Re: Crypt::*

[email protected] (Elaine -HFB- Ashton) Fri, 12 Nov 1999 16:56:16 -0600
Newsgroups perl.sdk
Message-ID <[email protected]>
Stephen Zander [[email protected]] quoth:
*>
*>This rapidly becomes a philisophical/political question, but
*>personally I don't see why stupid laws in *any* contry should be our
*>problem, as long as those providing access to the sdk (CPAN mirrors I
*>presume) aren't violating the laws of the country in which they
*>operate.  Caveat downloader. :)

Ignorance of the law was never and never shall be a suitable defense.
Stupid or not, ITAR exists in the US. There are few other countries so
concerned with the export or import of munitions such as cryptographic
tools. 

While I have no 'official' opinion on this, I did ask a few people about
the liabilities concerning these modules being freely available and
distributed worldwide. My thought is that I use the strongest encryption
available when I need it and if the government comes after me, well, they
had better fire up their supercomputer and start making keys :) 

However, the diffference with these modules is that they depend on
external libraries [openssl, crypt, etc] for the actual algorithm so that
it may be viewed as a tool and not a munition. Correct me if I am wrong in
this view.

*>That is, if exporting is OK, leave the users of the sdk to deal with
*>the legal implications of its use.  We should just warn them that
*>restrictions on use *may* exist.

Well...that isn't always the best method of CYA. I'm sure everyone
remembers penet.fi.....

Perhaps counsel at EFF could clarify the law?

As far as including them goes...I say no. Mostly because people who want
encryption are savvy enough to know where to find it and because imoho it
isn't an essential developer's module set.

e.