// COMPLETE THREAD

Suggestion for "the serious encryption customers" to end ITAR battle

2 expanded posts ยท every known parent and child

NODE c65ace67Suggestion for "the serious encryption customers" to end ITAR battle
I think we can all agree that the level of confidence in software-only
approaches to security is clearly lower than combination software plus
hardware approaches.

It is clear that what is available over the Internet is software.  (It
is much harder to distribute "hardware" as you can only really
distribute design information.  The closest analogy could be a FPGA
program, a Verilog description or some other ASIC net list.)

How about the following as an approach to resolving the dispute over
encryption exports:

1.  Allow arbitrary exports of software-only encryption.

    This means that PGP is exportable as is DES crypt libraries.

2.  Restrict exports of hardware-only or hardware/software encryption.

    This means that smart cards, HP's crypto policy cards, crypto
    processors with tamper-resistant casing, etc ... are restricted.

Why does this make sense?

1.  Reality check on export control of software:

    Software is just too transportable to be restricted, no matter
    WHAT the software does.  Any restriction on WHERE software may be
    or may go is just not feasible, and it's not going to get any
    easier in the foreseeable future.

2.  Take John Deutch at his word:

    Deutch has claimed that "serious users of cryptography" would not
    trust software downloaded over the Internet.  We clearly do not
    agree with him on this aspect, but if he truly believes it (and is
    not just making PR spin statements for the NSA), then he must
    believe that allowing software exports will not significantly
    increase the user base (and therefore, harm CIA's or NSA's
    intelligence capabilities), but it will shut up the software
    companies' complaints.

3.  Give the NSA what it wants:

    Software tends to standardize.  Encryption is only a small part of
    the chain of security measures.  Other weaknesses are surely part
    of the NSA's target for intercepts (no self-respecting
    codebreaking agency should stick to exploiting only one class of
    failures; if it is, we should question the value we are getting
    out of the billions of dollars we blindly give to the NSA).  If
    the NSA stops whining about what is too hard to break, then
    protocol weakness and other non-encryption problems could easily
    creep into standards, and the NSA would surely have an analytical
    advantage over anyone else.

    Since the NSA is happily bragging that it does not even need to
    crack the code to break in, it should be able to live with
    hardware-only export restriction.  The fact that the NSA is no
    longer drawing any lines anywhere for software will leave the bad
    guys guessing as to what it can really decode.

    In addition, hardware manufacturers will probably have a tougher
    overturning export restrictions on hardware-enhanced solutions
    after that because software companies will probably not care.  It
    is clear that the NSA only trusts hardware implementations, as it
    required Clipper to be manufactured in tamper-resistant cases.

All constructive replies welcome.

Ern
NODE 08aef190Re: Suggestion for "the serious encryption customers" to end ITARbattle
At 3:37 PM -0800 12/4/96, Ernest Hua wrote:
>I think we can all agree that the level of confidence in software-only
>approaches to security is clearly lower than combination software plus
>hardware approaches.
>
>It is clear that what is available over the Internet is software.  (It
>is much harder to distribute "hardware" as you can only really
>distribute design information.  The closest analogy could be a FPGA
>program, a Verilog description or some other ASIC net list.)

But of course this is a distinction without a difference, at least for all
but 0.00073% of Internet users. That is, downloading a Verilog or whatever
description would be no more "verifiable to the user" than a software-only
program. In fact, the hardware description _is_ just another program!


>How about the following as an approach to resolving the dispute over
>encryption exports:
>
>1.  Allow arbitrary exports of software-only encryption.

The government will of course not be fooled by this. Whether one accepts my
point that hardware = software (effectively), the government has heretofore
seen software as an important issue.

In fact, I will take issue with my distinguished colleague (are you
satisfied, Logos?) Ernest Hua's point that only hardware provides real
security. To whit, for several years we on the Cypherpunks list have
advocated this strategy:

-- standardized hardware, such as PCs and Soundlaster cards

-- community-checkable software, such as PGP

This combination is preferable to "black boxes" which the average user
cannot verify (not that the average user can verify, say, PGP, but digital
signatures means the average user can more effectively "trust" the
consensus of those who _have_ looked at, say, PGP 2.6ui, and have vouched
for it.

(This debate came up several times when people proposed specialized
hardware, which would be a) hard to verify, b) hard to distribute widely,
and c) something very few people would casually try. Regardless of our
arguments--though perhaps confirming them--there have been no commonly used
hardware widgets or cards used by any significant number of us.)

>2.  Take John Deutch at his word:
>
>    Deutch has claimed that "serious users of cryptography" would not
>    trust software downloaded over the Internet.  We clearly do not
>    agree with him on this aspect, but if he truly believes it (and is
>    not just making PR spin statements for the NSA), then he must
>    believe that allowing software exports will not significantly
>    increase the user base (and therefore, harm CIA's or NSA's
>    intelligence capabilities), but it will shut up the software
>    companies' complaints.

I don't think he believes this. Think: FUD. There is no evidence that
properly authenticated PGP is "weak." And if it were, John Deutch would be
a fool to cast doubt on it. I think they're terrified as hell about
software-only approaches running on widely-available hardware and would
like nothing more than to see hardware-only approaches mandated (as this
would provide slightly more control over exports and distibution). Not that
this'll happen, of course.

--Tim May

Just say "No" to "Big Brother Inside"
We got computers, we're tapping phone lines, I know that that ain't allowed.
---------:---------:---------:---------:---------:---------:---------:----
Timothy C. May              | Crypto Anarchy: encryption, digital money,
tcmay@got.net  408-728-0152 | anonymous networks, digital pseudonyms, zero
W.A.S.T.E.: Corralitos, CA  | knowledge, reputations, information markets,
Higher Power: 2^1398269     | black markets, collapse of governments.
"National borders aren't even speed bumps on the information superhighway."