3 ms·
I think it comes down to the question of; if you're passing data over a secure channel (SSL), does that fall within the U.S. governments compliance requirements
by coffee 16y ago
I think it comes down to the question of; if you're passing data over a secure channel (SSL), does that fall within the U.S. governments compliance requirements. mickdj had a link with a comment in it discussing this: http://stackoverflow.com/questions/2135081/does-my-application-contain-encryption/2341310#2341310 http://stackoverflow.com/questions/2135081/does-my-applicati... although, it's from earlier this year...
- Udo 16y agoPeople are allowed to bundle SSL implementations in their apps without being subject to export restrictions. I don't think it matters whether you call Apple's API to issue an HTTPS request on your behalf or whether you ship the library yourself, the latter of which is definitely legal because big-time software such as Firefox or Apache would have been sued out of existence a long time ago if it wasn't. Now, Apple (and possibly the government) might decide to see it differently, but this is the letter and spirit of the international agreement governing crypto export.
- dangrossman 16y agoSued out of existence? The process of exporting encryption software isn't that difficult. Fill out a form, send a copy of your source code to the NSA and you're done, generally. 10 minutes. That's second hand information but sounds reasonable to me given how much software uses encryption in some way.
- Udo 16y agoBecause if crypto export regulations actually were applied to SSL in practice, they'd have to prevent Apache and Firefox from getting into countries on the E:1 list, and possibly D:1 as well. And personally, I don't know any https-supporting website owner who ever filled out the mother-may-I crypto form. (see http://www.gpo.gov/bis/ear/pdf/740spir.pdf http://www.gpo.gov/bis/ear/pdf/740spir.pdf)