4 ms·
I often hear that (quote the article) "Government export controls crippled Internet security and the design of Internet protocols from the very beginning" Can
by colorincorrect 8y ago
I often hear that (quote the article) "Government export controls crippled Internet security and the design of Internet protocols from the very beginning"
Can anyone give me examples of which a design flaw in the protocol results directly in poorer security, and how it could have been better designed?
Not that I doubt the claim but I am not literate in this area.
- roel_v 8y agoAccording to this article, without export controls, X would have had strong crypto baked in. So the 'flaw' is that it was designed, well, without crypto.
- stordoff 8y agohttps://en.wikipedia.org/wiki/Export_of_cryptography_from_the_United_States https://en.wikipedia.org/wiki/Export_of_cryptography_from_th... is probably a good place to start. One fairly concrete example: > Shortly afterward, Netscape's SSL technology was widely adopted as a method for protecting credit card transactions using public key cryptography. Netscape developed two versions of its web browser. The "U.S. edition" supported full size (typically 1024-bit or larger) RSA public keys in combination with full size symmetric keys (secret keys) (128-bit RC4 or 3DES in SSL 3.0 and TLS 1.0). The "International Edition" had its effective key lengths reduced to 512 bits and 40 bits respectively (RSA_EXPORT with 40-bit RC2 or RC4 in SSL 2.0, SSL 3.0 and TLS 1.0), by zero-padding 88 bits of the normal 128-bit symmetric key. Acquiring the 'U.S. domestic' version turned out to be sufficient hassle that most computer users, even in the U.S., ended up with the 'International' version, whose weak 40-bit encryption could be broken in a matter of days using a single computer. A similar situation occurred with Lotus Notes for the same reasons. It's not necessarily a design flaw in the protocol, but it has basically the same effect.