[00:22.170 --> 00:23.050] Good, good. [00:23.730 --> 00:25.830] We have a couple of minutes before we get started. [00:28.130 --> 00:29.890] I'll do a couple of announcements. [00:30.450 --> 00:31.550] Some general stuff. [00:32.850 --> 00:34.230] Anybody went to the karaoke? [00:34.650 --> 00:35.910] Raise your hand last night. [00:36.290 --> 00:36.890] Any karaoke? [00:37.130 --> 00:37.390] Nice. [00:37.530 --> 00:38.130] How was that? [00:39.270 --> 00:40.630] Alright, did you perform? [00:43.350 --> 00:49.670] Okay, so hopefully at Hackers Got Talent tonight, you'll perform or somebody else will perform. [00:49.930 --> 00:51.230] Anybody thinking about performing? [00:53.570 --> 00:54.370] Don't be shy. [00:54.570 --> 00:55.210] Go for it, okay? [00:55.350 --> 00:56.110] This is the space. [00:56.210 --> 00:57.110] This is the place, alright? [00:59.530 --> 01:01.050] A couple of obvious things. [01:01.230 --> 01:01.970] Please stay hydrated. [01:02.070 --> 01:03.150] I went outside during lunch. [01:03.150 --> 01:04.670] It's really, really hot, okay? [01:04.750 --> 01:08.690] So make sure you're drinking water, not just coffee and more coffee, okay? [01:08.990 --> 01:11.390] Keep your masks on when you're indoors. [01:11.570 --> 01:12.810] We want to make sure everybody's safe. [01:13.950 --> 01:15.210] Mute your phones, please. [01:16.070 --> 01:19.710] We still need workshop helpers for Saturday and Sunday. [01:20.270 --> 01:26.550] So visit room 301 or speak to Mitch when you see him and offer your help. [01:26.710 --> 01:27.290] That would be awesome. [01:28.950 --> 01:29.590] And... [01:29.590 --> 01:32.410] I think there's one more schedule change. [01:32.590 --> 01:33.810] You probably already heard of it. [01:34.290 --> 01:35.750] 10 PM tonight. [01:35.750 --> 01:38.850] Check out medical devices, security and privacy issues. [01:39.010 --> 01:42.190] Greg was talking about it during the intro earlier. [01:42.590 --> 01:43.690] So that's it. [01:44.010 --> 01:49.510] You are here for Executive Order 14-028 and Zero Trust Architecture. [01:49.930 --> 01:50.470] Please welcome... [01:52.290 --> 01:53.190] Harri Hursti. [01:53.310 --> 01:54.350] Harri Hursti. [01:54.550 --> 01:54.790] Harri Hursti, please. [01:54.950 --> 01:55.830] Give him a round of applause. [01:59.150 --> 02:00.010] Thank you. [02:00.190 --> 02:01.150] Thank you so much. [02:01.330 --> 02:02.650] It's so nice to be HOPE. [02:02.710 --> 02:05.970] I was just trying to remember how many times I've been speaking here. [02:06.130 --> 02:09.690] But this is the least technical talk I have ever given. [02:09.950 --> 02:21.450] Because this is now driven about the craziness around Zero Trust, which is the worst password in a recent history, most unused, most misunderstood. [02:22.250 --> 02:26.250] Everybody's trying to use it, misuse it, and sell you snake oil. [02:26.470 --> 02:28.390] And of course, we love snake oil. [02:28.570 --> 02:29.630] That's always so tasty. [02:29.850 --> 02:36.730] But this is a talk where we are going to touch the Executive Order given what Zero Trust means. [02:36.730 --> 02:41.630] A little bit of philosophy, again, behind human mind. [02:42.290 --> 02:50.070] And also, talk wouldn't be a talk if you are only talking about the problem and not offering any kind of idea how to solve a problem. [02:50.250 --> 02:56.990] So I'm also going to talk about an open-source project, which is solving a lot of these problems. [02:57.150 --> 02:59.730] We are going not all of the problems, but some of the problems. [02:59.730 --> 03:05.390] And also why open-source is now the preferred solution by governments. [03:05.770 --> 03:12.610] And even when we are talking here about the United States Executive Order, there's an international aspect to this. [03:12.970 --> 03:18.450] And a number of other governments are in different phases of implementing similar regulation in the place. [03:18.610 --> 03:27.450] So this is a global trend now to have a government mandated transition to Zero Trust architecture is not U.S. centric. [03:29.030 --> 03:32.290] So, first of all, my slides are always full of a lot of stuff. [03:32.450 --> 03:34.250] I'm not going to read them line by line. [03:34.490 --> 03:39.310] So I know when you put a new slide, people are tending to be a little bit losing me. [03:39.470 --> 03:40.670] So whatever you want to do. [03:40.850 --> 03:46.730] But the whole idea is to understand that Zero Trust is a very old term. [03:48.010 --> 03:52.090] There's two different, so to speak, fathers for that. [03:52.090 --> 04:03.010] Usually, it's recognized that John Kinderwag is the father because he brought the term into a global knowledge and broader knowledge. [04:03.170 --> 04:08.330] But actually, if you look behind, there was a lot of work done by different parties. [04:08.330 --> 04:14.270] And the Jericho Forum was a first people around. [04:14.610 --> 04:18.890] And this is... 2004 is not an exact date. [04:19.210 --> 04:22.350] The conversation in Jericho Forum took over a year. [04:22.530 --> 04:26.810] So it spilled over to 2003 in the beginning. [04:27.070 --> 04:36.470] But they were starting to define the de-parameterization, so edgeless network, which is, of course, one of the key concepts of Zero Trust. [04:36.470 --> 04:39.990] So that happened already in 2004. [04:40.910 --> 04:55.750] And BeyondCorp, which is, in a lot of ways, the first definition of modern idea of Zero Trust architecture, how it would work in corporate infrastructure, that was also 2009. [04:56.630 --> 05:10.970] Today, we are in a situation where we do have a formal definition of what Zero Trust architecture looks like, a standard for National Institute of Standards and Technology, the 800-207. [05:11.290 --> 05:13.330] So there is a formal definition. [05:13.830 --> 05:20.050] As you see, 2018 was the year when that started to be drafted. [05:20.050 --> 05:23.310] The final version, I believe, came summer 2020. [05:23.310 --> 05:29.690] So it came after the pandemic started, but still it didn't incorporate the changes. [05:29.950 --> 05:37.890] And if we look what Zero Trust comes from, it comes from a need to adapt yourself into an enterprise world. [05:38.070 --> 05:40.570] And now, of course, pandemic is changing everything. [05:42.050 --> 05:48.050] So these are the original roots of this idea. [05:48.050 --> 05:56.670] But if you look where the idea comes from, this is a much narrower view than how we understand Zero Trust today. [05:56.950 --> 06:08.950] Because Zero Trust really is a set, it's a family of massive paradigm changes across the methodology and across the way we think cyber security. [06:09.890 --> 06:17.310] And because it's a combination of multiple paradigm changes, it causes confusion. [06:18.670 --> 06:22.730] I asked in the previous slide, why don't we understand this? [06:22.810 --> 06:24.330] Why we have still confusion? [06:24.850 --> 06:28.130] That is because this is not a simple thing. [06:28.310 --> 06:32.470] This is not something which is going to be defined as it is today. [06:32.470 --> 06:34.410] It's going to be evolving. [06:36.470 --> 06:44.330] When I went to RSA, about one third of the companies on the floor were selling something Zero Trust. [06:44.330 --> 06:54.570] So I took my chances against COVID, and I started walking from one booth to another, asking if I buy you a Zero Trust, what I'm going to get. [06:55.570 --> 07:00.610] And I started to do a little bit of non-scientific study, what it means. [07:00.970 --> 07:06.630] The most interesting thing was, all of the five most common answers were wrong. [07:06.630 --> 07:14.390] They were very... some of them might be, in a broader idea, one of the building blocks in the... [07:14.390 --> 07:20.550] And I'm actually not going to talk about the Zero Trust Maturity Model, which is another document from National... [07:20.550 --> 07:26.690] CISA, the Cyber and Cyber Space and Cyber Security and Infrastructure Security Agency. [07:27.130 --> 07:30.690] There is a document which is still in draft version about that. [07:30.830 --> 07:32.170] I'm not going to talk about that. [07:32.170 --> 07:43.590] But the most important thing is, when you look at the commercial space, you are in a situation where what is being sold to you is beside the point, most of the time. [07:44.970 --> 07:50.510] The number one, passwordless, was by far the most common, what they were selling. [07:51.050 --> 08:02.090] And even if... when I went to some of the company's websites, where they had better answers and more realistic answers, what Zero Trust is in their website. [08:02.710 --> 08:09.310] When you speak on a soul floor, the answers were basically mostly wrong. [08:09.870 --> 08:16.390] So, I also had, because I do like beer, I had a conversation with people, like, why are you doing this? [08:16.390 --> 08:19.970] And basically it is, well, everybody wants to buy a solution. [08:20.090 --> 08:22.590] They don't want to hear this is a journey. [08:22.590 --> 08:30.990] They want to have something which I can buy, it's a Zero Trust, I implement it next month, checkbox, Zero Trust compliance, Archie. [08:31.190 --> 08:34.270] Of course, that is absolutely not true. [08:35.170 --> 08:44.750] But the most interesting thing is, if you look at the cornerstones of the definition of Zero Trust, they were starting to show a little bit in top ten. [08:44.750 --> 08:56.830] So, we are very far away from being able to go to, as a purchase manager, as a SISO, who doesn't have a technological background. [08:57.010 --> 09:07.310] And that's another part which is always eye-opening to go to RSA to realize how few of the SISOs actually have a security background. [09:07.310 --> 09:10.970] Most of the people are, right now, more in the sales-oriented mode. [09:11.110 --> 09:14.030] Their background is marketing, sales, operations. [09:14.670 --> 09:16.450] They don't have an understanding. [09:16.670 --> 09:20.710] So, they are in a managerial position, which is always needed. [09:21.030 --> 09:27.750] But they don't have an understanding, if somebody is going to sell them, what this actually means for the corporation. [09:27.750 --> 09:30.650] What they are buying and what they should be paying attention to. [09:32.210 --> 09:34.630] Of course, this is where it all comes from. [09:35.190 --> 09:39.030] Everybody has their own favorite layer of the model. [09:39.550 --> 09:45.950] And everybody is trying to sell you something which is helping to secure their favorite layer of the model. [09:47.030 --> 09:49.030] That is driving the sales pitches. [09:49.410 --> 09:54.430] The network people are still selling a Zero Trust while they are selling you a better firewall. [09:56.150 --> 10:00.050] That's beside the point, because Zero Trust is an edgeless network. [10:00.310 --> 10:09.890] So, that's one thing where you immediately know, well, now we are talking about a, at the best, partial solution. [10:09.890 --> 10:18.230] But if you think about it in an ideological and philosophical way, you are selling something which is philosophically wrong. [10:20.290 --> 10:23.010] We have learned so much during Ukraine war. [10:23.270 --> 10:28.830] And as much as I hate the war, it's always good to understand the lessons learned. [10:29.710 --> 10:36.150] This is a good example how we already knew that we misplaced trust into the network. [10:36.330 --> 10:41.250] And we are trusting network too much based on what the network knows about you. [10:41.770 --> 10:45.470] And allow that to guide your security decisions. [10:46.530 --> 10:52.650] When the war started, 8 or 9 small ISPs in Russia got blocked. [10:53.170 --> 10:56.130] And it shouldn't be having this effect. [10:56.330 --> 11:03.150] But the effect was, this is the number of tweets about anti-vaccine messages targeting Canada dropping. [11:03.150 --> 11:21.630] So, now we are in a situation where literally by trusting the network, you have been, they have been allowing a massive impact in a social media messaging to pass through based on unfounded trust on the network and unfounded trust on the parameters. [11:21.630 --> 11:25.610] AS number is the most cruelsome way of thinking this. [11:25.850 --> 11:28.050] But this is just a symptomatic. [11:28.330 --> 11:37.810] If there is this kind of impact coming from this kind of a mistrust, you can only imagine what the impact is in more nuanced approaches. [11:38.110 --> 11:46.750] Of course, you start to see it only took two days, basically three days before the traffic started to find another ways to spread. [11:50.310 --> 11:57.410] So, zero trust is never about fixing one layer and trusting the others to provide you something. [11:57.610 --> 12:01.070] You have to distrust the whole stack. [12:01.450 --> 12:03.930] Because that is what zero trust is all about. [12:04.570 --> 12:08.350] Zero trust is not a word which you can add. [12:08.530 --> 12:14.690] It's not something you can put in front of your layer and make it more trustworthy. [12:15.970 --> 12:31.310] Because their layers itself, while they are useful for both from network design point of view, for us to understand the structure of the network, when you look from a data flow point of view, it has actually started to lose meaning. [12:32.030 --> 12:40.110] Zero trust was driven by, as an ideology, why it started to be so massively adapted, was driven by two megatrends. [12:40.110 --> 12:46.310] First was cloud, and second was, bring your own disaster, also called bring your own device. [12:46.670 --> 13:01.710] Which already blurs that the CASEL AMOT model doesn't work, because now you are allowing devices, which are not from your origin, and can contain things out of your purview and under your control, into your corporate network. [13:01.850 --> 13:08.790] And at the same time, you are placing your assets outside of your MOT, outside of your firewall. [13:08.790 --> 13:19.070] So, we are already in a situation today, where a typical enterprise, and in enterprise, I don't exclude government from the definition of enterprise. [13:19.350 --> 13:25.770] Government agencies, offices, they are enterprise as anything else, regardless of the government. [13:26.830 --> 13:36.190] So, if you are asking from an enterprise, do you know where your data actually is? [13:36.190 --> 13:40.150] If they answer yes, that means they are lying, because they don't. [13:40.270 --> 13:50.750] It is, it's living in a virtual environment, it's living in the containers, it's living in other host systems, in the devices outside of their control. [13:51.110 --> 13:53.050] They don't know where the data is. [13:53.170 --> 14:06.410] So, hence, how you can even think about the previous paradigm of having the CASEL AMOT parameter defense approach to be any shape or form relevant for today's world. [14:06.610 --> 14:20.430] I mean, it's irrelevant for the crime organization point of view, but it's not relevant for the defender's point of view, because you don't, organizations lack completely the visibility today, know where the crown jewels are. [14:20.650 --> 14:30.750] They have no idea where a particular crown jewel is geographically, where it is legislative, because it might not be even in a continent they think it is. [14:31.470 --> 14:37.370] And at the same time, they don't know in what kind of environment, and on what kind of governance model it is today. [14:37.990 --> 14:41.410] And we don't even start from talking about security. [14:41.670 --> 14:43.510] We just don't know where the hell it is. [14:45.530 --> 14:57.330] One more thing which is so important in the definition of zero trust, and which is a new thing coming to this mix, is the software supply chain security. [14:57.970 --> 15:11.870] So, when we look how governments are looking right now, as a regulatory point of view, from a regulatory point of view, the zero trust, they are starting to increasingly include the software supply chain into the discussion. [15:12.790 --> 15:23.590] Of course, there are a lot of commercial entities who are selling a solution, claiming they are open-source when they have only open-sourced the SDK part. [15:24.270 --> 15:30.870] And, obviously, this is not anything else than a snake oil to blur the definition of open-source. [15:32.090 --> 15:39.770] We are now starting to understand the open standards and protocols, their value and meaning in a zero trust architecture world. [15:40.970 --> 15:43.270] But that's only starting right now. [15:43.270 --> 15:49.050] And, of course, the one where this is going is interoperability. [15:49.470 --> 16:00.890] Because the same way as the previous model was fragmented, if you don't have interoperability, you are just replacing a fragmented model with another fragmented model. [16:01.110 --> 16:10.010] We have to bring a unity, because no enterprise today of any reasonable size is working on a single architecture, a single solution. [16:11.710 --> 16:27.930] Most importantly, if we look where the whole definition of zero trust came from, we are still in the paradigm of people not understanding how the definition between hardware and software has been blurring. [16:28.230 --> 16:32.330] So, zero trust is still looked to be a software-centric model. [16:33.790 --> 16:47.970] And not taking into account the elements of what is living in an embedded system, how much code is living in a hidden firmware, how much microcode is, how much all of this is living inside of the systems. [16:48.430 --> 17:03.410] So, eventually, and this is my prediction, we will be evolving more towards understanding that the software supply chain is a supply chain, and that we will have to include open hardware as part of the concept. [17:07.330 --> 17:10.230] Now, if we look about where we are today. [17:10.710 --> 17:23.730] Today, as a bastardization of a Russian proverb, trust but verify, which was by Reagan, it really today is sign in and then ignore. [17:24.030 --> 17:25.770] Trust and maybe verify later. [17:26.010 --> 17:29.210] And that is the opposite of what zero trust is. [17:29.350 --> 17:32.630] Zero trust is never trust and always verify. [17:33.210 --> 17:36.330] The key part is always verify. [17:36.590 --> 17:43.910] It means that the initial login, the initial signing in, the initial getting in the system is just one transaction. [17:43.910 --> 17:50.250] It is only meaning that you got to the place where you can start to send requests. [17:51.150 --> 17:59.010] Now, when you send requests, every request can have to be mapped against multiple different parameters. [17:59.350 --> 18:00.710] So, you have to validate. [18:00.710 --> 18:04.870] Even when, five seconds ago, your policies were accepting that. [18:05.050 --> 18:07.650] Has the policies changed since the last time? [18:07.650 --> 18:17.470] But also, in the edgeless network, because you cannot assume any trust based on where you are, based on what the infrastructure knows, you have to validate all of that again. [18:18.930 --> 18:27.010] And the context also means that you have to think about, and the system has to be thinking, is this behaviorally acceptable? [18:27.690 --> 18:42.430] It's okay if you ask this document, five in the afternoon, and you ask that one document, and maybe a couple of other documents, but what if you ask that document, and a hundred other documents, five in the morning? [18:42.670 --> 18:46.830] Is that behaviorally something which should be a red flag or not? [18:47.970 --> 18:55.350] So, the only way we can get this done is by tokenization of security. [18:57.490 --> 19:04.850] If you are bringing tokenization that allows you to start to run an identity-based security. [19:05.250 --> 19:07.950] An identity here is not the user. [19:08.310 --> 19:09.710] Identity is everything. [19:10.250 --> 19:12.090] Everything needs to have an identity. [19:12.390 --> 19:16.650] The user, the device, the instance, the process. [19:17.030 --> 19:20.790] But also, you have to have an identity to the subjects. [19:21.050 --> 19:23.970] So, you have to have an identity to all the crown jewels. [19:23.970 --> 19:26.490] And that allows you to do a mapping model. [19:27.230 --> 19:33.630] This is leading into the most fundamental part of Zero Trust. [19:33.810 --> 19:43.450] If you take Zero Trust tools, and you don't change the way you are thinking about security, you are probably going to do a disservice and weaken your security. [19:43.750 --> 19:52.270] Because now you are opening, with a tokenization, new attack surface, new attack vectors, which you need to deal separately. [19:52.850 --> 20:00.030] You cannot... when you have a tokenization world, you cannot live still in LDAP world and think about if I disable this account, I'm done. [20:00.290 --> 20:05.550] And that thing, whatever it is, that process, that instance, or that user is locked out. [20:05.730 --> 20:06.890] It doesn't work that way. [20:07.050 --> 20:09.570] So, we have to think about the whole model. [20:09.830 --> 20:12.430] We have to start thinking about our crown jewels. [20:12.830 --> 20:16.050] And we have to think about how this works. [20:16.890 --> 20:29.790] Most importantly, as a security practitioners, and as a security community members, one thing which we have been lacking, and we are still lacking, is the usability studies of security. [20:30.230 --> 20:39.330] If we make security which is unusable, the users, the end users, the system, everybody will find a way around it. [20:39.330 --> 20:44.030] Because the convenience will always win over security. [20:46.330 --> 20:59.710] And from that point of view, zero trust, when we are bringing in a tokenization, is a massive opportunity for us as a security community to think about the end user. [20:59.870 --> 21:08.310] Think about how we make the security to work with the end users in such a way that the end user doesn't feel the pain. [21:08.310 --> 21:14.370] And because the end user, again, will be... that will be driving a Dropbox problem. [21:14.530 --> 21:17.890] You will have unauthorized Dropboxes in organization and whatnot. [21:18.150 --> 21:24.810] They are all symptoms of security being getting in the way of the people who need to have an access to data. [21:25.190 --> 21:32.390] And they are only seeing that as a prohibitor of them to achieve the goals set to them. [21:33.450 --> 21:41.650] So, again, the philosophy is, instead of looking your perimeter, your servers, your firewalls, you have to be looking what are my crown jewels. [21:42.050 --> 21:47.130] And the crown jewels are digital assets and they are workflows. [21:49.330 --> 21:53.950] Actually, the crown jewel very seldom has a human face. [21:54.590 --> 21:57.070] The crown jewels are what you are guarding. [21:58.950 --> 22:04.230] Again, you have to give away from everything you are trusting today, which is what your infrastructure knows. [22:06.050 --> 22:13.710] Also, you have to think about in a way that even when you are allowing user, the users can start to be malicious. [22:13.710 --> 22:18.010] So, by accessing user, all the process can turn to be malicious. [22:18.330 --> 22:23.650] So, you have to be continuously looking into those aspects. [22:23.970 --> 22:31.570] And last but not least, privacy and anonymity has to be preserved while you are using strong identification. [22:32.290 --> 22:36.330] Those two things cannot be competing against each other. [22:36.450 --> 22:37.870] We all have rights to privacy. [22:38.150 --> 22:40.010] We all have rights to anonymity. [22:40.010 --> 22:43.730] In the European Union, we have a law right to be forgotten. [22:44.290 --> 22:50.250] So, you have to be able to coexist with a strong identification of everything. [22:51.550 --> 23:00.850] And remember, when I say everything, it also means, because also now the crown jewels, the files, the digital assets has their own IDs, how we make these coexisting. [23:01.130 --> 23:03.010] And there are a lot of solutions for that. [23:03.230 --> 23:07.650] But if we lose the... if we are... this is a danger zone also. [23:07.650 --> 23:18.910] If we don't think about the privacy and anonymity requirements, when we are looking into the path and journey to zero trust, we are missing the point. [23:20.970 --> 23:24.590] So, as I said, this is a great cold rush. [23:25.770 --> 23:38.070] We are in a situation where the most important part to convey to our organizations, wherever we work, is that zero trust is not the product. [23:38.270 --> 23:39.810] Zero trust is not the solution. [23:40.030 --> 23:42.010] So, zero trust is not something you can buy. [23:43.750 --> 23:44.610] It's a journey. [23:46.010 --> 23:52.710] However we define zero trust today is going to be different than what we think zero trust is five years down the road. [23:52.710 --> 23:54.310] It's going to be evolving. [23:54.510 --> 24:06.550] And we already have an outdated model, because the way we define zero trust today was defined before pandemic, before Ukraine war. [24:06.810 --> 24:09.210] And all of these are great accelerators. [24:10.130 --> 24:17.470] The pandemic was a great accelerator, which caused an adaptation to remote working. [24:17.470 --> 24:19.650] It caused changes of information paths. [24:19.810 --> 24:22.350] It actually threw away our heuristic models. [24:22.650 --> 24:30.270] So, a lot of the security principles, our automated security is working on today, are not actually working. [24:30.990 --> 24:35.590] We are still, we haven't updated the heuristic models, which are inherently in the system. [24:35.750 --> 24:42.850] And for that reason, we are in a situation where the light remains green, even when it should go yellow or red. [24:45.660 --> 24:48.700] So, zero trust will take time. [24:48.940 --> 24:50.740] Zero trust will be evolving. [24:51.060 --> 24:52.800] We will have new requirements. [24:53.820 --> 24:58.240] And most important requirement is to change your thinking. [24:59.560 --> 25:01.600] Just to go through a few things. [25:02.080 --> 25:05.120] So, this is the document I was mentioning. [25:05.480 --> 25:13.540] This is the 800-207 Zero Trust Architecture by National Institute of Standards and Technology. [25:13.540 --> 25:16.440] As you see, there is the document history. [25:16.660 --> 25:19.340] The final version was August 2020. [25:19.780 --> 25:23.020] The first draft version was 2018. [25:23.760 --> 25:33.400] So, this document, while it is better than anything else we have today as a standard, it's still starting to show its age. [25:34.200 --> 25:47.900] Most importantly, if you read through this document and compare it to the solutions to be sold to you, it's blatantly obvious that the solutions sold to you are not meeting the requirements. [25:48.320 --> 25:58.740] So, if you are in a position of making recommendations, then familiarizing with this standard is key document. [25:58.740 --> 26:08.480] To understand what United States government and other governments who are implementing these standards, for example, common criteria countries, they all are requiring it. [26:08.680 --> 26:15.840] So, I would say today, give or take 30 countries are looking at this document as the key document. [26:18.020 --> 26:22.140] How this current urge started, it was May 12th. [26:22.240 --> 26:30.060] This is the Executed Order 14-028, which was mentioned in the name of the speech. [26:31.200 --> 26:40.060] This document has a number of things which are, I would say, untraditional and good. [26:41.500 --> 26:48.140] Usually, when you have executed order, when you are having mandate, it is how the federal government will work. [26:48.280 --> 26:51.040] Because that is the traditional way of thinking this. [26:51.140 --> 26:53.240] And that's the primary focus and authorization. [26:53.880 --> 27:01.200] But already, this document is calling a wider cooperation between public and private sector. [27:01.200 --> 27:08.160] Recognizing that how much of the government functions are outsourced. [27:08.360 --> 27:19.040] And how actually, in that sense, a lot of times government is not even self-aware the extent of the outsourcing. [27:19.620 --> 27:25.700] This was followed by the Office of Budget Management releases the federal strategy. [27:26.520 --> 27:31.060] And now you see the zero-tracks architecture already on the headline. [27:32.500 --> 27:40.380] This is putting even more pressure towards the private industries to comply if they want to do business with the federal government. [27:41.160 --> 27:45.060] Not all businesses need to do business with the federal government. [27:45.060 --> 27:58.920] But this also was the launching shot for a number of other governments to pick up their pen and start to look into the standardization. [27:59.120 --> 28:05.020] If we go back to here, we already see that, for example, Japan is involved already in this document first. [28:06.740 --> 28:12.240] So, the implementation is required to be complete by end of physical year 24. [28:12.240 --> 28:14.500] So, there's also a deadline set. [28:15.980 --> 28:21.060] If you want to look what the strategy document is, itself, this is the strategy document. [28:21.280 --> 28:37.180] And this is the part where a lot of other governments are looking into this document and see what part of this strategy is applicable and how to implement that to their respective governments, like European Union is right now looking. [28:37.180 --> 28:45.120] So, this is the document where you understand what the overall strategy looks like. [28:45.220 --> 28:48.160] And that is 29 pages for a strategy document. [28:48.220 --> 28:49.620] It's not very long. [28:49.840 --> 28:51.500] It's a fun reading. [28:52.160 --> 28:53.520] Gives you good sleep. [28:53.800 --> 28:55.520] Well, not actually. [28:55.760 --> 29:00.880] But it's one way of getting understanding where we are going. [29:00.880 --> 29:03.860] And this is only one of the milestones. [29:04.260 --> 29:06.940] Because this is the follow-up document. [29:07.840 --> 29:08.940] There's a lot of... [29:08.940 --> 29:16.940] NIST is publishing the Exhibit Order Section 4 Task and Timelines follow-up. [29:17.200 --> 29:26.640] So, unlike a lot of times when a government is issuing a guidance or requirement, and it just goes in a wait. [29:27.080 --> 29:28.240] And there's no follow-up. [29:28.340 --> 29:29.780] Nobody is following timelines. [29:30.180 --> 29:33.840] Rest assured, in this case, there is a published... [29:33.840 --> 29:36.200] These all are in NIST website. [29:36.480 --> 29:39.200] There's published follow-up and deadlines. [29:39.460 --> 29:40.720] And the train is going. [29:41.020 --> 30:05.800] I have to say, personally, that when the 26th of January, the strategic document was issued, less than two weeks from that, I was in a series of conference calls with a lot of government bodies and their private sector consciences, where it was already started to be hammered down to the private sector players. [30:06.320 --> 30:11.840] What is... what we want you to do, and how late in the game you are if you haven't started. [30:12.260 --> 30:20.360] If you didn't start your certification this or process that, you are already pushing your luck. [30:20.360 --> 30:21.640] to be compliant. [30:22.240 --> 30:31.660] So, again, this has been a strongly... government has been strongly helpful for private sector to understand what they are expected to do. [30:31.780 --> 30:32.560] What is the deadline? [30:32.880 --> 30:35.200] And, by the way, we have eyes on you. [30:35.600 --> 30:38.660] This is not something which will go away and be forgotten. [30:41.480 --> 30:48.280] And the more to follow, this is, again, a widely followed area. [30:48.280 --> 30:54.540] There is a lot of sector-specific follow-ups, industry-specific follow-ups. [30:54.920 --> 31:00.660] This is something where a lot of government attention is brought to. [31:01.160 --> 31:10.600] And, again, the point here is, I think government is here just asking something to be done, which should be done anyway. [31:10.600 --> 31:15.020] They are not imposing something unreasonable or extra burden. [31:15.720 --> 31:19.980] We are in a situation where we cannot live without this. [31:21.060 --> 31:23.160] So, it's all about identities. [31:23.600 --> 31:25.300] The first is your identity. [31:25.920 --> 31:27.980] Then you authenticate the identity. [31:28.520 --> 31:31.020] Then you contextualize every request. [31:31.200 --> 31:42.560] And every single time you have a new request, you go through this process, unless there is a specific reason not to go through the whole process and say you trust for the next two minutes or whatnot. [31:43.240 --> 31:46.540] You grant the minimum possible privileges. [31:47.320 --> 31:50.800] So, you analyze the context of the request. [31:51.280 --> 32:03.200] Then you determine what is the minimum possible privileges which you are required to grant to enable that request to go through. [32:03.620 --> 32:05.160] And then automatic generation. [32:05.560 --> 32:12.040] Once the request is done, once the purpose is done, automatically degenerate and remove the privileges. [32:12.240 --> 32:15.700] Don't let them hang around unless there is a reason. [32:16.140 --> 32:39.340] Because you are still assuming that while that request was reasonable at the time when it was given, once the permissions have been granted, the user process, instance, the device, whatever it is you have granted it to, will be having an opportunity to turn malicious and misuse the privileges as granted. [32:39.700 --> 32:43.520] So, privileges are different than trust. [32:45.560 --> 32:50.160] And as mentioned before, tokenization is the only way we can get this done. [32:51.640 --> 32:56.820] And tokens, again, can be copied, spoofed, free play attack. [32:57.040 --> 32:58.860] We all know all the tricks in the book. [32:59.100 --> 33:08.540] So, once we say token, now we open ourselves to a whole new area of security which we have to think through. [33:09.560 --> 33:15.280] If you look how the tokens were used originally, they were used inside of trusted network. [33:15.280 --> 33:20.700] Or they were used as the augmentation of the infrastructure security. [33:21.180 --> 33:25.040] Say, Microsoft networks, for example. [33:25.380 --> 33:28.280] So, the point here is we cannot even... [33:28.860 --> 33:35.460] We have to rethink the token, the concept of token, how it works in this kind of environment. [33:39.790 --> 33:48.270] So, this is just a recapping again, because repeating the same thing is always a good idea. [33:48.810 --> 33:51.190] Always assume everything is hostile. [33:52.350 --> 33:53.510] Don't let... [33:53.510 --> 33:55.090] Don't give a token... [33:55.090 --> 34:02.230] This is a token for the next 365 days and assume it's good because the time to leave for the token or expiration hasn't gone. [34:02.230 --> 34:06.250] You have to be looking this from the completely different point of view. [34:06.350 --> 34:07.750] Tokens can always be copied. [34:08.310 --> 34:10.090] Tokens can always be misused. [34:10.450 --> 34:17.670] And even if the token arrives from a trusted network which shouldn't be trusted, that is no excuse. [34:20.290 --> 34:22.470] And humanly, we are... [34:22.470 --> 34:25.250] Now we come to the philosophical part. [34:25.250 --> 34:32.530] But we are always assuming in an old model that once you have authenticated, you can trust. [34:32.910 --> 34:36.830] But authentication, authenticated is very different concept than trust. [34:37.610 --> 34:43.990] So, if you are knowing that this is a doctor of evil, it doesn't change the fact it's evil. [34:44.150 --> 34:48.470] Sometimes you need to speak with the doctor of evil and it's good to know that it's not somebody else. [34:50.170 --> 34:52.570] But authentication is not trust. [34:52.570 --> 34:57.290] And all is fair in love and war and stealing your digital assets. [34:58.450 --> 35:00.590] So, we have to remember this. [35:00.690 --> 35:06.930] Tokens are not an intrinsic implementation of trust. [35:07.130 --> 35:08.570] It's not a something you can... [35:08.570 --> 35:10.030] I have this challenge coin. [35:10.390 --> 35:13.030] Hence, trust me, I work for that agency. [35:13.310 --> 35:14.790] We all know that doesn't work that way. [35:17.190 --> 35:21.570] This all comes from the fact that we are not thinking critically. [35:21.570 --> 35:26.050] And because we are not thinking critically, the code we write is not thinking critically. [35:26.330 --> 35:30.470] And the systems we design are not thinking critically. [35:31.450 --> 35:37.450] And it all comes from the fact that we all want to believe that we can think like the enemy. [35:37.670 --> 35:38.610] But it's really hard. [35:38.990 --> 35:44.110] And the problem is, most of the time we are thinking how we would love our enemy to think. [35:44.110 --> 35:46.290] But it's called enemy for a good reason. [35:46.790 --> 35:52.450] It's because we don't have a consensus with the enemy that this is how you should be playing this game. [35:53.550 --> 35:58.930] Because the enemy, your adversary, in their own mind, they think they are the good guys. [35:58.930 --> 36:03.790] Nobody goes in front of the mirror every day and say, I'm the evil. [36:04.450 --> 36:04.570] No. [36:05.270 --> 36:06.770] Whatever is the excuse. [36:07.290 --> 36:14.770] Whatever is the way you are able to turn and think that you are the good guy, you are the good guy. [36:15.090 --> 36:23.210] And this is the major part where our human mind and our monkey brain is misleading the way we think about security. [36:23.210 --> 36:27.950] Because we think, if I'm good, hence the other person has to be evil. [36:28.090 --> 36:36.690] If I'm a defender, then the other person must have a moral dilemma, a moral thing they have to overcome. [36:36.690 --> 36:39.670] Because they are attacking me and they are trying to steal my stuff. [36:40.130 --> 36:41.410] That doesn't work that way. [36:41.890 --> 36:48.530] And we are now talking about, not curiosity, we are talking about the real cyber war and real cyber crime. [36:48.770 --> 36:50.970] A criminal enterprise, nation state. [36:50.970 --> 36:54.990] They still have their own mission and they think they are the good guys. [36:57.150 --> 37:02.130] We humans are so successful in the planet because humans, we build communities. [37:04.010 --> 37:08.930] And because we build communities, the root thing is we trust. [37:09.130 --> 37:12.450] We intrusively trust each other until proven otherwise. [37:13.410 --> 37:21.610] Because we are building communities, that also means everybody, even the people who have critical thinking, they will go native eventually. [37:22.090 --> 37:23.010] We all will go native. [37:23.450 --> 37:35.670] Critical thinking is so unnatural for humans that you have to cherish, you have to put a lot of effort, as a sexual repractioner, to keep your powder dry, to be able to think critically. [37:37.930 --> 37:44.370] Because we all have our neighbors, we all have our hacker friends, we all have the people we drink beer with. [37:44.370 --> 37:47.350] And all of that is based on trust. [37:47.690 --> 37:53.330] We give our credit card to bartender and we trust that there is a social contract. [37:53.790 --> 38:01.910] We are all the time, every action we do, even when in advertising it says everything is a negotiation, we are actually, everything is based on trust. [38:03.030 --> 38:07.950] And because of this, every system we build has a flaw of over-trusting. [38:08.090 --> 38:09.910] Because that comes from us. [38:13.830 --> 38:28.750] So, the last but not least in the philosophical section is when the consultancy companies, which I think are mainly evil, because if you are not part of a solution, a good money can be made by prolonging the problem. [38:29.670 --> 38:39.750] A lot of the think tanks are always claiming that they are seeing and they are helping you to see the future, but they are really looking for an expected surprise. [38:40.130 --> 38:43.490] They are not very good in looking for unexpected surprises. [38:43.990 --> 38:55.050] So, the idea of zero race, the ideas of something going drastically wrong outside of the definition, that is not coming from them. [38:58.010 --> 39:05.230] So, zero trust, the whole idea of zero trust as philosophy is to get us out of this vicious loop of trust. [39:06.410 --> 39:11.690] Force us into the mindset where trusting is not an option. [39:12.550 --> 39:18.550] Breaking the way our monkey brain is trying to build a community in the area of security. [39:18.550 --> 39:26.630] making us think in a way of emulating what a critical thinker would do. [39:27.850 --> 39:37.090] And I cannot overstress this, you cannot implement zero trust tools and have good results if you don't change your way of thinking as a security practitioner. [39:37.390 --> 39:48.310] This is all about starting from our mind, because the same part is your adversary, if you talk about nation-state, or you are very well-motivated crime organization. [39:48.530 --> 39:49.990] They are not looking at your technology. [39:50.230 --> 39:53.450] They are looking at your mind as a defender, your blue team. [39:53.870 --> 39:54.750] That's what they are after. [39:54.870 --> 39:58.270] They are trying to understand how you think in order to go around. [40:01.230 --> 40:15.530] So, the part where I was promised that instead of only telling about how the world is horrible and broken, which it is, a little bit of hope how the things can be fixed, and how you can do this with open-source. [40:19.230 --> 40:29.430] So, when we look at our current solutions, and when we understand the open-sources journey, we cannot implement this overnight. [40:30.230 --> 40:34.930] Every single company, every single security practitioner, you have to prioritize. [40:35.370 --> 40:39.910] You have to understand what is the most important thing I can do first, second, third. [40:39.910 --> 40:46.510] What is the maximum impact I can generate in a limited resources I have and time? [40:46.890 --> 40:49.170] And what is my journey? [40:49.450 --> 40:51.230] And everybody's journey is different. [40:51.450 --> 41:03.350] You cannot copy the company X's journey and assume it works for you, because everybody's network, everybody's physical organization, the human organization processes are different. [41:03.530 --> 41:05.810] It always has to be looped. [41:05.890 --> 41:08.150] What are my crown jewels? [41:08.150 --> 41:10.290] What is my weakest point? [41:10.430 --> 41:18.510] And how I start my journey to start implementing the principles of zero trust, step by step? [41:19.470 --> 41:29.430] This also is revealing the other scenario, because the sales pitch is, well, we have this wonderful overlay network. [41:29.610 --> 41:31.010] We drop it on top of your thing. [41:31.150 --> 41:32.290] Now you are zero trust. [41:32.450 --> 41:33.710] You are good to go. [41:33.970 --> 41:35.350] It doesn't work this way. [41:36.270 --> 41:48.110] Sometimes you can use reverse proxies and other technologies to bring your legacy systems under a zero trust umbrella, but it's still hard. [41:48.530 --> 41:53.870] And there's still all the psychological, the philosophical thinking has to change. [41:54.090 --> 42:00.110] You cannot drop something on top of your current system and expect that to solve the problem. [42:00.810 --> 42:06.630] So, I'm talking about a little bit of open-source system project. [42:06.810 --> 42:08.390] It's a number of tools called ORI. [42:08.650 --> 42:15.830] In the interest of full disclosure, I'm the head of security research of ORI, open-source and ORI company. [42:16.070 --> 42:20.210] So, I'm talking about a little bit what is the open-source model for this. [42:20.210 --> 42:24.910] First of all, this is a... this doesn't solve all the open-source problems. [42:25.050 --> 42:27.570] It's a permissive, a license model. [42:27.750 --> 42:30.690] So, everything is... and it's full open-source. [42:30.810 --> 42:33.330] This is a... everything is in the GitHub. [42:34.050 --> 42:36.370] The core system is in the GitHub. [42:36.610 --> 42:39.690] So, there's no propriety code hiding in a corner. [42:40.070 --> 42:52.830] The only place where there's a code running in the system is if you want to use ORI as a cloud service, which has the benefits of threat intelligence and the federated identities and whatnot. [42:53.190 --> 42:57.850] If you self-host, you can self-host it and we don't even know you exist. [42:58.270 --> 43:04.310] Just to give you a few ideas what size of community ORI is, it's almost 500 contributors. [43:04.910 --> 43:11.070] As of today, it's 276 million docker pools checked an hour ago. [43:11.070 --> 43:20.110] I don't know what is the decimal behind it because the current poll rate is over a million pools per 24 hours. [43:20.570 --> 43:21.490] That's the reason. [43:21.670 --> 43:25.410] So, I actually... from last night, I needed to change the five to six. [43:26.190 --> 43:30.110] It's a 25.5 million GitHub stars. [43:30.590 --> 43:48.970] And then, from a telemetry point of view, if you're self-hosting, there is no telemetry coming to our site, but currently, 365 billion requests served over 50 billion per month. [43:49.150 --> 43:51.790] You know, there's a little bit of a seasonality. [43:52.190 --> 44:05.790] But this already gives you a good idea that even when we don't know the massive number, which comes from the docker pools, the one trillion request is going to happen this year, probably October. [44:05.790 --> 44:12.850] So, we are massively having the information, getting the threat intelligence, understanding what happens in the world. [44:13.190 --> 44:16.810] The ORI project itself has four major parts. [44:17.570 --> 44:21.850] It's a Kratos, which is a... first of all, everything is headless. [44:23.050 --> 44:31.290] So, this is... there is no... whatever you want to have the user interface is your user interface when you use ORI open-source platform. [44:32.430 --> 44:43.950] Kratos gives you all of the things which user loves and needs, from passwordless to social sign-in, which seems to be the crazed dance of today, which everybody wants to have. [44:44.290 --> 44:50.150] So, the question here is, why would you write your own login today? [44:51.130 --> 45:05.510] We all know that when you write your own login, when you write your own authentication, injections happen, shit hits the fan and money is lost or user accounts were leaked or whatnot. [45:05.910 --> 45:12.650] So, the question here is, when you think as a security practitioner, where you put your resources? [45:12.650 --> 45:16.910] We all have a problem of hiring qualified people. [45:17.190 --> 45:28.210] That is the scarce resource, where you put your human resources, so that they benefit best your security and your companies and protecting your jewels. [45:28.430 --> 45:32.530] So, Kratos is handling the part of authentication. [45:32.990 --> 45:36.730] Hydra is, again, API on headless. [45:37.230 --> 45:39.730] And it is the identity site. [45:39.730 --> 45:45.770] So, that is handling the OAuth 2.0 open ID, connect provider, etc. [45:46.130 --> 45:51.870] And it is an identity management platform, which provides the interoperability. [45:52.650 --> 45:55.510] As mentioned before, the world today is fragmented. [45:55.650 --> 45:56.650] It's not going to change. [45:57.330 --> 46:08.430] And it's going to be very hard to imagine a world where you can transition into a place where, all of a sudden, everything is coming from a single ID. [46:08.430 --> 46:13.190] So, Hydra provides you the interoperability between different identity providers. [46:15.090 --> 46:20.390] Oathkeeper is the reverse proxy, enabling you to transition into a zero-trust world. [46:21.470 --> 46:24.770] Again, it's a networking proxy. [46:24.950 --> 46:25.650] It's a sidecar. [46:26.970 --> 46:31.910] It handles the authentication, validation of the tokens, all of that part. [46:34.610 --> 46:43.730] And KITO is the planet-sized scalable infrastructure, an open-source implementation of Google Sansibar research paper, which we mentioned before. [46:44.410 --> 46:53.570] So, how... once you are... if you have a single location, single continent, you can self-host, that's great. [46:53.970 --> 47:01.770] When, if you are a... want to self-host, but you need to build a global infrastructure, this gives you that capability. [47:01.770 --> 47:06.490] So, I'm not trying to sell the idea of you have to use our cloud. [47:06.750 --> 47:12.370] I'm saying that this is the way you can implement yourself a planet-scale infrastructure. [47:17.010 --> 47:23.210] Again, as mentioned before, first of all, the snake oil sales is high. [47:24.190 --> 47:26.510] The question is how you implement it. [47:26.690 --> 47:32.330] What is... how you put your resources, your... your... your working hours, to give best bang for the buck. [47:34.230 --> 47:39.290] One question is when you are... if you are self-hosting, that means you are... you have to maintain... [47:39.290 --> 47:45.330] not only do software upgrades in your security software, but you have to maintain your execution environment. [47:45.330 --> 47:47.210] You... and all of that. [47:48.110 --> 47:53.730] You have to understand also, and remember that when you do a context... context relation... [47:53.730 --> 47:57.590] I have dyslexia... context relation of... of every request. [47:57.870 --> 48:00.830] And you do a validation of the cryptocurrency token every single time. [48:01.030 --> 48:02.730] It's not computationally cheap. [48:03.070 --> 48:07.470] So, there is a lot of things you have to think about how you manage latency and jittering. [48:08.370 --> 48:13.270] If you... if somebody is selling you a solution which doesn't give you an answer to that... [48:13.270 --> 48:15.390] that's the one part where you have to think about. [48:15.710 --> 48:17.810] Especially gaming industry, for example. [48:18.090 --> 48:23.350] You get very quickly in a problem where your game doesn't run as it's supposed to run... [48:23.350 --> 48:25.470] if you haven't solved these problems. [48:27.330 --> 48:34.650] And the last but not least is... if you are running... system alone, you don't gain the threat intelligence... [48:35.590 --> 48:41.830] from what might have happened... is a trend in your continent, trend in your industry... [48:42.690 --> 48:45.290] or... in an area of... of identities. [48:45.590 --> 48:49.770] What... you don't know if the same identity has been compromised... [48:49.770 --> 48:52.190] in somewhere else, in some other environment. [48:54.330 --> 48:55.090] That's it. [48:55.250 --> 48:58.050] I... hopefully... ended in time. [48:58.350 --> 48:58.570] Yes. [48:58.850 --> 49:00.710] We have four minutes for questions. [49:10.690 --> 49:13.010] And I, by the way, don't see anything here. [49:17.600 --> 49:18.480] You have a question? [49:19.600 --> 49:21.080] Anybody have questions from the audience? [49:21.740 --> 49:22.440] Can you hear me? [49:22.600 --> 49:23.200] Yeah, there we go. [49:23.280 --> 49:23.660] Now it's on. [49:23.800 --> 49:24.160] There we go. [49:27.770 --> 49:28.130] Hello? [49:28.570 --> 49:28.790] Hello? [49:29.410 --> 49:32.830] I do a lot of critical and water... you know... [49:32.830 --> 49:34.970] Sorry, my dyslexia getting to me too. [49:35.730 --> 49:37.770] A lot of critical power and water auditing. [49:38.150 --> 49:40.750] And we hear a lot, you know, people asking for, you know... [49:40.750 --> 49:43.590] let's go from, you know, absolutely no security to zero trust... [49:43.590 --> 49:44.790] because in water, we're way behind. [49:44.870 --> 49:46.230] In electric, we're a little less behind. [49:47.850 --> 49:50.590] But along that thread of... that thread of thought... [49:50.590 --> 49:54.610] what do you think about, you know, for super legacy systems like that... [49:54.610 --> 49:57.850] looking at, like, the PLCs and the HMIs that run that kind of stuff... [49:57.850 --> 50:00.410] you know, do you think that's something that it's worth standing up? [50:00.930 --> 50:04.570] You kind of were mentioning the middleman component for zero trust. [50:04.570 --> 50:06.010] Is it worth standing something up there? [50:06.030 --> 50:08.730] Or is it worth waiting for equipment that's capable of doing it on its own? [50:09.990 --> 50:14.250] So, if you look at the critical infrastructure everywhere in the world... [50:14.250 --> 50:16.730] all areas of critical infrastructure... [50:16.730 --> 50:18.630] it's hilariously outdated. [50:20.210 --> 50:24.290] At the same time, it's going to be hilariously outdated 20 years down the road. [50:25.630 --> 50:29.270] So, this is a part where whatever it takes... [50:29.270 --> 50:33.670] if it's a micro-segmentation and gatekeepers, reverse proxies... [50:33.670 --> 50:38.110] if you wait for that area of the world... [50:38.110 --> 50:39.930] and especially the hardware... [50:39.930 --> 50:43.150] because today's new hardware offered is not secure... [50:43.150 --> 50:45.810] you need to wait for this generation to go outdated... [50:46.210 --> 50:47.270] which is 20 years down the road. [50:47.350 --> 50:47.990] You cannot wait. [50:48.350 --> 50:49.670] So, the question is then... [50:50.250 --> 50:53.430] alright, this is going to be a band-aid, which is bad... [50:53.430 --> 50:57.110] but what is the best band-aid I can have to protect them? [50:57.110 --> 50:58.750] how I implement something... [50:58.750 --> 51:02.590] whether it's a reverse proxy, micro-segmentation, gatekeepers... [51:03.050 --> 51:07.470] to help that hilariously outdated and insecure system... [51:07.470 --> 51:08.930] to survive in today's world. [51:09.170 --> 51:10.730] Because, at the same time... [51:10.730 --> 51:14.110] you hit the nail to its head... [51:14.670 --> 51:17.190] if you compromise the critical infrastructure... [51:17.650 --> 51:19.130] you compromise the society. [51:19.770 --> 51:21.250] we did a study... [51:21.250 --> 51:22.470] for one... [51:22.470 --> 51:23.330] a geographic area... [51:23.690 --> 51:24.610] and we found out that... [51:24.610 --> 51:26.610] if we shut down the water service... [51:26.610 --> 51:28.630] people will be unhappy... [51:28.630 --> 51:29.650] in a few days' time. [51:30.190 --> 51:31.150] unhappy meaning... [51:31.150 --> 51:32.310] they are starting dying. [51:32.910 --> 51:35.210] but if you bump the silver water... [51:35.210 --> 51:37.490] to the streets... [51:37.490 --> 51:39.750] you will have the society gone in three hours. [51:40.650 --> 51:41.170] so... [51:41.170 --> 51:42.770] we have to think about... [51:42.770 --> 51:43.750] the real-world consequences... [51:44.350 --> 51:45.890] of these BLI and SCADA systems... [51:47.090 --> 51:47.610] and... [51:47.610 --> 51:47.890] and... [51:47.890 --> 51:48.770] the answer to... [51:48.770 --> 51:49.890] to you is... [51:49.890 --> 51:50.870] you have to... [51:50.870 --> 51:51.930] you cannot wait... [51:51.930 --> 51:52.410] because... [51:52.410 --> 51:53.150] if you wait... [51:53.150 --> 51:54.190] you wait 20 years... [51:54.190 --> 51:54.870] and then... [51:54.870 --> 51:56.690] something bad will happen before that. [52:01.400 --> 52:03.340] I think we're out of time... [52:03.340 --> 52:03.720] for questions... [52:04.280 --> 52:04.800] but... [52:04.800 --> 52:05.480] you can... [52:05.480 --> 52:06.360] I think, Hari... [52:06.360 --> 52:07.300] if you have time... [52:07.300 --> 52:08.740] to speak to some folks... [52:08.740 --> 52:09.620] off the podium... [52:09.620 --> 52:10.260] that would be great. [52:10.260 --> 52:11.900] Give it up for Harvey Hirstie... [52:11.900 --> 52:12.740] one more time, everyone. [52:12.940 --> 52:13.340] Thank you.