[00:00.000 --> 00:03.020] I'm going to go run and find him a Mac dongle, but he's going to start his talk. [00:03.300 --> 00:03.620] Have fun. [00:05.900 --> 00:06.600] Thank you. [00:15.230 --> 00:15.990] Right on. [00:16.690 --> 00:16.910] Yes. [00:17.670 --> 00:18.070] Okay. [00:18.870 --> 00:19.890] Please give me a moment. [00:20.030 --> 00:23.230] I'm just going to plug this thing in and we'll be in business. [00:38.620 --> 00:39.280] All right. [00:44.610 --> 00:45.150] All right. [00:45.350 --> 00:45.490] Cool. [00:45.710 --> 00:46.970] Thank you, everyone, for coming. [00:49.070 --> 00:56.630] I would like to start by saying a word about Len Sassaman, for whom this room is named today. [00:56.930 --> 01:01.430] I first met Len at the 27C3 conference in Berlin. [01:02.130 --> 01:05.130] And when he came up and spoke to me, I didn't really even know who he was. [01:05.130 --> 01:09.870] And it took me quite a while to figure out that I had had this really amazing conversation with him. [01:12.030 --> 01:16.570] I hadn't heard anyone else sort of say something about that. [01:16.710 --> 01:25.170] So I just thought I would start off my talk by mentioning Len and remembering him and all of the work that he did for privacy and security research. [01:28.190 --> 01:31.190] So my talk today is called Privacy by Design. [01:32.590 --> 01:39.350] The subtitle is a dream for a telecommunications provider that uses strong cryptography to ensure your privacy. [01:43.630 --> 01:48.550] To start off with a little bit of background information. [01:49.890 --> 01:52.570] I am a native New Yorker. [01:52.870 --> 01:55.010] I grew up in Manhattan. [01:55.650 --> 02:04.130] And when I was a kid, 2600 held these meetings at the City Court building in Midtown. [02:06.790 --> 02:11.070] And I used to go, starting from when I was around a freshman in high school. [02:11.810 --> 02:16.830] And I met a lot of really interesting people, some of whom later became infamous. [02:17.770 --> 02:23.190] I was introduced to a lot of kind of free-thinking concepts that weren't taught in school. [02:24.430 --> 02:27.450] And I felt like I should kind of acknowledge that. [02:28.850 --> 02:34.290] Because it's not like it's the only thing that influenced me, but it was something that sort of added to my world view. [02:35.150 --> 02:38.010] And kind of helps explain a little bit about my background. [02:38.670 --> 02:40.470] And how I got where I am now. [02:41.870 --> 02:55.690] And around 1994, when there was a change made, there was a policy change made, with regard to the Internet, which had been run by the National Science Foundation and different parts of the government, a change was made. [02:56.390 --> 02:58.910] And this was where they said that Al Gore invented the Internet. [02:59.890 --> 03:05.270] What that really meant, though, was that commercial traffic became allowed on the Internet for the first time. [03:05.930 --> 03:09.790] Prior to that, it was only research and education materials allowed. [03:11.370 --> 03:13.590] I kind of saw the writing on the wall at that point. [03:13.710 --> 03:15.890] I thought that there was going to be a big change. [03:15.890 --> 03:21.330] And being an idealistic kid, I thought that... [03:22.250 --> 03:29.570] I remember thinking that the hurdle, the barrier to entry, to get into media in any other way, was just tremendous. [03:29.890 --> 03:35.330] If you wanted to get into radio or television, you had to buy these multi-million dollar licenses. [03:36.090 --> 03:39.030] And there was also a limited number of them. [03:39.190 --> 03:40.530] They were all grandfathered in. [03:40.630 --> 03:41.470] There were no more issued. [03:41.810 --> 03:54.770] And I remember thinking, wow, this is something that can propel you to a level where you can broadcast to everyone, but with basically no money and no supervision and no FCC and no regulation, for the most part. [03:56.130 --> 03:57.830] It was a very exciting time. [03:58.030 --> 04:05.030] And I started working with a lot of NGOs and non-profits that were doing stuff that I thought was interesting. [04:06.330 --> 04:16.550] And around 1997, I had been doing work with NGOs and non-profits, and I met some Dutch people that were doing basically the exact same work that I was doing. [04:16.970 --> 04:21.450] And we had this kind of idea, like, why are we doing the same thing in parallel? [04:21.570 --> 04:22.410] Why don't we team up? [04:23.090 --> 04:31.070] So I started to work with Dutch guys who were also working with the same group of NGOs that I was working with, but in Europe. [04:32.970 --> 04:41.190] Later, a guy whose name you might know if you're a real 2600 reader and you check out the masthead, there's a guy on the masthead called Bill SF. [04:41.730 --> 04:43.170] His name is Bill Squire. [04:43.350 --> 04:48.110] He's a guy from San Francisco who moved to Amsterdam like 25, 30 years ago. [04:48.670 --> 04:50.230] Really amazing hacker. [04:50.470 --> 04:51.190] Really amazing guy. [04:51.450 --> 04:58.530] He ended up becoming part of the company, and that really kind of added to the culture, so to speak. [05:00.950 --> 05:06.190] In 2004, I ended up getting a strange phone call. [05:08.470 --> 05:11.110] The phone rang one day when I was sitting at my desk. [05:11.130 --> 05:14.870] I picked it up, and the caller said they were calling from the FBI, and they had a letter for me. [05:16.930 --> 05:19.210] I said, okay, thanks, and I hung up. [05:19.590 --> 05:24.770] And I kind of assumed that maybe I would get something in the mail in the next week or so. [05:25.530 --> 05:31.970] But very soon after, there was a knock on the door, like a real heavy, you know, like serious, you know, authority knock. [05:32.830 --> 05:35.530] And when I opened the door, there was an actual agent there. [05:36.550 --> 05:37.630] The agent came in. [05:37.850 --> 05:38.610] They gave me this letter. [05:39.390 --> 05:54.030] And I opened the letter in the presence of the agent, and the letter demanded that I hand over just tons of information, reams of information, about one of the clients of the Internet provider, which at this time was more of a hosting company and security consultancy. [05:56.170 --> 06:09.910] Rather than hand over the information, I ended up getting caught up in a whole legal battle against the PATRIOT Act and against a specific provision of the PATRIOT Act called the National Security Letters Provision. [06:11.870 --> 06:19.670] The case was originally filed under seal, and nobody knew what the name of it was or who the plaintiff was or what it was about. [06:20.370 --> 06:24.510] This was due to the non-disclosure provision that came with the letter. [06:24.650 --> 06:27.710] The letter said that I could never tell anyone that I had been approached, ever. [06:29.330 --> 06:33.250] And when the agent was standing before me in my office, I said to the agent... [06:34.250 --> 06:36.430] And you'll notice that I say the agent. [06:36.470 --> 06:37.490] I don't say he or she. [06:37.730 --> 06:43.070] There's reasons for this because I'm still mostly under a non-disclosure thing now. [06:43.970 --> 06:52.830] And one of the details that I'm not supposed to disclose is the gender of the agent or what field office they came from or what day they came from or all kinds of mundane little bits of information. [06:53.330 --> 07:01.390] In any case, when I got the letter open and I got to the third or the fourth paragraph and I said I could never tell anyone, I said to the agent, what about my lawyer? [07:02.170 --> 07:03.290] And that was like... [07:03.290 --> 07:09.290] I kind of went right to the crux of the problem with this letter, like on my first speed reading of it. [07:11.170 --> 07:13.470] The case ended up lasting so long. [07:13.570 --> 07:17.830] It started in 2004 and it kind of was half-resolved in 2010. [07:18.390 --> 07:21.910] All through that time, I never told anyone that I was involved in this case. [07:22.690 --> 07:32.070] Not my business partners, not my clients, not my colleagues, not my friends, not my girlfriends, not my girlfriends, not my... [07:33.310 --> 07:34.830] really anyone but my lawyers. [07:37.190 --> 07:53.990] It was a really bizarre experience, very kind of Kafkaesque and surreal because it was in the news a lot and people that I knew would talk about the case because it resulted in the National Security Letter provision of the Patriot Act being ruled unconstitutional two times. [07:55.110 --> 08:02.750] So people were talking about it but it was always written up as anonymous ISP suing the government and nobody knew it was me. [08:02.890 --> 08:04.890] And sometimes people would ask, you know, is that you? [08:05.290 --> 08:06.350] And I just... [08:06.350 --> 08:13.270] I was basically forced to lie because if you say no comment, that kind of encourages people to ask more questions. [08:16.370 --> 08:22.430] In 2006, they modified the Patriot Act in response to the judge ruling it unconstitutional. [08:22.650 --> 08:28.510] It turned out that the NSL provision violates the First Amendment and the Fourth Amendment and the Fifth Amendment. [08:28.930 --> 08:40.550] The First Amendment being, you know, freedom of speech and that's because it came with this open-ended gag order that they didn't go to a judge to get permission for. [08:41.430 --> 08:47.310] The Fourth Amendment because it's a search without getting permission from a judge and proving probable cause. [08:47.470 --> 08:49.590] And the Fifth Amendment because there was no way to challenge it. [08:51.630 --> 08:53.390] The letter said, I can never tell anyone. [08:53.410 --> 08:54.810] That would mean you can't tell a lawyer. [08:54.990 --> 08:56.570] That would mean you can't tell the court clerk. [08:56.710 --> 08:57.850] That would mean you can't tell a judge. [08:57.850 --> 09:03.110] And you can't tell anyone, then you can't exercise your right to go to court and challenge it. [09:03.690 --> 09:06.790] Of course I did, so then they had to modify the law. [09:07.010 --> 09:10.890] That was actually the huge victory of the case. [09:11.270 --> 09:17.030] What happened after that, though, is that it ended up dragging out for years, and we argued and argued about First Amendment issues. [09:18.050 --> 09:24.870] And I kept trying to get out of the gag, which I partially did, only got my toe in the door in 2010. [09:24.870 --> 09:29.050] But it brings me to the point where I can sort of talk about my experience now. [09:30.790 --> 09:35.170] In 2007, despite being under the gag, I wrote an op-ed in the Washington Post. [09:36.190 --> 09:39.350] It was the first op-ed that the Post had ever published, as far as I know. [09:40.370 --> 09:42.710] It was called My National Security Letter Gag Order. [09:43.290 --> 09:45.070] And you can easily pull it up on Google. [09:47.490 --> 09:50.630] Because I didn't identify myself, it was cool. [09:51.390 --> 09:54.630] But it was really a super surreal thing. [09:55.370 --> 09:57.350] Because again, a lot of people were talking about it. [09:57.590 --> 09:58.930] It itself got coverage. [09:59.850 --> 10:02.990] The Washington Post policy is never to publish anonymous pieces. [10:03.230 --> 10:07.350] But they made an exception in this case, because they had spoken to my lawyers. [10:07.610 --> 10:10.230] And they knew that it was the real deal. [10:10.290 --> 10:12.170] And that I wanted to identify myself, but I couldn't. [10:13.210 --> 10:19.650] So then in 2010, I was partially released from the gag in August. [10:20.530 --> 10:29.070] And that winter, I flew to Berlin and I gave a talk there about my whole battle against NSLs. [10:30.710 --> 10:37.330] I don't want to go too far into the whole story of the National Security Letter Challenge, because I've spoken about it in the past. [10:37.490 --> 10:45.190] And if you really want to see me speak at length about it, you can look up my talk at 27C3, which is like on YouTube and various places. [10:47.870 --> 10:52.730] There's a few press clippings about the case. [10:53.430 --> 10:57.510] I have like a hundred of them, but this was just a few that I had sitting on my hard drive somewhere. [10:59.610 --> 11:02.250] There's an op-ed and a couple of random articles. [11:04.970 --> 11:11.090] Another amazing thing that came out of this case was that the Department of Justice ended up doing audits of its own use of national security letters. [11:13.650 --> 11:18.010] It actually did end up uncovering that there was massive abuse of them. [11:20.250 --> 11:25.430] The FBI hadn't apparently kept records of how many of them they had handed out. [11:27.270 --> 11:39.730] They claimed they undercounted by 22%, which I found strange because if they didn't keep records of them, I was curious how they came up with such an exact figure as 22%. [11:42.830 --> 11:49.770] What happened after that was the head of the FBI got called before Congress and really got grilled by both sides. [11:50.270 --> 11:52.530] The Republicans were screaming at him as much as the Democrats. [11:55.930 --> 12:08.050] There turned out that there was a procedure the FBI office in New York was using in which they were issuing letters called exigent letters, which were basically saying something like, we'll come back next week with a national security letter, we promise, [12:08.330 --> 12:09.670] but just give us all this data now. [12:09.930 --> 12:14.750] There's a really terrible emergency and the sky is falling and something really bad is going to happen, so just give it to us. [12:14.750 --> 12:17.550] And all the phone companies are just saying, okay, okay, here you go. [12:17.990 --> 12:21.730] It turned out in basically all these cases that there was no such emergency. [12:21.970 --> 12:24.510] They were just kind of making stuff up as they went along. [12:25.530 --> 12:31.210] Unfortunately, there were no real repercussions from all these revelations. [12:31.210 --> 12:38.730] As far as I know, you know, FBI said they were going to handle it somehow internally and nobody knows exactly what happened. [12:41.730 --> 12:47.450] EFF and ACLU ended up doing a ton of Freedom of Information Act requests and uncovered a lot of information. [12:47.450 --> 12:59.770] And I encourage you, if you're interested, to, you know, go look at these reports that they produced on their site, just talking about the abuses, talking about agents coming with post-it notes and getting tons of information with a post-it note. [13:02.270 --> 13:07.350] Some question that, you know, I had a lot of time to think about what happened afterwards. [13:07.750 --> 13:12.070] You know, it took me years to understand that... [13:13.950 --> 13:18.190] I thought that other companies were probably behind the scenes doing similar things to what I was doing. [13:18.330 --> 13:19.270] I found out that they weren't. [13:19.270 --> 13:22.530] I didn't understand why, and I gave it a lot of thought. [13:22.690 --> 13:24.250] I actually sat there thinking, why? [13:25.010 --> 13:26.730] Why did they all just go along with this? [13:27.690 --> 13:38.850] Some of the reasons that I came up with that seemed obvious, if you think back to the time of, like, the beginning of the War on Terror and all the hysteria that was going on, that there was a great fear of PR backlash. [13:40.130 --> 13:49.770] Companies were worried that if it was known that they were questioning or resisting stuff that the government was doing, that customers would get angry at them and walk out or boycott them. [13:51.030 --> 13:59.670] Obviously, there's sort of a vested interest there in terms of that a lot of companies, the big telcos, have a lot of government contracts that are worth a ton of money. [14:00.310 --> 14:05.230] So that's clearly a conflict of interest that might influence them in one way or another. [14:06.410 --> 14:15.810] Also, if you know much about the telcos and the security people there, there is somewhat of an overlap between top security officials at the telcos and ex-law enforcement. [14:15.950 --> 14:24.810] There's a lot of ex-FBI people and ex-police who are the people who are actually receiving national security letters and other requests for warrantless wiretapping. [14:24.810 --> 14:29.430] So there was kind of like a buddy-buddy thing going on. [14:31.370 --> 14:42.230] According to the FBI general counsel, former general counsel, Valerie Caproni, she says that they felt it was good corporate citizenship to go along with whatever the government asked of them. [14:42.930 --> 14:44.270] I guess that's possible. [14:45.450 --> 15:00.390] I was offended by this letter because from what I knew, which I can't disclose, it was obvious to me that there was no basis for this demand for this info, and that the underlying investigation was bogus. [15:01.150 --> 15:07.550] Unfortunately, I can't tell you why, because of the ongoing non-disclosure stuff, which, you know, dates from 2004. [15:07.790 --> 15:10.470] It's now 2012, but I'm still not allowed to talk about it. [15:12.690 --> 15:17.650] The last thing that happened when I went to court to challenge the non-disclosure provision, that was in 2009. [15:19.270 --> 15:24.010] The FBI showed secret evidence to the judge, somehow justifying that the gag go on. [15:24.570 --> 15:27.510] But I never got to see what it was, and my lawyers didn't get to see it either. [15:27.990 --> 15:32.710] So we couldn't really make a counter-argument since we couldn't see what it was. [15:35.430 --> 15:37.870] Later, the NSA spying scandal was revealed. [15:39.750 --> 15:41.330] I'm sure you guys all know the story. [15:42.430 --> 15:54.710] You know, the technician at the AT&T central office blew the whistle that he saw these guys going into this secret room, and the guys weren't union, and he was pissed off originally about some union issue. [15:55.470 --> 16:00.850] But then the more he dug, the more he found out that it was a thing where they were splitting the fiber. [16:00.850 --> 16:02.670] I'm sure you all know the story, so... [16:03.390 --> 16:08.450] But this is kind of the background on what brought me to the place that I'm at today. [16:08.630 --> 16:18.570] I was really offended by this, and I was really offended that I worked so hard to comply with the law, and not break the law, and not disclose things that I wasn't supposed to disclose for so many years. [16:18.610 --> 16:23.290] And then when all these telcos broke the law, they were all just given retroactive immunity. [16:23.290 --> 16:25.570] That really offended me also. [16:27.410 --> 16:36.410] I found out only in 2010 or 2011 that when I showed up at the ACLU's office with this national security letter, it was the first one that they had ever seen. [16:38.950 --> 16:40.690] There were a few notable exceptions. [16:41.570 --> 16:47.410] Quest refused to go along with the National Security Agency's spying program. [16:48.490 --> 16:51.690] Somehow the CEO of Quest then subsequently ended up in prison. [16:52.470 --> 16:55.450] I always wondered what the deal was with that. [16:57.370 --> 17:07.650] SonicNet, as you guys all probably know, questioned a national security letter that they had gotten, which allegedly had something to do with Jake Applebaum. [17:08.870 --> 17:16.650] But for the most part, no telco really has come forward to talk about what's going on. [17:18.710 --> 17:25.470] And even the ones that have said something like Quest and like Sonic haven't really done something to stop it. [17:25.670 --> 17:28.890] That was what I felt like was the most important thing to do. [17:28.970 --> 17:37.150] That was why I ended up going to court against the government, trying to overturn this part of the Patriot Act and actually trying to challenge the constitutionality of these practices. [17:38.450 --> 17:47.170] Simply just not going along is worthwhile and it's a brave act, but it doesn't change the big picture, which was always what I was after. [17:48.830 --> 18:06.590] In the wake of my sort of disappointment from not being able to change everything, I started to think about what else could I do because the law of diminishing returns became quickly apparent to me that the scope of the case that I was involved in was extremely wide at first and then it got narrower and narrower. [18:06.750 --> 18:08.990] And by the end, we were just talking about my First Amendment rights. [18:10.150 --> 18:22.850] Something else that also became apparent to me was that ACLU and EFF are really out there on the forefront, but their hands are somewhat tied if no one's going to come forward, talk about what's going on, and then be willing to challenge it along with them. [18:25.890 --> 18:33.390] In the National Security Letter case, a couple of years into it, another plaintiff also challenged the National Security Letter. [18:34.070 --> 18:41.150] At the time, I didn't know who it was, and it took a few years before it became apparent who the other plaintiff was. [18:45.070 --> 18:51.470] Most of the time that I was in the case with them, they were just known as John Doe, Connecticut, and they were calling me John Doe, New York. [18:52.750 --> 18:55.450] Later, it turned out that they were a bunch of librarians from Connecticut. [18:56.610 --> 19:11.010] This was like an extra juicy, ironic piece of info because the American Library Association had been going on talking about how the Patriot Act and Section 215 and the National Security Letter provisions could be used to get library patron information. [19:11.530 --> 19:15.570] And John Ashcroft went around mocking them. [19:15.710 --> 19:29.950] He literally went on a nationwide tour doing talks saying that the American Library Association were nuts and that they were paranoid and that they were, you know, seeing things to be afraid of behind every tree and under every rock. [19:29.950 --> 19:37.430] And then it turned out, a few years later, that the FBI was using the Patriot Act to get patron records from the libraries. [19:38.990 --> 19:51.030] Around that same time, stories began to appear in the papers about commercial booksellers, you know, Barnes & Noble, Amazon, those types, literally just handing over reams of information about all the books that people were buying. [19:51.770 --> 20:06.010] And that was kind of like a light bulb over the head moment for me, where I started to think that, you know, the librarians and the commercial booksellers in a lot of ways are in the same business, but with just a vastly different business model. [20:06.170 --> 20:13.230] One's nonprofit and kind of ideological and one's for profit and its goal is to make as much money for its shareholders as possible. [20:14.950 --> 20:22.390] I started to think to myself, why isn't there the equivalent of the ALA or the librarians in the telecommunications industry? [20:24.410 --> 20:29.250] That's when I started to come up with the idea for this nonprofit telco provider. [20:31.010 --> 20:34.090] It's a nonprofit with an educational and charitable purpose. [20:35.490 --> 20:41.030] Kind of the sub purpose is to promote best practices with regards to privacy within the telecommunications industry. [20:41.810 --> 20:52.770] And what we're planning on doing is building a framework for an Internet provider and a mobile phone provider with all the best privacy controls and best practices baked in from the beginning. [20:53.670 --> 20:58.050] So that would mean it would comply with all of EFF's best practices for service providers. [20:58.050 --> 21:00.370] That would mean it would use encryption wherever possible. [21:01.370 --> 21:11.470] That would mean that it would be an open framework with all the source code published on GitHub or somewhere so that anyone can audit it, so that anyone can contribute code to it. [21:12.830 --> 21:17.130] And then, of course, we're going to release it all under an open license. [21:18.490 --> 21:24.530] And we're also going to operate a testbed environment so that anyone can participate in testing it out. [21:25.150 --> 21:31.170] Anyone can sit there and hammer on it, poke at it, figure out if there were problems with it, how it could be better. [21:33.390 --> 21:38.290] The whole goal is to develop a framework that we can then give away and encourage other people to run anywhere. [21:38.850 --> 21:41.330] To kind of just change the way telecommunications works. [21:41.450 --> 21:46.210] To reimagine it as if a bunch of privacy people and security people had designed it from the get-go. [21:48.450 --> 22:02.270] The old analogy that I always was thinking about was like, you know, in the old days, before there was touch-tone, before there was rotary dialing, you picked up the handset on the old phone, you clicked the receiver, and an operator somewhere would pick up. [22:02.830 --> 22:05.610] And you would say, connect me to Dr. Johnson or something. [22:05.790 --> 22:07.730] And then she would plug a cable. [22:08.570 --> 22:11.170] And then she would be able to listen in on the whole call. [22:12.530 --> 22:18.730] And the town phone operator was always known as like the person you would go to to find out where anyone was, or to find out, you know, what was going on. [22:18.830 --> 22:19.830] She knew everything about everyone. [22:21.250 --> 22:28.330] You know, as technology moved forward, and we had crossbar switching, and then we had electronic switching, we had all these different systems, everything became digital. [22:29.570 --> 22:33.430] But in the end, it was still just as transparent as it had been in the 1800s. [22:35.110 --> 22:38.090] And I started to imagine, you know, how could this be done differently? [22:38.790 --> 22:40.270] And why do we accept this? [22:42.090 --> 23:00.770] One of the first things I started to do, to try to get support for the idea, is I went around and I talked to people that I thought were influential and smart, that would really help kind of flesh out the idea, and sort of lend some gravitas to this concept. [23:03.130 --> 23:10.170] The concept that I'm going for, and it's still a work in progress, is that I want to bring together four groups. [23:10.450 --> 23:13.030] One is kind of the open-source and hacker community. [23:13.290 --> 23:16.630] One is like the civil liberties community and the legal world. [23:17.210 --> 23:20.370] One is intelligence and law enforcement. [23:21.230 --> 23:23.270] And one is the enterprise. [23:24.170 --> 23:27.350] And those are kind of the four groups I'm trying to bring under a big tent. [23:28.790 --> 23:30.430] There's still some work to be done, I think. [23:30.610 --> 23:39.050] But, you know, I think I have like a decent assortment right now of people, some of whom you might know, some of whom you might not. [23:41.310 --> 23:46.710] The addition of Brian Snow, the former tech director of NSA, was a really strange thing. [23:47.870 --> 23:50.430] It's kind of requires explanation, I guess. [23:52.390 --> 23:58.590] I became friends with a guy who works at ACLU, who's a retired FBI agent. [23:58.790 --> 24:00.630] He'd been at FBI for like 25 years. [24:01.730 --> 24:04.530] I asked him, would he be willing to be on this advisory board? [24:04.990 --> 24:18.590] He said he couldn't because of conflict of interest rules, because at that time I was still like a quasi, maybe soon to be client of, you know, ACLU's, because we kept going back and challenging the gag provision. [24:19.330 --> 24:23.490] He said, but I can't do it, but I do know this guy, Brian Snow, that you should talk to. [24:23.790 --> 24:25.170] And I didn't know who he was. [24:25.450 --> 24:26.330] I'd never heard of him. [24:26.710 --> 24:28.330] I went home and I Googled the guy. [24:28.830 --> 24:34.730] And like Google image search pops up, and like I see this picture of him, and on his left is Diffie, and on his right is Hellman. [24:35.010 --> 24:36.030] And there he's in the middle. [24:36.170 --> 24:40.030] I'm like, okay, this guy's like pretty heavy. [24:40.030 --> 24:43.550] So I ended up going down and meeting with him when I was in Washington one time. [24:43.730 --> 24:53.670] And as it turns out, he left the agency in part because of the same reasons that you may have heard about at the keynote on Friday. [24:55.550 --> 24:59.470] He was unhappy about some of the stuff NSA was doing post 9-11. [25:00.130 --> 25:08.030] And he worked within the agency and tried to do as much as he could. [25:08.030 --> 25:12.810] But at a certain point, he understood that there were forces that were bigger than all of that. [25:13.170 --> 25:15.610] And he ended up retiring early because he didn't... [25:15.610 --> 25:25.230] My understanding is he didn't feel that he could stay there and watch the Constitution being disrespected. [25:26.250 --> 25:33.370] So it seems like a strange thing, but I'm kind of going for a strange bedfellows thing with a big tent concept. [25:34.690 --> 25:43.570] That you could have the former tech director of NSA with the president of the ACLU and with Jake Appelbaum and with Bob Barr on the same advisory board, to me, is like really powerful. [25:44.070 --> 25:47.670] Although it seems maybe crazy on some level. [25:50.570 --> 25:55.770] I also went out and kind of tried to get a bunch of partnerships with organizations that are working in this field. [25:57.150 --> 26:01.510] At Brooklyn Law School, there's this amazing law clinic that does a lot of telecommunications law work. [26:02.370 --> 26:03.250] They're called BLIP. [26:03.590 --> 26:08.330] And the professor there is a guy called Jonathan Askin, who's also on the advisory board. [26:08.330 --> 26:14.970] He used to be with FCC, and his father was a general counsel of ACLU for a number of decades. [26:15.130 --> 26:18.570] So he's kind of got one foot in telecommunications and one in civil liberties. [26:18.910 --> 26:24.530] And I've had really amazing meetings and talks at the EFF, and they're super on board. [26:27.870 --> 26:34.590] There is also a group called LEAP, which I'm sure pretty much none of you have heard of, because they're super obscure. [26:35.110 --> 26:45.090] But they're made up of a bunch of guys that I know who have been working in security and VPN and telco stuff for years. [26:45.910 --> 26:51.910] And along with my organization, we're working on developing the platform for the Internet services. [26:55.210 --> 26:58.510] They're really an interesting group of guys. [26:58.830 --> 27:00.090] Probably you know a bunch of them. [27:00.810 --> 27:05.230] They don't really have much public information out there right now, but soon they will. [27:06.570 --> 27:13.310] ACLU also has given me an amazing letter of recommendation, Guardian Project. [27:13.310 --> 27:17.350] I don't know if you've heard of them, but they do amazing phone crypto work. [27:17.750 --> 27:20.130] They ported the Tor client to Android. [27:20.410 --> 27:26.430] They have been porting a lot of ZRTP clients and such, and SMS encryption software. [27:26.430 --> 27:33.190] They do a lot of work with journalists and with NGOs in a lot of different parts of the world. [27:33.930 --> 27:35.690] And, of course, you know Tor. [27:38.010 --> 27:50.430] The concept for the ISP, as it's been developing, the design goal is to encrypt as much data as possible on the client side, so that only the user or the recipient can decrypt the data. [27:51.910 --> 27:58.370] One of the things that I kind of felt when I got caught up in the whole NSL thing was, here's two third parties. [27:59.630 --> 28:03.750] There's the FBI in one hand, and there's this client of my Internet provider in the other. [28:04.230 --> 28:07.830] And I kind of felt like, it's like when there's a fight outside a bar. [28:08.010 --> 28:11.530] If you like try to charge in between them and hold them apart, you're going to get hit on both sides. [28:11.650 --> 28:12.890] And that was kind of what was happening to me. [28:12.890 --> 28:14.970] I was getting kind of smacked around. [28:15.170 --> 28:18.070] I felt like I had responsibilities to my client and their privacy. [28:18.670 --> 28:21.650] I also felt like the FBI was coming down on me like a ton of bricks. [28:22.390 --> 28:25.370] And I didn't feel like any of this was my fault or had anything to do with me. [28:26.570 --> 28:28.050] So I started to think, like, why? [28:28.230 --> 28:30.230] How can I just remove myself from this equation? [28:30.970 --> 28:40.010] And the answer to me is to give the users the ability to encrypt all their data as much as possible, so that the telco doesn't have any visibility into the communications. [28:40.310 --> 28:44.650] I mean, this... I don't understand how this hasn't been done up to this point. [28:49.410 --> 28:52.230] The client... it's a client-server model. [28:52.410 --> 28:57.570] So you're going to have to run a client on your machine or on your handset or whatever device you have. [28:58.770 --> 29:01.750] All the data will be encrypted, outgoing, through VPN. [29:04.710 --> 29:06.770] Optionally, you're going to be able to use Tor as a transport layer. [29:06.870 --> 29:11.470] Because the concept that we're going for is that you don't have to be able to trust your carrier. [29:11.690 --> 29:12.970] You don't have to be able to trust your ISP. [29:15.590 --> 29:21.170] We're going to try to integrate everything with hosted Tor bridges and exit nodes, so that all the traffic can be merged together. [29:22.310 --> 29:27.710] So it'll be much more difficult to tell what's coming from the provider and what's just random Tor traffic. [29:29.150 --> 29:33.450] And then we're also working on a bunch of solutions for opportunistic content encryption. [29:34.770 --> 29:40.930] So that would include like automatic key distribution and opportunistic encryption and simplified trust mechanisms. [29:41.190 --> 29:47.170] And kind of the goal there is to make it so that there aren't ten steps to do everything. [29:47.530 --> 29:50.570] Like if you're going to send a PGP email to someone, you have to get their key. [29:50.690 --> 29:51.910] You have to validate their key. [29:52.070 --> 29:53.570] You have to, you know, trade keys. [29:53.670 --> 29:56.430] You have to do all this work before you ever send the first email. [29:56.430 --> 29:59.610] And this is in part, I think, why technology like this hasn't been adopted. [30:00.890 --> 30:08.190] You know, having key servers and all this stuff has kind of helped a lot because before there were key servers, there was much more manual. [30:09.790 --> 30:22.370] But if this is really going to be adopted by the general public or by people who are like not technical people, journalists, human rights organizations, we have to kind of figure out how to simplify and streamline a lot of this stuff. [30:27.210 --> 30:32.470] Another really interesting application that we're working on is client encrypted cloud storage. [30:33.270 --> 30:38.510] Kind of like Dropbox, but done right, so to speak. [30:39.750 --> 30:42.850] And what goes hand in hand with that is also client encrypted email. [30:45.690 --> 30:53.930] Again, some of the stuff that's happening with surveillance these days is that all data is being stored in the cloud. [30:54.830 --> 31:01.530] But email, particularly email that's stored in the cloud, has no protection at all after 90 days, pretty much. [31:01.690 --> 31:04.190] Not everyone knows this, but there's sort of a cutoff point. [31:05.410 --> 31:06.850] It's codified in law. [31:08.350 --> 31:12.270] And all email that's stored more than 90 days doesn't even require a warrant. [31:12.270 --> 31:14.430] It's only the freshest email that does. [31:16.590 --> 31:19.370] As a provider, I don't ever want to be asked for the person's info. [31:19.830 --> 31:32.970] I kind of think if someone wants that info, whether it's a hacker, whether it's someone involved in a civil suit with them, whether it's anyone, any third party, I think they need to go to the user and get it from them. [31:35.790 --> 31:52.810] So then also one of the more interesting parts of this system, the ISP system, is confederation, in that we are going to design it so that if other people are running the same system, that all traffic that's destined for the different providers will be automatically encrypted. [31:52.810 --> 31:56.770] So it'll eventually create sort of a larger cloud or a larger darknet. [31:59.150 --> 32:10.030] From the mobile side, I'm looking at basically a MVNO model, meaning that I'm not going to be putting up any towers. [32:10.030 --> 32:11.710] I'm not going to really build any infrastructure. [32:11.710 --> 32:24.350] I want to piggyback on existing towers and existing infrastructure, but use all kinds of security techniques and encryption to sort of mitigate the fact that I'm allowing customer data to fall into third party hands. [32:26.590 --> 32:44.790] So what that means essentially is curating a collection of security tools, VPN clients, Tor clients, ZRTP encryption, encrypted SMS, building phones, probably based on Android, that will have all the security tools built in, so that everything's on by default. [32:46.970 --> 32:53.770] And then one really important point here is that all data has to be encrypted by the customer on their own device. [32:55.210 --> 33:10.010] Part of the reason why that's so important is because of this law called CALEA, which maybe you've heard of, maybe you haven't, but it's a law that basically forces teleco providers to put back doors and all their equipment so that law enforcement can listen in. [33:11.750 --> 33:24.090] Fortunately, at least at the moment, and this may change because they keep proposing changes to it, it allows you to not decrypt the data if you, the provider, don't have the keys. [33:24.950 --> 33:27.210] I'll get into that more in a minute. [33:30.950 --> 33:46.630] So part of the whole best practices approach of this thing is to do flat rate billing, because part of what's so troublesome about the way that the teleco system has worked for so many years is that by billing by call, you end up with this massive database of everything that a person's done on every call. [33:46.630 --> 34:05.150] And this is, you know, really amazing for data mining, it's really amazing for, you know, for marketing purposes, but it also creates like a huge problem where every database you create like that is going to be abused eventually, as we've seen. [34:06.690 --> 34:10.950] The section of CALEA that I mentioned earlier is section 103B3. [34:11.430 --> 34:23.530] It says the telecommunications carrier shall not be responsible for decrypting or ensuring the government's ability to decrypt any communications encrypted by a subscriber or customer unless the encryption is provided by the carrier. [34:23.670 --> 34:24.890] And this is the key part. [34:25.050 --> 34:28.510] And the carrier possesses the information necessary to decrypt the communication. [34:29.090 --> 34:40.810] This is why I'm trying to make everything be encrypted by the customer on their own device and to not have any kind of key escrow or not have any of the customer keys ever fall into the possession of the provider. [34:47.110 --> 34:49.930] So, there are a few ways you can help. [34:51.470 --> 35:03.070] I just completed a fundraising campaign, a crowd-sourced fundraising campaign, which raised $70,000 in small donations, like $10,000, $20,000, $50,000 mostly. [35:03.070 --> 35:10.130] There were a few thousand dollars, a few $2,500, but basically, I need to raise a couple million dollars to build a facility. [35:11.650 --> 35:16.690] If you want to contribute money to our funding drive, the address is right there. [35:16.690 --> 35:19.190] Or if you go to the Calix Institute site, there's a donate button. [35:21.090 --> 35:33.230] If you can introduce us to angel donors, or if you know anyone who's got a lot of money that believes in privacy and the Constitution, wants to see things change, I don't think we should be discouraged and think that we can't change things. [35:33.410 --> 35:34.270] I think that we really can. [35:34.550 --> 35:38.850] It doesn't take... none of this stuff is mind-boggling. [35:38.970 --> 35:44.230] This is just taking, like, one thing that exists and another thing that exists and slam them together and make something new out of it. [35:46.250 --> 35:51.070] If anyone knows and experienced development director that can help us get grants, please introduce us. [35:51.430 --> 35:56.350] If you can help us get a grant from somewhere, if you work at a grant-giving organization, please get in touch with me. [35:58.470 --> 36:01.330] As I said earlier, we're doing this all as an open-source project. [36:02.190 --> 36:08.490] If you're a coder, if this is your field, if this is your specialty, you can contribute to this. [36:08.630 --> 36:13.390] We would love to have as many people look at what we're doing and critique it and add something to it. [36:13.810 --> 36:15.510] Give us constructive criticism. [36:16.070 --> 36:17.050] Give us ideas. [36:18.230 --> 36:20.390] You can follow us on Twitter, obviously. [36:20.730 --> 36:22.570] Kind of keep up with our progress. [36:23.590 --> 36:33.670] And once we release the software, if you're kind of an entrepreneurial-minded person, you know, you can start your own ISP, your own VPN provider, your own mobile provider using our software. [36:34.650 --> 36:38.830] That's really the end goal here, is to try to transform the telecommunications industry. [36:39.650 --> 36:55.590] To the extent that we can actually get some significant portion of the American public using privacy-focused telecommunications services, it will create basically a business case for the big telcos, which will make them realize that there is a market for privacy, [36:56.530 --> 36:58.370] which is being ignored up until now. [37:00.490 --> 37:12.310] One of the things that I ran into that was a problem for me, is trying to just put together the plan for this thing, is people say to me, what is the market for privacy in telco, and how big is it? [37:12.850 --> 37:17.050] And I couldn't find any research on it, because there is no market for privacy. [37:17.050 --> 37:21.950] So it's sort of like saying, what's the market for, like, you know, for unicorn saddles or something? [37:22.390 --> 37:23.690] There's no market for it. [37:23.790 --> 37:24.970] But it just doesn't exist. [37:25.130 --> 37:28.170] It sounds crazy, but that's the truth. [37:30.290 --> 37:37.470] And now I want to kind of open up the floor to questions from anyone who... [37:48.070 --> 37:51.970] Hi, I wanted to ask you about the software. [37:51.970 --> 37:54.750] Can it be decentralized? [37:55.170 --> 37:58.470] Can people independently set up their own networks with this stuff? [37:58.490 --> 38:03.070] Or is it just piggybacking through your ISP or somebody else's ISP? [38:04.250 --> 38:06.690] You can take it and run with it and do whatever you want with it. [38:07.130 --> 38:07.470] Okay. [38:07.630 --> 38:11.090] It's probably going to be GPL, so you're going to have to give changes back. [38:11.370 --> 38:13.370] But other than that, there's really no restrictions on it. [38:13.410 --> 38:15.790] You don't have to run it in a facility we build. [38:15.790 --> 38:17.970] You can take it and do whatever you want with it. [38:18.290 --> 38:18.410] All right. [38:18.530 --> 38:18.770] Thank you. [38:20.230 --> 38:20.470] Yeah. [38:20.550 --> 38:26.310] Do you have any idea of how many subscribers you'd need for it to be self-sustaining once it gets launched? [38:26.310 --> 38:31.390] Like, if a hundred people use it, if a million people use it, I mean, what point does it continue to live? [38:31.650 --> 38:34.030] I would say it's somewhere between a hundred and a million. [38:34.350 --> 38:34.630] Yeah. [38:37.730 --> 38:40.570] Probably right in the middle somewhere, I would guess. [38:40.950 --> 38:41.090] Okay. [38:41.110 --> 38:41.990] Or a little less. [38:42.150 --> 38:45.890] I would think it would be in the hundreds of thousands, is my guess. [38:46.130 --> 38:46.510] Okay. [38:46.650 --> 38:49.790] And do you know what the geographical area would be or would it be nationwide? [38:50.370 --> 38:51.410] Well, okay. [38:51.590 --> 38:55.050] Well, this gets into stuff that isn't settled yet. [38:56.390 --> 39:04.950] But there's sort of a potential deal on the table where we could use a certain wireless network that's in 70 markets in the U.S. [39:05.710 --> 39:07.790] And it's basically the top 70 markets. [39:09.610 --> 39:12.310] There's a different... a number of different ways we kind of envision it working. [39:12.470 --> 39:17.150] I mean, there's one way is bundled with a last mile service, like attached to someone's wireless network. [39:17.350 --> 39:18.070] Another is just... [39:18.070 --> 39:19.090] AOL or something, kind of? [39:19.350 --> 39:19.670] What? [39:19.770 --> 39:22.270] Like the model that AOL has with broadband subscribers? [39:23.330 --> 39:24.510] Yeah, I guess. [39:25.850 --> 39:26.290] It's... [39:26.770 --> 39:32.570] Yeah, it's kind of like pay one price, get a last mile service, bundled with a VPN, and privacy services. [39:33.710 --> 39:36.970] Another way it can be used, though, is just like a traditional VPN provider. [39:37.190 --> 39:41.730] Like you already have your ISP and then you just buy this service and bundle it on top of yourself. [39:43.110 --> 39:48.230] So in that respect, it can be used worldwide, if that makes sense. [39:48.410 --> 39:48.510] Cool. [39:48.770 --> 39:48.990] All right. [39:49.090 --> 39:49.690] Good luck with it. [39:50.230 --> 39:50.710] Thank you. [39:52.790 --> 40:00.830] I guess you partly answered my question, but I was wondering what your thoughts were on AT&T's and other... [40:00.830 --> 40:04.050] Well, the mobile monopoly that we have right now. [40:05.070 --> 40:08.590] And that's basically the model throughout North America right now. [40:08.750 --> 40:14.330] Like in Canada, we have a similar problem where telcos control the long lines and the last mile. [40:15.470 --> 40:27.310] And that while we can run VPNs on top of that, it's kind of an extra service that requires people to be aware of the problem and spend money, like extra money, to get an extra service. [40:27.310 --> 40:33.990] That it's difficult to get a critical mass of people to change the ISP's policy, since anyways, they have the monopoly. [40:35.350 --> 40:50.470] What are your thoughts on how we can fight back on that monopoly or what technologies or tools you think of using to go around maybe that kind of impossible problem that we've established in the last hundred years? [40:51.630 --> 40:53.070] Well, that's a huge question. [40:54.430 --> 40:56.630] Well, I don't know that I... [40:56.630 --> 40:57.190] Simple answer, you know. [40:57.310 --> 40:58.770] Yeah, I don't know that I have the answer. [40:58.990 --> 41:02.870] I mean, there are a lot of really interesting groups that are working on problems like that. [41:04.470 --> 41:07.230] You know, Access Now, groups like that. [41:09.510 --> 41:11.490] EFF works on that problem a lot. [41:12.130 --> 41:16.750] It's not one that I'm prepared to take on myself at this point. [41:16.950 --> 41:24.190] I'm just trying to stay laser focused on trying to change the way telecommunications views privacy. [41:25.370 --> 41:27.910] So, I'm sorry I don't have a better answer for that. [41:30.530 --> 41:32.410] How do you plan on dealing with lost keys? [41:32.990 --> 41:38.770] Because, like, if you don't have the keys, you can't, you know, send a password reset email if somebody, you know, loses their phone. [41:38.950 --> 41:39.770] That's very true. [41:41.170 --> 41:46.170] The way we're going to deal with it is that you're out of luck if you lose your key. [41:46.170 --> 41:47.290] Your email is gone. [41:47.930 --> 41:54.210] Like, I imagine getting that customer support phone call and being on the line with an irate person for, like, five hours. [41:54.470 --> 41:56.810] Like, that doesn't sound like a solution. [41:57.750 --> 41:58.250] No. [41:58.570 --> 42:04.530] I think it's going to be very important to set expectations at the beginning, from the very beginning. [42:04.930 --> 42:08.110] To let people know that if they lose their keys, that they're f*cked. [42:08.690 --> 42:09.210] Is... [42:14.410 --> 42:20.110] Unfortunately, there's just no way around it, because we intend for this to be used by journalists that go to unfriendly countries. [42:20.170 --> 42:22.470] We intend for it to be used by human rights researchers. [42:22.590 --> 42:25.310] We intend for it to be used by people whose lives are in danger. [42:25.770 --> 42:30.310] So, we obviously can't really have a key escrow system or some way that undercuts it. [42:30.950 --> 42:33.770] Because it would put people's lives in danger, so... [42:33.770 --> 42:34.890] What about biometrics? [42:35.210 --> 42:38.850] Like, is voice print authentication to the point where you could think about using that? [42:40.310 --> 42:41.450] Not that I know. [42:41.870 --> 42:44.310] I mean, it may be theoretically possible. [42:44.530 --> 42:47.210] Like, maybe you could hook me up with dudes from MIT that are working on it. [42:47.350 --> 42:49.850] But at this point, not that I know of. [42:49.950 --> 42:50.390] And we're... [42:51.350 --> 42:58.630] One thing that's really important to me from the design perspective of this thing is not to sort of go into uncharted territory and not try to reinvent the wheel. [42:58.750 --> 43:06.270] And we're trying to just work with existing battle-hardened, tested software that's been around and been knocked around a lot. [43:06.990 --> 43:11.970] So, I'd be worried about sort of moving into, like, the cutting, cutting edge. [43:12.270 --> 43:12.550] You know? [43:12.690 --> 43:14.710] That's why we're trying to stick with just basic public key. [43:16.230 --> 43:16.650] All right. [43:16.750 --> 43:16.930] Thanks. [43:23.920 --> 43:27.700] I'm not very technical, so this might be a stupid question, but... [43:28.200 --> 43:29.320] Would this prevent... [43:30.120 --> 43:34.720] I know your cell phone, like, pings towers, and then based on that, they can triangulate and say, oh, he was here. [43:35.180 --> 43:37.660] Would this prevent that in any way, or...? [43:37.660 --> 43:39.360] Not exactly, no. [43:40.040 --> 43:44.100] This is one of the problems in terms of not being able to control the whole network. [43:44.540 --> 43:51.500] If you piggyback on other people's networks, that means that you leave some parts of it open to being listened to. [43:51.860 --> 44:03.400] And one of the big things that law enforcement's been doing recently, you may have seen this in paper, you may not have, but it's worth looking into, is they request from telco something called a tower dump. [44:03.700 --> 44:07.040] And that tells them everyone that was connected to the tower at a certain period of time. [44:07.140 --> 44:12.200] They may be looking for some guy that robbed a bank, but they'll end up with a list of, like, 100,000 people that were connected to that tower. [44:12.460 --> 44:14.280] Maybe you, me, and everyone in this room. [44:15.000 --> 44:15.080] Yeah. [44:17.560 --> 44:17.920] So... [44:17.920 --> 44:19.760] The short answer is no. [44:19.900 --> 44:20.820] It doesn't prevent that. [44:21.480 --> 44:22.740] Because we don't control the towers. [44:22.880 --> 44:24.500] If we did, then maybe we could do something about it. [44:25.320 --> 44:30.400] To get more in-depth, you know, I've read about some interesting stuff, like I read about in Pakistan. [44:31.540 --> 44:33.100] This is a story I read about a long time ago. [44:33.200 --> 44:34.780] It's something I've been, like, knocking around in my head. [44:35.460 --> 44:38.240] They were bringing in these really cheap cell phones. [44:38.320 --> 44:39.100] They cost, like, a dollar. [44:39.280 --> 44:40.520] These Chinese cell phones. [44:41.160 --> 44:49.900] And the manufacturer, to cut corners and save money, coded the IMEI number in each phone as being all zeros. [44:50.320 --> 44:52.720] And it saved them, like, a penny on each phone or something. [44:52.720 --> 44:53.520] And they were like, yes. [44:53.780 --> 44:55.880] You know, and then there was, like, 99 cents instead of a dollar. [44:57.000 --> 44:57.360] And... [44:57.360 --> 45:01.080] But the problem they were having was that all the phones were all zeros. [45:01.320 --> 45:02.360] And they couldn't really tell them apart. [45:03.300 --> 45:15.080] And so one of the questions that I'm interested in exploring from a research and development point of view is exactly what part of the GSM spec, you know, is mandated under the law. [45:15.220 --> 45:16.860] And, like, how much wiggle room is there? [45:16.960 --> 45:22.040] And what can we do to sort of work around the fact that we're going to have to deal with other people's towers, that other people have access to? [45:22.780 --> 45:26.540] So I don't have, like, a final baked answer. [45:26.660 --> 45:28.640] Like, yes, we're going to deal with that this way. [45:29.260 --> 45:33.860] But I can say that, you know, people on my advisory board are really into that stuff. [45:34.000 --> 45:43.920] And people who aren't on the advisory board, but that I talk to a lot about these ideas, are, like, really interested in kind of going in-depth on these issues and figuring out what can be done and what can't be done. [45:44.580 --> 45:47.240] And that's something that we're absolutely concerned about. [45:47.920 --> 45:56.960] You know, the technology behind this, like, the GPS stuff in phones for Enhanced 911 has been abused, like, massively. [45:57.740 --> 46:03.120] On the other hand, if you're somehow skiing and you get in an avalanche, then it's kind of cool. [46:04.460 --> 46:07.220] So it's like, I can't say that it's bad technology. [46:08.000 --> 46:09.340] It's agnostic technology. [46:09.620 --> 46:13.960] It can be really awesome when you get pulled out of the snow. [46:14.380 --> 46:16.540] And it can also suck if you're being tracked everywhere. [46:16.840 --> 46:20.840] So it's like something that, it's an open question that we're looking to address. [46:21.960 --> 46:22.880] Best way I can put it. [46:23.040 --> 46:23.420] Thank you. [46:23.960 --> 46:24.240] Thank you. [46:26.380 --> 46:26.980] Hi, Nick. [46:26.980 --> 46:43.880] As one of your advisors, I'm not here to ask a question, but just sort of express to all of you the need for folks like Nick to sort of be in the vanguard of trying to bring this work to the masses and commercialize it and make it fair and just and usable. [46:44.400 --> 46:49.900] And that the way that, you know, all of us as advisors see is these aren't competitive efforts. [46:50.920 --> 46:55.920] As long as you're open and exchanging ideas, you know, we all want to use, like, we're tool builders. [46:56.100 --> 47:01.840] We want people to use and apply our tools to humans and to fight the robots that Evan was talking about. [47:02.200 --> 47:06.260] So anyway, so I think Nick needs our support. [47:06.260 --> 47:11.440] And to sort of pitch a talk at Five related to this is the Open Secure Telephony Network. [47:11.740 --> 47:17.420] This is, there's lots of names and titles and projects, but everything we're doing is totally feeding into this. [47:17.420 --> 47:23.140] So the more, if you want to start writing code now and playing with some of these ideas, you can run stuff like OSTN. [47:23.220 --> 47:29.180] You can use Moxie's Tech Secure and figure out, you know, since he's not committing code to it anymore, you might, you know, and things like this. [47:29.280 --> 47:36.580] So there's a lot you can do today to start hacking on this such that when Nick gets his piles of money, then you'll all be ready to help him build his dreams. [47:36.840 --> 47:37.300] So, thanks. [47:38.260 --> 47:39.060] Thank you, Nate. [47:42.450 --> 47:44.710] Nate Freitas from The Guardian Project. [47:47.330 --> 47:48.190] Any other questions? [47:48.510 --> 47:48.750] Sure. [47:48.890 --> 47:51.230] Have you thought about competing with Skype? [47:54.050 --> 47:59.110] I mean, in terms of, in terms of, in terms of doing voice over IP, yes. [48:01.570 --> 48:05.530] It's probably a slightly different model, but, but on some level, yes. [48:09.410 --> 48:17.290] Do you foresee any potential for laws to change for telephone providers to make what you're trying to do illegal became widespread? [48:17.290 --> 48:19.830] Like forcing back doors on phones, for example? [48:22.070 --> 48:24.590] There's absolutely the potential for the laws to change. [48:25.030 --> 48:27.030] Proposals are being put forth all the time. [48:28.070 --> 48:33.610] I mean, right now there's a lot of stuff going on in Great Britain and Australia and Canada that's horrifying. [48:34.330 --> 48:40.170] There's also bad, in my opinion, proposals being put forth in this country all the time. [48:41.450 --> 48:51.650] In fact, they're talking about modifying the CALEA law that I mentioned earlier and one of the worries that I have is that they might take out that exception that allows you to use encryption as long as you don't have the keys. [48:53.350 --> 48:55.470] So yes, it's a constant danger. [48:57.470 --> 49:05.310] The one thing that I think is a good thing is that there are other companies right now using this business model somewhat. [49:06.130 --> 49:08.410] BlackBerry is the best example, the most well-known example. [49:08.990 --> 49:10.710] It's only in their enterprise model. [49:11.150 --> 49:16.310] In the enterprise model for BlackBerry, they give you a server which is hosted in your data center, your office. [49:16.310 --> 49:20.630] And that server holds all the keys for all the devices in your organization. [49:21.530 --> 49:25.550] I think that's how they got around this requirement in CALEA. [49:25.670 --> 49:31.430] And this is also why BlackBerry ran into such trouble in India and a few other countries. [49:31.430 --> 49:38.470] You know, where they were being requested backdoor access into everything and they said we can't give it to you. [49:40.270 --> 49:44.990] So if it was only me doing this, that would... I would feel like super exposed. [49:44.990 --> 49:53.050] The fact that it's not just me and that there's other people doing it makes me feel like at least it's not huge numbers, but there's safety in some numbers. [49:54.810 --> 50:01.310] And I think an argument can be made that it's bad for innovation, it's bad for business, to ban cryptography. [50:02.470 --> 50:15.490] One of the things that I've been trying to do to sort of preempt these arguments that cryptography is bad or that it's bad for national security is to try to link together the concepts of privacy and cybersecurity. [50:15.490 --> 50:22.890] And to try to say that cybersecurity and privacy to a large degree are the same problem, but being described with different framing. [50:23.210 --> 50:30.730] And to the extent that you can introduce strong crypto at a low level into the telecommunication system, you can address both problems. [50:31.290 --> 50:44.770] This is sort of like a tactic to bring two different groups that don't think that they have similar interests under the same tent to make them realize that both of their problems can be addressed with one approach. [50:45.790 --> 50:56.970] So that's, you know, one of the things that I'm trying to do to sort of preempt people that would try to ban privacy-focused crypto. [50:59.330 --> 51:08.570] That would be bad for national security, bad for privacy, bad for all the defense contractors that are trying to protect their intellectual property from being stolen by, you know, Chinese hackers or whatever is the threat of the day. [51:10.510 --> 51:18.750] That's part of why I'm trying to work with people like the NSA tech director and former Republican congressman and former, you know, U.S. [51:18.830 --> 51:20.770] Attorney Bob Barr, people like that. [51:20.990 --> 51:22.150] These are like establishment people. [51:22.830 --> 51:38.350] But they have law enforcement and intelligence credentials that sort of give them gravitas when they speak out about how dragnet surveillance is un-American, anti-democratic, bad for business, and also bad for intellectual property protection. [51:38.570 --> 51:40.870] within industry. [51:41.750 --> 51:43.630] I hope that kind of addresses your question. [51:43.830 --> 51:44.430] I'm not sure it does. [51:44.690 --> 51:44.730] Thanks. [51:45.150 --> 51:45.330] Sure. [51:48.390 --> 51:48.930] Hi. [51:49.150 --> 51:51.490] You're talking about using an MVNO model. [51:51.910 --> 52:08.810] So not only would your clients or customers, you know, unavoidably give up their location to whoever the incumbent is, but they're also using shared infrastructure at least from the tower sort of one hop back. [52:09.310 --> 52:17.930] And how do you protect against interception between the tower and your HLR, et cetera? [52:18.150 --> 52:20.070] I just want to say that we just have two minutes. [52:20.270 --> 52:21.870] I've seen a sign that we have two minutes to go. [52:22.650 --> 52:36.210] Part of what I'm looking at is not using the voice channel, only using the data channel and encrypting everything, and then routing everything back through a network controlled by my organization, so that we're not having the incumbent route the calls. [52:36.490 --> 52:38.730] They won't see the to and the from on any phone call. [52:38.810 --> 52:40.290] They won't see the to and the from on any SMS. [52:41.350 --> 52:44.930] I kind of addressed the geo-positioning thing earlier. [52:45.350 --> 52:50.090] There's not a hell of a lot you can do about that, but I'm curious as to what is the exact... [52:50.530 --> 52:54.570] As I mentioned, I'm curious as to like what are the parameters of what you're allowed to do and what you're not allowed to do. [52:56.070 --> 52:59.470] And I definitely want to fall on the side of caution. [53:02.650 --> 53:04.990] I hope that kind of addresses your question. [53:05.090 --> 53:05.230] Yeah, thanks. [53:05.430 --> 53:05.650] Sure. [53:06.950 --> 53:08.610] So I think this is the last one. [53:08.610 --> 53:09.370] Is that... [53:09.370 --> 53:09.590] Yeah. [53:10.290 --> 53:10.770] Okay, go ahead. [53:10.770 --> 53:15.310] I just wanted to ask, what sorts of press have you been getting and seeking? [53:16.710 --> 53:18.990] I've been trying to get as much press as I could. [53:19.430 --> 53:28.730] I've been talking to a lot of journalists, mostly about the national security letter thing, and for like a year or more, I've been trying to interest them in talking about this project. [53:28.790 --> 53:34.550] And I haven't been getting much traction until Declan McCullough wrote about it in CNET. [53:35.370 --> 53:46.290] Just a couple of days ago, there was a piece in Slate, and there's another story coming out in a very big financial newspaper. [53:48.530 --> 53:49.570] Hopefully, soon. [53:50.030 --> 53:51.210] Could be imminently. [53:53.410 --> 53:57.330] Other than that, I'm, you know, I'd love to talk to anyone in the media about it. [53:57.590 --> 53:57.870] Cool. [53:58.370 --> 54:00.450] If you know anyone, please send them my way. [54:02.010 --> 54:02.530] Good luck. [54:04.590 --> 54:04.970] Yeah. [54:08.770 --> 54:12.630] Let me just mention that my email address is nick at calyx.com. [54:12.690 --> 54:14.050] That's C-A-L-Y-X. [54:14.310 --> 54:17.970] And if you want to come up and talk to me afterwards, I'd be happy to answer more questions. [54:18.610 --> 54:19.890] So thank you very much. [54:20.190 --> 54:20.210] Thank you very much. [54:20.210 --> 54:20.650] Thank you very much. [54:20.650 --> 54:20.670] Thank you very much. [54:20.670 --> 54:20.690] Thank you very much. [54:20.690 --> 54:20.790] Thank you very much.