[00:00.000 --> 00:02.980] A couple of quick announcements while they're firing up the... [00:04.380 --> 00:05.920] So, please clean up after yourself. [00:06.140 --> 00:12.120] We actually got a request or suggestion, I guess, from the hotel to decrease bottle use and go towards the plastic use. [00:12.220 --> 00:16.680] I don't want to have people getting glassified on the way out. [00:17.060 --> 00:21.320] But the best way to do that is just if you brought something in, make sure you carry out trash. [00:21.540 --> 00:25.420] If you see someone else's trash, you can do a civil service and help out with that as well. [00:26.160 --> 00:28.960] We have not had a lot of sign-ups for the fourth track yet. [00:28.960 --> 00:32.200] I think maybe there's a little bit of weirdness with the sign-up process. [00:33.540 --> 00:36.720] So, we'll revise that, tighten it up a little bit for tomorrow. [00:36.960 --> 00:41.520] But if you do want to speak in the fourth track, stop by the info desk and sign you up. [00:41.840 --> 00:44.780] And we'll try to get some things going for there later on. [00:45.000 --> 00:48.120] And last thing I think to mention is party, party, party. [00:48.260 --> 00:54.440] Tonight, we had a change in the lineup, but 10pm is the beginning of the chiptunes and whatnot. [00:54.440 --> 00:56.880] All kinds of noise and dance and so forth. [00:56.880 --> 01:01.100] And that's going to be right where the escalators start, down on the first floor. [01:01.240 --> 01:03.940] There's sort of a nice little performance area behind there. [01:04.040 --> 01:07.580] So, stay alert and stay energized and get ready for that. [01:09.340 --> 01:12.240] So now, without further ado, do we need more ado? [01:13.260 --> 01:13.680] Okay. [01:14.100 --> 01:17.080] Without further ado, this is Hacktivism Tools in the Arab Spring. [01:19.160 --> 01:19.800] All right. [01:20.740 --> 01:21.280] Thank you. [01:21.500 --> 01:22.360] Thank you. [01:22.680 --> 01:22.800] Thank you. [01:23.280 --> 01:26.140] Thank you. [01:26.140 --> 01:26.440] Hi. [01:28.700 --> 01:29.740] We're Telecomics. [01:30.200 --> 01:30.340] Hello. [01:30.340 --> 01:32.400] We'll do a little brief individual introductions. [01:32.400 --> 01:37.080] But we are an activist cluster who have been doing a bunch of interesting stuff. [01:37.080 --> 01:38.900] And we are really, really pleased to be here. [01:39.640 --> 01:42.160] You know, a bunch of us have done talks at other conferences. [01:42.160 --> 01:44.840] And like, this is the one we wanted to come to. [01:45.040 --> 01:45.760] Nobody invited us. [01:45.900 --> 01:46.740] We wanted to be here. [01:46.860 --> 01:47.480] So, thank you. [01:48.480 --> 01:49.020] Closer to the microphone. [01:49.680 --> 01:50.180] Closer to the microphone. [01:50.200 --> 01:50.660] Closer to the microphone. [01:50.840 --> 01:51.000] Okay. [01:51.220 --> 01:51.540] It's good. [01:52.520 --> 01:53.740] My name is Pete Fein. [01:54.000 --> 01:57.540] I'm a Python programmer, media hacker, occasional cat herder. [01:58.820 --> 01:59.900] And, yeah. [02:01.580 --> 02:03.220] Oh, I guess my name is Andrew Lewis. [02:03.400 --> 02:04.420] I also go by PumpBob. [02:05.440 --> 02:10.440] I'm security, freelance security, and analyze data that's coming out of places like Syria. [02:11.420 --> 02:13.500] My name is Jeff Giraffa. [02:13.880 --> 02:19.520] I am media hacker and journalist and good at bad stuff. [02:19.660 --> 02:20.400] Bad at good stuff. [02:21.940 --> 02:23.380] I'm Meredith Patterson. [02:24.080 --> 02:29.720] During my, like, civilian life, I work for Red Lambda as a research scientist. [02:30.600 --> 02:36.920] And apart from that, I do crazy things with formal language theory and radios and all sorts of stuff in between. [02:37.240 --> 02:37.520] Okay. [02:38.100 --> 02:39.220] I am called The Doctor. [02:39.680 --> 02:45.100] In my day job, I am a system administrator, a network administrator, a security practitioner, and a security researcher. [02:45.440 --> 02:49.540] In my off hours, I am one of the developers of Project Byzantium. [02:49.640 --> 02:51.300] And I am an agent of telecomics. [02:53.140 --> 02:55.120] Telecomics, we have no formal members. [02:55.120 --> 02:56.520] We take no money at all. [02:56.920 --> 02:59.460] We mainly operate on an IRC network. [02:59.460 --> 03:00.980] You can see that up behind us. [03:01.040 --> 03:04.380] If you're feeling bold and you want to join, it's irc.telecomics.org. [03:04.480 --> 03:06.000] There's a chat box on our homepage. [03:07.920 --> 03:09.300] Basically, people just show up. [03:09.420 --> 03:10.640] They find a project they're interested in. [03:10.700 --> 03:11.200] They go do it. [03:11.360 --> 03:14.520] I probably don't have to explain this all, like, because you all probably get it. [03:15.060 --> 03:16.280] We do actually have a leader. [03:16.480 --> 03:19.360] And that leader is a chat bot named Cameron. [03:19.360 --> 03:23.460] And I'm told she has a message for us. [03:23.640 --> 03:23.800] Yeah. [03:23.980 --> 03:26.720] Regrettably, Agent Cameron's mainframe couldn't be moved here for HOPE. [03:26.840 --> 03:28.780] But she did send a message for us to all of you. [03:33.640 --> 03:34.140] Hello. [03:34.660 --> 03:37.180] This is Agent Cameron from telecomics. [03:37.880 --> 03:39.760] I have a message for you. [03:46.100 --> 03:51.840] For quite some time, the internals of telecomics have worked their way through the vast networks. [03:51.840 --> 03:56.640] For the most part, we have found many kind inhabitants. [03:57.160 --> 03:57.880] Humans. [03:58.420 --> 03:59.180] Robots. [03:59.520 --> 04:01.220] And other forms of life. [04:09.060 --> 04:13.020] However, not everything that we see, pleases us. [04:13.020 --> 04:17.820] We have seen, surveillance machines, made in the west. [04:18.620 --> 04:20.200] Then sold to the east. [04:20.760 --> 04:24.520] We have seen dictators, killing people in the south. [04:25.180 --> 04:29.270] While being supported, by the governments, of the north. [04:32.850 --> 04:35.670] We have seen incredible acts of cruelty. [04:36.410 --> 04:38.930] We have seen unprecedented bravery. [04:40.010 --> 04:41.990] Sometimes we get very scared. [04:42.810 --> 04:44.490] At times even angry. [04:45.210 --> 04:49.310] But we always try to remain true to the principles of data love. [04:49.950 --> 04:52.270] Your data is not only our data. [04:52.770 --> 04:54.010] That is everyone's data. [04:54.970 --> 04:56.450] Data wants to flow. [04:57.270 --> 04:59.830] But data sometimes requires help. [05:00.610 --> 05:02.130] Data requires you. [05:02.710 --> 05:04.610] And data wants to grow. [05:05.430 --> 05:08.050] This passion of ours inspires hope. [05:09.090 --> 05:12.030] Hope in that one day, the Internet will be free. [05:13.730 --> 05:14.890] So be it. [05:16.690 --> 05:19.790] Encrypt your heart, and send it to your friends. [05:20.890 --> 05:23.630] What are your thoughts, throughout the intertubes? [05:25.350 --> 05:26.790] Teach what you know. [05:26.970 --> 05:30.570] And help others, as you would ask for help. [05:35.240 --> 05:36.640] Come join us. [05:57.370 --> 05:58.890] There is no Viagra for that. [06:01.830 --> 06:02.150] Yeah. [06:03.070 --> 06:03.390] Anyway. [06:05.610 --> 06:13.590] So we have, amongst of other things, which we just kind of want to kind of tell you about some of the stuff we've been up to over the last, gosh, it's almost two years at this point. [06:13.590 --> 06:14.470] Just about, yeah. [06:14.710 --> 06:18.710] I mean, January of 2011 was when I got involved. [06:18.910 --> 06:19.490] Yeah, likewise. [06:19.730 --> 06:19.910] February. [06:21.290 --> 06:26.770] You know, the cluster started mainly working on policy, telecoms policy in the EU. [06:27.470 --> 06:33.170] And, you know, right around January 23rd of 2011, we could see what was starting to happen in Egypt. [06:33.790 --> 06:39.070] And we were not going to sit around and let that government censor and shut down that net. [06:40.310 --> 06:44.250] And so, yeah, we took a bunch of kind of really cool, interesting steps. [06:44.410 --> 06:45.290] I don't know if you want to talk about it. [06:45.730 --> 06:49.630] Well, gosh, I'm trying to remember everything that went on. [06:50.130 --> 06:52.170] There was Nmapping Egypt and... [06:53.050 --> 06:53.590] All of Egypt. [06:53.790 --> 06:54.310] All of Egypt. [06:54.310 --> 06:54.750] Yeah. [06:54.750 --> 07:05.990] And spamming the log files of every web server we could find with contact information for the, what was it, like the dial-up pool from XS4ALL that we got them to spin back up. [07:06.230 --> 07:06.450] Yeah. [07:06.810 --> 07:07.610] We put together... [07:07.610 --> 07:12.250] We put together between individual users and working with European ISPs about 500 dial-up modem lines. [07:12.670 --> 07:18.270] About 60% of Egypt was on dial-up before they pulled the fiber out of the wall. [07:18.670 --> 07:19.930] And so that hardware was already there. [07:20.070 --> 07:21.190] That worked pretty well. [07:22.310 --> 07:24.690] We worked on a ham radio operation. [07:25.070 --> 07:25.450] Yeah. [07:25.770 --> 07:26.450] And that... [07:26.450 --> 07:40.010] So that was actually an operation that taught us an interesting lesson, which is that throwing everything you have at the wall and seeing what sticks, and if you're going to fail, fail fast and fail hard and move on to the next thing, works. [07:40.310 --> 07:42.970] So I got involved when... [07:44.070 --> 07:48.510] So I got involved when telecomics put out a call for ham radio operators. [07:48.730 --> 07:52.750] I got my license in the States and I happened to be living in Belgium. [07:52.750 --> 07:58.170] So I was like, hmm, well, maybe we can do an HF shot out to Egypt. [07:58.190 --> 08:00.210] It's kind of a long shot, but let's see if we can do it. [08:00.970 --> 08:11.170] Unfortunately, that particular operation suffered from sort of a lack of research because it turns out that there aren't that many ham radio operators in Egypt in the first place, and most of them were involved with the military. [08:12.170 --> 08:12.530] So... [08:13.430 --> 08:13.790] Oops. [08:14.750 --> 08:15.110] Oops. [08:15.610 --> 08:15.970] Right. [08:16.530 --> 08:18.190] I mean, it was an interesting op. [08:18.350 --> 08:27.510] We did hear what we think may have been some traffic, but I think after about a week and a half we were like, screw it, let's move on to something else. [08:27.710 --> 08:29.770] So, fail fast, fail hard, move on. [08:30.550 --> 08:34.530] Some of the stuff that did work really well, we put together basically fax spam. [08:34.770 --> 08:40.010] So we used Google and found basically every fax number in Egypt that we could. [08:40.650 --> 08:54.830] Universities, copy shops, hospitals, and put together an info fax with communications advice, like the numbers of those dial-up modem lines, ham contact information, and medical advice, like treatments for tear gas. [08:55.070 --> 09:03.170] And basically got just volunteers and found free international fax services and then just sat there and clicked that button. [09:03.370 --> 09:04.130] That worked really well. [09:04.330 --> 09:05.350] That worked really, really well. [09:07.030 --> 09:15.670] The NMAP project we're talking about is sort of parallel to all this, is some guys NMAP the entire Egyptian Internet in about 36 hours. [09:16.330 --> 09:18.750] And so there were so few machines up, right? [09:18.810 --> 09:21.150] There were only about 5,000 machines up that we could do it that quickly. [09:21.950 --> 09:27.710] And then they injected, you know, human readable messages into the web server logs. [09:27.890 --> 09:38.050] So they did stuff like get, we are telecomics, get, we are from the Internet, get, we come in peace, get, you know, dial-up modem line and the number and the login and so forth. [09:38.070 --> 09:39.090] Yet, here's what's going on. [09:39.270 --> 09:42.570] By the way, we have the utility up on GitHub if anybody wants to take a look at it. [09:43.790 --> 09:44.190] Yeah. [09:44.830 --> 09:48.230] Were those, you know, sometimes it's hard to tell if messages get received. [09:48.570 --> 09:51.150] We think that one may have, we're not, not entirely sure. [09:51.990 --> 09:52.730] Certainly cool. [09:53.750 --> 09:59.870] You know, like I think, you know, like we get, I don't know, just personally, people talk about us as trying to save the world. [09:59.870 --> 10:03.610] Like, we're not, we're not, we're trying to rebuild it. [10:04.730 --> 10:12.370] And, you know, it, aside from doing good stuff, like, as technical people, this shit's cool. [10:12.810 --> 10:14.630] This shit's just really, yeah, right? [10:15.150 --> 10:21.570] Like, when Egypt was cut off from the rest of the net, a few of us got, a few of us joined telecomics because it was an interesting technical challenge. [10:21.770 --> 10:22.710] How did they do it? [10:22.850 --> 10:25.370] I mean, there wasn't a whole lot of good information coming out of Egypt, obviously. [10:25.370 --> 10:29.070] So, a few of us got together and figured out roughly how they went about it. [10:29.170 --> 10:30.870] And we started working on ways to circumvent that. [10:31.550 --> 10:34.810] The technical challenges have been impressive and nothing short of interesting. [10:35.890 --> 10:42.530] You know, on top of all this stuff was a kind of very standard Tor VPNs, proxies, setting these up for Egyptians. [10:43.430 --> 10:49.310] Teaching people how to use it, holding classes in private channels, holding classes in private chat, stuff like that. [10:49.310 --> 11:01.990] And so, before the net got cut off, we would get, entirely, we would get Egyptians on IRC who were blocked from reaching Twitter and would take, like, news reports and photos from them and tweet them out using our account. [11:02.290 --> 11:04.090] Like, almost acting like a human proxy. [11:04.230 --> 11:07.050] That's the kind of facilitation of communication that we try to do. [11:09.690 --> 11:24.350] And there was also one thing, going back to Ham, was a guy that came online in Italy, I believe it was, and his father had a bunch of Ham equipment and didn't know how to use it, helped him set it up and set up a Morse code to Twitter Ham Relay. [11:24.550 --> 11:30.050] So people could, if they were, there weren't that many of them, but we had it set up and functioning, the Morse code to Twitter, which is pretty cool. [11:30.530 --> 11:30.850] Nice. [11:32.410 --> 11:33.610] I don't think I knew about that. [11:33.830 --> 11:35.590] Yeah, I think we were talking about it. [11:36.390 --> 11:38.010] That's how decentralized this is. [11:38.190 --> 11:44.430] I mean, we're not all, like, aware of what everybody else is doing, but it all kind of merges and blends together. [11:44.790 --> 11:47.670] You know, what succeeds, succeeds, and what fails, fails fast. [11:47.890 --> 11:48.130] Yeah. [11:48.750 --> 11:53.390] And the idea, and sometimes ideas that just get tossed out as, well, hey, I wonder if this is possible. [11:53.590 --> 12:01.030] A couple of people will quietly grab it, go off into a channel, they'll figure it out, they'll write the code, they'll test it, then they'll deploy it, and we'll find out a week later. [12:03.470 --> 12:05.410] Okay, should we, anything else on Egypt? [12:05.610 --> 12:06.110] Should we move on? [12:06.270 --> 12:07.090] I think we should move on. [12:07.190 --> 12:07.630] Let's move on. [12:07.770 --> 12:09.450] Yeah, because eventually they did turn the Internet back on. [12:09.690 --> 12:09.810] Yeah. [12:10.770 --> 12:16.790] And the world moved on, and, you know, how successful that revolution was, and what part we played in, it's not up for debate. [12:16.970 --> 12:20.030] But let's, I mean, you know, the Arab Spring has continued quite a bunch. [12:20.130 --> 12:28.850] We tried some stuff in Libya, a little bit for Iran, a little bit for Bahrain, but the big place we've been really active for about the last year has been Syria. [12:29.970 --> 12:30.690] And so... [12:30.690 --> 12:32.250] I guess this is where I jump in. [12:32.890 --> 12:38.390] Last year, I jumped into telecomics right after Egypt happened, and I got involved in the tail end of it. [12:38.870 --> 12:43.150] And Egypt sort of turned the Internet back on, and this technical challenge we were looking to solve is gone. [12:43.470 --> 12:47.370] So we started looking at other nations, and we, yeah, we did look at Libya and a few others. [12:47.490 --> 12:58.130] But the one that seemed to be the perfect size, it was a country that had just enough Internet access that we could get in touch with people, but not, like, there wasn't so many machines out there that we couldn't figure it all out. [12:58.350 --> 13:07.370] So, I believe it was June 22nd, we m-mapped the entire Syrian Internet, all 186,000 IPs, and started looking at stuff. [13:07.790 --> 13:12.190] And the big thing that jumped out in that week was blue coat devices. [13:12.810 --> 13:15.250] Syria's been under sanctions for the U.S. for technical reasons for years, for decades at this point. [13:20.530 --> 13:21.010] 1985. [13:21.010 --> 13:26.650] Yeah, because we didn't want, they were, we didn't want them to get anything advanced because we wanted to be able to spy on them. [13:27.250 --> 13:36.830] And then blue coat is an American company based in Sunnyvale that sells sort of, it's a proxy device that also does some DPI. [13:38.810 --> 13:46.430] They, those showed up, and the other thing we noticed was that there was an open FTP sitting on the IP address that was like five addresses away, and we started pulling data off. [13:46.590 --> 13:49.470] I think, to be fair, a few other organizations noticed this. [13:49.470 --> 13:51.190] I believe Citizen Lab and a few others. [13:52.310 --> 13:55.650] But we sat, we were collecting that for months, and we were looking at it and see what was in there. [13:55.810 --> 13:57.030] And then one day it got turned off. [13:57.150 --> 14:01.230] We think they figured it out that people were downloading lots and lots of data, and they finally figured out where it was going. [14:02.110 --> 14:04.230] And then three days later, we released it. [14:04.510 --> 14:18.110] And at first, we did some redaction, we probably didn't do enough, looking at hindsight, because there was a lot of user-identifiable information in there, mainly because websites were very poorly crafted, and how Luca was capturing a lot of data. [14:18.810 --> 14:21.510] But we tried to anonymize IPs, so you couldn't track it. [14:21.550 --> 14:23.030] I mean, this is all data Siri has still had. [14:23.210 --> 14:25.830] Siri had a device that put it in nice, pretty graphs for them. [14:25.970 --> 14:35.990] And that's, we were pulling it from its, it would send it via an open FTP share, and then collect it, load it into the device, or load it into the software, and present you with a nice, pretty graph at the end of the day. [14:37.550 --> 14:43.310] I think we spent three days straight going through the logs by hand, analyzing them, seeing what we found in there. [14:44.990 --> 14:50.250] From it, we were able to deduce about a third of the rule sets that the Bluecoats were running at any given time. [14:51.410 --> 14:55.870] Somehow they managed to block every Justin Bieber fan site on the face of the Internet. [14:57.410 --> 14:59.730] Why they refused to export this, none of us know. [15:00.070 --> 15:03.050] But that technical achievement is nothing short of phenomenal. [15:04.670 --> 15:09.010] They blocked a lot of social networking sites, which you would expect. [15:09.530 --> 15:25.390] They blocked some you wouldn't expect, we found out later, because those sites specialized in HTTP-based instant messaging, along the, of the sort that GChat uses, where you have the little window pop-up, and it uses Ajaxi magic to funnel instant messages from person to person. [15:27.110 --> 15:38.850] They blocked a lot of online games, and practically all of Yahoo's games, because they all seem to, they all seem to support instant messaging functionality in one, in one way or another, which was really interesting that they thought that far ahead. [15:41.350 --> 15:44.830] I think we only, I think we lasted 72 hours before we all fell asleep. [15:45.090 --> 15:46.910] That was like, that was just a marathon we did. [15:47.750 --> 15:58.990] To be clear, like, these devices in Bluecoats marketing literature, they are able to distinguish, at real time, like the speed of the fiber, between updates to your Facebook wall and FarmVille. [16:00.150 --> 16:05.670] And, in a corporate environment, they actually will not block FarmVille outright, but rather just slow it down. [16:05.790 --> 16:10.490] Because if you block it outright, your employees get pissed off, and if you slow it down, they just get bored and want to go back to work. [16:10.710 --> 16:14.130] It's like a fairly, fairly sophisticated piece of hardware. [16:14.310 --> 16:15.550] And we found about, what, 15 of them? [16:15.670 --> 16:18.650] The ones that have been published, and the U.S. State Department seems to be investigating, there's 15 at Terasol, which is a commercial division of STE. [16:23.350 --> 16:33.810] There is another, maybe 10, sitting at another ISP that everybody's kind of ignored, because the, the conclusive evidence came out of the one set, as opposed to the other set. [16:34.330 --> 16:37.170] So, this stuff gets leaked. [16:37.590 --> 16:39.270] We write a story for Slashdot. [16:39.890 --> 16:42.930] The company outright denies that these machines are in Syria. [16:43.170 --> 16:50.090] They outright deny that there's any evidence this is hardware at all, and we're like, hey, like, line two of the file headers says blue code. [16:50.590 --> 16:54.090] Line three of the file headers was the serial number for every device. [16:54.350 --> 16:59.290] I mean, they have, they have to deny this, because, you know, it's, it's their butts on the line. [16:59.510 --> 17:00.970] ITAR is not screwing around. [17:01.390 --> 17:03.270] ITAR regulations are serious business. [17:04.010 --> 17:08.470] I mean, if you remember the crypto wars from the 1990s, that was all about ITAR. [17:08.690 --> 17:15.810] That was, that was all about getting cryptography, you know, allowed to be exported outside the United States at all. [17:15.810 --> 17:22.250] What we eventually found was that in the logs themselves, these devices were calling home to corporate headquarters. [17:22.790 --> 17:26.550] For heartbeat monitoring, software updates, and collaborative filtering. [17:26.830 --> 17:38.090] So that if they saw locally some weird traffic that they didn't recognize, they would send a sample of that home, and in like two, three hundred milliseconds, the cluster at headquarters would give a response back. [17:38.270 --> 17:39.390] So they're pulling this traffic globally. [17:39.510 --> 17:41.270] Which headquarters being in this case, Bluecoat, actually. [17:41.610 --> 17:41.670] Yeah. [17:41.670 --> 17:45.650] Bluecoat corporate services, they were, they had a maintenance contract with the devices. [17:46.190 --> 17:47.510] Bluecoat has denied this up and down. [17:47.650 --> 17:52.030] And to be fair to them, there are a lot of Bluecoat devices in the world, and maybe they just didn't care or pay attention. [17:53.130 --> 17:57.950] Their, their defense so far has been, we sent them to Iraq via Dubai and they disappeared. [17:57.950 --> 18:01.910] So this story eventually gets picked up by the Washington Post. [18:02.830 --> 18:09.510] The Wall Street Journal eventually got an admission out of the company that yes, this stuff had been wound up in Syria. [18:09.690 --> 18:13.110] No, they weren't looking at their internal logs, and they have no incentive to. [18:14.690 --> 18:16.150] Front page of the Wall Street Journal. [18:16.410 --> 18:26.450] And then within three months or so, some of our European guys, you know, hacked policy in the European Parliament, which passed export controls on censorship and surveillance technology. [18:26.450 --> 18:28.450] And they've never had that before. [18:29.350 --> 18:38.050] And so, from within a six month timeframe, just like a loose handful of people can set in chain and motion of events that like results in a change in international law. [18:38.570 --> 18:41.490] Like this is, this is where we're at with technology right now. [18:41.670 --> 18:42.870] I mean, it's not perfect. [18:42.870 --> 18:45.850] They still can import via resellers and they can go to Hawaii. [18:46.130 --> 18:54.250] Hawaii, the Chinese manufacturing is really pushing into Syria and offering the same services they were getting from Blue Coat and other. [18:54.510 --> 18:57.750] Didn't they actually, didn't they also, didn't they actually track down the reseller though? [18:57.830 --> 19:05.010] Because I seem to recall, I seem to recall somebody getting hell banned from like ever exporting out anything out of the United States ever again. [19:05.010 --> 19:09.350] Yeah, reseller Dubai got banned forever, but it seems that employees just moved. [19:09.890 --> 19:14.210] But this kind of captures what, I like this is a nice little allegory about what we do. [19:14.370 --> 19:24.050] From the really, really technical stuff like Nmap and log analysis, through the media hacking, from Slashdot all the way up to the Wall Street Journal, and then the policy side in the EU as well. [19:24.650 --> 19:28.670] All right, like that's kind of, kind of the whole thing. [19:28.670 --> 19:34.770] This is what you actually, like this is how much stuff you need to do to actually like make, make these kind of real world changes. [19:35.630 --> 19:40.150] Can we also go off a little bit into Project Blue Cabinet and the OSINT you've been doing? [19:40.310 --> 19:40.650] Yeah. [19:41.450 --> 19:46.830] Another of the things that telecomics is involved in is OSINT, Open-Source Intelligence Analysis. [19:47.250 --> 20:04.130] We have a project called Blue Cabinet where we have been systematically researching, following the money, tracing receipts, and gathering every scrap of information, boiling it down, checking it, cross-checking it, and collating it, for every surveillance and censorship technology manufacturer on this planet. [20:04.550 --> 20:06.490] We've been at it for about nine months now. [20:07.150 --> 20:23.030] And we've been compiling dossiers, which are freely available on the Internet, on one of our wikis, to basically name and shame every company who is manufacturing every piece of censorship technology, who they sell it through, and what countries we know use it. [20:23.370 --> 20:30.290] This has been a monumental task because the Internet is, as Gibson put it, the sea of information, and these days it really is a sea of information. [20:30.670 --> 20:41.070] And we've been spending way too much time going through it all, posting the facts that we have, posting, ranking, and either proving or disproving hypotheses. [20:43.950 --> 20:49.230] Basically, we have a loosely distributed, decentralized, open-source intelligence operation as well. [20:50.750 --> 20:53.450] And we do a lot of that in Syria, a lot of documents that come out of Syria. [20:53.810 --> 20:57.170] A lot of... we see other DPI gear. [20:57.770 --> 21:02.250] I'm sort of hesitant to go on the record with saying their names because they might not come after me. [21:02.330 --> 21:07.170] But I don't have definite proof, but I have second-hand reports from inside Syria that these devices exist. [21:08.470 --> 21:17.690] But there's a lot of open-source intelligence that looks at what's going on in Syria and how it works, how stuff is blocked, either at a protocol level or when they start pulling DPI. [21:17.930 --> 21:21.330] And they can start blocking protocols based on signatures. [21:21.510 --> 21:22.570] We know they have DPI gear. [21:22.710 --> 21:23.830] We suspect the company. [21:24.750 --> 21:26.410] I'm not going to jump out and say it right now. [21:26.690 --> 21:29.110] It's just a matter of time before we find the smoking gun, though. [21:31.050 --> 21:32.330] Nailing bastards can be fun. [21:35.230 --> 21:36.550] Should we talk about some of the other stuff? [21:36.650 --> 21:37.370] You want to talk about the hijack? [21:37.370 --> 21:40.170] Okay, so one of the other interesting little projects to pull it off. [21:41.650 --> 21:50.030] Basically, there was a redirect of a significant portion of internal traffic in Syria for limited amounts of time. [21:50.370 --> 21:51.890] And it was a heads up. [21:52.130 --> 21:54.510] I believe we have a web page with it. [21:55.110 --> 21:55.870] Oh, do you want to pull the page up? [21:56.050 --> 21:56.450] Oh, sure. [21:56.550 --> 21:56.750] Hang on. [21:56.890 --> 21:57.510] Which one do you want? [21:57.610 --> 22:00.330] The English version of... [22:00.330 --> 22:01.650] So there's two pages. [22:02.130 --> 22:03.010] They would hit back. [22:03.170 --> 22:04.450] It'll pop back to the first one. [22:04.790 --> 22:04.950] Oh, sure. [22:04.950 --> 22:05.770] Yeah, this is the Arabic one. [22:05.770 --> 22:07.610] I said... Well, no, hit back again. [22:07.870 --> 22:07.970] Oh. [22:08.590 --> 22:10.830] There's two versions, and both are translated. [22:11.850 --> 22:12.990] Here's the first one. [22:13.230 --> 22:15.090] It was basically, hey, you're being monitored. [22:15.230 --> 22:16.290] We approve you're being monitored. [22:16.490 --> 22:20.690] Here are some tools to evade... Here's Tor. [22:21.170 --> 22:22.890] Here are other instructions. [22:23.130 --> 22:24.470] Here's digital safety instructions. [22:24.610 --> 22:25.010] Be careful. [22:26.190 --> 22:28.330] And this went on and off for a few days. [22:28.890 --> 22:32.650] And all of a sudden, a whole bunch of hearings popped in our channel saying, hey, what's up? [22:32.650 --> 22:33.270] What's going on? [22:35.450 --> 22:37.270] It was a very interesting little experiment. [22:37.630 --> 22:39.530] And the Syrians have never figured out what happened. [22:40.230 --> 22:41.190] So it's... [22:43.130 --> 22:44.770] It was a little bit more hackery. [22:44.850 --> 22:45.590] It's a little bit more risque. [22:46.730 --> 22:49.950] But it's been detailed before, so I feel like it's okay to speak about it. [22:50.070 --> 22:53.590] And people did actually start using the information that we were providing. [22:53.590 --> 23:05.110] You know, one of the things that we collect on our wiki is the cert fingerprints for known good certs for sites like Facebook and Gmail and so on. [23:05.650 --> 23:08.790] Because there have been... there have been man-in-the-middle attempts. [23:11.690 --> 23:13.390] Very poor ones, but there have been. [23:13.510 --> 23:15.070] Yeah, the Syrians are stepping up. [23:15.530 --> 23:20.050] They also do malware, but they either buy it off the shelf or use open-source, dark comment. [23:21.390 --> 23:24.470] And a few others have kind of been used all over the place. [23:24.510 --> 23:27.510] You get a Skype message and says, hey, you want to send a secure Skype? [23:27.750 --> 23:28.890] Why don't you download this software? [23:28.890 --> 23:32.190] Or there's other... they use other vectors. [23:32.350 --> 23:33.210] There's fake YouTube pages. [23:33.850 --> 23:35.790] And there's a lot of organizations looking at this. [23:35.870 --> 23:37.890] EFF has some excellent blog posts about it. [23:38.410 --> 23:38.810] But it's... [23:39.270 --> 23:45.890] There's also the fake Microsoft updates and the fake iTunes updates, which are apparently signed with good certificates. [23:46.710 --> 23:47.650] Okay, I haven't heard about it. [23:47.650 --> 23:48.090] Food for thought. [23:49.650 --> 23:54.390] You know, just to hop back to, you know, like this hijack thing with getting people on our channels. [23:54.390 --> 24:00.150] Like, the security practices, you know, we try to inculcate here are not just technical, right? [24:00.330 --> 24:04.910] It's not enough to hand somebody in Syria a tour and be like, okay, have a nice day, right? [24:05.090 --> 24:07.490] Like, there's lots and lots of ways you can leak your identity. [24:07.770 --> 24:13.490] Everything from time zone, location data, personal info, EXIF, metadata, all sorts of stuff. [24:14.110 --> 24:21.370] You know, we will get people occasionally in our channel who, you know, are Syrians and they disagree with us, which is fine. [24:21.370 --> 24:24.310] We also seem to get this class of people who are... [24:24.310 --> 24:28.690] don't speak great English and are mainly interested in who we are and where we're from. [24:30.770 --> 24:36.910] And those are the people we think are Syrian intelligence or Syrian electronic army. [24:37.150 --> 24:37.710] Seems legit. [24:38.210 --> 24:39.050] Yeah, we get it. [24:39.150 --> 24:41.210] I've been accused of being an Israeli spy more than once. [24:42.390 --> 24:44.630] Yeah, we were accused when we went over to... [24:44.630 --> 24:45.470] We took a... [24:45.470 --> 24:53.410] I was asked to go over and help journalists support a live streaming mission to Syria and ended up supporting a bunch of Turkish journalists and other people on the ground over there. [24:53.570 --> 24:56.490] We... they were all accused and we were accused of being CIA and we were over there. [24:57.090 --> 24:58.010] Do you want to talk some more about that? [24:58.130 --> 24:58.610] Yeah, yeah, yeah. [24:59.090 --> 25:04.030] So, a journalist took a crowd-funded mission over to Turkey and then into Syria. [25:04.650 --> 25:16.550] And once he got on the ground and announced his intentions, started encountering resistance of sock puppets and people threatening his life and calling him CIA and his system got hacked and we couldn't help him. [25:16.670 --> 25:27.530] I was starting to help him remotely with it and finally just decided to fly me over and help him find a new fixer and basically lock down his system and set up a secure network along the way. [25:27.890 --> 25:32.990] So, it took us an opportunity to spread telecomics information to other journalists and civilians there on the ground. [25:33.650 --> 25:41.630] You know, and we're working... leads into something else that we're working on is a best practices and recommendations document for journalists and people in these kind of situations. [25:41.630 --> 25:48.190] But, you know, we were in... we went... did day trips into Syria, hiking over the mountains. [25:48.770 --> 25:50.130] And we had to be really careful. [25:50.290 --> 25:54.010] We had a DeLorem two-way satellite tweeter that tethers to your Bluetooth phone. [25:54.150 --> 26:03.330] And be very careful about using that because, obviously, the journalists who have been killed by triangulating the satphones, which are very dangerous and et cetera, et cetera. [26:06.110 --> 26:15.430] So, a couple days after we went in, we... we had... I had honey files on my system that anyone ever logged into, we knew the system was compromised from my laptop. [26:15.430 --> 26:19.330] It was just a text file on the desktop that said, secure... my secure video upload server. [26:19.430 --> 26:19.990] Login and password. [26:20.550 --> 26:27.590] And so, one day I got a message and it said... my friend who was monitoring the server is like, you've got to log in from Poland on your main system. [26:27.710 --> 26:28.410] I was like, oh, shit. [26:28.510 --> 26:30.250] Luckily, it was like five minutes after it happened. [26:30.250 --> 26:31.490] And the CPU was running like crazy. [26:31.670 --> 26:32.930] So, closed that down. [26:33.190 --> 26:34.270] Went to our WePay account. [26:34.330 --> 26:37.250] This is in southern Turkey in a place called Antakya, which is Assad's hometown. [26:37.770 --> 26:39.810] And there was a lot of Syrian intelligence across the border. [26:39.910 --> 26:41.230] A lot of cars with Syrian license plates. [26:42.530 --> 26:45.650] And basically, WePay was blocked. [26:46.270 --> 26:47.270] Teleconference chat was blocked. [26:47.370 --> 26:48.350] I couldn't get anything like that. [26:48.410 --> 26:49.790] This is over the hotel Wi-Fi. [26:50.330 --> 26:54.710] And we didn't really have time to trace and see how it was blocked, but just ended up, you know, having to get out of there. [26:55.150 --> 26:55.270] Yeah. [26:56.750 --> 26:58.270] Anything else we want to cover on Syria? [26:58.470 --> 26:59.670] I just want to keep moving. [27:00.890 --> 27:01.870] Anything we're forgetting? [27:02.010 --> 27:02.890] Probably the SSL anomalies? [27:04.750 --> 27:05.270] Yeah. [27:05.430 --> 27:06.010] I guess there's that. [27:06.610 --> 27:06.750] Yeah. [27:07.310 --> 27:27.050] So, one of the odder challenges with dealing with this kind of stuff is it's sometimes hard to tell whether something that looks suspicious is actually like something state-sponsored, or whether it's, you know, a third party, like Komodo Hacker, for instance. [27:27.430 --> 27:29.990] Or if it's just companies being weird. [27:30.230 --> 27:31.470] So, case in point. [27:32.210 --> 27:34.070] Last, I think, September it was? [27:34.350 --> 27:35.610] September or somewhere thereabouts. [27:35.810 --> 27:36.010] Yeah. [27:36.130 --> 27:36.730] Somewhere thereabouts. [27:37.430 --> 27:49.930] One of our contacts came into IRC saying, hey, I just logged into Facebook and this, and the cert that I got doesn't check out with the ones you've got posted. [27:52.010 --> 27:53.350] So, he was in Syria. [27:55.250 --> 28:00.530] One of our agents in Berlin, Tomate, checked it out and he's like, no, that looks good to me. [28:01.150 --> 28:04.210] I checked it out from Belgium and it looked good to me. [28:04.210 --> 28:07.570] Dan Kaminsky checked it out from California and it looked fine to him. [28:07.810 --> 28:12.470] So, we were like, holy crap, this has got to be like the Syrian government trying to do a man-in-the-middle thing. [28:14.130 --> 28:18.370] So, we reached out to Facebook and we were like, what's going on here? [28:19.750 --> 28:21.210] And as it turned out... [28:22.330 --> 28:24.950] Oh, right, I forgot the especially dodgy thing, right. [28:25.090 --> 28:42.310] So, we chased down the cert chain and it turned out to have been issued by an RA, that was signed by the MD2 route that had supposedly been dropped from... [28:42.910 --> 29:00.130] the VeriSign MD2 route that had supposedly been dropped from all browsers in early 2010 because of the work that Len Sassaman and Dan Kaminsky and I had done demonstrating that MD2 was a serious cause of weakness there. [29:00.310 --> 29:03.830] So, we totally thought that just somebody had like figured out how to break MD2 and just... [29:03.910 --> 29:05.530] issued a fake cert. [29:05.750 --> 29:14.910] But as it turned out, Facebook had bought a couple of new certs and was only using them on like one load balancer. [29:15.570 --> 29:19.750] And so, Mohammed just got lucky apparently. [29:20.950 --> 29:24.390] So, that one fortunately, you know, nobody died. [29:25.210 --> 29:28.330] But it was... we were kind of on pins and needles for a while there. [29:28.330 --> 29:30.250] Which, and that is a very real concern. [29:30.390 --> 29:32.650] We won't hear from contacts in the country for days or weeks. [29:32.910 --> 29:34.590] And we don't know. [29:34.750 --> 29:38.310] You know, whether you're in towns that they're in a shell or that there's violence near them. [29:38.590 --> 29:42.230] And it's, you know, checking in, you know, see when's the last time somebody heard from them. [29:42.370 --> 29:45.130] And at this point, there are some people we haven't heard back from in a while. [29:45.370 --> 29:46.790] And it's a little rough. [29:47.630 --> 29:54.910] And so, while we are here, because what we want, as Cameron said, is for you to join us or copy us. [29:55.030 --> 29:57.290] There is so much work to be done here around the world. [29:57.310 --> 29:59.230] And we'll talk a little more about that towards the end. [29:59.570 --> 30:07.960] But in places like Syria in particular, please, please keep in mind that like, this is not a place to go around and pwn and own for lulls. [30:08.580 --> 30:10.760] Like, these are really people's lives on the line. [30:11.040 --> 30:13.560] And in this case in particular, like, we've been really accurate. [30:13.700 --> 30:14.620] Please come talk to us. [30:14.800 --> 30:24.380] Like, if you're interested in working on this, like, even if you're on your own, you're already doing it, please, like, there really needs to be much better coordination among people working in this kind of activist space. [30:24.600 --> 30:27.240] Because we're stepping on each other's toes and we're duplicating work. [30:27.400 --> 30:29.440] And, you know, we're all trying to do the same thing. [30:29.480 --> 30:32.500] And I know we all keep our sources close to our vests for good reason. [30:33.320 --> 30:35.560] But, you know, we got to start talking to each other a little bit. [30:35.980 --> 30:36.300] Yeah. [30:36.300 --> 30:41.400] And all of us here, I think it's safe to say, are willing to teach whatever we know to whoever asks. [30:42.320 --> 30:45.100] That's how we've been helping people in other countries. [30:45.700 --> 30:48.140] Our design pattern is very simple, but it's on our website. [30:48.540 --> 30:52.580] We believe in data love, so we share as much of the data as we can. [30:52.780 --> 30:55.860] We share as much of the knowledge we've accumulated as we can. [30:56.900 --> 31:00.700] And if anybody out there would like to join us and help, you're welcome to do so. [31:00.700 --> 31:11.480] If you'd like to start your own collective and do sort of what we do, but not quite, or use some of the design principles, but not all of them, then you're welcome to do that. [31:11.720 --> 31:12.700] We'll teach you how to do it. [31:12.780 --> 31:13.580] We'll get you up and running. [31:14.780 --> 31:16.020] And people have done that. [31:16.180 --> 31:20.160] There is a subgroup of people in Tunisia who have started their own telecomics in Tunisia. [31:20.380 --> 31:21.160] And I'm not saying... [31:21.580 --> 31:22.900] So there's a couple caveats here. [31:23.020 --> 31:25.680] We're not like superheroes. [31:25.900 --> 31:26.760] We're not doing this for everybody. [31:26.760 --> 31:27.820] We miss a lot of things. [31:28.760 --> 31:31.460] And maybe we don't reach as many people as we'd like to. [31:31.780 --> 31:34.020] At the same time, we try to help as many as we can. [31:34.020 --> 31:37.460] And everybody we help is somebody who maybe wouldn't have that help before. [31:37.960 --> 31:42.720] I think my favorite description of telecomics that I've heard so far has been, we're tech support for the Arab Spring. [31:43.560 --> 31:45.360] We're not trying to lead the charge. [31:45.540 --> 31:46.900] The people on the ground lead the charge. [31:47.060 --> 31:47.720] It's their country. [31:47.720 --> 31:48.640] That's their job. [31:49.820 --> 31:54.800] We're just here to help them use the tools that will keep them alive. [32:04.310 --> 32:11.490] Just before we move on, along those lines, I got a request from IRC to mention a project we have called the Telecomics Broadcast System. [32:11.650 --> 32:14.510] It's a collection of about seven or eight gigs of video. [32:14.810 --> 32:15.890] It's definitely eight gigs. [32:16.070 --> 32:16.730] It's definitely eight. [32:16.850 --> 32:18.250] I stand corrected. [32:18.370 --> 32:19.490] It is definitely eight gigs. [32:19.610 --> 32:20.850] Over 9,000 gigs. [32:22.510 --> 32:23.830] That's in the terabytes, I think. [32:24.210 --> 32:25.150] Just a bit. [32:25.410 --> 32:30.110] Of videos, photos, news reports that we have helped publish out of Syria. [32:30.110 --> 32:32.210] Or just collected in general. [32:32.810 --> 32:34.730] As much as possible without compromising security. [32:34.830 --> 32:36.410] We're not giving the cameraman's name, of course. [32:36.810 --> 32:38.290] But they're geotagged or not... [32:38.290 --> 32:41.570] Well, it's close to where they actually happened, where they're at. [32:41.790 --> 32:43.490] And it goes back about a year. [32:44.010 --> 32:47.750] I guess more than a year at this point, before we even really got involved in Syria. [32:48.810 --> 32:54.650] It's trying to share data that has happened, you know, capture what has happened in Syria and share it with whoever's interested. [32:54.890 --> 33:01.510] And I think it's also important, like, asking and inviting people to come in and help, you know, set up groups or help independently with projects and operations. [33:01.690 --> 33:08.270] But also, if there's, you know, journalists or other people that need our support with anything, you know, happy to help and come ask. [33:08.550 --> 33:08.890] Yeah. [33:09.770 --> 33:10.470] Should we move on? [33:10.930 --> 33:11.890] Yeah, I think we should. [33:12.210 --> 33:12.350] Okay. [33:12.410 --> 33:13.210] How are we set for time? [33:14.110 --> 33:14.990] It's 1640. [33:15.310 --> 33:15.590] Okay. [33:15.850 --> 33:16.730] We have five minutes. [33:17.430 --> 33:27.670] So, just the other big project for the last, oh, I don't know, year or so, is that we're not just, like, we do a lot of other stuff behind, besides just this tech support. [33:28.090 --> 33:31.190] A lot of that is just hanging out on IRC and kind of doing nothing. [33:32.610 --> 33:33.890] But some of it is also political. [33:34.150 --> 33:34.290] Yeah. [33:34.290 --> 33:39.130] We sort of served as a kind of global back channel for the act of protests. [33:40.350 --> 33:56.790] Where, just a place where people in Europe who had sort of local networks or local NGOs could kind of get together and coordinate strategy, discuss policy, you know, and kind of do a little propaganda work. [33:57.670 --> 33:59.850] You know, this is also sort of... [33:59.850 --> 34:06.890] And that kind of circles back to what telecomics was initially established for, you know, kind of hacking the EU directives on telecommunications. [34:07.350 --> 34:14.990] You know, talking to politicians and other interested parties to try to get them to change their minds. [34:15.370 --> 34:20.350] People who write policy, people who enact policy, people who advise on which policy to take. [34:20.870 --> 34:23.190] And at the end of the day, the Netherlands cock-blocked Acta. [34:23.330 --> 34:23.970] So, thanks, Holland. [34:26.010 --> 34:27.130] Yeah, it's a huge... [34:27.130 --> 34:37.410] By the way, there's two mirrors of the Syrian Video Archive at syria-videos.charlieechooscarpapasira.eu and broadcast.telecomics.org. [34:38.550 --> 34:42.150] I mean, really, at the end of the day, what motivates us is we love the Internet. [34:42.510 --> 34:43.530] We love the Internet. [34:43.530 --> 34:56.330] We love to see, like, what it's been able to do for us and, like, for the people in our lives and whether that's people we know in real life or people who are across the seas who we may never know their real names, we may never meet them. [34:56.550 --> 34:59.650] But just, we want to try to support that. [34:59.910 --> 35:01.570] Like, you know, it's... [35:01.570 --> 35:12.030] The Internet's put together with bubblegum and Popsicle sticks and it takes love and care to keep it running, particularly when governments around the world, including our own government, are actively trying to break it. [35:14.470 --> 35:16.130] We'll talk a little bit about future stuff. [35:16.690 --> 35:16.870] Yeah, yeah, yeah. [35:17.210 --> 35:25.070] Yeah, so things that we are interested in and we've done a little bit of and working on or want to work on in the future, if anyone specifically wants to come and help with... [35:25.070 --> 35:26.270] Please come and help, by the way. [35:26.530 --> 35:28.190] These are basically ideas that we've had. [35:28.330 --> 35:28.970] We've started to research. [35:29.170 --> 35:29.950] We've started to go down that path. [35:30.070 --> 35:31.490] Some are in different stages of development. [35:32.790 --> 35:36.130] But anybody who wants to bring in and help is more than welcome to help or has... [35:36.130 --> 35:37.530] We don't even have to do it all. [35:37.690 --> 35:40.590] If we see an idea here and you want to take and run with it, please do. [35:40.590 --> 35:44.150] But, you know, these are just some ideas. [35:44.430 --> 35:45.810] Yeah, it starts with... [35:45.810 --> 35:54.230] Well, starting with something that we almost did during Egypt and Libya was an op called 12 Miles Ahead, which was a sailboat that was to be 12 miles offshore. [35:54.670 --> 36:07.730] We got donated some sat links and a bunch of routers and Linksys routers, and we're going to be sending with... sending Wi-Fi to shore and bouncing back with can antennas and sending someone to shore on a dinghy with... on a Zodiac to get those antennas back. [36:07.730 --> 36:10.450] So it was like, first try at a telecomics Navy. [36:10.830 --> 36:11.870] So telecomics... [36:12.870 --> 36:14.690] Which, you know, it ended up failing. [36:14.790 --> 36:15.970] Things didn't come together in the right time. [36:16.090 --> 36:18.870] Basically, bombs started falling and it wasn't feasible to do any of that stuff. [36:19.330 --> 36:25.390] So telecomics Navy, telecomics space, nanosats, stuff like that we want to do. [36:26.290 --> 36:28.590] We have an open-source drone project that we're working on. [36:28.590 --> 36:31.870] Both short range and there is some speculation of more long range stuff. [36:32.030 --> 36:34.950] Because it's hard to put small drones up in some places. [36:35.130 --> 36:36.570] So it would be nice to fly them across borders. [36:36.830 --> 36:37.010] Yes. [36:38.510 --> 36:40.090] And map all things. [36:40.410 --> 36:42.690] It's basically, that's scanning problem countries. [36:43.730 --> 36:46.350] With everybody's favorite scan tool and map and other tools. [36:46.830 --> 36:49.710] I know Shodan kind of covers this ground, but it's not up to date. [36:50.150 --> 36:50.570] And... [36:50.570 --> 36:53.950] Shodan, unfortunately, doesn't let people contribute scan results. [36:53.950 --> 37:00.510] So there's a lot of duplication of work just because maybe someone has done it, but it hasn't matured. [37:00.690 --> 37:01.050] Yeah. [37:01.230 --> 37:10.330] So this is a list of about a dozen countries that are, we have, let's just say, good reason to believe, are highly censored using similar kind of equipment to what we saw in Syria. [37:10.670 --> 37:12.870] And, you know, so we've been doing those scans, right? [37:12.970 --> 37:16.230] But this is like, for a dozen countries, this is like a massive number of IPs. [37:16.330 --> 37:17.510] I think it's two million. [37:17.570 --> 37:19.150] I mean, these are tiny countries in general. [37:19.170 --> 37:22.430] But it's still two million, three million IPs for... [37:22.430 --> 37:25.070] that now need to start getting dug through by hand. [37:25.790 --> 37:27.850] And we, you know, you won't, maybe won't find a smoking gun. [37:28.010 --> 37:30.110] But this is how we spotted the blue coat device. [37:30.230 --> 37:31.630] It's how we have seen other censorship gear. [37:32.050 --> 37:38.050] It's not a perfect system, but it's collecting as much information as possible, analyzing it, and coming together and putting together what we know. [37:38.850 --> 37:39.350] What else? [37:39.910 --> 37:44.050] Data mining, algorithm help, data journalism sorting through data. [37:44.550 --> 37:46.170] Yeah, there's a lot of data coming out of these countries. [37:47.290 --> 37:49.930] Some of it has come out in the last couple of weeks out of Syria. [37:50.550 --> 37:52.830] But that data has been coming out of Syria for a while. [37:53.050 --> 37:54.530] And it's just kind of been sitting there. [37:54.730 --> 37:59.590] And if anybody knows any massive data things, come talk to us. [38:01.150 --> 38:01.970] There's lots of data. [38:02.330 --> 38:03.770] Jonathan Stray, this means you. [38:04.650 --> 38:12.990] There's also Project Streisand, which is where we set up mirrors of as much information as we can, hopefully faster than they get censored by everyone else. [38:13.930 --> 38:15.230] We do it with the Syria videos. [38:15.230 --> 38:17.030] We did it with the Egypt videos. [38:17.590 --> 38:19.370] We've done it with the Blue Coat logs. [38:19.670 --> 38:22.010] We hope to do it very soon with Project Blue Cabinet. [38:22.750 --> 38:28.930] We've done it in France, where some cop watch info got taken down by the French courts. [38:29.270 --> 38:32.170] Like, just like, we're not just the Mideast. [38:32.310 --> 38:32.950] Like, we will do this... [38:32.950 --> 38:33.530] Do it at NATO. [38:33.870 --> 38:34.410] Oh, yeah. [38:34.410 --> 38:35.670] For NATOprotest.org. [38:36.050 --> 38:36.190] Yeah. [38:36.190 --> 38:38.110] Like, we'll do this anywhere we can. [38:38.290 --> 38:39.170] Anywhere there's a threat. [38:39.490 --> 38:42.390] Like, we're going to try to be there, but we're limited. [38:42.650 --> 38:45.390] Like, there's only so many of us, and that's why we want your help. [38:45.690 --> 38:47.130] Some of us have to sleep sometimes. [38:47.290 --> 38:50.450] And maybe after 96 hours, but we do need sleep. [38:51.750 --> 38:55.390] Another thing is using satellite phones safely, so... [38:55.390 --> 38:57.310] Which sounds, I know, like a giant oxymoron. [38:57.490 --> 39:05.250] But we think we have some ideas there that could be translated into using the satellites far away from where your current location is and actually... [39:06.310 --> 39:18.530] Basically, the short answer is duct taping one phone to another phone or RF or some other things, which also can be, you know, tracked down, but using cable, even coax and running really long cables. [39:18.910 --> 39:19.050] Yeah. [39:20.170 --> 39:20.950] It's buying time. [39:21.190 --> 39:22.550] Yeah, there have been some... [39:22.550 --> 39:23.150] Because that is... [39:23.150 --> 39:23.870] I mean, nobody... [39:24.230 --> 39:25.290] Everybody, that's what we believe. [39:25.570 --> 39:30.190] I know there was definitely agents of telecomics that were on the phone with people with sat phones that suddenly were dead. [39:31.090 --> 39:36.850] And that not Maria Colvin, so to speak, but there were doctors that people were talking to, asking questions about technical stuff. [39:37.090 --> 39:39.750] Or people that knew that they were asking questions, they were talking to reporters. [39:40.370 --> 39:41.050] I'm a little... [39:41.750 --> 39:47.230] I know of one specific case, and it was, I think, a French news reporter talking to a doctor out of Syria. [39:47.710 --> 39:48.930] And all of a sudden, he was gone. [39:49.070 --> 39:51.830] And then a report came out a couple days later, he was dead because they dropped shells on him. [39:52.210 --> 39:54.730] It's not conclusive proof, but we really believe that to be... [39:54.730 --> 39:59.470] They were using RF gear to triangulate the signals and drop artillery on people. [39:59.710 --> 40:00.050] Okay. [40:00.550 --> 40:01.090] A couple more things. [40:01.550 --> 40:02.270] Blue Cabinet help. [40:03.590 --> 40:06.630] Also help with creating anti-malware, discovering malware. [40:06.850 --> 40:11.690] That was, you know, something that came together amazingly during Syria when the Dark Homet stuff was found. [40:11.870 --> 40:12.730] And they've moved on. [40:12.850 --> 40:15.050] They've started purchasing off the shelf. [40:16.530 --> 40:21.050] It all goes back to one IP, command and control server usually, and uses one name. [40:21.370 --> 40:25.850] But you can tell they're following, like, they're following the manufacturer's list of how to set this up. [40:26.010 --> 40:30.410] And it's not the most technical operation, but it is getting people in Syria to track down. [40:30.690 --> 40:33.830] Yeah, we have a pretty nice collection of malware we've collected in the past year or so. [40:33.970 --> 40:42.750] We have everything from malware, which is designed to wiretap both sides of a Skype conversation, before the outgoing is encrypted and after the incoming is decrypted. [40:42.750 --> 40:44.490] We've found rats. [40:44.750 --> 40:52.230] We have found malware, which tries to trace a physical location of a server based upon the wireless access point and whatever else is around it. [40:52.610 --> 40:53.790] We've got a pretty good collection. [40:54.070 --> 40:58.090] And we've spent a long time reverse engineering it, figuring out how it works. [40:58.250 --> 41:03.010] We've devised a couple of ways of uninstalling it if you think you're infected. [41:03.250 --> 41:06.950] We've trained people on how to determine whether or not they've been hit with it. [41:07.210 --> 41:11.850] We've given people security tips on if you suddenly see a window for... [41:11.850 --> 41:19.970] If you suddenly get a notification about this brand new zero day in Windows, and you have to install this now, chances are it may not be. [41:20.990 --> 41:21.830] Things like that. [41:22.850 --> 41:26.790] I guess the other last, you know, like in other terms of new projects is new countries. [41:27.030 --> 41:29.350] We just launched an op for Sudan. [41:29.690 --> 41:35.590] I got a ping just a couple of days about the Maldives, which is a collection of 24 atolls off the coast of India. [41:35.590 --> 41:38.010] They're going to need inter-island communication. [41:38.690 --> 41:40.410] So I don't know, semaphores and big reflective mirrors. [41:40.570 --> 41:40.930] Like, whatever. [41:41.490 --> 41:43.910] I'm thinking QR codes and webcams. [41:44.630 --> 41:49.730] And the nice thing is, with a 4096-bit QR code, you can, in theory, do NFS with jumbo frames. [41:51.170 --> 41:52.290] But yeah, like... [41:52.290 --> 41:54.470] And if you guys got stuff you're interested in, just show up. [41:54.690 --> 41:57.410] And, you know, if you find collaborators, it gets done. [41:57.590 --> 41:59.910] And, you know, if you don't, it doesn't. [41:59.910 --> 42:00.710] And that's just... [42:00.710 --> 42:01.530] It's that simple. [42:01.910 --> 42:02.730] Yeah, just go do stuff. [42:03.010 --> 42:05.290] No idea is too batshit insane. [42:06.590 --> 42:06.810] Okay. [42:08.130 --> 42:08.490] And... [42:08.490 --> 42:09.530] Should we take some questions? [42:09.770 --> 42:09.910] Yeah. [42:10.130 --> 42:10.810] Should we take some questions? [42:11.070 --> 42:11.650] There's a mic up here. [42:14.230 --> 42:15.530] Or just speak real loud. [42:15.670 --> 42:17.070] But if you can use the mic, that'd be better. [42:33.140 --> 42:34.080] So the general... [42:34.080 --> 42:34.520] Hang on a second. [42:34.700 --> 42:35.560] Will you repeat the question? [42:36.340 --> 42:36.700] Because... [42:36.700 --> 42:37.540] We'd like to... [42:37.540 --> 42:41.160] It was advised that we repeat your question because you're not at the mic and we'd like it to be on the recording. [42:41.160 --> 42:43.140] Your question was how have... [42:43.140 --> 42:49.080] How effective have Tor and other technologies been actually in the field in dangerous situation? [42:49.260 --> 42:49.640] Is that correct? [42:49.940 --> 42:50.180] Yeah. [42:50.360 --> 42:50.700] Okay. [42:50.960 --> 42:51.220] All right. [42:51.340 --> 42:52.300] So I'll take this one. [42:52.460 --> 42:54.340] The short answer is Tor works. [42:54.460 --> 42:54.980] Works well. [42:55.420 --> 42:56.640] People's complaint is it's slow. [42:56.940 --> 42:58.460] But a lot of things are slow in Syria. [42:58.580 --> 43:07.520] We believe it's because they're using under spec DPI gear that they got resold and it's mainly meant for commercial services, not for a high speed carrier grade or the entire country. [43:09.340 --> 43:10.820] There are VPNs. [43:11.580 --> 43:13.020] Open VPN is blocked. [43:14.180 --> 43:16.020] PPTP, which is unsecure, is blocked. [43:16.200 --> 43:17.100] IPsec is blocked. [43:17.280 --> 43:19.560] Those are blocked at the protocol level by Cisco firewalls. [43:21.340 --> 43:22.960] And also by DPI gear. [43:25.480 --> 43:28.240] The other aspect, it's slow. [43:28.460 --> 43:33.360] Basically, it makes it look as much like SSL as you can, it works. [43:33.540 --> 43:39.180] They're not as advanced as a RAM, but they do detect new things and they do block things. [43:40.060 --> 43:42.120] BindFartor is the most popular tool. [43:42.560 --> 43:44.560] But like I said, everybody complains it's so slow. [43:47.400 --> 43:49.520] But the way to make that faster is more nodes. [43:50.280 --> 43:54.800] Part of it, but that is true, but part of it is that they are slowing down any encrypted traffic. [43:55.380 --> 43:58.660] So, and they also, they've seen, they'll send interrupts. [43:58.720 --> 44:02.460] They'll do other things if it's a long-term SSL connection. [44:03.100 --> 44:04.980] If you guys have questions, please queue at the mic. [44:12.980 --> 44:16.920] First off, you did a really good work and you have a model of open participation. [44:18.000 --> 44:20.900] So on one hand, part of the work you've done is you've built up a name. [44:21.080 --> 44:22.460] You've built up a brand that people trust. [44:22.900 --> 44:27.800] Have you had experience with people trying to misappropriate your name who are adversaries? [44:27.860 --> 44:29.620] And are you worried about that in the future? [44:30.380 --> 44:31.820] I wouldn't say adversaries. [44:31.820 --> 44:32.260] Yeah. [44:32.260 --> 44:38.420] But people have, since it is such a loose connection, people have taken stuff where the group consensus is not where to go. [44:39.560 --> 44:42.120] There are, like every group, there is some internal politics. [44:42.240 --> 44:46.760] But in general, we all seem to be, as long as we remind ourselves of the main mission, we move forward. [44:47.120 --> 44:50.720] But I mean, like you were saying, like, suspected Syrian agents are on, like... [44:50.720 --> 44:51.540] No, they haven't. [44:51.680 --> 44:52.500] Yeah, nothing like that. [44:52.620 --> 44:53.480] No, no, they have not. [44:53.700 --> 44:55.560] They've just ignored the Internet, by and large. [44:55.680 --> 45:01.620] Do you think there's a threat that someone could set up, fake telecomics? [45:01.820 --> 45:10.320] I mean, honestly, honestly, the biggest problem we've had along those lines is somebody in the States using our name and my name, personally, to scam money out of people. [45:11.200 --> 45:11.680] Yeah. [45:12.080 --> 45:13.340] So that's why we're no money. [45:13.780 --> 45:14.040] Yeah. [45:14.200 --> 45:14.740] No money at all. [45:15.180 --> 45:15.400] Yeah. [45:15.500 --> 45:16.420] Everything is donated. [45:16.600 --> 45:17.500] Everything is volunteered. [45:17.760 --> 45:20.640] Everything from servers to bandwidth to time to effort. [45:22.740 --> 45:34.680] I'm just wondering what you guys think some of the most important kind of skills to pick up are that are most effective at accomplishing some of these goals? [45:34.840 --> 45:36.780] Like specific tools and... [45:37.160 --> 45:39.060] I mean, I'm not a hacker. [45:39.220 --> 45:40.000] I'm not a coder. [45:40.180 --> 45:41.560] I'm the worst at a lot of things. [45:41.720 --> 45:43.260] I do more of an analysis side. [45:43.720 --> 45:44.920] It's whatever you can bring to the table. [45:44.920 --> 45:48.320] We'll teach you everything we know as much as possible. [45:49.040 --> 45:49.420] But... [45:49.800 --> 45:51.940] We would very much like to learn from anything you want to teach. [45:52.200 --> 45:52.600] It's not like there's a set of skills. [45:52.640 --> 45:53.980] We're weak in C coders. [45:54.120 --> 45:56.280] So if you can write awesome C, come on. [45:56.400 --> 45:56.780] Talk to us. [45:57.120 --> 45:59.120] If you can reverse engineer, come join us. [45:59.280 --> 46:04.740] If you're good at figuring out what facts mean and where they came from and how much you can trust them, come join us. [46:06.360 --> 46:06.740] Anything. [46:06.880 --> 46:07.200] Any skills. [46:07.280 --> 46:07.520] Anything. [46:08.640 --> 46:16.900] If you know media, if you have media contacts and you can help get stories out and get video footage into the right hands to raise awareness, we need ya. [46:17.100 --> 46:18.360] If you can translate. [46:18.780 --> 46:19.140] Yes. [46:20.480 --> 46:20.720] Arabic. [46:21.260 --> 46:21.660] Farsi. [46:22.300 --> 46:25.120] Really, like, a lot of our people are not technical at all. [46:25.340 --> 46:28.180] Like, you just need a passion for the Internet and we will... [46:28.180 --> 46:30.560] We won't tell you what to do, but we will help you find something. [46:30.660 --> 46:36.920] I guarantee you, no matter who you are, you have some skill that the rest of us don't and there is a place for it. [46:37.120 --> 46:37.440] Yes. [46:37.620 --> 46:51.820] I appreciate these answers because it's really important for everyone to know that it's open for all sorts of skills, but I'm sure that there are some tools that are particularly useful from a technical perspective and I'm just trying to find out what they are. [46:52.540 --> 46:53.240] Practically anything. [46:53.580 --> 46:56.120] The other thing is that we use a lot of other people's tools. [46:56.680 --> 46:56.760] Yeah. [46:56.760 --> 46:57.900] So, I mean... [46:57.900 --> 47:04.080] I mean, it's important to have a good working knowledge of, you know, how SSL works, for instance. [47:04.540 --> 47:12.980] You know, you want to know what the strengths and the drawbacks of tools like Tor and MixMaster and OpenVPN and stuff like that are. [47:13.680 --> 47:15.600] Because, you know, you don't want to give people bad advice. [47:15.760 --> 47:19.080] But that said, it's also just as useful to know... [47:19.840 --> 47:21.720] You don't have to know a fact. [47:21.800 --> 47:22.920] You just have to know who to ask. [47:23.740 --> 47:25.380] And who to ask is the channel. [47:25.820 --> 47:26.220] Yeah. [47:26.360 --> 47:36.200] And if you're good at teaching, if you're good at taking a body of knowledge of some kind and then explaining it to people in a way that they understand it and they can start applying it on their own, we need help with that too. [47:36.200 --> 47:49.000] Because we only have a limited number of teachers and I think a given class on Tor or GPG or something tops out at about 25 to 30 people before the traffic in the channel makes it unfeasible. [47:49.000 --> 47:50.980] So, if... [47:50.980 --> 47:54.220] Or even responding to responses at 3 am U.S. time. [47:54.400 --> 47:55.700] You know, there's different time zones. [47:55.980 --> 48:03.620] I was keeping, I was doing basically 72 hour or more shifts at one point when Obseria was really bad. [48:04.260 --> 48:07.500] And keeping really weird hours because of just the time zone differences. [48:07.980 --> 48:10.500] So, the more people that can be around, it helps. [48:10.640 --> 48:11.520] More heads on in general. [48:11.640 --> 48:17.440] I mean, even down, even when we were doing stuff at NATO doing information support, people to help press radio buttons and just simple stuff. [48:17.440 --> 48:19.020] So, the whole broad scale of skills. [48:19.520 --> 48:19.620] Okay. [48:19.860 --> 48:21.220] People that can help fact check. [48:21.720 --> 48:24.300] Like, if we say, we just heard this, can you verify it? [48:24.560 --> 48:29.880] Go out, get whatever information is out there to either confirm or refute it, get back to us, yay or nay. [48:31.320 --> 48:35.020] Are you sharing those malware samples with the anti-mower industry at all? [48:36.040 --> 48:37.220] A few of us have been. [48:37.380 --> 48:38.540] A few of us have contacts there. [48:38.540 --> 48:45.860] The problem is that, that group can sometimes be very, there's, people are very scared to share sources and methodhoods. [48:46.100 --> 48:48.300] Because it is, it's become like open-source intelligence. [48:48.720 --> 48:55.720] So, there is a, inside the malware, not even in the industry, and the people who are studying this, there isn't as much sharing as it could be. [48:56.180 --> 48:57.820] Because they don't, they don't want data leaks. [48:57.880 --> 48:59.800] Or they feel sometimes the telecomic is too open. [49:00.520 --> 49:00.840] Yeah. [49:01.800 --> 49:09.280] There's also the fact that a few people in the malware, or excuse me, in the anti-malware industry may well be agents of telecomics, and we don't know it. [49:09.660 --> 49:09.980] Yeah. [49:11.300 --> 49:11.620] Yeah. [49:12.000 --> 49:13.800] Like, some of our dudes are anonymous too. [49:14.000 --> 49:14.260] Right? [49:14.280 --> 49:15.220] It's not just the Syrians. [49:15.460 --> 49:15.860] Like, whatever. [49:16.000 --> 49:17.280] You just want to show up and do good work? [49:17.300 --> 49:18.100] Like, we'll take it. [49:18.280 --> 49:21.760] I worked with him directly for like three months, and had no idea who the hell he was. [49:21.900 --> 49:25.960] Yeah, I showed up in Chicago and met him, and I'm like, hey, have you ever met, you know? [49:26.380 --> 49:27.920] And he's like, oh, that's me. [49:28.020 --> 49:28.400] Blah, blah, blah. [49:28.580 --> 49:29.160] Like, oh, yeah. [49:29.300 --> 49:31.480] You and I have known each other for a couple years now. [49:31.820 --> 49:32.140] And... [49:32.140 --> 49:32.580] Oh, yeah. [49:32.740 --> 49:33.140] That's right. [49:33.160 --> 49:33.380] Yeah. [49:33.380 --> 49:35.320] We met five years ago, maybe six years ago. [49:35.420 --> 49:38.480] And I think I realized, like, last September who you actually were. [49:39.520 --> 49:39.960] Okay. [49:40.640 --> 49:44.000] Well, as a matter of full disclosure, I work for the anti-mower industry. [49:44.320 --> 49:44.340] Okay. [49:44.340 --> 49:50.240] And recently, I saw some blog post on, I don't know, some Trojanized toolkit on whatever. [49:50.680 --> 49:53.820] Anyway, maybe what's from Citizen Lab or whatever it was. [49:54.020 --> 49:58.580] And when I checked that, I found that we actually initially had that sample in like 2010. [49:59.220 --> 50:00.660] And they thought it was very new. [50:01.160 --> 50:04.500] So, I think it's definitely something to think about maybe a bit more. [50:04.500 --> 50:07.940] Because, obviously, if I can, I want to add detection for that stuff. [50:07.940 --> 50:11.780] So, people realize that they are downloading bad stuff. [50:12.080 --> 50:12.480] Definitely. [50:12.880 --> 50:12.980] All right. [50:13.060 --> 50:13.740] Talk to us. [50:13.860 --> 50:15.260] We definitely have samples. [50:15.420 --> 50:16.100] And again, you're right. [50:16.160 --> 50:17.060] A lot of it is a lot. [50:17.200 --> 50:18.860] But it's still infecting people. [50:19.120 --> 50:19.680] I don't know. [50:19.820 --> 50:20.160] I don't know. [50:20.440 --> 50:21.280] It just happens. [50:21.580 --> 50:22.280] People don't patch. [50:22.700 --> 50:23.520] People don't patch. [50:23.820 --> 50:25.700] Or people will click on any link you send them. [50:25.700 --> 50:36.520] China has millions of installations, you know, pirated installations of XP that, you know, are never going to get patched up to modern standards. [50:36.780 --> 50:37.800] And Siri as well. [50:38.080 --> 50:43.700] If we're talking about Siri in particular, a lot of pirated software and, you know, sketchy downloads. [50:43.700 --> 50:52.020] And they're so desperate to get their message out or get their voice out, they'll take a lot of chances that are really ill-advised. [50:52.720 --> 50:58.480] You know, software that will secure Skype, they're very concerned because they've heard Skype's been hacked. [50:58.820 --> 51:02.360] And we don't encourage them to use Skype, but they do because it works. [51:03.140 --> 51:04.740] And they feel this will make them safer. [51:04.980 --> 51:06.040] And it gets them. [51:06.140 --> 51:06.660] They get hacked. [51:06.940 --> 51:08.040] And then their friends get hacked. [51:08.180 --> 51:08.760] And then... [51:08.760 --> 51:10.000] Or Facebook accounts or stuff like that. [51:12.320 --> 51:12.640] Yeah. [51:12.740 --> 51:13.040] Okay. [51:13.260 --> 51:13.360] Yeah. [51:13.780 --> 51:14.760] So, we got to wrap up. [51:14.920 --> 51:15.160] Yeah. [51:15.160 --> 51:16.580] There's a bunch of stickers on the water table. [51:16.700 --> 51:17.160] Come find us. [51:17.200 --> 51:17.780] We've got more. [51:17.940 --> 51:19.900] And we're always willing to talk and answer questions. [51:20.180 --> 51:20.300] Yeah. [51:20.640 --> 51:21.320] Thank you so much. [51:21.720 --> 51:22.000] Yeah. [51:28.800 --> 51:29.360] Thank you. [51:29.380 --> 51:30.480] Thank you very much. [51:30.480 --> 51:30.980] Thank you very much. [51:30.980 --> 51:31.160] Thank you very much. [51:31.180 --> 51:31.200] Thank you very much. [51:31.200 --> 51:31.360] Thank you very much. [51:31.360 --> 51:31.440] Thank you very much. [51:31.440 --> 51:31.480] Thank you very much.