the Crypto Wars
lorecryptographyprivacygovernance & risk
The 1990s battle over whether strong cryptography could be exported, escrowed, or used freely at all.
The US government classed strong crypto as a munition, proposed the key-escrowed Clipper chip in 1993, and investigated Phil Zimmermann for years after PGP escaped onto the Internet; activists answered by printing source code in books, which the First Amendment protects. Export rules were largely relaxed by 2000, and the browsers' padlock is the peace dividend. Every modern proposal for lawful-access backdoors reopens the same trench lines.
The crypto wars were the long argument over whether civilians should have access to strong encryption. In the United States it involved export controls that classified cryptography as a munition, the Clipper chip proposal for key escrow, and litigation over whether publishing source code was protected speech.
The technical objection to key escrow was never about privacy alone, and this is the part that keeps being relevant. A mechanism that allows authorized access is a mechanism, and mechanisms have implementation flaws, insider risk and no way to distinguish the authority it was built for from anyone who obtains the same access. Cryptographers argued that exceptional access could not be built without weakening the system for everyone, and that argument has not been refuted since.
The wars are commonly described as won, on the grounds that strong encryption became ubiquitous. That is true and the argument recurs on a cycle, currently around messaging and client-side scanning, with the same structure and the same technical objection. Anyone encountering the current version benefits from knowing that it is the third or fourth iteration rather than a new question.
Also known as: Clipper chip, export controls