// COMPLETE THREAD

Precedent for PGP legality

4 expanded posts ยท every known parent and child

NODE 0199f5acPrecedent for PGP legality
Found on alt.security.pgp. This might be worth researching and putting in a
future PGP manual. While it wouldn't keep PKP from harassing commercial
services into taking PGP down, it might help to keep keyservers and the
like alive. This is a court decision that found the construction of a
patented device for nonprofit purposes is not an infringement.

From: cjohnst@xmission.com (Charles Johnston)
Newsgroups: alt.security.pgp
Subject: PGP could be perfectly legal in the United States!!!!!

I was researching in the University of Utah law library nearby,
and I found a case that talks about patents and
private/experimental use.

It's 73 Fed 206,211 if you're interested in looking it up.
I haven't Shepardized it yet (found all future cases 
affecting the opinions), but here it is.

This is Bonsack Mach. Co. v. Underwood

Speaking of patents:

"The making of an infringing machine merely as an experiment
is not an actionable infringment..."

and

"To constitute an infringement, the making must be with an
intent to use for profit, and not for the mere purpose of
a philosophical experiment."

This seems to say that PGP is okay to use!  I would appreciate
ANY comments!  I will be researching this further REALLY soon!

By the way, when was the RSA patent granted?  They only last
17 years!

Charles Johnston
NODE 18b71419Re: Precedent for PGP legality
Mike Ingle (whose post I am replying to) or Charles Johnston (whose
name was included at the bottom of the post) writes:

> like alive. This is a court decision that found the construction of a
> patented device for nonprofit purposes is not an infringement.
...

> This seems to say that PGP is okay to use!  I would appreciate
> ANY comments!  I will be researching this further REALLY soon!

Yes, this is well-known and is mentioned, I believe, in the PGP docs.
Private use for experimental purposes, or for the purposes of
improving an invention, are recognized legit uses. Implementing RSA as
a class project or textbook problem is common, and RSADSI will not
bother with such cases. (Nor has RSADSI bothered any users of PGP, if
truth be told, unless they were involved in the hassling of Zimmermann
vis-a-vis the grand jury investigation...which hasn't been established
one way or another.)

Where it gets dicey is when people are using an invention in a way
that circumvents the patent rights of the inventor. The common use of
PGP is clearly for communication, for most people, not for study on
their home machines of how the algorithm works, how it might be
improved, etc.

I'm not arguing RSADSI's side, merely pointing out that calling the
growing use of PGP for communication and the signing of articles an
"experiment" is misleading, and even disingenuous. Not to sound like
Sterno here, but I think the lawyers here will back me up on this.

Now maybe the RSA patents are invalid, maybe the fact that public
money was used to support the researches at Stanford and MIT that led
to public key and RSA means "we" own the patents (not supported by
decisions, though), etc. 

In any case, I think PGP is the best thing that has ever happened to
the popularity of RSA and RSADSI, and I have told Jim Bidzos this.

> By the way, when was the RSA patent granted?  They only last
> 17 years!
> 
> Charles Johnston

The "cloud" of P-K and RSA patents begins to expire in 1997 or 1998
and the last of the original five expires in 2002. The five patents
have been listed several times here and many times in sci.crypt, so
watch that space for details--or rummage through your archived mail.

RSADSI has tried to ensure its future licensing revenue stream by
acquiring other patents. It recently bought the "Schnorr" patent,
which apparently covers the DSS/DSA digital signature algorithm. This
patent will run until 2010 or later, I gather.

--Tim May


-- 
..........................................................................
Timothy C. May         | Crypto Anarchy: encryption, digital money,  
tcmay@netcom.com       | anonymous networks, digital pseudonyms, zero
408-688-5409           | knowledge, reputations, information markets, 
W.A.S.T.E.: Aptos, CA  | black markets, collapse of governments.
Higher Power:2**859433 | Public Key: PGP and MailSafe available.
NODE 7d76b46aRe: Precedent for PGP legality
Timothy C. May sez:
> 
> Yes, this is well-known and is mentioned, I believe, in the PGP docs.
> Private use for experimental purposes, or for the purposes of
> improving an invention, are recognized legit uses. Implementing RSA as
> a class project or textbook problem is common, and RSADSI will not
> bother with such cases. (Nor has RSADSI bothered any users of PGP, if
> truth be told, unless they were involved in the hassling of Zimmermann
> vis-a-vis the grand jury investigation...which hasn't been established
> one way or another.)

It is true that there was a great deal of enmity between RSA's
president, Jim Bidzos, and Phil but that was just starting to thaw a
year or so ago when I let Jim know that Phil was interested in
licensing RSA's patents (for those that haven't bothered to check,
RSA's fees are incredibly reasonable) because there were some
businesses interested in using PGP that wouldn't because of its
geurillaware status.  I believe that they worked something out or Phil
would not have been pursuing the commercial work he got busted/hassled
for by the fed.  I don't think that RSA deserves any suspicion with
regard to Phil's troubles.

> 
> Where it gets dicey is when people are using an invention in a way
> that circumvents the patent rights of the inventor. The common use of
> PGP is clearly for communication, for most people, not for study on
> their home machines of how the algorithm works, how it might be
> improved, etc.
> 
> I'm not arguing RSADSI's side, merely pointing out that calling the
> growing use of PGP for communication and the signing of articles an
> "experiment" is misleading, and even disingenuous. Not to sound like
> Sterno here, but I think the lawyers here will back me up on this.

Yes, I was told by a patent attorney that the way we use PGP is
not within the experimental guideline and we are probably standing
in violation of these patents.  Not that that means much, RSA 
is not about to joust windmills by trying to mess with anybody.

> 
> Now maybe the RSA patents are invalid, maybe the fact that public
> money was used to support the researches at Stanford and MIT that led
> to public key and RSA means "we" own the patents (not supported by
> decisions, though), etc. 

A whole lot of precedent for this.  It is in effect one way that the
federal government helps support research without direct taxation.
I read recently that Stanford rakes in an obscene amount each year
from the patents it holds but I really have no problem with that
since it benefits education as a whole.

> 
> In any case, I think PGP is the best thing that has ever happened to
> the popularity of RSA and RSADSI, and I have told Jim Bidzos this.

That's funny, in a weak moment *he* told me that a year ago.  :-)


Peace,

Bob

-- 
Bob Cain    rcain@netcom.com   408-354-8021


           "I used to be different.  But now I'm the same."


--------------PGP 1.0 or 2.0 public key available on request.------------------
NODE 5012c991Re: Precedent for PGP legality
Bob Cain writes:

> It is true that there was a great deal of enmity between RSA's
> president, Jim Bidzos, and Phil but that was just starting to thaw a
> year or so ago when I let Jim know that Phil was interested in

"Just starting to thaw"? Have you checked recently? As recently as
last Friday night, when I talked to Phil on the phone, the polar
icecap was small by comparison.

> licensing RSA's patents (for those that haven't bothered to check,
> RSA's fees are incredibly reasonable) because there were some
> businesses interested in using PGP that wouldn't because of its
> geurillaware status.  I believe that they worked something out or Phil
> would not have been pursuing the commercial work he got busted/hassled
> for by the fed.  I don't think that RSA deserves any suspicion with
> regard to Phil's troubles.

About Phil having worked something out, you are very misinformed. What
Phil did was to do an end-run arount RSA's objections, and without
RSA's foreknowledge, by working with ViaCrypt, which has already
obtained its own license. Reports are that Bidzos was furious, but
nothing could be done. (I haven't talked to Bidzos since last April,
so of course I can't confirm his side. I have confirmed this in talks
with Phil.)

About any RSA involvement with the Grand Jury issue, RSA was
interviewed and was copied on memos written by the investigators,
according to copies obtained (legally) by Phil Zimmermann. What this
means is anyone's guess, but it ought to be borne in mind.

I don't necessarily view Bidzos as an agent of the AntiChrist as some
do, but things are definitely complicated and soap operish. The "Phil
and Jim Show" has a few more episodes.

--Tim May


-- 
..........................................................................
Timothy C. May         | Crypto Anarchy: encryption, digital money,  
tcmay@netcom.com       | anonymous networks, digital pseudonyms, zero
408-688-5409           | knowledge, reputations, information markets, 
W.A.S.T.E.: Aptos, CA  | black markets, collapse of governments.
Higher Power:2**859433 | Public Key: PGP and MailSafe available.