Autor Beitrag
3marci
ontopic starontopic starontopic starontopic starontopic starontopic starofftopic starofftopic star
Beiträge: 61
Erhaltene Danke: 5

Windows 7 / Kubuntu 11.04
C# / vb.net / php / progress (VS 2010 Express / SharpDevelop / NetBeans / proAlpha)
BeitragVerfasst: Mo 10.01.11 04:50 
Hallo Leute!

Ich habe mal eine kleine Frage zu einem kleinen Tool das ich geschrieben habe.
Und zwar ist es ein Programm mit dem man Texte ver-und entschlüsseln kann.
Dieses Programm habe ich auf sourceforge.net registriert und veröffentlicht.
Und bei den Einstellungen auf zu den Projektinformationen gibt es zwei zur Auswahl stehenden Punkte (mit einem Radiobutton), und zwar:

1. "This project does NOT incorporate, access, call upon, or otherwise use encryption of any kind, including, but not limited to, open source algorithms and/or calls to encryption in the operating system or underlying platform."

2. "This project DOES incorporate, access, call upon or otherwise use encryption. Posting of open source encryption is controlled under U.S. Export Control Classification Number "ECCN" 5D002 and must be simultaneously reported by email to the U.S. government. You are responsible for submitting this email report to the U.S. government in accordance with procedures described in: www.bis.doc.gov/encr...ourceCodeNotify.html and Section 740.13(e) of the Export Administration Regulations ("EAR") 15 C.F.R. Parts 730-772."

Es ist sicher schon klar worauf ich hinaus will...
Natürlich habe ich den Radiobutton bei der Nr. 2 gesetzt, aber wie ist das mit der Email... ich meine ich bin ja deutscher.
Muss ich trotzdem so eine Email an die US-Regierung schreiben??? Das Programm ist noch nicht mal 100 KB gross, die lachen mich doch aus xD

Ich hoffe ihr könnt mir weiterhelfen... thx schonmal
Martok
ontopic starontopic starontopic starontopic starontopic starontopic starofftopic starofftopic star
Beiträge: 3661
Erhaltene Danke: 604

Win 8.1, Win 10 x64
Pascal: Lazarus Snapshot, Delphi 7,2007; PHP, JS: WebStorm
BeitragVerfasst: Mo 10.01.11 08:06 
Das Thema dürfte sich bald erledigt haben. "Publicly available" wäre ja genau der Fall Sourceforge.

Wie das bisher ist, weiß ich aber nicht...

_________________
"The phoenix's price isn't inevitable. It's not part of some deep balance built into the universe. It's just the parts of the game where you haven't figured out yet how to cheat."
BenBE
ontopic starontopic starontopic starontopic starontopic starontopic starhalf ontopic starofftopic star
Beiträge: 8721
Erhaltene Danke: 191

Win95, Win98SE, Win2K, WinXP
D1S, D3S, D4S, D5E, D6E, D7E, D9PE, D10E, D12P, DXEP, L0.9\FPC2.0
BeitragVerfasst: Do 13.01.11 08:57 
Hab da mal kurz im verlinkten Dokument nachgeschaut und finde da folgende Aussage:

Link hat folgendes geschrieben:
(3) removes the phrase “and mass market encryption software with symmetric key length exceeding 64-bits classified under ECCN 5D992;” and (4) adds the phrase, “except for publicly available encryption object code software classified under ECCN 5D002 when the corresponding source code meets the criteria specified in § 740.13(e) of the EAR.” This revision narrows the scope of publicly available software subject to the EAR to include only encryption source code classified under ECCN 5D002. The sixth sentence of section 732.2 is removed by this rule, as it is redundant.


Kurz nach "verständlich" übersetzt heißt das:
  • Erlaubt Open Source Krypto (wie Fefe bereits geschrieben hat
  • Legt fest, dass bei Closed Source Krypto die Export-Beschränkungen gelten
  • Die Liste der betroffenen Programme/Quellcodes wird verringert


Dass Closed Source Krypto auch nur "Open Source Krypto, die noch nicht reversed wurde," ist, wissen wir von diversen Kongressen; daher erspar ich mir mal die Diskussion. ;-)

Schauen wir mal weiter:
Link hat folgendes geschrieben:
Publicly available encryption software in object code that corresponds to encryption source code made eligible for License Exception TSU under section 740.13(e) is not subject to the EAR.


k, heißt also, Code, der unter besagten Absatz fällt, bedarf keiner Benachrichtigung, weil hier "Export-Lizenz-Ausnahmeregelungen" gelten, die im folgenden beschrieben sind:

Link hat folgendes geschrieben:
This rule removes the phrase “without review” in the first sentence of (e)(1), because it is not necessary and may be confusing to state what actions are not required to be eligible for this license exception. The first sentence of (e)(1) is further amended by adding the descriptor “publicly available” in front of “encryption source code,” to be more specific about what type of source code is eligible for this license exception. In addition, this rule replaces the phrase “if not controlled by ECCN 5D002, would be considered publicly available under § 734.3(b)(3)” with “is subject to the EAR pursuant to § 734.3(b)(3)” to simplify the first sentence in paragraph (e)(1). For consistency with the change making specified object code not subject to the EAR, this rule removes the last sentence in paragraph (e)(1), which stated “This paragraph also authorizes the export and reexport of the corresponding object code (i.e., that which is compiled from source code that is authorized for export and reexport under this paragraph) if both the object code and the source code from which it is compiled would be considered publicly available under § 734.3(b)(3) of the EAR, if they were not controlled under ECCN 5D002.”


Ist ein etwas länglicher Teil, aber kurz zusammengefasst:
"Without Review" bezeichnet hier das Spionage-Privileg der US-Behörden bei Open Source Krypto den Quelltext sehen zu dürfen ;-) Wenn also das verwendete Krypto-Verfahren öffentlich bekannt ist, so unterliegt der Quelltext zu dessen Implementierung KEINEN Export-Beschränkungen und ist damit auch nicht anmeldepflichtig.

Soweit meine Einschätzung der Lage, wenn ich die Gesetzestexte grad richtig interpretiere.

IANAL und müde. Fehler unterliegen der WTFPL.

P.S.: LOL:

Link hat folgendes geschrieben:
Notwithstanding any other provision of law, no person is required to respond to, nor shall any person be subject to a penalty for failure to comply with a collection of information subject to the requirements of the Paperwork Reduction Act of 1995 (44 U.S.C. 3501 et seq.) (PRA), unless that collection of information displays a currently valid Office of Management and Budget (OMB) Control Number.


Bürokratie-Abbau a la USA ;-) Aber wenigstens ist man nicht haftbar, wenn man ein Formblatt auszufüllen vergisst :mrgreen:

_________________
Anyone who is capable of being elected president should on no account be allowed to do the job.
Ich code EdgeMonkey - In dubio pro Setting.