From PGP to Mythos: a brief history of export controls that didn’t stop anyone

The Futile Battle: Export Controls on Encryption Couldn't Stop the Digital Tide

In the early days of the internet, a quiet but intense battle unfolded over the future of digital privacy and security. At its heart was encryption software, particularly Pretty Good Privacy (PGP), which became a symbol of a larger struggle against government attempts to control information. A look back at the history of export controls on strong cryptography reveals a determined, yet ultimately futile, effort to rein in technology that, in hindsight, was always destined to be free.

For decades, strong encryption was classified as a munition by the United States government, akin to weapons and other sensitive military technology. This classification, largely a relic of the Cold War, meant that software like PGP, developed by Phil Zimmermann in the early 1990s, could not be freely exported from the U.S. without a license. The rationale was national security: authorities feared that widely available, uncrackable encryption would hinder intelligence gathering and law enforcement efforts, allowing criminals and terrorists to communicate beyond government reach. This period, often dubbed the "Crypto Wars," pitted privacy advocates and tech innovators against government agencies.

However, the very nature of software and the burgeoning internet made these controls inherently difficult, if not impossible, to enforce. The global digital network meant that information, once released, could spread universally in moments. Activists and developers found ingenious ways to circumvent the restrictions. One famous example involved "exporting" PGP by printing its source code in a physical book, then allowing it to be scanned and re-digitized abroad, arguing that books were protected by free speech and not subject to munitions regulations. Legal challenges, such as Bernstein v. United States, further chipped away at the government's stance, asserting that software code was a form of speech.

The tide eventually turned. By the late 1990s and early 2000s, the U.S. government began to relax its export controls on encryption, acknowledging the impracticality of enforcement and the growing global demand for secure online communications. The rise of e-commerce and the widespread adoption of secure sockets layer (SSL/TLS) for websites made strong encryption a fundamental component of daily internet use. What was once considered a weapon became an essential building block for everything from online banking to private messaging.

Today, strong encryption is ubiquitous. From the end-to-end encryption in messaging apps like Signal and WhatsApp to the secure connections protecting nearly every website we visit, the "Mythos" of impenetrable digital communication has largely come to pass. This widespread adoption, far from being stopped, was only momentarily delayed by export controls. The historical battle over PGP offers a powerful lesson: in the digital age, attempts to control the flow of information, particularly fundamental technologies like encryption, are often doomed to fail. The internet's inherent design for redundancy and resilience means that information, once released, will always find a way to its intended audience, regardless of national borders or regulatory hurdles.

Original reporting TechCrunch
Return to Homepage