Mozilla Firefox Not In Violation of US Export Rules
darthcamaro writes "While the internet may know no borders, the US government does. There are a number of rules that affect software vendors, including encryption export regulations from the US Department of Commerce and export sanctions by the Department of Treasury. But what do you do when your application is open source and freely available to anyone in the world? Do the same the rules apply? It's a question that Mozilla asked the US government about. The answer they received could have profound implications not just for Firefox but for all open source software vendors. 'We really couldn't accept the notion that these government rules could jeopardize the participatory nature of an open source project, so we sought to challenge it,' Harvey Anderson, VP and General Counsel of Mozilla, told InternetNews.com. 'We argued that First Amendment free speech rights would prevail in this scenario. The government took our filing and then we got back a no-violation letter, which is fantastic.'"
You're right. See their Crypto page. In fact, they build their binary releases only in Canada, Sweden, and Germany to avoid ITAR type restrictions.
if firefox is shielded from these export restrictions because of first amendment protection wouldn't any open source implementation of strong encryption also be protected? wouldn't this make those export restrictions very nearly mute?
Don't people remember what happened with Phil Zimmerman over PGP?
The munitions classification on encryption software was used against him for posting the PGP source code on Usenet. They really, really wanted to nail him to the wall over that one.
There was a certain irony in the restrictions on exporting crypto software deemed 'munitions'. You could take the source, publish it as a book in an OCR font (with the page numbers between comment delimiters), and export it anywhere in the world.
Where's the Kaboom?
There's supposed to be an Earth-shattering Kaboom.
Yes, it contributed correctness to the world - always a good thing.
Seriously, it also (if the original poster is able to take criticism) helped them avoid this mistake in the future, potentially in front of a prospective client/etc.
There's a big difference between a typo or otherwise one-off failure and mistaking one word for another. It's nitpicking over typos because it's unlikely someone thinks 'teh' is correct, but when they use a word like mute in place of moot - not easily mistyped but easily mistaken - it's usually an indicator that they don't know better.
Ho-hum. Unrestricted export of open-source products incorporating encryption from the US has been legal for quite a while. All you have to do is file an application with the Feds under the Export Regs Section 740.13 "TECHNOLOGY AND SOFTWARE -- UNRESTRICTED (TSU)" before you make the source and binaries available, and you don't have to screen downloads or worry if the Officially Designated Bad Guys download your code: your ass is covered.
This war was won a loooong time ago by Philip Zimmermann when the Feds wanted to crush him for releasing PGP. All props go to Phil!