Re: [Full-disclosure] Questions regarding cryptography laws

2011-09-08 Thread Jeffrey Walton
On Wed, Sep 7, 2011 at 8:44 AM, Sihan sihanzh...@gmail.com wrote:
 Hello list!

 This is my first time posting software on sourceforge, and I see this:
 This project DOES incorporate, access, call upon or otherwise use
 encryption. Posting of open source encryption is controlled under U.S.
 Export Control Classification Number ECCN 5D002 and must be simultaneously
 reported by email to the U.S. government. You are responsible for submitting
 this email report to the U.S. government in accordance with procedures
 described
 in:http://www.bis.doc.gov/encryption/PubAvailEncSourceCodeNotify.htmland
 Section 740.13(e) of the Export Administration Regulations (EAR) 15 C.F.R.
 Parts 730-772.

 I am in Canada, so i assume this does not apply to me. But are there any
 paperwork I should do in Canada?
Yes, it does apply. If you need guidance, call the Bureau of Exporter
Services, Encryption Division. They are very helpful.

This address is the NSA:

Attn: ENC Encryption Request Coordinator
9800 Savage Road, Suite 6940
Ft. Meade, MD 20755-6000

Jeff

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] Questions regarding cryptography laws

2011-09-07 Thread Valdis . Kletnieks
On Wed, 07 Sep 2011 08:44:14 EDT, Sihan said:


 I am in Canada, so i assume this does not apply to me. But are there any 
 paperwork I should do in Canada?

As a practical matter, nobody sane cares if you use OpenSSL anymore.  If you're
lving in an insane country, or doing crypto other than OpenSSL, you may have an
issue.

If you live in an insane country, good luck. If you're doing crypto other than
OpenSSL, again, good luck - hope you got enough cryptographers to look at it to
make sure it's actually secure. ;)



pgpNKSMfORNRY.pgp
Description: PGP signature
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Questions regarding cryptography laws

2011-09-07 Thread Walter van Holst
On Wed, 07 Sep 2011 08:44:14 -0400, Sihan wrote:
 Hello list!

  This is my first time posting software on sourceforge, and I see
 this:
  This project DOES incorporate, access, call upon or otherwise use
 encryption. Posting of open source encryption is controlled under 
 U.S.
 Export Control Classification Number ECCN 5D002 and must be
 simultaneously reported by email to the U.S. government. You are
 responsible for submitting this email report to the U.S. government 
 in
 accordance with procedures described
 in:http://www.bis.doc.gov/encryption/PubAvailEncSourceCodeNotify.html
 [1]and Section 740.13(e) of the Export Administration Regulations
 (EAR) 15 C.F.R. Parts 730-772.

  I am in Canada, so i assume this does not apply to me. But are there
 any paperwork I should do in Canada?

Your assumption is wrong. Sourceforge is in the USA, and has per their 
usage conditions made you responsible for their paperwork in the USA. 
Moreover, Canada is like most western countries a signatory to the 
Wassenaar Agreement on export controls, so this rule effectively applies 
to you as well.

Regards,

  Walter

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] Questions regarding cryptography laws

2011-09-07 Thread Peter Dawson
Canada Law and policy

http://www.ic.gc.ca/eic/site/ecic-ceac.nsf/eng/h_gv00084.html

/pd
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/