[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Fwd: OECD nixes key escrow, no "international consensus"
- To: "Mailingliste FITUG-debate" <email@example.com>
- Subject: Fwd: OECD nixes key escrow, no "international consensus"
- From: "Gunnar Anzinger" <firstname.lastname@example.org>
- Date: Thu, 06 Feb 97 01:47:41 +0100
- Comment: This message comes from the debate mailing list.
- Priority: Normal
- Reply-To: "Gunnar Anzinger" <email@example.com>
- Sender: firstname.lastname@example.org
==================BEGIN FORWARDED MESSAGE==================
>Date: Wed, 5 Feb 1997 08:58:25 -0800 (PST)
>From: Declan McCullagh <email@example.com>
>Subject: OECD nixes key escrow, no "international consensus"
The OECD shot down key escrow. The OECD nixed "key recovery." The OECD
stood up to U.S. pressure and did not endorse government access to keys.
It's important to stress this point since administration officials, most
notably Ambassador Aaron, have been misrepresenting the OECD's position.
For months they have talked of a growing international consensus,
insisting that the U.S. must follow other countries.
The OECD's carefully neutral position gives the lie to the government's
---------- Forwarded message ----------
Global group fails to endorse Clinton encryption plan
Washington: An influential economic research group is preparing
guidelines on computer encryption for its member countries but
will duck some of the most contentious issues involved, according
to a draft obtained by Reuters.
The Clinton administration, seeking to rally support for its
controversial policy on exporting encryption products -- which
encode and decode e-mail and other computerized messages -- failed
to win an endorsement from the Organisation for Economic Cooperation
and Development (OECD), although the group did discuss the
On perhaps the most difficult issue, the draft guidelines do not
favour or oppose a requirement in the U.S. policy that data-scrambling
encryption programmes provide a way for law enforcement officials to
obtain keys to crack the codes when necessary.
After indicating that governments should carefully weigh the costs and
benefits of imposing so-called key recovery, the draft report said,
"this principle should not be interpreted as implying that governments
should, or should not, initiate legislation that would allow lawful
On all the controversial areas in the draft, "the member countries of
the OECD have strongly held views but they don't always coincide,"
John Dryden, head of the group's Information, Computer and Communications
Policy division, said in a telephone interview from Paris.
Some countries see widespread use of encryption as a way to protect the
privacy of computer users and businesses, thereby encouraging global
commerce, Dryden said. But others see encryption as possibly thwarting
law enforcement's efforts to catch riminals and global terrorists, he
The guidelines suggest encryption users should have access to products
that meet their needs. Government controls should be "no more than are
essential to the discharge of government responsibilities."
Instead of reconciling the different views, the draft guidelines lay out
competing interests and approaches.
"It's not in itself a cryptography policy and it's not an attempt to
draft a model national law that we're encouraging people to adopt,"
Dryden said. Cryptography refers to products and systems used in
The guidelines also suggest encryption standards and usage should be
"determined by the market in an open and competitive environment."
"There's a strong view that the private sector should have the
possibility to use information networks to the best of their potential
in order to create growth and jobs," Dryden said.
U.S. officials who have seen the preliminary draft praised the guidelines.
"They're an important and helpful step forward," Undersecretary of
Commerce William Reinsch said.
"They're helpful because they put down on paper the proper foundation for
getting into this," he added.
Reinsch said most countries will follow the U.S. lead and require
so-called key recovery features for law enforcement. Under the Clinton
policy, domestic use of encryption is not regulated but the strongest
coding products cannot be exported unless they include key recovery.
U.S. companies that have opposed the Clinton policy, contending it stifles
their ability to compete with unfettered foreign firms, drew little solace
from the draft guidelines.
"This is not helpful," said Netscape Communications Corp.'s public policy
counsel, Peter Harter. Netscape and other companies preferred stronger
language endorsing free-market policies, he said.
The draft guidelines, approved by a group of government and private-sector
experts at a meeting at the end of January, still must be approved by a
top-level OECD officials from the group's 29 member countries, including
the United States.
===================END FORWARDED MESSAGE===================