Dear Lists,

All these projects are very interesting.  Forgive a slightly off-topic
but important question that they raise, though.

What are the legal implications of contributing to these sorts of
wrapper projects?  Do such projects count as "export" of "dual use"
cryptography for the purpose of EU and USA laws?

In the past, such questions have caused open source projects no end of


The "crypto law survey" attempts to answer some of these questions.

Following the links for the UK and the USA, it looks to me as if *any*
project that facilitates the use of cryptography would have to take
legal advice, even if it is merely a wrapper for another program or
library, and would have to be careful about where it was hosted, and
who it accepted contributions from.

Is that correct?

The GPG project itself must have hit many of these issues.  Is there a
write-up anywhere of their conclusions?  Something like that might be
helpful for other people starting these sorts of projects.

Best wishes,

(I am not a lawyer...)

