7 ms·
Announced officially to the mythical cypherpunks@toad.com mailing list... Fighting to legalize cryptography on the internet. PGP was banned. Sending encrypted
by joak 3y ago
Announced officially to the mythical cypherpunks@toad.com mailing list...
Fighting to legalize cryptography on the internet. PGP was banned. Sending encrypted emails was illegal...
Cypherpunks won. Thanks to them.
- IAmNotACellist 3y agoConspiracy-minded theory: only once the government successfully arranged for a process (behind closed doors) to subvert or capture any US-based cryptography efforts or communications.
- tptacek 3y agoWhere were you that PGP was banned, or encrypting emails was illegal?
- mratsim 3y agoCryptography was considered a war weapon and only allowed for military use. The United States had to be brought to court to finally allow cryptography: https://en.m.wikipedia.org/wiki/Bernstein_v._United_States https://en.m.wikipedia.org/wiki/Bernstein_v._United_States > Years before, the government had placed encryption, a method for scrambling messages so they can only be understood by their intended recipients, on the United States Munitions List, alongside bombs and flamethrowers, as a weapon to be regulated for national security purposes. Companies and individuals exporting items on the munitions list, including software with encryption capabilities, had to obtain prior State Department approval. — Electronic Frontier Foundation: EFF's History Before that, export rules could be "worked around" by printing cryptography in books. See also https://en.m.wikipedia.org/wiki/Export_of_cryptography_from_the_United_States https://en.m.wikipedia.org/wiki/Export_of_cryptography_from_...
- tiernano 3y agonot quite crypto related, or at least directly, i remember this old Mac G4 ad: https://youtu.be/lb7EhYy-2RE?si=3tvJK4BXbA71LbGQ https://youtu.be/lb7EhYy-2RE?si=3tvJK4BXbA71LbGQ
- lloeki 3y ago> Cryptography was considered a war weapon It still is. e.g in France: https://cyber.gouv.fr/en/protection-sensitive-and-restricted-information https://cyber.gouv.fr/en/protection-sensitive-and-restricted... This legal framework has been introduced in 2011 in order to protect facilities, knowledge, savoir-faire, information which, if intercepted, could: - Affect French economic interests (risk 1); - Reinforce military capacities of other country or weaken French military capacities (risk 2); - Lead to the proliferation of weapons of mass destruction in nuclear, ballistic, chemical or biological fields; - Lead to the development of terrorist activities on French territory or abroad. It's just that import/export constraints have been relaxed. See Annexe 1 here: https://www.legifrance.gouv.fr/loda/id/JORFTEXT000000646995?init=true&page=1&query=catégorie+3+de+l’annexe+2+du+décret+n°+2007-663+du+2+mai+2007&searchField=ALL&tab_selection=all https://www.legifrance.gouv.fr/loda/id/JORFTEXT000000646995?... This is one of the reasons why MobiusSync is not available in the French iOS App Store since it doesn't use iOS crypt which already has approval plus it doesn't fit into some of the exceptions to the restrictions, so they'd have to fill in paperwork which is only available in French and submit via snail mail (go figure, although they do accept answers written in English as a courtesy). https://github.com/MobiusSync/MobiusSync/issues/27 https://github.com/MobiusSync/MobiusSync/issues/27 Similar concerns, processes, and exceptions are effective for other countries, e.g for the U.S. you need Encryption Registration (ERN) approval from the U.S. Bureau of Industry (BIS). Exceptions are described in Category 5, Part 2 of the U.S. Export Administration Regulations.
- cjbprime 3y ago"You have to get an export license if you're distributing from inside the US to outside the US" is pretty different to "sending encrypted emails was illegal", no? For one thing, it sounds like sending wasn't impacted at all, once you had the software.
- mratsim 3y agoHow would you send encrypted email without an encryption library?
- Tor3 3y agoFrom what I remember, what was illegal was exporting a (useful) encryption library, and that Wikipedia link supports my memory: It talks about exporting munitions. I remember at the time that even though libraries existed inside the US they weren't supposed to be exported to other countries (i.e. the rest of us should get encryption libraries developed outside the US). Nothing prevented US citizens in the US to use encryption. Nothing in that "cryptography is considered munitions" legal issue, at least, because that was about export.
- Thorrez 3y agoThey can't use encryption if they can't get encryption software. I recall hearing that companies outside the US could distribute software with competent encryption without problems (to people inside and outside the US), but companies inside the US basically couldn't distribute software with competent encryption, because someone outside the US might download it.
- Tor3 3y agoBut I remember the time. The software could be downloaded from inside USA. Mid-nineties the internet wasn't particularly large and (what's nowadays) simple measures were in place. In practice you could get it from the US even if you were outside, but then again USA wasn't the only place where encryption software was made, so we all thought it a bit silly. What I'm getting at is that it's simply incorrect that encryption wasn't available in the US, and it's also incorrect that encryption couldn't or wasn't in use. It most definitely was. The regulations were only about export. 40 bits max and all that.
- TedDoesntTalk 3y agoSending encrypted email in the US was NOT illegal. Sharing encryption libraries was.
- mratsim 3y agoHow would you send encrypted emails without an encryption library?
- DonHopkins 3y agoYou're not reading or comprehending the multiple correct replies. I won't repeat them because apparently that won't get through to you, but you should go back and read them again and again until you understand, or at least stop repeating the same incorrect information, if not finally understanding the correct information people keep trying to tell you. https://en.wikipedia.org/wiki/Sealioning https://en.wikipedia.org/wiki/Sealioning
- rnmmrnm 3y agowoah I'm so glad he did it, I now got better picture of twitter altogether.
- mratsim 3y agoI am reading the replies. You don't understand the legal liabilities people open themselves to if they provide the software. Now they have to fully KYC customers to make sure they are from the US, with US only storage, and firewall so that people travelling cannot use the encryption library from out of the US. You've seen the lawsuits on just P2P link providers, this is even worse.
- SAI_Peregrinus 3y agoPeople inside the US could trade encryption libraries. They just couldn't send those libraries to outside the US. You could download a cryptography library from outside the US, and your foreign recipient could do the same, and thus send emails back & forth. In practice all it meant was that US developers couldn't write make useful cryptography libraries, and the development got done elsewhere. The US still restricts the export of (some) cryptography to (some) countries & organizations. Mostly that just requires submitting a self-classification report to the BIS stating that the cryptography is "mass market" and matches the definition thereof in the export regulations.
- deaddodo 3y agoThat's an oversimplification and also inferring a completely incorrect situation. It was perfectly fine for American citizens to use cryptography amongst each other or with outside nationals. It was also completely fine to download and use externally developed software. What was illegal was developing and exporting cryptographic software. This is why, for the longest time, you would see warnings on web pages (puTTy, for instance) saying the software was only intended for use in the United States.
- KMnO4 3y agoI remember publishing some apps to the iOS App Store and was asked to “declare cryptography to the US government”. I’m not even American. The form made it clear that using HTTPS is considered cryptography, so I’m fairly sure almost every app on the store has checked “yes” to that question.
- mratsim 3y agoI disagree. To fully comply with this you would need as a library provider to fully KYC your clients so that there is a firewall between their US and non-US entities, and that travelling people don't bring out an encryption library at the same time. It would be a operational nightmare.
- tptacek 3y agoIn the time period we're discussing, I was on a team shipping a commercial (shrink-wrap!) software project that extensively used cryptography, including an export version of same. It was not a big deal; it was not an operational nightmare; in the North American market, it wasn't a thing at all, you just did whatever you wanted.
- deaddodo 3y agoWhich part are you disagreeing with? I'm literally laymaning the law. The law never covered using cryptography, it was always about exporting it. Mostly it was written around keeping military specific cryptography from entering rival powers hands, but was overbearing. So they amended it to allow commercially developed/homegrown cryptography (explicitly not developed for governmental/military use) to be distributed normally. In practice, it's still a little muddy as many of those use DoJ/DoS-funded cryptography patterns, but the government has chosen to take a fairly hands off approach on those (RSA and DSA are key examples). You're correct that it would also be almost impossible to enforce the original wording in today's world of globalization. They also have little power to enforce it on foreign nationals, which is why a warning was usually Good Enough(TM) for American software developers.
- tptacek 3y agoSo far as I'm aware, this was never the case. Bernstein's case started in 1995 (it was decided in 1999). I assure you, cryptographic software was widespread and, apart from export controls, unchecked in 1995. Source: my professional career started in 1995. In (I think) early 1995 I bought a "This T-Shirt Is A Munition" shirt with RSA source code on it, by typing the information from the bottom of a personal check(!) into a web page. It was a whole thing.
- atoav 3y agoYou are probably from the US and not aware how things looked outside of it? https://en.m.wikipedia.org/wiki/Crypto_Wars https://en.m.wikipedia.org/wiki/Crypto_Wars
- sjamaan 3y agoQuite recently, the researchers behind the Tetraburst attack (https://www.tetraburst.com/ https://www.tetraburst.com/) discovered that Tetra's encryption has "levels" which depend on the intended recipient's country. This leaves the critical infrastructure of emergency services and police force for a lot of countries (notably, US non-allies) wide open to attack.
- rsynnott 3y agoThe existence of the levels was previously known; what they discovered was just how bad some of them are.
- michaelt 3y agoPGP was not exactly banned but if you were in Europe when ITAR restricted its export, and you were trying to download from strait-laced corporate types like AOL, they wouldn't let you. And even if a determined person could get around the blocks, they severely limited the network effects; office workers on their employers' PCs weren't going to be getting encryption software from IRC bots to bypass arms export laws. Some time towards the late 90s PGP became much more easily available.
- graemep 3y agoIts effects are still with us. Hardly anyone uses encrypted email even though it is now easy to set up. The (lack of) network effects has persisted.
- SAI_Peregrinus 3y agoIMO that's less due to the ease of setup and more due to the lack of any sane key exchange system & general impossibility of encrypting all email content (e.g. subject line).
- jeroenhd 3y agoEncryption was (and in some countries, still legally is) considered dual use technology. You needed to go through paperwork and licensing to export cryptography across the border. Symmetric keys longer than 64 bits were considered too strong. This led to all kinds of stupidity. Internet Explorer shipped with nerfed TLS capabilities, limiting key sizes to 40 bits or 56 bits depending on the version. When the encryption laws changed in 2000, Microsoft allowed users to download an update to improve SSL encryption: https://learn.microsoft.com/en-us/previous-versions/tn-archive/cc722908(v=technet.10)?redirectedfrom=MSDN https://learn.microsoft.com/en-us/previous-versions/tn-archi... You could legally encrypt emails, of course, as long as you kept the key sizes small and didn't export the encryption software to another country. If you sell and export encryption products from the USA (and a bunch of other countries, see the Wassenaar Accords) to certain places (including China and Russia), you're still obligated to register your product if you use modern key sizes. I'm not sure if governments still care now that OpenSSL and PGP are freely available to anyone, but if your proprietary email encryption program is found on North Korean computers, your government may ask you some uncomfortable questions.
- sliken 3y agoAs discussed on thread, not banned, but posting it somewhere could get you in significant trouble. In fact, Phil Zimmermann got in quite a bit of trouble for his contribution towards the world getting a hold of PGP, which was considered a export restricted munition. I believe there was at least one court case, harassment, tax audit, and hassle at the border. My memory is a big vague, but you get the idea. I was at codecon, forget if Zimmerman was there, or just quoted. His story was recounted, then someone else who attended codecon and mentioned releasing ITAR restricted crypto. They were part of a leak of the RC4 source code. A copy was sent to a well known member of sci.crypt, saying along the lines of "I think you can post this anonymously", if you agree to this please post a "Looking for Joe Random" post on sci.crypt. The source code was posted and there was no lawsuit, no tax audit, and no hassling by the government.
- ahazred8ta 3y agoThis quickly led to a cottage industry of instructions on how to write your own RC4 CipherSaber util - https://github.com/search?q=ciphersaber&type=repositories https://github.com/search?q=ciphersaber&type=repositories -- http://ciphersaber.gurus.org/faq.html http://ciphersaber.gurus.org/faq.html
- astrashe2 3y agoI was on the Cypherpunks list, mostly as a lurker. The technical discussions were amazing. I was really into it at the time, but now I find some of the political ideas to be embarrassing. Other people had a lot to do with the spread of strong crypto as well. Many people realized that encryption was necessary if we wanted to do business online. Matt Blaze (who was on the Cypherpunks list, but never said anything crazy), helped blow up the government's compromise solution, mandatory key escrow, by demonstrating flaws in their Clipper chip technology. The MIT Press published PGP's source code in book form, using an OCR font, because books couldn't be blocked as munitions. I think Hal Abelson, who wasn't on the list, was the person behind that. The basic political idea behind the list was that you could effect change by writing code. Instead of going to the government, with your cap in your hand, and saying, Please, sir, can we have strong encryption?, you write code and give it away, thus making the law impossible to enforce. This sounds really cool when you're young, especially if you write code, but it's an anti-democratic idea. The political positions of some of the leaders was kind of an extreme, anarchist spin on libertarianism. Bitcoin is a currency designed to solve a specific problem -- it's kind of the ultimate solution to the old goldbug fear that governments will print money and dilute the currency. That's impossible under Bitcoin. The original crypto currency the Cypherpunks were really into was David Chaum's Digicash, which was designed to solve a completely different problem, the same one Monero is aimed at today. It was supposed to be untraceable. Instead of asking governments to lower taxes, the idea was that programmers could create a way to transfer funds anonymously. In theory, taxes would become impossible to collect, and national borders would collapse. Eventually this led to things like discussions of anonymous murder contracts. There was a proposed protocol that was supposed to allow you to put out a hit on someone with complete safety. You could pay the killer anonymously with digital currency. I think the payment would go into some sort of escrow, so the killer would know they'd get paid. I don't remember how the system was able to know that the hit had taken place. Those murder contracts were one of the things that made me pull back from the list. But it really was terrific to read, even though I think it would be a mistake to lionize it too much. Arguably, they were struggling to make the whole world run on 8chan's rules.
- Hendrikto 3y ago> This sounds really cool when you're young, especially if you write code, but it's an anti-democratic idea. Is it? Code was deemed free speech, after all. So suppressing it would be anti-democratic, not spreading it.