[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: PIS_son



At 04:11 PM 10/22/96 -0700, Jeff Weinstein wrote:
>John Young wrote:
>>    10-17-96, BuWi:
>>    "Apple, IBM, JavaSoft, Motorola, Netscape, Nortel, Novell,
>>    RSA, and Silicon Graphics Announce PICA Crypto-Alliance"
>>       The PICA specification will also be designed to make the
>>       task of developing differing domestic and exportable
>>       security requirements much easier. [GAK alliance 2.]
>
>  John, I think you are misreading the intent here.  By making
>it easier to develop separate domestic and exportable
>versions of a product, we foil the government's attempt to
>force weak domestic encryption because it is too much work to
>maintain two different versions.

What about making it easier to interconvert the domestic and exportable 
versions of the program?  Okay, I understand that given your position you 
might not want to come out on the record on this issue, but it seems to me 
that it would serve your interests to make it as easy as possible for a 
foreign buyer to convert a legally-exported copy of Netscape into an 
export-restricted one.

The default way for foreign buyers:  Buy Netscape from your Co., put it on 
the shelf, download illegally-exported version and use it.  Doable, 
obviously.  However, a more subtle way would be to add (or, for that matter, 
subtract) a portion of the program that controls whether or not 
export-quality encryption would "go."  

True, the "erase a file to enable good crypto" might not fly, but the 
opposite might.  I'm not talking about conventional "crypto with a hole," 
but simply a program which always contains crypto whose functioning is 
limited by an external program.


Jim Bell
[email protected]