4 ms·
Anachronistically, The US still enforces a broad based embargo on trade with Cuba, leaving it with the dubious honor of the tightest controlled destination, bea
by trotsky 14y ago
Anachronistically, The US still enforces a broad based embargo on trade with Cuba, leaving it with the dubious honor of the tightest controlled destination, beating out even Iran and North Korea. We also have it on the list of states that sponsor terrorism which is recognized by many 3rd party nations.
Top tier crypto gear including anything suitable for trunk class traffic is one of the most controlled export goods - canada is literally the only country on earth that doesn't require an export license.
Realistically it's mostly a formality if the destination is on the list of favored nations, mostly western democracies. There are 3 more tiers: mostly ambivalent, our shit list and lastly those we label rogue/terrorist.
Mass communications gear and business grade crypto get a lot of scrutiny, really only topped by spaceflight and the tools of war.
Theoretically you'd probably be able to get export licenses for high speed aes to send to Venezuela, but practically it would be subject to a ton of discretionary terms that would make it a non-starter. A smattering of possible terms the US would impose: all source code including 100% of the ASIC designs, use of a US ASIC fab with production under the supervision of the government, require lawful intercept functions to be enabled, key escrow storage in us territory only, no customer access to source code, software upgrades performed only by us personel on site, mandatory random on site checks by us government officials to ensure it hasn't been transferred, is used in a licensed manner, hasn't been tampered with, software is approved version, etc.
It's not like they'd demand a huge obvious list like that, but pretty much any one of those restrictions means the customer is pretty much at the mercy of the US government. Most of those practices are designed to find or insert flaws that enable total plaintext recovery.
Understandably most states that are subject to intense US intelligence activity generally don't even consider it. There is plenty of diversion that goes on through cutouts, but there are plenty of published stories where US intelligence knew all about it and owned the gear before it shipped.
Practically your other choice is chinese gear, which is what most of that class of country buys. But the chinese gear is almost certainly subject to similar intentional weaknesses in addition to stuff placed by multiple competing domestic security services so they can spy on each other. It's a pretty safe bet that a number of western intelligence agencies can exploit these as well - so you're back to square one again.
General purpose software is an option of course, but i think itd take a lot of kludges to handle such a fat pipe with consumer cpus/gpus. And then of course they are a bunch of computers on a network with static encryption keys sitting in memory run by poorly paid government workers, probably not something that would resist a motivated attacker.
- mikeash 14y agoLovely reply, thank you for such a thorough explanation.