1993-06-05 - (fwd) NIST CSSPAB Resolutions 6/4/93

Header Data

From: tcmay@netcom.com (Timothy C. May)
To: cypherpunks@toad.com
Message Hash: c24794689cab093c3d4838748e8f98d84cae56819cc6f2f37cd19bfdf08cab75
Message ID: <9306050117.AA03457@netcom3.netcom.com>
Reply To: N/A
UTC Datetime: 1993-06-05 01:16:57 UTC
Raw Date: Fri, 4 Jun 93 18:16:57 PDT

Raw message

From: tcmay@netcom.com (Timothy C. May)
Date: Fri, 4 Jun 93 18:16:57 PDT
To: cypherpunks@toad.com
Subject: (fwd) NIST CSSPAB Resolutions 6/4/93
Message-ID: <9306050117.AA03457@netcom3.netcom.com>
MIME-Version: 1.0
Content-Type: text/plain


Here's something important from sci.crypt!

-Tim May


Xref: netcom.com alt.privacy:7178 alt.security:9808 comp.org.eff.talk:18101 sci.crypt:15143 alt.privacy.clipper:555
Path: netcom.com!netcomsv!decwrl!elroy.jpl.nasa.gov!usc!math.ohio-state.edu!sol.ctr.columbia.edu!news.kei.com!eff!wilson.eff.org!Banisar
From: Dave Banisar <Banisar@washofc.cpsr.org>
Newsgroups: alt.privacy,alt.security,comp.org.eff.talk,sci.crypt,alt.privacy.clipper
Subject: NIST CSSPAB Resolutions 6/4/93
Date: 5 Jun 1993 00:48:11 GMT
Organization: CPSR Washington Office
Lines: 101
Distribution: world
Message-ID: <1uoqgb$peg@kragar.eff.org>
NNTP-Posting-Host: wilson.eff.org
X-UserAgent: Nuntius v1.1.1d17
X-XXMessage-ID: <A8356712AB01AC7F@wilson.eff.org>
X-XXDate: Fri, 4 Jun 93 01:54:42 GMT



                 NIST Crypto Resolutions

  Computer System Security and Privacy Advisory Board
                       June 4, 1993

                      Resolution #1

At Mr. Kammer's request we have conducted two days of 
hearings.  The clear message of the majority of input 
was that there are serious concerns regarding the Key 
Escrow Initiative and the Board concurs with these 
concerns.  Many of these issues are still to be fully 
understood and more time is needed to achieving that 
understanding.

Accordingly, this Board resolves to have an additional 
meeting in July 1993 in order to more completely respond 
to Mr. Kammer's request and to fulfill its statutory 
obligations under P.L. 100-235.  The Board recommends 
that the inter-agency review take note of our input 
collected, our preliminary finding, and adjust the 
timetable to allow for resolution of the significant 
issues and problems raised.

Attached to this resolution is a preliminary 
distillation of the serious concerns and problems.


                     Resolution #2

Key escrowing encryption technology represents a 
dramatic change in the nation's information 
infrastructure.  The full implications of this 
encryption technique are not fully understood at this 
time.  Therefore, the Board recommends that key 
escrowing encryption technology not be deployed beyond 
current implementations planned within the Executive 
Branch, until the significant public policy and 
technical issues inherent with this encryption technique 
are fully understood.

[Attachment to Resolution #1]]

-  A convincing statement of the problem that Clipper 
attempts to solve has not been provided.

- Export and important controls over cryptographic 
products must be reviewed.  Based upon data compiled 
from U.S. and international vendors, current controls 
are negatively impacting U.S. competitiveness in the 
world market and are not inhibiting the foreign 
production and use of cryptography (DES and RSA)

- The Clipper/Capstone proposal does not address the 
needs of the software industry, which is a critical and 
significant component of the National Information 
Infrastructure and the U.S. economy.

- Additional DES encryption alternatives and key 
management alternatives should be considered since there 
is a significant installed base.

- The individuals reviewing the Skipjack algorithm and 
key management system must be given an appropriate time 
period and environment in which to perform a thorough 
review.  This review must address the escrow protocol 
and chip implementation as well as the algorithm itself.

- Sufficient information must be provided on the 
proposed key escrow scheme to allow it to be fully 
understood by the general public.  It does not appear to 
be clearly defined at this time and, since it is an 
integral part of the security of the system, it appears 
to require further development and consideration of 
alternatives to the key escrow scheme (e.g., three 
"escrow" entities, one of which is a non-government 
agency, and a software based solution).

- The economic implications for the Clipper/Capstone 
proposal have not been examined.  These costs go beyond 
the vendor cost of the chip and include such factors as 
customer installation, maintenance, administration, chip 
replacement, integration and interfacing, government 
escrow systems costs, etc.

- Legal issues raised by the proposal must be reviewed.

- Congress, as well as the Administration, should play a 
role in the conduct and approval of the results of the 
review.

=======================================================
    NIST Resolutions on Key Escow Issues and Clipper
                       provided by
                 CPSR Washington office
           666 Pennsylvania Ave., SE Suite 303
                  Washington, DC 20003
               rotenberg@washofc.cpsr.org
=======================================================

--
..........................................................................
Timothy C. May         | Crypto Anarchy: encryption, digital money,  
tcmay@netcom.com       | anonymous networks, digital pseudonyms, zero
408-688-5409           | knowledge, reputations, information markets, 
W.A.S.T.E.: Aptos, CA  | black markets, collapse of governments.
Higher Power: 2^756839 | Public Key: PGP and MailSafe available.
Note: I put time and money into writing this posting. I hope you enjoy it.





Thread