Archive for the ‘BIS’ Category


Jun

26

Vladimir Wants To See Your Source Code


Posted by at 4:08 pm on June 26, 2017
Category: BISEncryption

Vladimir Putin by Kremlin.ru [CC BY 3.0 (http://creativecommons.org/licenses/by/3.0)] via https://commons.wikimedia.org/wiki/File%3AVladimir_Putin_12019.jpg [cropped]According to this Reuters report, the Russians are demanding from U.S. companies the right to view source code of software that these companies wish to sell in Russia. The software at issue includes software with encryption capabilities, anti-virus software and firewalls. You don’t have to be a rocket (or computer) scientist to figure out why Vladimir and his spy master buddies want to look at such software. They are looking for vulnerabilities that would allow the Russians to continue to hack into U.S. networks and infrastructure. Surprisingly, Reuters suggests that some big names in U.S. software are actually complying.

That’s surprising because, as many readers probably know, handing over the source code of programs with encryption functionality to the Russian government requires a license from the Bureau of Industry and Security (“BIS”). Normally, I would expect BIS, at least for the moment, to grant such a license when hell freezes over or, as Vladimir himself might say, когда рак на горе свистнет (“when crawfish whistle in the mountains.”)

Here’s why a license is necessary. First, keep in mind that BIS controls the export of software with encryption functionality. This includes software that does not contain any encryption algorithms but calls those algorithms from an external source to perform the actual encryption. Although the language of the EAR is far from making it clear, BIS makes it quite clear here on its website:

Almost all items controlled under Category 5, Part 2 of the EAR are controlled because they include encryption functionality. Items may be controlled as encryption items even if the encryption is actually performed by the operating system, an external library, a third-party product or a cryptographic processor. If an item uses encryption functionality, whether or not the code that performs the encryption is included with the item, then BIS evaluates the item based on the encryption functionality it uses.

Most programs, in fact, call encryption from the operating system. Some browsers, such as Firefox, incorporate their own encryption, and programs may utilize browser encryption when sending and retrieving date from the Internet. In any event, the vast majority of software has some encryption functionality either by using the operating system or native encryption in certain browsers.

Second, source code does not fall under EAR section 740.17(b)(1) and is not eligible for self-classification and export under License Exception ENC. Rather source code that is not publicly available falls under 740.17(b)(2)(i)(B). Items that fall within (b)(2), such as source code, can be exported thirty days after the filing of a classification report to “non-‘government end users’ located or headquartered in a country not listed in supplement no. 3.” See Section 740.17(b)(2)(i). As a result, license exception ENC does not authorize exports to government end-users outside Supplement 3 countries. As Russia is not a Supplement 3 country, a license is required to provide source code with encryption functionality to the government of Russia.

I have no way of knowing whether the U.S. companies that have let Vlad peek at their source code bothered with, or even knew of the requirement for, licenses.   And although not so long ago, BIS would probably have said “nyet” to any such license request, it is altogether possible that BIS is now saying “da” instead.   In any event, companies should think long and hard before spilling their source code for software with encryption functionality to the Russkis without getting a license from BIS first.

 

Permalink Comments Off on Vladimir Wants To See Your Source Code

Bookmark and Share


Copyright © 2017 Clif Burns. All Rights Reserved.
(No republication, syndication or use permitted without my consent.)

Jun

13

Sales Clerk Charged with Illegal Exports Given New Trial


Posted by at 10:17 am on June 13, 2017
Category: BISCriminal Penalties

Alexander Fishenko
ABOVE: Alexander Fishenko


Almost a year ago, I commented on the fate of a lowly sales clerk, Anastasia Diatlova, in the prosecution of Alexander Fishenko, his company Arc Electronics, and employees of Arc for exports of various items to Russia without a license. Ms. Diatlova, the most junior sales clerk in the organization, had refused a plea of time served and gone to trial. This infuriated the prosecutors who took that offer off the table when a jury convicted Ms. Diatlova. Last month, however, Ms. Diatlova was granted a new trial on the export charges. The district court, in granting the new trial, held that there was insufficient evidence that Ms. Diatlova knew that it was illegal to ship the item in question.

The court described the evidence of criminal intent presented by the prosecution as follows:

(1) Diatlova received training on export controls and was aware that microelectronics, when mailed to Russia, are “generally subject to U.S. export control laws (emphasis added);” (2) the higher-ups at Arc (Fishenko, Posobilov and Abdullaev) “routinely lied and fabricated documents in order to evade export control restrictions”; (3) Diatlova filled out a “End-Use Certification/Statement of Assurance” indicating that the end user was Izhevsky Radio Plant, when the recipient was instead Atrilor, LTD, making her, at a minimum, guilty of aiding and abetting the illegal shipment of that part; and that proof exists that she was aware in April of 2012, upon arrest, that the part at issue was restricted.

The court held that allowing the jury verdict to stand “would constitute a ‘manifest injustice’ in light of the flimsiness of this evidence,” noting quite reasonably that her knowledge about the export at the time of arrest had little bearing on her knowledge as of the time of the export. Nor could the illegal intent of other employees be attributed to her. The court did not even comment on the export control training, implicitly rejecting the notion that training alone can lay the groundwork for subsequent criminal prosecution. Finally, putting the wrong end-user on the end-use certificate was seen as the court as a sufficient predicate to let Ms. Diatlova’s conviction for wire fraud stand but not as proof that she knew the export was illegal.

This highlights the difficulty confronted by prosecutors when they target people in the cubicles.  As we noted in our prior post on Ms. Diatlova, she had only an eighth-grade education and was being paid only $15 per hour.   Sadly, this appears to be another case of prosecutors who are more concerned about their conviction stats than anything else.

Permalink Comments Off on Sales Clerk Charged with Illegal Exports Given New Trial

Bookmark and Share


Copyright © 2017 Clif Burns. All Rights Reserved.
(No republication, syndication or use permitted without my consent.)

May

3

Maybe BIS Should Read This Blog More Often


Posted by at 6:21 pm on May 3, 2017
Category: BISEntity ListOFACRussia Sanctions

Vladimir Putin via http://en.kremlin.ru/events/president/news/27394 [Fair Use]Way back in January of this year, I pointed out a problem that the Bureau of Industry and Security (“BIS”) and the Office of Foreign Assets Control  (“OFAC”) may have unwittingly created for U.S. manufacturers of encryption-enabled products, i.e., virtually anything that touches the Internet or a private network.  Both agencies had imposed sanctions on the FSB, the Kremlin spy agency formerly known as the KGB.  The problem with this otherwise laudable move is that the FSB regulates import of encryption products into Putinstan, er, Russia, and these restrictions could effectively prevent exports of U.S. encryption items into Russia.  This would happen because U.S. exporters were forbidden from filing the necessary paperwork with the FSB by virtue of its addition to OFAC’s SDN List and BIS’s Entity List.

Well, OFAC heard the howls of industry and in just after a little more than a week after the issue had come to light issued General License 1 to permit the filing with the FSB of the necessary paperwork for imports of these products.  BIS, however, slept through those howls and did nothing.   The original post on this problem had noted the difficulties posed by BIS having put FSB on the Entity List.   It was at least possible that the FSB notification and application forms could contain unpublished EAR99 technology regarding the device to be exported to Russia, in which case a BIS license would be necessary before the notification or application could be sent to the FSB.   That would be the case even after the OFAC General License authorized the notification and application forms to be sent

Rip van BIS-winkle has finally roused itself from its slumber on this issue.  On April 17, 2017, BIS amended the Entity List designation for FSB to remove the license requirement for transactions for “items subject to the EAR” that are “related to transactions that are authorized by the Department of the Treasury’s Office of Foreign Assets Control pursuant to General License No. 1 of February 2, 2017.” What do you want to bet that a number of FSB applications were filed with technology “subject to the EAR” without the required license before this amendment to the Entity List? Technology, even technology relating to an EAR99 item, is subject to the EAR unless it has already been published or has arisen during “fundamental research.” Few people would think that unpublished information about a commercial EAR99 item would require a license. Most people probably felt that the OFAC General License got them to the finish line when dealing with the FSB. It now does, but it did not before April 17.

Permalink Comments Off on Maybe BIS Should Read This Blog More Often

Bookmark and Share


Copyright © 2017 Clif Burns. All Rights Reserved.
(No republication, syndication or use permitted without my consent.)

Apr

27

The Gray Lady Seems Pretty Gray About Export Law


Posted by at 5:51 pm on April 27, 2017
Category: BISOFAC

Huawei HQ by Brücke-Osteuropa Ditzel [Public Domain], via https://commons.wikimedia.org/wiki/File:Huawei_1.JPGThe New York Times yesterday reported that it had, somehow or other, laid its hands on an administrative subpoena sent last December by the Office of Foreign Assets Control (“OFAC”) to Chinese telecom manufacturer Huawei. The subpoena, according to the newspaper, asks for information on the company’s dealings with “Cuba, Iran, Sudan and Syria over the past five years.”

The article notes that a similar subpoena had been issued earlier last summer by the Department of Commerce, presumably a reference to the Bureau of Industry and Security (“BIS”). This appears to have caused the Times to become perplexed over why OFAC was now sticking its nose into the matter. So they asked someone whom they imagined to be an expert what was going on and he came up with this humdinger:

The most likely thing happening here is that Commerce figured out there was more to this than dual-use commodities, and they decided to notify Treasury.

Nope. Let’s hope for this guy’s sake that he’s been misquoted. Our expert here seems to be unaware that BIS is concerned with more than the export of dual use items. Maybe Part 746 was ripped out of his copy of the Export Administration Regulations or, possibly, his dog ate that part. That part regulates exports of all items “subject to the EAR” to Cuba, Syria, North Korea and Crimea, not just dual-use items.

And, of course, OFAC has rules that prohibit exports of goods to Cuba, North Korea, Sudan, Crimea and Iran and the export of services to Syria as well as the five previously mentioned locations. So the real answer here as to why OFAC is piling on here is because it can, not because there were concerns by BIS about transactions outside its jurisdiction.

Permalink Comments Off on The Gray Lady Seems Pretty Gray About Export Law

Bookmark and Share


Copyright © 2017 Clif Burns. All Rights Reserved.
(No republication, syndication or use permitted without my consent.)

Mar

28

Commerce Export Award Winner Fined $27 Million for Export Violations


Posted by at 8:08 pm on March 28, 2017
Category: BIS

Access USA Facebook Page photo via https://www.facebook.com/myuscom/photos/a.10150689214007268.416222.88639537267/10154158962337268/?type=3&theater [Fair Use]

Access USA Shipping, which runs the website MyUS.com, was once the darling of the Commerce Department.  According to the company’s website, the company won that agency’s “President’s ‘E’ Award” for exporters. Do they still get to keep that award after agreeing to pay the Department of Commerce’s Bureau of Industry and Security (“BIS”) a $27 million for 150 export violations?

The allegations contained in the BIS Charging Documents, if true, are pretty harrowing. According to BIS, Access USA changed values and item descriptions in export documents to avoid export scrutiny, describing, for example, guns and weapons parts as “sporting goods accessories,” “fishing tools and spare parts,” or “tailoring tools.” In another case, employees described exported rifle stocks and grips as “toy accessories.” And then, according to BIS, the company had a “personal shopper program” not to help busy executives pick out the best ties or dresses but to have employees pose as the foreign customer, using the employee’s own personal credit cards and home addresses, where the U.S. seller had refused to sell export controlled goods to that foreign customer. There’s plenty more, but you get the gist.

Not surprisingly, the charging documents point out at length that BIS had made “outreach” visits to explain the export laws to Access Shipping. The purpose of these references, apparently, was to bolster the case, as if that were needed, that the company knew what it was doing was on the dark side of the shady line. It strikes me that when guns are described as fishing tools — hey look, it’s a barrel of fish! — you’ve pretty much got the intent issue covered.

This reference to “outreach” visits reinforces the point I’ve made before that these “outreach” visits are not as much made out of the agency’s altruistic desire to educate as they are made to build future cases when the “outreach” victim makes a mistake — although this particular case, admittedly, seems pretty far from an innocent mistake.  Just say no to “outreach” visits.  They will provide less information than sending employees to real training conferences and seminars and will only come back to haunt you.

Permalink Comments Off on Commerce Export Award Winner Fined $27 Million for Export Violations

Bookmark and Share


Copyright © 2017 Clif Burns. All Rights Reserved.
(No republication, syndication or use permitted without my consent.)