Personal tools
inbar_comments.txt
From cos@cs.brandeis.edu Mon Sep 27 19:48:20 1993
Subject: Clipper Chip Comments
To: cryptnow@eff.org, clipper@washofc.cpsr.org
Date: Mon, 27 Sep 1993 19:49:29 -0500 (EDT)
Ofer Inbar
266 Crescent Street
Waltham, MA 02154
(617) 899-8154
27 September 1993
Director, Computer Systems Laboratory
Proposed FIPS for Escrowed Encryption Standard
Technology Building, Room B-154
National Institute of Standards and Technology
Gaithersburg, MD 20899
Director:
Over the past several years, while using the computer nets, I have
rarely come upon a need to personally make use of encryption. I have,
however, several times had my tasks made more complicated for me by
what I consider to be unreasonable US cryptography policy.
For example, I distribute shareware and public domain software to
several BBSes and online services, including ZiffNet/CompuServe. Much
of the software I collect is available on the Internet, at large
public archives inside the US. However, several popular packages,
such as PKZIP, now have two separate versions. One, with encryption,
cannot be made available from the US to people in other countries,
while the other version, without encryption, is free from
restrictions. Aside from having to sort through to make sure I have
the version I need, or sometimes get both, this usually means getting
software from outside the US, which is both slower and less reliable,
and certainly an extra hassle.
Now, it looks like the already annoying situation is about to become
worse. Unless you believe that foreign governments or companies will
adopt a "standard" form of encryption to which the US government
controls key access, the split between products for the US and
products for the rest of the world will grow even larger, and affect
an even greater proportion of the population.
Personally, I even have doubts that something like Clipper can
really catch on as a standard inside the US. For whatever reason,
there are a lot of people who really distrust the government. And for
the most part, this is the same group of people who will be using
encryption, in the short term. Perhaps large corporations can be
convinced to use Clipper, but I will certainly not use it myself.
So, if I don't believe it can become a standard, why the concern?
The reason is that I don't think any encryption system can become a
real standard unless it is either blessed by the government, or the
government stands back and lets another institution do the blessing.
Nobody can successfully compete with Clipper and build a real
standard.
In effect, it seems to me the NIST is preparing to use its standard
setting powers, not to define a standard for the public, but to deny a
standard to the public. If you take this step, contrary to the name
of your organization, the resulting chaos in encryption will be a
disservice to everyone. That is my concern, thank you for taking the
time to read this.
-- Cos (Ofer Inbar) -- cos@cs.brandeis.edu
-- WBRS (BRiS) -- WBRS@binah.cc.brandeis.edu WBRS@brandeis.bitnet
"One has a moral responsibility to disobey unjust laws."
-- Dr. Martin Luther King, Jr.
======================================================================
Created before October 2004
