NODE 3652786bRe: NSA, ITAR, NCSA and plug-in hooks.
Rich Salz <rsalz@osf.org>Wed, 15 Nov 1995 03:52:00 +0800
As I said in my original message about Pegasus:
The NSA consider this kind of thing "crypto with a hole"
It's stupid, the hole is the crypto. But, the rest of
the code is considered by the Agency to be an "ancilliary
device" as defined under ITAR.
NODE dda8686aRe: NSA, ITAR, NCSA and plug-in hooks.
Simon Spero <ses@tipper.oit.unc.edu>Wed, 15 Nov 1995 04:26:30 +0800
On Tue, 14 Nov 1995, Rich Salz wrote:
> As I said in my original message about Pegasus:
> The NSA consider this kind of thing "crypto with a hole"
> It's stupid, the hole is the crypto. But, the rest of
> the code is considered by the Agency to be an "ancilliary
> device" as defined under ITAR.
The interesting question is how narrow the interface has to be before it
becomes in violation of the ITAR. Is the key question whether the "holes"
are specifically designed for the insertion of cryptographic materials,
or is it the fact that they could be used to support cryptographic
enhancements?
NODE c5c8413fRe: NSA, ITAR, NCSA and plug-in hooks.
Scott Brickner <sjb@universe.digex.net>Wed, 15 Nov 1995 05:29:36 +0800
Simon Spero writes:
>The interesting question is how narrow the interface has to be before it
>becomes in violation of the ITAR. Is the key question whether the "holes"
>are specifically designed for the insertion of cryptographic materials,
>or is it the fact that they could be used to support cryptographic
>enhancements?
If the ban *is* due to Category XIII (b) (5), the wording would
indicate that the "hole" must be "specifically designed or modified" to
support crypto. One that was specifically designed to support some
sort of block compression library should be exempt under that
paragraph, even if someone else were to write and distribute a crypto
library with an identical interface.
'Course, IANAL, and the interpreters of the ITAR don't really seem to
care what it *says*, anyway.