[00:00.920 --> 00:12.980] So we're actually going to do something a little bit different than what's in the program because I was relatively shocked to see Lee Felsenstein here. [00:13.220 --> 00:15.900] He's one of the original kind of hackers. [00:16.440 --> 00:25.680] And what we're building with NimVPN is a defensive tool to resist mass surveillance even by nation state level adversaries. [00:25.680 --> 00:35.580] And so on some level, we're fighting a negative system, a society of control, in order to give ourselves a degree of freedom. [00:35.820 --> 00:37.500] That's what privacy affords us. [00:38.120 --> 00:43.780] However, I think it's also important to have a vision, a positive vision of social change. [00:43.780 --> 00:59.900] And so I think we should... I'm going to do my talk relatively quickly in order to hand the mic to Lee, who will give forth his, I think, positive vision of what... and both the history of what can be done to change society via technology. [01:00.740 --> 01:02.020] So this is Lee. [01:02.400 --> 01:03.280] He's right there. [01:03.780 --> 01:09.860] Just for people who may not know of him, it's detailed in an excellent little book, at least the first third, called Hackers. [01:10.020 --> 01:16.880] But he originated a lot of work in social media with community memory in the 70s and personal computing with the sole 20s. [01:16.880 --> 01:23.420] And he's selling his book, because he's probably too polite to advertise, next to the info desk. [01:25.540 --> 01:31.160] And then, you know, after... I'm just going to give a little bit of historical context about why we're building this. [01:31.980 --> 01:42.200] Obviously, digital communication took off due to the work of Lee and many other people, my former boss, Tim Berners-Lee, so forth and so on. [01:42.200 --> 01:50.520] However, one of the main problems facing the early Internet is there was no cryptography, right? [01:50.620 --> 01:55.320] So cryptography at that point, when ARPANET was taking off, was effectively a military secret. [01:55.600 --> 02:00.260] I mean, I know Vint Cerf, and he said, yeah, that we knew about it, but we couldn't put it in the public version. [02:00.880 --> 02:05.500] And thanks to Whitfield Diffie and Hellman, we did get public key cryptography. [02:07.060 --> 02:10.420] However, public key cryptography only solves half of the problem. [02:10.420 --> 02:20.880] You can have an encrypted message, but the metadata, who is sending data to whom, reveals valuable information. [02:20.980 --> 02:25.400] Something that's more valuable than the actual content of the message you're sending. [02:25.840 --> 02:35.120] So David Cham, another personal hero of mine, invented this thing called MixNets, which is honestly a little bit simpler intuitively than cryptography. [02:35.120 --> 02:49.180] How a mixnet works is that when you're sending a message and you want to make who's sending it to who anonymous, you just mix it up like shuffling a deck of cards with other people's messages. [02:49.180 --> 02:52.220] So it's a bit, you know, does what it says on the tin, so to speak. [02:52.540 --> 02:56.080] And that allows kind of anonymous, untraceable communication networks. [02:56.200 --> 03:06.240] The concept was from like his PhD thesis in 79, printed in this wonderful essay, which is very readable, called Untraceable Electronic Mail, Return Address to Digital Pseudonyms. [03:06.240 --> 03:20.600] And then he came up with a second concept to prevent what he considered the dossier society, which would rob our way of, you know, how information is used about us, which is to create what's called anonymous credentials. [03:20.600 --> 03:23.800] So we're probably familiar with credentials, certificates. [03:24.320 --> 03:27.040] You get TLS certificates whenever you connect to a website. [03:27.340 --> 03:31.040] Certificates just like you have a signed thing, which gives you some attributes. [03:31.280 --> 03:40.540] And what he imagined is that rather than giving yourself a permanent identifier, you would have a way to prove anonymously, you know, who you are, what you've done. [03:40.660 --> 03:44.420] I attended HOPE or, you know, I'm over 18 or whatever. [03:44.680 --> 03:47.200] And you could do this with anonymous credentials. [03:47.200 --> 03:52.880] So we actually use both kinds of systems to make a fully anonymous communication network. [03:53.120 --> 03:58.500] And we believe this is continuing the legacy of the cypherpunks, one of Lee's friends, Jude Milhoun. [03:58.680 --> 04:06.160] And a lot of people think, okay, all this crypto anarchist stuff is very right-wing libertarian. [04:06.160 --> 04:17.780] However, I think it is important to remember that the editor of Mondo 2000, who invented the term cypherpunk, you know, was a civil rights activist and a woman. [04:18.000 --> 04:26.820] So we have a lot of representatives from the very originating origination of these terms from people who are facing oppression. [04:27.340 --> 04:39.880] And the concept of the mixed net came to me, I know he's somewhat of a controversial character in these circles, but nonetheless, I think he's also was a political prisoner and someone we should support from Julian Assange. [04:39.880 --> 04:51.300] Because he, you know, someone who's taking in very valuable data where that communication between, you know, someone like Julian Assange and a whistleblower would get the whistleblower put in jail. [04:51.600 --> 04:59.600] He was very concerned that when you're using most communication networks, a global adversary that can watch the entire network could de-anonymize you. [04:59.600 --> 05:08.440] And there was also additional concerns, which I think are valid under the Trump regime, that a lot of the tools we use now, such as Tor, what's going to happen when the U.S. government cuts their funding? [05:08.780 --> 05:09.700] They're already trying. [05:09.940 --> 05:11.600] So what we did over the last... [05:12.360 --> 05:16.820] We presented the first version of the system way back in HOPE 2020. [05:17.380 --> 05:20.480] It's called Resist the NSA-Level Global Address Series by NIMMixNet. [05:20.500 --> 05:22.240] So I'm not going to go into technical details. [05:22.440 --> 05:23.620] You can watch that video. [05:23.620 --> 05:24.420] It's online. [05:24.420 --> 05:29.780] But essentially, how a MixNet works is it has kind of two components. [05:30.240 --> 05:31.880] One is very similar to Tor. [05:32.260 --> 05:40.280] We hop your traffic through multiple independent servers, ran by independent people who we don't even know who they are. [05:40.480 --> 05:45.040] In our case, that's ran by a smart contract on a blockchain, but there's probably other ways to do it. [05:45.320 --> 05:46.720] That's the only way we've seen that works. [05:47.760 --> 05:50.060] We also use cover traffic. [05:50.060 --> 05:53.760] So this is not something that's in the original Chami and MixNet designs. [05:53.960 --> 06:00.660] But effectively, if you want to imagine, like, if I'm sending a message and I'm mixing other messages, that's fine. [06:00.740 --> 06:01.960] But what if I'm not sending a message? [06:02.080 --> 06:03.820] Well, there's not enough people sending messages. [06:04.420 --> 06:07.520] So what we do is we add fake cover traffic. [06:07.520 --> 06:09.300] So you're always emitting messages. [06:09.460 --> 06:11.260] It does, on mobile, burn your battery down. [06:11.360 --> 06:12.200] So you turn it off on mobile. [06:12.300 --> 06:17.980] But it continues to be what we do on desktop NIMMixNet applications. [06:17.980 --> 06:22.920] And the most important thing is, you know, the general concept of Choms, of packet mixing. [06:23.180 --> 06:27.820] So when you use something like Tor, maybe we should do a quick illustration. [06:29.920 --> 06:42.060] What happens is that you create a circuit through the Tor network and you synchronously stream Internet traffic for, you know, I think it's like 10 minutes right now. [06:42.060 --> 06:44.640] You can possibly change that parameter, create new circuits. [06:44.860 --> 06:46.820] And then every 10 minutes, you create a new circuit. [06:46.960 --> 06:51.260] And all your packets for those 10 minutes or so go through that circuit. [06:51.800 --> 06:53.540] So a mixnet is very different. [06:53.540 --> 06:54.860] That's the bottom here. [06:55.680 --> 06:59.220] What we do is we mix the packets up. [06:59.220 --> 07:09.180] So the packets are put in, your data is put in encrypted packets using a packet format called the Sphinx packet format, which you can read about and subscribe to Anya's previous presentation. [07:09.560 --> 07:15.480] And that Sphinx packet format takes whatever some of your data and ships it through one route. [07:15.660 --> 07:23.240] And your next part of your data you're sending goes through another Sphinx packet through an independently chosen route. [07:23.240 --> 07:30.560] So what's different is that a mixnet is what you would call message-based asynchronous communication. [07:31.140 --> 07:38.400] And that makes it a bit more anonymous because we can put stuff in these packets, which are of uniform length and encrypted. [07:39.020 --> 07:46.200] And then at each hop, we basically take... we do an exponentiation. [07:46.200 --> 07:46.940] I'm not sure exactly. [07:47.500 --> 07:50.440] And that basically scrambles the ciphertext. [07:50.680 --> 07:55.980] So like the bits in each ciphertext are scrambled at each hop. [07:56.180 --> 07:57.640] You do five hops. [07:57.760 --> 07:58.500] That's a lot of scrambling. [07:58.760 --> 08:01.460] You can't link who sent what packet. [08:01.600 --> 08:02.600] That's really important. [08:02.720 --> 08:06.580] So you go to a first hop, which is a gateway, which you choose. [08:06.720 --> 08:09.820] And you're going somewhere, which is an exit gateway. [08:10.140 --> 08:11.340] Maybe it's the Internet. [08:11.560 --> 08:12.620] Maybe it's a service provider. [08:12.620 --> 08:18.860] And you're sending these packets, these kind of equal-sized packets, through this distributed network. [08:19.100 --> 08:23.960] And that's in contrast to... and that's what you call the mixnet mode. [08:24.080 --> 08:31.980] We also made a fast mode because the problem with mixnet mode is it's perfect for things like signal messages or telegram. [08:33.140 --> 08:35.480] It's not so great if you want to stream video. [08:35.600 --> 08:40.820] It's okay for like browsing Wikipedia, but maybe not browsing a site that has a lot of JavaScript. [08:40.820 --> 08:46.060] So we made a fast mode for people that want... that uses the same decentralized network. [08:46.060 --> 08:50.400] So those packets kind of... at least on running through the same routes as the mixnet. [08:50.580 --> 08:55.240] But it only goes through two hops, effectively using WireGuard, which I think there's been a workshop on. [08:55.360 --> 08:57.300] And it's a popular VPN protocol. [08:58.500 --> 09:03.680] And then I think this is much superior to centralized VPNs. [09:03.700 --> 09:05.540] How many people here have a VPN? [09:06.240 --> 09:07.620] So, okay, that's good. [09:09.100 --> 09:14.040] I mean, VPNs are much more problematic, though, than most people think. [09:14.180 --> 09:19.600] So if you're cool and you took the workshop with Michael Taggart yesterday, you've set your own WireGuard on your own server. [09:19.820 --> 09:34.020] Now, just be clear, even with Tor or your own WireGuard server, an adversary who's watching like your ISP connection, your router, and they're trying to figure out, oh, are you going to some dodgy website or communicating to someone else, they can still... [09:34.020 --> 09:45.840] even if the message is encrypted, because those packets are flowing and the timing and volume of those packets is revealed, they can still de-anonymize your packets. [09:46.060 --> 09:49.840] So they don't know, because of encryption, they don't know what you're saying, but they know who you're sending it to. [09:49.840 --> 10:05.760] And centralized VPNs of any sort, unless you run it yourself or you're using Tor, are incredibly dangerous, even if they're quote-unquote multi-hop, because they're all run by an entity, and that entity knows exactly what you're doing. [10:05.900 --> 10:12.840] So rather than like your ISP knowing what you're doing, you're trusting some often very shady VPN company with what you're doing. [10:13.020 --> 10:15.700] A lot of these VPN companies are actually honeypots. [10:15.800 --> 10:27.880] They collect your data, they can give it, they sell it to government sometimes, they sell it to other private actors, and they use your connection often as sort of botnet or for malware delivery. [10:28.140 --> 10:35.920] So VPNs in general, unless you're using maybe some of the nicer ones like Mulvat or Proton, are pretty dangerous. [10:36.760 --> 10:41.120] And even when they are good, you're still not anonymous. [10:41.280 --> 10:47.360] You may be slightly more secure, maybe anonymous against a very weak enemy, but definitely not something kind of NSA level. [10:47.360 --> 10:51.040] And what's NSA level is now, you know, it's not just NSA. [10:51.780 --> 10:52.820] It's Palantir. [10:55.140 --> 11:02.600] It's most governments, I think, particularly I would say China and Russia, probably have these kinds of mass surveillance capabilities. [11:02.980 --> 11:05.580] So we just sort of summarized where we're at. [11:05.800 --> 11:10.380] Again, we have an anonymous mode, which is really slow, right? [11:10.460 --> 11:11.820] So just to be a slower than Tor. [11:11.820 --> 11:14.260] But fine for things like Signal. [11:15.060 --> 11:19.120] And it uses encryption, but it also protects metadata. [11:19.540 --> 11:27.740] You can also use Tor, which I recommend I use Tor, or our fast mode, which is a little bit faster in Tor because it's pure UDP over WireGuard. [11:28.140 --> 11:31.380] And that's less private and secure, but much faster. [11:31.380 --> 11:38.900] And then the centralized VPNs, which obviously we're never going to be quite as fast as, but they're essentially dangerous to use. [11:38.980 --> 11:43.360] So I really would recommend you, particularly if you're doing anything important, do not use them. [11:43.360 --> 11:45.420] So we have built this. [11:45.820 --> 11:47.560] You know, five years ago, we presented the design. [11:47.760 --> 11:49.980] That was a much more in-depth take on the design. [11:50.100 --> 11:52.240] But I just wanted to tell everyone, I hope, we actually did build it. [11:52.360 --> 12:00.920] So it works on all the operating systems, including ones that's a little bit shakier on operating systems we don't like, like Microsoft, because we don't like coding for Windows. [12:01.180 --> 12:03.840] But, you know, if you're using iOS or Linux, it's pretty good. [12:04.840 --> 12:06.780] And you just install it. [12:06.860 --> 12:09.320] You click if you want to be anonymous or you want to be fast. [12:10.420 --> 12:14.440] And it's all open-source, free software, GPL. [12:14.640 --> 12:16.180] We security audit every year. [12:16.340 --> 12:17.100] We have a kill switch. [12:17.220 --> 12:18.480] Not perfect, but we're getting there. [12:18.860 --> 12:21.000] And it looks like a normal VPN. [12:21.960 --> 12:28.180] And most importantly, we're trying to make it available to people in repressed places, such as Russia. [12:28.180 --> 12:31.500] So we are enabling some censorship resistance. [12:32.380 --> 12:37.300] Importantly, the most dangerous thing with a VPN is that you're often talking to your credit card, which completely doxes you. [12:37.300 --> 12:39.900] I don't understand why people don't think that's really problematic. [12:40.580 --> 12:43.300] We do let you sign with a credit card, but we discourage it. [12:43.780 --> 12:47.100] And we do not require any personal data to sign up, any email. [12:47.360 --> 12:48.380] You just sign up. [12:48.680 --> 12:51.560] You can pay in Monero, Shielded Zcash. [12:51.560 --> 12:54.980] You can ship us cash in an envelope if you're really crazy. [12:55.300 --> 12:55.760] Whatever. [12:56.020 --> 12:56.680] We don't care. [12:57.120 --> 12:59.420] And we just give you, essentially, a private key. [12:59.520 --> 13:00.980] And that's all we have. [13:01.060 --> 13:01.980] And that's your connection. [13:01.980 --> 13:10.380] And then we delink even your payment information, because we don't want you to have any identifier which you reveal to any server in our network. [13:10.640 --> 13:23.580] So going back to the beginning of the talk, we give you a Chamian anonymous credential, decentralized one, which we call ZKNIM, as a sort of proof of payment, so that when you pay, we kind of... [13:23.580 --> 13:25.260] You pay some money. [13:25.260 --> 13:31.220] It goes into, like, a smart contract, or, you know, a BTC pay server, depending on how you pay. [13:31.500 --> 13:33.280] And then back, you get, like, a little receipt. [13:33.540 --> 13:42.240] And the nice thing is that receipt is anonymous, because, again, that receipt is a digital signature, which you can just take to another exponent, and then it's scrambled, but still verifies. [13:42.340 --> 13:43.540] That's the general concept. [13:44.500 --> 13:49.180] And what happens to all the money we get in, this is a decentralized network, has to go pay the nodes. [13:49.520 --> 13:52.140] Now, we're not a volunteer network, so I love altruism. [13:52.280 --> 13:53.020] I'm an anarchist. [13:53.500 --> 13:54.700] Power to altruist. [13:54.700 --> 14:00.100] I do think altruism is very important, but we also don't want to compete with, like, the same altruists who are running Tor nodes. [14:00.300 --> 14:06.980] So we actually pay for people to run these nodes using cryptocurrency, which I understand is probably pretty controversial here. [14:07.140 --> 14:09.780] But nonetheless, it does help us get a lot of nodes. [14:09.980 --> 14:14.600] So we have 500 people or so, 500 different servers, 700 maybe, running nodes. [14:15.360 --> 14:23.740] And they're, hopefully, financially sustainable, and we don't even have any idea who these people are, because they just kind of register through a smart contract. [14:23.740 --> 14:33.400] So we understand blockchain technology is mostly used for, as I said yesterday, transparently bribing our president, but there are other use cases which we hope are fine. [14:33.500 --> 14:38.980] And that's a very complex diagram, which I'm not going to go into, because Lee's here, about how all the payment and everything works. [14:38.980 --> 14:43.500] But very briefly, when you want to access the Internet, you're over here. [14:44.120 --> 14:46.580] The Internet is that weird globe-looking thing. [14:46.840 --> 14:53.320] You basically talk to, you start the VPN on your laptop, or your phone, or whatever. [14:53.320 --> 14:55.340] You get a little anomalous credential back. [14:55.640 --> 14:57.420] That anomalous credential is like your proof of payment. [14:57.420 --> 14:59.240] You show that to the first gateway. [14:59.500 --> 15:00.640] That's the country you selected. [15:00.820 --> 15:02.100] That gateway said, hey, yeah, you paid. [15:02.300 --> 15:05.880] And then it lets you through the mixnet, this noise-generating mixnet. [15:05.880 --> 15:17.780] You exit to the Internet, and then at the end of every day or so, the people that you showed those kind of proof of payments to, they collect them, they hand them to us, and then the smart contract pays them. [15:18.100 --> 15:19.200] We are trying... [15:19.200 --> 15:24.060] It is not a particularly great VPN to use in China right now, but we are working on that very hard. [15:24.340 --> 15:25.780] And we are also currently... [15:25.780 --> 15:27.500] And hopefully, we get a presentation on this next year. [15:27.800 --> 15:38.420] We are currently working really hard to upgrade to post-quantum cryptography using MacEllis, Classic MacEllis, and MLChem, following the vice of DJB and other cryptographers that we are working with. [15:39.420 --> 15:44.600] And you are like, well, that is terrible, a cool system, but why are you forcing me to pay for it, motherfucker? [15:44.880 --> 15:46.440] And I agree, that is a terrible thing. [15:46.760 --> 15:53.400] That being said, again, we want to be financially independent from non-profit grants because I detest the non-profit industrial complex. [15:53.580 --> 15:54.280] I worked at BC. [15:54.500 --> 15:55.560] I am very familiar with it. [15:55.880 --> 16:00.460] We want to be independent, particularly as all the governments are moving towards various forms of fascism. [16:00.460 --> 16:06.040] So if people are going to pay for VPNs that are total scams, they should at least pay us, get real privacy. [16:06.380 --> 16:06.980] That's cool. [16:07.120 --> 16:11.520] But that being said, the thing which is interesting probably for everyone here is the MixNet, because that's what makes you really anonymous. [16:11.920 --> 16:16.520] And while you have to pay for the VPN, which is the fast mode, MixNet's free. [16:16.520 --> 16:26.760] You guys can set up your own fast thing with the WireGuard server, but the MixNet is free to use and access via our APIs and SDKs, which are built on Rust, JavaScript, and we have bindings for C and Go. [16:26.960 --> 16:29.280] Just go there, and we hope people... [16:29.280 --> 16:37.120] We've been kind of hoping more people would build cool anonymous apps, like anonymous chat apps, or anonymous, or at least privacy-preserving social networks. [16:37.340 --> 16:38.260] So that's me. [16:38.440 --> 16:40.820] If you have any questions, just pop me an email. [16:41.860 --> 16:45.820] I think I disabled my X account, but maybe one day I'll re-enable it. [16:45.820 --> 16:49.620] But I'm definitely able to email and give us bug reports. [16:49.800 --> 16:52.580] It's still a pretty buggy piece of software, but we're proud of it. [16:52.740 --> 16:55.340] And we think that it is one of our best... [16:55.340 --> 17:04.780] Right now, again, I'm trying to build defensive software to prevent the rising tide of fascism from throwing everyone in jail or killing people. [17:05.020 --> 17:07.320] So, however, that's not very uplifting. [17:07.620 --> 17:10.440] So I want to end on a more uplifting note. [17:10.600 --> 17:12.640] So I'm going to hand the mic to Lee. [17:13.100 --> 17:14.280] Maybe you want to come up here, Lee. [17:14.280 --> 17:15.660] We'll plug your laptop in. [17:15.660 --> 17:19.680] We'll get a nice, I think, history, which I think contextualizes that we don't need... [17:19.680 --> 17:39.040] We need not just to build technologies for defense, although I personally like building those technologies, but technologies for offense and for communication and social media to not only defend our existing social lives, build the kind of society that we want. [17:39.040 --> 17:39.600] That's because we need to get into our life. [17:39.600 --> 17:39.720] Thank you very much. [17:39.720 --> 17:39.780] Thank you very much. [17:39.780 --> 17:40.020] Thank you very much.