[00:00.000 --> 00:05.640] ...that literally loads a kernel image in your web browser and runs it pretty quickly. [00:05.780 --> 00:06.760] There's a Game Boy emulator. [00:07.060 --> 00:15.980] Very recently, there's a BitTorrent client that does all the fancy network stocketing things that BitTorrent does and all in your browser, which I found really fascinating. [00:16.200 --> 00:19.240] And this was all done in JavaScript. [00:21.500 --> 00:26.420] So my wonderful idea was encrypted Google Docs. [00:26.520 --> 00:27.040] Why not? [00:27.240 --> 00:28.200] Encrypted Google Talk. [00:28.260 --> 00:28.760] Why not? [00:28.880 --> 00:39.120] Because you could have... I mean, why not investigate the area of encrypting things in the browser so that all of these services that everyone is using for all of their data can be encrypted by default. [00:39.280 --> 00:43.560] In the sense that the user would not even be aware that that was happening because they didn't need to be. [00:44.080 --> 00:54.700] And there was an issue also that, well, you could argue that Google and Facebook would never do this because Facebook depends on your data to make money and that's a very valid argument. [00:54.860 --> 00:58.220] But there are a couple of services out there such as Google Docs. [00:58.360 --> 01:03.880] And Google doesn't depend on the context of your PowerPoint presentation, but more in the volume of the PowerPoint presentations that it has. [01:04.020 --> 01:10.120] And so if you encrypt it, that actually might be okay with them because it also saves them the illegal overhead. [01:11.300 --> 01:20.380] And so it's possible to, for me, it appeared at the time that it was possible to have client-side encryption for those easy accessible services. [01:20.880 --> 01:21.620] And, you know, why not? [01:21.780 --> 01:22.360] Let's do it. [01:22.420 --> 01:23.180] What a great idea, right? [01:23.280 --> 01:24.000] I was so excited. [01:24.180 --> 01:24.960] I tend to get excited. [01:26.260 --> 01:28.780] So that was more than a year ago. [01:28.780 --> 01:34.180] And at the time we had some rudimentary client-side crypto for browsers in JavaScript. [01:35.600 --> 01:44.320] And woefully lacking in terms of quality and necessarily not in terms of numbers, because we had a lot of those things and we still do. [01:45.240 --> 01:49.300] That was a year ago, more than a year ago, a year or two months ago. [01:50.020 --> 01:52.380] And to top it off, this was a new and experimental field. [01:52.920 --> 01:58.440] Their, you know, browser, client-side browser crypto wasn't exactly something that everyone was worrying about. [01:58.580 --> 02:07.380] People were more busy worrying about HTTPS, which is, uh, end-to-end encryption that does not actually encrypt the information that you're storing on the server. [02:07.500 --> 02:13.480] It only encrypts it as it arrives to the server as it goes through the web or through the Internet. [02:14.360 --> 02:17.460] And so everyone hated this field because the problems in it were too numerous. [02:17.580 --> 02:18.740] And I'll be discussing these problems today. [02:19.540 --> 02:20.560] But what the heck? [02:20.820 --> 02:22.620] I like cats. [02:22.760 --> 02:23.280] Cats are great. [02:23.460 --> 02:30.360] And so I created a project called Cryptocat to combine my love for cryptography and cats. [02:30.600 --> 02:33.760] It was a pure vision of childhood innocence. [02:36.360 --> 02:43.580] And I had starry looks in my eyes as I stared upon the horizon and thought that one day my project would be something great that everyone would love. [02:46.520 --> 02:48.380] So Cryptocat was my experiment. [02:48.680 --> 02:51.720] It was to create an accessible, you know, OTR, right? [02:51.800 --> 02:52.840] Raise your hand if you've used OTR. [02:53.580 --> 02:54.020] Okay. [02:54.500 --> 02:56.940] Keep your hand raised if you're a journalist who's used OTR. [02:58.360 --> 02:59.860] Whoa, two hands? [03:00.440 --> 03:00.880] Okay. [03:01.360 --> 03:05.380] Um, so the point here is that, you know, we're all hackers. [03:05.640 --> 03:06.000] It's great. [03:06.160 --> 03:07.180] We all like how to use OTR. [03:07.460 --> 03:10.280] We're all very smart with our crypto and our audited spec. [03:10.280 --> 03:14.220] And so those are obviously, I mean, very important things, extremely important things. [03:14.360 --> 03:24.220] But I come from... so let me tell you a story, a miserable story about how when I tried to go to the Middle East and tell people how to use OTR. [03:24.320 --> 03:24.560] And I did. [03:24.620 --> 03:25.320] And it worked fine. [03:25.400 --> 03:26.780] They all knew how to use OTR. [03:27.200 --> 03:28.180] And they did not. [03:28.640 --> 03:35.680] Not because I suck as a teacher, but because OTR is not accessible. [03:35.900 --> 03:37.500] It's not a pleasure to use. [03:37.620 --> 03:42.460] You have to download Pigeon, install OTR as a plugin, configure it, verify fingerprints, make sure that the other party... and that's the biggest thing. [03:42.600 --> 03:44.640] Make sure that the other party does the exact same thing. [03:45.040 --> 03:48.200] And in many cases, the other party isn't someone you've given an OTR workshop to. [03:48.700 --> 04:02.640] So that's not exactly conducive to a revolution where everyone can communicate openly because communicating is basically like passing the U.S. border when it comes to being able to do it with someone else. [04:05.380 --> 04:07.280] So the point was that to make it accessible. [04:08.000 --> 04:09.260] In the browser, you just open. [04:09.360 --> 04:10.360] You can send a link to someone. [04:10.440 --> 04:11.000] You have a chat room. [04:11.040 --> 04:13.220] It's encrypted with an OTR-like protocol. [04:13.740 --> 04:14.400] And it works. [04:14.400 --> 04:15.260] And it's secure. [04:15.300 --> 04:16.120] And it's client-side encryption. [04:16.180 --> 04:17.560] And it works exactly like Pigeon OTR. [04:18.260 --> 04:32.240] And also, and this is very important, realizing early on that this was an experimental field, I thought that my project would be a testbed to test solutions and see what works and produce solutions that work for other projects too and for the field in general. [04:33.900 --> 04:35.360] But there were so many problems. [04:35.600 --> 04:42.840] Not only did browser cryptography totally suck at the time, but this was your reaction to what I did for the past year. [04:44.700 --> 04:46.260] So thanks a lot for that. [04:49.180 --> 04:50.160] Was it justified? [04:50.320 --> 04:50.460] Yes. [04:51.580 --> 04:54.660] Multi-party encrypted messaging in the browser. [04:54.960 --> 04:56.540] With these primitives, I must be crazy. [04:56.740 --> 04:57.440] And I might be. [04:57.600 --> 04:58.720] I totally was at the time. [04:59.260 --> 05:01.220] It wasn't a feasible idea. [05:01.360 --> 05:02.080] It was an experiment. [05:02.320 --> 05:09.320] It was the product of an idealism of what computers could be, which I believe is extremely important, but definitely not what computers were at the time. [05:10.820 --> 05:12.140] The problems, finally. [05:12.380 --> 05:13.100] Code delivery. [05:13.380 --> 05:19.520] Delivering the code from the website, from the web app to your browser. [05:20.780 --> 05:22.460] Is it safe to do that? [05:22.460 --> 05:24.520] Is the code going to get modified on the way? [05:24.680 --> 05:26.360] Is it going to get modified before it's sent? [05:27.240 --> 05:27.780] These are interesting. [05:28.040 --> 05:29.960] What if I, you know, yeah, yeah, yeah, yeah. [05:30.020 --> 05:36.700] I will modify everyone's JavaScript code and, you know, send that to... It's totally possible that I would do that from a security perspective. [05:36.700 --> 05:39.480] And it's reasonable to have safeguards against me doing that. [05:39.600 --> 05:41.080] Because the difference... And I'll get to that in a bit. [05:41.540 --> 05:42.980] And also random number generation. [05:43.260 --> 05:45.840] So JavaScript relies on the current time to generate random numbers. [05:45.980 --> 05:46.560] Cool story, bro. [05:47.700 --> 05:48.580] Cryptographic primitives. [05:48.980 --> 05:50.060] I'll speak about that. [05:50.560 --> 05:56.820] Browser sandboxing means basically that every tab in the browser has to be a different CPU thread. [05:57.400 --> 05:59.180] Basically how operating systems work. [05:59.300 --> 06:06.200] And if it's not, then a simple XSS in one tab can result in a complete crypto compromise in the other, which is terrible. [06:06.360 --> 06:09.160] And there were no standards in the sense that there wasn't exactly a great library. [06:09.340 --> 06:12.520] If you discount the work at the time, now there's more than one good library. [06:12.660 --> 06:17.360] But at the time, the only one was the Stanford crypto library, which was by Emily Stark, I believe. [06:17.460 --> 06:17.940] It was pretty good. [06:20.420 --> 06:23.680] So, let's go into depth into these problems. [06:23.820 --> 06:24.320] Code delivery. [06:24.600 --> 06:25.860] Does anyone remember Hushmail? [06:26.880 --> 06:27.320] Yeah. [06:27.780 --> 06:29.180] So, this is a great example actually. [06:29.360 --> 06:32.980] Because Hushmail offered encrypted email. [06:33.780 --> 06:35.200] And it worked in the browser. [06:35.540 --> 06:40.220] And it was supposedly private, all encrypted as it's stored and also as it's sent to other Hushmail accounts. [06:41.120 --> 06:49.680] And what they did was an early form of client-side crypto that used the Java applet, which was really horrendous from an efficiency point of view. [06:50.100 --> 07:00.340] But anyway, and they apparently did as they were, did as they claimed until they got approached by the federal agencies and they wiretapped everyone. [07:00.760 --> 07:01.840] Just like that. [07:02.240 --> 07:07.900] And this is a terrible example to give. [07:08.120 --> 07:12.820] Well, it's a good example to give about the terribleness of the problems with code delivery. [07:13.060 --> 07:17.060] So, when you download Tor, you download it, you install it once, and you're done. [07:17.520 --> 07:19.660] When you download Pigeon, you download, install it once, and you're done. [07:19.720 --> 07:23.040] But when using a web app, you're downloading it from scratch every time you open the website. [07:23.480 --> 07:28.660] And so, when you download Tor, there's only time for the code poisoning to occur when you're downloading. [07:28.800 --> 07:30.640] And then you verify the hash or whatever, and then you're fine. [07:30.740 --> 07:46.640] But you have to verify Every single time you open Cryptocat or whatever, any other encrypted Google Docs, SuperCrypto, Facebook, I don't know, whenever you download, whenever you open your encrypted dating website, you have to verify it. [07:47.620 --> 07:51.220] Another problem, random number generation. [07:51.560 --> 08:01.880] So MathOrRandom uses the current time proceeding, and some browser crypto libraries, libraries at the time, used that for randomness, which made me very eager to see it. [08:01.880 --> 08:04.780] I wanted to test the structural integrity of the nearest wall using my head. [08:08.420 --> 08:23.360] But a perfect storm was brewing, at least from my perspective, and there were many technologies, as technologies tend to crop up, to propel this platform into something better, at least better than what it was, which, I mean, was quite terrible. [08:23.540 --> 08:25.460] So we were able to solve a lot of problems. [08:25.780 --> 08:27.120] So code delivery. [08:27.460 --> 08:30.140] Is HTTPS good enough to solve the problem of code delivery? [08:30.320 --> 08:30.540] No. [08:30.540 --> 08:36.180] Because HTTPS makes it harder for people to poison the code as it's arriving to you. [08:36.340 --> 08:37.200] But what if I do it? [08:37.700 --> 08:41.560] I mean, I could easily... and HTTPS would have no effect whatsoever. [08:42.040 --> 08:45.000] There's also problems with certificate authorities in HTTPS. [08:45.000 --> 08:56.280] So, which means that, uh, random kid in Iran was capable of, literally, getting root CA, like, root certificates for half the Internet, including Google. [08:56.400 --> 08:57.440] It was really scary. [08:57.660 --> 09:00.220] Thanks to the Komodo hack, which happened, I believe, a year and a half ago. [09:02.560 --> 09:12.120] But, Chrome, Google Chrome, and I believe, which I believe is the best browser in the world right now, uh, had implemented local apps recently, which meant that, uh, just... [09:12.120 --> 09:22.600] And I believe they did this for Chrome OS, uh, which is just so that as you can install an app in your computer, on your Mac, or on your Windows or Linux machine, you could also download and install an app in your browser and work exactly the same way. [09:22.600 --> 09:29.720] It'd be sandboxed into its own CPU thread, it'll be... it'll load locally just as... and so your browser handles apps the way an operating system handles apps. [09:30.280 --> 09:33.640] And, obviously, this ties into Chrome OS in obvious ways. [09:34.240 --> 09:36.100] And so, Cryptocat became a Chrome app. [09:36.200 --> 09:39.940] And that solved the problem of code delivery, in my view, completely. [09:41.880 --> 09:49.540] Because it just worked the same as Pigeon or Tor, and, you know, just as I said before, and that was very... a very feasible way to solve the problem. [09:49.540 --> 10:04.140] And not only did Chrome, uh, actually just... I mean, the advantages of local apps are actually more than what they seem to be, especially with the recent release of Manifest version 2, which, uh, prohibits certain eval statements and, uh, inline JavaScript code and makes it, [10:04.200 --> 10:07.620] you know, really tight in security in ways that I find very creative and very effective. [10:07.840 --> 10:10.700] And I really have a lot of respect for the security work that people do at Google Chrome. [10:11.840 --> 10:13.100] Um, yes. [10:14.020 --> 10:15.280] So, yeah. [10:15.980 --> 10:17.460] Oh, I think I already went through this. [10:17.460 --> 10:21.860] So, so Chrome loads it, loads the code securely in its own thread. [10:22.120 --> 10:26.180] And we were suddenly mimicking a regular IM client very closely in terms of code delivery. [10:27.920 --> 10:29.360] Um, yeah. [10:29.700 --> 10:30.380] Math.random. [10:30.680 --> 10:32.760] Uh, so forget about that. [10:32.920 --> 10:42.780] We implemented, um, Bruce Schneier's random number generator, Fortuna, which is a cryptographically secure random number generator implemented in JavaScript. [10:42.780 --> 10:44.260] And there's a library for that out there. [10:44.260 --> 10:46.200] It's not particularly difficult to implement either. [10:47.360 --> 10:53.920] And so what happens is that you just use that and it, it has its own and it completely discards math.random. [10:54.040 --> 11:02.160] And then, uh, Google Chrome went and implemented their own random number generator, which actually gets its data from dev random, which is pretty good. [11:02.340 --> 11:03.040] Not too bad. [11:03.240 --> 11:07.960] Uh, certainly a lot better than math.random. [11:07.960 --> 11:11.360] And so seeding the cryptographic random number generators. [11:11.520 --> 11:19.380] Seeding means that, I mean, in, in, in computers, unless you're using quantum computers or quantum state, uh, you know, hardware, you don't have true randomness. [11:19.440 --> 11:25.240] And so you have to give it something that's really random, some, some randomly produced data for it to use it to produce randomness. [11:25.260 --> 11:27.440] And we call this the seed because I'm sure a lot of you know this. [11:28.160 --> 11:32.840] Um, not an issue of using window.crypto.getrandom since it uses that random and it's self seeded. [11:32.840 --> 11:33.680] And that's no problem. [11:33.880 --> 11:36.940] So Chrome and Safari are done and Firefox soon, apparently. [11:37.200 --> 11:37.780] I hope so. [11:38.100 --> 11:38.680] Firefox devs. [11:39.020 --> 11:48.920] Um, but for Fortuna, there's a whole bunch of things that exist in the browser that you can use for, uh, seeding, uh, a random number generator that you wouldn't think of. [11:49.200 --> 11:59.740] Uh, keyboard input, key press, depress timings, as in the time between pressing and depressing a key, every key, uh, mouse movement, obviously variable state and a window position and so on and so forth. [12:00.220 --> 12:10.840] Uh, on mobile phones, uh, we use the accelerometer, which literally meant that in order for your chat to be secure, you had to dance with your phone in the most unpredictable way possible. [12:12.620 --> 12:15.220] So, I, I think I did a good job at that myself. [12:19.570 --> 12:23.570] Um, so aside from that, crypto primitives. [12:24.350 --> 12:26.710] Um, we serve them within Cryptocat, obviously. [12:26.850 --> 12:28.090] I don't know why this is a slight point. [12:28.090 --> 12:31.830] Um, AES-CTR, uh, AES in CTR mode. [12:32.270 --> 12:33.090] It's SHA-512. [12:34.030 --> 12:36.670] And elliptic curve, uh, Diffie-Hellman and DSA. [12:36.930 --> 12:42.650] So, obviously, since we're doing things in JavaScript, doing things like 1496-bit Diffie-Hellman is a pain in the ass. [12:42.730 --> 12:44.950] And especially if you're doing RSA, because you have to generate two primes. [12:44.950 --> 12:58.510] But, um, elliptic curve crypto is actually smaller, a, a faster, a much like four times, to up to 15 times faster way of generating keys and public keys in the browser. [12:59.670 --> 13:01.310] And it's incredibly fast. [13:01.310 --> 13:10.590] In the sense that we can generate, uh, 512-bit keys, which is a very high, um, number of bits for elliptic curve, in the browser in, I believe, less than three seconds. [13:10.970 --> 13:20.970] So, that's really, I mean, it makes it so that these complex crypto operations work in the browser as if you're, I mean, at the same speed and efficiency as if you're working on a desktop client. [13:21.850 --> 13:30.350] Actually, it's faster than the OTR key generation process, even though the OTR key generation process, uh, in terms for, sorry, only in terms of the public key generation process. [13:30.350 --> 13:34.490] Not, not, not, not the, not the rest of OTR, because that's another story. [13:34.750 --> 13:41.790] But, the, specifically, the Diffie-Hellman key generation process, ours, even though it's safer, is actually faster, and even though it's being done in the browser. [13:44.550 --> 13:46.770] Um, what about the protocol? [13:47.010 --> 13:51.930] So, uh, we didn't handle this as well as I, as well as we could have. [13:52.050 --> 13:56.730] Our protocol, we rolled our own, but it's, it's specified and somewhat peer-reviewed by some respected people. [13:57.090 --> 14:02.530] Um, but we still rolled our own, and we could have, we could have went with implementing OTR. [14:03.450 --> 14:07.990] And that would have been helpful, because we'd have an OTR library in JavaScript, so that everyone else could implement OTR. [14:08.130 --> 14:13.790] But, uh, the, why we didn't do that, because OTR was, uh, not... [14:13.790 --> 14:21.130] At the time, I was focusing on more features, and so I wanted multi-party chat, I wanted image sharing, and file sharing, and all those things, and private messaging, et cetera, et cetera. [14:21.370 --> 14:22.150] And OTR didn't have that. [14:22.230 --> 14:24.230] OTR was just conversations between two people and nothing else. [14:24.230 --> 14:28.570] And so that's why we implemented our own, but something very special is coming up. [14:28.970 --> 14:30.630] MPOTR, and I'll be talking about that soon. [14:30.850 --> 14:31.930] It's gonna be awesome. [14:33.230 --> 14:49.890] So, uh, browser sandboxing remains a serious issue, but it's just as serious as a, it's just as serious an issue as anything that, uh, any Windows Oday that, you know, gets you access to any running process or any Mac Oday. [14:49.890 --> 14:53.810] At this level, it becomes this, it's never gonna not become a serious issue. [14:53.950 --> 15:02.530] And there's, um, evidence in Google, uh, so whatever Google offers a bajillion dollars to have work and break Google Chrome, Google Chrome gets broken in two minutes. [15:02.710 --> 15:04.830] Is it because Google Chrome can't be broken in two minutes? [15:04.950 --> 15:05.130] No. [15:05.310 --> 15:10.850] It's because someone shows up and demonstrates how it's broken in two minutes after having spent months on how to break it. [15:10.850 --> 15:15.930] And that time when that happened in Google Chrome's defense, and I only recently learned this when I was yesterday actually here. [15:18.190 --> 15:20.370] The time when that happened was the only time. [15:20.730 --> 15:26.970] And apparently it's involved chaining together seven Odays, which is something that I have never heard before in my life. [15:27.050 --> 15:28.850] I didn't know someone could bug chain seven Odays. [15:33.390 --> 15:34.930] So what have we accomplished? [15:35.210 --> 15:39.870] We have accomplished multi-party encrypted chat in the browser and on your phones. [15:40.590 --> 15:46.450] Uh, a homogenous code base that's easily deployable across servers, browsers, and phones. [15:46.550 --> 15:50.990] The same code base, which is, which speaks volumes in terms of accessibility. [15:51.250 --> 16:02.750] Because as I said earlier, uh, accessibility and making sure people in danger actually use your software instead of glancing at it and thinking it's too hard or too inaccessible or the other person won't know how to use it as happens a lot with PGP, for example, [16:03.010 --> 16:04.390] is an important facet of security. [16:04.850 --> 16:06.610] Uh, encrypted file sharing. [16:06.610 --> 16:10.010] You can share files with each other, you know, very Facebook style sort of. [16:10.630 --> 16:12.790] And yeah, we've made accessing it a lot easier. [16:13.430 --> 16:16.330] So still an experiment, very much an experiment, experiment. [16:16.830 --> 16:19.090] Um, but with interesting and worthwhile outcomes. [16:19.230 --> 16:21.350] And you can check out the website at project.crypto.cat. [16:21.470 --> 16:22.350] It's fully functional, by the way. [16:22.430 --> 16:26.050] I'm not talking about like a half, half baked like software. [16:26.150 --> 16:28.630] It actually works and everything is there and there's a spec and development. [16:28.870 --> 16:31.470] And you know, it's, it's, it's an actual project, even though it's an experiment. [16:32.790 --> 16:34.310] But this is not about Cryptocat. [16:34.470 --> 16:36.910] This talk, um, is about a lot more. [16:37.070 --> 16:42.170] It's about the future of browser cryptography as a legitimate platform. [16:42.410 --> 16:44.110] Which is something that all of us should be focused about. [16:44.310 --> 16:46.610] And all of us should care about because I believe it's very important. [16:46.730 --> 16:47.530] And it's very important. [16:48.110 --> 16:49.610] Uh, it's not there yet. [16:49.610 --> 16:52.790] But when we make it there, the potential is immense. [16:53.170 --> 16:55.810] And these are problems that we can solve. [16:55.990 --> 17:02.830] And I completely disagree absolutely with the notion that there are, that browser crypto is not a problem that is solvable. [17:03.070 --> 17:03.470] That's bullshit. [17:03.750 --> 17:06.990] We've, I mean, really, I mean, better hackers have solved bigger problems before. [17:07.430 --> 17:10.830] Just to put it simply, there's no, there's no more romantic reason than that. [17:10.830 --> 17:18.230] And so, uh, I want you to imagine a standardized web crypto API that's internalized across every single browser. [17:18.370 --> 17:28.930] And I mean, across every mobile browser, every desktop browser, everything from Opera to Safari to, um, Firefox to Chrome to not Internet Explorer because Internet Explorer is not a browser. [17:29.530 --> 17:37.490] Uh, and it's specified by the W3C, which is the same organization, of course, that specifies everything from HTML to RSS to CSS. [17:37.490 --> 17:38.610] And that actually exists! [17:39.270 --> 17:41.890] Uh, well, it's going to exist fully soon, but it's currently, we're working on it. [17:41.990 --> 17:43.310] It's called the Web Cryptography Working Group. [17:43.730 --> 17:46.030] And it's something that the W3C has initiated. [17:46.370 --> 17:48.250] Uh, it's been, it's been like six months now. [17:48.790 --> 17:50.990] And the spec is going to be released, I think, in a year and a half. [17:51.170 --> 17:52.490] And Cryptocat is part of that project. [17:54.910 --> 17:56.470] And this is, this is what we're working on. [17:56.510 --> 17:57.170] This is what we want to do. [17:57.270 --> 18:04.850] We want to have an API to transparently make it possible to encrypt everything done in the browser. [18:04.850 --> 18:12.670] Anything sent to a web app, for any web app to instantly be able to provide a crypto API that's so transparent that the user doesn't even have to know it's there. [18:13.090 --> 18:17.330] You just use Google Docs, and you do whatever you want, and you don't even know. [18:17.510 --> 18:19.910] Google doesn't even have to tell you that there's a crypto API going on. [18:20.050 --> 18:20.710] But it's there. [18:21.110 --> 18:26.210] And that, I believe, is an amazing foot in the door for web privacy from a computer science perspective. [18:26.210 --> 18:36.170] For achieving web privacy from a practical mathematical perspective, which is just as important as advocating for it politically and, you know, any other means you mean, you think are effective. [18:37.710 --> 18:45.630] What's at stake is, of course, there's other collateral security benefits for, you know, security. [18:45.630 --> 18:49.090] I really can't imagine a few right now, but I'm sure they're there. [18:50.930 --> 19:00.070] And, yeah, the transparent data privacy potential can be wrapped around the malleability and the flexibility and the creativeness of the web app platform. [19:00.330 --> 19:03.430] And this is something that more and more people are trusting with their data every day. [19:03.770 --> 19:06.650] And it's a very important field, therefore, to focus on. [19:08.530 --> 19:14.470] Things to implement inside this API include block ciphers, public key systems, hashes. [19:14.830 --> 19:16.090] And also, this is very important. [19:16.210 --> 19:17.110] I haven't mentioned this before. [19:17.890 --> 19:26.850] Protected key space in browsers so that when you get an XSS in your web app, you can't immediately... it can't immediately be used to disclose your private key. [19:27.170 --> 19:40.270] That means that you have... you implement protected variables in JavaScript that can only be accessed in restricted ways so that your private key isn't treated as, like, the same variable as your window size or any other. [19:40.630 --> 19:42.050] Just... it's given a lot more security. [19:42.150 --> 19:46.770] And this is something that no browser has at the moment, which I believe would be very useful in implementing an API like this. [19:46.830 --> 20:00.270] And, of course, this API, I believe, has to be fully OpenSSL compatible, as in the cipher output of it has to be possible via OpenSSL because I believe that we can use this sort of format as a standard for interoperability with other APIs and crypto platforms. [20:02.170 --> 20:03.070] So, Cryptocat 2. [20:03.190 --> 20:04.050] That's what I'm working on right now. [20:04.050 --> 20:09.250] Yeah, it's the new, you know, Cryptocat 2, the sequel. [20:09.410 --> 20:11.750] Cryptocat 2, the drones, strike back, crypto... yeah. [20:12.370 --> 20:15.230] So, it's an XMPP client in the browser. [20:15.570 --> 20:20.290] So, instead of using our own chat, whatever, IRC sort of thing, it's an actual Jabber client. [20:20.430 --> 20:22.550] And it works exactly like a Jabber client, but it works in the browser. [20:22.810 --> 20:24.990] Instead of using our own spec, we're implementing OTR. [20:26.330 --> 20:27.290] And MPOTR. [20:29.690 --> 20:34.790] So, MPOTR means multi-party OTR, and it's the future of encrypted web chatting, in my opinion. [20:34.930 --> 20:46.010] And I believe it should be your opinion as well, because what it's going to do is that it's going to make it possible to have conversations with more than two people at once across the board. [20:46.010 --> 21:04.850] It's going to make group chats encrypted, and it's going to make them... and with Cryptocat, hopefully, and if BrowserCrypto becomes a viable platform, then we will be able to offer group conversations to people via the browsers, via a web app, and it'll be very easy for them to actually access this new standard, [21:04.890 --> 21:10.290] which will not only offer group chat, but will also offer encrypted file sharing, which I believe... [21:10.290 --> 21:10.890] I mean, why not? [21:11.110 --> 21:11.370] Why not? [21:11.430 --> 21:11.710] Why not? [21:11.770 --> 21:12.570] It's really easy, actually. [21:12.690 --> 21:13.190] All you have to do... [21:13.190 --> 21:14.370] I mean, I can explain to you how it works right now. [21:14.450 --> 21:20.730] You just convert the file to a Base64 data URL, and you send it as a message. [21:21.290 --> 21:22.930] I mean, it's really done. [21:23.550 --> 21:24.530] It's a two-line function. [21:26.570 --> 21:28.690] And private messaging, you know, why not? [21:30.150 --> 21:34.430] Also, we can improve on the primitives that OTR currently uses, which are... [21:34.430 --> 21:37.730] I mean, it's not to say that they're completely dated, but it's that they could be improved upon. [21:37.830 --> 21:39.490] I mean, instead of SHA-1, we could use SHA-512. [21:39.490 --> 21:43.930] Instead of 1536-bit Diffie-Hellman, we could use elliptic curve Diffie-Hellman. [21:44.190 --> 21:44.630] Why not? [21:45.810 --> 21:46.550] This is our... [21:47.110 --> 21:50.030] If we're going to implement our new protocol, it hasn't been implemented yet. [21:50.130 --> 21:51.210] We should be the first to do it. [21:52.910 --> 21:57.910] We should make it as recent and as flexible as possible. [21:59.490 --> 21:59.890] Whoops. [22:00.810 --> 22:01.970] So come help us write the spec. [22:02.250 --> 22:02.790] Why not? [22:02.950 --> 22:03.130] Come. [22:03.330 --> 22:04.250] I mean, it's on GitHub. [22:04.390 --> 22:05.490] I opened an issue that there's... [22:05.490 --> 22:08.530] The spec is half-written, and we have code contributed to the project. [22:09.170 --> 22:11.530] That actually is a functional... [22:12.490 --> 22:14.370] I mean, we have the code. [22:14.470 --> 22:16.950] We've implemented enough to be able to have a functional MPOTR chat. [22:17.310 --> 22:21.510] And I have had an MPOTR chat in my browser working fully. [22:23.010 --> 22:24.690] It's not to say that it's completely efficient. [22:24.690 --> 22:30.970] It takes, like, the initialization shutdown sequence is a bit convoluted. [22:31.570 --> 22:33.070] So we might need to work on that. [22:33.550 --> 22:34.070] But, yeah. [22:34.270 --> 22:34.510] GitHub. [22:34.790 --> 22:34.970] Woo! [22:35.370 --> 22:35.650] Come. [22:35.830 --> 22:36.630] Help us work on that. [22:38.750 --> 22:42.650] So, practicality is important, and we can't rely on PGP. [22:42.750 --> 22:45.990] Just to summarize the important things that I want to drive into your heads. [22:45.990 --> 22:51.730] And we can't deny that the web is a major battlefront that we need to populate with accessible crypto. [22:53.230 --> 23:04.230] And this is why I'm working with the Guardian Project on introducing AWESOME, which is Always Secure Messaging, or the acronym that Nathan Freitas came up with. [23:04.230 --> 23:14.490] It's a coalition between the Guardian Project, which offers encrypted instant messaging applications for Android, Chat Secure, which offers encrypted instant messaging for iPhone, and Cryptocat. [23:14.790 --> 23:22.110] And so, we're basically going to have a criteria of evaluating other apps into our standard, which is, are they awesome or not awesome? [23:22.230 --> 23:23.190] Very simple criteria. [23:24.330 --> 23:32.130] Our principles are privacy by design, practicality and usefulness, open protocols, and the collaborative community. [23:32.690 --> 23:35.370] It's all very simple, very diplomatic stuff. [23:37.610 --> 23:43.970] And we also want to have end-to-end encryption, you know, very obvious first, you know, step. [23:44.330 --> 23:53.270] The ability to control logging, so that you're not logging all your conversations by mistake, which has got a lot of high-profile cases in trouble, apparently. [23:56.170 --> 24:05.430] And also, you want to have guaranteed eventual message delivery, so that if you're going through a tunnel and you're sending a message and it doesn't get there, it gets there when you're out of the tunnel, you know, when you're sort of queuing messages properly. [24:05.890 --> 24:08.650] And group messaging and other things. [24:08.830 --> 24:11.890] So, that's all I've wanted to... [24:14.490 --> 24:16.030] Oh, well, that's cool. [24:17.690 --> 24:20.750] So, that's all I wanted to talk to you about today. [24:21.250 --> 24:26.230] And I really hope that you will agree with me that this is an experimental platform. [24:26.690 --> 24:35.510] And this is not something that's been easy to research for the past year because of how to come up with solutions to difficult problems. [24:35.710 --> 24:43.370] But I believe it's worth it when you can actually go to the Middle East for once and show something to people that they will enjoy using. [24:43.370 --> 24:44.250] Because it's user-friendly. [24:44.470 --> 24:54.030] Because, you know, it's blue, it has a cat, color scheme, you know, audio notifications, desktop notifications. [24:54.170 --> 24:55.810] Because that is an important part of security as well. [24:56.570 --> 25:00.230] It's not just auditing your software or making sure you're using awesome crypto. [25:00.390 --> 25:08.150] It's also realizing the fact that here, you know, North America and Europe, we are exporters of cryptography. [25:08.150 --> 25:12.450] Or at least you are, I'm from the Middle East, but exporters of cryptography software. [25:13.130 --> 25:16.610] And the other part of the world is importing the software. [25:17.530 --> 25:20.930] And they are not surrounded by the same community of people that develop it. [25:21.070 --> 25:24.510] So, to them, this is a strange product from another continent. [25:26.290 --> 25:34.430] And you can tell them that it's safe to use, but you also need to convince them that this can fit into their life. [25:35.050 --> 25:41.410] Because we, it fits into our lives, or, well, I guess I'm like sort of dual cultured by now, I don't know. [25:42.370 --> 25:48.850] It fits into the North American European life because these are the cultures that produce this software. [25:49.250 --> 25:52.190] But we need to make it fit into those lives as well. [25:52.250 --> 25:57.770] And we need to get a foot in the door in the malleability and flexibility of the web app platform. [25:58.130 --> 26:00.470] Because that's a very important thing to do. [26:02.490 --> 26:05.530] So, if you have any questions, and I hope you do. [26:05.710 --> 26:09.730] Because, I mean, honestly, I get flooded with flaming all the time. [26:09.830 --> 26:11.490] And so, this is your chance to do it in real life. [26:11.650 --> 26:11.970] Go ahead. [26:13.150 --> 26:14.090] Oh, okay, cool. [26:14.770 --> 26:15.210] Yes? [26:25.880 --> 26:26.320] So... [26:26.320 --> 26:27.100] Okay. [26:27.480 --> 26:33.020] So, the question was, you're curious how in multi-party chats we're doing key agreement? [26:33.400 --> 26:34.700] Yeah, key agreement and key exchange. [26:34.800 --> 26:36.260] Okay, key agreement and key exchange. [26:36.780 --> 26:37.100] So... [26:37.100 --> 26:37.800] And authentication. [26:38.120 --> 26:39.140] And authentication, okay. [26:39.140 --> 26:39.180] Okay. [26:39.580 --> 26:43.600] So, are you curious about the protocol we have in place right now? [26:43.780 --> 26:45.100] Or the future MPOTR protocol? [26:46.440 --> 26:46.920] Uh... [26:46.920 --> 26:47.080] Probably. [26:47.420 --> 26:47.900] Okay. [26:48.480 --> 26:48.820] Very well. [26:49.080 --> 26:52.140] So, the protocol we have in place right now is actually very simple. [26:53.100 --> 26:53.580] Um... [26:53.580 --> 26:56.320] To the point where the simplicity might be a weakness, in fact. [26:56.560 --> 26:58.540] In the sense that we have... [26:58.540 --> 26:59.900] We just generate keys. [26:59.900 --> 27:02.140] So, every user generates a key pair. [27:02.460 --> 27:03.280] Keeps the private key. [27:03.880 --> 27:05.200] And sends the private key... [27:05.200 --> 27:05.520] Sorry. [27:05.640 --> 27:07.520] Sends the public key to the server. [27:07.780 --> 27:11.000] And then the server is responsible of exchanging that key to everyone else. [27:11.200 --> 27:14.180] So, whenever you join a room, you get a list of public keys for everyone. [27:14.360 --> 27:19.240] And then you can verify those keys using a very OTR-like fingerprint. [27:20.060 --> 27:21.240] And then you're done. [27:22.500 --> 27:22.900] Uh... [27:22.900 --> 27:25.340] In terms of whether there's ephemeral keys right now. [27:25.820 --> 27:26.220] Uh... [27:26.220 --> 27:27.140] All keys are ephemeral. [27:27.240 --> 27:28.000] There are no permanent keys. [27:28.140 --> 27:31.060] So, every time you use Cryptocat, your fingerprint changes. [27:31.240 --> 27:32.260] Because you're generating a new key. [27:32.260 --> 27:34.140] And this is done... [27:34.140 --> 27:38.560] This was done as a quick way to achieve forward secrecy. [27:38.840 --> 27:47.960] And also because we weren't particularly interested in looking at permanent storage for storing private keys at the time. [27:48.100 --> 27:49.860] Because we weren't sure it was a good idea, to be honest. [27:50.180 --> 27:55.040] In terms of MPOTR, MPOTR specifies a group key exchange. [27:56.740 --> 27:59.260] Which I can't remember the specifics of that at the moment. [27:59.300 --> 27:59.740] I'm sorry. [28:01.100 --> 28:04.260] But the keys are authenticated also using DSA. [28:05.180 --> 28:06.960] And also at the end of the chat... [28:07.340 --> 28:12.220] When someone exits a chat from MPOTR, his key is published. [28:12.460 --> 28:15.400] And then the publication of his key is denied. [28:15.780 --> 28:16.220] I'm sorry. [28:16.300 --> 28:17.620] It's verified by everyone else. [28:17.620 --> 28:18.920] So as not to be accepted again. [28:19.140 --> 28:22.860] And that is what provides deniability in MPOTR. [28:22.920 --> 28:24.820] Also in OTR, it's a very similar mechanism. [28:25.740 --> 28:26.680] Any other questions? [28:27.320 --> 28:27.940] Yes, please. [28:34.420 --> 28:35.760] Are we using curve 25519? [28:36.560 --> 28:36.980] Yes, we are. [28:37.940 --> 28:38.020] Yes. [28:38.180 --> 28:48.400] Well, it's a curve 25519 is a elliptic curve sort of set of parameters defined by Daniel Burstein, which is an incredible cryptographer. [28:48.620 --> 28:49.520] One of the best, I think. [28:50.480 --> 28:53.140] And we're using it because it has a good track record. [28:53.280 --> 28:53.980] It's pretty fast. [28:54.820 --> 28:55.400] And I mean... [28:55.400 --> 28:56.700] Yeah, that's pretty much it. [28:57.800 --> 28:58.160] So... [28:58.160 --> 29:01.620] Oh, sure, sure, sure. [29:01.900 --> 29:02.100] Okay. [29:02.820 --> 29:03.600] I'd love to actually. [29:03.720 --> 29:04.540] That's a good thing to talk about. [29:06.220 --> 29:06.620] So... [29:06.620 --> 29:10.920] When I started, it was only Stanford, the Stanford crypto library, which was, you know, not too bad. [29:12.300 --> 29:13.620] Now, I've never used that. [29:13.720 --> 29:21.720] I actually use a different library called CryptoJS, which is developed and very well maintained by Jeff Mott and a bunch of, you know, other volunteers. [29:24.940 --> 29:25.440] It's... [29:26.400 --> 29:33.620] It offers SHA-512, it offers legacy hashes, and it offers AES and a multiplicity of modes. [29:33.800 --> 29:37.520] And also recently, it will offer RSA because someone recently contributed some RSA code. [29:38.980 --> 29:45.120] And those libraries have increased in seriousness over time in the sense that they're... [29:45.120 --> 29:55.840] If you try to submit something to them, there is an active mailing list of people who will go and verify that your implementation... they'll ask you first if you verify that your implementation matches the test vectors, and then they will go verify it themselves. [29:56.120 --> 30:00.520] And they will also look at it and test for other, you know, side channel attacks. [30:00.900 --> 30:01.860] And so... [30:03.320 --> 30:08.180] Using that, you can realize that there's a trend, a rising trend in adopting those libraries a lot more seriously. [30:08.340 --> 30:13.780] And from a personal perspective, I believe that CryptoJS recently came out with version 3. [30:13.940 --> 30:17.720] And version 3 is a particularly malleable cross-compatible library that... [30:18.220 --> 30:22.440] really seriously deserves taking a look at it because it's really very promising. [30:23.800 --> 30:24.800] There's also... [30:26.000 --> 30:30.140] Oh, the other libraries aren't worth mentioning compared to... [30:34.470 --> 30:34.970] . [30:38.350 --> 30:38.850] . [30:42.190 --> 30:42.690] Okay. [30:43.110 --> 30:45.170] So, it's a bad idea because... [30:45.170 --> 30:46.140] Well, it's a bad idea first... [30:47.050 --> 30:50.090] The first thought that came to my mind, the reason I was... [30:50.090 --> 30:51.990] I scoffed at it is because simply it's inefficient. [30:52.490 --> 30:59.090] And in the sense that Java is bulky and it doesn't work without installing a large... [30:59.750 --> 31:02.670] You know, you have to install Java basically, which is similar to installing Flash. [31:02.830 --> 31:06.550] And Java historically has had a lot of security problems exactly like Flash. [31:06.750 --> 31:11.350] And in fact, remember the browser sandboxing that was broken that I mentioned in Chrome that used seven O days? [31:11.350 --> 31:17.210] That wouldn't have been possible without Flash being included in Chrome because most of those O days depended on Flash. [31:18.150 --> 31:20.470] And so, Java... [31:20.470 --> 31:25.390] The Java virtual machine has a very similar sort of security... [31:25.390 --> 31:29.810] This set of security flaws that is regularly exploited and isn't fixed on time, if ever. [31:31.210 --> 31:35.430] And it's also really slow and it's also closed source. [31:35.650 --> 31:39.710] So, you can't examine the source code unless you're good at Java disassembly. [31:39.850 --> 31:42.470] You can't examine the source code of a Java binary easily. [31:43.090 --> 31:51.410] Whereas other, you know, JavaScript, while not perfect, at least has the capacity of being easily forked into like a good hub repository. [31:51.830 --> 31:52.950] And you can also... [31:52.950 --> 31:55.890] You can examine the code more easily than just... [31:56.750 --> 31:58.950] I mean, you can like curl it and check it out. [32:00.190 --> 32:00.450] Yeah. [32:06.880 --> 32:08.460] Well, if you're doing... [32:08.460 --> 32:16.980] If you're downloading the local app for Chrome and soon for Firefox, then I believe that you would be protected from man in the middle in terms of being served the code. [32:21.770 --> 32:22.270] Mm-hmm. [32:22.650 --> 32:23.650] Oh, we... [32:23.650 --> 32:28.530] So, that's why we encourage users to verify fingerprints in a way that's very similar to how OTR works. [32:28.810 --> 32:30.750] We have a very similar... [32:30.750 --> 32:33.250] It's really just a SHA... [32:33.250 --> 32:35.490] SHA-1 or SHA-256. [32:35.610 --> 32:35.870] Sorry. [32:35.990 --> 32:38.030] SHA-256 of the fingerprint. [32:40.050 --> 32:41.090] And that's... [32:41.090 --> 32:42.330] That's the... [32:42.330 --> 32:42.570] Sorry. [32:42.670 --> 32:43.230] Of the... [32:43.230 --> 32:43.930] Of the public key. [32:44.030 --> 32:44.630] And that's the fingerprint. [32:44.790 --> 32:46.330] And just verify it same way. [32:53.470 --> 32:53.990] Okay. [32:55.090 --> 32:55.710] All right. [32:56.250 --> 32:57.610] We're currently not using... [32:57.610 --> 32:57.770] Sorry. [32:57.770 --> 33:00.310] AS and CTR mode will be deployed in MPOTR. [33:00.730 --> 33:05.190] And so, if you would like to contribute against those attacks or talk to discuss them more in detail, I would love that. [33:05.490 --> 33:08.810] But right now, the current Cryptocat spec actually uses it in CBC mode. [33:09.790 --> 33:10.010] Okay. [33:10.350 --> 33:11.350] Please, gentleman in the back. [33:11.350 --> 33:11.390] So, [33:14.910 --> 33:33.440] that's a very good point. [33:33.440 --> 33:46.160] There is, of course, the risk, theoretically, that Google does host the local app, and so that's not necessarily the best way to host it. [33:46.260 --> 33:54.800] But that's why we also offer, on GitHub, instructions for how to download and install your own Chrome app. [33:54.900 --> 33:55.560] And it's very easy. [33:56.200 --> 34:06.960] It's just you download the GitHub zip file, and there's a directory that you right-click on and click create zip file, and then you load the zip file in Chrome, and that's how it works. [34:07.100 --> 34:08.880] So that's one way to do it. [34:09.460 --> 34:09.860] Yes? [34:16.980 --> 34:25.200] You can either send them a link, so every chat has a link to it, or you could send them the name of the chat. [34:25.980 --> 34:36.620] But yeah, obviously, when you do that, if you do it over an open channel, then someone else could intercept the chat address and join the chat instead of the other person. [34:36.740 --> 34:37.560] But that's... [34:38.900 --> 34:40.620] Well, that's what you use fingerprints for. [34:42.840 --> 34:49.080] You can also choose to limit the people who can send you messages and things like that. [34:50.120 --> 34:54.100] But in Cryptocat, too, this will be incredibly immaterial because we're just going to use XMPP. [34:54.240 --> 35:01.320] So there's just XMPP clients, like XMPP accounts, just like Google Talk, or Jabber.ccc.de, or whatever. [35:01.780 --> 35:01.900] Yes? [35:08.900 --> 35:09.400] Yes. [35:11.300 --> 35:11.500] Yes. [35:21.170 --> 35:21.510] Okay. [35:28.090 --> 35:28.590] Okay. [35:29.170 --> 35:31.850] So this is something that I've been thinking about, actually. [35:32.050 --> 35:33.730] The question was that... [35:33.730 --> 35:36.650] So in the current version of Cryptocat, there's randomly generated... [35:36.650 --> 35:36.970] Oh, sorry. [35:37.070 --> 35:42.890] Well, the nickname that you get is basically like bunny or puppy, generated nicknames, kitty, pony. [35:43.470 --> 35:47.590] And so in the new version of Cryptocat, there's going to be XMPP usernames. [35:47.670 --> 35:50.030] And so will that make it so that you're more identifiable? [35:50.310 --> 35:58.390] And so the reason I have decided to sort of address this problem is by making it so that when you log into Cryptocat 2, let me show you. [36:02.820 --> 36:06.340] So this is the Cryptocat 2 login screen. [36:06.840 --> 36:13.900] And the difference between logging in and creating a new account is checking this box. [36:18.420 --> 36:24.180] So that makes it so that you can create a new account every time, if you want. [36:24.380 --> 36:38.820] So by making the difference, by making the barrier between using your old account and creating a new one, very, very small, very transparent like this, just check this box, you are making it less easy to identify people. [36:38.980 --> 36:41.140] Because, heck, I can just choose to create a new account every single time. [36:41.760 --> 36:42.160] Why not? [36:42.940 --> 36:46.260] Accounts will expire, I think, when we launch this, like on the default Cryptocat server. [36:46.480 --> 36:49.020] You can log into Cryptocat 2 with your Gtalk account, by the way. [36:49.120 --> 36:50.560] You're going to be able to log in with any account you want. [36:50.660 --> 36:55.900] You're going to be able to use Cryptocat 2 to talk to someone using OTR on Pidgin using the Google Talk account from your Cryptocat account. [36:55.900 --> 36:58.680] So, there's going to be a lot of interesting things like that. [36:59.380 --> 36:59.780] Yes? [37:05.480 --> 37:05.880] Which? [37:06.080 --> 37:09.820] The MPOTR or... MPOTR or the... Okay. [37:10.560 --> 37:10.960] Yes. [37:11.300 --> 37:12.580] I mean... Okay. [37:12.760 --> 37:14.440] So, the MPOTR... [37:14.440 --> 37:23.100] Yeah, it is the current version, the text version, but honestly, also look at the code, because I think I've done some improvements in the code that I haven't mirrored in the text spec yet. [37:27.420 --> 37:28.260] No, no. [37:28.420 --> 37:29.180] We should discuss that. [37:37.790 --> 37:46.090] No, but the thing with MPOTR is that the key agreement... sorry, the key exchange is already specified in Ian Goldberg's paper. [37:46.910 --> 37:49.770] I'm going to find you later. [37:49.850 --> 37:51.810] No, but please, I would love to discuss that. [37:51.990 --> 37:52.350] No problem. [37:52.350 --> 37:52.650] Okay. [37:52.650 --> 37:52.830] So, [37:56.590 --> 38:02.950] there's people in the pair does the key exchange with that secret. [38:03.190 --> 38:04.710] It's a public here that you can see. [38:05.830 --> 38:07.510] Public key generated from... [38:09.130 --> 38:10.790] ...shared secret, they... [38:10.790 --> 38:11.650] ...you have... [38:11.650 --> 38:12.490] ...you have... [38:13.610 --> 38:15.510] ...say you've got eight people who have... [38:16.110 --> 38:19.010] ...four shared secrets and two shared secrets and one shared secret. [38:26.300 --> 38:26.620] Okay. [38:28.220 --> 38:28.540] Okay. [38:28.800 --> 38:31.000] Well, no, that sounds interesting. [38:31.120 --> 38:32.300] I would love to discuss it with you after... [38:33.220 --> 38:35.720] Yeah, I'll have to find a paper on the mail. [38:36.050 --> 38:37.550] Well, you can just meet me outside, man. [38:38.040 --> 38:38.360] Okay. [38:40.330 --> 38:40.980] Anyone else? [38:44.120 --> 38:45.320] Oh, please, please, go ahead. [38:50.380 --> 38:50.780] Okay. [39:20.230 --> 39:22.390] So, the question that was raised is that... [39:23.130 --> 39:30.550] ...however you deliver Cryptocat or any, you know, web app, even if you have a local app, you're still trusting it to a certain degree, and how can you get past that? [39:30.810 --> 39:35.370] So, this is also a problem in every single other application ever made. [39:35.370 --> 39:45.390] Every single package you download on Linux, when you download Tor, when you download Pigeon, when you download a Linux distribution, when you download an operating system even, you are encouraged to verify them using hashes. [39:46.230 --> 39:48.530] And that's because there really is no better solution. [39:49.450 --> 39:51.350] You just... you can download it. [39:51.570 --> 39:52.090] There's a hash. [39:52.270 --> 39:57.630] Sometimes the hash is stored on the same server as the server you've downloaded the file from, which is hilarious. [39:58.670 --> 39:59.630] And so... [40:01.830 --> 40:02.310] Yeah. [40:03.470 --> 40:06.310] To a certain degree, you are going to have to... [40:07.050 --> 40:10.950] I mean, if you don't want to trust the hash even, then you can go through the source card. [40:11.230 --> 40:13.750] But other than going through the source card, ultimately there's nothing you can do. [40:18.170 --> 40:18.490] So... [40:18.490 --> 40:19.790] Oh, please. [40:28.660 --> 40:33.020] Maybe I have other opinion, that instead of just shipping... [40:33.640 --> 40:49.770] The checksum that are on the same server, these are actually usually signed by a project, that key can be signed by members of the project, which had their key signed by other people. [40:50.150 --> 40:53.850] And you can verify those signatures with. [40:54.130 --> 40:56.750] And these days, any testing package being installed [41:24.150 --> 41:36.910] Okay, so there is a suggestion to using PGP to either, more simplistically, just sign the hashes or the fingerprints or establish a PGP web of trust, which is really interesting. [41:37.050 --> 41:38.330] I think we should talk about that. [41:39.390 --> 41:40.950] I think there was someone else? [41:41.450 --> 41:42.250] Yes, yes. [41:42.530 --> 41:43.210] I have one [41:46.510 --> 41:49.530] multi-user multiplayer games. [41:49.770 --> 42:05.610] What they do is, actually, when you try logging in to the EA server to start a new multiplayer game, the software itself uses some sort of basically hash and sends the hash value to the server. [42:11.430 --> 42:12.450] Oh, oh. [42:12.750 --> 42:14.770] Well, you can't... [42:16.590 --> 42:20.770] I don't know if you can trust the server to verify the clients, because the server, you know, might maliciously... [42:21.410 --> 42:26.070] Oh, no, I'm not saying that, but maybe it would be good to post a display, [42:29.630 --> 42:32.230] but we know something's a mess here. [42:32.510 --> 42:35.730] Oh, well, that could easily be removed from the client, too. [42:35.730 --> 42:41.890] Oh, I know, but it's something that maybe will be put in by a text message, and so... [42:41.890 --> 42:48.490] Well, you have to assume that any part of the code base can be compromised, sadly. [42:48.870 --> 42:49.570] One more hoop. [42:50.090 --> 42:51.130] Okay, all right. [42:53.690 --> 42:54.170] So... [42:55.050 --> 42:57.510] Wait, I'm pretty sure someone here had their hand raised? [43:16.560 --> 43:17.940] The current version. [43:18.140 --> 43:22.100] Is the current version of Cryptocat good enough to be used in people in dangerous situations? [43:23.140 --> 43:29.660] People in Iran, against the Iranian regime right now, I am not sure. [43:29.880 --> 43:30.820] I'm not sure at all. [43:31.420 --> 43:36.140] If it's... I mean, heck, we could do some field testing and find out, but I am not optimistic. [43:39.640 --> 43:41.140] I am not optimistic. [43:42.720 --> 43:47.180] But listen, the thing is, like, when you... I have to be responsible. [43:47.340 --> 43:51.360] When you launch Tor every single time, it tells you Tor is an experiment. [43:51.360 --> 43:53.080] Do not rely on it for strong anonymity. [43:53.500 --> 43:55.580] This displays this warning every single time you launch it. [43:55.720 --> 43:57.820] And this is not to say that I'm even close to being like Tor. [43:57.920 --> 44:00.780] I'm still far away from the same level of quality as that project. [44:00.960 --> 44:11.560] But I am more concerned with establishing the best precedent I can and helping further the legitimacy of this platform right now. [44:12.300 --> 44:14.760] And also providing a product that can be used... [44:15.240 --> 44:26.640] that can be used maybe for organizing small political events, whatever, but Cryptocat as it is right now, I would not depend on it for my life. [44:27.200 --> 44:34.160] Simply because this is a huge claim to make that I don't believe any respectable product ever makes in the security community. [44:34.420 --> 44:35.560] And no one ever should. [44:37.120 --> 44:55.020] Because we are supposed to be scientists and we are supposed to always assume the worst and always, you know, work towards making it better pragmatically without making tall claims and without vouching for something unless we have been on the ground and we have tested it ourselves and we have seen it work. [44:55.340 --> 45:01.460] So I am much more interested in working on an engineering perspective on making it as best as I can. [45:01.460 --> 45:04.540] And whatever it is used for, I hope it is used for great things. [45:04.940 --> 45:11.140] But for now, I advise everyone to just focus on research first. [45:12.600 --> 45:12.900] Yes, please. [45:13.400 --> 45:14.000] Do you have [45:17.700 --> 45:22.520] resistance against graph analysis or perhaps even just an integration with Tor? [45:22.760 --> 45:32.400] Oh, so we have a policy in our architecture and lifecycle document that every single version of Cryptocat ever released has to be tested to be compatible with Tor first. [45:33.720 --> 45:36.720] Because I personally am a big supporter of the Tor project. [45:36.960 --> 45:41.820] And I believe that we can definitely benefit from an anonymity and circumvention platform like Tor. [45:42.320 --> 45:46.640] In terms of graph analysis, use Tor. [45:46.860 --> 45:49.500] I mean really, so when we have... [45:50.200 --> 45:56.480] I'm already trying to convince the Tor project to include Cryptocat in the Tor browser bundle. [45:56.480 --> 45:59.500] And so I'm not gonna vouch for that now. [45:59.680 --> 46:17.880] But one day, especially with Cryptocat 2, when we have OTR and MPOTR implemented in an XMPP version, and when we've done more testing, then it would be a really good idea to have Cryptocat 2 integrated into the Tor browser bundle because it's like a one-click chatting solution for a lot of people that works over Tor that's in the browser, [46:18.000 --> 46:18.420] et cetera, et cetera. [46:18.860 --> 46:24.420] And I think that Firefox should implement better sandboxing first before we do that. [46:25.780 --> 46:30.420] But yeah, that's, I mean, I'm working on an instant messaging platform. [46:30.780 --> 46:37.900] For the other things, I think it's better to rely on the experts over at Tor because it just, it saves me a lot of work. [46:38.040 --> 46:40.160] And I really, I mean, they're doing incredible work over there. [46:40.240 --> 46:41.100] So why not benefit from it? [46:42.540 --> 46:43.460] I believe you, sir? [46:43.680 --> 46:43.900] Yes. [46:56.860 --> 47:00.300] It's going slowly because it's a volunteer thing and it's, there's a lot of people in it. [47:00.400 --> 47:03.160] So the W3C crypto API spec. [47:03.780 --> 47:08.400] There's a lot of people who are, you know, everyone on it is from Google or Gemalto. [47:09.500 --> 47:13.420] So a lot of crazy organizations, a lot of very busy people. [47:13.420 --> 47:15.780] So it's going slowly. [47:16.840 --> 47:22.180] I think the schedule is around 2014, but that's about it. [47:25.580 --> 47:34.320] It's, there are productive discussions being done, but this is something that takes a lot of time, especially to come to a consensus in terms of what's, you know, solving a lot of problems. [47:34.460 --> 47:37.160] And, you know, some people think it's better to do this in the API. [47:37.300 --> 47:38.440] Some people think it's better to do that. [47:38.560 --> 47:41.600] And this is an API that's going to be standardized across every single browser ever, hopefully. [47:41.600 --> 47:46.060] So we have to make sure we get it right from the first time or at least as close to the first time as possible. [47:52.530 --> 48:02.930] So this is, this is me speaking personally, but I was concerned that there might be, that, that this, that this sort of effort might be used to... [48:04.990 --> 48:15.210] So, so I was concerned that some people were inside this effort or some people would be interested in this effort to use it towards implementing DRM in the browser. [48:15.210 --> 48:19.350] Which, which is, I mean, and, and this, this becomes then a completely like purely political issue. [48:19.610 --> 48:32.010] But, but at that, at that point, I think that when implementing an API, you should focus on the science and on making, on being objective and just focusing on engineering. [48:33.970 --> 48:38.790] Because all of us have, I mean, a lot of us have, I have political goals out of this API. [48:38.790 --> 48:43.830] And so maybe some people won't agree with me, but that doesn't mean they shouldn't work with me on making it happen. [48:45.690 --> 48:46.790] So, anyone else? [48:46.970 --> 48:47.930] Do we have time even? [48:50.680 --> 48:51.400] Oh, it's okay. [48:51.500 --> 48:55.140] We have like eight minutes, so... [48:55.140 --> 48:56.720] Oh, or we're done. [48:57.120 --> 48:59.940] Well, it's been very nice talking to you all. [48:59.940 --> 49:02.840] I've been meaning to come to HOPE ever since I was 16, actually. [49:03.140 --> 49:06.000] And so, this is my first time here, and I really appreciate talking to you. [49:06.220 --> 49:07.080] So, thank you very much. [49:07.080 --> 49:08.060] Thank you very much.