The United States had to be brought to court to finally allow cryptography: https://en.m.wikipedia.org/wiki/Bernstein_v._United_States
> Years before, the government had placed encryption, a method for scrambling messages so they can only be understood by their intended recipients, on the United States Munitions List, alongside bombs and flamethrowers, as a weapon to be regulated for national security purposes. Companies and individuals exporting items on the munitions list, including software with encryption capabilities, had to obtain prior State Department approval. — Electronic Frontier Foundation: EFF's History
Before that, export rules could be "worked around" by printing cryptography in books.
See also https://en.m.wikipedia.org/wiki/Export_of_cryptography_from_...
It still is.
e.g in France:
https://cyber.gouv.fr/en/protection-sensitive-and-restricted...
This legal framework has been introduced in 2011 in order to protect facilities, knowledge, savoir-faire, information which, if intercepted, could:
- Affect French economic interests (risk 1);
- Reinforce military capacities of other country or weaken French military capacities (risk 2);
- Lead to the proliferation of weapons of mass destruction in nuclear, ballistic, chemical or biological fields;
- Lead to the development of terrorist activities on French territory or abroad.
It's just that import/export constraints have been relaxed.See Annexe 1 here: https://www.legifrance.gouv.fr/loda/id/JORFTEXT000000646995?...
This is one of the reasons why MobiusSync is not available in the French iOS App Store since it doesn't use iOS crypt which already has approval plus it doesn't fit into some of the exceptions to the restrictions, so they'd have to fill in paperwork which is only available in French and submit via snail mail (go figure, although they do accept answers written in English as a courtesy).
https://github.com/MobiusSync/MobiusSync/issues/27
Similar concerns, processes, and exceptions are effective for other countries, e.g for the U.S. you need Encryption Registration (ERN) approval from the U.S. Bureau of Industry (BIS). Exceptions are described in Category 5, Part 2 of the U.S. Export Administration Regulations.
For one thing, it sounds like sending wasn't impacted at all, once you had the software.
What I'm getting at is that it's simply incorrect that encryption wasn't available in the US, and it's also incorrect that encryption couldn't or wasn't in use. It most definitely was. The regulations were only about export. 40 bits max and all that.
This is way too much of an unknown. And we've seen with P2P/Napster and DMCA where just listing links without distributing still opens people to legal issues.
Edit: As for Napster and DMCA, the Napster story happened in 1999 and the DMCA in 1998. The limitations on crypto were loosened in 1998 and 1999 and removed in 2000. In other words, Napster and DMCA isn't really relevant here - the encryption story mostly unfolded before that time.
Really, even back in 1995, people did understand how the Internet works. Nobody was under any illusions that you could actually control "export" of cryptographic software. If you were a US-based company that sold shrink-wrap software, you probably also filled out some paperwork once a year. For "open source" software (note: not a thing, as such, in 1995): forget about it.
You don't understand the legal liabilities people open themselves to if they provide the software.
Now they have to fully KYC customers to make sure they are from the US, with US only storage, and firewall so that people travelling cannot use the encryption library from out of the US.
You've seen the lawsuits on just P2P link providers, this is even worse.
The US still restricts the export of (some) cryptography to (some) countries & organizations. Mostly that just requires submitting a self-classification report to the BIS stating that the cryptography is "mass market" and matches the definition thereof in the export regulations.
The issue here is the complexity of complying and closing all loopholes that would allow the government to bring the full weight of the legal system against a library writer.
It was perfectly fine for American citizens to use cryptography amongst each other or with outside nationals. It was also completely fine to download and use externally developed software.
What was illegal was developing and exporting cryptographic software. This is why, for the longest time, you would see warnings on web pages (puTTy, for instance) saying the software was only intended for use in the United States.
The form made it clear that using HTTPS is considered cryptography, so I’m fairly sure almost every app on the store has checked “yes” to that question.
To fully comply with this you would need as a library provider to fully KYC your clients so that there is a firewall between their US and non-US entities, and that travelling people don't bring out an encryption library at the same time.
It would be a operational nightmare.
The law never covered using cryptography, it was always about exporting it. Mostly it was written around keeping military specific cryptography from entering rival powers hands, but was overbearing. So they amended it to allow commercially developed/homegrown cryptography (explicitly not developed for governmental/military use) to be distributed normally. In practice, it's still a little muddy as many of those use DoJ/DoS-funded cryptography patterns, but the government has chosen to take a fairly hands off approach on those (RSA and DSA are key examples).
You're correct that it would also be almost impossible to enforce the original wording in today's world of globalization. They also have little power to enforce it on foreign nationals, which is why a warning was usually Good Enough(TM) for American software developers.
Re-read the first post and the last paragraph of the one you're replying to. Everything you're knee jerk contrarianizing is covered.
In (I think) early 1995 I bought a "This T-Shirt Is A Munition" shirt with RSA source code on it, by typing the information from the bottom of a personal check(!) into a web page. It was a whole thing.
This led to all kinds of stupidity. Internet Explorer shipped with nerfed TLS capabilities, limiting key sizes to 40 bits or 56 bits depending on the version.
When the encryption laws changed in 2000, Microsoft allowed users to download an update to improve SSL encryption: https://learn.microsoft.com/en-us/previous-versions/tn-archi...
You could legally encrypt emails, of course, as long as you kept the key sizes small and didn't export the encryption software to another country.
If you sell and export encryption products from the USA (and a bunch of other countries, see the Wassenaar Accords) to certain places (including China and Russia), you're still obligated to register your product if you use modern key sizes. I'm not sure if governments still care now that OpenSSL and PGP are freely available to anyone, but if your proprietary email encryption program is found on North Korean computers, your government may ask you some uncomfortable questions.
This leaves the critical infrastructure of emergency services and police force for a lot of countries (notably, US non-allies) wide open to attack.
And even if a determined person could get around the blocks, they severely limited the network effects; office workers on their employers' PCs weren't going to be getting encryption software from IRC bots to bypass arms export laws.
Some time towards the late 90s PGP became much more easily available.
I was at codecon, forget if Zimmerman was there, or just quoted. His story was recounted, then someone else who attended codecon and mentioned releasing ITAR restricted crypto. They were part of a leak of the RC4 source code. A copy was sent to a well known member of sci.crypt, saying along the lines of "I think you can post this anonymously", if you agree to this please post a "Looking for Joe Random" post on sci.crypt. The source code was posted and there was no lawsuit, no tax audit, and no hassling by the government.