The Crypto Home Shopping Network
I noticed a little blurb on the Business Wireservices today stating that a company named "Digital Delivery" has licensed technology from RSADSI for a turnkey CD-ROM software catalog called "CD Product Portfolio". The product is supposed to permit a company's most valuable software and intellectual property to be browsed, ordered, unlocked, and installed from CD-ROM with "absolutely no worry about hacking or unauthorized use." The product is based on BSAFE and uses the RSA Public Key Cryptosystem and the RC4 stream cipher. Now the interesting part is that this product has been granted commodity jurisdiction from the Department of Commerce and will be be allowed to be EXPORTED outside the United States under license, permitting foreign customers to create encrypted software catalogs and make use of this distribution mechanism. Through the magic of RSA encryption, a given program or image (!) on the CD-ROM will only be released after the browser has actually ordered and paid for the product. Do you think this crypto is "strong"? I am not familiar with RC4, but it would seem unlikely that it is both hack-proof and exportable at the same time. Cost considerations probably preclude encrypting CDs individually with different keys, so it is difficult to see what prevents disk owners from communicating keys to one another for the purpose of unlocking software. This idea of mass-produced CDs might nicely dovetail with DigiCash to enable the complete electronic purchase of programs without the necessity of having a high-bandwidth connection with the seller to transfer the software to ones own machine. Given the extensive "Threat of Crypto" propaganda we have been hearing from government minions lately, it is very nice to see the government pushing us towards a future where we may buy all sorts of interesting things from foreign mass-produced encrypted CD-ROMs with anonymous DigiCash, all in complete privacy. Thank-YOU Big Brother. :) -- Mike Duvos $ PGP 2.6 Public Key available $ mpd@netcom.com $ via Finger. $
A year or so ago, my employer's export control expert said that decrypt-only strong crypto for intellectual property protection was exportable (in object code form only). - Bill
[...] decrypt-only strong crypto for intellectual property protection was exportable (in object code form only). - Bill
What's to say the source code isn't encrypted on the disk? Could this be the answer to exporting the source in Schneier's book? Just hide it in a kid's game on a 3.5" |-] TTFN. -- -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- - DrZaphod #Don't Come Any Closer Or I'll Encrypt! - - [AC/DC] / [DnA][HP] #Xcitement thru Technology and Creativity - - [drzaphod@brewmeister.xstablu.com] [MindPolice Censored This Bit] - - 50 19 1C F3 5F 34 53 B7 B9 BB 7A 40 37 67 09 5B - -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
A year or so ago, my employer's export control expert said that decrypt-only strong crypto for intellectual property protection was exportable (in object code form only).
Seems to me it's pretty hard to make a stream cipher decrypt-only. A little hacking around and you can do what you want with the stream. Eli ebrandt@hmc.edu (or you could snarf PGP from Finland, but Commerce hasn't clued in on that)
participants (4)
-
drzaphod@brewmeister.xstablu.com -
Eli Brandt -
mpd@netcom.com -
sommerfeld@orchard.medford.ma.us