[00:00.620 --> 00:12.660] There also were ugly, clumsy, not nice looking devices, but if it comes to security, personally, I don't think that fashion should be important in voice encryption. [00:13.900 --> 00:15.780] But it is, sir. [00:16.480 --> 00:33.060] When we talk to the people who are caring for, let's say, a head of a company who has a high privacy profile and needs to protect his phone calls, one of the things that we get to hear from them is, okay, the phone needs to be new and shiny. [00:34.580 --> 00:44.740] Because if I need to get this guy to make his phone calls, at least a few phone calls, secure, then there must be a phone that he's proud to show to his pals on the golf lane. [00:46.000 --> 00:56.760] And not some old, ugly, six-year-old thingy that he needs to hide in his pocket and only make his phone call in secret to not be exposed to the loss of his pals. [00:57.480 --> 01:04.840] So, being on recent devices was certainly one of the things that we wanted to do. [01:05.160 --> 01:05.300] Yeah. [01:06.580 --> 01:24.020] So, another problem was that most of the stuff that was on the market when we started didn't have any full system integration, meaning there was no system, except one, which is the U.S. government type one system, that could do mobile phone to landline to satellite. [01:24.660 --> 01:39.520] So, which is a requirement in a lot of regions of the world, and especially for activists and journalists and people who are out there reporting stuff, they need a full integrated solution that is not just mobile to mobile or not just landline to landline encryption. [01:39.520 --> 01:39.740] Yeah. [01:40.740 --> 01:49.020] So, the phones that were on the market when we started, in short, were not really what we needed. [01:49.960 --> 01:50.540] So... [01:53.800 --> 01:54.380] Okay. [01:54.560 --> 02:02.100] So, when Rop and myself started to look into this, which is maybe fifteen years ago, we ran into some problems. [02:03.960 --> 02:10.700] And the thing is, the biggest problem that we ran into was CPU to compress the voice. [02:10.700 --> 02:16.060] You would think that encrypting the voice is CPU intensive, but it's actually not. [02:16.200 --> 02:17.100] It's compressing the voice. [02:17.440 --> 02:22.280] And it took some while before we actually had a platform that we could do this on. [02:23.520 --> 02:28.860] So, just for short explanation, sir, how voice encryption really works today. [02:29.700 --> 02:46.020] A while ago, there were so-called scramblers, where the state-of-the-art, what was publicly available, what was basically adding some noise to the voice or chopping the voice up in little chunks and realigning these chunks so that it sounds like garble. [02:46.380 --> 02:52.620] All these methods really don't stand up against the modern processing power, so they cannot be regarded secure. [02:52.620 --> 03:08.040] So, real voice encryption works that way that you digitize the voice, compress it, and then use the compression result as the input for an encryption system, and then use a data channel to transport the digitized, encrypt, compressed voice to the other side, [03:08.120 --> 03:09.340] and there reverse the process. [03:09.600 --> 03:17.260] So, meaning, what you redo is doing data transmission with encrypted, compressed voice chunks inside. [03:17.260 --> 03:22.400] So, we need a lot of CPU, for instance, especially for the voice compression. [03:23.880 --> 03:32.720] So, when we thought about this, we knew for sure that it was not going to be an analog scrambler, because analog voice encryption cannot be secure. [03:32.960 --> 03:43.680] If you listen to analog voice encryptors, and you remain silent, you say nothing into these devices, most of the time, you will hear nothing. [03:44.280 --> 03:47.300] And when you start talking, you know, you will start hearing noise. [03:47.460 --> 03:59.940] So, if you can already detect when somebody's talking and when it's silent, you know, you can figure out that with some DSPs and with some processing power, you can always turn it back, because the human voice really can be predicted pretty well. [04:00.780 --> 04:02.620] But, you know, this slide is called Goals. [04:02.780 --> 04:15.400] So, the thing that we had in mind was to provide something trustworthy, that people can really see for themselves that at least we did as good as a job as possible in making things secure. [04:16.640 --> 04:17.880] Meaning, no back doors. [04:18.220 --> 04:19.860] We had to publish the source code. [04:19.980 --> 04:23.480] This was the first thing that, you know, we discussed. [04:23.780 --> 04:26.540] We said, whatever we do, we have to publish the source. [04:26.660 --> 04:33.080] This is, you know, the only way that you can at least get some confidence from your customers that you are doing the right thing. [04:34.460 --> 04:38.700] There are some disadvantages to publishing the source that we will get into later. [04:40.420 --> 04:45.320] Another thing that we really wanted to do is not to have PKI infrastructures. [04:46.020 --> 04:52.400] And basically, the design goal of the phone was to keep it as simple as possible for the user. [04:52.960 --> 04:56.600] No selections for encryption algorithms, you know. [04:56.600 --> 05:06.780] How does the user know if they should use IDEA or triple DES or single DES, or really, you know, you should consider the user as dumb as possible with all respect for the user. [05:07.100 --> 05:16.840] But, you know, we designed the thing, we make it as strong as possible, and no options for the user to set to screw things up and mess things up. [05:18.040 --> 05:23.280] Commercially available, meaning that everybody must be able to buy these phones. [05:23.280 --> 05:31.160] Even people I maybe don't like, you know, it should be crypto for everybody who wants it. [05:32.360 --> 05:48.180] And we also decided that since our phone is basically a piece of software, we might as well give out a free program for Windows PCs that will turn your PC or your laptop into a secure phone, and that you can actually use what we have written. [05:48.180 --> 05:49.800] And that's what we did. [05:49.960 --> 05:54.480] We wrote a small PC client that people can just run for free on their machine. [05:54.660 --> 05:55.940] It's not voice over IP. [05:56.080 --> 05:57.280] It only works with modems. [05:57.540 --> 06:03.860] So, two people, two persons got to have a modem and a PC to be able to communicate with each other. [06:03.960 --> 06:08.060] But then they can use the full unblocked version of a crypto phone. [06:08.060 --> 06:22.700] And another advantage that this has is if somebody already is a crypto phone owner, and, you know, they need to make an urgent call, and they can't wait for the other party to also buy a crypto phone, they can say, well, you know, here's a few steps. [06:22.880 --> 06:28.400] Go to that website, download the program, you know, hook the modem up to your phone line, and I will give you a call there. [06:29.260 --> 06:33.400] This was the design goal for crypto phone. [06:33.640 --> 06:46.640] So, part of the reasoning for doing the free PC client is we are basically from a community that is very close to the hacker scene, and that has always wanted to support political activists. [06:46.940 --> 06:51.120] And we realized that the mobile phones will not be cheap. [06:51.300 --> 06:58.060] So, we come into that later, but they will not be cheap enough for every human rights activist to get one. [06:58.060 --> 07:03.740] So, we wanted to have from the beginning a method for those people who really need it to get it for free. [07:04.440 --> 07:11.400] And so, that's why we decided that there will be always the free PC client, and there will always be a free PC client for future products. [07:11.540 --> 07:15.320] So, this is one of the things that the company is based on. [07:15.480 --> 07:22.080] So, giving back stuff to the community and enabling people to have secure communication without paying a lot for that. [07:24.320 --> 07:27.320] So, as you may have guessed, financially the company works. [07:27.320 --> 07:31.520] We are selling the mobile phones, and we are giving the PC client for free. [07:31.740 --> 07:34.860] So, people who have money who need mobile phones can buy the mobile phones. [07:35.260 --> 07:39.360] People who don't have money just get the free PC client that works very well. [07:44.060 --> 07:53.260] So, publishing the source code, as Barry said, was one of the key objectives to get trust into this whole business. [07:55.120 --> 07:57.720] We actually have customers who verify the source code. [07:58.060 --> 07:59.120] A lot of them do not. [07:59.780 --> 08:00.660] Some of them do. [08:01.640 --> 08:09.900] We had larger customers who hired university teams to look into the source code, especially for backdoors, look if the cryptography is really as strong as we claim. [08:10.560 --> 08:13.380] And every one of them so far has been very well satisfied. [08:14.480 --> 08:20.420] The back side is, of course, that competitors also look into our source code and sometimes outright steal source code. [08:20.520 --> 08:27.920] So, we had one case in Europe where a German company actually based their product on source code that they stole from us. [08:29.580 --> 08:33.840] So, of course, our engineers know how to look into other people's binary. [08:34.100 --> 08:41.020] Which was not difficult because even the synchronization tones, when these phones connect, they have a synchronization tone. [08:41.200 --> 08:43.320] They even stole the synchronization tone. [08:43.460 --> 08:48.720] So, there was a clue that, you know, these people might have looked into our code a little too well. [08:48.720 --> 09:01.820] But, I mean, you know, having another product and testing their beta version and hearing your synchronization tones, when they exchange a secure key, is like, did we do something wrong? [09:02.260 --> 09:03.840] So, it's amazing. [09:04.120 --> 09:08.920] This tone has the internal nickname of the sound of pinguins mating. [09:09.800 --> 09:21.220] And it basically has been originating as one of our guys singing to the microphone and then playing along with the sound programs until it achieved the result that we wanted. [09:21.300 --> 09:23.600] So, it was really our sound. [09:24.620 --> 09:45.040] And so, then we looked into their binary and found out that they hadn't even bothered to really rewrite the stuff, but copy-pasted source code from ours so that we figured how to replicate their compiler settings so that we could show that we compiling our source code with their compiler settings ended up in their binary. [09:45.040 --> 09:46.900] So, that was pretty stupid. [09:48.240 --> 10:00.860] In the end, they went bankrupt because we raided their place two days before they wanted to sign a major venture capital agreement, which didn't sit too well with the venture capitalists. [10:01.080 --> 10:03.860] And so, that was them then. [10:04.340 --> 10:11.520] So, it's kind of a Venus trap approach, but we hadn't noticed before that it works that way. [10:12.040 --> 10:26.420] So, the published source code is not GPL, it's not under any of the known licenses, but it's a special license that says, okay, you can review the source code, you can look into the source code, you can analyze it as long as you want, but you cannot do anything else with that. [10:28.180 --> 10:31.060] I mean, you cannot base your own products on them and so on and so on. [10:31.160 --> 10:44.700] So, that's basically the trade-off between the need to publish the source code and give everybody the possibility to look for backdoors, and on the other hand, protecting the business interests so that we can have a commercial viable company. [10:48.100 --> 10:55.340] So, okay, the system, what we're basically doing, we're using Windows Mobile smartphones and PDAs for the mobile side. [10:56.580 --> 11:04.940] The reason that we used Windows Mobile is that the moment that we started, they were the only phones that had sufficient CPU power, namely at least a 200 MHz ARM processor. [11:05.320 --> 11:09.200] Which is not completely true, there was also the Nokia stuff. [11:09.340 --> 11:09.720] It was slower. [11:10.360 --> 11:12.180] No, no, it was also 200 MHz. [11:12.700 --> 11:13.840] The first... [11:14.740 --> 11:21.020] But the thing was that the Symbian operating system did not support streaming audio. [11:21.840 --> 11:29.480] So, first the Nokia 9200, that was a PDA phone that would flip open with a keyboard. [11:29.880 --> 11:30.740] Really a nice phone. [11:30.940 --> 11:35.720] But we couldn't get enough support to get streaming audio, only to record and playback. [11:36.100 --> 11:39.440] And we never figured it out, how we could make streaming audio. [11:39.720 --> 11:44.260] And then, yeah, then the first phone, the XDA, came out. [11:44.440 --> 11:48.560] And that was a phone that ran Windows CE, actually. [11:49.060 --> 11:55.780] And what was good about Windows CE is that there's a lot of source code published on CE. [11:56.060 --> 11:57.580] Many people don't realize that. [11:57.740 --> 12:03.040] But there is actually quite some source code out of Windows CE. [12:03.040 --> 12:11.520] And that really enabled us to look deeper into it and, you know, made us do whatever we had to do to get this running. [12:11.520 --> 12:22.860] So, the major aspect which also differ a lot from competition that has come up over the last years is that we are really caring for the phone that we are running on. [12:22.980 --> 12:28.660] So, it's not just a piece of software running on a generic operating system because that wouldn't get your security. [12:28.660 --> 12:34.800] Windows Mobile out of the box is nice and fine, but you need to do a lot of stuff to harden it against the tech. [12:34.800 --> 12:50.720] So, what we do is we have invented something that we call the Security Profile Manager where we give the user the possibility to choose between functionality of the operating system and security of the operating system. [12:50.880 --> 12:58.780] So, basically saying, okay, if I don't need Internet on this device and if I don't need MMS and if I don't need VBScript and all this other crap, then you can just remove that. [12:58.780 --> 13:00.960] Very easy, very user-friendly. [13:01.280 --> 13:03.420] You see here the Security Profile Selector. [13:04.900 --> 13:10.060] For standard of the shelf phones, we have four different levels of security between no added security. [13:10.140 --> 13:15.880] We have to do just some minor stuff to prevent outright user stupidity like installing applications on that. [13:16.840 --> 13:20.540] To extreme security where nothing else but phone calls work. [13:20.760 --> 13:32.460] So, in between we have a spectrum of removing stuff, adding watchdogs, removing attack vectors, disabling protocols, doing stuff like disabling Bluetooth headset use during crypto calls. [13:32.700 --> 13:42.120] Because people would really be so stupid as using their Bluetooth headset to broadcast their secure call contents around before it gets to the encryption engine. [13:42.980 --> 13:43.620] Stuff like that. [13:43.740 --> 13:49.200] So, the real main problem in security is preventing the user from doing stupid things. [13:49.580 --> 13:53.620] So, that's one of the main problems that we face in user interface design. [13:54.540 --> 14:01.820] For instance, I talked to a guy who worked for the Russian NSA equivalent. [14:02.200 --> 14:04.240] So, basically, the Russian signals intelligence people. [14:04.540 --> 14:16.900] And he said, yeah, okay, the main source of information that we had was monitoring the lines where the Americans had secure encrypted phones on for the chitchat that was going on before and after secure call. [14:16.900 --> 14:19.020] So, basically, people would... [14:20.520 --> 14:26.760] And when they noticed that they started to drift into classified areas, they would switch on the encryption. [14:27.740 --> 14:32.540] But what's going on before and after was interesting enough to justify monitoring the lines. [14:32.860 --> 14:39.640] So, one of the things that we decided is there should be absolutely no confusion at all about whether you're in a secure mode or not. [14:39.640 --> 14:44.660] And you should not be able to set up an unsecure call and then switch over to secure mode. [14:44.760 --> 14:47.660] But you have to decide if you make an unsecure call or a secure call. [14:47.940 --> 14:53.320] So, that's, for instance, why our landline model, we have also a landline phone, has only secure call mode. [14:53.420 --> 14:56.980] So, there is simply no option of doing something stupid on that. [14:57.480 --> 14:58.480] So, that's... [14:59.120 --> 15:01.020] It has some inconveniences on the other side. [15:01.020 --> 15:11.440] But we feel that since our phones are being used by people who have really something to lose, up to their lives, we should try to prevent them from being stupid as much as possible. [15:12.800 --> 15:20.420] Part of that approach is that we are not selling the software, but we're selling pre-configured, pre-flashed mobile phones. [15:20.760 --> 15:26.480] So, that's really more or less like the Macintosh experience, meaning unwrap, insert, place, secure call. [15:26.480 --> 15:28.440] So, that was the goal. [15:29.460 --> 15:38.780] And it also enables us to do these things to the operating system to make it secure and prevent problems on that layer. [15:39.000 --> 15:43.340] There's actually one thing missing before unwrap, insert, SIM, place, call. [15:43.500 --> 15:49.520] And that is open seal and verify that the seal has not been opened before. [15:49.520 --> 15:58.920] Whenever we ship a phone, we put it in a secure container with high-security hologram seals on it that have a serial number. [15:59.200 --> 16:05.380] And before the phones leave the facility, we made high-resolution photos of these seals. [16:05.660 --> 16:12.820] So, if you receive your crypto phone in a sealed box, you can send us an email saying, you know, I received the phone or phones. [16:12.820 --> 16:14.760] Can you please send me the pictures? [16:15.560 --> 16:19.100] And then we can either, with PGP signed, we can send you these pictures. [16:19.400 --> 16:36.280] And you can actually verify for yourself that within the 24 hours that it takes to transfer the phones from our office to your place, wherever you are, nobody has tampered with the box and, you know, gave you a special update on your phone that you might not really want. [16:36.280 --> 16:39.340] So, and I think that we're about the only company that does that, right? [16:39.480 --> 16:39.960] Correct, yeah. [16:40.080 --> 16:42.520] Everybody else outside of the government domain. [16:42.740 --> 16:49.860] So, I think the U.S. government, also German government, when they send out their special government type phones, they do something similar. [16:50.100 --> 16:56.780] They have a separate Korean network for cryptographic systems, which we unfortunately don't have. [16:56.900 --> 17:01.540] But we do as much as we can to prevent tampering with the phones. [17:04.040 --> 17:11.240] Okay, so, speaking about encryption, what we do is we do a 4096-bit Diffie-Hellman key exchange. [17:12.560 --> 17:25.000] It takes a moment longer than on most competing products because we have 4096-bit, which takes a while to transport over the 9.6-kilobit data call that we use to transport the voice. [17:25.000 --> 17:30.400] So, yes, we're using, on GSM, 9.6-kilobit CSD circuit switch data. [17:30.540 --> 17:32.380] So, it's not GPRS, but CSD. [17:32.580 --> 17:34.700] It's a direct link between the two phones. [17:35.220 --> 17:37.220] More or less like a modem call on GSM. [17:38.600 --> 17:44.640] So, after the key exchange, we hash the result into three different subkeys. [17:45.180 --> 17:53.180] We're using SHA256 because there seems to be no other decent hash algorithm still living. [17:54.820 --> 18:02.860] If you notice the crypto design, even if there's some collision attack happening to SHA256 in this design, in the future, it doesn't break the crypto. [18:03.800 --> 18:05.920] It also doesn't make it more predictable. [18:06.960 --> 18:13.040] So, the whole design is set up in a way that things can go wrong for one of the algorithms involved. [18:13.360 --> 18:16.860] So, that's also why we use AES and TwoFish. [18:17.060 --> 18:19.920] So, we think TwoFish is stronger than AES. [18:20.540 --> 18:22.000] Most other people agree on that. [18:23.140 --> 18:30.620] AES has the advantage that it's more or less standardized algorithm that is very well researched and that people know, so the name is known, which is good for marketing. [18:31.020 --> 18:32.880] And you also need to market the crypto product. [18:34.060 --> 18:43.800] So, we run these two algorithms in counter mode, XORing the result, generating a key stream, XORing the key stream to the voice data. [18:44.800 --> 18:52.640] So, this design is also relatively CPU friendly, meaning on a 200 megahertz CPU, optimized everything. [18:53.080 --> 18:56.860] We are in the region of 6-7% of CPUs only for the encryption process. [18:56.860 --> 19:14.920] And the way that we invented or thought about this crypto scheme was we had in mind that we wanted to use the most secure, biggest length keys on the market or known to work and that were researched. [19:14.920 --> 19:23.340] Because our philosophy is that if people make a call with the phone now, it should remain a secret for as long as possible. [19:23.600 --> 19:28.080] And we could have gone for 2048 bit encryption. [19:28.680 --> 19:36.360] Right now, everybody thinks that's great, but maybe in one year or how many years, you know, the lower key lengths will probably always fall first. [19:36.360 --> 19:42.120] So, we really had in mind that we hope that calls will be secure for 10, 15, 20. [19:42.300 --> 19:49.420] You never can guess that, but we really did our best to make sure that it's as long as possible. [19:49.700 --> 19:54.820] And that if something breaks, that we don't need to redesign the phone, but that the phone can still operate. [19:54.820 --> 20:01.500] Because, you know, if AES is broken, then TwoFish is not broken because it works a little bit different internally, we hope. [20:02.680 --> 20:03.760] That type of thing. [20:03.920 --> 20:11.520] So, we really tried to harden the crypto layer as hard as we could to make the calls last as secure as long as possible. [20:12.240 --> 20:14.180] That was the basic design goal. [20:14.360 --> 20:16.000] While still having it usable. [20:16.520 --> 20:16.980] Yes. [20:17.160 --> 20:26.060] There are other crypto systems around that are using fantastically long key lengths, but where the key exchange takes so long that you basically cannot use it anymore. [20:27.920 --> 20:35.260] So, design is always a compromise, we know, but we try to err on the side of caution and make the design as hard as possible. [20:36.340 --> 20:42.660] A number of crypto experts have looked at it and no one has found a problem so far on that. [20:44.240 --> 20:46.160] Yeah, that's basically the crypto design. [20:49.320 --> 20:57.120] So, people who know a bit about cryptography will notice that Diffie-Hellman, of course, has no authentication built in. [20:57.460 --> 21:01.760] So, Diffie-Hellman key exchange, you need somehow to know who is the other side. [21:01.880 --> 21:09.860] Otherwise, you could do a man in the middle attack by using two crypto phones back to back, building up a secure connection to each side. [21:09.860 --> 21:17.900] And everybody on A and B, Alice and Bob, are thinking that they have a secure connection with each other, but they are working on different keys. [21:18.340 --> 21:30.600] So, what we do is we are generating in the crypto system, going one back, you see that the third path, where the sub-key is hashed down to six characters and shown to the user. [21:30.600 --> 21:40.840] And so, the user can, at any point in call, even multiple times, verify the key hash, thereby making sure that both users are on the same key. [21:42.320 --> 21:51.380] I was, at first, a bit reluctant saying, okay, people are going to omit it or not doing it, because it seems complicated reading stuff. [21:51.600 --> 21:56.420] So, but what we see from our users so far is that they actually love that. [21:56.600 --> 21:59.080] So, because it gives them a feeling of being in control. [21:59.580 --> 22:04.460] So, it gives them a feeling of being in control of their destiny and doing something for their security. [22:04.760 --> 22:08.140] So, that actually works relatively well. [22:08.720 --> 22:12.740] The drawback, of course, is if you don't know the voice of your partner, you could be fooled. [22:12.980 --> 22:25.120] So, if somebody is coming along with a really sophisticated voice impersonation, that he can cue into a call, even if you are asking in the middle of the call for something, then he could do a man-in-the-middle attack. [22:25.120 --> 22:33.140] So, technically, doing a man-in-the-middle attack on GSM networks is not trivial, but it is, in theory, possible. [22:33.360 --> 22:36.140] So far, we have not seen any evidence that something like this has happened. [22:36.960 --> 22:45.800] And, honestly, I really don't expect somebody going to this kind of length, because then he could more easily go after the users with directional microphones. [22:45.900 --> 22:46.660] That would be much cheaper. [22:48.220 --> 22:54.960] So, that also basically outlines what we aim to do, is giving you security on the wire. [22:55.740 --> 23:08.420] So, making sure that your call on your wire is secure, so we cannot prevent NSA driving behind you with a vent full of equipment that basically reads your thoughts before you think them. [23:09.640 --> 23:11.960] So, then we simply cannot help you. [23:12.080 --> 23:15.440] If you're in that kind of target category, then we simply cannot help you. [23:15.540 --> 23:18.080] So, all devices are also not Tempest-proof. [23:18.720 --> 23:20.920] It is civilian hardware for a civilian market. [23:22.880 --> 23:24.120] But, it's the best effort. [23:24.380 --> 23:24.660] Yeah. [23:26.320 --> 23:28.660] The crypto design has a lot of advantages. [23:28.920 --> 23:32.800] One of them is that there's a new session key generated for each call. [23:32.960 --> 23:41.980] So, each call forces the adversary to go again after a 256-bit session call generated out of a 4096-bit secret. [23:42.180 --> 23:48.140] So, after you press the red button and hang up, no key material is still on the device. [23:48.140 --> 23:56.420] So, it means that if you hang up, or even at that moment the secret agent comes and grabs your device, he can do nothing about your last call. [23:56.580 --> 23:57.480] So, it's gone. [23:58.660 --> 24:07.100] So, which also means that they cannot do a rubber hose attack on you, or any other kind of forcing you to reveal key material simply doesn't work. [24:08.500 --> 24:14.420] It also makes it possible to set up secure communication networks very quickly. [24:14.420 --> 24:28.020] So, we had one customer who requested two phones, one to his office address, and one gift wrap to an address that sounded familiarly like a lady in some other state. [24:28.900 --> 24:33.820] And apparently, it was one of the states with a really expensive divorce laws. [24:34.940 --> 24:44.340] And so, basically, we support shipping, all kinds of shipping options, as you can imagine, as long as they are in countries that we can ship. [24:46.800 --> 24:52.800] So, basically, what you do is send out the phones, people unwrap them, stick in the SIM, and can call secure immediately. [24:53.960 --> 24:55.720] That's a great advantage of the system. [24:56.860 --> 24:57.380] Okay. [24:58.900 --> 25:00.820] This is a short overview of what we are currently doing. [25:01.000 --> 25:08.020] We have GSM mobile phones, smartphones, PDAs, landline phones for analog and ISDN. [25:08.820 --> 25:10.920] We have a satellite option for Thuraya. [25:11.160 --> 25:16.600] Thuraya is a satellite system that's, I think, only not covering the U.S., but everything else. [25:17.200 --> 25:19.140] Or not covering America, to be precise. [25:21.800 --> 25:24.580] And we also have an Inverse.M4 option that's not shown here. [25:25.300 --> 25:42.880] And we also have an VoiceOver IP option, which is basically only working over quality of service controlled TCP/IP networks, because what we are doing is modem path through over VoiceOver IP, which, as you may know, only works if there is not too much delay jitter and packet loss on that. [25:43.860 --> 25:46.820] So, we are constantly developing on the products. [25:47.580 --> 25:50.780] All of them are available for nearly immediate shipment. [25:51.220 --> 25:52.960] So, that's very nice. [25:54.460 --> 25:58.260] And here's another overview on the models. [25:58.460 --> 26:04.780] You see, on the left side, we have the phones, where we basically modify the firmware. [26:05.100 --> 26:11.040] On the right side, we have our own hardware development, where we develop stuff for the Thuraya and for fixed line stuff. [26:12.220 --> 26:15.900] So, it has become quite an extensive operation in the last year. [26:16.020 --> 26:17.660] So, we started 2003 selling, yeah? [26:18.080 --> 26:18.920] How much are you? [26:19.220 --> 26:20.380] I'm coming to that later. [26:24.920 --> 26:25.400] Okay. [26:26.820 --> 26:32.440] We are active basically everywhere where we can legally export to, from Germany. [26:32.440 --> 26:33.280] Germany. [26:33.340 --> 26:40.600] The German crypto laws are really in favor of us, meaning where we can basically ship to everybody who is not really evil. [26:41.040 --> 26:52.420] As you see, there are some countries like China and Russia where we are not officially doing stuff because they have internal crypto regulations. [26:52.420 --> 26:59.600] And in this line of business, we learn a lot about the practical implications of doing crypto business. [27:02.440 --> 27:03.980] So, let's start with China. [27:04.200 --> 27:15.240] In China, we cannot trip to China because of German crypto regulations, meaning we could, but we would need to obtain a permit for each and every sale. [27:15.560 --> 27:20.840] However, for some bizarre reason, we can ship with any hassle to Hong Kong. [27:23.100 --> 27:25.700] So, we happen to ship a lot of phones to Hong Kong. [27:28.900 --> 27:32.040] So, in Russia, the situation is a bit more complicated. [27:32.240 --> 27:39.640] They have, as in China, they have severe internal crypto regulations, meaning that you need to register yourself as a crypto user. [27:39.840 --> 27:44.120] And in theory, you can only use state-approved crypto systems. [27:44.520 --> 27:49.100] Ours is not state-approved, of course, because you can get only approval if you have a backdoor. [27:49.100 --> 27:54.400] Or have so weak crypto that the FAPSI, which is the NSA equivalent there, simply doesn't care. [27:55.460 --> 28:00.040] A number of competitors' products are, interestingly, for sale in Russia. [28:01.280 --> 28:11.900] So, what happens is, of course, people are going to neighboring countries and buying the stuff at our dealers, their cash, and importing them in the pockets of their pants. [28:12.980 --> 28:14.360] That works pretty well. [28:16.480 --> 28:16.980] Yeah. [28:17.140 --> 28:21.200] So, for the export restrictions, it is... [28:21.200 --> 28:24.620] I'm going into this because it seems to be interesting for a lot of people. [28:24.620 --> 28:31.240] So, the list of countries under German export control, there's one... [28:31.240 --> 28:36.800] It's the A-list, which is the real evil countries, where you cannot even think about shipping to. [28:37.280 --> 28:42.880] You could, of course, in theory, obtain a permit, but you would never get it, like Iran, North Korea. [28:43.920 --> 28:47.180] Libya is about to come down from this list, but it's still on there. [28:48.180 --> 28:50.640] And so, they basically need a permit for every single shipment. [28:50.800 --> 29:03.120] So, then there are the not-so-nice countries where you need a permit only if the shipment goes to entities that are associated with the security side of government, like military, Minister of Interior, secret services, stuff like that. [29:03.860 --> 29:06.660] And so, they need a permit to ship to them. [29:07.460 --> 29:16.420] Then there's a general clause of zones of war and armed conflict, where you need to obtain permits or basically don't even think about it. [29:17.060 --> 29:28.400] We have an internal policy of monitoring the news and not shipping to certain zones, like currently we're not shipping to Israel for this reason, and stuff like that. [29:28.480 --> 29:31.940] So, we try to stay on the sane side of the business. [29:33.760 --> 29:39.660] And there is an additional list, which is the so-called bad guys list, that is rather bizarre. [29:40.280 --> 29:49.520] That list contains thousands and thousands of names, among them about 120 different writings of Osama Bin Laden. [29:49.960 --> 29:52.380] So, like 100 different spellings of his name. [29:53.360 --> 30:04.320] And then there are addresses in there, like the something else something honey trading company at the shrine behind the gas station in Karachi. [30:06.280 --> 30:08.520] That's the address that's in the embargo list. [30:08.700 --> 30:09.500] Do not ship to there. [30:09.960 --> 30:11.340] So, I have no clue. [30:12.680 --> 30:13.220] So... [30:13.220 --> 30:14.580] Are you allowed to say that? [30:14.580 --> 30:15.400] Yes, sure. [30:15.520 --> 30:17.800] It's an official public list. [30:17.980 --> 30:31.440] And if you're in this line of business, you need to have a subscription to this list and need to verify every shipment that goes out against this list, which is kind of hard because it's such a bizarre and not really precise list. [30:31.660 --> 30:35.520] So, the information that goes in there seems to be... [30:35.520 --> 30:38.720] I don't know where they get it, but it is not really straightforward. [30:40.460 --> 30:47.280] So, basically, these things prevent you from just dealing with people who you don't want to deal anywhere because it only leads to trouble. [30:48.300 --> 30:55.420] So, we are very observant in that since the market is big enough, we don't really care for all the shady and gray areas there. [30:56.080 --> 30:59.720] We just ship to everybody who we can ship to, which is a lot of people. [31:02.720 --> 31:04.560] So, who is buying the stuff? [31:05.200 --> 31:15.380] It's also very interesting to see because there are not many high security companies who have made a business plan that actually worked out. [31:17.420 --> 31:25.160] We started also doing a business plan, but as it turned out, it was completely different from what we expected. [31:25.160 --> 31:32.700] So, for one of the first... I think first quarter, we nearly exclusively lived of the European scrap metal industry. [31:33.460 --> 31:43.220] Because, apparently, scrap metal is such a cutthroat business that they are really on to each other, but they also really need to talk to each other securely. [31:43.220 --> 31:45.760] So, our system was nearly perfect for them. [31:45.860 --> 31:48.580] And so, we sold a lot of funds to the European scrap metal industry. [31:49.880 --> 31:50.320] Whatever. [31:50.320 --> 31:54.120] So, usually, the people who are buying our stuff are consultants of all kinds. [31:54.920 --> 31:59.720] Security, business, merger acquisition, banking, finance, that kind of stuff. [32:00.440 --> 32:06.100] Lots of doctors with high-profile clients who really cannot afford to be overheard on what they are doing. [32:06.860 --> 32:10.520] We have a large business with human rights and environments. [32:10.660 --> 32:13.820] Political activists are also international organizations. [32:13.820 --> 32:17.020] We have a lot of them on our client list. [32:18.300 --> 32:23.820] For human rights organizations and environmental activists, we have a special discount policy. [32:24.600 --> 32:31.020] On an individual base, we give to them the funds for much, much cheaper than what a merchant acquisition consultant would get as a pricing. [32:31.720 --> 32:34.700] Because, actually, these are the people that we are doing this stuff for. [32:35.600 --> 32:37.640] These are the people that we really want to support. [32:38.920 --> 32:42.100] So, of course, then there's the usual lawyers. [32:42.740 --> 32:44.720] Even some governments we have as customers. [32:44.880 --> 32:54.580] We have even police forces as customers who need to protect themselves against drug criminals that have become so rich that they can afford the surveillance of police officers. [32:55.600 --> 33:02.860] So, there are police forces out there who are really in a surveillance battle with large-scale criminals. [33:02.860 --> 33:10.780] Because all it takes is just, you know, one corrupt person in a switch or at a, you know, the cell phone provider. [33:11.220 --> 33:15.920] And, you know, a whole operation could be completely out in the open. [33:16.980 --> 33:19.620] And a lot of information leaks that way. [33:19.860 --> 33:24.500] You know, they can put a quality tap on a line to see if there's anything bad. [33:25.460 --> 33:31.700] There's many options that people at phone companies have to either monitor lines, et cetera, et cetera. [33:31.700 --> 33:51.400] So, one example, in a country in Eastern Europe, one of our customers told us, okay, so, he got an offer from a corrupt employee at a phone company that for $5,000 a month, he would get a CD with all the calls of his competitor flat. [33:52.240 --> 33:55.800] And there was also an additional option to have them already transcribed. [33:55.800 --> 33:59.960] So, not as audio, but getting them a searchable text file. [34:01.380 --> 34:05.720] And when he asked, so, I assume you have made the same offer to my competitor? [34:05.980 --> 34:07.220] I said, sure, of course. [34:09.760 --> 34:20.920] So, for instance, in certain countries in Asia, political parties, normal political parties, have their own intelligence agencies with surveillance capabilities. [34:21.900 --> 34:29.840] So, there are countries where it's completely and perfectly normal that political candidates assume that their competition is always on their phone. [34:30.440 --> 34:38.860] So, they incur, of course, fantastic travel expenses because they need to travel a lot to talk to each other. [34:39.480 --> 34:40.880] or they buy all stuff. [34:41.060 --> 34:48.440] So, it is an increasingly normal phenomenon that people have GSM interception. [34:48.800 --> 34:50.660] So, all kinds of stuff. [34:50.840 --> 34:52.780] So, the equipment has become really cheap. [34:52.920 --> 34:59.620] So, for instance, you can buy a passive interception system for GSM in the region of $60,000. [35:00.960 --> 35:06.120] And that gives you, then, eight channels of GSM passive off the air. [35:06.120 --> 35:15.100] So, if you want to have a more expensive system that can do also the higher grade encryptions or encodings for GSM, it's maybe double the price. [35:15.780 --> 35:20.640] But for that, you also then get already 32 channels decoded off the air. [35:20.880 --> 35:32.600] And that's not like the IMSI catcher of earlier days where you basically play a man in the middle and need to do a lot of stuff and know what you're doing, but it's just switch on like a police scanner and you get at everything. [35:34.200 --> 35:37.240] So, that's the state of art and technology there. [35:38.100 --> 35:42.800] And we think that, you know, there will be more and more people with... [35:42.800 --> 35:44.600] What's this thing called with Blossom? [35:45.300 --> 35:46.100] The GNU radio. [35:46.200 --> 35:46.760] The GNU radio. [35:47.160 --> 35:47.380] Yeah. [35:47.500 --> 35:55.240] There's a lot of development going on in software radio where we think that, you know, even amateurs can do this in a certain amount of time. [35:55.240 --> 35:59.780] And if we would have made a prediction, we thought that by now you would have seen something like that. [35:59.900 --> 36:01.560] So, it takes longer than we expected. [36:01.820 --> 36:07.360] But at the end of the day, amateurs will also be able to listen to GSM calls. [36:07.480 --> 36:08.520] That's my opinion at least. [36:08.520 --> 36:08.760] Yeah. [36:08.960 --> 36:10.600] Two or three years down the road, that will be the case. [36:10.800 --> 36:24.120] So, currently, the stuff that you can buy on an open or grey market is of relatively mediocre quality, except for one company in Switzerland that is making really decent equipment, but it simply works. [36:24.240 --> 36:27.340] So, it's most of the time, it's just some special hardware attached to a PC. [36:27.340 --> 36:33.720] And what I found fascinating is that interception on the interception side must be pretty boring. [36:35.420 --> 36:44.620] All of these systems have a listen at random button where the system basically chooses a channel of the air and just listens in to see if there's something interesting in. [36:46.800 --> 36:47.320] Okay. [36:47.440 --> 36:48.580] So, where are we going? [36:50.020 --> 36:53.360] The company is profitable. [36:53.400 --> 36:56.380] So, we are growing moderately, not too fast. [36:58.080 --> 37:02.280] We continue to port crypto phone to new phone models. [37:02.580 --> 37:19.120] So, we are basically in sync with the innovation cycle of the industry, meaning that we have every 12 to 18 months a new phone generation where crypto phone is running on, which as I said in the beginning is really important because we have VIP customers that really need to have the newest and shiny camera whatever phone. [37:19.920 --> 37:38.000] The next big step for us is going one more forward from securing the operating system, from securing the voice to building an integrated secure system, meaning that you have integrated secure messaging, integrated secure storage, so that you can basically do everything that you do today with the BlackBerry, [37:38.060 --> 37:38.940] but in a secure fashion. [37:40.160 --> 37:43.820] We are not going to BlackBerry, but we are staying currently on Windows Mobile. [37:44.900 --> 38:00.560] We thought about going to mobile Linux, but the problem is that the distributions for that are so inherently unsecure that you would basically need to roll our own distribution for that, which is a bit outside of our capabilities. [38:00.560 --> 38:09.060] So, we currently for the moment will stick with the Windows Mobile stuff because we know it very well and we get the support from the necessary entities there. [38:10.160 --> 38:12.440] One of the big topics, of course, is traffic analysis. [38:13.000 --> 38:23.600] What we currently provide is content security, meaning they can no longer listen in to your calls, but we cannot prevent them from knowing whom you are calling. [38:24.860 --> 38:28.500] Our customers have found a number of solutions to that, of course. [38:29.380 --> 38:36.180] For instance, one head of state that is using our product has a guy running next to him that is a SIM switcher. [38:36.180 --> 38:41.200] It has literally a bag of SIMs with him and a large table. [38:43.360 --> 38:51.540] And according, I don't know if it's time of day or after one call or whatever, he switched the SIM on phone and hands the phone back to the head of state. [38:52.500 --> 38:59.280] And the other sites, other communicating sites, have tables which number is the current number for the day. [38:59.280 --> 39:08.900] So and they're switching and if there's in times of crisis, they're switching like every 10 minutes or so, while even interrupting calls to do that stuff like that. [39:09.020 --> 39:18.100] So basically trying to make as much noise as possible on the traffic analysis side, which is kind of clumsy, of course. [39:20.080 --> 39:35.220] So interestingly, I heard that first from the head of state and later on read that apparently Al-Qaeda in Africa has done the same thing when they busted the people who had tried to shut down airliners. [39:35.360 --> 39:37.460] They had like 26 phones or so in their Jeep. [39:37.880 --> 39:40.080] And they're basically doing the same thing. [39:40.180 --> 39:41.680] Okay, this is, of course, not sustainable. [39:41.680 --> 39:42.520] We need something better. [39:42.780 --> 39:43.300] So we're working... [39:43.300 --> 39:43.820] 10 minutes. [39:43.980 --> 39:46.500] We're working on that, but it's not easy. [39:47.320 --> 39:57.700] Of course, we're going to IP-based stuff beyond just modem pass-through over voice over IP, but it's also taking some time just encrypting voice over IP, like Will Zimmermann does with Z-Phone. [39:58.080 --> 40:06.200] It does not really fit our bill of having a fully integrated system, like going to mobile, going over satellite and so on. [40:06.260 --> 40:08.820] That's really difficult with only encrypting voice over IP. [40:09.800 --> 40:14.320] And we also will try to do secure mobile video telephony and 3G networks. [40:14.460 --> 40:15.460] We have some demand for that. [40:17.180 --> 40:18.860] Okay, so questions. [40:19.440 --> 40:21.320] First question we had, how much is it? [40:23.240 --> 40:24.720] That's a difficult question, actually. [40:25.700 --> 40:36.680] Because we sell in a lot of regions of the world, and our distributors in the countries have a lot of different pricing constrictions. [40:36.680 --> 40:42.960] So for the U.S., roughly, it's in the region of $2,000 per phone before discounts for a single phone. [40:43.220 --> 40:45.500] So that's the rough pricing. [40:46.260 --> 40:48.340] If you buy more phones, there are step discounts. [40:48.580 --> 40:51.920] If you're in other regions of the world, it might be cheaper or more expensive. [40:51.920 --> 40:54.580] But that's the rough number. [40:55.500 --> 40:56.460] Other questions? [40:58.960 --> 40:59.940] Two questions. [41:00.300 --> 41:09.360] The first question is, do you have a way of providing users the capability of doing binary fingerprinting of the software on the phone, both that you provide and the OS? [41:09.480 --> 41:16.420] And the second question being, what control does the user of the phone have over their key? [41:16.420 --> 41:18.900] I wasn't clear on that in the presentation. [41:19.640 --> 41:21.760] Okay, so binary fingerprinting. [41:21.940 --> 41:40.500] There is a binary fingerprint running up on the start of the application that also runs a number of cryptographic test vectors through the application to be sure that you're having real crypto in there, not just somebody fiddling with the cryptography. [41:41.420 --> 41:43.440] So we tried as good as we can. [41:43.440 --> 41:49.060] But of course, if you have the device in your hands, you can manipulate as long as you want. [41:49.280 --> 42:02.380] And then you can even fake stuff like, for instance, putting in a daemon that prevents reading out a certain memory area and giving back the right number of bytes in the right order to create the right fingerprint. [42:02.600 --> 42:07.500] So we're not putting too much effort into that because we know that's easy to circumvent if you're at it. [42:08.800 --> 42:10.180] Sorry, the second question was? [42:11.180 --> 42:16.920] The second question was, how do you allow the user to maintain control of their primary key? [42:17.260 --> 42:18.440] There's no primary key. [42:18.520 --> 42:19.920] The key is generated from random. [42:20.300 --> 42:24.020] And we mean real random each time a new call is set up. [42:24.100 --> 42:28.060] So there's no stored key material, but we're using basically every random source. [42:28.060 --> 42:40.880] I mean real random source that we have on the device like noise from the microphone, CPU internal noise generators and so on, and creating the noise for the randomness for the Diffie-Hellman from that. [42:40.980 --> 42:42.280] So there's no stored key material. [42:45.300 --> 42:58.840] Regarding changing the cards in the phone like every ten minutes, wouldn't it be possible to just call a 1-800 number or, you know, another phone number that's set up and then punch in the number that you actually want to call and then connect? [42:59.060 --> 43:03.640] It's difficult doing that for CSD data calls because you have a data call. [43:04.000 --> 43:18.080] And you would need some sort of gateway solution and we decided against it because it might be either a source of the null service attack or a problem when somebody sits on the gateway and registers all the numbers that you're dialing through. [43:18.940 --> 43:24.280] So that's not really a solution we thought about it, but it really doesn't solve the problem. [43:24.420 --> 43:26.140] It just shifts the problem to another dimension. [43:28.780 --> 43:31.460] I think your technical stuff is all right on. [43:31.820 --> 43:35.200] So my question is more about your policies. [43:35.760 --> 43:52.440] I just find it a little weird that you say that in who this can be, you know, useful to, that you, you know, the crypto phone can save lives because, you know, in places where people are being oppressed or things are difficult, this can actually be a very valuable tool for people. [43:52.880 --> 43:58.340] But at the same time, you're limiting export to the general definition of regions of conflict. [43:58.880 --> 44:02.440] Like you mentioned right now, you're not shipping to Israel because of what's going on right now. [44:02.440 --> 44:12.060] But I could see that these phones could be a very valuable tool for people living in Lebanon who are trying to be in communication with their families and be safe. [44:14.900 --> 44:18.320] Okay, this is, of course, a difficult question. [44:18.920 --> 44:31.040] In general, what we try to do is being as accessible as possible to people who are in trouble while not being subject to state repression. [44:31.280 --> 44:34.380] Is it a Germany or a EU law that says... [44:34.380 --> 44:37.100] Yes, Lebanon is, for instance, is on a do not ship list. [44:37.380 --> 44:38.480] So that's very simple. [44:38.540 --> 44:40.980] So is that not your control or is that... [44:40.980 --> 44:41.760] No, it's not my control. [44:41.980 --> 44:44.720] So I cannot simply, I simply cannot ship to Lebanon today. [44:45.000 --> 44:47.340] So since four years ago, I think. [44:48.560 --> 44:52.720] So there are regions where we are always discussing if you want to ship to there. [44:52.980 --> 44:56.340] We could ship there, but sometimes we simply do not want to. [44:57.020 --> 44:58.560] Either because we don't like the customer. [44:58.700 --> 45:02.320] So we retain the right to refuse customers. [45:02.640 --> 45:06.980] So if the customer is some real evil intelligence agency, I really don't want to ship to them. [45:08.180 --> 45:16.060] So at other customers, we say, okay, they are not really our friends, but we have the general policy of providing security to everyone. [45:16.340 --> 45:22.420] So even if we don't like their face, we sell to them because we have general access policy on that. [45:22.540 --> 45:23.000] So we... [45:23.620 --> 45:25.120] It is a difficult process. [45:25.280 --> 45:27.160] So I cannot kind of say there's a general rule of it, but... [45:27.160 --> 45:31.140] Are you trying to loosen the laws a little? [45:31.280 --> 45:39.760] Or are you trying to take any action that would promote being able to ship these phones to troubled regions for the purposes of positive change? [45:39.760 --> 45:45.540] The problem is that when you're shipping to troubled regions, you never know whom you're ending up with. [45:45.780 --> 46:00.420] So we had some cases, for instance, in Africa, where we had requests to ship there, and we asked the export control people to please verify who the real customer is, because we thought it would be a bit fishy. [46:00.660 --> 46:10.240] And at first it sounded really good, and it seems to be some collective of human rights activists, and it ended up with being a group of real bad people. [46:10.540 --> 46:11.960] So we didn't ship to them. [46:13.860 --> 46:18.840] So the whole process of whom to ship to, whom to not ship to, is something that's very fluent. [46:19.060 --> 46:23.940] So we're not trying to influence the laws there, because simply we are too small for that. [46:24.260 --> 46:37.780] So there are other companies like the big weapon manufacturers who are already doing that, for instance, that Libya is now coming from the list, is mostly in part because of the effort of the oil industry that wants to ship dual-use equipment to them. [46:38.660 --> 46:42.560] China is the topic of discussion, for instance, on a German list. [46:43.880 --> 46:48.840] The German government really wants to be able to ship stuff to China. [46:50.080 --> 46:53.980] Other people in the politics don't want the China embargo to fall. [46:54.680 --> 47:00.140] So this is a humongous area of lobbying and so on and so on. [47:00.280 --> 47:02.720] So it's not easy. [47:03.200 --> 47:03.760] Just curious. [47:04.000 --> 47:04.940] Also, are you guys hiring? [47:05.480 --> 47:05.540] Huh? [47:08.160 --> 47:08.700] What's that? [47:08.940 --> 47:09.960] Are you hiring? [47:10.200 --> 47:10.600] No, no, no. [47:11.780 --> 47:15.960] With your land-based lines, your land-based crypto phones, you're obviously dealing with a TCP/IP stream. [47:16.300 --> 47:21.960] Have you put any thought into providing onion routing or any other method of actually protecting the privacy in regard to who's talking to who? [47:24.960 --> 47:30.000] As I said, we are working on stuff there which I really don't want to announce yet because it's not done yet. [47:30.260 --> 47:39.780] So we are having some really interesting stuff in the works, but maybe next year or so on a conference, I would be ready to announce that. [47:40.020 --> 47:41.200] I'll take that as a yes. [47:45.680 --> 48:02.080] My question is, does the crypto phone compromise quality of the phone call and how exactly is on the other side of the phone, how exactly is that implemented on the towers themselves or that kind of thing? [48:02.420 --> 48:03.520] I don't get your question. [48:03.520 --> 48:09.260] Like, what are the physical constraints on the crypto phone in terms of quality of the phone call? [48:09.420 --> 48:11.040] And how exactly are those... [48:11.040 --> 48:15.540] How physically is this kind of thing put into the phone system? [48:16.880 --> 48:22.700] So what you basically do is we modify the flash of the operating system and that also holds all the applications. [48:22.700 --> 48:24.820] That is the physical part on the phone. [48:25.560 --> 48:30.060] For the GSM network, what we do is, as I said, CSD data call. [48:30.800 --> 48:35.500] CSD data call requires a bit better GSM coverage than normal voice call does. [48:36.420 --> 48:39.840] So we need to have relatively good coverage to place a crypto call. [48:41.800 --> 48:44.680] But in most areas of the world, it works most of the time. [48:45.520 --> 48:52.240] So we have, in general, we have an above 90% call success rate on normal GSM networks. [48:54.680 --> 49:02.680] Can you tell me again, like, how exactly on the other end of the phone, like, do you have to put something on the towers to be able to do this? [49:02.920 --> 49:03.120] No, no, no. [49:03.140 --> 49:04.080] It works end-to-end. [49:04.260 --> 49:07.800] So both people need to have the crypto phone. [49:07.880 --> 49:15.980] It's not like in James Bond movies where there is a secure line, but it's real end-to-end encryption. [49:16.240 --> 49:17.760] You need both end-to-end. [49:17.800 --> 49:18.120] Correct. [49:18.120 --> 49:20.980] So both people have to pay $2,000 for this phone. [49:20.980 --> 49:22.800] Or download the free Windows client. [49:23.500 --> 49:25.660] You can also download the free Windows client and use that. [49:25.680 --> 49:30.800] You could basically use this phone against two people could call each other anywhere in the world, basically. [49:31.040 --> 49:31.320] Correct. [49:32.100 --> 49:32.360] Okay. [49:34.520 --> 49:35.620] Okay, we have... [49:35.620 --> 49:36.200] No, no. [49:36.300 --> 49:38.100] We have the sign that says stop. [49:38.460 --> 49:40.120] No, we start three minutes late. [49:40.260 --> 49:41.780] So we have one more question, please. [49:41.780 --> 49:45.420] Have you noticed places in the world where it's more popular, less popular? [49:45.920 --> 49:48.120] Like East Germany, West Germany, any differences you noticed? [49:49.100 --> 50:02.280] We have a distribution that is roughly equal to population that has a relatively high gross domestic income. [50:02.280 --> 50:04.780] So we have... [50:04.780 --> 50:06.820] So that's the rough measure. [50:06.980 --> 50:10.800] So, of course, we used to joke that we can predict crises. [50:12.200 --> 50:21.100] When we see demand going up in a certain country, then there is a relatively high chance that this country will be in trouble within the next month. [50:21.100 --> 50:25.800] So that is a rough measure. [50:26.760 --> 50:33.900] Of course, let's say the developed countries have the highest demand like EU, Eastern Europe, U.S. [50:34.240 --> 50:35.580] This is where most of the stuff goes. [50:36.280 --> 50:38.980] We also have a relatively high demand in Asia. [50:39.260 --> 50:41.500] So where there are GSM networks. [50:42.180 --> 50:50.300] And for most customers, especially large ones, we really don't know where the phones are used because they are international customers. [50:50.300 --> 50:57.540] It's like international organizations, international human rights organizations, where they give out the phones to activists and they travel around the world. [50:59.720 --> 51:01.000] Okay, then, thanks very much. [51:01.620 --> 51:02.200] Thank you.