NODE 6f8afda4Australian "ITAR" regulations
Sherry Mayo <scmayo@rschp2.anu.edu.au>Thu, 19 Sep 1996 16:17:03 +0800
Hi all
Some time ago I had various email exchanges regarding Australian crypto
export regulations. More recently I've been put in the picture by David
Cox and others that there are in fact ITAR-like laws in force in Australia.
The last time I looked into this, Matt Crean(?) had very little luck finding
any info from the various relevant departments, have of whom didn't seem
to have a clue.
In short, Crypto export from Australia is illegal without a licence -
this is making it difficult for David's software firm to compete
with their unhampered German competition.
Using the following search URL you can find the relevant text (shortened
version appended))
http://www.austlii.edu.au/cgi-bin/sinodisp.pl/au/legis/cth/consol_reg/cer439/sch13.html?query=cryptographic
However, if anything is done about ITAR in the US, I wouldn't be at all
surprised if Australia follows suit.
Sherry
ps There is an awful lot of crap on c'punks these days - reading it is a bit
of a needle in a haystack exercise ;-(
=========================
CUSTOMS (PROHIBITED EXPORTS) REGULATIONS - SCHEDULE 13
MILITARY AND NON-MILITARY GOODS (EXPORTATION PROHIBITED
EXCEPT ON PRODUCTION OF A LICENCE OR PERMISSION UNDER
REGULATION 13B)
>>>[snip]<<<
43. Other goods as follows:
(a) complete or partially complete cryptographic equipment
designed to ensure the secrecy of communications (including
data communications and communications through the medium of
telegraphy, video, telephony and facsimile) or stored
information;
(b) software controlling, or computers performing the
function of, cryptographic equipment referred to in
paragraph (a);
(c) parts designed for goods referred to in paragraphs (a)
or (b);
(d) applications software for cryptographic or cryptanalytic
purposes including software used for the design and analysis
of cryptologics;
(e) radio transmitters and receivers for spread spectrum or
frequency agile communications systems having a total
transmitted bandwidth that is:
(i) 100 or more times greater than the bandwidth of any one
information channel in the system;
(ii) in excess of 50 kilohertz; or
(iii) designed or modified to use cryptographic techniques
to generate the spreading code for spread spectrum or the
hopping code for frequency agile systems;
(f) parts designed or adapted for goods referred to in
paragraph (e);
(g) software and equipment designed or adapted for
controlling the functions of goods referred to in paragraph
(e) ;
(h) information security systems, equipment, software,
application specific assemblies, modules or integrated
circuits, designed or modified to provide certified or
certifiable multi-level security of user-isolation at a
level exceeding Class E4 of the Information Technology
Security Evaluation Criteria (ITSEC) or equivalent in force
at the commencement of these Regulations;
(i) software designed or adapted for the purpose of
demonstrating that the information security features
referred to in paragraph (h) provide a multi-level security
or user-isolation function.
NODE d5d1f189Re: Australian "ITAR" regulations
Matthew Gream <matt@lust.bio.uts.edu.au>Fri, 20 Sep 1996 02:40:52 +0800
Hi Sherry,
> Some time ago I had various email exchanges regarding Australian crypto
> export regulations. More recently I've been put in the picture by David
> Cox and others that there are in fact ITAR-like laws in force in Australia.
> The last time I looked into this, Matt Crean(?) had very little luck finding
> any info from the various relevant departments, have of whom didn't seem
> to have a clue.
Yes I did in fact investigate this area back in 1994. I managed to obtain
sufficient information to indicate that there were ITAR like controls in
place. My liasons with departments did result in some vague answers though,
but the legislation was clear. You can find details about my findings at:
http://www.next.com.au/spyfood/geekgirl/001stick/crypto/aust/index.html
I've not revisited the area since that time, so there may have been
recent developments.
As you have mentioned, there are indeed controls. The regulations enforce
these through two mechanisms; the first being explict coverage in the
Prohibited Exports Regulations, and the second through COCOM related DUT
controls via. documentation referenced in said regulations. This latter
area may have been revised with recent COCOM activity.
At the time, and I suspect still at this point in time, there seems to be
little awareness that these controls are in place.
Cheers,
Matthew.
--
Matthew Gream -- matt@lust.bio.uts.edu.au.