When submitting or updating an app, one question you are faced with is:
Have you added or made changes to encryption features since you last uploaded a binary for this product?
Image:

My question is, if I use the encryption you get from the <CommonCrypto/CommonCryptor.h> library, do I have to check YES to that Q?
I have a file I'd like to encrypt, send to the iphone, and decrypt on the iphone using CommonCrypto. I've gotten mixed responses when talking with coworkers. Some believe that since it's an included framework that it's fair game, others say you have to get government approval.
It appears CommonCrypto supports (at best) AES 128 bit encryption with a cipher mode of ECB. So, that's what I was planning on using.
Side Note: I plan on using the NSData+CommonCrypto category from AlanQuatermain / aqtoolkit on github. This is just a wrapper around CommonCrypto and nothing more.
Related is, do you have to check YES if you use HTTPS (SSL)? See iPhone Encryption Export Compliance for Apps making HTTPS (TLS) Connections - Continued. I don't need https connections, still this surprises me...