On 20 Jun 2000, Rhett R. Rodewald wrote:

> >*You* fail to understand the problem if you think the US government has
> >anything to do with the problem.  The US government only restricts the
> >*export* of crypto code, not its use, and even that is no longer true if
> >you fill out enough paperwork.  The only difference the lack of export
> >restrictions would make is that the International SSL code could be hosted
> >on Holger's server instead of Vapor's.
> 
> Actually, Fred,  I think the problem is in the _possibility_ of an
> "international" user downloading the "US" version -- and thus "exporting" it.
> Therefore it is not simply a link.  The government has significantly relaxed

This is true, but what I was responding to, which you snipped, was the
claim that the US government is restricting the cryptographic code that
can be *used in the US*, and that *that* is the reason for the different
versions of the SSL code.  That was *never* true.

> the rules in the last 6 months or so -- but if I were Holger, I wouldn't
> change anything until it became standard operating procedure for other
> companies to do the same.  Perhaps even wait for a court battle or two to

No, it's just a question of whether Holger wants to do the paperwork for
an export license.

> Last I checked, you still had to go through 500 screens of "provide us with
> all request information, including the last time you clipped your toenails,
> and certify that you are a US citizen, downloading from a US IP address, for
> use only in the United States...  yada, yada, yada..." before you can
> download IE or Netscrape with 128 bit encryption.  This may have changed
> since congress loosened things up -- but I'll bet they still have the
> download sites reverse-check IP addresses before you can download.

You obviously haven't checked the Netscape site lately.  Now you simply
have to certify that you're not on one of the countries in the "bad guy"
list (e.g. Iraq), and that you won't further export it. 

> P.S.  I believe that you _can_ download the international version and use it.
>       Although this is of questionable legality, you should be much better
>       off IMPORTing crypto than EXPORTing it under current US law.
>       (But if I needed it...  nudge, nudge, wink, wink, know-what-I-mean...)

As I stated previously, that has always been perfectly legal with respect
to government regulations, and it's just a question of whether RSADSI will
sue you for violating their intellectual property rights.  Obviously
Holger can't encourage that, or they'd sue *him*.

As of next September 20, it will be perfectly legal to use "international"
implementations of RSA in the US, leaving RC4/ARCFOUR as the only legally
required difference between the versions.

                                        Fred Wright


-- 

To unsubscribe send "unsubscribe miami-talk-ml" to
"[EMAIL PROTECTED]". For help on list commands send "help" to
"[EMAIL PROTECTED]".


Reply via email to