[00:00.000 --> 00:02.200] ...to install or use the tools. [00:03.760 --> 00:07.000] And this is what we are going to show you in the next hour. [00:08.720 --> 00:12.560] The second projector is not as good, so I am sorry for the quality. [00:12.800 --> 00:18.380] We are trying to show two parts of a conversation at once, so that is why we are using two projectors. [00:18.560 --> 00:19.820] So we will see how it turns out. [01:07.050 --> 01:09.330] Okay, well, so we will start. [01:09.630 --> 01:10.990] My name is Paul Wouters. [01:11.230 --> 01:12.570] Next to me is Aldert Hazenberg. [01:12.590 --> 01:13.330] Hi. [01:17.190 --> 01:18.890] What is our background, briefly? [01:19.650 --> 01:25.510] I guess we are both what people consider hackers, or maybe not him. [01:28.030 --> 01:35.290] We are involved, we have done a lot with privacy, we have done a lot with wireless and trying to make people safer than they were. [01:36.330 --> 01:41.230] Aldert is involved with wireless Amsterdam and making mesh networking in Amsterdam. [01:41.510 --> 01:46.350] So if you are in Amsterdam and you open your laptop, it is a good chance that you are online because of Aldert's involvement. [01:48.990 --> 01:49.550] No? [01:54.350 --> 02:00.710] For a living, what I am doing is I am a developer of OpenSwan, which is the IPsec code on Linux. [02:03.090 --> 02:07.950] So probably some people, if you are running VPNs on Linux, that you are probably running our code. [02:08.530 --> 02:09.890] And this is just our hobby. [02:15.880 --> 02:21.420] So, the misconception that people have is that using encryption is really difficult. [02:21.580 --> 02:30.720] And if you look at all these talks that I have seen here and in the years before, it is really always very difficult to get encryption running and to really set it up. [02:30.840 --> 02:32.080] So a lot of people have just given up. [02:32.180 --> 02:33.140] Like, well, forget it. [02:33.220 --> 02:34.000] I am not going to use it. [02:34.200 --> 02:35.580] It is just way too difficult. [02:36.500 --> 02:38.600] Well, we are going to show today that it is not difficult. [02:38.800 --> 02:45.800] It is really easy and we are going to show you how to encrypt most of your traffic within the hour. [02:46.040 --> 02:48.640] And that is including all the things that will go wrong during our presentation. [02:48.980 --> 02:49.920] So it is really easy. [02:52.180 --> 02:54.760] Some sort of the presentations will be available on the server. [02:55.800 --> 03:00.940] If you have any questions later on, just catch either me or Aldert out in the hallway. [03:01.660 --> 03:08.900] If your question becomes too technical for this talk, then we will cut you off and tell you that we will happily explain it in the hallway later as well. [03:10.020 --> 03:21.540] The purpose is also a little bit to convince you that you can actually make sure that your parents and your uncle and your aunts and your little sister also have security and privacy on the Internet. [03:24.360 --> 03:27.060] And that you can do that for them easily. [03:28.560 --> 03:42.620] So in the next few minutes, I will explain the three concepts you need to know a little bit of for encryption to understand why you need to see so many windows with fingerprints and weird numbers. [03:43.120 --> 03:45.900] I am going to try and keep it really simple. [03:45.900 --> 03:49.100] But you need to know these three basic concepts. [03:49.440 --> 03:50.280] And that is all you need to know. [03:50.800 --> 03:53.980] All the rest is the underlying math that nobody needs to know. [03:57.520 --> 03:59.980] So one point that is always very important. [04:00.680 --> 04:02.840] The network, per definition, is very unsafe. [04:03.000 --> 04:03.860] You should never trust it. [04:04.040 --> 04:05.320] That is good. [04:07.640 --> 04:09.740] Also, a lot of software is proprietary. [04:09.960 --> 04:13.420] You don't have the source code to it and you can't really see if it works or not. [04:14.160 --> 04:21.260] The problem is, it has been proven the other way by a friend of ours, Rudiger Weiss in Germany, a professor in Berlin. [04:21.440 --> 04:28.540] He has proven that if you do not have the source code, that you can hide information leaking into any cryptographic channel. [04:28.740 --> 04:34.660] So if you don't have the source code, you can never prove that nobody is eavesdropping on you and that the machine is not backdoored. [04:34.860 --> 04:37.160] You can never be sure. [04:37.160 --> 04:44.300] So our focus is on open source and free tools because those are the ones where you could actually verify that it is properly working. [04:44.700 --> 04:45.680] So it is very important. [04:45.820 --> 04:53.260] If you have a choice between any binary only commercial tool or an open source tool, go for the open source tool. [04:55.920 --> 04:58.120] So this is briefly what we will be covering. [04:58.120 --> 05:04.460] First we will show you instant message because that tends to be the most private conversations going. [05:04.680 --> 05:06.220] The most sensitive data. [05:06.580 --> 05:09.200] And it is the most easy to secure these days. [05:09.920 --> 05:11.300] We will talk about Internet browsing. [05:12.140 --> 05:16.620] How to make sure that you don't end up on the screen like the other people in the beginning of this talk. [05:17.180 --> 05:18.340] We will talk about email. [05:18.880 --> 05:19.600] How to secure that. [05:19.820 --> 05:20.440] It is a little bit harder. [05:20.680 --> 05:21.280] A little bit more work. [05:21.420 --> 05:22.180] But still doable. [05:23.340 --> 05:26.440] Voice over IP might briefly show or not. [05:29.200 --> 05:33.920] But the Windows software is currently broken according to the website. [05:34.200 --> 05:34.800] It is expired. [05:35.780 --> 05:36.160] Really funny. [05:37.080 --> 05:38.520] So Phil Zimmerman did not do his job very well. [05:39.160 --> 05:42.940] And then we will not talk about disk encryption or VPNs or Wi-Fi encryption. [05:43.100 --> 05:46.460] If you want to talk about any of these, then again, catch us in the hallways. [05:51.020 --> 05:56.820] In principle, all the encryption used in the software is what people call military grade. [05:56.980 --> 05:59.160] Which means like it is unbreakable even by the military. [06:00.840 --> 06:06.340] Even though that is true, there is a lot of other factors that determine whether or not you are secure or not. [06:06.480 --> 06:11.580] And usually it comes down to if your machine is owned because you have been browsing too many porn sites. [06:11.800 --> 06:13.660] Then your machine is not going to be really secure. [06:13.820 --> 06:15.300] And you can have military grade encryption. [06:15.300 --> 06:20.000] But if your whole machine is back-doored and has key lockers installed and everything. [06:20.320 --> 06:22.380] Then they will know what you are saying anyway. [06:23.640 --> 06:27.880] So what we are at least guaranteeing is that your communications will be encrypted. [06:28.120 --> 06:31.440] And it is up to you to make sure that your machine is still trustworthy. [06:35.160 --> 06:37.260] So this is the basic threat. [06:38.400 --> 06:39.060] Number one. [06:39.240 --> 06:39.700] It is the Internet. [06:39.840 --> 06:40.480] All the bad guys. [06:41.500 --> 06:45.960] Again, we use Alice and Bob as the two people who are trying to communicate as a sort of standard. [06:47.040 --> 06:48.720] You will see the bad guys on the Internet. [06:49.200 --> 06:52.640] And what people don't always realize is that in this case. [06:52.780 --> 06:55.520] And we have done this by encircling Bob in red as well. [06:56.160 --> 06:58.500] Is that Bob can turn out to be a bad guy too. [06:59.280 --> 07:02.720] For instance, I could be talking to Aldert over instant message for two years. [07:02.940 --> 07:03.780] And I trust him. [07:04.400 --> 07:06.900] And during this presentation we run into a big fight. [07:07.280 --> 07:08.740] And we hate each other afterwards. [07:09.380 --> 07:12.160] So suddenly, everything I have told Aldert. [07:12.700 --> 07:16.880] And if it is encrypted, he can sort of prove that I have said this to all these people. [07:17.120 --> 07:20.480] You know, oh, all this gossip I sort of trusted him before. [07:20.800 --> 07:22.900] Suddenly now it becomes available to everybody. [07:23.940 --> 07:29.680] So even though it is not always possible to protect against the malicious Alice or Bob. [07:30.000 --> 07:33.200] We will see with the instant messenger we actually can protect against that. [07:33.300 --> 07:33.620] And we do. [07:33.620 --> 07:36.700] So you can gossip with everybody, very secure. [07:36.900 --> 07:40.040] And even if you run into fights later, you can deny everything. [07:43.640 --> 07:50.440] The second, and this is probably the most important threat that you face, is the so-called man in the middle attack. [07:50.860 --> 07:51.740] It is demonstrated here. [07:52.120 --> 07:53.200] Alice and Bob are talking. [07:53.640 --> 07:55.240] So Alice is saying, hi Bob. [07:56.020 --> 08:00.840] And Bob hears, or not hears, he sees through text, hi Bob. [08:01.560 --> 08:03.680] So he goes like, oh well, that must be Alice, that is good. [08:04.200 --> 08:09.300] However, there could be an evil person in between the two of them that is just relaying the messages. [08:10.640 --> 08:13.920] So Alice is actually not talking to Bob, Alice is talking to Mallory. [08:14.340 --> 08:17.260] And Bob is not talking to Alice, but Bob is talking to Mallory. [08:19.440 --> 08:23.140] These arrows in between signify encrypted connections. [08:23.520 --> 08:30.920] So even though nobody in the room can eavesdrop between Alice and Mallory, Alice is still talking to the wrong person. [08:33.140 --> 08:43.080] So it is very important that once we have an encrypted connection going, and we know it is secure and nobody can eavesdrop on it, we still need to make sure that we are actually talking to the person we think we are talking to. [08:46.040 --> 08:50.100] The solution for this is, forget the name, it is called Diffie-Hellman Key Exchange. [08:50.940 --> 08:59.960] If you look at the picture, what you will see is that when Alice is talking to Mallory over an encrypted connection, there is a few properties of that encrypted connection. [09:00.240 --> 09:04.500] It is signified here with a bunch of letters, starting with D9J. [09:06.080 --> 09:12.180] Mallory is talking to Bob and that is another encrypted connection and that also has some properties. [09:12.460 --> 09:15.020] And again, there are some numbers to signify that. [09:15.900 --> 09:22.780] So, now we can see that there is a difference between one connection between Alice and Bob and two connections where Mallory is in between. [09:22.780 --> 09:31.280] Now, the only thing you need to do is to make sure that you somehow convey these properties of this encrypted connection between Alice and Bob. [09:34.410 --> 09:36.870] So, and that is called a trusted third party. [09:37.070 --> 09:45.550] So, without using the encrypted channel, you pick up the phone and you go like, hey Bob, this is the properties of my connection. [09:45.650 --> 09:46.450] Is that the same as yours? [09:46.770 --> 09:51.370] And then in this case, Bob will go like, no, no, mine is really different from what you are saying. [09:51.490 --> 09:52.350] Oh, that must be wrong then. [09:52.350 --> 09:55.330] Oh, okay, so somebody is listening in on us. [09:55.650 --> 10:00.210] And if it is correct, if it is the same letters, then they know that there is nobody in the middle. [10:01.890 --> 10:05.050] Does anybody understand this concept? [10:06.390 --> 10:17.310] So, some people, for instance, if they are using Instant Messenger and they set up an encrypted connection, they go like, oh, I am really Paul because I am wearing glasses and I am really skinny so you know it is me. [10:17.910 --> 10:23.910] But again, Mallory can just hear that and replay that and say, oh, hi, I am Paul, I am skinny and I wear glasses. [10:24.230 --> 10:27.890] So, it is not good enough to say this information on the encrypted channel. [10:28.030 --> 10:31.290] You have to do it somehow in some different way. [10:33.110 --> 10:34.670] So, that is where the phone call comes in. [10:38.860 --> 10:40.440] So, I talked about this. [10:42.040 --> 10:44.820] And in a way, a text message is not solving this. [10:45.160 --> 10:54.820] So, you should really talk to each other and hear each other's voices and make really sure by questioning who is who and then talk about the properties of this connection. [10:55.840 --> 10:56.460] Yes, sorry. [10:56.540 --> 11:00.660] The implication in the previous slide was that you recognize the voice of this other person. [11:00.800 --> 11:06.800] If you have never spoken to this person before, who is to say that Mallory is not picking up the phone and answering your questions. [11:10.670 --> 11:12.530] And then there is one third danger. [11:12.930 --> 11:23.950] Even though everything could be secure and nobody is eavesdropping on you or nobody is man in the middle of you, somebody could still be capturing everything you say through encryption and they just have to encrypt the data. [11:24.110 --> 11:25.270] There is nothing they can do with it. [11:25.550 --> 11:37.590] But then at some point, you know, they come in Mallory, in Alice or Bob's house and they steal their computer or they, you know, copy the secret keys or, you know, the machine gets compromised. [11:38.530 --> 11:46.270] And then suddenly, with the information from Alice's machine, they can decrypt everything that they have eavesdropped before. [11:48.670 --> 12:02.270] The defense against that, which you might know from some software, is first of all the private key, that is actually the valuable thing that you need to steal from this machine, can be protected by a pin or a password or a passphrase. [12:02.270 --> 12:06.910] This actually, it works for, you know, to prevent your little sister from getting it. [12:07.290 --> 12:12.950] But, you know, if the NSA is, you know, has this file, it will just take them a couple of hours to just get it. [12:13.070 --> 12:20.010] So, if you lose, like, your PGP private key, don't count on the password to make it safe. [12:21.670 --> 12:33.050] The second way where a lot of protection is built in is that they use session keys so that everything you eavesdrop is encrypted with a temporary key that you throw away in an hour. [12:33.230 --> 12:44.410] So, even though they can sniff a year's worth of traffic that's encrypted, not even Alice and Bob can decrypt that traffic anymore because they use temporary keys that they agreed on with their real keys. [12:44.610 --> 12:48.770] So that, you know, the sniffing that traffic is completely useless. [12:49.610 --> 12:51.590] That's called perfect forward secrecy. [12:54.950 --> 12:56.350] So, that was the theory. [12:56.570 --> 12:59.970] So now we're going back to the, back to live demoing. [13:00.310 --> 13:04.150] So, if anybody has any questions, this would be a good point. [13:05.790 --> 13:07.350] And you should walk to the microphone. [13:11.520 --> 13:12.500] Very quick questions. [13:12.820 --> 13:20.440] First of all, do you have to do the phone call for every chat session that you do because you have a different, like, signature for your chat? [13:21.140 --> 13:22.000] Or just once? [13:22.180 --> 13:29.260] In principle, you only need to do this once because then you've verified that there's nobody in between and then you can trust that point on. [13:29.400 --> 13:35.040] So, using that, you can then create new keys that you trust because you know nobody's e-stopping on them. [13:35.360 --> 13:35.560] Okay. [13:35.760 --> 13:38.640] And the second is the thing you just said in the previous slide. [13:38.980 --> 13:52.780] If they, if you first establish a channel, right, and then you use that to establish the temporary short-lived keys, if they capture all the traffic and they capture, like, your initial key, can they replay that, figure out what the temporary key was? [13:52.980 --> 13:53.240] No. [13:53.640 --> 13:55.880] You can't figure out what the temporary key was. [13:56.020 --> 13:56.820] That's completely random. [13:57.260 --> 13:57.460] Okay. [13:59.100 --> 14:07.520] You should, of course, still, as soon as your computer is compromised, you should, if Alice, her computer is compromised, she should immediately tell Bob, throw away all the keys you have for me. [14:07.560 --> 14:08.120] They're compromised. [14:08.720 --> 14:13.320] So, you have to start from scratch, but your traffic cannot be analyzed afterwards. [14:14.180 --> 14:19.760] For the purposes of your presentation, are you making no distinction between PGP and GPG? [14:21.100 --> 14:22.080] No, we're not. [14:24.890 --> 14:26.630] We're actually using GPG. [14:27.970 --> 14:33.690] If you're going to start an instant message conversation with a phone call, why not continue the phone call? [14:35.970 --> 14:42.190] Because later on you might not be in phone range, or it's, you need to do a one-time out-of-bound verification. [14:42.630 --> 14:44.050] There's no way around this. [14:44.050 --> 14:47.630] If you skip this, you have no way of knowing that you're not talking to Mallory ever. [14:48.030 --> 14:48.770] I understand that. [14:48.890 --> 14:50.490] Is there a better way than a phone call? [14:50.630 --> 14:52.730] Is there some other third channel you could go through? [14:52.930 --> 14:54.390] Do you have a suggestion for that? [14:55.290 --> 14:56.730] Something using the computer only? [14:57.010 --> 14:59.290] The phone call is the fastest and the most reliable. [15:00.210 --> 15:01.130] There are other things. [15:01.550 --> 15:04.790] Let's not go too much into it, but you've got like PGP, Web of Trust. [15:05.030 --> 15:10.590] There's other things where you can sort of, you know, make a leap of faith and continue from there. [15:10.590 --> 15:13.090] You can have a business card with something written on it. [15:13.210 --> 15:14.390] There are many ways of doing this. [15:16.090 --> 15:19.190] But normally the easiest way is to just do a phone call. [15:19.410 --> 15:20.830] And we try to keep it simple. [15:21.630 --> 15:21.870] Thank you. [15:24.720 --> 15:31.740] So, the live part, of course, at every hackers conference, the network is, well, difficult. [15:32.820 --> 15:33.840] Just like here. [15:34.080 --> 15:35.660] So, we have some screenshots. [15:36.140 --> 15:40.400] Not everything might be live, might be semi-live or not live at all. [15:41.060 --> 15:41.700] Bear with us. [15:42.700 --> 15:43.980] We will show the stuff. [15:46.100 --> 15:50.560] So, the first thing we'll show you is instant measured encryption. [15:51.180 --> 15:54.600] What we're using is something called OTR, off the record. [15:56.460 --> 16:03.480] Which, apart from having the properties that I talked about before, that it's encrypting everything and it's making everything secure. [16:04.040 --> 16:07.800] It also ensures that you can always deny that you've said something. [16:08.080 --> 16:10.120] I won't go into the details of how that works. [16:10.300 --> 16:12.180] If you want to know that, catch me later in the hallway. [16:13.260 --> 16:15.900] Off the record has been implemented in a lot of software now. [16:16.940 --> 16:19.560] It's available on OSX via ADM. [16:19.560 --> 16:23.420] There's a proxy server that you can use with iChat. [16:23.660 --> 16:25.200] Both of which we're demonstrating. [16:26.260 --> 16:28.080] For Windows, there's game for Windows. [16:28.580 --> 16:31.160] There's Miranda via plug-in. [16:31.320 --> 16:33.340] And there's a trillion plug-in. [16:33.860 --> 16:36.980] Just to get a feeling for who's using which messenger. [16:37.940 --> 16:39.860] Who's using ADM? [16:41.320 --> 16:42.340] It's a handful. [16:42.840 --> 16:43.800] Who's using iChat? [16:45.340 --> 16:46.980] It's less than ADM, interesting. [16:46.980 --> 16:49.700] Who's using like game for Windows? [16:50.860 --> 16:52.060] A game on Linux? [16:53.420 --> 16:54.160] Quite some... [16:54.160 --> 16:57.640] We will not show anything Linux because we tend to... [16:57.640 --> 16:58.980] This was like a talk for... [16:59.880 --> 17:03.620] To make it simple and in general, people who run Linux really know everything well. [17:03.820 --> 17:06.720] But game for Windows obviously looks the same as game for Linux. [17:06.940 --> 17:08.620] So you can just pick it up from there. [17:09.420 --> 17:10.400] So anybody using Miranda? [17:12.380 --> 17:12.860] Excellent. [17:13.240 --> 17:13.540] Trillion? [17:14.500 --> 17:15.760] There's a few trillion users. [17:16.280 --> 17:17.540] Okay, who's using Trillion Pro? [17:19.780 --> 17:21.040] And who actually bought it? [17:25.400 --> 17:27.740] Okay, so you're the only one who can use the plug-in. [17:54.310 --> 17:59.210] For web browsing, we'll be using Tor and Perfectsy. [18:00.550 --> 18:03.950] And this works for every browser on every operating system. [18:05.530 --> 18:08.950] For email, we'll actually be using GPG. [18:09.770 --> 18:12.250] It's available on all these platforms. [18:13.050 --> 18:18.330] We'll show how to use Apple's mail app with GPG mail. [18:18.650 --> 18:21.690] And we'll show Thunderbird with Enigma on Windows. [18:22.630 --> 18:25.410] And again, it will work for Linux as well. [18:27.610 --> 18:28.810] So these are all the slides. [18:28.970 --> 18:31.130] So now we'll go and try to get the demo running. [18:31.410 --> 18:35.010] So bear with us while we try to use this network. [18:44.780 --> 18:48.900] So first I'll take the easiest one on OS X, which is Adium. [18:49.700 --> 18:54.820] Adium comes with the OTR completely enabled and in it already. [18:54.980 --> 18:57.360] So it really just happens, everything happens automatically. [18:58.840 --> 19:00.660] So I'll try to get on the wireless here. [19:06.590 --> 19:08.810] Wow, there's absolutely no wireless on this end. [19:10.150 --> 19:10.630] Cool. [19:19.910 --> 19:24.130] Can somebody from the organization maybe reboot the airport in the room? [19:25.190 --> 19:26.530] It's doing really difficult. [19:43.320 --> 19:45.220] Okay, so I'm on the wired actually. [19:47.290 --> 19:51.010] So we can see now that at least I logged in. [19:52.380 --> 19:58.120] Since I have a special account called Bob OTR for this, there's no but as you can see. [19:58.270 --> 20:00.320] There's only Alice who you can see is offline. [20:37.100 --> 20:40.620] You can see that the Windows machine is actually a Mac running Windows. [20:52.970 --> 20:53.830] Okay, there we go. [20:54.710 --> 20:56.850] So Aldert is now logging in Alice. [20:57.170 --> 20:59.610] In this case, I'm Bob and already logged in. [20:59.610 --> 21:02.390] So we'll just wait and see if these contacts will see each other. [21:07.890 --> 21:13.010] So what Aldert has done, he's only installed game, which is a standard download from SourceForge. [21:13.190 --> 21:18.430] And he's downloaded and installed game-otr, which is the plugin that gives OTR. [21:19.510 --> 21:21.590] And now we can see that Alice logged on. [21:21.750 --> 21:23.510] So she's appearing on my buddy list. [21:25.170 --> 21:31.370] So we have not done anything like we've talked normally before without using any encryption. [21:31.590 --> 21:33.670] And now we both have the tools installed. [21:33.910 --> 21:35.290] We haven't configured anything. [21:35.730 --> 21:40.790] And now we'll see what happens when Aldert starts a conversation with me. [21:43.390 --> 21:44.710] Yes, go for it. [21:54.800 --> 21:57.120] So we see Aldert told me something. [21:58.760 --> 22:00.760] And this is all clear text. [22:00.920 --> 22:02.860] So anybody sniffing this would be able to see this. [22:12.380 --> 22:15.200] So interesting it's not picking up automatically. [22:27.020 --> 22:27.380] Okay. [22:29.660 --> 22:36.340] So what Aldert didn't do is, which I'm not sure if you can see it on the screen, but he needs to actually enable the plugin. [22:36.520 --> 22:41.160] So apart from installing the plugin, you need to just select like on, on the plugin, which he will do now. [22:44.770 --> 22:45.690] So there we go. [22:53.260 --> 22:54.420] So now let's try this again. [22:59.100 --> 23:03.020] It's a good thing because I would have forgotten to explain to you that you should enable the plugin. [23:16.430 --> 23:16.830] Okay. [23:17.030 --> 23:17.850] So Alice is back. [23:19.030 --> 23:19.830] Alice reconnected. [23:21.450 --> 23:23.210] And Alice will tell me something again. [23:35.830 --> 23:38.710] And now we see that my laptop just started to generate a key. [23:38.910 --> 23:43.450] You saw it quickly, but we've now... [23:45.370 --> 23:46.110] Did you get up? [23:46.310 --> 23:46.690] Okay. [23:49.980 --> 23:54.800] My system now automatically generated a key, which is the long-term key that we'll be using. [23:55.100 --> 23:56.710] So this is not the session key. [23:59.720 --> 24:04.300] But I'm still waiting for my screen to say that encryption started, which it didn't. [24:11.860 --> 24:12.340] Okay. [24:12.480 --> 24:18.420] So if it doesn't start automatically, which it should, but apparently game is not sending the right triggers to do this. [24:18.900 --> 24:22.100] ADM at least has this lock symbol here where I can manually start it. [24:22.280 --> 24:23.080] So that's what I'll do now. [24:23.920 --> 24:26.080] I'll say initiate encrypted OTR chat. [24:59.590 --> 25:01.690] Oh, I actually lost my wireless now. [25:03.290 --> 25:03.770] Or... [25:03.770 --> 25:04.670] Oh no, I'm on the wire. [25:05.470 --> 25:06.030] Let's see where I go. [25:18.770 --> 25:19.910] There we go. [25:28.450 --> 25:32.780] It's at the moment generating a key for my JAME installation. [25:33.980 --> 25:38.800] And it says now, LSOTR has received an unknown fingerprint from Bob. [25:39.450 --> 25:44.120] With this fingerprint, we call each other and we verify if this is the fingerprint. [25:45.220 --> 25:45.580] Okay. [25:45.740 --> 25:46.900] So meanwhile, I got the window as well. [25:47.100 --> 25:53.800] So I think your fingerprint should be 737E8F6, blah, blah, blah, blah, blah. [25:53.950 --> 25:56.560] And we'll do this really securely and all the digits and... [25:56.980 --> 25:58.040] Does it end on B6? [25:58.360 --> 25:59.300] Yeah, it does. [25:59.460 --> 25:59.680] Cool. [26:00.000 --> 26:00.320] Cool. [26:00.740 --> 26:01.880] So this is our phone call. [26:02.040 --> 26:02.820] We have verified it. [26:06.330 --> 26:07.370] Trying to keep it simple. [26:10.690 --> 26:13.230] Now, we could have started talking without verifying. [26:13.350 --> 26:19.450] We could have said verify later and it would still be encrypted, but it would not be guaranteed that I'm actually only talking to Alder. [26:19.530 --> 26:22.050] There could be this man in the middle still doing it. [26:22.190 --> 26:34.010] So the way this works normally, of course, not if you're demoing it before a couple of hundred people, is that it will just automatically say initiated OTR talk. [26:34.190 --> 26:34.870] And you will just... [26:34.870 --> 26:38.190] You will switch to encrypted and then you can always verify later. [26:38.810 --> 26:45.630] But the thing is, it automatically detects when the other end has an OTR enabled instant message client as well. [26:46.590 --> 26:48.390] So from this point on, everything is encrypted. [26:48.770 --> 26:54.750] And since in this case we verified it, there's nobody who can eavesdrop on us from this point on. [26:57.450 --> 27:00.670] And yeah, that's, I guess, the end of this part of our demo. [27:01.270 --> 27:02.930] So we'll show some other clients. [27:02.930 --> 27:07.890] So I'll switch to iChat on the Mac because some... [27:07.890 --> 27:08.870] Oh, there's questions? [27:09.070 --> 27:09.170] Sure. [27:09.510 --> 27:10.850] Just about this... [27:10.850 --> 27:11.590] Hello? [27:13.250 --> 27:13.950] It's on? [27:14.110 --> 27:14.310] Okay. [27:14.610 --> 27:20.970] Just about this session, was the key that you guys verified over the telephone exchanged electronically? [27:22.590 --> 27:30.210] Actually, OTR works slightly different because it's only doing a Diffie-Helman key exchange per message and it's not using public-private keys and signatures. [27:30.210 --> 27:31.270] So I can... [27:31.730 --> 27:32.510] I can talk... [27:32.510 --> 27:32.550] So... [27:32.550 --> 27:33.770] If you want, I can talk to this later. [27:34.030 --> 27:34.650] Well, but the... [27:34.650 --> 27:39.350] Just the question of the key that you verified over the telephone, that was exchanged only through your computers, right? [27:40.290 --> 27:40.610] It was... [27:40.610 --> 27:41.710] Between your message clients. [27:42.270 --> 27:44.190] No, it was a Diffie-Helman key exchange. [27:44.370 --> 27:45.650] I will explain it to you. [27:45.790 --> 27:46.090] Oh, okay. [27:46.090 --> 27:50.610] I can show you a slide that I'm not demoing now that I can show you that explains the Diffie-Helman key exchange. [27:50.710 --> 27:53.250] Okay, so you went through a third party in the Internet? [27:53.390 --> 27:53.410] No. [27:53.410 --> 27:54.370] I'll explain it to you. [27:54.530 --> 27:54.810] Okay. [27:54.950 --> 27:55.130] Okay? [27:55.390 --> 27:55.530] Okay. [27:55.530 --> 27:56.090] But... [27:56.090 --> 27:57.550] Well, just answer this question for me then. [27:58.550 --> 28:08.190] If, like, you did this at a corporation that was storing all the instant message traffic and later somebody took that and analyzed it, they would not be able to get that key then, right? [28:08.350 --> 28:08.590] No. [28:08.850 --> 28:09.230] They would not. [28:09.330 --> 28:10.330] You're not transmitting the key. [28:14.880 --> 28:16.940] I just had a quick question. [28:17.120 --> 28:18.560] Does the fingerprint change? [28:19.800 --> 28:23.020] Like, say, the fingerprint that popped up that you verify on the phone. [28:23.020 --> 28:24.820] How often will that change? [28:25.620 --> 28:29.780] In principle, it will never change unless you delete your private key. [28:30.160 --> 28:35.640] However, sometimes, and this actually happens quite a lot, is that people will use different clients, different computers. [28:35.820 --> 28:37.580] They will log in from home or from work. [28:37.720 --> 28:43.280] So they will have multiple keys and multiple fingerprints associated with one instant message account. [28:43.740 --> 28:48.540] So is that something you'd want to have on, like, your business card along with your, like, PGP key? [28:49.840 --> 28:54.080] You could, but then you really have to be careful on not losing that key. [28:54.320 --> 29:00.740] It's, in general, because people use instant messages from a lot of machines they don't trust, you tend not to do it. [29:00.860 --> 29:02.380] You don't put that much... [29:02.380 --> 29:05.100] It's not like a PGP key that you'll use for five years. [29:06.060 --> 29:09.640] People tend to sort of quickly go through these kind of keys. [29:10.340 --> 29:11.980] And just one last one. [29:12.160 --> 29:16.280] How is it a lot more secure than the Secure.i.am that's built into Trillium? [29:16.280 --> 29:17.440] Secure.i.am is not secure. [29:17.620 --> 29:18.300] Okay, thank you. [29:22.000 --> 29:30.920] How secure would it be if both of you, instead of doing it this way, if both of you used Tor to connect between you and AIM, so that there wasn't... [29:30.920 --> 29:31.300] Sure, okay. [29:31.380 --> 29:34.320] You've just postponed the problem where I need to verify the Tor connection. [29:34.680 --> 29:37.320] Like, at some point I will need to do this verification somehow. [29:38.680 --> 29:38.880] All right. [29:38.980 --> 29:42.380] Because it makes it more difficult because they're, you know, they have a roaming target. [29:42.840 --> 29:51.860] You know, I mean, they'd have to either be immediately between your local machine and the first Tor node that you connect to. [29:52.080 --> 29:55.540] Which means, you know, that's being done, like, on your local machine. [29:55.540 --> 29:57.740] So even if it's encrypted within your local network. [29:57.900 --> 29:58.880] So even if they were... [29:58.880 --> 30:01.180] Sure, but if I'm sitting at Starbucks, it's not really going to help me. [30:01.920 --> 30:04.440] So it's still wireless and everybody can still see the first hop. [30:05.940 --> 30:08.260] You should never trust the network. [30:08.420 --> 30:09.520] Always check out of bounds. [30:09.720 --> 30:10.220] There's no... [30:10.220 --> 30:11.420] There's nothing around this. [30:11.600 --> 30:12.840] There's no way around this. [30:13.060 --> 30:13.460] Yeah. [30:13.520 --> 30:15.820] You must do an out of bound check on your key. [30:16.400 --> 30:18.160] And also, this doesn't... [30:18.160 --> 30:19.840] The problem of... [30:19.840 --> 30:21.440] I mean, yeah, this is great for if... [30:22.160 --> 30:23.460] You know, this is... [30:23.460 --> 30:24.300] AIM has... [30:24.300 --> 30:29.360] You know, if you're actually talking to somebody and you're trying to encrypt your connection, this is great. [30:29.540 --> 30:30.280] And it's nice and secure. [30:30.460 --> 30:35.100] But AIM also has this nasty problem with buddy images, where it does a direct connection. [30:35.420 --> 30:40.240] And so, you know, it gives whoever you're talking to your IP address. [30:40.400 --> 30:43.340] So if somebody IMs you cold, they have your IP. [30:45.000 --> 30:45.420] So... [30:45.420 --> 30:48.380] Sure, but if you don't use direct aim, then you don't have that issue. [30:49.200 --> 30:49.540] Yeah, okay. [30:49.540 --> 30:52.620] Like, it doesn't really matter who sees the traffic, right? [30:52.720 --> 30:53.600] Because it's all encrypted. [30:54.560 --> 30:55.780] So it shouldn't really matter. [30:56.000 --> 30:59.860] This is actually an entirely different thing that's sort of unrelated and I probably shouldn't have brought it up. [30:59.900 --> 31:01.020] Anyway, but... [31:03.400 --> 31:07.780] Okay, so I'll switch to iChat and demonstrate that. [31:08.220 --> 31:09.960] iChat is from Apple. [31:10.120 --> 31:10.840] It's a proprietary software. [31:10.980 --> 31:13.200] We can't really hook in our own things easily. [31:13.460 --> 31:22.820] So instead of what we've done, there's a program called OTR proxy, which basically puts all the functionality in this proxy program. [31:24.480 --> 31:26.540] So this is the output of the proxy. [31:28.040 --> 31:29.520] And I'll start iChat now. [31:29.920 --> 31:31.380] And I should close ADM. [31:46.830 --> 31:49.590] I would say this is a bit more difficult for your parents at home. [31:49.810 --> 31:54.370] But if you set it up for them, you can teach them to use this, you know, easily. [31:54.970 --> 31:57.150] It's easier to use than email, I guess. [31:59.090 --> 32:00.710] So you can still try it. [32:01.770 --> 32:03.490] It's a bit more difficult than with game. [32:04.510 --> 32:07.730] But still, OTR proxy is getting more and more better. [32:07.930 --> 32:12.790] You know, we need some more time to build a GUI in a way that everybody really understands it right off the box. [32:12.790 --> 32:16.770] But it's really difficult because everybody has a different understanding what a good GUI is. [32:17.830 --> 32:22.710] So we need a common ground there first before we can rebuild this tool. [32:24.130 --> 32:24.850] Okay, okay. [32:24.870 --> 32:25.990] So I've started iChat. [32:26.310 --> 32:27.850] This is just the standard iChat. [32:28.070 --> 32:29.090] Nothing is installed. [32:29.310 --> 32:29.970] No encryption. [32:31.050 --> 32:32.850] The OTR proxy has been started. [32:33.150 --> 32:36.650] And now the only thing you need to do is with iChat to say we should be using a proxy. [32:36.810 --> 32:37.590] So I'll go to preferences. [32:39.750 --> 32:41.870] And I'll have to have a look where... [32:43.170 --> 32:44.830] Go to server settings. [32:46.470 --> 32:46.950] And... [32:46.950 --> 32:47.830] Oh, I forgot about that. [32:47.970 --> 32:50.050] You have to be offline before you can change anything. [32:50.270 --> 32:51.490] So I will go offline. [32:54.640 --> 32:56.900] Now I can say connect using proxy. [32:57.440 --> 32:59.620] Local host support 8080 using HTTP. [33:00.580 --> 33:04.320] It also supports SOCKS5 and HTTPS, the proxy. [33:04.900 --> 33:06.580] Unfortunately, iChat is very buggy. [33:06.760 --> 33:08.000] So it doesn't actually work with it. [33:08.120 --> 33:09.760] So you have to use HTTP proxy. [33:11.780 --> 33:13.780] So once we've done that... [33:14.700 --> 33:20.840] I can go back online and I will go online via the OTR proxy that's running on my machine. [33:30.060 --> 33:30.520] Excellent. [33:30.780 --> 33:32.300] Could not connect to the AIM server. [33:35.720 --> 33:36.920] So we'll try this again. [33:46.970 --> 33:48.250] It's a new Jabber account. [33:54.540 --> 33:57.560] I'll try to reconnect to Jabber so that it will use the proxy as well. [33:59.660 --> 34:00.420] Okay, there we go. [34:00.720 --> 34:02.080] So now I'm online again with AIM. [34:04.500 --> 34:05.100] Yeah. [34:05.380 --> 34:06.920] And I can see Alice. [34:08.020 --> 34:09.500] So let's talk to Alice. [34:10.740 --> 34:12.480] Now we'll see two things happening. [34:22.320 --> 34:26.540] So we see here that in the OTR screen the proxy started. [34:26.800 --> 34:29.720] But I'm not seeing a private connection yet. [34:31.740 --> 34:33.800] Can you say something back? [34:42.610 --> 34:45.250] Okay, we see now that OTR proxy is generating the key. [34:45.470 --> 34:46.290] So this is a new key. [34:47.570 --> 34:51.230] Has no relationship to the other key even though we are using the same AIM account. [34:52.230 --> 34:53.550] So we have to go through this again. [34:53.970 --> 34:54.410] Hey, Aldert. [34:56.730 --> 34:58.090] I thought your name was Bob. [35:00.190 --> 35:00.850] That's true. [35:01.070 --> 35:02.750] But with a zero though, you are Bob. [35:04.250 --> 35:09.210] Okay, so the fingerprint starts with 3469CD8 blah blah blah blah and ends with DD. [35:11.330 --> 35:11.810] No. [35:15.430 --> 35:16.330] Okay, that's yours. [35:18.490 --> 35:21.370] Mine starts with the same. [35:21.610 --> 35:22.070] That's interesting. [35:25.950 --> 35:26.850] That's the same. [35:36.640 --> 35:38.420] So you're saying we've been man in the middle? [35:40.000 --> 35:41.020] That would be cool. [35:41.460 --> 35:42.400] You should come on stage. [35:51.910 --> 35:53.610] So obviously we should not trust this. [36:12.980 --> 36:14.700] I am seeing Bob. [36:15.130 --> 36:17.480] Bob, that's me, has received unknown fingerprint from Alice. [36:17.480 --> 36:18.440] So yeah, that's your key. [36:19.070 --> 36:20.460] Can you read your key, Aldert? [36:24.380 --> 36:24.780] Okay. [36:40.260 --> 36:44.580] So if you, if you, if you right click on the OTR button and game, you can get this menu. [36:44.600 --> 36:48.140] If you do verify fingerprint, you actually see your key and the other person's key. [36:48.140 --> 36:49.880] So now if I ask Aldert. [36:50.020 --> 36:50.460] Hi, Aldert. [36:50.560 --> 36:54.160] I think your key is 3469CDB and ends with DD. [36:54.960 --> 36:55.660] Yes, it is. [36:55.940 --> 36:56.300] Cool. [37:04.260 --> 37:08.180] The session ID you see here is also, you can also verify it by the session ID. [37:08.360 --> 37:12.080] And because these are these properties of the encrypted channel that I talked about earlier. [37:12.080 --> 37:15.560] If you verify this, it automatically means that you've also verified the key. [37:15.740 --> 37:18.340] Because there's no person in the middle. [37:20.520 --> 37:28.380] So now we, now we've, now we've accomplished the same thing with, with iChat without actually having, you know, native encryption capabilities in iChat. [37:29.460 --> 37:31.360] It's all done by the OTR proxy here. [37:33.900 --> 37:35.900] So again, from here on, we're completely encrypted. [37:41.020 --> 37:43.720] So any questions on instant message encryption? [37:45.120 --> 37:48.980] You can, you can force the encryption settings after you've done this once. [37:49.280 --> 37:52.180] You will, you will notice that the first message we sent was plain text. [37:52.360 --> 37:56.320] Because that triggers the OTR plugin to recognize that it can do cryptography. [37:57.060 --> 38:03.280] Once you've done this, you can, you can change your buddy setting to be always, always encrypt. [38:03.420 --> 38:06.320] So that you never send out a single plain text package. [38:07.060 --> 38:10.200] Maybe Aldit can demonstrate that on the, on game if it's readable. [38:12.280 --> 38:14.540] There you go, those are the default settings. [38:14.940 --> 38:18.120] And then you can change the default and say require private messaging. [38:18.540 --> 38:20.920] So now I could never talk to him and encrypt it. [38:21.080 --> 38:23.860] I'll, I'll see if I can demo this by turning off the proxy. [38:27.420 --> 38:29.940] And then actually you'll, yeah. [38:31.160 --> 38:33.520] So I have to go offline first. [38:37.310 --> 38:39.430] And I'll disable the proxy. [38:42.470 --> 38:43.750] I'll go back online. [38:46.590 --> 38:50.150] And I might as well terminate the proxy since I'm not using it. [38:54.500 --> 38:56.220] So connecting, connecting. [39:01.660 --> 39:03.760] Wow, do we only have 15 minutes left? [39:03.760 --> 39:05.200] Wow, we should raise. [39:10.340 --> 39:13.960] So now, again if I say something, it will be in plain text. [39:17.100 --> 39:19.780] But Aldit cannot prevent that because I'm just sending him a message. [39:19.920 --> 39:21.560] He can't prevent me from sending plain text. [39:21.680 --> 39:24.140] However, if he now types something, he should not be able to. [39:24.280 --> 39:25.860] And he should be blocked from typing it. [39:32.400 --> 39:34.780] Okay, so, so what happened here, it's, it's good to see. [39:34.780 --> 39:38.900] What happened here is that Alder did not know that I reconnected and disabled my OTR. [39:39.240 --> 39:42.620] So he's just sending me an encrypted message because he doesn't know any better than that. [39:42.760 --> 39:44.240] You know, we are still talking encrypted. [39:45.120 --> 39:46.820] So at this point I go like, no. [39:49.780 --> 39:52.660] And he should end his private connection. [39:53.540 --> 39:55.680] You can do that with the OTR button as well. [39:55.820 --> 39:59.220] You go right click and end private conversation. [40:01.680 --> 40:05.460] And then what we see is that it immediately tries to initiate OTR. [40:06.980 --> 40:10.520] And in this case, I get a helpful link saying, oh, you should download OTR here. [40:14.120 --> 40:20.100] So Aldit will still receive plain text messages, but he can't send them because he's configured his client to only send encrypted. [40:21.780 --> 40:27.460] Okay, I'll race through our next step because we only have 10 minutes even. [40:27.640 --> 40:28.120] That's cheating. [40:28.340 --> 40:30.020] My laptop says I have 15 minutes. [40:30.660 --> 40:31.820] Mine says 17. [40:34.780 --> 40:39.800] Okay, so I will quickly show how to encrypt your browser, your browsing traffic. [40:45.060 --> 40:48.780] It involves installing Tor, which is a package which I've already installed here. [40:49.300 --> 40:51.220] I think most people know Tor by now. [40:52.280 --> 40:53.860] How many people do use Tor? [40:56.790 --> 40:59.050] Please don't use it for torrents. [40:59.530 --> 41:01.190] Don't download over Tor. [41:01.450 --> 41:02.630] That's just plain stupid. [41:02.930 --> 41:04.250] They will see your IP address anyway. [41:05.230 --> 41:09.390] What you do is in Firefox, you go to extensions, you get an extension. [41:10.350 --> 41:14.670] And in this case, I have the extension on file. [41:22.800 --> 41:30.280] Torrent is basically a way of shielding yourself from the other party, basically the website, to know who you are. [41:30.440 --> 41:31.700] I think most people know that by now. [41:32.840 --> 41:34.300] It's a very convenient way. [41:34.300 --> 41:41.660] It's a bit slow because the network is, you know, overburdened by people trying to actually download ISOs over it, which is, well, stupid. [41:42.060 --> 41:49.520] But you can still use it if you want to register your account without anybody knowing about it. [41:49.740 --> 41:54.560] Or you want to visit some websites that your government maybe not appreciate. [41:57.080 --> 42:00.200] How about we briefly switch because you've already installed the plugin. [42:00.540 --> 42:02.160] I cannot get an uplink actually going. [42:02.500 --> 42:04.420] So I can actually not go through the window. [42:04.720 --> 42:08.620] So we'll just switch the monitor screen to show the plugin. [42:18.090 --> 42:18.930] Does it work? [42:24.200 --> 42:25.140] Yeah, now it does. [42:26.520 --> 42:28.900] Well, welcome to Windows XP on the Mac OS. [42:30.760 --> 42:32.440] Okay, so all it will start Firefox. [42:34.480 --> 42:38.800] And he has done the get extensions and he's gotten the... what was the name again? [42:39.520 --> 42:41.180] I'm actually not going to show the installation. [42:41.400 --> 42:44.440] The installation is really like you press the next button five times. [42:44.440 --> 42:47.440] You go to tor.eff.org, you download it. [42:47.580 --> 42:49.320] It's incredibly easy to install. [42:49.780 --> 42:50.600] Just install it. [42:51.000 --> 42:51.860] You reboot your computer. [42:52.200 --> 42:55.380] Everything is set up for different OS's. [42:55.600 --> 42:56.480] It's so easy. [42:57.200 --> 43:03.300] And then you'll find the extension called Tor Button, which I have here, but I can't actually double click it, but I want to start up in Firefox. [43:04.000 --> 43:05.020] So I'll let us down that. [43:05.340 --> 43:10.340] He's already included the Tor Button extension, then restart his browse. [43:10.340 --> 43:17.820] And then you'll notice at the bottom right, you'll see it says Tor disengaged. [43:19.080 --> 43:19.480] Disabled. [43:20.160 --> 43:20.940] Oh, you can see it. [43:21.080 --> 43:21.200] Hold on. [43:22.280 --> 43:24.640] Can you make your browser a little bit? [43:25.800 --> 43:26.600] Oh, is that so? [43:26.700 --> 43:26.840] Yeah. [43:28.960 --> 43:29.900] It's a bit too small. [43:30.100 --> 43:30.780] Yeah, yeah, yeah, yeah. [43:34.120 --> 43:34.720] Okay, yeah. [43:34.860 --> 43:35.520] Can you see this? [43:36.040 --> 43:37.700] So now you see Tor disabled. [43:38.220 --> 43:41.480] So if he goes to ip.accelerance.com? [43:41.860 --> 43:43.260] The network is that slow. [43:43.520 --> 43:44.460] I cannot connect to anything. [43:44.760 --> 43:46.420] I can only show you how it should work. [43:47.600 --> 43:54.580] So basically, I've installed this little button here, or default in your browser over here. [43:55.360 --> 43:56.460] Standard is disabled. [43:56.460 --> 44:08.520] You go to a website, like an IP checker, like what's my ip.com, you will see that if you then first have it disabled, you have your own ADL line or whatever cable IP address. [44:08.740 --> 44:17.380] The moment you start enabling it, and you refresh your page for what's my ip.com, you will see that you have a different IP address, and you're using Tor. [44:17.520 --> 44:18.780] That's the way how to verify it. [44:19.880 --> 44:22.040] And it runs basically out of the box. [44:24.790 --> 44:29.310] But I cannot show you it right now, because the network is really too slow. [44:29.830 --> 44:29.930] Sorry. [44:38.590 --> 44:43.230] So since we can't show things live anyway, I'll show another thing we can't show live. [44:51.100 --> 44:53.160] Which is to encrypt your VoIP calls. [44:53.440 --> 44:54.440] This is Gizmo. [44:54.440 --> 45:00.320] It's a free client available on OSX and Windows, and Linux as well. [45:00.820 --> 45:01.600] It's a SIP client. [45:01.800 --> 45:03.700] SIP is a standard protocol to do VoIP with. [45:04.380 --> 45:06.060] There's a tool called Z phone. [45:08.740 --> 45:14.660] And what this does is it's capturing all the SIP packets, and then encrypting them. [45:15.220 --> 45:19.760] What happens if, of course, I have the same problem, I can't really connect to anything. [45:20.240 --> 45:23.160] As soon as I connect, this window will show insecure. [45:23.160 --> 45:28.120] If I then start a VoIP call with anybody, it will show insecure. [45:28.340 --> 45:29.880] And I can go to click secure. [45:30.460 --> 45:41.680] If the other end runs Z phone as well, there will be two numbers appearing here in the boxes, which are the Diffie-Hellman key numbers, which is the fingerprint of the key. [45:41.940 --> 45:48.180] So since this is a VoIP call, and we know each other's voice, we actually don't have to pick up another phone. [45:48.320 --> 45:49.500] We just use the same connection. [45:49.500 --> 45:52.790] And we say, hi, the numbers I'm hearing is blah, blah, blah, blah, blah. [45:52.960 --> 46:00.180] And since I know Aldert's voice, I can trust that, you know, Mallory's not, you know, repeating different numbers using Aldert's voice. [46:01.480 --> 46:08.460] And then, once we verify these numbers, we're safe to go and we can talk, and we know that nobody's listening in on our voice calls. [46:09.320 --> 46:15.340] This does not work with Skype, because Skype is doing evil things to hide everything it can from the network. [46:15.340 --> 46:16.980] So it's not possible to use this for Skype. [46:18.120 --> 46:19.520] So that's VoIP. [46:20.320 --> 46:26.640] And then the last thing on our list was encryption with Thunderbird for email. [46:26.880 --> 46:28.640] But I think we really ran out of time for that. [46:29.020 --> 46:30.680] Unless Aldert can do this in two seconds. [46:30.920 --> 46:31.290] Yeah, sure. [46:31.500 --> 46:31.660] Okay. [46:31.960 --> 46:33.100] And Aldert will do this in two seconds. [46:33.980 --> 46:35.020] Give me the connection, Mark. [46:42.810 --> 46:49.910] So Thunderbird is a wonderful tool, because they make all these extensions, and we have these great people that built the adding mail extension. [46:50.190 --> 46:51.210] Do you know people about it? [46:52.150 --> 46:55.830] It's the possibility to tie PGP into your Thunderbird. [46:56.770 --> 47:01.950] If you just install, you go to the website, the extension website of Thunderbird, you install it. [47:02.430 --> 47:03.850] Basically, you get an extra menu. [47:05.370 --> 47:10.130] This one, you have to think about it, that you also need GPG. [47:10.330 --> 47:14.830] So you have to go to the GPG website, and also download GPG and install that. [47:15.130 --> 47:16.730] It's all out of the box again. [47:16.730 --> 47:17.990] And next, next, next, next, next, next. [47:18.110 --> 47:18.730] And you're done. [47:22.270 --> 47:24.070] ANIC mail, that's the extension. [47:25.190 --> 47:25.990] And GPG... [47:27.170 --> 47:27.930] Oh, sorry. [47:28.110 --> 47:28.610] My accent. [47:29.170 --> 47:31.410] And my voice is killing me, so... [47:35.360 --> 47:43.580] For those who have a Mac, if you look at the smaller project, I'm just installing GPG mail on mail.app, and I will hopefully show some of the same things without talking too much. [47:51.320 --> 48:05.660] So basically, the only thing you need to do is after you installed Thunderbird, the ENIC mail extension in GPG, is to create a key, so that you, you know, have something where you can encrypt your messages with, or you can have other people encrypt messages with, [48:05.760 --> 48:06.300] they're sent to you. [48:06.980 --> 48:08.600] So you have a key management, [48:11.880 --> 48:14.940] where the only thing you have to do is say, I want a new key. [48:27.450 --> 48:33.070] A passphrase, which is needed, so that you can protect your key, so that other people cannot actually start using your key when they find your key. [48:39.800 --> 48:53.900] This takes a little while, but basically the main thing is, the moment you have GPG and your key, you can start encrypting your emails to other people and the other way around, because you can, everything that you need, like to download keys from key servers, [48:54.140 --> 48:56.000] is all embedded already in the extension. [48:56.420 --> 49:03.800] So all the stuff that you used to do on the command prompt on your OS, is now something that's all tied into a GUI. [49:03.800 --> 49:05.220] It's pretty awesome. [49:24.030 --> 49:30.810] I cannot show you now how to send an email encrypted exactly, because the wireless is really not working for me. [49:31.150 --> 49:34.030] But trust me, you have all kinds of buttons. [49:34.290 --> 49:35.470] I can show you a little bit. [49:38.560 --> 49:42.200] We're happy to show this later on, if there's spots where we can have network access. [49:42.380 --> 49:45.640] So just, you know, grab us from the hallway and we'll show how easy it is. [49:49.740 --> 49:51.640] There's the little button here, open GPG. [49:51.640 --> 50:06.500] If you just say encrypt and press OK, and you have the key of Bob already on your machine, in your key chain, or your key management utility of Enigmail, you can start sending encrypted emails and receiving them at the same time. [50:06.780 --> 50:12.680] So it's really not difficult that you need to install and configure all kinds of difficult things with command lines. [50:12.880 --> 50:14.280] It's really like all in the GUI. [50:14.420 --> 50:16.200] Click, click, click, click, click, and you're there. [50:16.560 --> 50:17.880] It's really easy. [50:20.700 --> 50:22.360] And I will, if you have a question. [50:27.370 --> 50:30.730] What happens when you get your mail at different machines? [50:31.250 --> 50:33.330] You've got your key on this machine, for example. [50:33.470 --> 50:36.510] Let's say that's your office machine, but, you know, you got a home machine. [50:37.030 --> 50:40.510] But your mail in general is sort of all over the place. [50:40.770 --> 50:48.670] Well, I guess that, you know, your personal encrypted email is something you don't want to read at work, because the machine at work is from, you know, the business at work. [50:49.450 --> 50:53.570] You don't want them to own anything that's really private and personal to you. [50:53.810 --> 50:59.390] So I would recommend to actually start a second email address that you use only at home. [50:59.970 --> 51:07.850] And another address maybe where people, so that people know, okay, if you want to send you something encrypted, then send it to the second email address, if that's your situation. [51:08.450 --> 51:10.330] For me, I carry my laptop around. [51:10.470 --> 51:11.070] That is my office. [51:11.190 --> 51:11.770] That is my home. [51:12.290 --> 51:16.250] If I go and be a consultant and work somewhere else, I work from this laptop. [51:17.390 --> 51:18.570] So, for me, it's easy. [51:20.070 --> 51:24.970] For people who are in this deadline, should I bring my key to work? [51:25.130 --> 51:27.230] I would say, no, don't do it. [51:30.800 --> 51:32.300] If you trust... [51:32.300 --> 51:33.820] Do you trust all three computers? [51:33.960 --> 51:35.920] Do you keep them all up to date with all the software? [51:36.540 --> 51:38.580] Well, then you just install the keys on all three of them. [51:38.680 --> 51:39.620] Yeah, then you copy the keys. [51:42.360 --> 51:43.880] Yeah, you can export and import all the keys. [51:43.880 --> 51:44.720] It's export and import. [51:45.140 --> 51:49.480] It's just like, you know, you know how to transfer your bookmarks from one computer to the other one. [51:50.300 --> 51:51.400] This is just like that. [51:51.600 --> 51:52.480] It's really easy. [51:52.680 --> 51:53.860] On the screen now, you can see this. [51:54.000 --> 51:58.260] I quickly installed GNUPG on the Mac and GPG mail. [51:58.420 --> 52:00.740] And this is mail app on the Mac. [52:00.920 --> 52:02.820] It just got an extra menu. [52:06.360 --> 52:07.660] An extra menu here. [52:08.020 --> 52:09.280] PGP for the configuration. [52:09.880 --> 52:11.440] And you can configure everything as well. [52:11.980 --> 52:13.080] We really have to stop now. [52:13.560 --> 52:15.980] But we'll take these two questions and then we'll stop. [52:16.260 --> 52:18.720] I just had a question about the browsing encryption. [52:18.900 --> 52:19.960] Have you used Tor or something? [52:20.260 --> 52:22.680] Won't your ISP still have records of everything? [52:23.640 --> 52:25.760] Or is that encrypted to them too? [52:26.180 --> 52:27.200] Yes, it's encrypted. [52:28.540 --> 52:32.220] You start encryption to the first node and then you go through the Tor network. [52:32.220 --> 52:36.180] Your ISP knows your connection between you and your first Tor node. [52:36.780 --> 52:38.020] And after that, they don't know. [52:38.340 --> 52:39.060] But, yeah. [52:40.000 --> 52:45.280] How do you use this perfect forward security or secrecy that you named in the chat client? [52:45.500 --> 52:47.640] What do you have to delete or what do you have to remove? [52:48.540 --> 52:51.140] Sorry, you don't understand perfect forward secrecy? [52:51.220 --> 52:51.940] I guess I don't. [52:51.980 --> 52:53.580] How do you use it with the chat that you showed? [52:53.760 --> 52:55.560] Or how do you make sure people can... [52:56.240 --> 53:04.300] With the chat client, it generates a new key for every message and then it leaks part of the key so that people can force messages in the past. [53:04.940 --> 53:07.380] So, every message actually has a new key. [53:08.420 --> 53:13.940] So, it doesn't use a session key like, like, like, for instance, IPsec or SSH does. [53:15.220 --> 53:16.860] But I can explain it to you in the hallway. [53:17.040 --> 53:17.640] Okay, thank you. [53:18.880 --> 53:20.020] Any other questions? [53:22.460 --> 53:27.480] Okay, since we couldn't really demo everything, we'd love to, you know, help you demo it somewhere else. [53:27.600 --> 53:30.260] So, just, you know, catch us and we'll help you. [53:30.860 --> 53:31.260] Okay. [53:31.260 --> 53:32.860] Next year, we will do a two-hour session. [53:32.860 --> 53:32.940] Thanks, Johan! [53:33.060 --> 53:33.100] Thanks, Johan. [53:33.100 --> 53:33.140] Thanks, thanks, everyone. [53:33.140 --> 53:33.180] Thank you. [53:33.180 --> 53:33.440] And hopefully Thank you. [53:33.460 --> 53:33.480] Thanks. [53:33.760 --> 53:33.840] Thank you.