Skip to content
DevMeme
3169 of 7590
Cryptography Post #3490 · source on Telegram

When the NSA thought math was a weapon

Description

This image uses the 'Is this a pigeon?' anime meme format to comment on a specific moment in tech history. The anime character is labeled 'NSA 1992,' and he is looking at a butterfly labeled 'KEYS LONGER THAN 40 BITS.' The subtitle below reads, 'IS THIS AMMUNITION?'. The meme humorously references the United States' export regulations during the 'Crypto Wars' of the 1990s. At the time, software with strong encryption (using keys longer than 40 bits) was classified as a 'munition' under the International Traffic in Arms Regulations (ITAR), treating cryptographic code as if it were a weapon. This policy was heavily criticized by privacy advocates and the tech industry, including the Electronic Frontier Foundation (EFF) mentioned in the post's caption, as it stifled innovation and weakened global software security

Comments

13
Anonymous ★ Top Pick Remember the 90s when you could accidentally commit a felony by exporting a web browser? The original military-grade encryption was literally just math the military didn't want you to share
  1. Anonymous ★ Top Pick

    Remember the 90s when you could accidentally commit a felony by exporting a web browser? The original military-grade encryption was literally just math the military didn't want you to share

  2. Anonymous

    1992: “Ship the RC4-40 build or we need an export license.” 2024: “Ship the post-quantum build or we need a breach notification.” Amazing how the definition of ‘munitions’ keeps moving up the key schedule

  3. Anonymous

    The best part about treating 40-bit keys as weapons-grade munitions is that by the time your export license was approved, a teenager with a Pentium could've already cracked it during their lunch break

  4. Anonymous

    Back when the NSA genuinely believed that exporting RSA keys over 512 bits would destabilize global security more than, you know, actual ammunition. Meanwhile, every cryptographer was printing PGP source code on t-shirts and calling it 'free speech' - technically correct, the best kind of correct. The irony? By the time they relaxed export controls in 2000, script kiddies worldwide had already implemented AES in JavaScript. Turns out you can't put the mathematical genie back in the bottle, no matter how many export licenses you require

  5. Anonymous

    1999: 41-bit keys were “munitions”; 2015 proved it - leave EXPORT cipher suites enabled and TLS turns into FREAK

  6. Anonymous

    Ah, the era when shipping 41-bit RSA overseas required ATF paperwork longer than your modulus

  7. Anonymous

    Classifying entropy as ammunition gave us export ciphers - FREAK/LOGJAM were just the interest on that policy-driven technical debt

  8. @pyproman 5y

    What

    1. @anatoli26 5y

      https://en.m.wikipedia.org/wiki/Export_of_cryptography_from_the_United_States

      1. @chupasaurus 5y

        The article doesn't mention the witch hunt for RSA authors

        1. @anatoli26 5y

          Ahh sure, it’s quite extensive topic as a whole. Actually, that’s why OpenBSD (considered the most secure general-purpose OS) was developed in Canada, to stay outside the most democratic country in the whole world 😆

          1. @chupasaurus 5y

            GCHQ might still have a word there, but there isn't a law that mandates the access to data for the officials

  9. @slnt_opp 5y

    I will, if they stop spamming.___.

Use J and K for navigation