// COMPLETE THREAD

Re: NSA, ITAR, NCSA and plug-in hooks.

3 expanded posts ยท every known parent and child

NODE 3652786bRe: NSA, ITAR, NCSA and plug-in hooks.
As I said in my original message about Pegasus:
	The NSA consider this kind of thing "crypto with a hole"
	It's stupid, the hole is the crypto.  But, the rest of
	the code is considered by the Agency to be an "ancilliary
	device" as defined under ITAR.
NODE dda8686aRe: NSA, ITAR, NCSA and plug-in hooks.
On Tue, 14 Nov 1995, Rich Salz wrote:

> As I said in my original message about Pegasus:
> 	The NSA consider this kind of thing "crypto with a hole"
> 	It's stupid, the hole is the crypto.  But, the rest of
> 	the code is considered by the Agency to be an "ancilliary
> 	device" as defined under ITAR.

The interesting question is how narrow the interface has to be before it 
becomes in violation of the ITAR. Is the key question whether the "holes" 
are specifically designed for the insertion of cryptographic materials, 
or is it the fact that they could be used to support cryptographic 
enhancements?
NODE c5c8413fRe: NSA, ITAR, NCSA and plug-in hooks.
Simon Spero writes:
>The interesting question is how narrow the interface has to be before it 
>becomes in violation of the ITAR. Is the key question whether the "holes" 
>are specifically designed for the insertion of cryptographic materials, 
>or is it the fact that they could be used to support cryptographic 
>enhancements?

If the ban *is* due to Category XIII (b) (5), the wording would
indicate that the "hole" must be "specifically designed or modified" to
support crypto.  One that was specifically designed to support some
sort of block compression library should be exempt under that
paragraph, even if someone else were to write and distribute a crypto
library with an identical interface.

'Course, IANAL, and the interpreters of the ITAR don't really seem to
care what it *says*, anyway.