Re: U.S. Export Control Compliance

Rudi De Vos <[email protected]> Fri, 07 Jul 2006 01:09:42 +0200
Newsgroups gmane.network.vnc.ultravnc.general
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--===============1862302743==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

For feature requests and bug reports RC15 RC16. Please use the forum at http://forum.ultravnc.net/


--===============1862302743==
Content-Type: multipart/alternative;
	boundary="------------020901010703020207010608"

This is a multi-part message in MIME format.
--------------020901010703020207010608
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Transfer-Encoding: 7bit

You can easy replace the vncpasswd with plain text when you use the 
encryption plugins...
D3des can hardly be called encryption  with the current technology...

Following the "wassenaar agreement" encryption restriction does not 
count for "plublic domain" software.
Only Australia, the USA, New Zealand, France and Russia  don't respect 
the agreement, but in all other countries
you can freely use any encryption....even above 56bits.





Bob Friesenhahn wrote:

>For feature requests and bug reports RC15 RC16. Please use the forum at http://forum.ultravnc.net/
>
>  
>
>>UltraVnc is encryption free, encryption is done with plugins.
>>Use the plugins based on the MS crypto engine, thoose plugins do 
>>encryption, but don't contain
>>encryption code and i'm sure MS have a ECCN number.
>>    
>>
>
>This statement is not true.  Ultravnc *does* enclude encryption code 
>which is not done with a plugin.  The source for this encryption code 
>is in the rfb/d3des.c file, and is required in order to support VNC 
>authentication.
>
>The code does not quite implment DES.  The VNC inventors were really 
>"smart" and made a minor source tweak so that the results are 
>different than true DES.  The VNC protocol specification fails to 
>mention this tweak.  Regardless, it did not take long for VNC crack 
>tools to emerge since the source code was readily available (i.e. it 
>was a bad idea).
>
>Bob
>
>Using Tomcat but need to do more? Need to support web services, security?
>Get stuff done quickly with pre-integrated technology to make your job easier
>Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo
>http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642
>
>
>  
>

--------------020901010703020207010608
Content-Type: text/html; charset=us-ascii
Content-Transfer-Encoding: 7bit

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
  <meta http-equiv="Content-Type" content="text/html;charset=ISO-8859-1">
  <title></title>
</head>
<body text="#000000" bgcolor="#ffffff">
You can easy replace the vncpasswd with plain text when you use the
encryption plugins...<br>
D3des can hardly be called encryption&nbsp; with the current technology...<br>
<br>
Following the "wassenaar agreement" encryption restriction does not
count for "plublic domain" software.<br>
Only Australia, the USA, New Zealand, France and Russia&nbsp; don't respect
the agreement, but in all other countries<br>
you can freely use any encryption....even above 56bits.<br>
<br>
<br>
<br>
<br>
<br>
Bob Friesenhahn wrote:<br>
<blockquote type="cite"
 cite="[email protected]">
  <pre wrap="">For feature requests and bug reports RC15 RC16. Please use the forum at <a class="moz-txt-link-freetext" href="http://forum.ultravnc.net/">http://forum.ultravnc.net/</a>

  </pre>
  <blockquote type="cite">
    <pre wrap="">UltraVnc is encryption free, encryption is done with plugins.
Use the plugins based on the MS crypto engine, thoose plugins do 
encryption, but don't contain
encryption code and i'm sure MS have a ECCN number.
    </pre>
  </blockquote>
  <pre wrap=""><!---->
This statement is not true.  Ultravnc *does* enclude encryption code 
which is not done with a plugin.  The source for this encryption code 
is in the rfb/d3des.c file, and is required in order to support VNC 
authentication.

The code does not quite implment DES.  The VNC inventors were really 
"smart" and made a minor source tweak so that the results are 
different than true DES.  The VNC protocol specification fails to 
mention this tweak.  Regardless, it did not take long for VNC crack 
tools to emerge since the source code was readily available (i.e. it 
was a bad idea).

Bob

Using Tomcat but need to do more? Need to support web services, security?
Get stuff done quickly with pre-integrated technology to make your job easier
Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo
<a class="moz-txt-link-freetext" href="http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642">http://sel.as-us.falkag.net/sel?cmd=lnk&amp;kid=120709&amp;bid=263057&amp;dat=121642</a>


  </pre>
</blockquote>
</body>
</html>

--------------020901010703020207010608--



--===============1862302743==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

Using Tomcat but need to do more? Need to support web services, security?
Get stuff done quickly with pre-integrated technology to make your job easier
Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo
http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642

--===============1862302743==--