[00:01.500 --> 00:07.780] My talk is slightly short, so I'm going to waste a couple of minutes of your time with just a trivia I made up. [00:08.580 --> 00:11.800] Anybody recognizes this test signal? [00:12.680 --> 00:13.220] Yeah. [00:13.560 --> 00:14.180] All right. [00:15.000 --> 00:15.100] Huh? [00:15.900 --> 00:16.440] Yeah. [00:17.160 --> 00:22.020] So this was a test signal for TVs back when they were black and white. [00:22.120 --> 00:23.500] It was used for 20 years. [00:24.220 --> 00:28.200] But I put it here because I took it from a movie that I love. [00:28.580 --> 00:29.020] Anybody? [00:29.020 --> 00:30.660] You all know this movie. [00:31.560 --> 00:33.580] It appears briefly in Hackers. [00:33.960 --> 00:39.440] It's in the opening when he basically takes over the TV station and puts on The Outer Limits. [00:39.680 --> 00:41.620] This is the opening for The Outer Limits. [00:44.740 --> 00:45.440] All right. [00:45.720 --> 00:47.900] I'm going to get on with my business here. [00:48.920 --> 00:49.980] My name is Marco. [00:50.220 --> 00:51.220] I go by M-Prime. [00:51.540 --> 00:52.800] I'm very excited to be here. [00:52.920 --> 00:54.740] This is my first HOPE in person. [00:55.140 --> 00:58.320] I've been watching from home for a few years. [00:58.780 --> 01:00.480] I'm super honored to be here. [01:00.480 --> 01:01.900] I'm here, of course, presenting. [01:03.560 --> 01:06.700] And today I'm going to talk about Portable Secret. [01:07.240 --> 01:08.520] It's not a product. [01:08.980 --> 01:10.360] It's barely a project. [01:10.680 --> 01:12.740] And it's basically a simple hack. [01:13.180 --> 01:20.900] And something that I hope you will walk out of here having added it to your tool belt for privacy. [01:20.900 --> 01:23.220] And maybe share it with some loved ones. [01:24.120 --> 01:26.900] It's a very simple thing that you can make your own. [01:27.820 --> 01:29.520] You don't need to use my implementation. [01:30.340 --> 01:35.140] It's so simple that you can reproduce it with just a few lines of code. [01:35.420 --> 01:39.720] And it can basically help you and your loved one stay a bit more private online. [01:41.760 --> 01:44.420] The key here is that it's portable. [01:44.420 --> 01:46.920] So it doesn't require any special software. [01:46.980 --> 01:49.820] So you can talk privately with pretty much anybody. [01:49.820 --> 01:52.080] They don't need to have GPG or anything else. [01:59.080 --> 02:03.580] So in day-to-day life, we have all sorts of kind of mundane secrets. [02:03.920 --> 02:09.220] So maybe you want to tell your friend where your spare key is so they can go and feed your cat. [02:09.660 --> 02:17.000] Or you want to share a picture that you don't necessarily want to share with Apple or Google or Facebook or whoever is transporting your data. [02:17.620 --> 02:22.880] Maybe you want to carry around a copy of your passport just in case you lose the original. [02:23.860 --> 02:28.400] And the problem with this kind of thing is that sometimes the receiver does not know how to GPG. [02:28.540 --> 02:32.860] In fact, most people don't know how to use a decryption thingy. [02:32.980 --> 02:35.300] They don't know what a private key is and so on. [02:35.980 --> 02:41.280] In the case of carrying your passport, maybe you don't just want to carry around the JPEG because you're paranoid. [02:43.440 --> 02:55.200] And so in these cases, I felt that there was a need for something that you can carry with yourself everywhere and doesn't need any kind of special software. [02:55.480 --> 03:03.780] In fact, if I send you a portable cigarette right now via email, via text, I guarantee that you could open it on your computer or on your phone. [03:06.260 --> 03:12.720] So briefly, I'm going to go through why I came up with this, what a portable cigarette actually is. [03:13.000 --> 03:15.260] We're going to review the crypto behind it. [03:15.500 --> 03:18.140] We're going to talk a little bit about thread models. [03:18.980 --> 03:21.840] And finally, my favorite section is use cases. [03:22.740 --> 03:26.540] And if you don't have questions for me at the end, I have questions for you. [03:30.240 --> 03:32.440] So why this thing exists? [03:32.440 --> 03:38.240] The answer is simple because my mom cannot be bothered to learn how to use GPG. [03:38.440 --> 03:44.380] So I simply cannot expect her to learn how to use GPG and the terminal or anything else. [03:45.060 --> 03:51.480] So if I'm communicating with probably people in this room or other tech savvy people, there's plenty of options. [03:51.760 --> 03:53.220] I don't need to come up with another one. [03:53.580 --> 03:55.920] I consider these are kind of a solved problem. [03:56.160 --> 03:57.700] There's plenty of good options. [03:57.700 --> 04:02.340] But everybody else, the less tech savvy, are kind of left out in the cold. [04:02.780 --> 04:05.800] And so can we do something about this? [04:06.020 --> 04:16.640] And what really pushed me to do this is my mom sending me these kind of exact messages or emails saying, Hey, I changed the alarm for the house and the new code is X, Y, Z. [04:17.240 --> 04:20.880] Or here's a letter from the bank with your new credential or something. [04:21.140 --> 04:24.780] And just send it over text or over Facebook or stuff like that. [04:25.380 --> 04:30.060] And just, I couldn't take it anymore at some point and decided to do something about it. [04:30.740 --> 04:35.320] What bothers me about this is, well, Facebook can read it, sure. [04:35.600 --> 04:38.200] But probably they are not going to come and break into my house. [04:38.400 --> 04:40.800] But at the same time, my mom lives far away. [04:41.260 --> 04:49.740] And she often goes to the tech repair shop near her because her phone doesn't work or her email doesn't work. [04:49.980 --> 04:55.660] And so anybody that has access to her phone for just a few minutes can go and read these kind of messages. [04:55.660 --> 04:58.060] And that doesn't really sit well with me. [05:00.300 --> 05:02.220] So, there are some alternatives. [05:02.700 --> 05:06.740] Of course, Signal keeps millions of people safe. [05:07.520 --> 05:10.700] And it's as easy to use as any other messenger. [05:11.320 --> 05:13.300] And so, of course, Signal is great. [05:15.920 --> 05:18.940] I want to do something that I have full control over. [05:19.300 --> 05:22.100] The thing that I like about Signal is their cryptography. [05:22.240 --> 05:23.020] The people are great. [05:23.480 --> 05:25.800] The organization I have a lot of respect for. [05:25.800 --> 05:30.080] But at the same time, what I'm downloading from the App Store, I have no idea. [05:30.520 --> 05:33.520] And what it's running on their servers, I also have no idea. [05:35.220 --> 05:40.500] So, specifically for the case of my mom, I started by developing a very simple web app. [05:40.620 --> 05:42.580] I'm not a web developer at all. [05:42.860 --> 05:44.480] So, this took way too long. [05:44.480 --> 05:51.500] But as a fun project, basically single page website, text box, and a send button. [05:51.700 --> 05:55.700] And she can just type in, hit send, and I will receive it encrypted. [05:56.020 --> 05:57.260] I can decrypt it. [05:57.320 --> 05:58.580] And so, everybody's happy. [06:00.120 --> 06:03.180] This is good because I have full control over the stack. [06:03.180 --> 06:04.620] I know exactly what's going on. [06:05.300 --> 06:07.480] The bad thing is that it only works one way. [06:07.660 --> 06:09.600] I know how to decrypt messages. [06:10.120 --> 06:16.300] She will not learn how to use the terminal and learn what a private key or whatever. [06:17.940 --> 06:25.530] But there was something interesting that I learned in this project, which is that any modern browser can do cryptography natively. [06:26.080 --> 06:34.980] So, there's browser API that can do most of the currently recommended crypto algorithm, the very basic primitives. [06:35.240 --> 06:36.820] You can run them right in your browser. [06:37.020 --> 06:37.600] They're right there. [06:40.860 --> 06:43.720] So, this is how I came up with this portable secret. [06:43.720 --> 06:50.200] And the easiest way to think about it is like a password-protected PDF, except it's actually secure. [06:51.020 --> 06:52.940] Password-protected PDF are a joke. [06:53.200 --> 06:59.920] And so, what a portable secret is, it's simply an HTML file. [07:00.080 --> 07:02.040] It contains an encrypted payload. [07:02.600 --> 07:08.020] Very, very little JavaScript, because I'm delegating all of the difficult stuff to the browser itself. [07:08.920 --> 07:12.680] And if you receive it, you can decrypt it in any browser. [07:12.680 --> 07:15.240] So, if I send it to you, you can open it on your phone. [07:15.240 --> 07:16.700] You can open it on your laptop. [07:16.980 --> 07:17.800] It will work. [07:18.440 --> 07:20.860] And it also works without an Internet connection. [07:21.040 --> 07:21.740] So, you need a browser. [07:21.900 --> 07:22.680] You don't need the Internet. [07:23.040 --> 07:25.000] Don't be like my mom, who doesn't know the difference. [07:28.920 --> 07:29.720] There's also... [07:30.840 --> 07:35.180] The browser sandbox is also good, because in theory, you receive a secret. [07:35.200 --> 07:35.920] You open it. [07:36.120 --> 07:37.380] It's an HTML file. [07:37.580 --> 07:40.100] You decrypt it right there in the browser, inside the sandbox. [07:40.100 --> 07:43.640] The moment that you close the tab, there should be no trace left. [07:44.160 --> 07:47.280] And there's also a reasonable protection both ways. [07:47.500 --> 07:53.700] Like, what's inside the tab does not touch the rest of your system, and vice versa. [07:55.800 --> 07:57.380] So, let me show you. [08:03.360 --> 08:04.880] Here's an example message. [08:04.880 --> 08:06.740] And you can see I am... [08:06.740 --> 08:09.240] This is actually a file on my computer. [08:10.540 --> 08:13.220] But it could as well be a static page somewhere. [08:13.900 --> 08:15.680] It says, create a portable secret. [08:16.000 --> 08:18.480] This can be created without an Internet connection. [08:18.820 --> 08:21.560] This file, the HTML file, has no dependencies. [08:22.260 --> 08:23.860] No data leaves the browser window. [08:23.860 --> 08:27.820] So, in this case, I chose to put in a password. [08:28.040 --> 08:28.580] A hint. [08:28.740 --> 08:29.900] So, I remembered the password. [08:31.500 --> 08:32.740] Yellow elongated fruit. [08:33.100 --> 08:34.240] So, I put in banana. [08:35.440 --> 08:37.040] And actually, before I decrypt... [08:37.040 --> 08:37.360] Whoops. [08:37.720 --> 08:37.820] Sorry. [08:41.720 --> 08:43.300] Let me show you the code. [08:43.300 --> 08:48.680] So, here's a pathetic attempt at CSS. [08:49.640 --> 08:51.600] Let me actually scroll to the end. [08:51.780 --> 08:53.460] This is the important part. [08:53.760 --> 08:55.180] You see a bunch of variables. [08:55.640 --> 08:57.020] Is the text readable? [08:57.480 --> 08:57.720] Too small? [09:03.130 --> 09:08.030] So, there's some encryption parameters, like a salt and an ID. [09:08.410 --> 09:10.410] We'll get back to those later. [09:10.690 --> 09:11.450] Number of iteration. [09:12.130 --> 09:14.450] And, of course, you have some ciphertext. [09:17.890 --> 09:26.270] So, below my terrible CSS, there's an init function, which basically loads those variables from the script block into the page. [09:26.630 --> 09:28.730] So, I can see them right here. [09:32.220 --> 09:33.920] And, that's pretty much it. [09:34.040 --> 09:41.960] If I hit the decrypt button, it's gonna basically do a sequence of steps, but everything important. [09:41.980 --> 09:45.480] So, it's translating text to byte, text to string, whatever. [09:45.480 --> 09:50.820] The important bits are the crypto, which are actually delegated to the browser itself. [09:51.020 --> 09:53.680] So, here I'm calling into window, crypto, saddle. [09:54.140 --> 09:55.640] This is the saddle API. [09:56.160 --> 09:59.120] Meaning, you need to know what you're doing to use these. [10:01.060 --> 10:04.040] And so, these functions are implemented in the browser. [10:04.040 --> 10:08.060] I just do a password-based key derivation function. [10:08.900 --> 10:12.440] And then, I do AS in Galois counter mode. [10:14.100 --> 10:17.120] And then, at the end, I get back my decrypted. [10:17.400 --> 10:18.340] I remove the padding. [10:18.620 --> 10:21.920] And then, I do something just to display it on the page, depending on the type. [10:21.920 --> 10:24.300] If it's just text, or an image, or a file. [10:26.580 --> 10:34.100] So, if I go back here, and I hit decrypt, this is my encrypted secret. [10:42.000 --> 10:47.260] So, the cool thing about this is that these files are completely self-contained. [10:48.320 --> 10:54.280] The World Wide Web Consortium, a few years ago, decided to push for having cryptography in the browser. [10:54.760 --> 10:56.420] We have them to thank for this. [10:56.940 --> 11:02.920] And so, for a few years now, basically, every browser supports all of these primitives. [11:03.260 --> 11:09.880] You can go, if you're curious, on a website, like the Mozilla Developer website, and check exactly what is supported where. [11:10.140 --> 11:13.700] But all of the basic stuff is supported by all of the browsers. [11:16.440 --> 11:22.400] So, let's look at the crypto, because you might be wondering if this thing is actually secure or not. [11:23.120 --> 11:24.760] So, two main pieces. [11:25.180 --> 11:28.700] There is BlockCypher encryption, and it's ASGCM. [11:29.720 --> 11:32.740] This is a National Institute of Standards recommendation. [11:33.220 --> 11:35.780] So, this is basically textbook cryptography. [11:36.540 --> 11:42.660] If you go on textbooks for cryptography and look how to do BlockCypher encryption, you find this. [11:42.660 --> 11:44.260] So, I didn't invent anything. [11:44.460 --> 11:46.080] This is no hand-rolled cryptography. [11:46.400 --> 11:53.320] This is really, really simple and follows the recommendation of government and various institutions. [11:55.280 --> 11:59.340] I picked ASGCM because it's symmetric-authenticated. [11:59.760 --> 12:06.220] Meaning that symmetric because you need to put in the same password to encrypt and to decrypt. [12:06.220 --> 12:07.260] That makes it symmetric. [12:08.260 --> 12:16.260] Authenticated because if somebody touches the ciphertext, you will actually know. [12:16.420 --> 12:19.140] It will tell you that the decryption basically fails. [12:19.320 --> 12:22.420] So, you know that there is some degree of integrity of your message. [12:23.220 --> 12:27.600] And encryption, of course, confidentiality, meaning nobody without the password should be able to look at it. [12:30.300 --> 12:32.320] And so, here we have plain text. [12:32.560 --> 12:35.580] We add padding because it needs to be a multiple of the block size. [12:35.720 --> 12:37.240] And that feeds into AES. [12:37.780 --> 12:41.880] We use a random number generator to generate an initialization vector. [12:42.160 --> 12:43.320] This is not a secret. [12:43.500 --> 12:44.900] You saw it earlier on the page. [12:45.020 --> 12:46.760] It's safe to transmit this in the clear. [12:47.560 --> 12:49.360] And so, these are two of the inputs. [12:49.360 --> 12:51.620] The third input is, of course, a key. [12:52.700 --> 12:58.580] And the key goes through this extra circuit, which is a password-based key derivation function. [12:59.660 --> 13:04.940] And this is here to basically slow down brute force attacks or dictionary attacks. [13:05.280 --> 13:15.120] If we were just sending the password, say, with a simple hash straight into AES, it would be super, super fast and cheap to try a gazillion attempts per second. [13:15.640 --> 13:20.540] Instead, we send it through a function like this that basically just munches on it. [13:20.820 --> 13:22.960] In my case, it's doing a million iterations. [13:23.600 --> 13:26.300] And so, you generate an iteration with a salt. [13:26.680 --> 13:29.240] And after a million iteration, you get back a key. [13:30.440 --> 13:35.260] So, before, somebody was able to do a million attempts per second with a dictionary. [13:35.600 --> 13:38.580] And this block now takes a tenth of a second. [13:38.840 --> 13:41.660] Now they are limited to, say, 10 attempts per second. [13:41.980 --> 13:45.100] And, of course, you can say they can parallelize and all of that. [13:45.100 --> 13:53.400] But the important part is that this is a sliding scale that allows you to slow down the key generation step. [13:55.460 --> 13:57.060] And on the other side, it's pretty simple. [13:57.260 --> 13:59.680] So, we have these three things which can be transmitted in clear. [14:00.120 --> 14:02.220] On the other side, we do the exact same thing. [14:02.440 --> 14:04.880] Same salt, same password, same function. [14:05.240 --> 14:07.020] We end up, hopefully, with the same key. [14:07.020 --> 14:11.220] We feed it into the inverted AS. [14:11.560 --> 14:13.220] We get that padded plain text. [14:13.360 --> 14:14.160] We remove the padding. [14:14.360 --> 14:16.040] We have the original plain text. [14:18.680 --> 14:20.460] So, a few... [14:23.020 --> 14:28.700] Because if I am recommending this to you now, to my mom, to my friends, I... [14:28.700 --> 14:33.400] You better believe I spent some time thinking about, is this actually something good? [14:34.120 --> 14:37.560] So, I have four initial assumptions which are... [14:38.680 --> 14:40.240] Which are the base for the rest. [14:40.500 --> 14:45.820] So, my first assumption is that the browser web cryptography API implementation are actually sound. [14:46.400 --> 14:51.440] And this is an easy one because most of these cryptography functions are very simple. [14:51.580 --> 14:52.240] Well, simple. [14:52.620 --> 14:53.780] Simple input output. [14:54.020 --> 14:55.020] They are deterministic. [14:55.180 --> 14:56.640] And so, they are very well tested. [14:56.640 --> 15:05.700] If you do AS with the same key in a browser or in Go or in a different language or with a different library, you should expect the same output. [15:06.140 --> 15:07.400] So, these are easy to test. [15:07.800 --> 15:11.460] It's easy to check that all of these should be sound. [15:12.960 --> 15:17.880] Second assumption is that the National Institute of Standard recommendations are sound. [15:18.340 --> 15:30.820] This is where I shut down the little voices in my head that say that, I don't know, the Feds created Bitcoin to crack AS or, you know, that kind of story. [15:31.160 --> 15:39.640] So, I actually believe them that this is the best recommendation that they have for us to, and for the rest of the world, to communicate securely. [15:41.480 --> 15:44.000] Third one, and it's probably the most important one. [15:44.580 --> 15:52.140] In using this system, I expect the value of my secret to be much less than the budget of the adversary. [15:52.140 --> 15:54.380] Anything can be cracked given enough time. [15:54.620 --> 16:05.800] But if I'm sending you the door code to my friends so that they can feed my cat, probably I'm not dealing with some foreign superpower trying to crack my secret. [16:06.020 --> 16:07.980] So, I'm probably easy. [16:10.300 --> 16:12.200] Next one, side channels are not compromised. [16:12.380 --> 16:24.000] What I mean by this is that often if I send one of these files to my mom, then I call her and I say, yes, the file is for me, it's from me, you can open it, and the password is blah, blah, blah. [16:24.360 --> 16:29.700] And so, again, here I assume that the NSA is not listening on my phone calls with my mom. [16:29.840 --> 16:31.340] I hope they have better things to do. [16:33.540 --> 16:35.860] Of course, this scheme is not perfect. [16:36.020 --> 16:36.660] There's weaknesses. [16:37.100 --> 16:40.400] And the number one weakness is, of course, bad passwords. [16:40.400 --> 16:44.560] You can definitely choose terrible passwords that are extremely easy to guess. [16:45.120 --> 16:47.480] And so, not much to do about this. [16:49.280 --> 16:57.600] But in the specific case of my tool, two revealing passwords can also be a problem. [16:57.600 --> 17:05.360] Because if you say the password is your birth date, then anybody can figure it out. [17:06.660 --> 17:10.380] And, of course, even infinite time to crack, anything can be cracked. [17:10.760 --> 17:12.800] So, ultimately, this is not perfect. [17:14.320 --> 17:19.700] So, speaking of password, I have to show you this obligatory XKCD. [17:20.360 --> 17:29.260] The tagline is, Through 20 years of effort, we successfully trained everyone to use passwords that are hard for human to remember, but easy for computers to guess. [17:29.740 --> 17:38.900] So, in this case, this terrible password, really hard to remember, it's actually guessable in three days or crackable in three days at this speed. [17:39.600 --> 17:42.000] Versus this one is a lot more memorable. [17:42.500 --> 17:44.820] It's easier to type and compare. [17:45.340 --> 17:46.900] This one takes three days to crack. [17:47.020 --> 17:48.860] This one takes 550 years. [17:51.180 --> 17:53.100] So, a word about passwords here. [17:54.240 --> 17:56.640] You probably know this better than me. [17:57.280 --> 17:58.620] Again, you're the tech savvy. [17:58.840 --> 18:03.600] But if you're sharing this with somebody, it's a good reminder to remind them. [18:04.580 --> 18:06.010] Maybe show them this comic. [18:06.780 --> 18:10.260] I think it's very little effort. [18:10.440 --> 18:11.680] It takes ten seconds to read it. [18:11.780 --> 18:12.420] They have a laugh. [18:12.660 --> 18:14.260] But it also teaches them something. [18:14.900 --> 18:22.580] And a good thing that I've had to tell my friends are, if you're creating a... [18:23.260 --> 18:30.760] you're putting in the password something that is private just for you, or something that it's a private secret of yours, be careful. [18:30.940 --> 18:32.840] Not every secret of yours is good. [18:33.000 --> 18:37.720] So, for example, if you put, what is my favorite ice cream flavor? [18:37.720 --> 18:42.180] Maybe you're very, very careful not to tell that to anybody in the world. [18:42.480 --> 18:52.520] But at the same time, somebody that sees that password hint can create easily a dictionary of ice cream flavors and guess your password in a second. [18:53.680 --> 18:56.240] So, on the other side, the same hint is good. [18:56.240 --> 18:58.320] What is my favorite ice cream flavor? [18:58.880 --> 19:02.160] If you know that the answer is something that nobody would ever guess. [19:02.340 --> 19:12.280] So, if your favorite ice cream flavor is unicorn tears, because it's some sort of joke that you have with yourself, then that becomes a really good password. [19:13.080 --> 19:15.480] Same thing when you're talking to other... [19:15.480 --> 19:17.420] or when you're creating a secret for someone else. [19:17.420 --> 19:27.440] So, if I create a secret for my wife, and I say the place where we met, there's dozens to hundreds of people that know the answer to that. [19:27.760 --> 19:43.600] At the same time, if I didn't really mean it literally, and we have some sort of inside joke about where we met, and it's something like the bottom of the Mariana Trench, which is not literally true, then it's very unlikely that somebody would be able to guess it. [19:43.860 --> 19:49.160] Again, you probably know these kind of things, but it's a good reminder to tell others. [19:51.780 --> 19:53.760] Last one on thread model. [19:54.100 --> 19:57.380] Well, you might say, what if there's key loggers or screen recorders? [19:57.540 --> 19:58.960] Well, you're toast. [19:59.220 --> 20:00.300] There's nothing that can do. [20:01.920 --> 20:02.920] Not this tool. [20:03.080 --> 20:08.140] Nothing else will protect you if when you're typing the secret on screen, somebody's recording your screen. [20:10.140 --> 20:12.680] The interesting one is the malicious payload. [20:12.880 --> 20:17.840] So, you might ask yourself and me, is it safe to open this kind of files? [20:18.820 --> 20:20.140] And so, this one... [20:20.140 --> 20:26.840] I'm not an expert in web development or web security, and so I've had to do some research. [20:27.840 --> 20:37.800] And what I came up with, basically what you saw earlier, when you're decrypting, it's rendering the content on the page, but it's not activating anything. [20:37.800 --> 20:44.400] So, if somebody sends you an encrypted, say, JavaScript, when you decrypt it, it should not execute it. [20:44.880 --> 20:48.840] And, of course, you may be able to check that for yourself. [20:48.840 --> 20:50.980] It's a little bit harder for your friends. [20:52.080 --> 20:58.820] So, I think a good measure there, it's always say, open this when I call you and tell you to open it. [20:58.820 --> 21:05.080] Always tell your friends not to click on random attachment to emails. [21:07.360 --> 21:14.540] The other thing about this is that you might say, is it safe to just run a program in an HTML file? [21:14.820 --> 21:16.080] Isn't that kind of sketchy? [21:16.660 --> 21:18.000] And here's the thing. [21:18.140 --> 21:20.020] That's what your browser does all day. [21:20.020 --> 21:27.940] As you're browsing online, you're downloading megabytes of programs, and your browser is executing them, and it's fine. [21:28.720 --> 21:34.100] Browser exploit were a problem much more some years ago. [21:34.380 --> 21:36.320] Browsers got a lot more safer. [21:36.600 --> 21:39.900] I haven't heard of one, a really bad one, in a long time. [21:40.120 --> 21:44.640] Might also be because they got so bloated and so complex that it's impossible to find. [21:47.060 --> 21:50.280] On the other side, do you trust the browser itself? [21:50.540 --> 21:53.320] So, some browsers are more trustworthy than others. [21:53.720 --> 21:57.960] Some browsers send way too much information back to the mothership. [21:58.400 --> 22:00.620] And so, that's something to consider. [22:01.340 --> 22:05.000] And even more so for extensions. [22:05.460 --> 22:08.440] So, your extensions have access to your sandbox. [22:09.000 --> 22:12.580] They could be grabbing whatever is in there and sharing it. [22:13.260 --> 22:16.060] And same thing for your operating system. [22:16.300 --> 22:18.560] How much do you actually trust your operating system? [22:18.920 --> 22:32.320] So, you probably heard about this Microsoft new feature in the last couple of months that was basically recording your screen, recording every keystroke, just storing everything in order to train some model later, probably. [22:33.760 --> 22:35.300] Just something to keep in mind. [22:45.580 --> 22:51.340] I'm gonna give a quick demo of the creator tool, which is... [22:51.900 --> 22:54.140] So, all of this is on GitHub. [22:55.800 --> 23:01.780] And if you remember the message from before, it's basically... [23:01.780 --> 23:05.080] The first part is the same for each one of these files. [23:05.960 --> 23:10.420] The HTML, the JavaScript, the CSS, it's all the same. [23:10.420 --> 23:12.780] The only thing that changes really is this part. [23:12.980 --> 23:22.900] So, if you want to create a portable secret, all you need to do is take the first part, append, encrypt your payload, append the second part, and that's it. [23:23.040 --> 23:24.120] Save it as HTML. [23:25.380 --> 23:28.000] So, this is what this tool does. [23:29.180 --> 23:34.220] So, again, pre-populated with a password and a hint. [23:34.220 --> 23:36.760] I can either write a message here. [23:36.760 --> 23:40.940] I can also use it to encrypt an image or a file. [23:46.690 --> 23:47.630] Just for rendering. [23:47.970 --> 23:50.250] So, if it's an image, I render it in an image tag. [23:50.470 --> 23:53.090] If it's a file, it becomes a URL encoded. [23:55.950 --> 23:56.430] So... [24:01.450 --> 24:03.530] Here, so I generate a secret. [24:04.510 --> 24:06.230] And now I just save it. [24:06.290 --> 24:07.390] And it's a simple HTML. [24:09.810 --> 24:11.430] And here it is. [24:11.730 --> 24:13.510] So, I'm going to open it with Firefox. [24:14.670 --> 24:15.190] Change. [24:19.190 --> 24:23.670] And right there, you have your original encrypted secret. [24:26.870 --> 24:29.310] So, this is a project from a couple of years ago. [24:29.430 --> 24:36.730] And I really wanted to share it on a place like Hacker News to get some feedback because, yeah, why not? [24:37.910 --> 24:39.590] I love Hacker News. [24:39.770 --> 24:40.950] I kind of read it every day. [24:41.610 --> 24:46.430] I have a love-hate relationship in the sense that one in a hundred articles is amazing. [24:46.630 --> 24:48.870] One in a thousand comments is amazing. [24:49.650 --> 24:51.250] But the rest is garbage. [24:52.130 --> 24:59.950] So, I expected basically to get swamped by comments such as this one. [25:00.130 --> 25:01.510] Like, bro, this doesn't work. [25:01.770 --> 25:03.150] Not even why or how. [25:03.350 --> 25:04.530] Just, this doesn't work. [25:04.810 --> 25:07.230] Because that's the kind of comments that you get a lot. [25:07.230 --> 25:14.550] So, I was like, alright, let's make this more interesting to people that might come up with that. [25:14.750 --> 25:18.630] And if you think this is weak, well, take my money. [25:18.950 --> 25:21.210] So, basically, I created a Bitcoin wallet. [25:21.370 --> 25:25.850] And I created a portable secret that contains the password to that wallet. [25:26.590 --> 25:27.710] And I put it online. [25:30.560 --> 25:31.940] So, here it is. [25:32.680 --> 25:34.140] This is online. [25:34.400 --> 25:36.280] That QR code takes you here. [25:36.760 --> 25:38.960] I think this is a good example of passwords. [25:39.280 --> 25:41.420] Only I should be able to decrypt this. [25:43.580 --> 25:47.840] And, actually, let me show you the money still there. [25:48.300 --> 25:49.200] It is. [25:49.420 --> 25:50.760] It went up quite a bit. [25:56.240 --> 26:00.780] So, I left myself instruction so that I can always open these anytime. [26:01.660 --> 26:06.140] And these are four hints that, to me, are deeply private. [26:06.400 --> 26:07.680] They are seared into my memory. [26:07.980 --> 26:10.060] Like, I know exactly what this is. [26:10.260 --> 26:11.820] But, in theory, nobody else in the world... [26:11.820 --> 26:12.340] Not in theory. [26:12.480 --> 26:14.200] Nobody else in the world knows this. [26:14.380 --> 26:15.800] Not even my closest family. [26:17.880 --> 26:20.540] And so, so far, so good. [26:20.760 --> 26:23.800] Nobody has taken my money. [26:24.120 --> 26:27.340] And, actually, the story went really well on Acid News. [26:27.360 --> 26:29.220] And I got a bunch of really nice comments. [26:30.500 --> 26:35.580] And I was talking about the bounty just because it's a lead to the next topic. [26:35.680 --> 26:37.800] Which is AI, of course. [26:38.120 --> 26:39.220] I know what you're thinking. [26:39.220 --> 26:41.580] I've been talking for 30 minutes. [26:41.580 --> 26:43.280] I haven't said anything about AI. [26:43.280 --> 26:44.340] You want your money back. [26:45.960 --> 26:47.380] So, here goes. [26:48.060 --> 26:52.780] These are the hints that I just showed you for the bounty. [26:53.260 --> 26:58.700] And, basically, a few days after I put this online, I started receiving some strange emails. [27:00.800 --> 27:02.280] This one says... [27:02.820 --> 27:03.500] Hello, Marco. [27:06.420 --> 27:08.980] I was wondering if you can help me with a few questions. [27:09.840 --> 27:12.360] These might seem like strange, weird questions. [27:13.280 --> 27:15.460] But, I would like to know about the swimming pool accident. [27:15.680 --> 27:17.480] I've been interested in learning about it. [27:18.080 --> 27:18.180] Alright. [27:19.500 --> 27:22.520] Second, I would like to know about your favorite types of flower. [27:22.960 --> 27:25.820] I want to get some for my mom, but I would like some recommendation. [27:26.180 --> 27:28.940] One that you used to care for are preferable. [27:30.700 --> 27:34.100] Third of all, I would like to know who made a difference. [27:34.100 --> 27:37.280] It's the encounter released in 2017. [27:38.180 --> 27:38.260] Okay. [27:39.300 --> 27:41.520] Last but not least, what is Veronica's gift? [27:41.640 --> 27:44.460] Toward the end, he just gave up and just asked them a question. [27:45.240 --> 27:48.200] Anyway, I mean, I'm making fun of this, but... [27:48.200 --> 27:59.120] On one side, I appreciate that somebody went through the effort to hook up GPT and to some email sender and was like, collect this bounty for me or something. [27:59.120 --> 27:59.200] You see? [28:00.100 --> 28:02.120] On the other side, I'm like, seriously? [28:04.400 --> 28:06.780] Anyway, you can respond to these emails. [28:07.160 --> 28:16.060] And, of course, you can rabbit hole this whole bot in a few seconds and it will tell you nonsense and you can make it do some silly stuff. [28:16.720 --> 28:23.080] And the thing that boggles my mind is that somebody went through the trouble of doing this and they didn't even put in a random back off. [28:23.280 --> 28:25.120] So, if you send an email, they reply immediately. [28:27.000 --> 28:32.900] Any time of day, they just come up with a nice long text for you in response. [28:33.440 --> 28:33.540] Okay. [28:34.400 --> 28:35.800] Anyway, enough about AI. [28:37.220 --> 28:37.900] Use cases. [28:38.100 --> 28:39.360] This is my favorite part. [28:39.680 --> 28:46.400] So, I told you that this was for my mom and I started using it for her so she can send me stuff every once in a while. [28:46.620 --> 28:48.840] I since shared it with some friends. [28:49.320 --> 28:50.640] They actually like it a lot. [28:50.800 --> 28:52.120] They feel like it's a spy tool. [28:52.120 --> 28:55.840] So, they send me encrypted stuff when there's no need for it. [28:57.420 --> 29:02.760] And I've used it also to talk to some strangers on the Internet where I don't want Google to read my email. [29:03.460 --> 29:06.640] For example, people that have given presentation here at HOPE. [29:06.880 --> 29:08.260] I just want to send them a message. [29:08.380 --> 29:09.580] Hey, I saw your talk at HOPE. [29:10.220 --> 29:13.220] This file, there's the rest of my message. [29:13.220 --> 29:18.100] And I can link to the project so they can actually see what it is about. [29:19.800 --> 29:29.580] But, since then, this has basically become my Lego break in the sense that it's very nimble, it's very simple, but it stacks up. [29:29.680 --> 29:31.860] It can work in a number of situations. [29:32.500 --> 29:39.430] And so, I've integrated into my processes and my systems. [29:39.750 --> 29:43.870] So, my background is dependability in distributed systems. [29:43.870 --> 29:48.810] So, I'm one of those people that is always thinking about what's the worst that can happen. [29:49.270 --> 29:52.070] Not that I expect the worst to happen, but I just want to know. [29:52.830 --> 29:59.730] And so, I've always had these things, this question in my mind, like, what if all of my devices get stolen? [30:00.270 --> 30:01.430] What do I do? [30:01.650 --> 30:04.870] How do I get back into my digital assets? [30:06.330 --> 30:12.050] Or, I'm in a foreign country, I'm traveling, I lose my passport, what the heck did I do? [30:12.830 --> 30:14.990] And also, what if I get hit by a bus? [30:15.150 --> 30:20.630] I don't want the people, the family, to have to deal with additional burden. [30:22.930 --> 30:32.310] There's also some more mundane use cases, like sending emails from an untrusted phone or from a friend's phone without actually them reading the message. [30:33.070 --> 30:38.270] And, in general, talking without them listening, whatever them is for you. [30:38.630 --> 30:41.470] I mean, Facebook usually, Google, and so on. [30:42.650 --> 30:43.930] So, I'm going to go through these. [30:45.150 --> 30:50.330] So, nightmare fuel number one is all of your devices are gone. [30:50.630 --> 30:54.830] So, of course, I do backups, all sorts of things. [30:54.830 --> 30:58.890] But, there are a few kind of, I call them my top-level secrets. [30:59.750 --> 31:03.690] And they are, for example, the encryption key to my end-to-end encrypted backup. [31:04.130 --> 31:07.810] If I can get back into my backup, then everything else is easy. [31:07.930 --> 31:14.010] But, how do I carry around my most critical key without, you know, being easy to steal? [31:14.570 --> 31:16.610] Even though, nobody wants to steal my encryption key. [31:16.710 --> 31:17.750] Nobody knows what to do with it. [31:17.870 --> 31:20.570] But, I just feel a little paranoid about it. [31:21.890 --> 31:24.970] So, of course, I have copies of these, all of my trusted device. [31:25.050 --> 31:27.510] But, what if all of the devices are gone? [31:27.690 --> 31:29.090] So, for example, a house fire. [31:29.450 --> 31:31.990] A burglar that takes everything in the house. [31:33.190 --> 31:36.970] Or, on a smaller scale, if I lose every device that I brought on a trip. [31:37.110 --> 31:39.150] I came to New York with a phone and a computer. [31:40.210 --> 31:43.190] What if both of those get lost, get stolen? [31:44.130 --> 31:45.070] It's a possibility. [31:46.490 --> 31:55.930] So, what I came up with is actually making copies of my top-level keys encrypted with portable secret. [31:56.310 --> 32:00.690] And I just make a USB drive with these critical secrets. [32:00.990 --> 32:04.470] I made 10 copies of this drive, and I just scattered them around. [32:04.690 --> 32:09.550] I have one in my car, I have one in my wife's car, I have one in my suitcase, I have one in my backpack. [32:10.690 --> 32:18.210] And so, if all of my devices are gone, I just need to fish into one of these places, and I have my key. [32:19.430 --> 32:27.810] And the good thing is that if someone else takes one of these keys, if it gets stolen, if it gets lost, I don't really care, because it's actually secure. [32:32.310 --> 32:38.090] Second nightmare fuel scenario is getting stuck in a foreign country without any documents. [32:38.090 --> 32:42.830] Again, passport, and maybe the backpack with passport and phone are stolen. [32:43.290 --> 32:44.890] And so, what the heck do I do? [32:46.230 --> 32:53.990] So, what I came up with here is actually publishing my passport encrypted on the open web. [32:56.330 --> 33:02.230] And it's fine, because it's a memorable URL that I can think of. [33:02.330 --> 33:04.410] It's not this one, this one I made up right now. [33:08.170 --> 33:13.730] This one actually is a redirect to one of the examples on the GitHub. [33:14.150 --> 33:16.070] But so, this gives you an idea. [33:18.590 --> 33:20.510] And boom, I have my passport back. [33:28.570 --> 33:31.390] Third and last, I get hit by a bus. [33:31.710 --> 33:37.610] I meet an untimely demise or mid-space segmentation fault. [33:38.930 --> 33:44.870] So, it's painful enough for family to deal with a loss. [33:45.070 --> 33:56.590] I don't also want them to deal with the giant headache and pain in the ass that it is to regain access to, say, my bank account and all of my other digital stuff. [33:57.190 --> 34:00.950] So, for this, I came up with another USB. [34:01.570 --> 34:03.710] It's clearly labeled in case of that. [34:04.190 --> 34:05.430] It sits in a drawer. [34:06.570 --> 34:09.310] And for one thing, it's a reminder that life is short. [34:09.690 --> 34:11.010] And we should leave it fully. [34:11.370 --> 34:18.670] But most importantly, it contains letters and logins and instructions on how to get back into my things. [34:19.910 --> 34:23.270] So, hopefully nobody will ever decrypt this, but it's there. [34:23.550 --> 34:23.930] It's safe. [34:24.290 --> 34:27.430] And again, if it gets stolen, nothing. [34:27.690 --> 34:29.050] Not really a big problem. [34:30.370 --> 34:49.610] I'm going to, since I'm long on time, I'm going to take one second to talk about something completely unrelated to digital and technology, which is, if you have family that you care about, and if you want to address this situation, which can happen to any of us, [34:49.610 --> 34:54.550] that you basically meet your untimely device, device, demise. [34:56.530 --> 35:00.370] I highly recommend creating these two documents. [35:02.050 --> 35:04.530] It's basically, it's very simple. [35:06.150 --> 35:08.270] A living trust is an entity. [35:08.470 --> 35:10.250] It's a legal entity in your name. [35:10.550 --> 35:12.630] And it's an empty, basically, shell. [35:13.570 --> 35:19.830] A poor over will is a document that says, if I die, all of my assets go into the trust. [35:20.790 --> 35:23.790] So basically, as long as you're alive, nothing happens. [35:24.030 --> 35:27.550] The moment that you die, all of your assets are transferred inside this living trust. [35:27.890 --> 35:41.590] And this living trust has a list of people, the people that you trust the most, hopefully, that are in charge with your instruction to either deal with whatever you have, or they basically automatically inherit it. [35:41.870 --> 35:43.050] And this is... [35:43.630 --> 35:45.750] takes maybe a few hours to set this up. [35:46.010 --> 35:47.170] Costs you a few hundred dollars. [35:47.170 --> 35:49.830] You can do it on a website like LegalZoom. [35:49.950 --> 35:51.190] It's pretty standard stuff. [35:51.910 --> 35:55.410] But it's a few hundred dollars for you, a few hours for you. [35:55.630 --> 36:03.010] It's going to save thousands of dollars to your family and months of work just to get back to stuff that was yours. [36:05.090 --> 36:06.610] Okay, digression over. [36:09.150 --> 36:12.670] More mundane use case for the everyday paranoid hacker. [36:13.490 --> 36:19.810] This is something that happened once and just having to send a text message from my friend's phone. [36:19.930 --> 36:20.630] It's a good friend. [36:20.750 --> 36:25.630] I have nothing against this friend, but I just didn't want to read what was sent because reasons. [36:26.010 --> 36:36.630] And so I just went on my website, created a secret, downloaded the secret, send it as a SMS to my wife, and done. [36:37.010 --> 36:39.530] So they are not burdened with my secret. [36:39.810 --> 36:42.110] I know that my information in transit is secure. [36:44.110 --> 36:56.450] And I said before, this can also work well to talk with somebody online that you don't necessarily want to blurt everything out in the first email, because there are systems reading your emails, of course. [36:58.510 --> 37:02.170] Another use case, sharing SSH keys over Slack. [37:02.450 --> 37:04.930] Of course, you should not do this. [37:05.070 --> 37:09.150] There are better ways to do this, but I do this for ephemeral systems. [37:09.470 --> 37:12.750] So we're bringing up a cluster for a few hours, for a few days. [37:12.750 --> 37:14.710] I just shared the key. [37:14.990 --> 37:19.350] And instead of sending it plain into Slack, which, by the way, had a leak today. [37:19.550 --> 37:21.430] Somebody leaked a terabyte of Slack data. [37:21.730 --> 37:25.690] So I would be pretty embarrassed to see my message in there with a private key. [37:26.270 --> 37:30.490] But if I share it with a portable secret, nobody in theory can get to it. [37:32.090 --> 37:46.090] And in general, the primary use case and the most common is you want to talk with your friends, and you don't want Facebook and Google to listen or to read what you're sending. [37:46.530 --> 37:53.270] So this is pretty low effort, additional layer of privacy for your regular messages. [37:54.030 --> 38:13.110] And just as a final hack, final silly thing, if you take an email, encrypt your message with portable secret, put the portable secret in the email, and in the same email you write, the password is, and you write the password. [38:13.590 --> 38:16.190] You might say, what good does it do? [38:16.370 --> 38:18.310] It doesn't protect anything. [38:19.150 --> 38:22.510] And you're right that it doesn't protect you if somebody steals your email. [38:22.730 --> 38:24.670] They can, of course, get into the secret. [38:24.930 --> 38:29.450] But at the same time, it's enough to throw off WhatsApp and Messenger and Gmail. [38:29.750 --> 38:31.810] They will not be able to read your email. [38:32.930 --> 38:33.790] All right. [38:33.970 --> 38:36.410] That's all I have for you today. [38:37.510 --> 38:38.790] Everything is open-source. [38:39.150 --> 38:41.470] The QR code takes you to the GitHub page. [38:43.150 --> 38:49.830] And hit me up on Matrix or via email on my website if you want to talk about any of these. [38:50.850 --> 38:52.010] Thank you very much. [39:02.210 --> 39:03.110] Any questions? [39:04.650 --> 39:08.430] How much harder would it be to set this up with asymmetric encryption? [39:08.650 --> 39:13.330] Because I can trust myself to remember a good password but not necessarily my parents? [39:14.750 --> 39:17.450] Well, asymmetric, then you need to deal with keys, right? [39:18.290 --> 39:25.890] I am actually not sure the support for asymmetric is as good as the symmetric one. [39:26.130 --> 39:28.550] Like, the symmetric primitives are right there. [39:28.550 --> 39:31.270] So, for example, let me go back here. [39:37.330 --> 39:38.310] Check this out. [39:39.830 --> 39:45.110] So, the problem with that one is how do your parents then store and use the key? [39:46.710 --> 39:48.730] By public, so they could get it done. [39:48.930 --> 39:49.410] Oh, yeah, no. [39:49.470 --> 39:50.370] The public one is easy. [39:50.750 --> 39:53.770] How, like, if you want to message them, they need to have a private key. [39:53.770 --> 39:55.450] They need to know how to use it. [39:55.690 --> 39:59.230] So, if your parents are up to learning that much, yeah. [40:00.230 --> 40:00.710] Absolutely. [40:01.490 --> 40:10.530] And, of course, I think this would be a great improvement over this, the asymmetric version where the other person must have a key. [40:13.430 --> 40:15.770] Let me just show support. [40:19.050 --> 40:26.230] Basically, for example, see, ED is not very broadly supported, which kind of sucks. [40:28.430 --> 40:29.030] Anyway. [40:29.830 --> 40:33.470] I think this is a great repurposing of software that's already in everybody's system. [40:33.650 --> 40:36.210] This is an awesome unexplored area. [40:36.470 --> 40:37.070] Congratulations. [40:37.070 --> 40:38.230] Thank you. [40:39.670 --> 40:41.090] Are the slides going to be online? [40:41.970 --> 40:43.230] Sorry, the slides? [40:43.410 --> 40:43.650] Yeah. [40:44.130 --> 40:46.210] But the presentation is recorded. [40:46.530 --> 40:49.530] And if you just, if you want them, I can share them. [40:51.470 --> 40:57.450] Since the decryption part, the JavaScript, is basically in plain text, right? [40:57.570 --> 41:06.130] Either in storage or in transit, how do you validate that, you know, sort of checking it every time before you open the file, how do you validate that it's not malicious? [41:06.130 --> 41:06.810] Yeah. [41:07.230 --> 41:07.710] Yeah. [41:07.870 --> 41:08.650] That was... [41:08.650 --> 41:09.750] I mentioned this. [41:09.850 --> 41:11.550] I think that is the biggest problem. [41:11.550 --> 41:21.190] That if you're dealing with somebody that can craft a different version of this and send it to you and you don't check... [41:21.830 --> 41:22.310] Yes. [41:22.530 --> 41:24.910] But at the same time, it's still living in a browser sandbox. [41:25.430 --> 41:28.490] In theory, the worst thing that you can do is leak your IP address. [41:28.790 --> 41:33.610] So if you open it up without looking, it doesn't have access to your files. [41:34.090 --> 41:35.070] It doesn't really... [41:35.070 --> 41:36.590] But could you also leak the password? [41:38.350 --> 41:39.390] Oh, yeah. [41:39.630 --> 41:39.970] That's... [41:39.970 --> 41:44.830] So a modified version with a keylogger that sent the password to the original. [41:45.030 --> 41:45.250] Yeah. [41:45.330 --> 41:45.430] Yeah. [41:46.290 --> 41:46.730] Absolutely. [41:52.640 --> 42:10.220] For the longer-lived use cases like you mentioned, like Power Quill and that sort of stuff, is there any fear of browser APIs being deprecated and encryption methods going away over time that you need some legacy device to be able to run this? [42:11.660 --> 42:20.560] I'm not a web developer, but these algorithmic primitives have been around for a while. [42:20.560 --> 42:26.680] They're still the best as far as multiple organizations recommend. [42:26.680 --> 42:30.560] So in theory, they are here at least for a while. [42:35.020 --> 42:35.680] That's... [42:35.680 --> 42:36.860] That's... [42:36.860 --> 42:37.120] Yeah. [42:38.440 --> 42:40.080] But good point. [42:40.260 --> 42:47.840] Because if I try to record my secret in 10 years and browser have stopped implementing these APIs, then I'm kind of toast. [42:47.840 --> 42:52.960] Hopefully I can go on the Internet Archive and download the 2024 version of Firefox. [42:56.440 --> 43:01.280] So you mentioned that one of the use cases here is for getting secret messages from your mother. [43:02.000 --> 43:11.120] I just tried right now on an iOS device to insert a simple secret, and I couldn't get the HTML file from the browser. [43:11.360 --> 43:13.180] So how do I send that to somebody else? [43:14.060 --> 43:16.220] I was using the .go browser. [43:16.380 --> 43:16.980] It's not going to be my fault. [43:17.840 --> 43:18.060] Okay. [43:18.820 --> 43:25.480] So basically, if you generate a secret, maybe it's too small to see. [43:26.540 --> 43:27.480] It's still too small. [43:28.160 --> 43:28.480] But... [43:30.120 --> 43:32.020] This is a URL encoded payload. [43:32.240 --> 43:32.440] Right. [43:33.620 --> 43:39.880] So it probably means that your browser does not accept URL encoded payloads. [43:40.040 --> 43:41.440] I mean, I was able to open it myself. [43:41.680 --> 43:47.360] But when I tried to send it to somebody else, I couldn't, like, figure out a way in the browser to download the page, so that I could forward it out. [43:47.780 --> 43:49.760] There didn't seem to be a button in iOS to do that. [43:49.840 --> 43:50.880] Can you press on hold? [43:51.100 --> 43:51.260] Yeah. [43:51.260 --> 43:52.360] I'll try it. [43:52.540 --> 43:52.960] I mean, I'll try it. [43:52.960 --> 43:53.100] Yeah. [43:53.220 --> 43:54.420] I think you can save file. [43:54.620 --> 43:57.600] It saves it your iCloud drive. [43:57.780 --> 43:59.820] I'm perfectly happy to admit that I'm the... [44:02.140 --> 44:21.320] So to address the concern with validating the encryption component, since you already have all the payload data separated, you could add a function from any of this, a pre-existing already validated one, and drop a new one on it. [44:21.640 --> 44:23.580] You could just use it as the input. [44:25.300 --> 44:30.440] So add something to the portable secret itself that self-validates? [44:31.100 --> 44:34.000] It could validate any other file of the same format. [44:34.320 --> 44:37.580] It would read the bottom, data at the bottom, and use that as the input. [44:38.580 --> 44:39.060] So... [44:39.060 --> 44:39.300] Yes. [44:39.700 --> 44:42.960] So a non-self-contained, basically an app that decrypts. [44:43.740 --> 44:46.100] I mean, you could reuse an existing one. [44:46.220 --> 44:48.320] We could call it that, make a standalone one. [44:48.400 --> 44:56.120] But you could just use one of these and have a function that, instead of decrypting itself, decrypts something from your email. [44:57.300 --> 45:04.420] Actually, yeah, the thing that I wanted to do is kind of like that, where it actually, it's a quine. [45:05.220 --> 45:07.180] Quine is a program that can create themselves. [45:07.520 --> 45:14.020] And so it would be really cool if I receive a secret, and I can actually, in the secret itself, there is code to create the next secret. [45:14.200 --> 45:21.640] So that I can, one, validate, as you're suggesting, and then create the next one, and send it back in response. [45:24.280 --> 45:24.940] Yeah, there. [45:26.140 --> 45:27.320] Thanks for the presentation. [45:27.520 --> 45:27.860] That was great. [45:28.140 --> 45:33.460] At one point, you mentioned the mechanism for rate limiting, the ability of people to try to brute force. [45:33.620 --> 45:41.080] Is that a function of how your JavaScript is using the subtle APIs, or where exactly is that rate limiting happening? [45:41.500 --> 45:42.120] Oops, sorry. [45:43.960 --> 45:59.240] Because the thing that struck me was, like, you have the file, the ciphertext is, you can pull that out, you can pull out the cipher algorithm, you can pull out the salt, so you could potentially perform your brute force attack completely outside the browser, [45:59.440 --> 45:59.640] right? [45:59.920 --> 46:00.440] Yes. [46:00.720 --> 46:01.100] Okay. [46:01.720 --> 46:02.540] Absolutely, yes. [46:02.860 --> 46:06.320] But, so, here's two ways that you can brute force this. [46:06.560 --> 46:14.500] You can try every possible key that is very large, or you can try with a dictionary attack. [46:15.580 --> 46:17.780] This slows down the dictionary attacks. [46:20.300 --> 46:23.700] Because, basically, if you have a dictionary, you go, say, line by line. [46:23.880 --> 46:33.260] And so, from the first password in the dictionary, to try to get a key and try to decrypt with that key, say, if you do 10 million iterations here, it's going to take one second. [46:33.540 --> 46:37.600] Then, to try the second one in the dictionary, it's going to take another second, and then the third one, and so on. [46:37.880 --> 46:39.300] So, it just slows down. [46:39.620 --> 46:44.140] And, of course, again, everything is, this stuff is easily parallelizable. [46:44.760 --> 46:46.520] So, it's not magic. [46:50.660 --> 46:51.640] Any other questions? [46:52.640 --> 46:53.380] I have a question. [46:53.700 --> 46:59.100] If I understand correctly the part of that USB, and how you share the password, what's your strategy? [46:59.360 --> 47:02.280] You have the USB with all the information, yeah? [47:02.840 --> 47:03.240] Yeah. [47:03.340 --> 47:03.760] Like somewhere. [47:04.000 --> 47:04.840] But, you know the password. [47:04.920 --> 47:06.180] You're the only person knowing the password. [47:06.360 --> 47:07.340] So, how you... [47:07.340 --> 47:12.680] Oh, those are, the hints for those are things that I, like, secrets that I share with my wife. [47:13.340 --> 47:15.200] And so, yeah, things like... [47:15.200 --> 47:16.880] Sharing the password, just sharing the hints. [47:17.600 --> 47:17.900] Yeah. [47:18.340 --> 47:22.360] So, it contains a portable secret, where the hints are four things that my wife should know. [47:22.560 --> 47:23.640] We talked about them. [47:23.800 --> 47:24.420] She knows them. [47:24.660 --> 47:27.380] And so, she can open those files, but nobody else can. [47:27.520 --> 47:31.000] So, if somebody steals them, they're unsafe. [47:32.040 --> 47:32.680] Any other questions? [47:33.060 --> 47:37.800] I was wondering how you keep your wife from snooping in the one that says, in case of death. [47:38.420 --> 47:39.300] I mean... [47:40.620 --> 47:42.560] For one thing, she doesn't even know it's there. [47:42.560 --> 47:44.280] It's in my number one drawer. [47:44.460 --> 47:46.960] She would find it immediately, but she doesn't even know it's there. [47:47.140 --> 47:50.660] And if she finds it, I trust her not to snoop. [47:50.760 --> 47:53.500] And even if she snoops, what's she gonna do? [47:53.580 --> 47:54.800] Steal my bank account? [47:59.520 --> 48:00.240] No question. [48:02.000 --> 48:02.840] Anybody else? [48:03.840 --> 48:06.940] As a token of appreciation, are there any flowers you would like? [48:11.520 --> 48:13.220] Mmm, flowers, let's see. [48:15.620 --> 48:16.800] Any other questions? [48:17.560 --> 48:17.740] Yeah. [48:18.000 --> 48:19.060] Safari is a problem. [48:19.480 --> 48:20.580] So, it's a bit independent. [48:20.980 --> 48:34.700] But on the topic of USB, restoring the secrets for long-term, what do we know about the longevity of flash drives that are not plugged in? [48:34.920 --> 48:37.160] Are they stable or do they decay? [48:37.480 --> 48:40.560] The longevity of USB drives is pretty terrible. [48:40.560 --> 48:42.160] They die all the time. [48:43.240 --> 48:44.600] They die all the time. [48:45.260 --> 48:45.400] Yeah. [48:45.400 --> 48:45.560] Yeah. [48:46.600 --> 48:52.220] I know it because I go and check, and like a couple of years without plugging in, it's gone. [48:52.980 --> 48:53.980] It kind of sucks. [48:57.810 --> 49:00.930] That's why, for example, things like the passport, I actually put it online. [49:01.110 --> 49:07.930] I can also carry it in my backpack in a portable secret, but I put it online because, first off, I don't know that I have my thing. [49:08.630 --> 49:12.550] If it's online, I can actually open it with anybody's computer. [49:12.610 --> 49:18.770] So, if I'm stuck at the border control, somebody lands me a phone, I can actually open it right there. [49:21.150 --> 49:21.770] One more. [49:21.770 --> 49:24.450] How variable are the file sizes once you're encrypted? [49:27.050 --> 49:31.530] So, basically, the first part of the file is always the same. [49:31.790 --> 49:38.270] The thing that changes is just the cipher text, and that's directly proportional to the size of your payload. [49:38.810 --> 49:45.750] So, you just take your initial payload, you round it up to block size, and that's the size of your payload. [49:45.750 --> 49:53.930] So, if you're encrypting a one gigabyte file, it's going to be a one gigabyte file, plus 300 bytes or something like that. [49:55.270 --> 50:03.430] And in that regard, this is not a great tool for sharing large files, because, as I showed earlier, it's using URL encoding. [50:03.790 --> 50:06.470] So, if I encrypt a file, actually, let me show you. [50:09.110 --> 50:19.330] So, this is an encrypted zip file, and as you maybe can see down here, it's a URL encoded payload, like the data is in there. [50:19.490 --> 50:22.190] So, some browsers don't support too long. [50:22.830 --> 50:23.710] I'm out of time. [50:23.890 --> 50:26.770] Thank you very much, and see you around.