@c2.net mail archive
RE: draft regulations?
daemon@ATHENA.MIT.EDU (Rodger, William)
Mon Nov 29 12:16:50 1999
From: "Rodger, William" <wrodger@usatoday.com>
To: John Gilmore <gnu@toad.com>, "Rodger, William" <wrodger@usatoday.com>
Cc: William Allen Simpson <wsimpson@greendragon.com>, cryptography@c2.net
Date: Mon, 29 Nov 1999 11:52:37 -0500
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="----_=_NextPart_000_01BF3A89.19E3150A"
Message-Id: <19991129163611.3E467E3B9@smtpgate.gannett.com>
This message is in MIME format. Since your mail reader does not understand
this format, some or all of this message may not be legible.
------_=_NextPart_000_01BF3A89.19E3150A
Content-Type: text/plain;
charset="iso-8859-1"
> -----Original Message-----
> From: John Gilmore [mailto:gnu@toad.com]
> Sent: Thursday, November 25, 1999 3:55 PM
> To: Rodger, William
> Cc: William Allen Simpson; cryptography@c2.net; gnu@toad.com
> Subject: Re: draft regulations?
>
I wrote:
> > Open Source code, believe it or not, would be essentially
> > decontrolled by this proposal.
John GIlmore replied:
> Look closer. The large print granteth and the small print
> taketh away.
John's entirely right, provided one wants to guard against all future
possible reversals on this issue. My view is this process has been headed in
one direction only and at worst will stagnate there. Given that,
"essentially" decontrolled seems about right.
In the meantime, useful source code on disk remains non-exportable without a
license.
My own view: the entire regime will be dead within three years.
Will
> It would be simple to exempt published encryption software from the
> regulations; the Commerce Dept regs did this for years, before the
> State Dept rules were folded into it. The Commerce regs today state
> state that all other forms of published software -- except crypto --
> are "not subject to the EAR". It's in Part 734.3(b)(3). Published
> word processors and other software don't need to prevent web accesses
> from certain countries, or impose any conditions on recipients. True
> deregulation would involve *removing* the special case for crypto.
> This is not what the draft offers.
>
> Open source is not a single piece of code, it's a development process.
> The proposal offers open source developers poisoned bait. If you jump
> through some hoops, you can export single patches, or pieces of
> software, from the US. That's the bait. The poison is that the
> software and everything derived from it becomes permanently tainted
> with US export controls ("subject to the EAR"). This appears to
> include all future releases of the open source project, and all object
> code derived from them, no matter where in the world they are
> produced or used.
>
> (Every licensed export currently requires the exporter to get the
> recipient to agree that the recipient will not re-forward the exported
> stuff to places or recipients that the US disapproves of. The draft
> rules would drop the requirement to get prior permission for the
> export, but retain the requirement to impose US controls on every
> future recipient. And the US can change those controls at any time,
> either by sending you a private letter about an individual product --
> as they did by revoking their permission a year after giving Hugh
> Daniel written permission to export DNS Security authentication source
> code -- or by unilaterally altering their published regulations.)
>
> Suppose standard Linux releases included US-based crypto code under
> these rules. Every subsequent copy of Linux running everywhere in the
> world would become subject to US export controls, which are subject to
> the whim of the NSA and the current US administration. It would be a
> poor design decision to subject *every* Linux user to whatever new
> crazy ideas the NSA dreams up to help them wiretap the world next
> year.
>
> The draft rules also appear to require web sites to take active
> measures to discourage people from six or seven little countries from
> being able to access the site. This is just like the current BXA
> rules about publishing crypto on US web sites, except the list of
> countries "allowed" to access your web publications is bigger.
> (Anonymous accesses appear to be disallowed since they might be from a
> disallowed country.) The draft rules offer a bigger cage to censor
> yourself within, not a change to true freedom of expression for
> cryptographers.
>
> The censor-access-by-country rules would apply to any international
> web site (or mirror site) that published any code that includes US
> crypto source code contributions. Who would be idiotic enough to do
> this to their web sites? Much easier and safer to continue current
> policy of refusing to accept US contributions to int'l crypto code.
>
> At the moment nobody is crazy enough to start an open source crypto
> project in the US; they are all based in free countries. Naive
> readings of the draft proposal encourage US developers to start such
> projects (which end up producing products that are restricted by US
> export controls on object code). They also encourage internationally
> based projects to pollute their code by accepting contributions from
> US contributors, thereby rendering their entire source base subject to
> US export controls. Both of these outcomes would be poor decisions
> for open source projects to make.
>
> Someday the US will truly deregulate published crypto source code, so
> that the nationality of a crypto researcher or developer is not a
> factor in whether to accept their contributions to an open source
> project. With some luck, this will be backed up by a Supreme Court
> ruling in the Bernstein case, which can't be later rescinded by
> administrative whim. (BTW, none of the bills in Congress demands true
> free expression in crypto code.) The Administration seeks to avoid
> being required by the courts or Congress to stick to free expression
> even when it hurts, so it may temporarily truly deregulate on December
> 15, 1999. But even that much won't happen unless they make real
> changes to the draft rules they released this week.
>
> John Gilmore
> open source software developer
> & part of Bernstein litigation team for free expression
> in crypto code
>
------_=_NextPart_000_01BF3A89.19E3150A
Content-Type: application/ms-tnef
Content-Transfer-Encoding: base64
eJ8+Ig4QAQaQCAAEAAAAAAABAAEAAQeQBgAIAAAA5AQAAAAAAADoAAEIgAcAGAAAAElQTS5NaWNy
b3NvZnQgTWFpbC5Ob3RlADEIAQSAAQAYAAAAUkU6IGRyYWZ0IHJlZ3VsYXRpb25zPyAALggBCYAB
ACEAAAAwNkNCOEY3NzcwQTZEMzExODYwRTAwQzA0RjQxQkUzNgATBwEggAMADgAAAM8HCwAdAAsA
LQAKAAEAQQEBBYADAA4AAADPBwsAHQALADQAJQABAGMBAQ2ABAACAAAAAgACAAEDkAYA4BEAADAA
AAALAAIAAQAAAAsAKwAAAAAAAwAuAAAAAABAADkAQP1AJIo6vwEeAHAAAQAAABQAAABkcmFmdCBy
ZWd1bGF0aW9ucz8gAAIBcQABAAAAGwAAAAG/N4dKtEOuU52jWxHTqsgAEEuM7EgAwH9LsAACAQkQ
AQAAAPEMAADtDAAAAhkAAExaRnWqn/iqAwAKAHJjcGcxMjXiMgNDdGV4BUEBAwH3/wqAAqQD5AcT
AoAP8wBQBFY/CFUHshElDlEDAQIAY2jhCsBzZXQyBgAGwxEl9jMERhO3MBIsETMI7wn3tjsYHw4w
NREiDGBjAFCzCwkBZDM2FlALp2MBMEcK4wqECoA+IC0eEk89BRBnC4AHQAXQB5BzYSxnZR4THZZG
A2E6IOhKb2gDoEcDEARgGCAMIFsAwAMQdG86Z4hudUAhsGFkLgWgPG1dHZYGYAIwIHBUaEEIcHNk
YXksB7BvPHZlBtASgQ4wJBAxORElECAzOhpgIFBNrR2WVCHAB/FkH0ByJBAqVwMQbAcwbR2WQ2N/
IHAnBRDAJyAJ8AYAB3BwUnMCIDsgBQB5BTBvAQnAYXBoeUBjMjwubhQgKYAh6iK3dWKmagWQI2FS
ZSBwZCoQJQGAIBggZ3ULYHRpOQIgcz8dJR3wHTRJIDZ3A2AOsDodlh3wT3D7KOIIYWMhQAWgAQAk
ECSAZScwZSRQIGkFQAWxbksvUCQQdwhgbGQxQSDnHwEjQQcxbHkvmAWCAjCHA2AowTLBeSB0aAQA
JCBwA2Bwbx8gbC57HToglEkhBBggC1AIkGThL4dMb29rKZAXsBQQuHIuICOBIUALYHIfQD81oQuA
BUAqAQIwFCBoIO8AcDLANWAhQHMAwCcgOkVrHZYBkGs7A3cj8DY/J78EIDNCGCAzoC1QHoBoMlH5
NbF2aQEAMsACICFAPYBvAjAEICGwKuB1CxE7MGeNC3FzBUA74mZ1dAhw/zoxNfAAkAJgN7IkUBQA
B0C/BCACIDVUBAEKUDmATTVA/0AgB9E1gTVmMMAEERPgBCB/JIAo4TnAIkA1AQuAQHNk/z8hLIAt
0UBxP1E7Qi2wMnH/FABJMScRO7ABkCHgLbAhQP87gRggOYAg4CRQRCItsCQQ+iIzGSI0XBQQJGAE
IAGg7whgLUE/kj27SUQiIUAHgPc60QdxJBB1FBBCcEnhMJj7RAJH8HM5ABggIXEGMTIw/G4tDsA1
4AAgAaBDQQPw+zVgTfJhOeAN4AnwFBA5gPMdOkUBb3cDoEUyIHA7gv8+9C1SB3FJpDLhAQAiQFNz
50eBNWAJ0SB5RyAUAFSc+ycCHTxJSTIypQCQKTBDQW9BIQ7AJGAFMXAsQCcwc/85wDLACfApo0hS
KVABgD2A/yExA1I7ch2WLWkpgDuCCFD2bQeAMLJEN+AtQwQgR/D/O2I1gQIQBcBZAzEyYtFKc78i
twGQSmFhpC2QB5F3SrH/YsEysEdTQSEx0DmFYRdh8/8hsCPhSfIOsB2WaJNLU0Ij/y9QSqFiwk2h
XoBdGV53HhB/XKEwwAUxKaQeAR2WXsIiHzIxO7AsREESO4JFQVLeIjmBW1A+wUeBUArABUAANzM0
LjMoYinoKDMpOYFQXTYdlklRvzLARgVJYTszalRed2QCIP4nBUAqoDUBQSE1sDGROoH1ZbBiOzBj
RjIHkB2WXwPvMMBTEUeBBaB1NKEIkGNR/wWxKSE5QTsxNUA0gUfwLcP/RAJIEQUgCJBA4TmCZVBf
d28EgS13MnULgHYG8DGhKuNSEUARbmcqO3QwQHsA/R7BY0aQZeIFwCmkPbUmIX9EVDIiLyBp0juC
LQRegGb/Q6GAhx2WMDNQ1YFlVAAAkP9+kENBeyEwwWsRMPQx0D7B71QAAQAkUBewcAeAOoFGBf+A
iToyNdSCtTHwhEmHVYoSvzXgBABAgTLBC3Bm0klrIOJ5CGAganUpMDyHWLD/CGA/oFDBVzFTsDXQ
Y1GM8v9/kAOgUtSFdy2wE9B45YXzH2ryaOdehSQQXwYgVVP/OYMtsD7BO4KMVYkTi9NFdK+B9JHu
OzNDgnlYUmd8Yv9LETLAXwMx0SSAInEHkYtx/wOBI0E/UXgiDrBySFORk4Hnj6Y0hQQgKCJuv2/A
cYL/gRMqIDBAE/FBER2WC4A5IP51UWFCOT8xRyB28WsCO4L/ilo1sSxiJBBI42oiLFMdlvdRQ5hr
O4FtJBAyME+wLbD/DrAFwIHQZcJYc0ChBbAysd87gUjBGCAdljWxZBrQQFLPBcBQYSJQgz4oRZfC
VBY/XaGcJQhwGCCaUxggcXX/PyGUNFLUEoFBIhQgX0x7Bf9BEh8wWMKV5q/ZSbNuchggfi1i0V6x
O2SuNXJHQgB1/wEgdaMLYJGDBcB66LEIm+H/UcGe8UABkZM5hS0DX4dlZP8yky0ANdCxVa2Dh8Ou
xTpR/5EimfEEAUhSYtJfWVLUMTH/TgIUIHgyup9moXlkm+Gch79EEZezdyeg5nsFOYFBO1X/wNID
kRPRfpBKcnmCnIdp4v950VADvYdTkRKBNTEzMUfw75gxjPJUADpRdkpSKNCmw/9N1AORC4BH8EAh
QWA8Aqli/wVAbYmUMzVAYkI1MUNxOPD/mCI7gT8gvFpUAFkCOzABgGcSgR6QfnIgSI4xHZZE/wBw
CJADIC8wMdAOsAOgvGlzXIOP00ROBfEFkAhxdP9IwUKAOcAzUX+QXiUwoqR7/2xxBbE1MXiQAxBK
USoQM5GfQiGm0c1pXTctaS4pgz6/LDCfAHmCSgE7UEFyTAuAvHV4oTigFTLAk5AtjFD/rBJtFVFD
eJAEgY14B5A3sf9lYjmBq2SdMRQQrYB2IgWg/nBVgWsg27V4kAMAmDGXs/+nGnJZMrEyhpmCbqqb
72NR/4HQDeA7ISExnTje2edCKJD7odXTAEE7N6zF5gIiQLyQvwMAQgAqEC3Cb+MyeGGox/844AXA
AQAAkCHgNFIEANIV/Z02KpezfrDbtFBhrqOB0ttDgnVRd6R3KhB6NUBAMf/MJOoDLQBHIE2h2rBB
EjnA/my6cyiQA/C+wrp0p+QqoP8O0B2WWQKqT7h3ZUVD0bCR/58DQRKtZXZTAJAOsEEDPQL/dpEt
wCRQHZZPwUSwrbNBMO9RwXhxKhA6ImU10ENBXwP/AJDb8AWxFBBLIicwAkBDQf94d17zqtYkgJgi
UzOwgnaz/zt0+yGedjWBjTBCAScw+8Hx6ppCWEG5DE3UXSWYIv9tFUQR5hH61yQQbKU7gl1R94Ki
pHgAZiJCMVWgGDBMgH8CWMhxpvF2cV0j1ESBQ2L3P5AmsYCHKMPACBAUcFPA/4cRdrX5qVeyt3EL
hIVyMMH/qEO8kD+hMtJfA+1XETkARP09oCm4WWVFgsOHIQ40f4F/xPLeEVRR1hD2lzCR/3Bs/2sg
WDSmUlPixLZvQXvBXvH/dXFfIWsRUtGtsbzG8ggpxzeC/4jlF9QtdqTdUHktfxS1uXue8ZpysJF5
0ZrCcv9KQS3RQjByV/rlnQDWEbyQ/6zg/0L7IRUwacNdKHnE1bH/acOgFYcQk5AcrFDLNINDIPdC
gNlDw6BXU7AyeMywLdD/1CE+4Y4j/WLoiUWCb0PN0fX61z/DoE2pgJvAoXEAoP/JoTtRiaAWgt4D
M1Hb0Oq3/+1oDWHhc7DQQnCFggJGbOHvwNYp5sAjmtAnf3Hd2B4PvkGCBA+Ah8Mr8MnQZPLB/4cQ
8oQr6EoBcLHEgYpabRT/qMlu46d1k5Bgs6hzQiPdZO9wYRsSeGiU0U5SQPw489H/yCKht/ikiVdd
wf3VtzKLKP85V/0AkMA7PZzx51TIAfQi/6lEmCLLBbaFbiKtsXix77D/jCLXICfInB4IEaQUhnOe
ZP+oYvlyQhgie5pwASfdc0Tn/3WyZhCgQGmTzcImk9ZBMzT/B2Mz6wDqM6pzkaNwamJ2cP+tQt6S
zWjUAufCirTdYufv91MDnB2U0UJqUaHFwKHJ4f+ZhCrX7eXuxHcY1hGiT08V95oQ+8A1/1OOgWhS
tvWyQ/8awZpxfHei4dhHKG+S0Yvw/+iYgfUixtOCaxEaAW0krbH/zuGQwVzR7hKLNYTndyf78f95
In0hCaB0IzMIUAYz/Tnsnzs9KmKboo5zoEBja1QS/5WxskMS8YxQbxAUgfQxULLz2pK7IiBDirG4
+pgiPDV+QiKhBEABsX+D5zbEcSf/EtPWo0gCRqHc8tZAy6frmYd98elSlNEoQlRXplL/8dChxhbg
FEDcgnGBfpAb8vt8YZoRZLaBGtHCF7DSG8k3c7I1WRU1Qeubx+Fla/9sBM0wzLABLPpVzMPqk3Gi
77Wjeec5U6vQa/RSe729h+//kqcRyjHvwGiB4mPSmSL/mhDGYbsws+HO8NaQxmFhHjUIEUSRcW0S
8N7HMTX5o3AxOYpQWSLJ8f+DR4P+bS7SKtB0wkeQEHHOkD6w/wZRzDVeckASIzfEtC1W+Ju/qEPc
Fagib3J/EV6/XL7g0Q0QSm9ozpBH1pAPgL+oqJKzXPqW50LnkjsmDSD/OaIyQXNI/9HuYNRUSIDz
8F9co3u+n5jduqpcfZ0QAAAAAwD9P1IDAAAeAEIQAQAAACEAAAA8MTk5OTExMjUyMDU1Lk1BQTEy
MDM1QHRvYWQuY29tPgAAAAADAN4/r28AAAsAAYAIIAYAAAAAAMAAAAAAAABGAAAAAAOFAAAAAAAA
AwACgAggBgAAAAAAwAAAAAAAAEYAAAAAEIUAAAAAAAADAAOACCAGAAAAAADAAAAAAAAARgAAAABS
hQAA4xUAAB4ABYAIIAYAAAAAAMAAAAAAAABGAAAAAFSFAAABAAAABAAAADguNQALAA6ACCAGAAAA
AADAAAAAAAAARgAAAAAGhQAAAAAAAAMABIAIIAYAAAAAAMAAAAAAAABGAAAAAAGFAAAAAAAACwAG
gAggBgAAAAAAwAAAAAAAAEYAAAAADoUAAAAAAAADAAeACCAGAAAAAADAAAAAAAAARgAAAAARhQAA
AAAAAAMACIAIIAYAAAAAAMAAAAAAAABGAAAAABiFAAAAAAAAHgAJgAggBgAAAAAAwAAAAAAAAEYA
AAAANoUAAAEAAAABAAAAAAAAAB4ACoAIIAYAAAAAAMAAAAAAAABGAAAAADeFAAABAAAAAQAAAAAA
AAAeAAuACCAGAAAAAADAAAAAAAAARgAAAAA4hQAAAQAAAAEAAAAAAAAACwAMgAsgBgAAAAAAwAAA
AAAAAEYAAAAAAIgAAAAAAAALAA2ACyAGAAAAAADAAAAAAAAARgAAAAAFiAAAAAAAAAMAJgAAAAAA
AwA2AAAAAAAeADFAAQAAAAgAAABXUk9ER0VSAAMAGkAAAAAAHgAwQAEAAAAIAAAAV1JPREdFUgAD
ABlAAAAAAAMAgBD/////AgH5PwEAAABMAAAAAAAAANynQMjAQhAatLkIACsv4YIBAAAABgAAAC9P
PUdBTk5FVFQvT1U9VVNBVFNNVFAvQ049UkVDSVBJRU5UUy9DTj1XUk9ER0VSAB4A+D8BAAAAEAAA
AFJvZGdlciwgV2lsbGlhbQAeADhAAQAAAAgAAABXUk9ER0VSAAIB+z8BAAAATAAAAAAAAADcp0DI
wEIQGrS5CAArL+GCAQAAAAYAAAAvTz1HQU5ORVRUL09VPVVTQVRTTVRQL0NOPVJFQ0lQSUVOVFMv
Q049V1JPREdFUgAeAPo/AQAAABAAAABSb2RnZXIsIFdpbGxpYW0AHgA5QAEAAAAIAAAAV1JPREdF
UgBAAAcwYNbeR4k6vwFAAAgwChXjGYk6vwEeAD0AAQAAAAUAAABSRTogAAAAAB4AHQ4BAAAAFAAA
AGRyYWZ0IHJlZ3VsYXRpb25zPyAACwApAAAAAAALACMAAAAAAAMABhD9qiemAwAHEEoRAAADABAQ
AQAAAAMAERABAAAAHgAIEAEAAABlAAAALS0tLS1PUklHSU5BTE1FU1NBR0UtLS0tLUZST006Sk9I
TkdJTE1PUkVNQUlMVE86R05VQFRPQURDT01TRU5UOlRIVVJTREFZLE5PVkVNQkVSMjUsMTk5OTM6
NTVQTVRPOlJPRAAAAAA/Ew==
------_=_NextPart_000_01BF3A89.19E3150A--