Bernstein v. the U.S. Department of State (2014)
britannica.com
britannica.com
Code is speech.
Not all code. From the linked article:
> However, the court cautioned that not all software could be considered expressive, and thus not all source code would necessarily be protected.
This is by 'design':
* https://en.wikipedia.org/wiki/Common_law
Not sure if it's possible to convert things:
If we had a healthy legislative system then things could be better codified in law that was passed by elected representatives.
If we had a healthy legislative system.
If there is a legislative will to do something at federal level, then in an alternate system of civil law too there wouldn't be a statute allowing abortion.
In fact, without Supreme Court's Roe v Wade's 1970s decision, abortion would be pretty much illegal in the US (as it was, right before the 1970s decision).
Here is Illinois:
(5 ILCS 50/1) (from Ch. 1, par. 801) Sec. 1. That the common law of England, so far as the same is applicable and of a general nature, and all statutes or acts of the British parliament made in aid of, and to supply the defects of the common law, prior to the fourth year of James the First, excepting the second section of the sixth chapter of 43d Elizabeth, the eighth chapter of 13th Elizabeth, and ninth chapter of 37th Henry Eighth, and which are of a general nature and not local to that kingdom, shall be the rule of decision, and shall be considered as of full force until repealed by legislative authority.
https://en.wikipedia.org/wiki/Reception_statute#United_State...
He did quite a bit of work (and had a similar lawsuit) that code was speech.
He use to attend the Linux Users Groups meeting I was part of. Amazing person and really friggin' smart. Also, he was pretty good with Tex.
> Thus, cryptographers use source code to express their scientific ideas in much the same way that mathematicians use equations or economists use graphs. [...] In light of these considerations, we conclude that encryption software, in its source code form and as employed by those in the field of cryptography, must be viewed as expressive for First Amendment purposes, and thus is entitled to the protections of the prior restraint doctrine. [4233-4234]
and then they proceed to dismantle the US's understanding on source code. Lot's of material I would never normally think about.
[1]: https://archive.epic.org/crypto/export_controls/bernstein_de...
hi own archive on the case :
That .ph link is a tracking infected garbage, requiring JS.
curl this link and tell me that you see any text from the original website.
Bit of a different topic but I hope a landmark case tears down the DMCA nonsense in the U.S and other countries at some point.
In 1999, Judge voted that, no, encryption code was "scientific expression" and thus protected by the freedoms granted by First Amendment.
There was a fair bit more back-and-forth including shifting positions by the government under various administrations, but in effect this is the case that opened the gates to better public encryption.
An awful lot of things are built on NaCl, which is probably what djb is most famous for.
https://en.wikipedia.org/wiki/Curve25519
I saw him give a really awesome talk about the process of finding Curve25519 around the time he published it, and I think the story is a lot more interesting than people realize.
Curve25519's group of points over the whole curve is not of prime order. By Lagrange, the subgroups are the prime factorization of the group order. Luckily we do have a large prime order subgroup, but we also have a subgroup of order 8 and consequently of order 4 and 2 also. If you by chance decode a point into one of these groups, scalar multiplication has a high chance of hitting the identity point. In Diffie Hellman, this isn't a problem: we call it "non contributory behaviour".
If however you care about each party making a contribution and group properties, you end up having to check group membership anyway. Not having to do that is one of the main selling points of Curve25519.
Looking through the SafeCurves criteria, there are now complete addition law for prime-order weierstrass curves, negating another safecurves benefit. Since the NIST curves form a prime order group, they don't have the same subgroup problem (all Montgomery curves, by contrast, have a subgroup of order at least 4).
We owe the "fix" to this to Mike Hamburg, effectively, who came up with a mapping to and from a Jacobi Quartic form that allows you to encode and decode directly into the prime order subgroup. This is Decaf, one of the contributions of his Ed448-Goldilocks paper, and was applied to Curve25519 under the name Ristretto.
We can go further if you like. There's extensive literature on appropriate choices of pairing friendly curves, and I'm not aware of any DJB contributions here. There are also faster curves at the 128-bit security level for Diffie Hellman, i.e. FourQ, which uses the GLV decomposition and Q-curves. ---
While DJB has made some very notable contributions and helped push the state of the art along, he's not the only contributor to the field by a very long way. At the very least, we should also mention Peter Montgomery and Harold Edwards, but these are by no means the only names.
Before DJB became famous in encryption circles, he was famous for writing qmail (an SMTP mail server that was a more secure and simpler alternative to the ubiquitous sendmail).
> His software converted a one-way “hash function” (one that takes an input string of arbitrary length and compresses it into a finite, usually shorter, string; the function has many uses in cryptography) into a private-key encryption system (one that can be decoded only by whoever holds the private “key,” or pass code). The functionality of the software depended on two people’s having exchanged their private keys.
I get what you're saying, that would typically mean encrypt with private key, and decryption with public key, like how signature algorithms work, but still, there is no cryptosystem that makes it okay to start exchanging your private keys with random parties you're communicating with, by the very definition of "private key".
In public-key encryption, they share public keys.
He deserves to be recognized as a gift, a wonder, to the world.
In one of his talks he shows the OpenSSH 6.5 changelog - a release in which they adopt both "his" 25519 curve and chacha20-poly1305 as new features.
Weird.