[00:08.860 --> 00:09.480] We're good to go? [00:10.020 --> 00:10.560] All right. [00:11.340 --> 00:11.980] Testing one, two. [00:12.140 --> 00:12.660] Okay, cool. [00:12.740 --> 00:13.400] That sounds like it worked. [00:13.860 --> 00:14.520] Hi, everyone. [00:14.700 --> 00:16.940] Welcome to the XKEYSCORE talk. [00:17.680 --> 00:21.000] I'm introducing Rob Graham, who has done a lot of really interesting things. [00:21.120 --> 00:27.060] Two things he wanted me to mention were that he's done a lot of work with deep packet inspection, and you wrote the first IPS, you said? [00:27.280 --> 00:27.700] Is that correct? [00:27.840 --> 00:27.920] Yeah. [00:28.280 --> 00:29.800] So he's done a lot of work with this. [00:29.900 --> 00:41.420] And one of the things I want to emphasize, and this is not strictly related to hope, but just in general, most of the response to all the NSA revelations that I have seen have been mostly legal and policy things. [00:41.660 --> 00:45.600] And it is, like, really, really great to see somebody doing some technical analyses. [00:46.300 --> 00:50.520] So this is going to be really interesting for all those who are really interested in the technical juice. [00:50.640 --> 00:52.100] So with that, I'll hand it over to Rob. [00:52.220 --> 00:52.460] Thank you. [00:54.580 --> 01:01.200] By the way, if you're looking in your printed program, there was a different talk scheduled for this time, and that was canceled. [01:01.480 --> 01:04.540] So they had me come on to do an XKEYSCORE talk. [01:05.820 --> 01:10.760] So in case you're expecting one talk, this is going to be a completely different talk. [01:15.450 --> 01:21.730] What this talk is about is about recent XKEYSCORE code that has been released in the press. [01:25.460 --> 01:26.520] I'll be getting to that. [01:26.920 --> 01:27.400] Okay. [01:28.880 --> 01:30.780] So we're going to talk about that code. [01:31.380 --> 01:32.960] Well, I guess I can talk about it now. [01:33.460 --> 01:40.560] XKEYSCORE is sort of one of the biggest of the big brother programs in the NSA. [01:41.500 --> 01:52.420] It's... they've got sensors throughout the world, monitoring Internet traffic, and bringing all that data back to the Utah data center that we've seen in the news quite prominently. [01:53.600 --> 02:03.860] So when you're thinking about big brother NSA spying on me, outside of the context of phones and stuff, it's... a lot of it is related to this XKEYSCORE system. [02:05.500 --> 02:09.920] So code was released recently on... back in January. [02:09.920 --> 02:12.000] There was a code snippet released by the New York Times. [02:12.440 --> 02:14.720] They didn't mean to, but they did accidentally. [02:15.120 --> 02:22.940] They did the typical thing of putting a black box in a PDF over an image over the text, but the text is still there, so you just copy and paste and get the text. [02:24.160 --> 02:34.120] And then, just a few weeks ago, some more code, a lot of code, was released related to how this system is being used to spy on Tor. [02:36.420 --> 02:52.580] Who am I, as Aesthetic mentioned, is that I'm a long-time developer coder that's worked on deep packet inspection stuff, so technology that sniffs the Internet and then extracts interesting data from that data. [02:53.000 --> 03:02.540] Also on my GitHub account, I have DPI projects there, packet sniffing things that extract data from network traffic. [03:03.240 --> 03:08.840] You can use a spy on your home traffic and see what's there in a way similar to the NSA. [03:12.290 --> 03:14.570] So this talk is in four parts. [03:15.050 --> 03:18.150] The first part, I'm going to talk a lot about XKEYSCORE and the NSA. [03:18.430 --> 03:24.270] The second part, I'm going to talk about deep packet inspection technology and how that works, how they get data out of packets. [03:25.130 --> 03:27.870] Then we're going to look at the code itself and walk through that code. [03:28.810 --> 03:30.310] It shouldn't be too onerous. [03:30.430 --> 03:32.350] I mean, none of us read XKEYSCORE code. [03:32.350 --> 03:35.610] It's not a language that anyone knows outside of the NSA. [03:36.350 --> 03:40.550] And then on the fourth part, we're going to talk about the fun stuff of how we can jam that system. [03:44.660 --> 03:49.760] So this is the Verizon memo that started off the whole Snowden revelations. [03:49.820 --> 03:51.000] This is the first thing revealed. [03:51.260 --> 03:57.820] This is the Verizon memo that said we want all phone metadata, whether it's landlines or cell phones. [03:59.700 --> 04:00.820] I would have leaked this. [04:01.020 --> 04:03.420] Had I been in Snowden's position, I would have leaked this. [04:03.900 --> 04:07.400] And the reason I say this is because it marks me as sort of treasonous. [04:07.560 --> 04:12.840] It means that I can never get a clearance with the government ever again, admitting that I would have leaked this information. [04:13.520 --> 04:19.380] So who here also would like to mark themselves as treasonous and would have whistleblown this document? [04:21.700 --> 04:23.360] So none of you are getting clearance. [04:25.940 --> 04:29.080] The reason I bring that up is this next slide. [04:29.440 --> 04:33.080] A recent... a former NSA employee said this. [04:33.540 --> 04:37.460] People have unfairly demonized the NSA to a point that's too extreme. [04:37.860 --> 04:40.980] These are good people trying to do hard work for good reasons. [04:41.460 --> 04:43.400] How many people agree with this statement? [04:45.900 --> 04:48.120] Okay, leave your hand up if you know who said this. [04:50.060 --> 04:52.360] So this was said by Edward Snowden. [04:53.280 --> 04:59.500] About three weeks ago, he did an interview with the NBC, a TV station in the United States. [05:00.060 --> 05:01.280] And he said this. [05:02.160 --> 05:08.120] Because he's been on the inside of the NSA, he knows that they're not all evil people. [05:08.320 --> 05:11.380] That they are, in fact, good people doing good things for good reasons. [05:11.380 --> 05:14.560] That nuclear proliferation, terrorism, that sort of stuff. [05:16.080 --> 05:18.060] And it brings us up to see the counterpoint. [05:18.320 --> 05:24.180] Is that in the news, we have this impression of the NSA because we've only seen one side of the argument. [05:24.340 --> 05:31.200] Every new Snowden declaration gives one side of what the NSA is doing wrong. [05:31.600 --> 05:39.620] And we have... we've developed an impression that they're all powerful, they're all evil, they're all seeing that they can do anything. [05:39.620 --> 05:44.280] And in reality, as I go through this technology, they actually have a lot of limitations. [05:45.840 --> 05:52.040] So how we see them sort of informs us to how we need to interpret code and technology and things. [05:54.700 --> 05:56.800] One example of this is the word collection. [05:57.220 --> 06:01.720] So as that Verizon memo said, they're collecting all of the phone metadata. [06:02.400 --> 06:04.160] But in their viewpoint, they're not. [06:04.360 --> 06:07.600] The NSA has a very narrow definition of the word collection. [06:08.580 --> 06:13.200] When they gather the phone metadata and put it into a database, no one has access to that. [06:13.580 --> 06:19.600] And since no one has access to it without a FISA court order, they're not technically collecting the data. [06:19.980 --> 06:22.780] So in their minds, they're not spying on Americans. [06:22.980 --> 06:25.180] They're just putting data into a database. [06:26.960 --> 06:32.860] And that's a very interesting thing because when you talk to the NSA, they're not spying on Americans. [06:33.240 --> 06:37.500] No matter who you talk to at the NSA, they believe firmly they're not spying on Americans. [06:38.100 --> 06:45.660] But that's because they've gotten... they've sort of moved themselves into a corner of this perspective we're not spying on Americans. [06:45.660 --> 06:52.620] Even though as we've seen in the other Snowden revelations that they in fact are, depending upon how you define words like collection. [06:55.660 --> 06:58.160] One important concept is also tasking. [06:58.820 --> 07:04.560] A lot of our impression of the NSA is that they're just blanket spying on everything and gathering all the data. [07:05.300 --> 07:11.180] And in fact, while they're collecting data and putting it into databases, they're very rarely accessing it. [07:13.520 --> 07:23.320] NSA analysts have a very specific procedure they go through to go through that data, specify what they want, and then grasp it from the database. [07:23.540 --> 07:31.660] And it's all very bureaucratic and controlled and marked who the analyst is, who their target is, why they're getting data, and so on. [07:32.920 --> 07:34.420] And we don't see that bureaucracy. [07:34.420 --> 07:37.280] We just see this blanket thing of them getting everything. [07:38.420 --> 07:44.240] Along with this is efficiency, is analysts have an efficiency rating. [07:44.460 --> 07:45.860] They have to get results. [07:46.000 --> 07:49.020] They just can't rummage through data for years on end and get no results. [07:49.660 --> 07:52.820] They actually need to get specifically to a target. [07:53.020 --> 07:55.640] So we're afraid of them spying on us and rummaging around. [07:56.000 --> 07:59.200] Actually, they don't want to rummage around because they're getting no results. [07:59.320 --> 08:04.640] There was a story about how the team after Osama Bin Laden was reduced to four people. [08:04.640 --> 08:10.520] Because everyone who got on that team got no results for years and had their careers ruined, basically, by that search. [08:11.500 --> 08:20.140] So even the people who did find Osama Bin Laden in the end, they still had to leave the NSA, because their efficiency ratings could never be improved, because they only found one guy after years of work. [08:21.420 --> 08:30.360] This picture here is from the THX-1138 movie, where they eventually give up on getting going after the hero of the movie, because they're just over budget. [08:30.640 --> 08:33.100] And that's really a lot of what happens at the NSA. [08:35.300 --> 08:38.660] We have this fear that the NSA is a bunch of people, very smart people. [08:39.160 --> 08:45.520] In reality, they're successful because they've got money, they can solve things with this brute force, and they've got access. [08:45.800 --> 08:52.000] They can put network sensors grabbing data in the oddest places in the world, like on the bottom of the ocean floor. [08:52.120 --> 08:53.240] They've got their own submarine. [08:53.240 --> 08:58.680] They can drop to the bottom of the ocean floor and just put taps on subatlantic cables. [08:59.540 --> 09:02.260] Where they get their smarts, by the way, is from us. [09:02.660 --> 09:08.740] When we give presentations at Black Hat on some new technique, they start using it. [09:09.040 --> 09:11.480] So we're actually the source of most of their smarts. [09:13.760 --> 09:18.520] An example of this is this recent revelation from the GCHQ, the British spies. [09:20.680 --> 09:25.820] One of the things they have here is Changeling, which allows them to spoof email sender addresses. [09:26.480 --> 09:29.520] How many people here have spoofed an email sender address? [09:32.620 --> 09:34.500] So yeah, that's not very smart. [09:35.140 --> 09:37.520] They also have another one where they do SSH through Tor. [09:37.740 --> 09:39.340] How many people have SSH through Tor? [09:40.460 --> 09:41.740] Fewer, but many of us. [09:43.180 --> 09:45.920] So a lot of what they're doing is not smart. [09:48.660 --> 09:52.840] There's one program that was recently announced called Boundless Informant. [09:52.960 --> 09:57.600] And all this program does is it monitors all the other programs to see how much data they're collecting. [10:00.380 --> 10:06.500] One interesting piece of information from this was 97 billion records per month. [10:06.500 --> 10:11.180] This was like March of 2013, they had 97 billion records. [10:11.720 --> 10:18.060] The top one is DNI, which means Direct Network Interface, which means reading from Internet links. [10:18.380 --> 10:21.320] The second one was the phone records. [10:21.840 --> 10:24.120] The dialed number, whatever it stands for. [10:26.040 --> 10:28.700] So 97 billion records per month. [10:30.620 --> 10:37.180] And where they're spying is also on this graph, which is kind of cool, because we know that most of their attention is in the Mideast. [10:37.760 --> 10:43.000] You know, Iraq, Iran, Afghanistan, Pakistan, where their targets are. [10:43.100 --> 10:52.080] They're not really, you know, for all that we're afraid that they're targeting Americans, in reality we see where the sources of information are primarily where we expect them to be. [10:52.560 --> 10:53.720] Why green land? [10:54.820 --> 10:55.520] Pardon me? [10:56.200 --> 10:57.320] Why green land? [10:58.160 --> 10:59.960] Well, green means very little data. [11:01.960 --> 11:03.580] In this case, probably zero. [11:04.500 --> 11:06.580] I can't imagine there's much threat from green land. [11:06.720 --> 11:07.560] So dark? [11:10.360 --> 11:12.020] Dark green means very little sources. [11:12.220 --> 11:13.600] Lighter green means more data. [11:14.240 --> 11:15.760] Yellow means even more data. [11:16.240 --> 11:19.360] And then orange and red means lots and lots of data. [11:24.450 --> 11:25.210] Also that. [11:25.450 --> 11:29.270] So, for example, Libya, as you say, has, is fairly green. [11:29.890 --> 11:31.690] But it's someplace we do want to monitor. [11:31.930 --> 11:34.230] And that's probably just because there's just not a lot of Internet in Libya. [11:36.650 --> 11:38.370] Also, by the way, it's kind of strange. [11:39.210 --> 11:40.950] They do a lot of satellite tapping. [11:41.170 --> 11:47.810] So the Internet that is in Libya actually goes through, like, the United Arab Emirates, instead of Libya, because it goes up to a satellite and down. [11:47.970 --> 11:51.670] So where they're getting it is not actually from Libya, but it's Libyan traffic. [11:54.030 --> 11:57.610] So here's one of the slides released by Edward Snowden. [11:57.610 --> 12:02.350] And XKEYSCORE really is a user interface thing. [12:02.610 --> 12:10.350] Edward Snowden was at the top level sort of the user of the system rather than one of the low-level guys actually on a network link capturing the data. [12:11.230 --> 12:20.330] So XKEYSCORE, the way it works is it gathers, it puts link, packet sniffers on network links to grab data. [12:21.430 --> 12:23.950] And at the low-level here, we see three kinds. [12:24.370 --> 12:26.810] On the right, we see SSO site. [12:28.510 --> 12:30.170] That's Special Sources Operations. [12:30.170 --> 12:31.050] I don't know what it stands for. [12:31.270 --> 12:36.810] It means other partnerships, like the GCHQ or corporate partnerships, like with AT&T. [12:37.170 --> 12:38.290] That's where they get the data. [12:38.910 --> 12:41.350] The foreign sat means satellite. [12:41.670 --> 12:51.690] That's where they've got things watching satellite links, which is a big deal because in a lot of parts of the world where there's no infrastructure, satellites is how they get communications. [12:53.630 --> 13:00.210] If there's a chief of a village, he's got a satellite receiver doing satellite Internet that does Internet for the entire village. [13:01.530 --> 13:06.390] And this F6 HQS, that's where they get like a special forces team. [13:06.570 --> 13:10.690] They go into the desert, find a fiber optic link, and stick a monitor on it. [13:11.130 --> 13:15.310] So that's where all the evil monitoring that they don't want to get caught. [13:15.310 --> 13:19.290] If they get caught, that's because something bad's happened. [13:24.160 --> 13:27.480] So this slide is a slide about Google Maps, about them getting data. [13:27.540 --> 13:34.180] But the key part of the slide is where I've got this arrow that a lot of these sensors, they stick out in the world to monitor traffic. [13:34.180 --> 13:37.320] They gather too much traffic that they can't pull back to their headquarters. [13:38.560 --> 13:46.500] So a lot of this whole XKEYSCORE system is about filtering data at the point of collection, rather than pulling it all back to the database. [13:49.600 --> 13:54.060] So now I'm going to talk about deep packet inspection, because that's the technology they're using to monitor the Internet. [13:55.920 --> 13:58.140] All it is, is just tapping into network traffic. [13:58.140 --> 14:02.640] This is, I don't know if you guys have seen this before, the, it's the throwing star, land tap. [14:03.480 --> 14:09.400] And it, you plug it into a, to a wire, and then plug in two more wires to then sniff everything going to and from. [14:09.780 --> 14:12.220] And it's a great debugging tool for your, for your home network. [14:12.560 --> 14:16.500] It costs like 10 bucks at hacker stores. [14:17.260 --> 14:18.800] And that's essentially what the NSA is doing. [14:18.920 --> 14:20.660] They got a, they got a wire, they've got a hub. [14:20.980 --> 14:23.780] They just hook in there and say, give me a, give me a copy of all the traffic. [14:26.440 --> 14:28.080] So this is what packets look like. [14:28.240 --> 14:29.200] This is a real packet. [14:29.560 --> 14:32.800] It looks kind of like random data as far as we can see looking at it. [14:34.820 --> 14:35.840] But it's like the matrix. [14:36.360 --> 14:41.360] So in the, in the, in the, in the matrix we had, um, Cypher saying, hey, I don't see code here. [14:41.460 --> 14:44.240] What I see is, that's a red head, that's a blonde, and so on. [14:45.460 --> 14:51.300] And so we look at this packet and all of these data, all these pieces of data in here mean something. [14:51.840 --> 14:54.940] Um, for example, I've pulled out the IP address and the port number. [14:55.200 --> 15:01.300] So it's like HTTPS colon slash slash 74.125196128.443. [15:01.560 --> 15:03.020] So that's what this packet is. [15:03.100 --> 15:06.480] It's this packet, um, an SSL packet. [15:08.920 --> 15:10.400] I don't know how well you can read that. [15:10.660 --> 15:14.520] So we can take that entire packet and pull it apart field by field. [15:14.780 --> 15:19.300] What this packet was, was when the SSL server sends you the certificate. [15:20.660 --> 15:23.860] And every field in that packet means something. [15:24.020 --> 15:26.280] Every byte in that packet can be pulled apart. [15:26.500 --> 15:29.320] What we see here is a picture of a program called Wireshark. [15:29.620 --> 15:33.220] And it's what network technicians use to diagnose network errors. [15:33.700 --> 15:40.100] Um, they stick it on the wire, tap into the network, capture the packets, and then decode the packets and analyze them. [15:40.440 --> 15:47.700] And what the decoder does, it means saying for every byte here on the, the right hand side, we're going to say what, what it means on the left hand side. [15:48.000 --> 15:51.680] Because really, we, we like to think we can read the hex, but we really can't. [15:51.720 --> 15:52.840] We just use decoders like this. [15:54.360 --> 15:57.800] But what this also is, is a deep packet inspection tool. [15:59.540 --> 16:01.740] Oh, by the way, I want to mention something about Wireshark. [16:02.140 --> 16:03.900] So, all these bytes have meanings. [16:04.060 --> 16:09.060] I can tell Wireshark to take this SSL traffic and try to decode it as HTTP instead. [16:09.580 --> 16:10.920] And this is the result we get. [16:11.100 --> 16:11.480] It's an error. [16:11.720 --> 16:15.080] It can't decode it because of the, the data suddenly becomes meaningless. [16:15.680 --> 16:19.040] And then what I, I use this to highlight that the, the data has meaning. [16:19.200 --> 16:22.880] It looks like gibberish to us, but it actually all has, it all means something. [16:26.120 --> 16:29.540] So, what XKEYSCORE works is, um, it's like TCP dump. [16:29.900 --> 16:38.880] TCP dump has this ring buffer mode where you set aside, say, hey, hey, I want to, to do a hundred files and each of a gigabyte in size, and just keep capturing into that buffer. [16:38.880 --> 16:42.260] When you run to the end, just start writing at the start, at the beginning again. [16:42.580 --> 16:45.260] So, all you have is a hundred files that are one gigabyte each. [16:46.800 --> 16:49.340] And that's mostly what XKEYSCORE is doing. [16:49.520 --> 17:03.840] They've got sniffers throughout the world, on satellite links, on undersea cable links, in an Iraqi phone data center, uh, capturing, just on a server, just this nice little three days worth of data that just constantly always the last three days. [17:05.260 --> 17:10.260] And then what they do is they take all the deep packet inspection tools they have, and they use a lot of them. [17:10.480 --> 17:11.640] I've heard over a hundred. [17:13.220 --> 17:15.260] And they run them on this data. [17:15.840 --> 17:17.280] It could be Wireshark. [17:17.560 --> 17:20.060] Wireshark has a command line tool called T-Shark, which is really cool. [17:20.160 --> 17:20.780] I want to get into that. [17:21.380 --> 17:25.900] Uh, an IDS, intrusion detection system like Snorp, can be used to post-process the data. [17:25.900 --> 17:28.260] They use commercial products like NetWitness. [17:28.820 --> 17:32.020] NetWitness is a really cool tool for extracting files and stuff. [17:32.680 --> 17:39.420] Once they get the files, they're gonna run those files, like images they downloaded via the web, or sent via iPhone. [17:39.980 --> 17:45.900] They run those files through various parsers, like email parsers, and image parsers, PDF parsers. [17:46.460 --> 17:49.620] Um, and then grab as much data out of them as they can. [17:50.820 --> 17:56.460] And what they're looking for is not the content so much as, as we've seen in the stone revelations, but metadata. [17:56.920 --> 18:01.520] Like for image parsers, they want the, uh, the GPS locations that might be attached to an image. [18:03.980 --> 18:08.100] So, as an example here, I was gonna use Snort, because that's an intrusion detection system. [18:08.380 --> 18:10.660] That's, in which you run live and very similar to this. [18:11.060 --> 18:13.040] But I thought actually I'd focus on T-Shark. [18:13.180 --> 18:15.680] T-Shark is just a command line version of Wireshark. [18:15.760 --> 18:18.380] So what you saw in that GUI, it does in the command line. [18:18.960 --> 18:28.600] And what you can do in T-Shark is say, hey, pull out all the packets in this, you know, terabyte worth of data that satisfy one or more of these fields. [18:28.780 --> 18:36.760] So I can say, pull out all the packets where there's an X.509 certificate with the UTF-8 string of splat.google.com. [18:36.900 --> 18:38.240] And it'll pull out those packets. [18:40.000 --> 18:45.300] Uh, and T-Shark is great because it's got tens of thousands of these fields just like this. [18:45.300 --> 18:49.360] So that the listing of the fields that you can choose is tens of thousands. [18:49.600 --> 18:52.000] Because they decode every protocol under the sun. [18:52.080 --> 18:52.920] They decode everything. [18:53.140 --> 18:57.860] They're the most comprehensive deep packet inspection tool there is. [18:58.340 --> 18:59.540] Unfortunately, they're kind of slow. [18:59.660 --> 19:01.420] So you wouldn't actually attach this to a live network. [19:01.600 --> 19:04.460] But post-processing, interesting data, it runs pretty well. [19:05.780 --> 19:17.500] I mention this because people have this idea that, oh, we shouldn't release too much of the XKEYSCORE source code because it'll help other countries like, um, do spying on their own people. [19:17.620 --> 19:21.820] And it's too powerful of a code, too smart of a code to be released to the public. [19:22.120 --> 19:26.100] And in reality, whatever XKEYSCORe is doing is less than T-Shark. [19:27.520 --> 19:31.740] They might have faster tools and stuff like that, but it's less than T-Shark. [19:36.860 --> 19:44.980] So, yeah, just to reiterate, they have full capture systems like TCP dump grabbing all the data, three days, the last three days worth in the round robin. [19:45.360 --> 19:48.940] They extract data from it, metadata files and that sort of thing. [19:49.960 --> 19:53.600] And then they pass the metadata up to their major databases. [19:54.420 --> 20:13.160] What we saw in that previous slide is that when an analyst needs to get some of that data, like they've targeted someone, it passes that string on down, go back here, and says something like, hey, I'm looking for a certain name, so every email target passes a little command like this and says, [20:13.160 --> 20:14.080] go grab that data. [20:14.260 --> 20:19.320] And then it'll go post-process that three days worth of data, go grab all those emails and send them back to the analyst. [20:19.980 --> 20:24.460] But mostly all the traffic remains on the sensor and then just drops off after three days. [20:32.010 --> 20:35.810] There's also not just the analyst to grab this data, but also automated systems. [20:35.970 --> 20:42.010] It starts from an analyst setting a tasking to say, hey, I've got this automated system that's going to do these steps. [20:42.310 --> 20:48.430] Like, wait for that guy to log on and then try to send him a hostile PDF exploit. [20:49.610 --> 20:52.510] And that's where the TAO attacks come from. [20:55.460 --> 20:57.600] Okay, so let's look at the source code. [20:59.360 --> 21:06.580] This is the source code that was released on January of this year inadvertently by the New York Times. [21:06.900 --> 21:09.800] There's a lot of chunks here, so I'm going to sort of pare it down to the essentials. [21:11.140 --> 21:14.780] So at its essential, what it's doing is it's saying, I've got a fingerprint. [21:15.180 --> 21:16.080] I've got a file. [21:16.220 --> 21:17.800] I don't know what's in the file yet. [21:18.880 --> 21:25.000] But I'm going to test that file extension, just like the t-shark expressions work, whether it has JPEG on the end. [21:25.000 --> 21:27.960] And if it does, I'm going to add the metadata to the file. [21:28.020 --> 21:30.120] And in this, my little example here is saying picture. [21:32.280 --> 21:42.580] So that when an analyst needs to task the system and say, hey, show me all pictures that were taken from a rack, they've got this metadata that can satisfy the query. [21:46.490 --> 21:48.630] Now, this thing was a little bit more complicated. [21:48.790 --> 21:53.790] What it wanted to market was not simply as an image, but an image that has GPS locations in it. [21:53.790 --> 21:56.310] So therefore, the expression grows. [21:56.630 --> 22:03.430] So not only trigger when it has a JPEG file extension, but also when it has this EXIF information. [22:03.790 --> 22:05.690] The EXIF information is what's attached. [22:05.790 --> 22:10.810] Every time you snap a picture with your iPhone, it attaches your GPS latitude and longitude to it. [22:11.150 --> 22:13.030] And it's a feature that JPEGs have. [22:13.430 --> 22:15.850] And by the way, it's not a feature that GIFs have. [22:15.850 --> 22:19.870] So you see in this thing where they've added GIF as a file extension, it doesn't work. [22:20.230 --> 22:21.870] There's no... it'll never happen. [22:22.930 --> 22:26.630] So it's one thing we find with this XKEYSCORE code is there's lots of bugs in it. [22:28.030 --> 22:32.990] Bugs that don't stop it from working, but which we can just say, hey, you can take that GIF out, and it'll make no difference. [22:33.650 --> 22:34.170] Good question. [22:34.310 --> 22:36.490] Does that go by extension or by file signature? [22:37.370 --> 22:38.290] That's a good question. [22:39.610 --> 22:42.310] So there's three ways we can recognize what a file contains. [22:42.470 --> 22:44.730] By its extension in the file name, like .JPEG. [22:44.950 --> 22:49.770] The content type, when it's downloaded, the HTTP has a content type associated with it. [22:50.330 --> 22:55.550] Or by looking at the first few characters of the file name, it says, well, it can only be a JPEG. [22:55.610 --> 22:56.630] Or it can only be a GIF. [22:58.110 --> 23:02.010] And this code says file extension, which is the worst and stupidest way to do it. [23:02.570 --> 23:16.510] Which means either they really are that stupid and they're just doing file extension, or they've got some other thing in the pipeline before this that marked the files that, hey, it was downloaded via a content type of JPEG, so we're going to put a file extension JPEG on it, [23:16.630 --> 23:19.390] so that later things can trigger off of a file extension. [23:21.650 --> 23:22.810] So, I don't know. [23:27.050 --> 23:34.810] One thing to notice about this is that there's also another bug here, is it says the first condition and the second condition or the third condition. [23:35.850 --> 23:38.210] And people laugh because they know that's a bug. [23:39.930 --> 23:44.250] Because most languages would interpret it and it has a better precedence here. [23:44.510 --> 23:50.610] So, it says either it has latitude and file extension JPEG or it has longitude. [23:51.150 --> 23:53.730] It's how most programming languages interpret this. [23:55.350 --> 24:01.770] But that probably doesn't matter because it's not going to have that property of GPS longitude if it's not a JPEG in the first place. [24:02.210 --> 24:05.710] So, we could probably just take the whole test of whether it's a JPEG out of it to begin with. [24:10.250 --> 24:10.570] Yeah. [24:11.830 --> 24:16.470] And that's the thing is we look at this and like this is like one signature that was inadvertently done by the New York Times. [24:16.630 --> 24:21.110] And we found, we have questions about, okay, the operator precedence is wrong. [24:21.450 --> 24:23.010] They're using GIF files here. [24:24.150 --> 24:26.530] It looks like they're doing the lamest thing of just the file extension. [24:26.530 --> 24:29.150] So, we've got three problems with only one signature. [24:32.210 --> 24:32.690] Okay. [24:32.850 --> 24:34.050] Don't you think it was really? [24:39.190 --> 24:40.270] That's one theory. [24:42.730 --> 24:45.910] Yes, Snowden really is just, you know, he's a plant. [24:46.170 --> 24:47.470] Just to convince us of that. [24:50.550 --> 25:00.390] No, but it actually is true that the stuff that they put in these documents, in these stone documents, most of these documents were the presentations for the intelligence community. [25:00.390 --> 25:03.090] So, they're not putting in their smartest code. [25:03.310 --> 25:07.750] They're often in these presentations putting in examples or samples and not real code. [25:07.950 --> 25:13.290] So, there could be reasons why it's dumb code that may not, maybe the code they put actually out in the real world might be smarter. [25:18.110 --> 25:29.250] So, a couple weeks ago there was a story in a German radio website that talked about how they showed all the source code targeting Tor. [25:30.790 --> 25:34.670] And so, here's one of the first things that we're saying, hey, we want to mark this. [25:34.950 --> 25:37.950] Again, this fingerprint thing is just extracting metadata. [25:38.410 --> 25:40.130] We actually don't know where that goes. [25:40.370 --> 25:45.130] Does it go to an automatic targeting system that tries to automatically hack anyone who uses Tor? [25:45.550 --> 25:50.730] Or is there an analyst out there who's specifically at this moment looking for Tor and that's why this exists? [25:50.730 --> 25:57.210] Or is it Tor and other conditions we can't see in this source code, which happens in the whole process? [25:57.510 --> 26:01.030] Like, I want all access to Tor from Libya. [26:01.350 --> 26:02.470] Maybe that's his query. [26:03.330 --> 26:05.270] So, we don't see the whole picture here. [26:07.350 --> 26:11.850] Also, what we see is that in this code that was released, there's lots of missing pieces. [26:11.850 --> 26:16.490] We see this variable name Tor authority that's nowhere defined in the code. [26:16.910 --> 26:18.950] So, we don't know where the Tor authority is. [26:19.030 --> 26:24.710] We know in practice which servers they're talking about, but we don't know how they've defined that variable. [26:26.090 --> 26:34.470] So, again, the purpose of this is just to say, hey, we need to mark all TCP sessions that go to and from Tor node authority. [26:34.470 --> 26:37.530] And I'm going to mark it with this metadata so I can then query on it later. [26:43.410 --> 26:47.030] Another signature was this one, is they want to find all the Tor bridges. [26:48.970 --> 26:52.410] And this one worked by decoding the SSL certificate. [26:53.090 --> 27:00.050] And what we see here is it's looking for the X.509 subject name, the DNS names within certificates, SSL certificates. [27:00.210 --> 27:03.510] So, as soon as you connect to an SSL server, you see the certificate. [27:05.070 --> 27:11.070] And I mention this because it's very similar to the T-Shark signatures I showed you before, where T-Shark can pull all this information out. [27:12.010 --> 27:15.950] So, in fact, they may be using T-Shark as the underlying thing that services this. [27:16.690 --> 27:20.830] That they just send these, wrap them up in the T-Shark signatures, and then that's how it's done. [27:23.930 --> 27:28.670] They had a more complicated signature, and so this is sort of the outer portion of that signature. [27:29.330 --> 27:33.150] Where it looks for emails. [27:33.770 --> 27:35.330] One of the ways you can get Tor bridges... [27:35.330 --> 27:37.210] Oh, by the way, let me talk about what Tor bridges are. [27:37.950 --> 27:41.470] We have all the public Tor servers out there, the Tor nodes out there. [27:41.910 --> 27:43.890] But those are all banned a lot in countries. [27:44.130 --> 27:48.710] So, in Great Firewall, China and stuff just has that list in there of all the public servers and bans them or something. [27:49.230 --> 27:54.870] So, if you're an activist or a dissident in one of these countries, you want a secret server. [27:54.990 --> 27:59.810] A server that is a Tor node, but which is not generally known to the public as being a Tor node. [28:00.410 --> 28:05.570] So, you go to this bridges at torproject.org and they'll send you an email that says what those bridges... [28:05.570 --> 28:10.730] They'll give you five bridges that you can use that are not known to the public. [28:11.050 --> 28:13.830] And everyone who sends them an email gets a different list of five bridges. [28:14.770 --> 28:21.230] So, what this signature is looking for is I want to scan all the emails that I'm getting on my... collecting on my data. [28:21.510 --> 28:29.530] And I want to scan them and grab all those lists so that me as the intelligence operator can get my own list of all the public Tor bridges. [28:31.250 --> 28:33.210] And so, that's what this fingerprint starts with. [28:33.450 --> 28:39.490] It says, okay, the email address from bridges.torproject.org and somewhere in the email body is the string Tor bridges. [28:40.490 --> 28:44.410] And then, that we see here, it's going to shell out to C++ code. [28:44.830 --> 28:47.890] Which means whatever system is running, it's now going to run some C++. [28:49.770 --> 28:53.930] And what's in that C++ code is... I'm missing something here. [29:00.560 --> 29:03.480] Okay, I'm missing something, so I'm going to go out here to... [29:21.410 --> 29:24.550] Okay, what we see here is the regular expression. [29:24.550 --> 29:27.630] So, it takes an email message and runs what's called a regular expression. [29:28.170 --> 29:29.650] And that's this bit right here. [29:31.590 --> 29:36.790] And that's just matching that string of bridges, space, IP address, colon, port number. [29:37.370 --> 29:39.930] And that's all of this complicated regex is doing. [29:41.230 --> 29:43.970] I'm going to talk more about this regex in a bit, but... [29:44.690 --> 29:46.790] So, I just want to make sure you see the regex. [29:50.960 --> 29:54.980] So, that regex then causes C code to be executed. [29:54.980 --> 29:56.740] That regex has these things called captures. [29:56.940 --> 30:01.040] That when you put a parenthesis in a regular expression, to grab everything between that, the parenthesis. [30:01.820 --> 30:03.200] So, it grabs an IP and a port number. [30:04.060 --> 30:10.200] And what we see here in this code is that it takes that data and sticks it directly into a database. [30:10.780 --> 30:13.980] So, until this point, we've been using APIs. [30:15.240 --> 30:20.360] That fingerprinting, like fingerprinting an email, causes metadata to be attached to that email. [30:20.500 --> 30:22.780] So, that email can then be queried and pulled up by an analyst. [30:23.380 --> 30:28.700] And there's all... but there's always the source and destination of where the email came from, who that email is from and to. [30:29.100 --> 30:33.280] All that information was included with all that metadata and it wasn't lost. [30:33.360 --> 30:39.240] So, that if later an auditor comes in and says, what is that email you captured in American Citizen? [30:39.620 --> 30:42.480] They've got the full trail of where that email came from. [30:42.580 --> 30:43.480] They know where it was captured. [30:43.620 --> 30:44.520] They're like, okay, this was an interact. [30:44.880 --> 30:45.700] It was sent to this guy. [30:45.840 --> 30:47.020] It was sent from that guy and so on. [30:48.000 --> 30:56.560] But what we see here in this C++ code is they're extracting data, putting it into a database, losing all of that context. [30:57.720 --> 31:00.960] So, later on, if someone says, where did you get that bridge information? [31:01.440 --> 31:02.120] They don't know. [31:02.220 --> 31:03.660] We got it from monitoring the network. [31:03.760 --> 31:06.600] We don't know where it came from or whose emails we monitored. [31:06.800 --> 31:08.340] Was it an American Citizen or not? [31:08.400 --> 31:08.820] We don't know. [31:10.340 --> 31:12.820] So, this is one of two things. [31:13.200 --> 31:15.900] When I saw this in the source code, I had one of two thoughts. [31:16.120 --> 31:21.000] The first thought is, A, potentially, the NSA is breaking the law here. [31:21.260 --> 31:30.500] That it's something so technical that no FISA court auditor will ever notice that they're actually breaking the law and getting data without knowing who it came from. [31:33.280 --> 31:37.220] Or, maybe the source code that they got is not an NSA source code at all. [31:37.220 --> 31:39.620] As I said before, the NSA works with partners. [31:39.920 --> 31:44.080] Their biggest partner is the GCHQ, the British spies. [31:44.780 --> 31:49.740] Well, they don't have quite the requirements we have for monitoring their own citizens. [31:49.920 --> 31:54.280] They don't have quite the whole infrastructure for knowing where data came from. [31:54.680 --> 32:04.380] So, those guys have the ability to do a signature like this and send it down to their systems that they control of just grabbing data and saving it and not knowing who it came from. [32:06.120 --> 32:13.380] So, either the NSA is breaking the law or the American law or it's one of the partner systems. [32:13.580 --> 32:14.100] Is that a question? [32:22.660 --> 32:23.020] Right. [32:23.260 --> 32:25.380] That may be a product that they give to the NSA. [32:25.480 --> 32:26.880] The NSA just says, hands off. [32:26.960 --> 32:27.880] We don't know where the data came from. [32:27.940 --> 32:28.400] We don't care. [32:29.320 --> 32:30.600] The GCHQ gave it to us. [32:36.860 --> 32:37.840] That's also possible. [32:38.740 --> 32:41.580] For the contractors of the systems those contractors control. [32:44.680 --> 32:45.040] Right. [32:45.160 --> 32:47.040] They can get the data and dissolve themselves into an N run. [32:48.100 --> 32:49.580] But, they're not getting the... [32:49.580 --> 32:52.240] So, if they're getting it from their own sensors, they're breaking the law. [32:52.760 --> 32:54.640] If they're getting it from the GHCQ, they're not. [32:55.740 --> 33:03.900] Also, another weird thing to notice is that this C code has that API string XKS colon colon colon when it fires the fingerprint. [33:04.940 --> 33:09.180] That XKS is so deeply in the code, it seems kind of weird. [33:09.180 --> 33:13.560] Because XKEYSCORE is the project name for what the users see on top. [33:13.980 --> 33:17.140] Not all the hundreds of disparate systems down below. [33:17.840 --> 33:20.060] So, it's kind of strange to see it this low in the whole stack. [33:27.920 --> 33:29.740] So, they had some other strings. [33:32.700 --> 33:35.740] Here's another misspelling Tor project that they misspelled with a... [33:35.740 --> 33:36.860] Nope, missing an R there. [33:37.020 --> 33:37.560] Or a second R. [33:39.920 --> 33:45.040] But, one thing about the signature that's kind of interesting is it does show that they still care about where data comes from. [33:45.360 --> 33:52.260] So, whoever wrote these signatures do care that there's a different set of rules for the five English-speaking countries and everyone else. [33:52.460 --> 33:58.680] So, whatever rules they're breaking, we still see in the code everywhere that they're still trying to follow some sense of the rules. [34:00.880 --> 34:11.180] The big story from that German story was that it was calling people who use Tor and Tor websites as extremists. [34:11.820 --> 34:16.220] And that's kind of a misreading of what we see in the code. [34:16.340 --> 34:24.320] So, here's a comment that say that Tails, a version of Tor that runs on its own USB drive, is advocated by extremists on extremist forums. [34:24.980 --> 34:30.720] And a lot of people have interpreted that as meaning the reverse, that all people who use Tails are extremists. [34:30.960 --> 34:32.680] And that's not what this comment says. [34:32.920 --> 34:35.260] It just says extremists use Tails. [34:36.600 --> 34:37.900] Which is, by the way, true. [34:38.120 --> 34:45.460] If you go onto jihadi forums like ISIS, the Islamic caliphate now in Iraq, they recommend using Tor and Tails. [34:45.840 --> 34:47.840] You go into their forums and they recommend it. [34:48.300 --> 34:55.560] So, just because they use it, just because those guys advocate using it, doesn't mean that everyone who uses Tor and Tails is an extremist. [34:57.840 --> 34:59.780] And that's not what the code says either. [35:00.200 --> 35:05.580] Is the code is triggering on things like Linux Journal and the Tails website, which we see in these strings. [35:06.140 --> 35:10.680] But it's not labeling those forums as being extremist forums. [35:10.880 --> 35:15.000] They're saying extremist forums go to these websites in order to download Tails. [35:16.660 --> 35:17.920] And that's what we see in the code. [35:18.280 --> 35:22.480] So, that big story it has, again, is this one-sided story that kind of... [35:22.480 --> 35:29.760] And we see in the German news story, they take one-sided of it and don't kind of take the opposing side, that maybe that's not what the code says. [35:32.880 --> 35:34.000] There is another thing. [35:34.960 --> 35:37.520] Just like the bridges, it would pull out Onion addresses. [35:37.700 --> 35:39.780] Again, Onion addresses are not publicly known. [35:40.000 --> 35:44.980] Unless someone gives you their unique 16-byte code, you can't access that. [35:44.980 --> 35:45.400] It's their website. [35:47.440 --> 35:52.300] So, this again, it uses a regex to grab it. [35:53.220 --> 36:02.780] And one thing I wanted to focus on that regex is that both this regex and the one that grabbed the bridge information, they both optionally grabbed the port number when it was in the string. [36:03.320 --> 36:05.520] And they did so in two completely different ways. [36:05.760 --> 36:08.360] So, you see the snippets from the regexes. [36:08.520 --> 36:12.500] The first one is from the... is from this one grabbing the Onion addresses. [36:12.500 --> 36:16.500] And the second one is grabbing the port number when it's in the bridge address. [36:16.720 --> 36:18.380] There's no reason for these to be different. [36:18.800 --> 36:22.800] It's just that regex is such an ugly, terrible, nasty language. [36:22.940 --> 36:23.620] Like, just look at it. [36:23.780 --> 36:24.240] It's awful. [36:25.480 --> 36:27.320] That everyone does it slightly differently. [36:27.580 --> 36:33.280] Which means you can often fingerprint the author and know who wrote these regexes just by... [36:33.280 --> 36:34.760] They have a very distinctive style. [36:35.260 --> 36:38.160] So, we know, for example, that two different people wrote these regexes. [36:38.680 --> 36:42.000] Now, there may be reasons for it, like, they actually didn't write the regex themselves. [36:42.240 --> 36:47.240] They just copied it off of an Internet form that was talking about capturing Onion addresses and they just copied it into their NSA rules. [36:48.360 --> 36:51.880] So, it may not be the NSA person himself who wrote it. [36:52.300 --> 36:56.240] But that's an interesting thing to note about these regexes. [36:56.380 --> 36:57.520] They also have bugs, by the way. [36:57.600 --> 36:59.240] All these regexes have a bunch of bugs. [36:59.780 --> 37:01.760] Like, this first one here grabbing the port number. [37:01.880 --> 37:02.740] I mean, the second one. [37:03.940 --> 37:09.300] What that regex says is also grabs part of the port number, the first character after the port number. [37:10.460 --> 37:15.460] So, when you see this in the database, it always has additional characters that are not part of the number. [37:16.600 --> 37:18.340] Also, it's two to four characters. [37:18.560 --> 37:22.220] So, a port number with one byte, like zero through nine, doesn't get captured. [37:22.420 --> 37:26.700] Or a larger port number, like 30,000, doesn't get captured because it's got five digits. [37:27.460 --> 37:31.040] So, again, we see bugs up and down throughout this code. [37:37.030 --> 37:42.130] And then what it does with the port number is it puts it up into a Google protocol buffer. [37:42.490 --> 37:45.950] Google created this way of creating easy protocols called protocol buffers. [37:46.070 --> 37:47.770] It's kind of a weird, stupid name. [37:48.890 --> 37:55.210] But part of what this shows is that the NSA is just grabbing what everyone else is doing in the community. [37:55.210 --> 37:57.030] Oh, Google has this new thing called protobuffers. [37:57.030 --> 37:58.770] Well, we'll use protobuffers in our code. [37:58.850 --> 37:59.830] It satisfies our needs. [38:00.050 --> 38:01.950] Or the whole map reduce paradigm. [38:02.710 --> 38:06.030] Or everything that we would do to create this is just what they're doing. [38:06.250 --> 38:08.590] They're not doing anything special other than what we would be doing. [38:13.370 --> 38:20.770] And, again, what it does with the onion addresses, again, it just sticks them to the database, losing all source of where those things came from. [38:21.210 --> 38:24.850] Again, being maybe a product that GCHQ provides to the NSA or something. [38:27.830 --> 38:29.790] So, now let's talk about jamming the system. [38:30.890 --> 38:37.270] Now, most of what we talk about for the NSA is about evading them by encrypting our stuff so they can't see it. [38:37.970 --> 38:41.230] But it would be really fun just to attack them and do nasty things to them. [38:43.170 --> 38:47.490] For example, one of those signatures was looking for tails plus USB within Google searches. [38:49.070 --> 38:59.350] Well, what I can do on my website is I can put an image tag that's not normally seen by the users, but which goes out to the Google search URL and causes a search to happen for tails plus USB. [39:00.270 --> 39:06.470] What that means is, is now their database is now filled up with people throughout the world doing this search. [39:06.610 --> 39:07.910] And no one knows they're doing it. [39:07.910 --> 39:18.290] It's now the NSA analyst who is looking for this information, who's searching for tails on USB, has now been flooded with data. [39:18.510 --> 39:23.090] Their database has probably had maybe filled up on some of their sensors and now they can't process the data. [39:23.310 --> 39:28.710] Now their efficiency is going way down and their boss is saying, hey, you haven't produced us any results in the last month. [39:28.710 --> 39:29.470] What's going on? [39:29.610 --> 39:30.530] Do I need to demote you? [39:30.750 --> 39:34.510] And so they say, okay, I'm going to remove this from my searches because it's just too much noise. [39:44.600 --> 39:50.520] So one thing is with Tor is the Tor right now runs as a separate service. [39:50.700 --> 39:53.840] It uses SSL so it looks very much like a web server, but it's not a web server. [39:54.600 --> 39:55.940] Well, let's make it a web server. [39:56.220 --> 40:01.960] Let's make it so that our own web servers on our own websites actually have just a Tor as sort of an Apache plug-in. [40:01.960 --> 40:08.720] And now the NSA can't differentiate between people using Tor, which looks like SSL, but I really know it's not. [40:08.880 --> 40:09.740] It's really easy for me to tell. [40:10.060 --> 40:12.320] Well, now I see a website traffic. [40:12.460 --> 40:19.380] So I see normal website traffic as well as these long-term sessions that last for 15 minutes before they end. [40:19.860 --> 40:24.820] So it becomes very hard once we make our traffic look like other good traffic. [40:24.980 --> 40:29.600] It becomes very hard for those deep packet inspection tools to tell the difference between one and the other. [40:33.900 --> 40:43.220] That bridges thing, well, if that's what they're doing today, well, we can just start exchanging clear text emails with each other with just a million bridge addresses in them. [40:43.360 --> 40:46.020] Just start with like 001, 002, 003. [40:46.560 --> 40:52.080] So then they've got a database sensor that's maybe running on a low-end computer in Iraq or something. [40:52.080 --> 40:56.860] And now that the whole system floods up, the whole database fills up with invalid bridge numbers. [40:59.340 --> 41:02.520] And, of course, we can do the same thing with the onion addresses. [41:04.940 --> 41:14.980] That regex had a bug that is looking for HTTP and HTTPS, but really what's capturing is just any number of letters, alphanumeric characters, or alpha characters. [41:15.640 --> 41:19.580] So we can put any string we want there instead of HTTP, like something else. [41:20.620 --> 41:31.240] That could be not only a message for the analyst, but also we could put a thousand characters here, or a million characters here, and technically it would be matched by the regular expression. [41:32.040 --> 41:37.660] Which can destabilize the system and bring it down before it's able to actually build a list of onion addresses. [41:40.060 --> 41:47.540] One of the things I've been doing recently for the last year is a project called Mask Scan, which I've been using to scan the entire Internet. [41:49.540 --> 41:56.660] On an appropriately fast link, it will scan all four billion IP addresses in an hour. [41:59.740 --> 42:02.800] So deep packet inspection code hates two things. [42:02.940 --> 42:06.140] They hate lots of small packets because there's lots of overhead per packet. [42:06.140 --> 42:10.700] So when the network traffic consists of small packets rather than large packets, they get really unhappy. [42:12.080 --> 42:15.580] Second of all, they don't like lots of concurrent connections. [42:15.760 --> 42:18.360] They're built for maybe 100,000 concurrent connections. [42:18.480 --> 42:20.100] And that's a lot for most of their tools. [42:21.320 --> 42:23.060] Running Mask Scan, you can generate billions. [42:23.880 --> 42:31.580] And so I've heard through the grapevine that this has indeed happened, is that they've had sensors go down because I run Mask Scan and scan the entire Internet. [42:32.180 --> 42:35.000] So I've heard through the grapevine that indeed they've had sensors go down. [42:35.000 --> 42:40.280] They've had to write rules for the IP addresses that I do Mask Scan from to say, don't capture that data. [42:42.460 --> 42:44.260] Which, by the way, makes me feel really, really good. [42:44.800 --> 42:49.940] I mean, for most people to say, oh yeah, the NSA has added your IP addresses to their system. [42:50.220 --> 42:51.500] That would scare most people. [42:51.540 --> 42:53.820] But for me, of course, it's quite the opposite. [42:56.460 --> 42:58.460] We can do this with normal tools too. [42:58.780 --> 43:00.880] Like BitTorrent has this... [43:00.880 --> 43:07.160] DH this peer-to-peer tracker service over UDP that runs in the background and exchange... [43:07.160 --> 43:09.440] So it's a tracker-less system. [43:09.600 --> 43:13.840] So that we all exchange in peer-to-peer where the tracking information is from rather than having servers. [43:15.120 --> 43:16.820] This generates a lot of connections. [43:17.020 --> 43:20.840] So when you run this on your laptop, it just generates lots of connection records. [43:20.840 --> 43:24.860] And so if someone's trying to monitor you, their database fills up with connections. [43:25.860 --> 43:27.460] Bitcoin wallets have the same property. [43:27.800 --> 43:30.920] Because you talk to, eventually, every other Bitcoin wallet in the world. [43:31.380 --> 43:41.260] And so now you have lots of connections, and you've got the connectivity graph, and it just destroys an analyst's ability to be efficient in trying to track down who are you actually talking to. [43:45.400 --> 43:46.420] One cool thing... [43:46.420 --> 43:52.280] So there was that signature that looks for the bridge.torproject.org within X.509 certificates. [43:52.900 --> 43:54.640] Well, okay, let's all set up... [43:54.640 --> 43:56.820] You know, run Apache on a random port. [43:56.920 --> 43:58.160] Like one, two, three, four, five. [44:00.160 --> 44:04.760] And just create a self-signed certificate claiming to be a bridge at torproject.org. [44:04.980 --> 44:09.140] And just put it on the network, and then put like a little image tag within one of our HTML files. [44:09.140 --> 44:12.280] And cause people to download that certificate. [44:12.540 --> 44:13.940] Cause people to go buy a sensor. [44:14.580 --> 44:15.680] Pulling out that information. [44:19.060 --> 44:21.380] So, again, we'll cause a database to fill up. [44:21.580 --> 44:22.680] So we can use that principle. [44:22.820 --> 44:29.660] Anything we think of the NSA might be tracking, we'll just start doing it on our websites and causing their tracking system to become very inefficient. [44:32.520 --> 44:34.340] There's this tool from... [44:35.080 --> 44:36.340] I think maybe it's... [44:36.340 --> 44:38.620] I forget who does it. [44:39.900 --> 44:41.180] Called GoogleSharing.net. [44:41.640 --> 44:51.660] And what that tool does is when you do a search in this tool, instead of doing a search via your cookies, it sends a search to some other user of this product doing that search from their cookies. [44:51.940 --> 44:58.060] So if you want to do like ricin or bombs or something, you'll be searching using other people's cookies. [44:58.060 --> 45:00.320] And likewise, their searches will go through your system. [45:01.660 --> 45:06.000] And that will then totally disrupt trying to track down which people are doing which searches. [45:06.730 --> 45:09.920] But I think we need to do more projects like that. [45:10.120 --> 45:14.980] Where we would do something of like, let's just take our whole search history and just start exchanging it with each other. [45:15.440 --> 45:18.200] And just causing in the background those searches to happen on Google. [45:18.520 --> 45:23.360] So that eventually, every one of us has done all the searches that everyone else here has done. [45:23.580 --> 45:27.000] Making the whole search thing just make it go bonkers. [45:27.900 --> 45:29.540] We can also do the same thing with a cell phone. [45:29.730 --> 45:33.840] Imagine a nice little Android app that communicates over the Internet with each other. [45:34.560 --> 45:38.360] And then during the night, for most people have free minutes during the night and weekends. [45:38.780 --> 45:42.280] You just put your phone into roulette mode and then they just start calling each other. [45:42.800 --> 45:45.380] And you also turn off your speaker so you don't hear it. [45:45.420 --> 45:46.000] So you can go to sleep. [45:46.710 --> 45:50.280] But then we have metadata where all of us are calling everyone else. [45:50.280 --> 45:54.760] And now it becomes really hard for the metadata systems to pull out who actually are you calling. [45:56.300 --> 46:05.360] So the more that we exchange metadata and contact each other in the background, the less they can actually say for real who are we really contacting. [46:05.800 --> 46:09.060] So we're all kind of afraid of being that three hops away from a terrorist. [46:09.420 --> 46:16.680] But actually, when we're all three hops away from everyone else, the whole hops idea just drives down the NSA's efficiency and they can't really do much. [46:18.620 --> 46:20.820] And then finally, there's exploitation. [46:21.440 --> 46:23.640] I know that they're using open source tools. [46:23.760 --> 46:25.440] I know they're using Snort somewhere in the system. [46:25.660 --> 46:27.120] I know they're using T-Shark somewhere. [46:27.210 --> 46:32.040] I know for every deep packet inspection tool that exists, the NSA's probably trying to use it somewhere. [46:33.120 --> 46:36.730] Wireshark, in particular, has just buffer overflow bugs at the yin-yang. [46:37.080 --> 46:40.320] Just go pick a random protocol, search for a bug, and you'll find one. [46:40.320 --> 46:53.540] So, if we just start grabbing bugs and just knowing that what the source systems they have are probably x86 systems running in Linux, running these tools, we'll just start finding O-days in them and then running exploits for them. [46:53.960 --> 46:57.080] That the exploits go off and, like, delete everything on the system. [46:58.340 --> 47:00.420] And that will drive their efficiency way down. [47:04.710 --> 47:06.000] So, that's my talk. [47:06.120 --> 47:06.620] Any questions? [47:13.520 --> 47:14.520] You can come up here. [47:21.570 --> 47:23.850] So, first off, thank you very much for that talk. [47:24.010 --> 47:24.910] I really enjoyed it. [47:25.610 --> 47:29.570] So, it seems to me, like, within file formats, there's all this discussion on metadata. [47:30.010 --> 47:33.530] And the way that we store metadata within files is kind of finicky. [47:33.890 --> 47:42.770] And I could very easily change the way that it's stored as long as I have a program, say, on my side and my recipient's side that can understand the protocol that's being used. [47:42.770 --> 47:56.730] So, if you can change the protocol that easily to basically thwart these detections, can I draw conclusions about that, either from that idea, either about how the NSA operates or about how the people the NSA is targeting operate? [48:02.100 --> 48:06.200] Well, one thing is, is that protocols have a very wide range of what's accepted. [48:06.500 --> 48:15.600] Which means that you can encode your metadata one way that normal programs will read that metadata, but which may no longer be extractable by the NSA. [48:16.000 --> 48:24.100] So, I can maybe encode it so that other image programs can read, like Photoshop can still read my exit GPS locations, but I've done something that most tools that the NSA is using cannot. [48:24.500 --> 48:28.740] Just look on the open source tools that grab that data, say, hey, there's a bug here, or it's more limited. [48:29.000 --> 48:30.400] I encode it this way, I can evade it. [48:32.900 --> 48:34.980] But, the rest of your question, I don't really know how to answer. [48:36.740 --> 48:37.100] Question? [48:40.880 --> 48:43.500] Back in 1998, I wrote the first IPS. [48:44.040 --> 48:52.580] I wrote a suite of tools, all based on intrusion detection technology, called Black Ice, and it's deep packet inspection. [48:52.710 --> 48:56.400] It decodes a lot of protocols, looking for intrusions, and was like that. [48:57.230 --> 49:04.820] And in 2007, I did sidejacking, which is deep packet inspection to grab cookies, and then put them into your browser so that you can, like, hijack people's connections without knowing their password. [49:05.400 --> 49:10.000] And then, recently, I've got code up on my GitHub that does deep packet inspection. [49:10.360 --> 49:14.080] And second question, what ISP do you use that does that? [49:16.800 --> 49:17.840] That's a frequent question. [49:17.840 --> 49:21.100] And we work... the company is called CarryNet, which you can just do reverse. [49:21.300 --> 49:24.320] Look up on... look in your logs, see me scanning, and find out. [49:25.140 --> 49:26.800] But we work closely with them. [49:26.940 --> 49:32.420] So, we've got our own little swipe, little address range that gets the abuse complaints back to us. [49:32.820 --> 49:36.720] Everyone who asks, we put into our exclude files so we don't scan them again. [49:36.720 --> 49:42.460] So, we work closely with them to avoid any disruption. [49:44.060 --> 49:45.860] But, by the way, back to mass scanning. [49:46.340 --> 49:53.500] HOPE has a 10-gigabit uplink to the Internet, which means just go grab an Ethernet cable, go to one of their hubs, sit down there and just run mass scan. [49:53.660 --> 49:58.360] It runs on all platforms and just compile it, run it, start scanning the Internet yourself with the HOPE traffic. [49:58.940 --> 50:03.760] And you can, like, scan the whole Internet an hour from the proper gigabit adapter in your notebook. [50:04.460 --> 50:07.040] And they would love it, because they want to fill up that 10-gigabit pipe. [50:07.120 --> 50:09.360] And you're going to love it, because you're anonymous. [50:10.860 --> 50:15.480] The NSA's going to hate it, because if they're monitoring this traffic at all, they're not going to see... [50:15.980 --> 50:20.020] Suddenly, all their sensors go blind, because they fill up with the connection table limits, and get exceeded, and they just barf. [50:20.720 --> 50:24.440] One of the address ranges they have is, actually, a Netherlands address. [50:25.500 --> 50:32.040] So, NSA's probably not looking at HOPE from the, maybe the FBI, but not the NSA, on the American address ranges. [50:32.220 --> 50:36.540] But the ones that are actually Netherlands, officially assigned to Netherlands, they might be monitoring. [50:36.800 --> 50:41.860] So, you can cause them lots of headache if you just go downstairs, and hook into the hub, and start scanning. [50:44.720 --> 50:45.600] Any other questions? [50:55.420 --> 50:55.860] Right. [50:56.080 --> 50:58.780] The question is whether they're pipelining that data also to other products. [50:58.780 --> 50:59.640] And the answer is yes. [51:00.100 --> 51:05.540] So, I sort of talk about this as if everything's a key score, but in reality, it's not. [51:06.580 --> 51:11.880] There's metadata heading towards the Marina project, and analysts put stuff in PINWALL. [51:12.060 --> 51:13.520] It just goes all over the place. [51:20.070 --> 51:24.190] So, I think what they're looking for is things like, show me all... [51:24.190 --> 51:32.730] An analyst will say something like, show me all images where the GPS locations are in Mosul, which was recently taken over by the Islamic Caliphate. [51:32.730 --> 51:34.930] So, they want to know something about that. [51:35.510 --> 51:37.230] So, they say, hey, there was this... [51:37.230 --> 51:39.030] Maybe there was a missile launcher in the Ukraine. [51:39.690 --> 51:42.150] So, I know where these... that missile launcher was. [51:42.330 --> 51:49.510] Well, show me all images I intercepted from the Ukraine with a GPS location around where that, you know, that missile launcher was. [51:49.570 --> 51:50.530] Maybe the one mile radius. [51:51.110 --> 51:53.790] In the last, you know, three days. [51:53.790 --> 51:57.690] Do you not necessarily think there's a lot of automated surveillance going on in looking at content? [51:57.910 --> 51:58.830] Do you think there's more metadata? [51:59.030 --> 51:59.830] I think... [51:59.830 --> 52:00.210] Well, there's a... [52:00.210 --> 52:01.370] It's mostly metadata. [52:01.710 --> 52:09.670] But, of course, some smart guy says, hey, I know if I do this, this, and this, with facial recognition, I'm able to throw things into a smarter system. [52:09.810 --> 52:11.750] But the smarter systems take a lot more compute power. [52:11.890 --> 52:14.950] So, they can't grab every image and throw it through a facial recognition database. [52:14.950 --> 52:25.950] What they can say is, we'll grab maybe GPS data, narrow it down, view the metadata, and then just pass the small feeds up to Utah for more extensive processing or something. [52:26.290 --> 52:30.110] I'm also curious if you can run across some more information on what kind of hardware you are running. [52:31.110 --> 52:34.870] From what I hear, is they run everything, including Raspberry Pis. [52:36.370 --> 52:37.790] So, when they get... [52:37.790 --> 52:39.890] Like, when they break into a data center, they want... [52:39.890 --> 52:42.450] Like, they want monitor phones a lot. [52:42.450 --> 52:43.490] So, they're going to break... [52:43.490 --> 52:45.270] They're going to hack into someone's data center. [52:45.530 --> 52:46.910] They're just going to use the hardware that's available. [52:47.450 --> 52:50.350] Oh, there's this old decommissioned system that's still plugged into the network. [52:50.490 --> 52:51.990] Well, let's recommission it. [52:52.930 --> 52:54.690] And so, they're using some old piece of hardware. [52:57.700 --> 52:58.500] Any more questions? [53:00.060 --> 53:00.900] There's one in the back. [53:01.100 --> 53:01.620] Could you raise your hand? [53:02.360 --> 53:02.420] Oh. [53:04.580 --> 53:04.940] Okay. [53:05.100 --> 53:05.560] I guess that's it. [53:06.140 --> 53:06.920] Thank you very much.