NODE 3bf3e780Re: CryptoAPI and export question
Bill Stewart <stewarts@ix.netcom.com>Sat, 20 Jan 1996 13:07:23 +0800
Tom Johnston <tomj@microsoft.com>:
At 06:07 PM 1/17/96 EST, you wrote:
>Two points: the CSP development kit is export-controlled; and signing a
>CSP developed by a foreign vendor is treated as a export -- so the signature
>is export-controlled.
>
>We would ship a CSP development kit to a foreign vendor, and sign a CSP
>developed by the foreign vendor, but only with the appropriate export licenses.
Thanks for your reply to Dr. Vulis's question. I'd recommend examining this
policy somewhat critically, for a couple of reasons:
1) Development kits are useful, but if you've got an open, documented
interface, it's possible to develop code to use it without the kit.
(Ignoring, of course, the risk of smuggling. :-)
2) By "is treated as an export", do you mean by explicit government policy,
or by Microsoft? Digital signatures and encrypted documents are perfectly
legal to export, as is authentication code to make digital signatures.
3) Consider the case of a contractor who buys the development kit,
and gives you code to sign. You have no way to differentiate between
code that he developed himself, and code developed by some foreign
company that hired him and gave him the code (which is legal to import
into the US.) He probably can't legally re-export the code, or export
the signed version of it, but he can export the signature itself,
since that's not cryptographic code, and the foreign company can
reattach it to their original document, which you have now signed....
#--
# Thanks; Bill
# Bill Stewart, stewarts@ix.netcom.com, Pager/Voicemail 1-408-787-1281
#
# "Eternal vigilance is the price of liberty" used to mean us watching
# the government, not the other way around....
NODE 6c0527baRe: CryptoAPI and export question
Jiri Baum <jirib@sweeney.cs.monash.edu.au>Sat, 20 Jan 1996 19:50:03 +0800
-----BEGIN PGP SIGNED MESSAGE-----
Hello Tom Johnston <tomj@microsoft.com>
and Bill Stewart <stewarts@ix.netcom.com>
and cypherpunks@toad.com
Bill Stewart wrote:
...
> 3) Consider the case of a contractor who buys the development kit,
...
> into the US.) He probably can't legally re-export the code, or export
> the signed version of it, but he can export the signature itself,
> since that's not cryptographic code, and the foreign company can
> reattach it to their original document, which you have now signed....
...
This is not that difficult for MS to work around - for example, they
could modify the code harmlessly before signing it. Unless you
know *how* they modified it, you can't reproduce it.
Example: some assembly instructions have more than one machine
code representation. MS could put some kind of cryptographically
strong pattern into these (ie one that can't be reverse-engineered).
ObCrypto: Stego in .EXE files?
Jiri
- --
If you want an answer, please mail to <jirib@cs.monash.edu.au>.
On sweeney, I may delete without reading!
PGP 463A14D5 (but it's at home so it'll take a day or two)
PGP EF0607F9 (but it's at uni so don't rely on it too much)
-----BEGIN PGP SIGNATURE-----
Version: 2.6.2i
iQCVAwUBMQDT7ixV6mvvBgf5AQEEAwP/fJqfsCP1sA4ojwivHBeVxLpSfpKXEjpp
MgcHSVnFWkw1ezPUAmC9tugT0NEtIIDDs4ntDHUUa6Ki/bH1QFxqD5Gw8OCeGDJU
UQc/Y1o0K6XSAsiYWfEOE6fCnG3pbxGAc8s3Sz+TZbAhr0pqXIf3t1t6CNP3+dBn
Gnuq+OyIv5E=
=tfG3
-----END PGP SIGNATURE-----