3marci - Mo 10.01.11 04:50
Titel: Sourceforge.net und Verschlüsselungen
Hallo Leute!
Ich habe mal eine kleine Frage zu einem kleinen Tool das ich geschrieben habe.
Und zwar ist es ein Programm mit dem man Texte ver-und entschlüsseln kann.
Dieses Programm habe ich auf sourceforge.net registriert und veröffentlicht.
Und bei den Einstellungen auf zu den Projektinformationen gibt es zwei zur Auswahl stehenden Punkte (mit einem Radiobutton), und zwar:
1. "
This project does NOT incorporate, access, call upon, or otherwise use encryption of any kind, including, but not limited to, open source algorithms and/or calls to encryption in the operating system or underlying platform."
2. "
This project DOES incorporate, access, call upon or otherwise use encryption. Posting of open source encryption is controlled under U.S. Export Control Classification Number "ECCN" 5D002 and must be simultaneously reported by email to the U.S. government. You are responsible for submitting this email report to the U.S. government in accordance with procedures described in: http://www.bis.doc.gov/encryption/PubAvailEncSourceCodeNotify.html and Section 740.13(e) of the Export Administration Regulations ("EAR") 15 C.F.R. Parts 730-772."
Es ist sicher schon klar worauf ich hinaus will...
Natürlich habe ich den Radiobutton bei der Nr. 2 gesetzt, aber wie ist das mit der Email... ich meine ich bin ja deutscher.
Muss ich trotzdem so eine Email an die US-Regierung schreiben??? Das Programm ist noch nicht mal 100 KB gross,
die lachen mich doch aus xD
Ich hoffe ihr könnt mir weiterhelfen... thx schonmal
BenBE - Do 13.01.11 08:57
Hab da mal kurz im
verlinkten Dokument [
http://www.federalregister.gov/articles/2011/01/07/2010-32803/publicly-available-mass-market-encryption-software-and-other-specified-publicly-available-encryption] nachgeschaut und finde da folgende Aussage:
Kurz nach "verständlich" übersetzt heißt das:
- Erlaubt Open Source Krypto (wie Fefe bereits geschrieben hat
- Legt fest, dass bei Closed Source Krypto die Export-Beschränkungen gelten
- Die Liste der betroffenen Programme/Quellcodes wird verringert
Dass Closed Source Krypto auch nur "Open Source Krypto, die noch nicht reversed wurde," ist, wissen wir von diversen Kongressen; daher erspar ich mir mal die Diskussion. ;-)
Schauen wir mal weiter:
k, heißt also, Code, der unter besagten Absatz fällt, bedarf keiner Benachrichtigung, weil hier "Export-Lizenz-Ausnahmeregelungen" gelten, die im folgenden beschrieben sind:
| Link [http://www.federalregister.gov/articles/2011/01/07/2010-32803/publicly-available-mass-market-encryption-software-and-other-specified-publicly-available-encryption#h-10] hat folgendes geschrieben: |
| This rule removes the phrase “without review” in the first sentence of (e)(1), because it is not necessary and may be confusing to state what actions are not required to be eligible for this license exception. The first sentence of (e)(1) is further amended by adding the descriptor “publicly available” in front of “encryption source code,” to be more specific about what type of source code is eligible for this license exception. In addition, this rule replaces the phrase “if not controlled by ECCN 5D002, would be considered publicly available under § 734.3(b)(3)” with “is subject to the EAR pursuant to § 734.3(b)(3)” to simplify the first sentence in paragraph (e)(1). For consistency with the change making specified object code not subject to the EAR, this rule removes the last sentence in paragraph (e)(1), which stated “This paragraph also authorizes the export and reexport of the corresponding object code (i.e., that which is compiled from source code that is authorized for export and reexport under this paragraph) if both the object code and the source code from which it is compiled would be considered publicly available under § 734.3(b)(3) of the EAR, if they were not controlled under ECCN 5D002.” |
Ist ein etwas länglicher Teil, aber kurz zusammengefasst:
"Without Review" bezeichnet hier das Spionage-Privileg der US-Behörden bei Open Source Krypto den Quelltext sehen zu dürfen ;-) Wenn also das verwendete Krypto-Verfahren öffentlich bekannt ist, so unterliegt der Quelltext zu dessen Implementierung KEINEN Export-Beschränkungen und ist damit auch nicht anmeldepflichtig.
Soweit meine Einschätzung der Lage, wenn ich die Gesetzestexte grad richtig interpretiere.
IANAL und müde. Fehler unterliegen der WTFPL.
P.S.: LOL:
Bürokratie-Abbau a la USA ;-) Aber wenigstens ist man nicht haftbar, wenn man ein Formblatt auszufüllen vergisst :mrgreen: