next up previous contents
Next: Key Management Up: Cryptography HowTo Previous: Which cryptography program should   Contents


What are these legal issues?

The United States has some export laws which are problematic for cryptography. Basically, cryptography is considered a weapon which must be export-controlled. This means that you can't legally give a cryptography program to a non-US national if you are a citizen of the United States. Strictly speaking, you aren't even allowed to give this program to some people of the people who are here in the United States, as these individuals are considered a threat to national security. However, you are legally allowed to tell all of these people where they can download these same programs.

PGP is made in the United States. This means that it cannot legally be exported from the United States. In addition, earlier versions of PGP had problems with patents which were issued here in the US. Finally, PGP still uses some methods which are patented in Europe. The program itself is free for non-commercial use, but if you run a business and wish to use PGP, you must pay for a license to use it. Considering all these legal encumbrances, we cannot recommend PGP for use.

GPG is based in Germany, which does not have such problems exporting cryptography. GPG also doesn't use patented methods for its encryption. The program itself is being given away for free, for both commercial and non-commercial use. Putting all of these factors together, we have to suggest using GPG over using PGP, and will try harder to answer questions with GPG than we will with PGP.


next up previous contents
Next: Key Management Up: Cryptography HowTo Previous: Which cryptography program should   Contents
Greg Wooledge 2000-10-11