02-17-07 12:12 AM
Christian Danner wrote:
> To make Mixmaster and Reliable become unrestricted pieces of software
> for any kind of usage I see the necessity of alternatives to all
> (Cypherpunk / Type-I) applications of the patented IDEA(TM) block
> cipher algorithm. 'Encrypt-Key' (ek) can be avoided since
> 'Encrypt-CAST' and 'Encrypt-3DES (ekx) were added. But how about
> 'Esub'? Is there a chance to supplement the remailer software with
> e.g. a Triple-DES/SHA-1/Base64 based subject encryption ('Dsub')?
That's important not only for users, but particularly for the exposed
remops offering CP functionality! It has to be fixed asap. Otherwise,
for years to come it would threaten all remops, who in principal are
defenseless, as there's no chance to differentiate between the
forwarding of personal and commercial messages. Moreover, the IDEA
license emphasizes, that even non-profit organizations have a
commercial status and thereby are bound to pay license fees.
<quote>
This Software/Hardware product contains the algorithm IDEA(tm) as
described and claimed in US Patent No. 5,214,703, EPO Patent No.
0482154 and filed Japanese Patent Application No. 508119/1991 "Device
for the conversion of a digital block and use of same" (hereinafter
referred to as "Algorithm"). Any use of the Algorithm for Commercial
Purposes is thus subject to a license from Ascom Systec Ltd. of
CH-5506 Mägenwil (Switzerland), being the patentee and sole owner of
all rights, including the term IDEA(tm). Commercial Purposes shall
mean any revenue generating purpose including but not limited to
i) using the Algorithm for company internal purposes (subject to a
Site License).
ii) incorporating an application software containing the Algorithm
into any hardware and/or software and distributing such hardware
and/or software and/or providing services related thereto to others
(subject to a Product License).
iii) using a product containing an application software that uses the
Algorithm (subject to an End-User License), except in case where such
End-User has acquired an implied license by purchasing the said
product from an authorized licensee or where the End-User has already
signed up for a Site License.
All such commercial license agreements are available exclusively from
Ascom Systec Ltd. and may be requested via the Internet World Wide Web
at http://www.ascom.ch/systec/infosec.html or by sending an electronic
mail to IDEA@ascom.ch. Any misuse will be prosecuted.
Use other than for Commercial Purposes is strictly limited to data
transfer between private individuals and not serving Commercial
Purposes. The use by government agencies, non-profit organizations
etc. is considered as use for Commercial Purposes but may be subject
to special conditions. Requests for waivers for non-commercial use
(e.g. by software developers) are welcome.
</quote>
There's no reason to take such a risk for no practical advantage. So
I'd demand to be on the safe side by having an opportunity to
deactivate IDEA (ek and esub) as a whole after reaching an agreement
on an esub replacement.
Tia
.
[ Post a follow-up to this message ]
|