[00:02.320 --> 00:03.040] The works. [00:10.260 --> 00:11.540] You know the drill with time? [00:12.280 --> 00:13.940] Actually, I don't think there's anyone after you, is there? [00:14.640 --> 00:15.980] I don't think as much time as you want. [00:16.900 --> 00:19.720] The usual drill with time is wrap-up by 5-0. [00:24.800 --> 00:27.160] Just tell me and I'll get out of here. [00:28.240 --> 00:33.340] We'll give you a yellow card, which is your five-minute warning. [00:33.340 --> 00:35.640] And the red card is, thanks very much. [00:36.200 --> 00:36.560] Goodbye. [00:49.600 --> 00:51.500] Okay, it seems to have... [00:51.500 --> 00:52.100] Hello. [00:52.740 --> 00:53.140] Cool. [00:53.440 --> 00:54.520] I'm going to do a quick announcement. [00:54.720 --> 00:57.120] Then we'll do a quick introduction and then it's all yours. [00:58.700 --> 00:59.700] All right, everyone. [01:00.000 --> 01:00.720] Welcome back. [01:01.320 --> 01:02.760] Hope you're having a great time. [01:02.880 --> 01:03.460] Hope you're energized. [01:05.460 --> 01:06.500] Stay up tonight. [01:06.800 --> 01:08.820] Got sessions going until midnight. [01:10.020 --> 01:11.920] Have a variety of movies. [01:12.120 --> 01:14.280] The movie schedule has been posted in a few different areas. [01:14.440 --> 01:16.900] Look around for it or stop by the info desk on seconds. [01:17.120 --> 01:20.380] There's no reason to sleep at all the entire weekend, I urge you. [01:22.200 --> 01:23.080] Highly overrated. [01:24.820 --> 01:27.600] The network has been in a little bit of a yo-yo state. [01:27.840 --> 01:30.880] We're seeking stability and we may find it. [01:30.880 --> 01:32.520] We may enjoy it. [01:36.920 --> 01:43.380] I think the only two announcements that I have, brief ones, are for the third track session. [01:43.880 --> 01:51.980] Do keep in mind we're offering third track in what we call the C room, which is a Madison room, up the hallway to your left. [01:52.380 --> 01:53.380] It has some seats. [01:53.400 --> 01:54.680] We have a projector. [01:54.900 --> 01:55.580] We can loan you... [01:55.580 --> 01:59.360] We didn't leave it in the room, but we can loan you a computer projector if you'd like. [01:59.520 --> 02:06.400] We'd be really happy for people to sign up to talk about almost anything that they'd care to you related to the conference theme. [02:06.740 --> 02:12.100] The sign up sheet, I think, is now right next to that C room for Madison. [02:12.100 --> 02:17.700] So you're welcome to get involved with that and be a presenter, in addition to being an attendee. [02:20.460 --> 02:32.400] Other thing to mention briefly, because we had a very good crowd for the lockpicking workshop this afternoon, from about 2 till 5 down in area 8 of the second floor of the Penn Pavilion. [02:32.680 --> 02:37.100] There will be a lockpick workshop again tomorrow, and we'll announce the time. [02:37.100 --> 02:45.360] It'll either be starting during the Woz keynote, after the lockpicking panel, or it'll be after, right after the Woz keynote. [02:45.660 --> 02:50.600] But it'll be one of those two for a couple hours in the afternoon, so stay tuned for more details on that. [02:51.240 --> 02:57.820] Lastly, we are still a little bit short-handed, not too terribly, but a little short-handed in some of our audio-visual. [02:58.260 --> 03:13.040] Probably a couple of other areas as well, but if you're interested in spending a little time on camera, if you have experience... if you have experience... if you have experience on camera, do consider stopping by the AV table back there, and we'll take a card, [03:13.180 --> 03:17.240] take your cell number, something like that, and try to get you on the schedule for a few hours shift. [03:17.820 --> 03:24.020] Okay, without further delay, this talk is CryptoPhone with Rop. [03:25.560 --> 03:26.200] Thank you. [03:33.890 --> 03:43.350] Okay, I don't know how many of you have been two years ago to my presentation back then, when I said we were almost done with this great crypto telephone that we were building. [03:43.810 --> 03:56.790] Well, we actually did get done, and today I get to talk a little bit about the things that have happened, how it all came out, what we actually ended up doing technically, and a little bit about what happened afterwards. [03:58.890 --> 04:08.310] The presentation... I'm going to be looking back to the screen, the same screen you're seeing a lot of the time, because my notebook, for some reason, at this resolution can't do both screens at the same time, which is annoying. [04:10.130 --> 04:17.790] I'm going to describe a little bit our world view as we see how interception is developing, what the world looks like, at least from our point of view. [04:19.510 --> 04:29.950] Mobile, and specifically GSM interception, we're going to be covering a little bit of the technology, how does interception work, who intercepts, where is your phone calls being intercepted. [04:31.350 --> 04:47.070] Then we're going to talk a little bit about the crypto phone, what we set out to do, how we technically did it, and then I'm going to be talking a little bit about how the crypto phone can be more secure if more people actually would take time to look at the deeper technical insides of it. [04:48.090 --> 04:49.150] Let me drink some water. [04:54.710 --> 04:58.210] Okay, I think we can safely say that today we live in the interception age. [04:59.730 --> 05:03.810] No form of unencrypted electronic communication of any kind is secure. [05:04.950 --> 05:08.150] Wherever you use the phone, it can be intercepted. [05:11.230 --> 05:14.150] There's many, many, many interception points on all networks. [05:14.150 --> 05:17.870] We'll be covering a lot of that later in the technical slides. [05:18.150 --> 05:24.350] And the political risks and economic damage from eavesdropping by government and private organizations are huge. [05:27.150 --> 05:28.630] So who's intercepting? [05:28.710 --> 05:38.810] There's law enforcement agencies, of course, intelligence agencies, organized criminals, corporations, private investigators, and just interested amateurs. [05:39.330 --> 05:45.150] All depending on how easy it is to intercept a certain kind of traffic and what the stakes are. [05:47.170 --> 05:49.630] So let's first talk a little bit about intelligence gathering. [05:49.850 --> 05:53.290] By the way, if anyone has any questions, just jump up, ask your questions. [05:53.490 --> 05:57.490] I'm not good at speaking for like 45 minutes and then having questions. [05:57.610 --> 05:57.890] Yeah, shoot. [05:58.830 --> 06:03.270] Just come up to the mic and I'll be talking for like 10 minutes and then somebody can ask a few questions again. [06:05.170 --> 06:05.690] Thanks. [06:06.090 --> 06:12.790] On the previous slide, it said there are economic disadvantages for spying on people, eavesdropping. [06:13.290 --> 06:14.130] What is that? [06:14.430 --> 06:17.050] The potential for economic damage is huge. [06:17.270 --> 06:25.590] If your conversations or your privileged communication of any kind, if that is intercepted, the potential for economic damage is huge. [06:25.890 --> 06:30.290] If you are a corporate entity or even a country, people could hurt you. [06:37.140 --> 06:41.100] Interception increasingly targets everyone, whole populations. [06:42.060 --> 06:47.080] Not just a few select targets, not even a lot of select targets, but let's just get everything. [06:48.020 --> 06:51.940] And the new enemy, terrorism, whatever you call it, is all of us. [06:52.180 --> 06:53.960] Of course, it's always been all of us. [06:54.040 --> 06:55.680] The enemy has always been among us. [06:55.680 --> 06:58.560] But now the enemy is among us. [07:00.340 --> 07:10.680] So there is great incentive for intelligence, for countries, for the security establishment to basically get all of us, or at least all our traffic. [07:11.280 --> 07:13.720] And there's of course a huge potential for abuse. [07:15.560 --> 07:17.220] So why would they be selective? [07:17.940 --> 07:20.040] Ethics, regulations, what's stopping them? [07:21.860 --> 07:24.660] Most countries have very little in the way of legal oversight. [07:25.680 --> 07:35.480] I come from a country which is number two in the world in terms of using interception, both from the law enforcement and intelligence bureaucracies. [07:37.100 --> 07:42.460] I come from the Netherlands, by the way, and we rank very high on intercepting phone calls. [07:45.800 --> 07:53.360] Even if there is legal oversight, it's usually rubber stamping requests for phone intercepts. [07:55.420 --> 07:57.680] There's a whole thing called lawful access. [07:58.140 --> 08:03.600] It's lawful access to voice communications, lawful access to Internet traffic. [08:03.600 --> 08:06.440] There's a whole industry on doing that. [08:08.000 --> 08:11.500] Of course, most countries don't have even laws covering it. [08:11.600 --> 08:13.080] They don't have judicial oversight. [08:13.320 --> 08:19.140] So most countries, lawful access just means whoever wants to listen and happens to be currently in power. [08:21.400 --> 08:27.840] Whatever legal protection you have is going to evaporate over the next years, over the next months. [08:28.260 --> 08:30.220] And until then, they'll just ignore it. [08:32.160 --> 08:35.120] Even if your government cares, other governments care even less. [08:35.340 --> 08:37.660] And of course, these governments all have swapping agreements. [08:37.860 --> 08:51.560] It's long been a trick for, say, the U.S. government and the British government to spy on each other's dissidents, so that they could claim they're not spying on their own domestic insurgents. [08:51.560 --> 08:57.060] But then the British would do it for the Americans, the Americans would do it for the British, and they would swap the information gathered. [09:00.790 --> 09:02.470] So is technology stopping them? [09:02.690 --> 09:09.830] We did a little bit of a calculation how much it would cost to store everything, that is, all phone calls. [09:10.110 --> 09:14.170] And we did that for the country of Germany, which is a population of 85 million. [09:14.170 --> 09:19.850] So if you multiply all these figures by two to two and a half, you get the U.S. figures. [09:22.230 --> 09:31.330] If you record everything at 4.8 kilobits per second, which gets you a pretty decent voice, there's 319 billion minutes of fixed network calls. [09:31.530 --> 09:33.410] That's about 10 petabytes worth of data. [09:34.430 --> 09:36.190] And these are very high estimates. [09:36.510 --> 09:43.830] I was just part of building a petabyte, helping out the Internet Archive, and we actually came out a lot cheaper than this. [09:44.230 --> 09:50.530] But these are high estimates for keeping that data available on spinning disk, where people can actually access it and analyze it. [09:51.930 --> 09:57.010] 30 million dollars, 32 billion minutes of GSM traffic is 3 million dollars. [09:58.350 --> 10:03.770] And in very small print, there is the U.S. intelligence budget, which is 27 billion dollars a year. [10:04.570 --> 10:15.090] So as you can see, recording everything, every single phone call, on a large network for a large country isn't hard, isn't expensive, isn't difficult. [10:15.770 --> 10:21.330] The type of storage needed is the type of storage that private organizations are building right now for other things. [10:21.810 --> 10:27.450] This is not some huge amount of data that only an intelligence corporation could have. [10:29.410 --> 10:34.350] Anyway, so technology is not a stopper for storing everything. [10:34.490 --> 10:39.970] Of course, you could assume that there are certain calls you want to keep much longer than other calls. [10:40.110 --> 10:42.230] This is if you want to really keep everything. [10:42.390 --> 10:50.430] You can say, well, calls to call centers for utility companies are probably not that interesting, so we can expire them after three months. [10:51.030 --> 10:54.210] Calls between individuals are much more potentially interesting. [10:55.490 --> 11:05.750] You could do network analysis and try to figure out how interesting somebody is or how interesting his friends are, and sort of build your whole expiry algorithm around that. [11:05.870 --> 11:11.270] You don't have to choose to expire the whole data for all the country at the same time. [11:13.050 --> 11:15.170] Then there's non-government interception. [11:17.090 --> 11:22.110] There's now problems related to unauthorized interception of calls reported all over the world. [11:23.290 --> 11:27.310] It's no longer just big guys, no longer just large organized crime. [11:27.450 --> 11:33.570] There's just above street-level criminals the world over that are getting their hands on interception gear. [11:33.570 --> 11:41.010] Many countries still have analog phone networks, analog cellular networks, and also digital gear is becoming more and more accessible. [11:41.210 --> 11:43.630] There's more slides on that later on. [11:45.250 --> 11:50.750] Equipment is going to get cheaper and cheaper, and the communications landscape is going to get weirder and weirder. [11:51.170 --> 11:54.090] Many more people are going to start offering voice services. [11:54.290 --> 12:03.350] There's going to be many different voice over IP services, mobile IP services, and this whole world is going to sort of mesh and intermingle over the next few years. [12:04.850 --> 12:08.330] There's no incentive for any operators to offer anything that's unbroken. [12:08.910 --> 12:09.810] Why would they? [12:11.970 --> 12:20.370] And even if they did, the call is still decrypted as soon as it reaches the land, as soon as it stops being on the air. [12:22.050 --> 12:26.830] And as soon as it's decrypted, of course, people in their own companies have access to it. [12:29.470 --> 12:32.110] So let's focus a little bit on mobile interception. [12:34.830 --> 12:42.310] It's going to be an out-of-control problem, at least in the public view, much faster than anything else, because there's no state monopoly. [12:42.490 --> 12:47.490] Anybody can listen to the airwaves, and the equipment, for instance, for GSM, is going to be more and more accessible. [12:51.200 --> 12:52.980] All cell phone systems are broken. [12:54.780 --> 12:59.160] There are no cell phone systems that do end-to-end encryption between the phones. [12:59.320 --> 13:03.300] There are no cell phone systems that really protect the content of your call. [13:03.680 --> 13:07.960] It's just to keep your basic hobbyists with a scanner out, nothing else. [13:07.960 --> 13:08.840] Yeah. [13:08.960 --> 13:09.420] Yeah. [13:09.680 --> 13:18.500] I actually saw someone that claimed to only sell to governments or something, but they were selling a GSM interceptor for, I think, like, three-quarters of a million. [13:18.620 --> 13:24.860] They could do, like, the newer, like, not way-breached GSM stuff. [13:24.860 --> 13:32.880] And I was wondering, like, they don't provide any details of how they do that. [13:33.060 --> 13:36.080] Do you think that there's some sort of backdoor built into GSM? [13:36.480 --> 13:37.000] Or... [13:37.000 --> 13:39.140] We actually found a company in India. [13:39.340 --> 13:40.940] There's now... there's some slides on that. [13:41.040 --> 13:55.940] But there's a company in India that has built for $80,000, I think, a four-channel interception device that does A51 and A52, which is the most used encryption algorithms for GSM. [13:56.280 --> 14:02.080] And there's a company in Romania that ripped off their software and built their own hardware around it, and they sell it for $4,000. [14:02.580 --> 14:03.020] Wow. [14:03.100 --> 14:05.200] So there's four-channel gear for 4K. [14:06.780 --> 14:09.340] So... a quarter of a million is a little expensive. [14:10.260 --> 14:10.600] Yeah, that's a... [14:10.600 --> 14:14.560] But I'm sure there's plenty of companies that still sell it to plenty of governments for that price. [14:15.620 --> 14:16.060] There's... [14:16.060 --> 14:17.440] But do they have... [14:17.440 --> 14:23.220] But do they have some sort of, like, I guess, zero-day breach of encryption... [14:23.220 --> 14:24.280] Breach of the... [14:24.280 --> 14:25.420] Like, flaw in the algorithm? [14:25.740 --> 14:26.380] Or is... [14:26.900 --> 14:27.560] I don't... [14:28.060 --> 14:30.520] This is, like, for over-the-air interception. [14:31.200 --> 14:31.500] Mm-hmm. [14:31.760 --> 14:37.420] Let me get to that, because there's a couple of slides on that, and then we'll sort of do a short break and talk a little bit about GSM. [14:38.860 --> 14:40.560] There is a man in the middle attack. [14:40.840 --> 14:41.320] This is the... [14:41.320 --> 14:43.100] The old-style interception. [14:43.400 --> 14:46.000] The interception that law enforcement sometimes uses. [14:46.140 --> 14:51.760] The interception that intelligence used to use the world over before they were using this passive gear. [14:52.480 --> 14:58.500] There is a man in the middle attack because GSM has very strong authentication of the user towards the network. [14:58.500 --> 15:06.340] If I am a GSM user, my SIM is actually a fairly strong means of authenticating myself as the legitimate user towards the network. [15:07.300 --> 15:21.080] How GSM works is if I'm roaming on a network, that network will ask my home provider for authentication information for me, and my home provider will send what is called triplets to the roaming network. [15:21.800 --> 15:25.220] These triplets contain a challenge called SRAND. [15:25.580 --> 15:26.840] No, sorry, RAND. [15:27.180 --> 15:31.640] A response that I need to give, which is called SRAS, and a content key. [15:33.080 --> 15:34.780] The network gives me RAND. [15:34.960 --> 15:40.380] I provide back from calculating the thing that's in my SIM, the secret that's in my SIM. [15:40.500 --> 15:41.320] I use a calculation. [15:41.580 --> 15:48.460] I provide SRAS, the answer, which authenticates me towards the network, and then the content key is used to scramble the communication. [15:49.560 --> 15:52.380] However, the network never authenticates to me. [15:53.020 --> 16:00.520] So if I walk up to someone with a device that says, I am now the network, my phone will happily log into it. [16:01.980 --> 16:15.520] And, of course, this device doesn't have my secret, so the device can't know the content key, but the device can say, oh, by the way, this is a network in a country that is not very trusted, say, Iraq, before you guys went in there. [16:21.160 --> 16:24.500] Then my phone would say, oh, in that case, we just don't do any encryption. [16:24.700 --> 16:36.260] So I would set up a phone call through this box, and this box on the other end would have a normal GSM phone, or pretend to be a normal GSM phone on some other SIM, and would pass my call back out. [16:36.260 --> 16:38.200] This is a detectable attack. [16:38.720 --> 16:41.540] It's an attack I can see if I'm an expert. [16:41.540 --> 16:47.020] I can sort of figure out through analyzing what goes on in the air that I'm being attacked. [16:47.200 --> 16:57.260] And there's also other giveaways, like if you have no cooperation with the GSM provider, the other side would not see caller ID, even if they're used to seeing caller ID for me. [16:57.260 --> 17:03.720] Of course, the networks are sufficiently broken that you don't see caller ID all the time if you just walk around with your GSM phone. [17:05.700 --> 17:08.360] Then there's passive GSM interception. [17:08.520 --> 17:10.500] There's been some breakthroughs against A51. [17:11.940 --> 17:14.300] A52, the other algorithm, has always been broken. [17:15.760 --> 17:18.140] There's been all sorts of breakthroughs against GSM. [17:19.120 --> 17:23.300] There's now, I think, something where you have four terabytes of data. [17:23.300 --> 17:24.580] You do a pre-calculation. [17:24.700 --> 17:27.260] You calculate a table that is four terabytes in size. [17:27.600 --> 17:29.300] And then within... [17:30.700 --> 17:31.460] What was it? [17:31.640 --> 17:32.520] If you had... [17:33.200 --> 17:40.880] I don't have the numbers offhand, but there's a near real-time interception for GSM with very modest equipment. [17:43.280 --> 17:47.940] Passive interception is not noticeable, unlike the MZ Catcher. [17:49.440 --> 17:51.140] And they're both on the open market. [17:51.140 --> 17:53.220] And as I just said, they're not very expensive. [17:54.140 --> 17:55.680] Then there's the microwave links. [17:56.060 --> 17:59.360] All these GSM cells are often connected with microwave. [17:59.580 --> 18:05.920] And these microwaves often have large amounts of calls stacked into one microwave link to all these cells. [18:06.040 --> 18:15.320] And if you have, like, one of these master cells that are on the fiber that hosts what is called the base station controller, they have microwaves going out in 15 different directions to all these other cells. [18:15.320 --> 18:19.600] If you sit right next to that and you listen to all these microwave... [18:19.600 --> 18:21.260] Because they all overlap. [18:21.560 --> 18:23.200] They're not straight point to point. [18:23.340 --> 18:25.400] They all wave out a little bit. [18:26.240 --> 18:31.760] If you listen to all these microwave connections, you get many, many, many phone calls coming in at the same time. [18:34.880 --> 18:36.160] They're also cheap to intercept. [18:36.400 --> 18:40.900] It's, like, less than 40k of equipment to get many, many, many calls for, like, whole parts of the city. [18:41.720 --> 18:42.580] All in one go. [18:48.400 --> 18:49.880] So, what do you do against this? [18:50.020 --> 18:53.020] There is lots of mobile voice encryption stuff available. [18:55.420 --> 18:57.180] However, it's all sort of weird. [18:57.320 --> 19:00.540] They all use, or most of them use, 1024-bit key exchanges. [19:01.460 --> 19:05.360] 1024-bits is, I think, by now generally recognized as not enough. [19:06.940 --> 19:08.460] 128-bit session keys. [19:09.300 --> 19:10.340] Proprietary algorithms. [19:10.940 --> 19:12.620] They're all black boxes. [19:12.740 --> 19:14.720] You can't really see what's going on inside. [19:15.460 --> 19:18.820] They're closed-source, and there's lots of rumors that many of them are back-doored. [19:20.120 --> 19:24.940] Most of the companies that build them have close ties to the people that intercept your phone calls. [19:25.060 --> 19:34.500] They have close ties to either the NSA or to the GCHQ of Britain, the French services, the German services, the Bundesnachrichtendienst, whatever they're all called. [19:34.700 --> 19:40.140] The same companies that supply gear to them also supply secure telephones, which makes you wonder. [19:41.840 --> 19:46.660] They often use their own hardware, which has advantages, and also a lot of disadvantages. [19:47.120 --> 19:48.500] They're never modern phones. [19:48.720 --> 19:50.400] They use lots of batteries often. [19:51.240 --> 19:54.440] They're expensive, and they're sometimes very, very difficult to use. [19:56.860 --> 20:07.580] I guess I'm going to talk a little bit about what we did, the CryptoPhone, but if anybody has any questions on GSM interception in general, how that works, what the scale of that is... [20:08.240 --> 20:09.420] How does the microwave work? [20:10.660 --> 20:12.080] Better to walk up to the... [20:14.500 --> 20:15.880] How does the microwave work? [20:15.880 --> 20:17.360] How does the microwave work? [20:17.960 --> 20:25.860] Microwave is just a means they use to link the cells they call base station controllers to all the outlying cells. [20:26.860 --> 20:39.980] So a given area may be covered by 15 or 20 or 30 transmitting towers, and only two of those may actually be connected to the fixed network, and they talk via microwave antennas to all the other towers that are near there. [20:40.740 --> 20:42.880] So they make convenient points. [20:43.080 --> 20:49.340] These central cells make convenient points for getting hundreds and hundreds and hundreds of phone calls with just one antenna. [20:52.100 --> 20:52.620] Yeah? [20:55.940 --> 20:58.980] I'm sorry, but it's really hard to... [21:02.430 --> 21:04.010] Could you talk about the Duncan... [21:05.270 --> 21:12.890] Could you talk about the Duncan-Campbell report and how that can show how this applies to everybody, about ECHELON and... [21:12.890 --> 21:14.470] You talk about the Duncan-Campbell report. [21:14.710 --> 21:14.990] Go ahead. [21:15.350 --> 21:17.790] I don't think that I know enough about the subject. [21:19.070 --> 21:21.450] There's been a report done for the European Commission. [21:21.450 --> 21:23.570] It was called the STOA report, S-T-O-A. [21:24.150 --> 21:26.070] If you Google for it, you should find it. [21:26.290 --> 21:29.470] And it was a report done by Duncan Campbell of England. [21:30.510 --> 21:37.650] And it basically tried to uncover that interception wasn't being done selectively. [21:37.650 --> 21:44.730] It wasn't being done against specific targets that were on some list or that were monitored by intelligence. [21:44.950 --> 21:57.150] But that basically, specifically, an organization set up by the UK and the USA, called the UK-USA Intelligence Alliance, was basically sucking in everybody's phone calls. [21:57.410 --> 22:02.710] But they also did queries for certain organizations and other people that they would watch. [22:02.710 --> 22:04.290] And he talked about that as well, right? [22:04.530 --> 22:04.750] Uh-huh. [22:04.910 --> 22:10.270] Yeah, they were looking for certain organizations, NGOs such as Greenpeace, but also many others. [22:11.870 --> 22:13.370] Yes, there are watch lists. [22:13.490 --> 22:18.470] And, of course, there are also looking specifically, but they were also pulling in traffic from just everybody. [22:19.270 --> 22:23.590] Now, how difficult is the microwave interception given the beam width of the microwaves? [22:24.190 --> 22:29.110] If you have the equipment, which is very generic, it's not that difficult at all. [22:29.230 --> 22:33.010] It's just basically receiving a 2-megabit or a stack of 2-megabit carriers. [22:33.290 --> 22:38.190] Well, I assume you're talking NbyE1 or E3 or DS3 links or something like that. [22:38.230 --> 22:40.450] I'm referring to the European situation. [22:40.650 --> 22:42.490] In Europe, there are 2-megabit carriers. [22:42.490 --> 22:54.530] 2-megabit-stacked signals, and the 2-megabits are actually just primary-rate ISDN, basically, with signaling information added instead of the end signaling. [22:54.810 --> 22:57.550] Do any of the microwave manufacturers scramble those in transit? [22:59.490 --> 23:08.010] Supposedly, yes, but lots of people from that industry tell me privately that it's never used and that they have that on maybe a few sensitive links. [23:08.610 --> 23:13.910] They may have it on the cell tower that serves the president's house, but they don't have it anywhere else. [23:14.430 --> 23:14.870] Okay. [23:19.590 --> 23:26.260] So, all the interception methods that you've mentioned so far are kind of limited geographically in scope because they were wireless. [23:26.480 --> 23:28.310] So, you're either at the tower or whatnot. [23:28.550 --> 23:34.360] Does the GSM standard define the wired side of things, too? [23:34.500 --> 23:36.070] And would that be another interception point? [23:36.620 --> 23:41.940] Well, yeah, the GSM standard defines lots of stuff about protocols that are also used on the wired end. [23:42.200 --> 23:46.780] Of course, there's lots of interception happening just at undersea cables, everywhere. [23:49.600 --> 23:56.090] There's...it's very...it's a very...how do I say...well-defined industry. [23:56.090 --> 23:56.590] Mm-hmm. [23:56.680 --> 23:57.900] It's a very large industry. [23:58.050 --> 23:59.220] It's a very well-defined industry. [23:59.360 --> 24:01.040] And basically, everything is for sale. [24:01.260 --> 24:07.220] For any bit rate, any signaling system, you can get the corresponding interception gear and storage gear. [24:10.960 --> 24:11.400] Okay. [24:11.780 --> 24:18.820] So, what we set out to do is to build strong and easy-to-use voice encryption and put it in the hands of everybody that wants and needs it. [24:18.820 --> 24:34.240] Because the other thing is, even though all this other equipment that you can buy is, as far as we're concerned, at least suspect, and some of it is just very obviously broken, they still pretend that you have to be a government customer to be able to buy this stuff, [24:34.260 --> 24:36.340] and it's hot, and we just don't sell to everybody. [24:38.340 --> 24:44.980] And we eventually would like to see end-to-end encryption, end-to-end strong and verifiable encryption in the hands of everybody. [24:44.980 --> 24:52.180] We'd like to license or somehow make sure that this technology ends up in every cell phone and every phone around the world. [24:54.600 --> 24:55.600] It took a while. [24:55.780 --> 24:58.320] We were working on our product since 2001. [24:59.800 --> 25:05.000] We started a new company called GSMK CryptoPhone, incorporated in Berlin, Germany. [25:05.460 --> 25:07.660] And we're selling the crypto phone since November. [25:09.060 --> 25:13.000] And we're very, very glad that it's not just spooks and creeps that buy it. [25:13.000 --> 25:26.240] We were sort of afraid that we would only be selling to the government of country X, and the special forces of country Y, and oh yeah, the gentleman that brought the suitcase of money. [25:27.980 --> 25:34.900] And we're very glad to see that we actually are seeing interest from NGOs that do good things. [25:34.900 --> 25:55.820] We're seeing interest from random companies that have an obvious interest in protecting their information, research departments, pharmaceutical firms, just companies that have information to protect, and that are beginning to realize that they're spending a lot of money protecting their infrastructure in any other way, [25:55.820 --> 25:59.260] but that the most sensitive information is actually passed by phone. [25:59.680 --> 26:14.880] There's companies that spend millions on protecting their computer networks, and they realize that the real stuff, when they come out of the meeting, and they got the deal, or they didn't get the deal, they just run to the car, grab their phones, and start calling people. [26:19.080 --> 26:20.600] We got a tri-band phone. [26:20.820 --> 26:22.000] It's called the CryptoPhone 200. [26:22.000 --> 26:23.780] I'll be showing some pictures later on. [26:24.120 --> 26:25.620] There's a Thuraya version. [26:25.940 --> 26:32.500] Thuraya is a satellite phone system that is not really here, but it's in most of Europe and the Indian Ocean region and Africa. [26:34.480 --> 26:39.220] There's Landline, ISDX, ISDN, PABX versions, all coming up soon. [26:40.060 --> 26:41.160] And we're doing well. [26:41.300 --> 26:45.380] We're cash flow positive, and we're 100% owned by the employees, so we're still independent. [26:47.920 --> 26:48.740] This is it. [26:48.900 --> 26:57.500] As you can see, that's the phone we sell, and this is the free Windows 32 client we're giving out, that you can use any modem with, to talk to that. [26:58.860 --> 27:01.680] As you can see, the user interface on both is sort of similar. [27:02.560 --> 27:04.260] In fact, it's exactly the same. [27:10.150 --> 27:10.590] Sorry? [27:11.230 --> 27:13.010] Hopefully the phone doesn't crash. [27:13.750 --> 27:14.550] It doesn't. [27:17.370 --> 27:18.590] Windows being Windows. [27:19.910 --> 27:21.030] Windows being Windows. [27:24.850 --> 27:26.370] So what did we set out to do? [27:26.750 --> 27:30.770] We wanted to create maximum security without sacrificing any usability. [27:31.050 --> 27:32.750] It had to be very, very easy to use. [27:33.610 --> 27:36.270] So we didn't want to stick in any configuration dialogues. [27:36.550 --> 27:40.130] We worked very hard to make the product non-geeky. [27:41.490 --> 27:46.150] We wanted to make it not or not much more complicated than a GSM phone. [27:46.390 --> 27:51.610] It should also work on most, if not all, GSM networks, so it had to be low bandwidth. [27:52.630 --> 27:54.610] I'll be talking about that later on. [27:56.070 --> 27:58.990] And it had to work on the current generation of PDA phones. [28:01.030 --> 28:05.050] We also wanted to make sure that the technology we used or the protocols we used was unencumbered. [28:05.770 --> 28:06.730] This is our product. [28:06.890 --> 28:07.310] We sell it. [28:07.370 --> 28:08.130] We wrote the code. [28:08.550 --> 28:12.430] However, we wanted to make sure that people could build phones that would interoperate with it. [28:12.430 --> 28:16.010] We don't want to lock people into just buying phones from us. [28:16.210 --> 28:19.170] We wanted to create something that everybody could interoperate with. [28:19.550 --> 28:26.110] Meaning we couldn't use anything that was patented or closed-source or somehow in another way encumbered. [28:28.670 --> 28:31.990] We wanted to be able to publish the source so people could read it. [28:32.210 --> 28:33.210] I'll be getting back to that. [28:35.830 --> 28:38.270] Okay, so we looked at a lot of existing solutions. [28:39.030 --> 28:42.370] Of course, we knew a lot of these things already and we wanted to see what we could learn. [28:42.570 --> 28:46.570] And we wanted to see why what we were going to do wasn't there yet. [28:47.350 --> 28:56.510] Speak freely and Nautilus and PGP Phone are sort of semi-discontinued projects on the Internet to create phones that either do IP or use modems. [28:56.870 --> 29:01.350] So they either use the Internet to communicate or they talked over basically landlines. [29:03.410 --> 29:04.350] Some are discontinued. [29:06.270 --> 29:10.790] Some are too hard to use or they don't work over GSMs. [29:11.410 --> 29:12.990] Many things might be wrong with them. [29:13.950 --> 29:21.050] Of course, you could run H323, which is the sort of voice over IP standard protocol and use it over IPsec. [29:21.310 --> 29:27.250] We found it to be way too high latency, way too complicated to be running over GSM. [29:28.890 --> 29:33.650] There's Skype, which is done by the people that created peer-to-peer networks. [29:35.870 --> 29:42.950] But we didn't find them to think long and hard enough about the crypto and also it didn't work on phone lines. [29:44.250 --> 29:49.470] Then there's a range of companies creating commercial phones, both landline and GSM phones. [29:49.910 --> 29:52.630] But the problems that I just mentioned apply. [29:53.150 --> 29:59.050] There's no source code available to them, so we can't say that they're really doing what they're supposed to be doing. [30:01.850 --> 30:05.850] Otherwise, acceptable solutions lack portability and the ability to work over GSM. [30:05.970 --> 30:13.870] And no solution has the interoperability where you can talk using a computer and some piece of software and use a nice GSM phone. [30:16.290 --> 30:19.590] Then came the worry of wondering what platform we were going to use. [30:19.590 --> 30:25.550] Now, the first telephone that was remotely powerful enough to do this was the Nokia 9210, the flip-open communicator. [30:27.490 --> 30:34.470] We spent the good part of a year trying to work on it, only to find that there was almost no developer information. [30:34.470 --> 30:37.330] We're not, at present, a mass-market product. [30:37.630 --> 30:39.590] We don't have a million customers. [30:40.310 --> 30:44.830] We're not real networks doing a real player on your device. [30:44.830 --> 30:50.170] So we had to convince people to give us developer support, and developer support, we found, was severely lacking. [30:50.650 --> 30:54.570] We also found that Nokia was, at that time, very internally confused. [30:54.590 --> 30:56.370] They didn't even know that they knew stuff. [30:59.510 --> 31:04.250] And then we looked at Windows CE slash Pocket PC, and we found it to be surprisingly open. [31:05.130 --> 31:11.430] Contrary to the desktop windows, most of the OS source code is actually open and downloadable today. [31:12.690 --> 31:16.810] There's lots of devices, and there's very high-power PDA phones. [31:17.250 --> 31:22.670] The phone that we're currently running on is a 400 megahertz phone, a 400 megahertz X scale. [31:22.970 --> 31:24.590] So the power is available. [31:25.070 --> 31:31.370] And, crazy enough, Windows CE is the most open, available OS that you can buy on the market. [31:32.990 --> 31:36.790] We opted for the HTC Himalaya, which is the phone that was in the picture. [31:36.950 --> 31:38.030] It's the phone that I have here. [31:38.370 --> 31:39.590] Where's the phone that's in this? [31:40.610 --> 31:41.650] No, that's not it. [31:44.660 --> 31:45.500] It's this phone. [31:45.580 --> 31:46.540] This is the crypto phone. [31:48.060 --> 31:49.660] It's an HTC Himalaya. [31:49.820 --> 31:51.580] O2 sells it as the XDA2. [31:51.720 --> 31:54.280] O2 is the European phone company. [31:55.780 --> 31:58.960] And it's also sold as the MDA2 by T-Mobile. [32:01.320 --> 32:04.440] Of course, the crypto phone is an ideal application for a PDA phone. [32:04.620 --> 32:07.040] And this is a tri-band phone, so it should work everywhere. [32:10.320 --> 32:13.160] Pocket PC or WinCE scared us. [32:13.480 --> 32:17.820] And I think most operating systems should scare anyone that builds a secure phone. [32:18.860 --> 32:22.240] Because they have lots of things in there. [32:24.500 --> 32:27.820] They may have instant messaging enabled. [32:28.080 --> 32:30.100] They may have all sorts of clients open. [32:31.340 --> 32:36.320] There's all sorts of stuff happening on that phone that you really don't want to be happening on a secure telephone. [32:36.860 --> 32:40.380] So we created what we call the Security Profile Manager. [32:41.860 --> 32:45.000] To basically set what security mode you wanted to operate in. [32:45.160 --> 32:51.080] And based on that security mode, we ruthlessly disable all sorts of things that they normally turn on in this phone. [32:51.080 --> 32:53.740] We basically kill Internet Explorer. [32:53.960 --> 32:57.540] We kill all sorts of other things on this phone until it becomes something we trust. [32:57.660 --> 33:05.520] Remember, this is a much more compact operating system than, say, desktop Windows or any other desktop operating system. [33:05.600 --> 33:09.800] So you can actually have some level of trust in what's going on there. [33:09.940 --> 33:12.440] There is a limited number of ways in which it can be broken. [33:14.760 --> 33:17.200] Then we put our own key in the upgrade mechanism. [33:17.840 --> 33:22.240] So nobody but us will be supplying upgrades for that phone afterwards. [33:23.200 --> 33:25.940] And we protect against users installing binaries. [33:26.120 --> 33:28.540] We turn on the built-in protection mechanism. [33:28.840 --> 33:30.440] Of course, users can turn it off. [33:30.560 --> 33:31.660] We supply them with the password. [33:31.900 --> 33:33.020] Go ahead, you have a question. [33:33.020 --> 33:37.140] Is this just a two-way thing or can you encrypt conference calls with this technology? [33:37.660 --> 33:39.060] It's currently a two-way thing. [33:39.200 --> 33:40.580] We do not have conference bridges. [33:41.400 --> 33:46.900] And conference calls between units without a conference bridge is actually... [33:48.280 --> 33:54.560] It's difficult by the way the network works because you don't have the bandwidth to get the data from everyone to everyone. [33:56.520 --> 34:00.360] So there's a problem with that in the way it works. [34:00.520 --> 34:00.780] Thanks. [34:02.640 --> 34:03.180] Yeah. [34:03.600 --> 34:05.160] Can you walk up to the microphone? [34:05.280 --> 34:07.500] Because it's really hard for others to understand what you're saying. [34:16.680 --> 34:17.220] Thanks. [34:19.760 --> 34:24.560] Yeah, why you guys chose the protocol H323? [34:24.920 --> 34:25.880] Why we didn't? [34:25.880 --> 34:26.560] Yeah. [34:27.640 --> 34:28.700] Instead, C protocol. [34:29.700 --> 34:30.240] Sorry? [34:30.620 --> 34:34.360] Why you guys chose to use H323? [34:34.580 --> 34:35.200] No, we do not. [34:35.340 --> 34:36.100] We do not. [34:36.260 --> 34:37.400] We use our own protocol. [34:38.180 --> 34:46.660] We use our own protocol for the reason that the GSM channel is very weird and it's very narrow band. [34:47.060 --> 34:50.800] So we didn't want to waste any bits on protocol overhead. [34:51.320 --> 34:54.400] Because basically all the bits you waste end up in latency. [34:59.130 --> 35:01.130] Which is a nice lead-in to this slide. [35:02.850 --> 35:04.810] We use circuit-switched data. [35:05.450 --> 35:07.590] GSM has basically a couple of data modes. [35:07.750 --> 35:11.550] There's circuit-switched data, which is the old GSM data call. [35:11.710 --> 35:12.910] It's 9600 data. [35:14.130 --> 35:17.810] Then there's HSCSD, which I think was never introduced in America. [35:18.650 --> 35:26.770] It's high-speed circuit-switched data where you can use 19.2 and I think even higher, like 3800 or 38,000. [35:27.510 --> 35:29.510] But it was never big in America. [35:29.510 --> 35:30.450] It was big in Germany. [35:30.450 --> 35:32.570] I think it's the only country that it ever took off in. [35:33.850 --> 35:37.590] And then there's GPRS, the packet-switched mode for transferring data. [35:38.710 --> 35:41.890] The problem with HSCSD is that it's not available everywhere. [35:42.150 --> 35:46.530] The problem with GPRS is that the latency is high and it's unpredictable. [35:46.890 --> 35:54.190] We measured latency up into the three-second range for GPRS, which is way unacceptable for voice calls. [35:54.350 --> 35:55.870] And it's also very unpredictable. [35:55.870 --> 35:57.550] There's a large amount of jitter. [35:58.090 --> 36:01.990] One moment it's one and a half seconds, the next moment it's three seconds. [36:04.290 --> 36:06.150] CSD is available pretty much everywhere. [36:06.450 --> 36:08.690] Although you may need subscription SIMs for it. [36:09.270 --> 36:12.930] We tried to do CSD on every prepaid SIM we could buy here. [36:13.170 --> 36:14.530] Because we don't have subscriptions. [36:14.910 --> 36:16.370] And we couldn't get it to work. [36:20.490 --> 36:22.270] Anyway, is there any... [36:23.850 --> 36:29.670] Even CSD, even though it's much less latent and the latency is much more predictable, even CSD introduces latency. [36:31.450 --> 36:36.770] These providers, when they designed the network, wanted to make sure that they were the ones offering voice services. [36:36.950 --> 36:42.470] So they designed their data services to be intentionally crappy enough where people wouldn't want to use them for voice. [36:43.610 --> 36:44.950] Which, of course, is our problem. [36:49.320 --> 36:53.400] There's a number of ways you can get around dealing with those properties of CSD. [36:53.400 --> 36:54.540] And one is not to use it. [36:54.740 --> 36:57.840] You could use the voice channel to transfer your bits. [36:58.200 --> 37:07.400] But then, of course, whatever you try to transfer is going through the GSM codec and then coming back out of the GSM codec on the other end. [37:07.440 --> 37:13.180] So you have to make a signal that survives being voice codec and un-voice codec. [37:15.080 --> 37:29.260] Even though the GSM codec uses the raw GSM frames, so it gets about 14k bits per second, the amount of bits you could reliably get through that connection if you wanted to use it for data is about 1.8 kilobits. [37:29.800 --> 37:33.540] Which is way too little for the type of codec that we use. [37:36.800 --> 37:39.760] Codecs at 1,200 BPS either sound like... [37:39.760 --> 37:40.520] They sound like... [37:40.520 --> 37:42.660] They sound a bit like this. [37:43.880 --> 37:44.280] Or... [37:47.060 --> 37:48.640] Or if that... [37:49.460 --> 37:54.140] If they don't sound like that, they take way, way, way too much processing power, which we don't have on those devices. [37:56.240 --> 38:03.560] We have been thinking about it as a fallback mode for those that don't have the data call, that are in countries where there's no data call or... [38:04.080 --> 38:06.100] But we haven't done that so yet. [38:07.280 --> 38:19.140] You could make a very sophisticated predictive system and try to use all that 9600 bits per second that you have, and sort of figure out when you have it, when you don't have it, and adjust your codec rate appropriately. [38:19.140 --> 38:34.780] Or you can just use a codec that has few enough bits where you have some headroom, where you can actually make up for the moments where you don't have the 9600, where there's a few lost packets, you drive under a bridge, there's a few lost packets, and you have some headroom, [38:34.980 --> 38:37.880] and make up for those moments. [38:40.640 --> 38:43.240] We use a speech compression algorithm called KELP. [38:44.200 --> 38:46.720] Somewhat older, it's developed as a military standard. [38:48.340 --> 38:52.640] And we got it to run on a 200 megahertz strong arm, which was the previous model of CryptoPhone. [38:52.720 --> 38:57.520] We're now on a 400 megahertz X scale, so the problem isn't as stringent anymore as it was. [38:59.800 --> 39:02.640] Decent speech quality, 400 bits per second. [39:03.020 --> 39:05.920] And there's a number of newer codecs, which... [39:07.200 --> 39:09.980] There's speaks, there's MELP, GSM-AMR. [39:10.120 --> 39:11.280] We're looking into some of those. [39:11.980 --> 39:16.200] Other ones have... take too much processing power, or they're heavily encumbered. [39:17.700 --> 39:18.500] Patents, copyrights... [39:19.260 --> 39:21.600] We want to be able to publish the source code to what we do. [39:21.700 --> 39:25.260] There's plenty of codecs that we could buy that come with a binary license. [39:25.940 --> 39:29.800] We don't want stuff in our executable that we only have the binary to. [39:29.900 --> 39:33.400] We want to be able to publish the source of everything that we do. [39:37.590 --> 39:40.200] Okay, let's talk a little bit about the crypto that we do. [39:41.020 --> 39:44.360] As you can see, I can't really point in it now because... [39:44.360 --> 39:45.260] Where can I? [39:45.420 --> 39:46.000] There we are. [39:46.700 --> 39:59.590] As you can see, we do a Diffie-Hellman key exchange, out of which we get 4,096 bits, which we then put through SHA-256 to basically extract the entropy and put that in a 256-bit word. [40:00.630 --> 40:07.940] And then using some additions of a byte and new SHAs, we get three keys which are mathematically unrelated. [40:08.300 --> 40:19.340] They're based on the same 256 bits, but if you have one, you can't make your way back up to another unless SHA-256 is fundamentally very, very broken, in which case lots of people have lots of problems. [40:20.760 --> 40:30.900] Then we use both AES-256 and 2FISH to encode the speech that is being thrown into this XOR here. [40:31.110 --> 40:34.480] So we basically encrypt a counter to create a key stream. [40:34.680 --> 40:42.540] And these two key streams are first XORed, and then they're XORed with the voice and the user data message, which are basically the call control messages. [40:42.880 --> 40:45.070] Hang up, dial, all that stuff. [40:47.500 --> 40:52.550] We use a modified Diffie-Hellman exchange without going into any of the technical details. [40:52.550 --> 40:54.920] It makes sure that neither Alice or Bob can cheat. [40:55.360 --> 40:56.400] I'll get to that. [40:57.570 --> 41:07.650] What we do is we display during the call setup, after the call setup has completed, we display these letters here, these two groups of three letters. [41:08.090 --> 41:09.780] You say and partner says. [41:10.300 --> 41:14.960] What that does is it eliminates the man in the middle without the need for a public key infrastructure. [41:15.590 --> 41:25.480] If I call somebody and I know the voice of that person, I know who I'm talking to, and if I don't know who I'm talking to, I may have other problems keeping secrets. [41:26.280 --> 41:40.240] If I know who I'm talking to, I know the voice of that person, then if we can exchange these letters, if I can say XZW and the other person says DKI, the two of us know that we're looking at the same hash. [41:40.360 --> 41:42.630] And because we're looking at the same hash, we have the same key. [41:43.110 --> 41:55.200] And a man in the middle, although the man in the middle could have two phones, and can put them back to back and just loop the audio through, the man in the middle could never make sure that two of the keys that are negotiated are the same. [41:55.460 --> 41:58.130] And hence, the hash displayed isn't the same. [41:59.070 --> 42:00.680] There's a lot of math behind it. [42:00.820 --> 42:02.200] There's a lot of reading you could do. [42:02.300 --> 42:03.590] There's some reading on our website. [42:03.590 --> 42:11.020] We have a large frequently asked questions that details this in much better, much higher level of detail than I can do right now. [42:11.440 --> 42:22.200] What it basically means is, two people can have a secure communication without a central authority saying who is who or sort of authorizing keys or signing stuff. [42:25.020 --> 42:26.820] We don't have device authentication. [42:26.820 --> 42:28.460] We don't have a web of trust. [42:29.050 --> 42:36.840] No centralized key management, which has its advantages, but we're looking at implementing something like that anyway. [42:37.320 --> 42:38.680] So people can have both. [42:38.820 --> 42:55.610] They can have both this type of authentication, or they could have, for instance, role-based authentication, which is where I don't necessarily know who I'm talking to as a person, but I know that I'm talking to whoever is authorized to look into X for organization Y. [42:56.880 --> 43:04.720] But we're looking into a nice, decentral way of doing that where also organizations that don't have formal structures could still use that. [43:08.500 --> 43:10.130] Then there's the symmetric crypto. [43:11.520 --> 43:13.440] As I've shown, we use two ciphers. [43:13.550 --> 43:15.800] We use AES-256 and we use 2FISH. [43:16.070 --> 43:20.880] Those are both very strong or considered to be very strong crypto algorithms. [43:20.880 --> 43:28.360] And we use both of them because we feel AES-256, the encryption standard currently, is still too young. [43:28.550 --> 43:32.110] There may be some weird security problem discovered in it. [43:32.440 --> 43:37.050] And we don't feel confident in depending on only one. [43:37.240 --> 43:38.650] Even though we've gotten criticism. [43:38.840 --> 43:40.360] It's like, oh, you're being overly paranoid. [43:40.360 --> 43:41.220] This is crazy. [43:42.440 --> 43:45.160] We don't claim it's 512-bit crypto. [43:45.160 --> 43:48.340] We don't feel that it's going to make our device twice as secure. [43:48.540 --> 43:50.640] We just feel it was the conservative choice. [43:51.980 --> 43:59.840] We didn't use triple this because we felt we needed the newer, higher speed algorithms. [44:00.500 --> 44:01.400] You have a question. [44:01.400 --> 44:05.280] You said you're going to be, you have plans for implementing a PKI into it. [44:05.440 --> 44:07.980] Is that going to probably use an open PGP key? [44:10.060 --> 44:15.680] We're thinking of using our own homegrown system for doing that. [44:15.880 --> 44:32.200] We're thinking of creating a system where those keys can be exchanged very easily during call and where people can sign keys more readily and where it's more obvious to Joe random user what's going on. [44:32.580 --> 44:39.160] We feel the way PGP keys are currently being treated is not very obvious to Joe random user what's happening. [44:44.080 --> 44:50.400] Let me sort of quickly zap through slides here because I want to get into sort of a conversation and talk about this stuff a little bit. [44:52.500 --> 44:53.840] There's the issue of key handling. [44:54.040 --> 44:59.260] Our phone, if you have our phone in your hands and you hang up, everything about that call is destroyed. [44:59.460 --> 45:02.960] There's nothing you can divulge except those six letters if you happen to remember them. [45:03.240 --> 45:11.340] Those six letters are only a tiny representation of a key, of a derivate of a session key that you don't know. [45:11.760 --> 45:14.640] So there's nothing about that call that you can reveal afterwards. [45:14.840 --> 45:16.900] The phone doesn't remember anything about the call. [45:17.540 --> 45:20.280] And we wanted to make very sure that we delete the key. [45:21.080 --> 45:25.760] Now, deleting something from memory or disk or anywhere is a very hard thing. [45:26.600 --> 45:31.100] But we do a best effort of making sure that the key is as gone as we can make it gone. [45:36.470 --> 45:40.310] Of course, if they have physical access to your phone, you're screwed. [45:42.010 --> 45:45.290] There's nothing in software that can protect you from physical access. [45:46.050 --> 45:50.770] There's nothing you can do as a software maker that would protect the user. [45:51.530 --> 45:57.550] If nothing else, an adversary can just replace the battery with a battery that has a transmitter in it. [45:58.290 --> 45:59.910] They could place a room bug. [46:00.410 --> 46:06.110] They could do all sorts of things to get to your call content once they have access to your phone. [46:06.310 --> 46:08.330] Or to the place where you normally use it. [46:11.150 --> 46:13.330] So, take your phone wherever you go. [46:14.330 --> 46:16.890] It's one of the number one items in our manual. [46:17.330 --> 46:20.690] This device is only as secure as the way you keep it. [46:23.330 --> 46:27.910] These are just two slides I left in here to quickly go over what we do on the line. [46:28.150 --> 46:31.690] It's not something I want to get into now in too much level of detail. [46:31.710 --> 46:44.970] But what we basically do is we have an outer layer and an inner layer protocol where we transfer the counter value, basically the place where you are in the crypto protocol so you know what the key for that piece is. [46:46.690 --> 46:49.210] It's way too detailed for now, I guess. [46:50.170 --> 46:58.010] And there's codec packets and what we call user data packets which basically say what codec is being used or that we're now switching codec. [47:03.420 --> 47:08.820] The CryptoPhone code, the program we wrote, is now available for Pocket PC and for Win32. [47:09.160 --> 47:11.800] They're both compiled from the same code base. [47:14.880 --> 47:16.040] This is some details. [47:16.040 --> 47:21.580] It's written using MFC, Microsoft and Visual, Microsoft VC. [47:21.940 --> 47:24.720] We use GNU compiler for some parts, GCC. [47:26.840 --> 47:27.760] The back end. [47:30.960 --> 47:34.120] Yeah, we have Symbian and Linux versions planned of the CryptoPhone. [47:34.860 --> 47:36.160] And the protocol is open. [47:36.420 --> 47:37.580] We publish what we do. [47:37.760 --> 47:40.060] Others can write phones that talk to our phone. [47:41.700 --> 47:42.920] There's two processes. [47:43.800 --> 47:47.000] This is... I guess this is not readable for any of you, is it? [47:47.420 --> 47:47.720] No. [47:49.800 --> 47:53.360] There's basically a back end process which runs with real-time priority. [47:53.840 --> 47:55.300] It handles all the calls. [47:55.460 --> 47:56.140] It handles the audio. [47:56.320 --> 47:57.360] It talks to the speaker. [47:57.500 --> 47:58.430] It talks to the line. [47:59.120 --> 48:01.360] It does the symmetric encryption. [48:06.950 --> 48:08.510] And it also does the filtering. [48:08.510 --> 48:10.810] It does all the codec stuff. [48:11.570 --> 48:13.550] And it takes all the CPU cycles. [48:13.670 --> 48:15.190] It's the process that does everything. [48:15.810 --> 48:18.250] And then there's the UI which does the key exchange. [48:18.250 --> 48:19.290] It talks to the user. [48:19.410 --> 48:20.550] It brings up that nice window. [48:22.650 --> 48:24.690] And it also does the random number generator. [48:25.810 --> 48:27.890] For this protocol, we need random numbers. [48:28.510 --> 48:32.270] And we use Fortuna, which is the latest and greatest random number generator. [48:33.150 --> 48:40.030] And we initialize it with a hash of some audio that we sample from the microphone that's in the device before the call starts. [48:40.030 --> 48:44.210] So we make very sure that what we start from is actually strong random. [48:47.450 --> 48:50.210] Some quick going over the future roadmap. [48:50.430 --> 48:52.510] Of course, there's going to be ISDN and PABX. [48:52.610 --> 48:53.830] I already talked about that. [48:54.510 --> 48:56.290] We want to port to different platforms. [48:56.290 --> 48:58.130] We focus on mobile platforms. [48:58.350 --> 49:03.510] So Linux organizers, as soon as something hits the market that's big enough that we want to port to it. [49:03.530 --> 49:06.170] Of course, we're going to be putting out a Linux version. [49:06.950 --> 49:08.610] Symbian is something that's on the roadmap. [49:09.930 --> 49:17.810] We want to do something with voice over IP, especially if mobile IP, UMTS, low latency mobile IP, starts hitting the marketplace. [49:17.810 --> 49:19.290] We want to make sure that we're there. [49:20.630 --> 49:25.590] And business cards is sort of the name we gave to the concept of our own PKI. [49:25.990 --> 49:33.870] Or you can have business cards as a metaphor for people to use the phone in that way. [49:37.530 --> 49:40.210] How do you assess how secure the crypto phone is? [49:40.930 --> 49:44.790] We basically discern four types of threats against the crypto phone. [49:45.070 --> 49:51.430] The threat that we take most seriously is you store the contents of a encrypted call. [49:51.810 --> 49:53.670] You passively just listen to it. [49:53.750 --> 49:55.870] You store the contents and then you later attack it. [49:56.290 --> 49:58.010] That's the thing we're most worried about. [49:58.170 --> 50:02.350] That's the thing we stick most of our time in is making sure that will hopefully never happen. [50:04.150 --> 50:06.350] There's active attacks during a call. [50:07.090 --> 50:22.610] Somebody playing the role of Alice or Bob towards one of the participants or maybe calling one of the participants out of the blue pretending to be Alice and trying to get information from our software or from the user that would compromise call content. [50:24.130 --> 50:36.430] There's remote attacks against the rest of the OS, which worries us, which is why we wrote that security manager, which is why we kick off a lot of the PDA functionality when we turn it into a crypto phone. [50:37.830 --> 50:50.290] And there's looking for radio emissions from the device, trying to figure out whether the device transmits its key or something else that is useful to us in radio. [50:51.530 --> 51:01.490] And security evaluation needs to look at the whole system, the whole picture, and try to figure out how does an adversary, what is the lowest hanging fruit for an adversary to get to the content of that call. [51:05.970 --> 51:10.410] Crypto phone does not protect against room bugging, which is obvious, but you have to state it. [51:11.110 --> 51:16.270] It does not protect against an adversary to hazard access to the device, even if it was just for a moment. [51:17.630 --> 51:23.590] And it also does not protect against rafters, in other words, the compromising emissions, radio attacks. [51:23.990 --> 51:27.350] It is not a military-grade crypto device. [51:27.350 --> 51:29.550] It is not a $10,000 machine. [51:29.990 --> 51:32.630] However, those attacks, they're very real. [51:33.310 --> 51:39.830] You could face them, but then if you face them, you probably, much earlier, would face room bugging. [51:39.830 --> 51:44.430] You would face all sorts of other things, and these attacks do not scale. [51:44.590 --> 51:47.510] They cannot be used to listen to the entire population. [51:48.090 --> 51:52.410] We try to make the best we can do on commercially available hardware. [51:52.890 --> 51:53.970] That is the project. [51:54.090 --> 52:02.710] The project is we want to create something that works on phones, that are available in the open market, and create security on it. [52:05.090 --> 52:08.750] But if you're Osama Bin Laden, you probably don't want to use one of these. [52:08.910 --> 52:14.130] You probably want to just meet somewhere in the bushes and talk really softly. [52:19.100 --> 52:22.260] We publish the source code, and everybody thinks it's really, really cool. [52:23.080 --> 52:25.520] Everybody says it's necessary, and we're doing the right thing. [52:25.640 --> 52:26.920] Yeah, you publish the source code. [52:27.040 --> 52:27.900] Yeah, it's really important. [52:28.520 --> 52:31.980] Everybody... I can get like a hundred people applauding me for publishing the source code. [52:31.980 --> 52:33.920] Nobody ever looks at it. [52:34.240 --> 52:34.680] Just us. [52:36.280 --> 52:37.220] That is bad. [52:39.580 --> 52:44.280] We need lots of people to take a look, see if they can find something in there. [52:44.760 --> 52:46.420] Just comment to us on it. [52:46.520 --> 52:52.200] Say, hey, I looked at it, I couldn't find an obvious hole, but why did you guys do this? [52:52.200 --> 52:54.040] Or why does that happen? [52:54.220 --> 52:55.200] Or why did you not? [52:55.700 --> 52:59.820] We need people to take an interest in what we've done, and we need it to keep us honest. [52:59.820 --> 53:03.480] Keep us sharp, and it's also our life insurance policy. [53:03.640 --> 53:14.660] We don't want to have sold thousands and thousands of secure telephones to God knows who, and be the only ones that know insecurities or have potential knowledge of insecurities. [53:14.800 --> 53:21.380] We want lots of people to be looking at it, to find holes in it, tell us about it so we can update it, make fixes. [53:22.280 --> 53:28.280] It's very unlikely that we've done a perfect job right on, that we've done a perfect job hole-in-one. [53:28.520 --> 53:33.200] The first time we wrote a secure telephone on a project this size, we did perfect. [53:34.560 --> 53:39.600] It's probably better than most things, at least we've looked at, but we need help. [53:39.700 --> 53:42.580] We need your help, we need help of everybody that can look at source code. [53:42.880 --> 53:44.940] Go over it, even if it's just a tiny piece. [53:45.100 --> 53:52.820] If you can evaluate whether the random generator looks good to you, please do, please publish on it. [53:54.480 --> 53:56.900] Tell us what you find, tell the world what you find. [53:57.180 --> 54:01.880] Give us a little time if you find something, something bad. [54:03.300 --> 54:05.260] It's about 50k lines of code. [54:09.080 --> 54:11.140] There's a breakdown of what those lines are. [54:12.000 --> 54:14.720] And a lot of those lines are very easy to vet. [54:15.320 --> 54:22.040] If you take the codec, the codec deals with the speech when it's already decrypted. [54:22.040 --> 54:28.120] So if you look at that code from the standpoint of, does this touch anything but an encrypted voice? [54:28.700 --> 54:31.260] Does it write to any of the memory where the key is stored? [54:31.360 --> 54:32.920] Or read for memory where the key is stored? [54:33.060 --> 54:34.120] Does it do anything suspect? [54:34.960 --> 54:43.860] If the codec is a black box that just deals with the speech when it's already decrypted, or when it's still decrypted, there is no problem. [54:45.440 --> 54:49.500] So please help us take a look, look at some tiny piece of what we did. [54:51.880 --> 54:54.940] There's the web address to download the source code. [54:55.780 --> 54:58.040] As it says there, we're committed to rapidly fixing. [54:58.200 --> 55:02.980] If stuff is found, we really will try within days to fix what's found. [55:04.460 --> 55:06.100] Of course, give us a little bit of time. [55:06.260 --> 55:12.180] Give us a week or two weeks to tell customers to make sure that we have our fix out there, that it's tested. [55:12.180 --> 55:14.920] But please go after us, hurt us. [55:16.900 --> 55:21.280] If you find a severe security problem, you get a CryptoPhone. [55:21.740 --> 55:26.800] And severe meaning it would potentially lead to call content leaking out. [55:27.300 --> 55:27.940] Go ahead. [55:28.300 --> 55:30.560] I probably missed a little bit of the last question. [55:30.700 --> 55:32.220] And this probably relates a little bit. [55:32.220 --> 55:37.780] But I'm from the school of thought that says you can't build a secure system from insecure subsystems. [55:38.560 --> 55:54.820] So why didn't you take the attack vector of maybe producing a very minimal sort of security kernel type OS that sat underneath your application and really restricted what all the phone could do if you're going for a really, really secure environment? [55:56.280 --> 55:57.280] That's the approach. [55:58.300 --> 55:59.260] We've looked at that. [55:59.420 --> 56:01.680] We've looked at platforms that we could do that on. [56:01.900 --> 56:07.260] The thing is, the GSM engine for one wouldn't be a secure subsystem to begin with. [56:08.060 --> 56:10.080] We weren't about to write a GSM engine. [56:10.200 --> 56:15.320] We do what we think is a very decent best effort on a general purpose OS. [56:15.500 --> 56:17.580] And we try to strip it as much as we can. [56:18.200 --> 56:20.280] And we want to be available for more platforms. [56:20.280 --> 56:24.140] We also want people to have something in their pocket that they can actually use. [56:24.220 --> 56:25.220] That's still a phone. [56:25.400 --> 56:26.660] That still has an address book. [56:27.760 --> 56:32.120] That you can't give people something that they can't use. [56:32.200 --> 56:35.180] That has a dismal user interface. [56:35.380 --> 56:36.840] That doesn't have anything graphic. [56:37.160 --> 56:39.700] And you can't expect your random user to use it. [56:39.960 --> 56:42.400] So it's always going to be a compromise, we felt. [56:43.420 --> 56:44.600] But you have a good point. [56:44.700 --> 56:45.600] You have a very good point. [56:45.860 --> 56:51.240] And my second question is, what kind of metric would you use to sort of measure your... [56:53.020 --> 56:54.400] I always forget the word. [56:55.180 --> 56:57.080] How much faith do you have in the security? [56:57.260 --> 57:00.620] What is your metric for that? [57:00.840 --> 57:02.940] I mean, how do you measure that? [57:03.160 --> 57:04.480] How much faith do we have in what? [57:04.480 --> 57:06.320] How much faith do you have in the security? [57:06.660 --> 57:07.980] Do you have a metric for that? [57:08.120 --> 57:10.160] How you measure your security for the system? [57:12.360 --> 57:13.020] Not really. [57:13.180 --> 57:15.240] We feel we're the best CryptoPhone out there. [57:15.380 --> 57:18.900] We're the most trustworthy CryptoPhone because people can actually look at what happens inside. [57:19.220 --> 57:26.940] And we spent a lot of time talking to a lot of experts, a lot of people that are in this field, and we've had them look at what we did. [57:27.280 --> 57:31.140] And we try to make sure that we did the best thing we could possibly be doing. [57:31.780 --> 57:35.280] But no, we don't have a more formal way of looking at it. [57:35.500 --> 57:35.700] Okay. [57:35.940 --> 57:36.280] Thank you. [57:39.310 --> 57:41.670] I have a quick question about the Windows client. [57:41.850 --> 57:48.930] How do you get the GSM data packets from, I guess, a regular telephone modem onto the GSM data network? [57:50.210 --> 57:54.170] How do you get packets from the normal telephone network to the GSM? [57:54.570 --> 57:58.490] Calling from the GSM to the normal telephone network, it goes out over an analog modem. [57:58.590 --> 58:01.670] If you call an analog line, the provider handles that for you. [58:01.670 --> 58:17.870] Going back in, you either need a special data number, which your provider can give you, which is then a secondary phone number that, when people call it, they get a modem at the provider, which puts it into V110, which goes to your phone, or it doesn't work. [58:18.350 --> 58:18.490] Okay. [58:21.360 --> 58:21.760] Hi. [58:22.900 --> 58:32.120] So, I guess some governments might not be very pleased with the crypto phone and will push telcos maybe into preventing these types of phone calls. [58:32.320 --> 58:38.840] Is it easy for a telco to recognize a crypto phone phone call and drop the connection when they see one? [58:38.840 --> 58:40.060] Yes, they could. [58:40.400 --> 58:40.920] Yes, they could. [58:40.920 --> 58:50.780] They could either go after unit-to-unit data calls, which is basically a data call that is both mobile-originated and mobile-terminated. [58:51.000 --> 58:53.680] That is something that is basically only crypto phones. [58:54.580 --> 58:57.640] There is a couple of other brands that they would then also be blocking. [58:57.640 --> 59:07.840] But, for instance, if there was a suspect and you wanted to force them to use unencrypted communications, you could just turn off their data calls at some critical moment. [59:07.960 --> 59:08.760] Yes, that is possible. [59:12.280 --> 59:14.720] Last question, because I've been told we have to wrap it up. [59:14.900 --> 59:15.220] All right. [59:16.100 --> 59:23.440] I was wondering why you would want to use the two key generation algorithms together. [59:24.180 --> 59:28.380] I mean, it seems to me that that has the potential to actually make them less secure. [59:28.380 --> 59:30.860] No, it's not a potential attack. [59:31.760 --> 59:37.880] We use them together to safeguard against weaknesses being found mostly in AES. [59:38.080 --> 59:50.460] The time we made these decisions, AES was going through a shaky time because there was mathematical properties found in the way AES behaved and there was many more rounds of AES. [59:50.640 --> 59:52.380] Encryption algorithms work in rounds. [59:52.620 --> 59:58.080] And many more rounds of AES were considered vulnerable than was designed for. [59:58.080 --> 01:00:02.260] So we figured there might be more stuff found against AES. [01:00:02.440 --> 01:00:05.460] So we wanted to interleave two encryption algorithms. [01:00:05.580 --> 01:00:11.500] But we use separate keys that are not mathematically related and we XOR the key streams of counter mode. [01:00:11.680 --> 01:00:19.520] So we're not opening ourselves up to any vulnerabilities that might come from these two somehow interweaving. [01:00:20.920 --> 01:00:25.080] So we're actually as strong as the strongest one of the two. [01:00:25.320 --> 01:00:32.780] Well, if you're saying that one of them may be insecure, then they may be mathematically related. [01:00:32.780 --> 01:00:33.580] I mean, there's some... [01:00:33.580 --> 01:00:33.840] No, no, no, no. [01:00:33.860 --> 01:00:35.540] I'm saying we're using two... [01:00:35.540 --> 01:00:40.420] The keys that for those two encryption algorithms are both derived from that session key. [01:00:40.740 --> 01:00:47.540] And these keys are not mathematically related because we appended different bytes before shying the... [01:00:50.120 --> 01:00:54.880] So the crypto world tells us this is not in any way insecure. [01:01:00.350 --> 01:01:01.610] I guess that was it. [01:01:01.790 --> 01:01:02.530] Thank you very much. [01:01:15.700 --> 01:01:17.320] Hello, sound people. [01:01:19.520 --> 01:01:20.380] That's excellent. [01:01:20.660 --> 01:01:22.780] The mic at the podium doesn't even work. [01:01:23.400 --> 01:01:25.440] Thanks, Ron, for coming all the way from Germany. [01:01:26.300 --> 01:01:27.660] You came from Germany, yes? [01:01:28.100 --> 01:01:28.420] Holland. [01:01:28.620 --> 01:01:29.820] Holland, Germany, whatever. [01:01:30.040 --> 01:01:30.840] Listen, I'm an American. [01:01:32.100 --> 01:01:33.560] We were part of... [01:01:34.160 --> 01:01:36.560] We were actually part of Germany once, but we didn't like it. [01:01:36.560 --> 01:01:36.900] Whatever. [01:01:37.300 --> 01:01:37.660] Listen. [01:01:39.020 --> 01:01:42.620] The world began in 1776, according to the current president. [01:01:42.780 --> 01:01:43.000] All right. [01:01:44.760 --> 01:01:49.740] In this room, in about an hour, we will have a special broadcast of Off the Hook. [01:01:49.740 --> 01:01:53.180] If all the electronic hootenanny gets put together. [01:01:53.680 --> 01:01:54.500] It's...