Re: Crypt::*

[email protected] (Stephen Zander) 13 Nov 1999 11:00:17 -0800
Newsgroups perl.sdk
Organization speaking through, but not for, McKessonHBOC Corp.
Message-ID <[email protected]>
>>>>> "Elaine" == Elaine -HFB- Ashton <[email protected]> writes:
    Elaine> Ignorance of the law was never and never shall be a
    Elaine> suitable defense.  Stupid or not, ITAR exists in the
    Elaine> US. There are few other countries so concerned with the
    Elaine> export or import of munitions such as cryptographic tools.

I understand that: it's why I said CPAN mirrors would need to check
that they were compatible with the law *in their country of origin*.
The simple fact that CPAN mirrors in the US carry these modules
without checking that foreign nationals from embargoed countries
(North Korea, Cuba, Lybia etc) cannot download it is probably a
violation of US law.

I meant that it is not the job of the CPAN mirrors to check whteher
the recipient of the code may legally use it after they've downloaded
it.  For instance, if US law allows export to France but French law
doesn't allow use, that's the person in France's problem, not the US
server's problem.

    Elaine> However, the diffference with these modules is that they
    Elaine> depend on external libraries [openssl, crypt, etc] for the
    Elaine> actual algorithm so that it may be viewed as a tool and
    Elaine> not a munition. Correct me if I am wrong in this view.

The US government at least, does not care whether the code is doing
actual crypto or just acting as a hook to something else. The EAR,
which replaced ITAR, are sufficiently loose that the US govt can
decide just about anything is inappropriate.

    Elaine> As far as including them goes...I say no.

Fair enough.

-- 
Stephen

"And what do we burn apart from witches?"... "More witches!"