// COMPLETE THREAD

Re: ITAR financial crypto exception?

2 expanded posts ยท every known parent and child

NODE 92cc5a5bRe: ITAR financial crypto exception?
At  8:25 PM 11/1/96 -0800, Greg Broiles quoted:
>According to the "United States Munitions List", 22 CFR 121.1, Category
>XIII, "Auxiliary Military Equipment":
>
>"Information Security Systems and equipment, cryptographic devices,
>software, and components specifically designed or modified therefor" are
>included in the munitions list; but not if they are 
>
>"[s]pecially designed, developed or modified for use in machines for
>banking or money transactions, and restricted to use only in such
>transactions. Machines for banking or money transactions include automatic
>teller machines, self-service statement printers, point of sale terminals
>or equipment for the encryption of interbanking transactions." (22 CFR
>121.1, Category XIII (b)(1)(ii)),
>
>or if they are 
>
>"[l]imited to access control, such as automatic teller machines,
>self-service statement printers or point of sale terminals, which protects
>password or personal identification numbers (PIN) or similar data to prevent
>unauthorized access to facilities but does not allow for encryption of
>files or
>text, except as directly related to the password of PIN protection." (22
>CFR 121.1, Category XIII (b)(1)(v)).

I don't think either of these exclusions would cover the reference
implementation of the SET protocol.  I don't think it would cover an
electronic commerce application running on a personal computer/workstation
either.  Therefore I conclude that the ITAR is contributing to the
vulnerability of our emerging electronic commerce infrastructure.


-------------------------------------------------------------------------
Bill Frantz       | Tired of Dole/Clinton?     | Periwinkle -- Consulting
(408)356-8506     | Vote 3rd party.  I'm       | 16345 Englewood Ave.
frantz@netcom.com | Voting for Harry Browne    | Los Gatos, CA 95032, USA
NODE 634e61caWhat happened to the NSA's _second_ mission?
(president@whitehouse.gov removed from the cc: list for obvious reasons)

At 10:09 AM -0800 11/2/96, Bill Frantz wrote:

>I don't think either of these exclusions would cover the reference
>implementation of the SET protocol.  I don't think it would cover an
>electronic commerce application running on a personal computer/workstation
>either.  Therefore I conclude that the ITAR is contributing to the
>vulnerability of our emerging electronic commerce infrastructure.

Given the reported statistics on the _meager_ number of serious crimes
which have been stopped by the use of surveillance and wiretaps (reported
in various forms several times in recent months), and given that electronic
commerce may be vulnerable to _serious_ disruptions, one has to (again)
wonder if the charter of the National _Security_ Agency needs a careful
reevaluation.

Some years back, the NSA was more explicitly divided into two functions,
one function doing SIGINT/COMINT, and the other doing COMSEC and INFOSEC,
i.e., working on mechanisms to better secure the nation's communicaitons.
At about this time, circa 1988, the NSA's COMSEC folks were _explicitly_
warning that DES was long overdue for replacement and that new measures
were urgently needed to secure the nation's communications and financial
infrastructure. (The details have faded in my memory, but I believe this
was the time the "Commercial COMSEC Endorsement" program was being
discussed, with various hardware and software being proposed....don't know
how it eventually turned out, faded out, etc.)

So where are we today? Almost 10 years later, with huge advances in chip
power and density (500 MHz processors, 250,000-gate-equivalent PLDs, etc.),
and yet what do we have? Only plain old DES-level cryptography is being
encouraged, with various roadblocks placed in front of efforts to deploy
stronger crypto.

Jeesh. To supposedly wiretap a few terrorists we risk the whole enchilada.

Of course, I suspect the real issue is that the NSA understands the
implications of strong crypto, anonymous remailers, untraceable digital
cash, etc., and is thus taking what steps it thinks it can to limit the
spread of these technologies. The wiretap stuff is just a figleaf.

--Tim May




"The government announcement is disastrous," said Jim Bidzos,.."We warned IBM
that the National Security Agency would try to twist their technology."
[NYT, 1996-10-02]
We got computers, we're tapping phone lines, I know that that ain't allowed.
---------:---------:---------:---------:---------:---------:---------:----
Timothy C. May              | Crypto Anarchy: encryption, digital money,
tcmay@got.net  408-728-0152 | anonymous networks, digital pseudonyms, zero
W.A.S.T.E.: Corralitos, CA  | knowledge, reputations, information markets,
Higher Power: 2^1,257,787-1 | black markets, collapse of governments.
"National borders aren't even speed bumps on the information superhighway."