[00:00.000 --> 00:00.820] That's the way to shut off the music. [00:00.980 --> 00:01.340] There we go. [00:03.620 --> 00:04.480] In the back. [00:05.640 --> 00:06.040] Quiet. [00:06.380 --> 00:06.740] Thank you. [00:08.060 --> 00:09.200] So thank you all. [00:11.260 --> 00:12.360] Thank you all for coming. [00:12.540 --> 00:13.680] My name is Chris Soghoian. [00:13.860 --> 00:18.520] I'm the principal technologist with the ACLU's Speech Privacy and Technology Project. [00:18.780 --> 00:20.220] Can people in the back hear me okay? [00:21.300 --> 00:21.700] Yeah? [00:22.280 --> 00:23.020] Okay, cool. [00:24.840 --> 00:31.060] So I have a fun talk, I hope for you all today, about how I learned to love cyber. [00:32.880 --> 00:37.140] So before I start, it's been a really cool year for the ACLU. [00:37.680 --> 00:39.060] I work with a team of lawyers. [00:39.080 --> 00:46.380] I advise the lawyers at the ACLU who do most of our surveillance, both national security and law enforcement litigation. [00:48.900 --> 00:58.580] And I know that for many of you, you may have heard of the ACLU, but you may not realize how we work on the issues that you probably care very deeply about. [00:58.660 --> 01:01.900] So just a couple of things we've worked on in the last few months that have really borne fruit. [01:02.520 --> 01:09.640] About a month ago, the Supreme Court ruled that cell phones are a protected space when it comes to searches, incident to arrest. [01:09.800 --> 01:12.780] And so now the police need a warrant to search your cell phone. [01:19.330 --> 01:22.710] That was a big win, something we participated extensively in. [01:22.990 --> 01:33.590] We won a major decision at the 11th Circuit down in Florida, holding the location data, cellular location data, whether historical or real time, is also protected by a warrant. [01:33.590 --> 01:37.410] And so the government cannot just simply call up the phone company and get your data. [01:43.300 --> 01:46.560] And then I'm sure many of you watched Ed Snowden's talk yesterday. [01:47.300 --> 01:55.440] And my boss, Ben, has been advising Ed for some time, for some months in the last year. [01:55.640 --> 01:59.620] And so that has been one of the more exciting things that we've all gotten to work on. [02:00.060 --> 02:06.260] So, you know, we're really, really happy how things are going so far on that particular set of issues. [02:06.260 --> 02:12.840] But Ed Snowden's revelations have really sort of opened things up in many ways on many fronts on surveillance. [02:13.180 --> 02:15.580] And you'll really get a taste of that going forward. [02:16.520 --> 02:16.800] All right. [02:16.900 --> 02:18.680] So let's go back in time. [02:19.140 --> 02:20.440] Let's go back to 2009. [02:21.080 --> 02:21.820] Five years ago. [02:22.020 --> 02:32.320] It was a very, very different world for those of us who care about encryption, who care about surveillance, and who care about the extent to which the government can engage in massive dragnet surveillance. [02:33.580 --> 02:38.880] The world of SSL or TLS was not a good one in 2009. [02:39.560 --> 02:42.380] Of course, the technology existed within your browser. [02:42.800 --> 02:48.000] Probably you didn't have the most up-to-date version of TLS implemented in your browser. [02:48.120 --> 02:51.160] But your browser did support HTTPS. [02:51.560 --> 02:58.500] And unfortunately, most of the sites you were using, with the exception of financial sites, were probably not using it by default. [02:58.500 --> 03:10.440] And so unless you either sought out some hidden configuration option, or you typed in the URL manually, most of your data was going to be going over networks without any form of encryption. [03:10.860 --> 03:15.840] This, of course, meant that both content and non-content could be monitored by the NSA. [03:15.840 --> 03:27.200] And I think if there's one thing that we've seen in the last year, it's really that massive bulk surveillance is easiest when it's performed passively. [03:27.440 --> 03:32.620] When the government can just collect and monitor unencrypted data at choke points around the world. [03:33.360 --> 03:50.300] And so back in 2009, most of the big U.S. technology companies to whom we entrust our private data, Google, Facebook, Twitter, Microsoft Hotmail, and Yahoo, all of them sent their users most sensitive information over the Internet in plain text. [03:50.680 --> 03:57.640] We knew how to protect this information, but in 2009, these companies just were not turning on crypto by default. [03:57.640 --> 04:02.260] With the exception of the username and password during login. [04:03.440 --> 04:14.560] This is from a blog post that Google published in 2009 when they first made available an option, a configuration option to even require SSL in the future. [04:14.820 --> 04:17.660] They said, HTTPS can make your mail slower. [04:17.960 --> 04:20.960] Your computer has to do extra work to decrypt all that data. [04:21.320 --> 04:24.720] And encrypted data doesn't travel across the Internet as efficiently as unencrypted data. [04:24.900 --> 04:27.200] That's why we leave the choice up to you. [04:27.880 --> 04:30.200] And so this is... this is mid-2009. [04:31.000 --> 04:36.800] And this is Google's Gmail security team, on one hand, announcing a good thing. [04:36.980 --> 04:42.600] Announcing that people don't have to manually edit the URL every time they want to go back to Gmail in the future if they want to do so securely. [04:42.900 --> 04:48.560] But on the other hand, clearly putting the responsibility on the individual user to enable this obscure option. [04:48.560 --> 04:52.080] And the option was called, use SSL question mark. [04:52.420 --> 04:53.780] There was no label there. [04:53.960 --> 04:57.140] There was nothing suggesting that this was a security feature. [04:57.460 --> 04:59.560] Nothing describing the importance of it. [04:59.920 --> 05:06.100] And it was the 13th... 13 of 13 configuration options after the vacation auto away message. [05:06.280 --> 05:07.680] After Unicode settings. [05:07.680 --> 05:14.620] I mean, it was the least important setting in the order of the interface. [05:14.980 --> 05:20.320] And so, for obvious reasons, most people probably never enabled the setting. [05:22.420 --> 05:31.920] And so, in many ways, the fact that these companies were not encrypting data meant that the NSA had a wealth of data at their disposal. [05:33.180 --> 05:43.780] If we've seen anything in the last year, if we've learned anything from the Snowden documents, it's that the biggest problem for the NSA hasn't been how to access the data, our data. [05:44.000 --> 05:45.900] It's been how to parse all the data. [05:46.000 --> 05:48.800] How to cope with data at that scale. [05:49.520 --> 05:56.700] In many ways, the NSA has really just been gorging themselves on our sensitive and private information. [05:56.700 --> 06:04.020] And this really has been made possible because so many of these large companies have done so little to protect our private information. [06:05.260 --> 06:08.140] Okay, so, 2009 was a bad time. [06:09.160 --> 06:10.600] But that was five years ago. [06:10.760 --> 06:12.720] And things are slowly starting to get better. [06:12.900 --> 06:20.900] Over the last three or four years, and particularly in the last year, the big tech companies have really started to lock things down. [06:21.100 --> 06:24.600] And in particular, to lock down the connection between your computer and theirs. [06:25.680 --> 06:28.660] Of course, this is the result of Ed Snowden. [06:28.840 --> 06:33.120] Without Snowden's disclosures to the press, we would not be having this debate. [06:33.660 --> 06:37.860] Companies would not have been forced or shamed into updating their security. [06:38.000 --> 06:51.280] And so, it was the result of disclosures by Ed and then careful reporting by a few news outlets and the journalists working for them who really, really dug in to find things that mattered. [06:51.520 --> 06:59.840] And then, I think in many ways, to put direct pressure on these companies to tweak their security or in many ways to significantly enhance their security. [07:00.760 --> 07:06.240] This slide, when it was first published by the Washington Post, the SSL added or removed here. [07:06.800 --> 07:09.240] The slide, of course, upset many people. [07:09.240 --> 07:16.180] Famously, several Google engineers were said to have... or wrote on their blogs, you know, f*ck those guys. [07:17.500 --> 07:26.580] Obviously, there are people inside the Google security team who don't appreciate the NSA evading the Maginot Line security systems that they designed. [07:28.160 --> 07:37.620] And so, this was one example of a program by the NSA or GCHQ that definitely led to tech companies improving their security. [07:37.620 --> 07:46.740] In this case, it was Google, Twitter, and other companies deciding that, finally, they needed to encrypt the data center to data center links within their infrastructure. [07:47.940 --> 07:49.660] This story got a lot less press. [07:49.820 --> 07:54.560] It was also won by the Washington Post, the reporters Bart Gelman and Ashkin Sultani. [07:56.000 --> 08:00.980] And in this story, they revealed that one of the most interesting targets for the NSA were address books and buddy lists. [08:01.180 --> 08:06.280] So, information about who you contact, in many cases, is even more interesting than what you're saying to them. [08:07.080 --> 08:11.800] I'm just going to sort of zoom in to the chart on the bottom right-hand side. [08:12.480 --> 08:23.700] What the post revealed was that Yahoo and Hotmail users were having their address books collected by the NSA an order of magnitude more times than Google or Facebook. [08:24.300 --> 08:26.200] That seems like a pretty interesting data point. [08:26.340 --> 08:33.440] And, of course, the reason for this is that until January of this year, Yahoo wasn't using SSL at all for any of their services. [08:34.300 --> 08:36.160] So, Yahoo eventually fixed things. [08:36.380 --> 08:38.400] And Microsoft has fixed things, too. [08:38.640 --> 08:45.340] And Google has not only continued with their moves towards SSL, but they've enabled perfect forward secrecy. [08:45.480 --> 08:47.160] They've tweaked the algorithms they're using. [08:48.320 --> 08:54.260] And so, in many ways, the upgrades we've seen have really been as a result of this news coverage. [08:55.160 --> 09:03.820] In March of this year... or sorry, May of this year, a bunch of operators of Jabber servers or XMPP servers all got together and said, you know what? [09:03.920 --> 09:04.580] It's 2014. [09:04.900 --> 09:10.480] We should be requiring encryption by default for the transit links between our users and servers. [09:10.820 --> 09:11.800] And so, they all turned it on. [09:12.720 --> 09:21.960] And that was a really big thing because now the government... our government or, in fact, any other government cannot just sit on the wire and watch instant message traffic go back and forth. [09:22.620 --> 09:31.340] And so, we're really seeing this trend towards encrypting data in transit and towards encrypting data between the consumer and the server. [09:33.040 --> 09:38.000] This has really been helped by some of the Snowden stuff, but there have also been other efforts. [09:38.560 --> 09:47.440] Naming and shaming can work particularly well when the practice that the company is engaged in is largely indefensible, but not known to the general public. [09:47.440 --> 10:01.180] A few months ago, Google published this really useful transparency report revealing which of the servers they interact with, the mail servers they interact with, and which of those support StartTLS server-to-server email encryption and which of those don't. [10:02.360 --> 10:14.380] And the changes that have happened in just the last month or two since Google made this data available have really been night and day, because now we can name the companies who haven't turned on this basic option. [10:14.780 --> 10:25.360] And so, just in the last month or so, Comcast, Apple, Microsoft Outlook, Craigslist have all turned on TLS for their mail server-to-mail server connections. [10:25.680 --> 10:29.880] And they probably wouldn't have done this had Google not made this data set available. [10:29.880 --> 10:32.460] So this, again, has been really powerful. [10:32.700 --> 10:41.880] It's probably not really that much of a point to encrypt the connection between your computer and Google if Google is then going to send your emails plain text between Google and Yahoo or Google and Hotmail. [10:42.600 --> 10:46.000] And so naming and shaming has also been quite effective. [10:47.400 --> 10:56.100] I know that gamification is a pretty silly concept and is rightfully mocked by many people in the tech community, but it works. [10:56.100 --> 11:07.640] And one of the most interesting and useful examples here is the SSL Labs project by Qualys, where they give letter grades to server operators based on their SSL configuration. [11:07.980 --> 11:11.420] Are they using TLS, you know, 1.3? [11:11.580 --> 11:14.500] Are they using perfect forward secrecy? [11:14.640 --> 11:16.520] Are they protected against particular attacks? [11:17.020 --> 11:19.020] Do they have the right configuration options enabled? [11:19.260 --> 11:27.600] And I've seen server operators, like, continually tweaking their configuration until they get that A grade or, even better, the A-plus grade. [11:28.260 --> 11:29.040] This works. [11:29.300 --> 11:31.700] It doesn't cost any money to run this test. [11:31.880 --> 11:44.960] And if you administer a server or you work in an organization and you have contact to your IT department, I highly encourage you to go and check your own site against the SSL Labs testbed and see what your own letter grade is. [11:44.960 --> 11:57.300] And if you're not getting an A-plus, like my organization currently does not have, I encourage you to talk nicely to your IT department and offer them nice things until they agree to finally get you that A-plus score. [12:01.140 --> 12:22.040] So, when the Prism slide was first made public and Google's logo was up there, Apple's logo, Microsoft's logo was up there, these companies were in an NSA slide deck, essentially describing how they had been forced to collude with the government and surveil their customers. [12:22.260 --> 12:24.220] That looked really bad for those companies. [12:24.220 --> 12:33.420] And particularly when it came to their foreign markets and particularly in Europe, we've seen these companies first deny and then say, you know, we're in a tough situation. [12:34.460 --> 12:37.600] And then decide that they're going to start talking about surveillance. [12:37.980 --> 12:46.100] And they're in many ways talking about how they're making surveillance more difficult and they will push back against requests and they're going to fight where they can and file requests at the FISA court. [12:47.180 --> 12:50.060] But this is in many ways the exception rather than the norm. [12:50.860 --> 12:54.540] Typically, you won't find companies that want to talk about surveillance. [12:55.140 --> 12:59.020] You won't find companies that are going to talk about how they're making surveillance more difficult. [12:59.320 --> 13:05.900] You're definitely not going to see government officials, for the most part, talking about why surveillance is a bad thing. [13:06.320 --> 13:15.280] Even when we have progressive members of Congress who are on our side, at best we can hope that they will ask for a warrant. [13:15.560 --> 13:18.440] At best we can ask that they will hope for some kind of oversight. [13:18.640 --> 13:29.500] But it's very, very rare that you'll find a politician who will grandstand and say that there should be data that should be always off limits to law enforcement or always off limits to the intelligence community. [13:29.600 --> 13:36.580] It's very rare that you'll find a member of Congress who will say, you need to deploy this technology because the NSA should never get it. [13:36.580 --> 13:39.180] That will probably never happen. [13:39.520 --> 13:52.100] But there are many technologies that this community wants companies to deploy that, in fact, won't just raise the bar a little bit, but, in fact, raise the bar so high that data will, in many cases, be completely off limits to the state. [13:53.560 --> 14:12.540] And so if we want these technologies to be deployed, if we want Google to turn this on, end-to-end encryption on by default, or we want Dropbox to finally start using per-user keys that are not known to the company, then an anti-surveillance message is probably not going to be the thing that gets the company to do that. [14:12.620 --> 14:18.960] And we're definitely not going to get members of Congress to harass these companies to deploy technologies that will blind the NSA. [14:20.280 --> 14:22.780] And so for that reason, we need a different message. [14:22.880 --> 14:31.080] We need to be comfortable with spin, and we need to be comfortable using a message that, for far too long, we've left to our opponents. [14:31.520 --> 14:36.340] So this is Pamela Jones-Harbour, a former commissioner with the Federal Trade Commission. [14:36.740 --> 14:44.160] She was probably one of the leading voices of privacy when she was at the Commission until, I think, 2010, when she left. [14:44.460 --> 14:48.360] This is a speech she gave her last public speech, March of 2010. [14:48.780 --> 14:53.060] Today, I challenge all of the companies that are not yet using SSL by default. [14:53.060 --> 14:58.700] That includes email providers, social networking sites, and any website that transmits consumer data. [14:59.060 --> 15:01.120] Step up and protect consumers. [15:01.420 --> 15:03.120] Don't just do it some of the time. [15:03.380 --> 15:05.580] Make your websites secure by default. [15:06.740 --> 15:18.860] So I've looked really hard, and I think this is the first time any senior presidentially appointed U.S. government official even uttered the words SSL, let alone called for SSL by default. [15:19.080 --> 15:22.100] This was a very, very progressive speech. [15:22.100 --> 15:33.340] From an agency that doesn't typically use its soapbox, that hadn't previously used its soapbox to advocate for these kind of sweeping technical rollouts. [15:34.740 --> 15:41.220] Similar, Charles Schumer, the senator from New York, one of two senators from New York, a tough law and order senator. [15:41.680 --> 15:50.340] Just a few years ago, Schumer proposed a mandatory SIM card registration law because of the threat posed by anonymous burner phones. [15:50.900 --> 15:55.360] Schumer is about as tough on crime as they get. [15:55.980 --> 16:03.680] But just in 2011, Schumer wrote letters to Yahoo, Twitter, and Amazon calling on them to turn on SSL by default. [16:03.980 --> 16:12.760] He said, quote, So, providers of major websites have a responsibility to protect individuals who use their sites and submit private information. [16:12.980 --> 16:18.600] It's my hope that the major sites will immediately put in place secure HCPS web addresses. [16:19.580 --> 16:29.820] So, on one hand, you have these two government officials, senior government officials, calling on companies to deploy technology that will actually make bulk surveillance more difficult. [16:30.900 --> 16:31.980] Well, how does that happen? [16:32.100 --> 16:40.280] How do we get these people, these very powerful public officials to use their soapbox to push for the technologies that we want companies to deploy? [16:42.120 --> 16:46.500] Well, it turns out the threat that they were worried about was hackers. [16:47.100 --> 16:49.780] They weren't worried about the NSA, right? [16:49.900 --> 16:51.420] They weren't talking about the NSA. [16:51.420 --> 16:59.840] If you look in the full text of Commissioner Harbour's speech or Chuck Schumer, they were not talking about the Iranian government or the Chinese government. [17:00.100 --> 17:03.040] They were talking about hackers at Starbucks. [17:03.620 --> 17:12.860] They were talking about the widespread availability of tools that allow people to steal authentication cookies from open Wi-Fi networks and then log into each other's accounts. [17:13.580 --> 17:23.620] And in many ways, the thing that made this a front page issue was the availability of this tool, FireSheep, written by a security researcher named Eric Butler. [17:24.040 --> 17:33.720] And it was about two or three weeks after the New York Times wrote about FireSheep in 2011 that Chuck Schumer gave this speech on a Sunday afternoon and sent these letters out to a tech company. [17:34.160 --> 17:45.120] It was the threat of identity theft and petty crime stalking that led to these senior government officials calling for technology that we want companies to use. [17:45.540 --> 17:50.220] But technology that, for the last year, we have described as an anti-NSA technology. [17:50.800 --> 17:56.960] Now, we will never get Chuck Schumer to give a speech calling on tech companies to make things more difficult for the NSA. [17:57.560 --> 18:08.320] But we can get Chuck Schumer to give more speeches calling for technologies that make life more difficult for stalkers, for domestic abusers, for criminals, for petty thieves. [18:08.780 --> 18:13.680] And if those technologies happen to make life more difficult for the NSA, well, that's okay. [18:14.300 --> 18:21.560] But we cannot expect these politicians to call for technical controls that actually thwart the NSA's surveillance dragnet. [18:22.860 --> 18:28.180] In 2009, I wrote a public letter to Eric Schmidt, then the CEO of Google. [18:28.520 --> 18:33.780] The letter was co-signed by Bruce Schneier, by Ron Revest, the R in RSA. [18:34.060 --> 18:35.820] Thirty-seven security experts. [18:36.400 --> 18:40.680] We all wrote to Google and we said, you need to turn on SSL by default. [18:40.680 --> 18:43.440] This was about six months before Google eventually did it. [18:43.780 --> 18:47.440] And in that letter, again, we didn't use any language about the NSA. [18:47.440 --> 18:54.840] Even though, of course, many of us were thinking about the NSA, we used the language of identity theft and fraud and crime. [18:55.080 --> 19:01.080] We said, we strongly urge you to follow the lead of the financial industry and enable HTPS by default. [19:01.320 --> 19:08.980] Given the huge threat posed by identity theft, it is vital that Google take proactive steps to protect its users from these risks. [19:11.100 --> 19:16.960] So Google did eventually, actually relatively recently after that letter, turn on SSL. [19:17.260 --> 19:22.400] And when they did it, they did it the same day that they announced they'd been hacked by the Chinese government. [19:23.500 --> 19:30.540] And we can have a discussion about whether that was a very cynical move by Google and they were trying to show that they were doing something to stop the Chinese. [19:31.140 --> 19:45.080] But what's important to understand, again, is that when Google announced that they were turning this on, there was nothing in their marketing material, nothing in their blog post, about the NSA or the FBI or law enforcement or deep packet inspection by ISPs. [19:45.820 --> 19:49.100] It was timed with the announcement of the China hack. [19:49.380 --> 20:01.700] And so by framing things in the context of threats that U.S. government officials are worried about, we can make it much easier for companies to do the right thing in a way that we like. [20:02.660 --> 20:10.760] Okay, so in addition to that, we should remember, we have agencies at the federal level that are there to protect our privacy and our security online. [20:11.480 --> 20:14.860] The U.S. doesn't have a system as robust as Europe where you have... [20:14.860 --> 20:27.340] In many European countries and in Canada, you have a single privacy commissioner who at one day is giving a speech about Facebook and the next day is giving a speech about the intelligence community violating people's privacy rights. [20:27.340 --> 20:29.020] We don't have that in the United States. [20:29.420 --> 20:35.320] The two sort of biggest agencies we have are the Federal Trade Commission and the Federal Communications Commission. [20:35.800 --> 20:39.280] And the FTC's mandate doesn't extend to surveillance. [20:39.520 --> 20:42.220] It doesn't extend to the activities of government agencies. [20:42.220 --> 20:44.400] It extends to activities by companies. [20:44.620 --> 20:48.660] The FTC goes after Facebook for lying to you about how they protect your privacy. [20:48.800 --> 20:52.260] They go after, you know, TJ Maxx for losing credit card numbers. [20:52.260 --> 21:05.340] And so if we want the FTC to do things on our behalf, we need to sugarcoat it in a way that makes it palatable to them and allows them to make statements without making it seem like they are overstepping their authority. [21:05.740 --> 21:11.220] But by the same token, the Federal Communications Commission, they aid the surveillance state. [21:11.460 --> 21:17.500] They were the ones that were required by Congress to implement CALEA, a wiretapping law. [21:17.700 --> 21:21.280] They forced the carriers to build wiretapping features into their networks. [21:21.280 --> 21:27.820] And so if we make it difficult for them by asking them to do anti-surveillance actions, we're going to hit a brick wall. [21:28.000 --> 21:37.680] So we need to frame things in a way that are palatable to the two agencies that are most equipped and have the most power to do things to force companies to protect all of our data. [21:39.500 --> 21:41.560] Okay, so that brings me to cyber. [21:43.380 --> 21:47.100] I know that this term has a lot of baggage in this community. [21:48.760 --> 22:01.420] I know that for many people, cyber means a potentially embarrassing online conversation with someone whose gender and age may not actually be what they told you. [22:02.760 --> 22:12.880] And I know that there is this message in the community that people who say cyber and use it to mean Internet security are idiots. [22:14.100 --> 22:22.400] We have this idea that real experts talk about information security and idiots in DC talk about cyber. [22:22.640 --> 22:31.420] In the same way that we would like the word hacker to mean people who tinker, people who experiment, people who push boundaries in technology, not criminals. [22:32.740 --> 22:34.500] But that ship sailed a while ago. [22:35.560 --> 22:38.340] There is a cyber industry in DC. [22:41.580 --> 22:46.360] And they don't care about the fact that you think the word cyber is stupid. [22:46.680 --> 22:50.420] You may think that cyber means age, sex, location. [22:50.420 --> 22:52.560] But for the people that matter... [22:58.870 --> 23:02.710] For the people that matter, cyber means a massive threat. [23:03.270 --> 23:05.050] A threat that they don't understand. [23:05.590 --> 23:14.450] And a threat that requires massive resources, legislation, power, and compromise of core values. [23:15.250 --> 23:17.650] And we cannot change their minds. [23:18.470 --> 23:19.870] We can have that fight. [23:20.290 --> 23:24.490] We can stand there and try and convince them that cyber is a stupid word. [23:24.950 --> 23:27.670] Or we can focus on the actual core problem. [23:30.190 --> 23:32.370] Thank you for that one person who is a realist. [23:34.630 --> 23:42.230] So many of you may of course know James Clapper, who famously lied before Congress when describing what the NSA wasn't doing. [23:44.030 --> 23:46.430] Clapper gave a speech before Congress just a couple of years ago. [23:46.430 --> 23:47.990] 2013, last year. [23:48.330 --> 23:56.050] He said, when it comes to the distinct threat areas, our annual Intelligence Community Worldwide Threat Assessment this year leads with cyber. [23:56.270 --> 23:58.890] And it's hard to overemphasize its significance. [23:59.570 --> 24:05.470] In previous years, terrorism had been the number one threat that DNI identified as a threat to this country. [24:05.730 --> 24:10.870] In 2013, cyber was the number one threat that DNI identified. [24:11.150 --> 24:15.030] Again, we can have a debate about whether they know what they're talking about. [24:15.030 --> 24:17.290] We can have a debate about this word. [24:18.230 --> 24:20.590] But they've already put it at the front of the agenda. [24:20.870 --> 24:25.850] He added, these cyber threats put all sectors of our country at risk. [24:26.130 --> 24:28.990] From government and private networks to critical infrastructures. [24:29.950 --> 24:40.450] So when you have the top intelligence official in the country going before Congress and saying this cyber thing is a massive threat, members take note. [24:41.130 --> 24:54.070] When you have large defense contractors taking out subway advertisements in DC talking about zero days, the congressional staffers who ride the subway to work, they take note. [24:55.250 --> 25:01.090] And so, again, we can sit here from our ivory tower and say they don't know what they're talking about. [25:01.210 --> 25:02.490] They're not even using the right words. [25:02.970 --> 25:08.550] But members of Congress on a daily basis are hearing from people that they trust. [25:08.870 --> 25:13.150] People who have legitimate sounding resumes, who've worked in the government themselves. [25:13.750 --> 25:17.970] They're hearing from them that cyber is a massive threat and that they need to do something about it. [25:20.250 --> 25:24.710] Now, this is, of course, is Keith Alexander, until recently the director of the NSA. [25:25.410 --> 25:31.130] Those of us who are cynical, I think many people in this room are probably quite cynical, particularly after the last year. [25:31.390 --> 25:37.190] Those of us who are cynical might say, well, they're just hyping the cyber threat because they want to make lots of money. [25:38.290 --> 25:47.790] Keith Alexander famously, as soon as he left the government, started talking to financial firms and offering them cyber security consulting advice for a million dollars a month. [25:48.790 --> 25:52.570] And so we could say, look, these defense contractors, they want to get rich. [25:52.830 --> 25:56.930] Cyber security is the only part of the defense budget that's going up right now. [25:57.150 --> 26:03.030] These guys see an opportunity to make some money and they're ginning up the threat. [26:03.590 --> 26:06.230] They just want to make money. [26:06.690 --> 26:13.290] And the way they do that is by spreading fear, by going to Congress and saying that the sky is falling, that we're under attack. [26:14.490 --> 26:15.250] So what? [26:16.710 --> 26:27.010] Every day, a lobbyist is going to a member of Congress or a congressional staffer and telling them that there's a cyber security threat, that this is the biggest threat our country faces. [26:27.370 --> 26:40.850] Every day, congressional staff and members of Congress open up the newspaper and read stories about massive data breaches in which hundreds of millions of credit card numbers are stolen, confidential intellectual property, trade secrets, stuff is walking out the door. [26:41.730 --> 26:53.990] And if the response from our community, whether the technical side of the community or the civil liberties community, is to say that there is no cyber threat or that the cyber threat is overhyped, we won't be taken seriously. [26:54.510 --> 27:01.350] Because the fact is, there is a cyber threat, we just don't like the terminology that they're using and we question their motives. [27:02.250 --> 27:08.130] And so in many ways, this cyber stuff is like a train. [27:08.690 --> 27:13.370] It's a train that's moving really, really fast and there's a lot of weight behind it. [27:14.030 --> 27:16.990] And if we try and stand in front of it, we're going to get squished. [27:18.750 --> 27:23.790] But the thing is, we can sort of direct the direction of the train. [27:23.790 --> 27:27.390] And the reason for this is the people who are getting the briefing. [27:28.550 --> 27:31.630] This is Ted Stevens, the now deceased senator. [27:31.910 --> 27:39.670] And Ted Stevens very famously gave a speech in which he called the Internet a series of tubes and instantly became a global laughing stock. [27:40.370 --> 27:44.870] Now, I live in Washington and I go to Congress on occasion and I talk to staffers. [27:45.430 --> 27:53.210] And my guess as to what happened is that someone came in to give Ted Stevens a briefing and they described the Internet as a series of pipes. [27:54.390 --> 27:59.710] And then an hour later when he was talking to someone else or giving that speech, it sort of got flipped in his brain. [27:59.830 --> 28:02.950] And you can sort of see the connection between pipes and tubes. [28:03.330 --> 28:04.250] It's pretty close. [28:04.510 --> 28:09.690] And for a non-technologist, for a non-tech expert, grasping that concept is pretty impressive. [28:11.630 --> 28:12.930] And so here's how it works. [28:12.930 --> 28:19.470] You have these lobbyists, many of whom are former military or government officials who know nothing about technology. [28:19.790 --> 28:21.630] And they're now working for defense contractors. [28:22.410 --> 28:24.410] And they're going to Congress every day. [28:24.530 --> 28:27.870] They're going to the executive branch every day and talking about this cyber threat. [28:28.070 --> 28:37.150] And the people they're talking to are congressional staffers, most of whom are 25 years old with a political science degree, or members of Congress who don't have any technical background. [28:37.150 --> 28:38.830] And they're talking about the cyber threat. [28:38.970 --> 28:43.490] And so you have two people having a conversation, neither of whom actually understand the technology. [28:44.430 --> 28:56.850] And so what that means then is that a successful lobbying pitch by a ex-general now working for Booz Allen, or Raytheon, or Lockheed, is merely to leave the member with the impression that the cyber threat is big. [28:57.550 --> 29:03.170] And that maybe their company's tools and solutions are what they need to buy, or what we need to give money to. [29:03.390 --> 29:04.910] But they never get into the weeds. [29:04.910 --> 29:07.210] And so this is an opportunity for us. [29:07.450 --> 29:12.190] If we try and convince Congress that the cyber threat is not real, we will lose. [29:12.490 --> 29:20.090] If we say that the cyber threat is real, and the solutions that we want can solve the cyber threat, then we win. [29:21.010 --> 29:21.450] Right? [29:21.570 --> 29:26.950] There are many, many, many technologies that we would like that would in fact make it more difficult to steal credit card numbers. [29:27.110 --> 29:32.010] That would in fact make it more difficult for the Chinese government to steal proprietary information. [29:32.010 --> 29:39.530] But those technologies would also have the side effect of protecting our civil liberties and protecting our information from massive bulk dragnet surveillance. [29:41.050 --> 29:49.030] And so for far too long in Congress, there's been this decision that policymakers have been stuck with. [29:49.310 --> 29:54.870] They weigh on one hand civil liberties, and on the other hand, they weigh national security and public safety. [29:55.090 --> 29:59.550] They're told, you know, okay, we're going to allow wiretapping without a warrant. [29:59.810 --> 30:01.730] But on the other hand, we can stop this ticking bomb. [30:02.350 --> 30:08.570] And so all you need to do is just pass this legislation that gives these good people the authority to do what they need to do to keep us safe. [30:08.730 --> 30:13.810] And it's really difficult to go in and talk to a policy maker and tell them that that's a bad idea. [30:14.710 --> 30:20.130] Because if there's another attack, and they didn't sign onto that legislation, they're going to lose their next election. [30:21.250 --> 30:30.210] But if we tell them that the solutions that are being proposed by the FBI, the solutions that are being proposed by the NSA, would in fact make our network less secure. [30:30.610 --> 30:33.330] That would in fact make our network more vulnerable to attack. [30:33.630 --> 30:35.870] That retaining data is a target. [30:36.030 --> 30:40.210] The data retained for the intelligence community becomes an instant target for hackers. [30:40.510 --> 30:45.030] If we tell them that, then suddenly it becomes a debate of security versus security. [30:45.330 --> 30:49.930] Security from the local criminal against security from the cyber threat. [30:50.610 --> 30:52.730] And then suddenly the member is stuck. [30:52.930 --> 30:55.130] Because they know they want to keep this country safe. [30:55.390 --> 30:58.330] But they don't really know which threat is more serious. [30:58.650 --> 31:09.490] And that's a much better position to be arguing from than this sort of moral high ground of civil liberties that you know are going to be thrown under the bus the next time there's a terrorist attack. [31:10.710 --> 31:17.410] So for years, Bruce Schneier and others have been talking about the four horsemen of the information apocalypse. [31:18.210 --> 31:20.410] I'm sure some of you have heard of this. [31:22.630 --> 31:28.810] These are of course our drug dealers, terrorists, pedophiles and kidnappers. [31:29.630 --> 31:34.070] But there's a new horseman in this club that isn't yet in the picture. [31:34.510 --> 31:36.330] And his name is Ugly Gorilla. [31:40.610 --> 31:50.310] So the Chinese government has been demonized in Washington to the point that they are just as bad as terrorists and drug dealers and pedophiles. [31:51.310 --> 31:57.450] U.S. companies are not... are bullied into not buying equipment from Huawei or ZTE because of this threat. [31:58.930 --> 32:07.050] The U.S. government risks upsetting trade relations with the Chinese government in order to send a message about how upset it is about these cyber actions of the Chinese army. [32:07.990 --> 32:15.470] And so usually the people in the civil liberties community, the people that I work with, we are on the receiving end of the four horsemen. [32:15.890 --> 32:15.950] Right? [32:16.070 --> 32:20.530] So we are arguing in court about the importance of the Fourth Amendment and why the government should get a warrant. [32:20.970 --> 32:31.410] And on the government side, they're talking about how if the government has to get a warrant, this sexual predator might not get charged or we might not stop the next terrorist attack. [32:31.630 --> 32:40.190] And so usually those of us who care about civil liberties are defending ourselves from attacks, from accusations that we will aid the four horsemen. [32:40.330 --> 32:41.590] That we will aid the bad guys. [32:42.790 --> 32:50.270] This cyber thing actually gives us an opportunity to use one of the four horsemen, or now the five horsemen, for our side. [32:50.750 --> 32:51.050] Right? [32:51.130 --> 32:55.390] The things that the intelligence community wants actually make us more vulnerable. [32:55.670 --> 32:57.030] They make our systems weaker. [32:57.130 --> 32:58.310] They make our security worse. [32:58.750 --> 33:07.270] And that gives us a position of moral authority and technical authority from which we can really defend a lot more of what we care about. [33:08.470 --> 33:08.950] Okay. [33:09.110 --> 33:10.170] So what this means then? [33:10.530 --> 33:15.090] Tor is not an anonymizing service that hides you from the NSA. [33:15.610 --> 33:19.750] Tor is a cybersecurity technology that protects U.S. private information from foreign threats. [33:27.460 --> 33:32.220] Silent Circle and Red Phone, the two technologies that use the ZRTP protocol. [33:32.440 --> 33:40.550] These are not secure technologies that blind the NSA or wiretapping proof technologies that keep the FBI out. [33:40.790 --> 33:45.760] They are cybersecurity technologies that stop foreign governments from stealing U.S. secrets. [33:51.350 --> 34:02.370] The Whisper Systems Tech Secure app, which I hope all of you are using because it's finally the first easy to use encrypted instant messaging solution that I can actually get my family members to use. [34:03.370 --> 34:05.630] This is not a tool for terrorists or criminals. [34:05.830 --> 34:10.390] This is a cybersecurity solution and we should all be pushing cybersecurity solutions. [34:15.100 --> 34:15.660] All right. [34:15.900 --> 34:16.960] So repeat after me. [34:17.320 --> 34:19.200] Cyber, cyber, cyber. [34:19.860 --> 34:20.400] All right. [34:20.480 --> 34:21.080] You don't have to actually. [34:21.240 --> 34:22.860] But really, you get the idea, right? [34:23.300 --> 34:29.440] In the same way that Giuliani is 9-11, 9-11, 9-11, we should be cyber, cyber, cyber. [34:29.580 --> 34:35.520] To anything that we don't like that promotes more surveillance, the answer should be cyber. [34:35.700 --> 34:49.320] Because everything that the NSA has proposed to date on the Hill in Washington, D.C., whether it's information sharing, whether it's data retention, whether it's wiretapping back doors and communication networks, they're all bad for cybersecurity. [34:50.560 --> 34:53.760] But we haven't been pushing this message hard enough. [34:55.200 --> 34:57.500] And so we really need to go on the attack. [34:57.740 --> 35:04.380] The entire technical community, the civil liberties community, we need to develop an affirmative cybersecurity agenda. [35:04.780 --> 35:13.240] And what I mean by that is if you ask the public interest groups, if you ask technical organizations what they would like on privacy, they have a list of things. [35:13.380 --> 35:17.720] We want to pass legislation to require a warrant for email access. [35:17.800 --> 35:21.320] We want to require that the government post transparency reports. [35:21.380 --> 35:22.220] So we have a list of things. [35:22.340 --> 35:31.160] If you ask them what we would like on IP or on patents or on so many issues, we have a wish list of legislation of affirmative changes. [35:31.380 --> 35:36.660] But to date, if you ask us what we want on cybersecurity, it's please don't pass CISPA. [35:36.840 --> 35:39.360] We don't like the legislation that the NSA has proposed. [35:39.580 --> 35:47.100] And our community has done a really bad job to date of pushing back and calling for things that will actually improve cybersecurity. [35:47.460 --> 35:57.720] And so the problem with this is that if every day or every week you go up to Congress and you say we don't like what you proposed, and every week there's a new data breach, eventually you get ignored. [35:58.300 --> 36:04.260] Eventually they dismiss your concerns and they say the threats are too important, we need to do something. [36:04.620 --> 36:12.760] But if we go there every week and we say here's a problem and you're not fixing it and you're making systems less secure, then we at least bring something to the table. [36:12.860 --> 36:16.040] Then we have a place, a legitimate place at the table. [36:17.380 --> 36:25.280] And so there are things that we should be calling on that are so obvious, that are so indefensible, that we can really put the government on the defensive. [36:25.520 --> 36:31.180] So for example, 10% of U.S. government computers apparently are still running Windows XP. [36:31.560 --> 36:33.260] This is laughable. [36:33.460 --> 36:38.280] And this would actually lead to a significant and real improvement in cybersecurity. [36:38.600 --> 36:42.840] It's of course impossible to protect a 15 year old operating system from attacks. [36:42.920 --> 36:47.720] A 15 year old operating system that hasn't been hardened, that doesn't have any new defenses. [36:49.180 --> 36:52.340] This is something that we are slowly adopting at the ACLU. [36:52.480 --> 36:57.960] It's taking a little bit of time because as a civil liberties group we've never thought about things in this way. [36:58.360 --> 37:01.280] And my position didn't even exist until two years ago. [37:01.280 --> 37:06.080] So we now have two full-time technologists who are working on issues like this. [37:06.240 --> 37:15.080] And so last year we filed a complaint with the Federal Trade Commission, and we said that it was disgraceful that consumers are not getting regular security updates for their Android devices. [37:15.880 --> 37:19.620] People shouldn't have to wait six months or a year for a security fix. [37:19.740 --> 37:26.000] And if the carriers don't want to give people updates, they should get out of the way or let people out of their contracts so that they can get a secure device. [37:26.300 --> 37:34.120] And you know, you may not agree about this particular approach or this particular issue, but what's important is that we're now pushing an agenda. [37:34.300 --> 37:43.820] We have a list of things that we want the government to fix that will make us more secure, and that more importantly won't violate our civil liberties or require that we give up any of our privacy. [37:44.840 --> 37:50.520] And so cyber is this huge opportunity for us because all the technical knowledge is on our side. [37:51.100 --> 37:59.120] We understand this stuff way more than the folks on the Hill and the Intelligence Committee in the White House. [37:59.260 --> 38:01.200] There just aren't many technologists in the government. [38:01.920 --> 38:10.400] And so we really have this position of technical authority from which to push back and to tear apart all of their proposed cyber solutions. [38:10.720 --> 38:12.300] We haven't been doing this to date. [38:12.380 --> 38:18.300] And I really think this isn't something, pardon me, that the civil liberties community can do by itself. [38:18.480 --> 38:21.360] We need the input of the security community. [38:21.520 --> 38:28.040] We need the input of the hacker community because you all are far closer to where the action is. [38:28.140 --> 38:41.760] And you have ideas for really what things that will make a big difference while also not requiring major investments of resources or requiring that the government do significant things that they probably cannot do. [38:43.660 --> 38:45.260] So thank you very much for your time. [38:46.000 --> 38:48.260] I think I have about five or ten minutes for questions. [38:48.820 --> 38:51.180] And there's an ACLU table outside. [38:59.940 --> 39:02.240] So I don't know how the mic thing works here. [39:02.480 --> 39:03.240] Is there a mic? [39:03.400 --> 39:04.220] There's a mic over there. [39:04.360 --> 39:05.180] I can't see anything. [39:05.560 --> 39:11.820] So if you want to ask any questions or rant for preferably no longer than 20 seconds, please come up to the mic. [39:12.220 --> 39:15.560] Otherwise, you can find my contact information online. [39:15.980 --> 39:20.680] And we are always looking for suggestions for things that we should be working on that are sane. [39:21.800 --> 39:22.280] Hi. [39:22.680 --> 39:23.520] Can you hear me? [39:24.900 --> 39:25.400] Mike? [39:26.860 --> 39:27.680] Can you hear me? [39:27.980 --> 39:28.100] Yes. [39:28.740 --> 39:33.580] There used to be an office of technology assessment to advise Congress. [39:33.900 --> 39:37.780] Do you think that it's worth... I think it's been gone for a while. [39:38.420 --> 39:44.840] Do you think it's worth a community effort to try and advocate for its reinstatement? [39:45.480 --> 39:56.940] So what she's saying, there used to be an office of science and technology or something along those lines in Congress that provided non-biased technical advice to members of Congress, non-partisan, non-biased advice. [39:57.360 --> 40:01.300] And when Newt Gingrich came into Congress, he shut it down because he said it was a waste of money. [40:01.740 --> 40:08.400] So what it essentially means is that there are very, very few to no technical experts working in Congress. [40:08.640 --> 40:11.680] Most of the people there have political science degrees. [40:11.680 --> 40:13.300] They are not technically skilled. [40:13.540 --> 40:17.140] I think it would be a great idea if Congress hired technologists. [40:17.420 --> 40:20.580] I was the first technologist that the Federal Trade Commission ever hired. [40:20.700 --> 40:23.200] And then they hired several more, including some of my friends. [40:23.280 --> 40:29.940] And then they appointed a chief technologist, which is now a senior computer scientist on rotation through the agency. [40:30.140 --> 40:33.280] I think the more technical experts we get in D.C., the better. [40:34.240 --> 40:39.580] It's always a good idea if you can have people who know what they're doing advising policymakers. [40:39.880 --> 40:48.760] So that way when a lobbyist comes to them and says, this great idea will fix everything, they can say, well, actually, it's not that good of an idea after all, and it will break the Internet. [40:49.640 --> 40:50.220] Yes, ma'am. [40:50.460 --> 40:51.940] Chris, great presentation. [40:52.240 --> 40:53.040] Thank you so much. [40:53.040 --> 40:57.380] Isn't this really about protecting American intellectual property? [40:58.220 --> 41:06.320] And isn't that another thing that can help unite people, that we need to strengthen the security systems across the board? [41:07.320 --> 41:11.580] I'm not going to walk down the road of IP laws. [41:11.780 --> 41:18.180] I suspect that my opinions are probably not the same as many folks in Congress on IP issues. [41:18.180 --> 41:29.960] But I will say that given that we have a multi-billion dollar industry complaining about IP theft, if we can say that security technologies will protect IP from being stolen, let's go with that and use them to our advantage. [41:31.240 --> 41:34.600] So yay for three women asking questions right off the bat. [41:34.980 --> 41:37.720] But no, my question was, I think, well, it's not really a question. [41:37.820 --> 41:43.080] I just think that it's good to have messaging, and so I really appreciate that. [41:43.080 --> 41:45.300] And I also appreciate then supporting tools. [41:45.580 --> 41:49.600] But I feel like there's a missing piece and we have to go further. [41:50.360 --> 42:07.980] Because, you know, using tools and protecting ourselves, you know, citizenry of countries who are engaging in, you know, cyber warfare against one another, which is actually what's going on, I mean, it doesn't really protect us from, it doesn't really protect against DDoSing or, [42:08.000 --> 42:11.800] you know, pretty high level espionage or the zero days. [42:11.800 --> 42:14.780] Like, so these are problems that are going to always exist. [42:14.980 --> 42:17.020] And they're only escalating at this point. [42:17.220 --> 42:34.740] So I think just beyond saying, you know, making a case for, you know, using, or making the Internet infrastructure and end user tools more secure, we also have to be talking about including civil society voices in policy making in a multi-stakeholder model, [42:34.800 --> 42:39.540] which is what Internet governance is, but it's definitely not, you know, that's not how things are done. [42:41.220 --> 42:43.600] In military and or law enforcement, right? [42:43.780 --> 42:55.340] So I just want to say that I think it's a good starting point and to think more long-term as well about how the sort of larger and maybe more root problems can be solved. [42:56.380 --> 43:06.100] So I will agree and acknowledge that there's this strange disconnect between the problems that are identified by members of Congress and the solutions that they propose. [43:06.100 --> 43:16.320] So you will have, in the same statement, a member of Congress talk about identity theft and stolen credit cards and then talk about how their bill is really important to cybersecurity. [43:16.580 --> 43:31.540] But the information sharing legislation they're proposing, which essentially allows companies to share information with each other or with the government without fear of lawsuits, privacy lawsuits, that won't really do much to stop someone from breaking into your computer and taking your information. [43:31.540 --> 43:43.240] And so we do have policymakers sort of calling out identity theft as this threat, a threat they say that they care about, but then nothing that they're proposing really addresses that. [43:43.360 --> 43:47.960] And so that gives us an opportunity to say, well, hang on, we have solutions to this identity theft problem. [43:48.020 --> 43:54.600] We have solutions to this issue of 50 million credit card databases getting stolen, or databases with credit card information getting stolen. [43:54.860 --> 43:55.860] All right, my time is up. [43:55.960 --> 43:56.660] Thank you all very much. [43:56.720 --> 43:57.180] I appreciate it. [43:57.180 --> 43:58.100] Thank you.