Skip to content

The Crypto Wars of the 1990s

Abstract

For most of the Cold War, cryptography was legally a weapon: US export rules classified encryption software alongside missiles and fighter jets. In the 1990s this collided with a civilian internet that needed encryption for everything. The decade-long fight (the Clipper chip and its broken backdoor, the criminal investigation of Phil Zimmermann, the court ruling that source code is speech, and a $250,000 machine that publicly cracked the government’s own cipher standard) ended with near-total defeat for the controls. Its debris, the deliberately weakened “export-grade” ciphers, was still breaking TLS connections in 2015.

Cryptography as Munition

Under the International Traffic in Arms Regulations, encryption sat on the US Munitions List, so exporting strong cryptographic software required a State Department arms license. The practical ceiling for mass-market software was a 40-bit key, breakable by brute force in days on ordinary hardware. The rules produced absurd artifacts: Netscape shipped two browsers, a US edition with 128-bit SSL and an International Edition that used 128-bit keys but transmitted 88 of the bits in the clear, leaving 40 secret bits to protect the world’s first online credit-card payments (see SSL and Public Key Cryptography). Since anyone could buy strong crypto from European or Israeli vendors, the controls increasingly regulated only where good software could be written, not who could have it.

The Clipper Chip

In April 1993 the Clinton administration announced its compromise: strong encryption for everyone, with a spare key for the government. The Clipper chip was an NSA-designed tamper-resistant processor for telephones running a classified cipher called Skipjack. Each conversation transmitted a Law Enforcement Access Field (LEAF) containing the session key, encrypted to keys held in escrow by two federal agencies; with a warrant, agencies could fetch the halves and listen. AT&T built the chip into its TSD-3600 secure phone.

The backlash united an unusual coalition of civil libertarians, cryptographers, and industry, and the technical kill came quickly. In 1994 Matt Blaze of AT&T Bell Labs published “Protocol Failure in the Escrowed Encryption Standard”, showing that the LEAF’s integrity was protected by only a 16-bit checksum: a user could brute-force a bogus LEAF that passed validation but gave wiretappers nothing, using the chip’s strong encryption while cutting off the escrow. A backdoor that can be closed by its target is just overhead. Nobody bought the phones except the Department of Justice, and by 1996 Clipper was dead. The lesson cited in every “exceptional access” debate since is that the hard part is not the cryptography but building a master-key system that only the right people can use.

Code as Speech

The enforcement side fared no better. The three-year criminal investigation of Phil Zimmermann for the internet spread of PGP collapsed in 1996 without charges; MIT Press meanwhile printed PGP’s source code as a book, which the First Amendment protected and which European volunteers scanned back in, making the export rules look ridiculous in the process (the full story, including Germany’s parallel Kryptodebatte, is in Phil Zimmermann and PGP).

The decisive legal blow came from a graduate student. Daniel Bernstein wanted to publish his encryption system Snuffle and sued the government when told he needed an arms license. In 1996 federal judge Marilyn Hall Patel ruled that source code is speech protected by the First Amendment, and the Ninth Circuit affirmed in 1999; Peter Junger won similar relief in Ohio. Licensing schemes that function as prior restraint on publishing code do not survive that framing.

Breaking DES in Public

The government’s own standard became the demonstration piece. DES, adopted in 1977 with its key length trimmed to 56 bits under NSA influence, was defended through the 1990s as adequate for commercial use. In July 1998 the Electronic Frontier Foundation unveiled Deep Crack, a machine of 1,856 custom chips built for under $250,000 with Paul Kocher of Cryptography Research as principal designer. It won RSA’s DES Challenge II-2 by finding a key in 56 hours, and in January 1999, working with distributed.net, cut that to 22 hours 15 minutes. The argument was over: if a nonprofit could do this for pocket change, the claim that 56-bit crypto protected anyone from serious adversaries was untenable. NIST’s replacement competition produced AES in 2000, selecting a cipher designed by two Belgians, beyond export control by birth.

Surrender

Executive Order 13026 moved commercial encryption from the Munitions List to the Commerce Department’s control in 1996, and regulations issued in January 2000 dismantled most of what remained, allowing export of retail and open-source crypto with minimal formality. Browsers everywhere quietly turned on 128-bit encryption. The policy fight had lasted a decade; the liberalization took a paragraph in the Federal Register.

Dead End: Export-Grade Ciphers

The wars left live ammunition in the protocols. SSL/TLS retained its negotiation machinery for the old 40-bit and 512-bit “export” cipher suites long after anyone needed them, and in 2015 researchers showed the debt was still collectable: the FREAK attack tricked servers into downgrading to export-grade 512-bit RSA, and Logjam did the same to export-grade Diffie-Hellman, breaking connections of clients that had never knowingly used weak crypto. Deliberately weakened cryptography, once standardized, outlives the policy that demanded it by decades.

The underlying conflict did not end; it moved. The Snowden documents revealed the NSA had shifted from front-door regulation to covert sabotage of standards and implementations (see Edward Snowden and the NSA and BULLRUN), and the 2016 Apple-FBI standoff over a locked iPhone replayed the Clipper arguments nearly verbatim. Each round rediscovers Blaze’s 1994 result: there is no key that opens only for the good guys.

📚 Sources