1997-04-15 01:35:39

cbreed(_at_)pgp(_dot_)com said:
3. Unfortunately, the MUST profile (for interoperability), will be US
export controlled. US export requirements should NOT be imposed upon
an international standards organization. (Why should someone in Japan
be forced to uses 40-bit weak crypto to communicate with someone in
Germany, if their profile is unknown?) It is more dangerous to resort
to weak crypto than nothing 

What I find very difficult to understand is, why the technology:
- which is the defacto standard
- the most widely used (world wide)
- which is not suffering from the US-export equirements (as it is already
  available outside US)
- which allows almost arbitrarily strong crypto 
is not considered for the MUST technology?

Another thing, is it not true, assuming the technology is available, that
nothing prevents a user in US and a user outside US to communicate using
stong crypto ( e.g. 128 bit keys)?



