[00:00.000 --> 00:05.660] To our hearts, Jacob Appelbaum and Seth Schoen will talk about Tor and Internet censorship. [00:14.030 --> 00:14.870] Thanks, everybody. [00:15.610 --> 00:15.830] Hi. [00:16.990 --> 00:17.890] Great to be here. [00:18.070 --> 00:21.070] We're going to have to keep craning our necks because we don't actually have this here. [00:21.150 --> 00:22.970] So that's our only version of it. [00:25.270 --> 00:28.170] So we're Jake and Seth, not necessarily in that order. [00:28.950 --> 00:30.070] And I'm Seth. [00:32.570 --> 00:36.170] So we're from the Tor project and from EFF. [00:37.790 --> 00:38.730] I'm from EFF. [00:38.850 --> 00:39.410] Jake's from Tor. [00:39.630 --> 00:43.910] And we're going to talk a bit about Internet censorship and Tor and some of Jake's exciting world travels. [00:46.290 --> 00:51.190] So I suppose that if you guys have any questions, we will take questions afterwards. [00:51.410 --> 00:54.690] We have, like, about one slide per minute allocated. [00:55.010 --> 00:57.750] So we're going to go reasonably fast. [00:57.750 --> 01:01.070] And thanks to Club-Mate, we'll have the energy to do that. [01:02.230 --> 01:05.310] Everyone should thank Loesher for this wonderful moment. [01:07.350 --> 01:09.230] So we're pretty interested in this stuff. [01:09.470 --> 01:13.310] I worked on a book with Floss Manuals called How to Circumvent Internet Censorship. [01:14.190 --> 01:24.570] Jake has been a developer with the Tor project for a while and has also traveled around the world and taught trainings to teach people how to use Tor in a wide variety of countries and a wide variety of contexts. [01:25.750 --> 01:34.790] If there are particular things that you want to see Tor do in the future, like, let's say you want to advance the way that DNS works and you want to be able to make anonymized DNS queries. [01:35.030 --> 01:38.650] People have requested that for a long time and we've been really making rapid developments. [01:38.650 --> 01:49.310] We think that an anonymous communication channel is extremely important and hearing what you would use this for and why you use it is really helpful to us so that we can basically make your dreams a reality. [01:49.810 --> 01:58.010] And if, for example, you don't need any of this stuff or you think you don't need anything like this, you should consider using your privilege to help other people. [01:58.010 --> 01:59.910] And we'll talk about that a little bit in this talk. [02:02.270 --> 02:04.970] So our organizations are very friendly with one another. [02:05.430 --> 02:09.570] And we at EFF really appreciate the work that the Tor people do. [02:10.150 --> 02:12.950] We were previously one of their sources of funding. [02:13.450 --> 02:17.550] You'll see from their slides that they've had quite a lot of interesting sources of funding. [02:17.770 --> 02:18.890] And we were one of those. [02:19.750 --> 02:24.630] We've also given them advice and one of our attorneys was on their board of directors for a time. [02:25.490 --> 02:29.790] So we're very proud of Tor now that they're an independent nonprofit organization. [02:31.330 --> 02:35.910] That they're so effective as one of the leading providers of Internet privacy technology. [02:36.890 --> 02:38.310] It's really a great thing. [02:39.450 --> 02:45.790] We've also been interested in educating people who run Tor nodes about legal issues that they might encounter. [02:46.150 --> 02:49.010] And some of our attorneys are really interested in that. [02:50.210 --> 02:55.490] They'd be happy to hear about your exciting experiences as a Tor node operator. [02:56.650 --> 03:00.130] At the moment, our organizations are working on a thing called HTTPS everywhere. [03:01.030 --> 03:03.830] Which has some relevance to our topic today. [03:04.130 --> 03:08.210] Because it addresses a concern that a lot of people have about Tor. [03:08.210 --> 03:15.970] Which is that the exit node operator, the last party in the hop, if you don't know what that means, Jake will have a little picture in a few minutes. [03:17.070 --> 03:18.670] Is in a position to spy on you. [03:19.370 --> 03:21.710] You're trusting them with all of your traffic. [03:21.930 --> 03:26.010] And if it's unencrypted, they have the ability to see it and to potentially record it. [03:27.410 --> 03:28.450] And so... [03:29.330 --> 03:35.250] Also, even if you're not using Tor, a lot of your traffic is unencrypted on the Internet that potentially could be encrypted on the Internet. [03:36.050 --> 03:39.910] So Tor and EFF have been working together on this Firefox extension called HTTPS everywhere. [03:40.170 --> 03:44.610] That will make your browser use HTTPS on sites that we know offer it. [03:45.010 --> 03:46.650] It's actually quite a lot of sites. [03:47.070 --> 03:50.110] So it provides protection to non-Tor users and Tor users alike. [03:51.610 --> 03:54.310] These are some of the sites that are now supporting HTTPS. [03:54.510 --> 03:55.330] Just a selected list. [03:55.670 --> 03:57.070] And I think it's a great thing. [03:58.010 --> 03:58.510] I'm going to... [03:58.510 --> 04:00.870] In fact, I think it's so great that I'm going to give a whole talk about it tomorrow. [04:01.310 --> 04:03.330] So I won't go much further into that right now. [04:03.990 --> 04:07.770] But there's been a great trend because a lot of people think of this as something that's just for credit cards. [04:08.130 --> 04:09.770] And it's really not the case. [04:09.970 --> 04:15.190] Credit cards are not the most private or the most sensitive thing for many people that they do or communicate online. [04:15.530 --> 04:18.850] And it's great that so many sites are recognizing that and offering HTTPS. [04:19.750 --> 04:22.890] So we're trying to make it easier for people to take advantage of those protections. [04:24.990 --> 04:25.390] Okay. [04:25.970 --> 04:28.410] So our main theme today is going to be Internet censorship. [04:28.830 --> 04:30.470] And there's really quite a lot of it. [04:32.470 --> 04:35.410] It's something that happens in a lot of places, on a lot of networks. [04:39.030 --> 04:39.430] Yeah. [04:39.750 --> 04:43.490] There's a connection between censorship and surveillance that the Tor people experience all the time. [04:43.490 --> 04:44.490] Which is basically... [04:45.390 --> 04:51.090] Anyone who wants to block your communications based on their content needs to know what the content of your communications is. [04:51.750 --> 04:58.250] If they want to stop you from talking about a certain term, they need to see when you're talking about that term and when you're not. [04:58.610 --> 05:01.390] And so they need to spy on your communications in order to censor them. [05:02.590 --> 05:13.450] It's true that if people want to do much coarser censorship, like preventing you from communicating with a particular company or particular network or particular country, they could just block that. [05:14.050 --> 05:19.270] But for the really fine-grained content-based stuff, they actually have to be there on the network looking at what you do. [05:19.270 --> 05:22.870] And that produces a very deep connection between censorship and surveillance. [05:25.270 --> 05:30.390] And you'll hear in a few minutes that Jake has been going all around the world talking to people about this stuff. [05:31.030 --> 05:40.630] One of the things that he did in many of the countries that he visited was to test some of their networks and see how the censorship works in terms of doing trace routes, in terms of doing other things. [05:40.850 --> 05:43.130] To look at the technical infrastructure behind the censorship. [05:43.450 --> 05:44.990] What kind of software are they using? [05:45.230 --> 05:46.010] Who made it? [05:46.950 --> 05:48.490] Whose network is it installed in? [05:48.610 --> 05:52.950] Is it installed in a national firewall kind of thing or is it installed in the individual ISPs? [05:53.810 --> 05:59.910] So it's neat to actually take a look at some of those details and see some of the kind of disturbing answers. [06:00.710 --> 06:02.790] So this is a great example. [06:03.110 --> 06:05.630] I mean, these are everywhere, right? [06:05.790 --> 06:09.890] Everywhere I go when traveling, I must travel to some funny places, you'd think, right? [06:10.130 --> 06:13.510] But this is in Bahrain. [06:13.730 --> 06:15.210] I've actually never been to Bahrain. [06:15.210 --> 06:18.250] But I met one of their censors while I was in Qatar. [06:18.950 --> 06:22.970] I went to meet with some people from Al Jazeera to talk to them about issues that they have. [06:23.150 --> 06:31.730] You know, one of the main problems that Al Jazeera has is that when they're discovered as a journalist in a country, usually that country wants to throw them out. [06:32.890 --> 06:33.290] Right? [06:33.430 --> 06:46.030] Because usually Al Jazeera is reporting something, regardless of how you feel about what Al Jazeera is doing, it's interesting to note that a lot of these governments don't want Al Jazeera to be anywhere near their country. [06:46.230 --> 06:47.550] They don't want them to report anything at all. [06:47.670 --> 06:49.370] They want total silence in some cases. [06:49.750 --> 06:54.550] And so I met this guy who worked on the censorship system from Bahrain. [06:54.730 --> 06:55.630] And he pointed me at this. [06:55.770 --> 06:58.690] And he said, yeah, you can actually go to anonymous.com. [07:00.130 --> 07:01.390] I think it's BH. [07:01.570 --> 07:02.590] I can't really read it from here. [07:03.690 --> 07:06.230] And you can actually see the censorship site as if you were there. [07:06.230 --> 07:09.550] And it turns out that, like, you can visit a whole bunch of the sites this way. [07:09.630 --> 07:11.970] And you can see in the bottom right-hand corner, it says Tor disabled. [07:12.390 --> 07:17.950] So, I mean, obviously, if you use Tor to go to the censorship URL, you still get the URL. [07:18.150 --> 07:23.330] But if you were in Bahrain, you would see this, and enabling Tor would allow you to get around it. [07:24.010 --> 07:25.670] So in this case, it's kind of interesting. [07:26.710 --> 07:27.690] I don't even... [07:27.690 --> 07:29.250] I think this was maybe... [07:29.250 --> 07:29.750] Is that Jordan? [07:29.970 --> 07:31.470] Yeah, I think this was the airport in Jordan. [07:32.270 --> 07:40.250] I was traveling through giving a talk at a university in Jordan, and I wanted to use the Internet to connect back to my work. [07:40.470 --> 07:42.850] And I wanted to say, hey, you know, I have this problem. [07:43.430 --> 07:46.810] I'm in Jordan, and my contact hasn't showed up, and I'm stranded at the airport. [07:46.970 --> 07:49.990] And it's not a big deal, but just to let you know, I'm not going to check in like I normally did. [07:50.090 --> 07:51.410] Well, you know, it's a little bit of trouble. [07:52.650 --> 08:00.410] So I had to actually use Tor to be able to tell my work that I was okay, which was kind of like a hilarious, good thing we work on this project, right? [08:01.390 --> 08:03.130] But you can also learn a lot about this. [08:03.250 --> 08:04.950] Like, what does this access denied... [08:04.950 --> 08:06.110] What does this tell you? [08:06.330 --> 08:08.110] I mean, anybody here use Squid, for example? [08:09.150 --> 08:11.370] Like, does that look like a Squid access denied page to you? [08:12.050 --> 08:14.270] Like, you can start to fingerprint some of these... [08:14.270 --> 08:17.630] Like, some of the censorship systems that are set up around the world are just... [08:18.510 --> 08:20.110] They're not even really best effort. [08:20.490 --> 08:22.330] They're sort of like last-ditch effort. [08:23.250 --> 08:24.990] So in that case... [08:24.990 --> 08:26.290] This one's pretty funny. [08:27.850 --> 08:29.170] I don't even... [08:29.170 --> 08:30.730] I don't remember where that one is from either. [08:30.850 --> 08:31.850] But I like this. [08:32.010 --> 08:33.490] Please choose from the following options. [08:33.650 --> 08:35.390] Disable filtering or modify settings. [08:35.990 --> 08:36.510] Right? [08:38.330 --> 08:44.350] And you can also see in the bottom right-hand corner the company that makes this. [08:44.690 --> 08:46.250] Net Sweeper, I believe is what it says. [08:46.250 --> 08:49.330] And so you can actually say, like, oh, Net Sweeper. [08:49.470 --> 08:54.810] Yeah, those are those guys that collaborate with that government in order to filter the people that are living behind that network. [08:55.450 --> 08:56.450] Yeah, those guys. [08:56.630 --> 08:59.270] Those guys are not necessarily the guys you want to support. [09:00.950 --> 09:03.450] And so there's a lot of interesting... [09:03.450 --> 09:05.610] There's a lot of interesting filtering like this that takes place. [09:05.730 --> 09:07.810] And we'll talk a little bit about how to circumvent it. [09:07.910 --> 09:12.550] But there's some interesting stuff coming out of a project called ONI, which Seth will tell you about here in a second. [09:12.550 --> 09:18.150] And some of the stuff that I'm doing, I think, has some merit that goes really well with ONI's reports. [09:18.730 --> 09:23.270] Because ONI has the backing of some really brilliant political scientists. [09:23.690 --> 09:26.230] And they have some pretty good people that know how to write software. [09:26.690 --> 09:27.750] But they have a sort of like... [09:27.750 --> 09:29.610] I guess you could say they have a different perspective. [09:30.170 --> 09:35.750] ONI's sort of MO is that they want to talk about the filtering at a very high level. [09:35.890 --> 09:39.030] So that's not really useful if you want to write tools for getting around censorship. [09:39.030 --> 09:41.910] Because you say, okay, Cuban dissidents have this problem. [09:42.230 --> 09:44.170] Or, you know, people in Syria have this issue. [09:44.370 --> 09:46.090] Or this website is blocked in China. [09:46.770 --> 09:47.790] Well, how is it blocked? [09:48.070 --> 09:50.550] You know, why is it that Cuban dissidents are this way? [09:50.630 --> 09:51.410] Like, how are they targeted? [09:51.850 --> 09:56.610] And ONI doesn't really get into that in great detail in a way that I would like. [09:56.710 --> 10:03.630] They don't provide PCAP files that explain to you that China sends bi-directional resets, like four TTLs out from where you are, for example. [10:03.630 --> 10:05.730] Like, that's information you really want to know. [10:06.010 --> 10:07.690] And I have collected some of that information. [10:08.030 --> 10:24.450] And I'd like to write a series of tools with anyone that's interested, specifically for, like, automatically detecting, collecting this stuff, and make it safe to run from these countries so we can automate all these tests and we can basically build real-time filtering detection systems that will keep people out of trouble, [10:24.730 --> 10:29.750] for one, and will also allow us to have a greater technical understanding of the things that are happening. [10:30.930 --> 10:34.910] Yeah, EFF actually built a tool which theoretically could be used for that called Switzerland. [10:35.350 --> 10:36.730] It's a network neutrality tester. [10:37.450 --> 10:43.390] And you can run Switzerland on two different machines and have a server, and the machines can try to communicate with each other. [10:43.910 --> 10:53.010] And Switzerland will tell you if the network has tampered with their communications because each machine will check in with the Switzerland server and say what it sent and what it received. [10:53.330 --> 10:55.130] And then the server will sort of diff them. [10:55.410 --> 10:57.250] So you can see what the network has done to your packets. [10:57.250 --> 11:07.010] The problem with a lot of these countries is that using any kind of proxy at all immediately makes Switzerland say, yeah, they're tampering with your packets because you're being redirected to a proxy. [11:08.290 --> 11:12.590] So you'll just sort of get yes, which might not be exactly what you wanted to know. [11:13.390 --> 11:19.030] The thing I wanted to mention at this point about the OpenNet initiative, they published a couple of books which are very good. [11:19.650 --> 11:21.290] The first is called Access Denied. [11:21.430 --> 11:22.910] The second is called Access Controlled. [11:22.910 --> 11:26.170] They're about their studies of Internet censorship around the world. [11:26.730 --> 11:33.670] One of the points that they've really been stressing in their most recent book and their most recent work is that Internet censorship is not just a technical thing. [11:33.970 --> 11:48.490] It also really has these important social aspects, including how people feel about communications and communications privacy and how people feel about censorship in terms of whether they sympathize with it, in terms of whether they feel safe about trying to get around it, [11:49.130 --> 11:52.950] in terms of whether they self-censor because of a perception that they're always being watched. [11:53.630 --> 11:54.890] And so there are all these social dimensions. [11:55.690 --> 12:03.450] And then there is also censorship by trying to attack websites and intermediaries that facilitate speech that someone doesn't like. [12:03.930 --> 12:07.590] As opposed to trying to block it, you can try to take it offline completely. [12:07.590 --> 12:18.110] And so OpenNet Initiative has documented some people trying to attack web hosts that host particular magazines or forums that particular governments don't like and just trying to take them down completely. [12:18.470 --> 12:19.710] And that's a whole other level. [12:19.870 --> 12:23.030] And you can't really get around that with just a single proxy. [12:23.290 --> 12:28.750] So, unfortunately, we don't really have elaborate answers to those other dimensions. [12:28.750 --> 12:40.110] But I just wanted to mention that they're there because we're going to be talking more about proxy types or convention, which is the first thing that comes to people's mind when they think about how are you going to censor stuff? [12:40.230 --> 12:42.030] How are you going to get around it with a proxy? [12:42.210 --> 12:44.070] But there are these other layers and they're very important. [12:47.590 --> 12:47.990] Another... [12:50.510 --> 12:53.630] So we have to back off and try again after a random number of milliseconds. [12:53.810 --> 12:56.750] Carrier sense multiple access collision detection for microphones? [12:57.030 --> 12:57.250] Yeah. [12:57.650 --> 12:57.950] Okay. [12:58.110 --> 12:58.490] Okay. [12:58.610 --> 12:59.830] A random number of seconds have gone by. [12:59.830 --> 13:00.290] Okay. [13:00.770 --> 13:05.890] So this is a billboard of the funny variety. [13:06.450 --> 13:12.690] I used to work at a small independent film company that specialized in online rehabilitation videos using heavy machinery. [13:12.890 --> 13:13.890] It was a very boring job. [13:14.070 --> 13:17.870] But in general, it afforded me a fantastic view of an AT&T billboard. [13:18.030 --> 13:20.530] And one day I noticed from my office, which is the... [13:20.530 --> 13:25.170] Or at the time it was basically a military base that had been bought by the film company. [13:26.670 --> 13:30.790] The billboard liberation front had hit the AT&T billboard. [13:30.970 --> 13:32.230] And they were making a stand. [13:32.590 --> 13:35.250] And they were basically saying what a lot of people were thinking about. [13:35.550 --> 13:39.190] Which is that at second in Folsom, there is an AT&T building. [13:39.190 --> 13:45.050] And that AT&T building has very clearly been the source of some illegal wiretapping. [13:45.050 --> 13:48.550] And Mark Klein disclosed this as a whistleblower. [13:48.730 --> 13:51.970] And has shown that the U.S. government is doing things. [13:52.170 --> 13:53.410] And at the time was doing things. [13:53.550 --> 13:55.630] And I personally believe that they are still doing it. [13:56.170 --> 13:59.090] That are clearly wiretapping without a warrant. [13:59.090 --> 14:07.770] And I was really happy to see that people in the local San Francisco Bay Area, where I used to live at the time, weren't happy with that. [14:08.070 --> 14:08.470] Right? [14:08.650 --> 14:12.070] It's really easy to think about it as those countries and those people. [14:12.210 --> 14:13.610] But we're really all in this together. [14:13.810 --> 14:19.390] And when we do this kind of grouping thing where we say like, these people here are good and those people there are bad. [14:19.610 --> 14:23.030] We are sort of forgetting about the fact that we are all people together. [14:23.210 --> 14:23.850] And we're in this. [14:23.990 --> 14:25.870] And the Internet is this idea that we're interconnected. [14:25.870 --> 14:33.770] And when people start to put up roadblocks in between, what they're saying is that the individual doesn't have the same right as people who are somehow super individuals. [14:34.330 --> 14:34.430] Right? [14:34.590 --> 14:35.770] And we should put filters in between. [14:35.950 --> 14:36.650] And we should think for them. [14:36.750 --> 14:38.530] And we should block what they have access to. [14:38.750 --> 14:40.870] So I was very pleased to see this. [14:41.130 --> 14:43.010] Because I think that we should see more of this. [14:43.510 --> 14:43.730] Right? [14:43.810 --> 14:46.330] We should see people saying, it's not just about Iran. [14:46.510 --> 14:47.330] It's happening everywhere. [14:47.590 --> 14:49.590] Issues like network neutrality really matter. [14:49.970 --> 14:54.010] And people doing filtering and wiretapping here is not just a myth. [14:54.110 --> 14:54.630] This is real. [14:54.630 --> 15:02.250] If you've made a phone call in the United States in the last 10 years, the chances are that it was recorded by this warrantless wiretapping program in some way. [15:02.650 --> 15:05.670] Or the information and the metadata about the call is depending on who you are. [15:06.030 --> 15:06.870] That's really scary. [15:07.070 --> 15:10.270] And it's especially scary because it's pretty much obvious that it is illegal. [15:10.450 --> 15:11.830] And courts have ruled that this is illegal. [15:11.990 --> 15:13.950] But we don't actually see a lot of change. [15:14.510 --> 15:16.950] So we have to build some things that make this irrelevant. [15:16.950 --> 15:17.250] Right? [15:17.750 --> 15:20.730] The cypherpunks talked about getting rid of trusting the infrastructure. [15:21.130 --> 15:21.450] I don't know. [15:21.610 --> 15:22.390] Declan, when was that? [15:22.530 --> 15:23.270] 20 years ago? [15:24.570 --> 15:25.010] Yeah. [15:25.410 --> 15:26.050] 18 years ago. [15:26.330 --> 15:27.950] Well, the cypherpunks totally failed. [15:28.210 --> 15:28.310] Right? [15:29.090 --> 15:29.970] Most of them quit. [15:30.190 --> 15:31.030] And most of them sold out. [15:31.170 --> 15:32.090] And started doing other things. [15:32.310 --> 15:36.130] But I think that we need to have a new generation of people that aren't quitters. [15:36.130 --> 15:36.910] Sorry, Declan. [15:37.050 --> 15:38.490] I don't think you're a quitter, just for the record. [15:39.970 --> 15:42.910] But we need to build tools that make wiretapping irrelevant. [15:43.250 --> 15:49.390] We need to build systems that mean that when people break policies or laws, that they don't get anything that's interesting. [15:49.690 --> 15:49.770] Right? [15:49.970 --> 15:59.550] Because while the rule of law is nice, when the leaders of your country do not follow it, there's simply nothing that you can do except try to resist in ways that have nothing to do with these laws. [15:59.730 --> 15:59.830] Right? [15:59.970 --> 16:10.070] Like, instead of trying to get Bush or Obama or some other administration to be held accountable for the crimes that they have clearly committed during their administration, it is actually important to make those crimes irrelevant. [16:10.270 --> 16:12.990] Make them so that they can commit them all they like and they get nothing. [16:13.630 --> 16:13.710] Right? [16:13.850 --> 16:21.190] And I think that part of what Tor is working on is to make it so that when other governments do this, it is still useful for people here in our government. [16:21.390 --> 16:23.870] I mean, I'm an American and I'm disgusted with what's happening here. [16:23.970 --> 16:26.950] This NSA wiretapping thing is absolutely unbelievable. [16:27.330 --> 16:27.550] Right? [16:27.790 --> 16:31.030] And we're all responsible for this because we all pay taxes on this. [16:31.310 --> 16:34.870] So we can't think of it as us and them and we're good and they're bad. [16:34.990 --> 16:36.150] Because it just isn't that simple. [16:36.350 --> 16:36.710] Right? [16:36.810 --> 16:38.410] We have a responsibility in this. [16:38.530 --> 16:39.050] We are doing this. [16:39.130 --> 16:41.630] One of you probably works at a facility like this. [16:41.790 --> 16:47.810] So it's up to you to tell the world about crimes that are being committed and help us to design systems that resist those crimes. [16:48.450 --> 16:48.810] Right? [16:48.890 --> 16:51.050] That's how we change the world and make it a better place. [16:51.230 --> 16:53.310] Because we make people who abuse their power irrelevant. [17:04.540 --> 17:07.000] So I think that's a hard act to follow. [17:13.060 --> 17:15.500] So just trying to echo that in a way. [17:16.500 --> 17:22.460] There is a real role even if you look at surveillance outside of liberal democracies. [17:22.720 --> 17:28.020] There's a real role that liberal democracies, governments and technology companies have played in that. [17:29.020 --> 17:39.640] Jake will have a couple more screenshots that demonstrate this again and again in terms of countries in the U.S. building surveillance infrastructure that's used by people all around the world. [17:41.620 --> 17:58.360] One of the points that I think is interesting is that if you read material about the Internet Internet from, say, the PRC government, in terms of why do they block stuff, they basically say, well, every country blocks stuff. [17:58.620 --> 18:01.000] Every country has stuff that they don't like and they block it. [18:02.560 --> 18:06.120] And they started to say that a few years ago and it sort of wasn't true. [18:06.300 --> 18:07.560] And it was like, what are they talking about? [18:09.700 --> 18:12.560] This blocking thing is really new and weird. [18:13.710 --> 18:17.360] And the unfortunate thing is that it's becoming more and more true. [18:17.360 --> 18:21.680] But if a government says, all countries block things, we just block slightly different things than they do. [18:23.140 --> 18:27.840] Over time, that's becoming more and more accurate and less and less of a sort of rationalization. [18:28.880 --> 18:29.720] So there's that. [18:30.840 --> 18:32.340] There's the exporting technologies. [18:32.940 --> 18:36.540] And there's the U.S. firms building things that are used for censorship. [18:36.860 --> 18:38.620] And often leaving their logos on them. [18:38.680 --> 18:39.320] I have a quick question. [18:39.440 --> 18:42.120] Who here works at a firm that makes this type of stuff? [18:42.280 --> 18:43.720] Like, we won't ridicule you or anything. [18:43.840 --> 18:44.980] I actually just want to survey. [18:45.900 --> 18:49.180] Anybody here work at a place that builds filtering technologies at all? [18:51.550 --> 18:51.910] No. [18:52.470 --> 18:53.050] I mean, it's okay. [18:53.230 --> 18:54.010] You don't have to raise your hand. [18:54.110 --> 18:56.770] Just say like, yes, tap your neighbor, make them make a noise. [18:56.890 --> 18:57.210] Anybody? [18:57.330 --> 18:58.630] Does anybody work at a place like this? [18:59.110 --> 18:59.990] Yeah, I'm there. [19:00.310 --> 19:00.670] Fantastic. [19:01.150 --> 19:02.970] I have a suggestion for you. [19:04.090 --> 19:05.070] F*ck up your tools. [19:08.750 --> 19:09.110] Right? [19:09.470 --> 19:10.510] I want to see... [19:10.510 --> 19:15.370] I want to see software that is exported to a country that is bug doored. [19:15.850 --> 19:16.130] Right? [19:16.230 --> 19:17.410] Do you know what a bug door everyone is? [19:17.490 --> 19:18.410] Does everybody know what this is? [19:18.470 --> 19:18.750] Bug door? [19:19.250 --> 19:25.030] A bug door is a back door that you place in a piece of software by accidentally making a bug. [19:25.230 --> 19:25.490] Right? [19:26.010 --> 19:29.230] And if you exploit the bug, then you have a back door into the system. [19:29.230 --> 19:33.610] So I have a demonstration of a thing that looks a lot like a bug door later in the slides. [19:33.770 --> 19:34.350] And we'll get to that. [19:34.490 --> 19:36.350] But a challenge for you, right? [19:36.710 --> 19:47.450] If this software gets sent to a country or to a group of people that are doing something that is wrong, release an exploit and do not provide a patch for that country until they patch their society. [19:55.290 --> 20:05.950] So there's been a lot of discussion here in the U.S., like in the U.S. Congress, for example, about this issue of people exporting stuff. [20:06.590 --> 20:22.010] One of the difficulties that I see is exactly what Jake said just a couple of minutes ago, that it's very tempting to try to say that there's this list of bad countries that do bad stuff and that they're sort of the villains. [20:22.270 --> 20:25.530] And if we just didn't help them, then everything would be okay. [20:26.870 --> 20:34.030] And there are really important differences, obviously, in the kind of political freedom that people enjoy in different places. [20:35.150 --> 20:37.430] Very major and very dramatic differences. [20:38.050 --> 20:47.190] At the same time, over at EFF, we're always in court with the U.S. government challenging the U.S. government's restrictions on the Internet. [20:47.630 --> 20:49.370] So it's not that they don't exist. [20:49.650 --> 20:54.450] You know, all day long, we're there fighting with the U.S. government over its restrictions on the Internet. [20:55.550 --> 21:03.270] So I don't think there's going to be a list of who the bad countries are and who the good countries are in that sense. [21:04.510 --> 21:07.730] Try to have rankings or something, as some human rights groups try to do. [21:08.030 --> 21:11.210] But I don't think there's going to be the villains and the rest. [21:12.490 --> 21:23.810] One distinction that is interesting is that in some places, there are technical infrastructure specifically to block particular websites. [21:24.890 --> 21:27.250] And an idea that this is a routine thing to do. [21:27.490 --> 21:31.910] And in other places, there is not yet such infrastructure. [21:32.150 --> 21:38.030] Although there's potentially legal infrastructure that could make that possible in particular situations. [21:41.410 --> 22:03.750] One thing that's come out of this is a thing called the global network initiative, where a bunch of industry firms and a bunch of human rights activist organizations have gotten together and created a forum to talk about government pressures and how to resist some of those pressures by trying to rely on the rule of law and transparency. [22:04.350 --> 22:07.610] And I think this is a really neat development and EFF is a part of it. [22:08.430 --> 22:11.370] And there are a lot of meetings and it's a good opportunity to work on this. [22:11.970 --> 22:17.790] I definitely don't think that this is the solution or the whole picture or anything like that. [22:17.930 --> 22:22.330] But I think it's nice that there's a forum where some companies are willing to talk about these things. [22:23.190 --> 22:25.570] And what they're going to do about them and what they're encountering. [22:25.570 --> 22:34.530] In some cases, companies don't want to talk about things because they're afraid of alienating a particular government and harming their business prospects there. [22:35.430 --> 22:45.610] In the particular case of China, there's a concern about talking about things because China considers a lot of their rules to be state secrets. [22:45.890 --> 22:53.450] And if you talk about what the government asks you to do, then they can prosecute you for divulging state secrets. [22:53.450 --> 23:04.150] And that's been a problem, for example, for Google, which has been trying to be more transparent about interactions with government and law enforcement about requests for people's information and requests to take things down. [23:04.550 --> 23:12.950] And they've got this cool site where you can look up how many requests of different kinds came from different governments over the course of the year. [23:13.070 --> 23:14.830] And they have this big question mark on China. [23:15.110 --> 23:19.450] And they say, well, we can't tell you because they say that's a state secret and we could be prosecuted. [23:20.650 --> 23:28.290] And that's actually the only country, apparently, where they received requests where they were not even allowed to say how many requests they received. [23:30.470 --> 23:42.370] So another piece of the puzzle that's very obvious to people as something that you could do, especially if you're, like, a computer geek and you have a copy of Netcat or something, is that you could have a proxy and you could get around things. [23:43.010 --> 23:48.330] And if other people don't have proxies, you could give them proxies and set up proxies and tell them about the proxies. [23:48.670 --> 23:51.510] And then they could circumvent their Internet censorship by technical means. [23:52.330 --> 23:54.950] This is something that people have been doing for a long time. [23:54.950 --> 24:01.570] And it produces this famous kind of cat and mouse game where sensors try to figure out where the proxies are and block them. [24:01.990 --> 24:05.370] Or figure out what a proxy looks like and how you can block it in an automated way. [24:07.230 --> 24:11.770] There are a lot of trade-offs in terms of different features of these proxies. [24:12.550 --> 24:18.770] There's a talk... is it 10 things or 20 things that you should ask about your circumvention system? [24:21.530 --> 24:30.110] And the point is that there are trade-offs in terms of ease of use and cost and security against different kinds of adversaries and different kinds of threats. [24:31.250 --> 24:34.790] There are at least 20 different factors that are potential trade-offs. [24:35.990 --> 24:39.770] So the most common kind of proxy is a single-hop proxy, right? [24:39.910 --> 24:46.870] Where people who are being censored just go to a proxy that's not being censored in the same way and they ask the proxy to do something. [24:46.870 --> 24:49.110] And the proxy goes and does it and tells them the result. [24:51.390 --> 24:53.570] There's a lot of potential privacy concern about that. [24:55.890 --> 25:02.130] So the Tor people are of the opinion that that's not really safe enough for a lot of threat models. [25:02.450 --> 25:13.070] And they've done a lot of work to give you typically in the current Tor configuration three hops where you go through three different proxies before you come back out into the public Internet. [25:13.070 --> 25:14.950] And it's pretty complex. [25:15.170 --> 25:16.770] There's a lot of engineering work that's gone into it. [25:17.310 --> 25:22.730] And it's certainly, like, a lot harder than just setting up a squid proxy somewhere and then telling people about it. [25:23.130 --> 25:24.730] Or a CGI proxy or something. [25:25.130 --> 25:26.610] It's a lot more complexity. [25:26.890 --> 25:30.070] I don't mean that it's harder for the end user necessarily to run it. [25:30.950 --> 25:35.870] But it might be slower and it certainly requires more engineering effort from the people at the Tor project. [25:36.330 --> 25:36.870] The Tor developers. [25:37.290 --> 25:38.270] So there's a question. [25:38.870 --> 25:44.810] Why do the Tor people go to all this trouble to have this design and all this academic research and so on? [25:47.250 --> 25:51.950] So the main point seems to be the privacy threat, the threat of detection, the threat of monitoring. [25:53.330 --> 25:56.690] In the best case, the single hop proxy is encrypted. [25:56.970 --> 25:59.550] Do you want to take over on this threat and rationale? [25:59.870 --> 26:00.010] Sure. [26:00.330 --> 26:00.530] Absolutely. [26:00.970 --> 26:03.550] So, I mean, there have been a couple of cases. [26:04.030 --> 26:07.930] There's a guy in the audience right now who's a super badass Iranian activist. [26:07.930 --> 26:14.430] And he works, if I may be so bold as to talk about his work, he's very public about it. [26:14.510 --> 26:15.850] And I have a lot of respect for him. [26:16.070 --> 26:19.950] I actually consider him to be like a driving force behind the reason that I work on this software. [26:20.090 --> 26:21.750] It's people like him, but specifically him. [26:22.330 --> 26:26.030] And he works with people that they get killed, right? [26:26.150 --> 26:26.750] They get arrested. [26:27.010 --> 26:30.110] They get sentenced to death when they get caught. [26:31.010 --> 26:33.950] That's some f*cking serious shit right there, right? [26:33.950 --> 26:37.950] So, it's not dicking around time, basically, when that happens. [26:38.250 --> 26:41.450] You have to make bold claims and be willing to stand for them. [26:41.570 --> 26:43.290] And you still have to tell people that it's risky. [26:43.570 --> 26:49.210] So, just jumping from your computer to another computer is not going to cut it, right? [26:49.530 --> 26:51.110] There's all sorts of things that can happen. [26:51.350 --> 26:58.570] You will be in a situation in which the, say, Iranian government, and it's not just the Iranians, but they'll have access to the logs on that server. [26:58.750 --> 27:01.130] And they'll be able to do correlations and timing attacks. [27:01.130 --> 27:05.490] They may, in fact, run the proxies, which is why the proxies may, in fact, still function. [27:05.750 --> 27:06.870] They may not have crypto. [27:07.150 --> 27:08.650] They might be spoofing something. [27:08.810 --> 27:11.950] If they use self-signed certificates, they might be doing a man-in-the-middle attack. [27:12.150 --> 27:13.770] They might be doing something else. [27:13.990 --> 27:16.790] They could be doing BGP prefix hijacking, right? [27:16.890 --> 27:21.610] You need strong crypto, and you need distributed identity, and you need distributed trust. [27:21.970 --> 27:24.230] And most people think, well, that's not me. [27:24.230 --> 27:26.790] But it isn't you today. [27:27.390 --> 27:31.130] But everything that you do on the Internet builds a profile that tells a story about you tomorrow. [27:31.930 --> 27:35.910] And so it's absolutely a necessity to not use a single-hop proxy. [27:36.050 --> 27:41.570] And when I say one-hop, I actually think that it's important to distinguish between just one physical hop and one entity. [27:41.950 --> 27:46.390] So, yes, it's true that a one-hop proxy might be faster in some cases. [27:46.390 --> 27:50.610] But you have to ask yourself, especially in my friend's case, you know, how fast do you want to die? [27:51.590 --> 27:53.790] I would think the answer is not very fast. [27:54.010 --> 27:55.730] I'm working on dying quite slowly, thank you. [27:56.690 --> 28:10.210] But it comes down to another fact, which is that if you have a whole bunch of proxies and they're all run by one company, whether they're the shadiest company you've ever heard of or the most secure awesome company you've ever heard of, there's still one company, [28:10.290 --> 28:13.510] which means that they still have all of the organizational blunders of a company. [28:14.210 --> 28:16.710] There's no what we call privacy by design. [28:17.250 --> 28:20.250] And this is a really important distinction when you evaluate something like this. [28:20.370 --> 28:23.850] Like using a VPN provider, totally fantastic until they decide to burn you. [28:24.130 --> 28:24.530] Right? [28:24.770 --> 28:25.530] Or until they're owned. [28:25.730 --> 28:29.230] And how many people here have ever seen computer systems that are owned and no one knew they were owned? [28:29.370 --> 28:29.610] Anyone? [28:30.570 --> 28:30.970] Right. [28:31.110 --> 28:32.710] So that's probably your VPN provider. [28:34.050 --> 28:36.570] And it doesn't matter if it's your job or whatever. [28:36.790 --> 28:38.790] If it's your job, it's almost certainly owned. [28:38.930 --> 28:39.030] Right? [28:39.230 --> 28:40.230] Like, I mean, how... [28:40.230 --> 28:40.930] I mean, whoa. [28:41.450 --> 28:42.490] So it's a bad idea. [28:42.490 --> 28:45.290] So what we want to do is we want to build something that's a little bit stronger. [28:45.650 --> 28:48.010] Let's see if I can stand up here and wave my arms like a monkey. [28:48.590 --> 28:48.810] Okay. [28:49.410 --> 28:50.330] So we have Alice. [28:50.630 --> 28:55.290] And Alice is, let's say, someone that's just wanting to get onto the Internet. [28:55.450 --> 28:57.590] She wants to be able to read Facebook or Twitter. [28:57.810 --> 29:01.890] She wants to be able to post a picture of a cop shooting Netta in the heart. [29:02.450 --> 29:08.770] Or, you know, basically wants to do something that she might have to fear retribution from the state or from other actors. [29:08.770 --> 29:11.410] So Alice needs to connect to the first relay. [29:11.690 --> 29:12.870] She has a list of relays. [29:13.050 --> 29:14.370] And we can talk about that in a second. [29:14.570 --> 29:17.470] But she has these little colored streams. [29:17.810 --> 29:19.970] And the idea is that she has a TLS connection. [29:20.170 --> 29:23.050] This looks like Apache and Firefox talking to each other. [29:23.050 --> 29:26.070] So it's a little bit of network steganography. [29:26.350 --> 29:28.030] Jesus Christ, that club motto is fantastic. [29:29.750 --> 29:31.970] So there's a TLS connection between the two of them. [29:32.590 --> 29:34.470] We like to think that it's not really Stego. [29:34.730 --> 29:38.870] And the reason is because Stego is a pretty strange thing. [29:39.130 --> 29:41.690] And people like to pretend that they've fixed it or that it's perfected. [29:41.790 --> 29:44.110] But Stego is basically only one bit of security. [29:44.270 --> 29:46.810] You're hiding and you're hidden or you're not. [29:46.810 --> 29:50.230] And I think that it's like a little dangerous to make the claim of Stego. [29:50.470 --> 29:52.170] And so people that do that, you should be pretty... [29:52.170 --> 29:53.470] You should worry about what they're saying. [29:54.010 --> 29:56.050] In any case, Relay 1 knows about Alice. [29:56.470 --> 30:00.090] Knows that Alice is in Canada or Iran or wherever, right? [30:00.190 --> 30:02.350] And she knows this herself, obviously. [30:02.610 --> 30:04.810] So what she does is she builds what's called a circuit. [30:05.030 --> 30:06.470] And she builds a circuit to Relay 1. [30:06.630 --> 30:07.870] She extends it to Relay 2. [30:08.050 --> 30:09.550] Relay 2 now knows about 1. [30:09.890 --> 30:12.250] And Relay 2 will soon learn about Relay 3. [30:12.730 --> 30:14.650] And Relay 3 knows where Alice is going. [30:14.650 --> 30:15.890] Alice wants to talk to Bob. [30:16.530 --> 30:19.230] And Relay 3 has no idea where Alice is anymore. [30:20.050 --> 30:23.950] Each different Relay is run by either a different person or a different organization. [30:24.370 --> 30:26.430] And this is an example of privacy by design, right? [30:26.690 --> 30:29.170] So there's a whole bunch of people in the audience here that run Tor servers. [30:29.370 --> 30:33.490] And unless they all collaborate together, you're not using one organization. [30:33.750 --> 30:37.190] Each person has a subset of the information required to screw you over. [30:37.430 --> 30:42.430] And they won't do it because the reason they run it is because they need it themselves and because they want to help you. [30:42.430 --> 30:46.990] There are cases where this could happen, where someone could run all of them together. [30:47.270 --> 30:52.270] But I think that it is extremely unlikely that you will run into those cases. [30:53.150 --> 30:57.170] We'd love to hear about cases where you think that that is happening so that we can improve the software. [30:57.410 --> 31:02.930] For example, if you want to create a circuit, our circuit selection algorithm is all free software. [31:03.550 --> 31:05.470] And so you can see how we select the circuit. [31:05.570 --> 31:07.510] But we have a set of constraints you have to satisfy. [31:07.510 --> 31:11.970] So if you want to build a connection to the first hop, it has to have like a guard flag, for example. [31:12.230 --> 31:15.770] And if you want to exit from the network, the network server has to have an exit policy allowing it. [31:16.310 --> 31:21.210] None of the servers in your circuit are allowed to be in the same slash 16 network block. [31:21.590 --> 31:24.470] And there are other things like people that want to run 50 Tor servers. [31:24.470 --> 31:27.330] I run about 15 Tor servers at any given point in time. [31:27.510 --> 31:29.850] And most of them are tied together in what's called a family. [31:30.070 --> 31:36.450] So that you, when you choose one of my servers, you don't choose 14 other of my servers in later cases when you build circuits. [31:37.770 --> 31:38.150] Wow. [31:38.230 --> 31:39.350] I wish I could read this off the screen. [31:39.570 --> 31:43.210] But this is pretty much exactly what I'm talking about with Iran. [31:43.390 --> 31:48.490] And this is super scary because this is the future of a lot of places if people choose to take it in this direction. [31:48.490 --> 31:54.110] When you have an authoritarian regime, which is every government in power except maybe in Christiania in Denmark. [31:55.150 --> 31:57.010] For those of you that have been there, you understand. [31:57.170 --> 31:59.650] And for those of you that haven't, I suggest a visit to Copenhagen. [32:02.070 --> 32:07.530] Essentially, it says these people should know where they are sending the SMS and email as these systems are under control. [32:07.730 --> 32:11.150] They should not think using proxies will prevent their identification. [32:11.370 --> 32:12.250] So this is key, right? [32:12.450 --> 32:17.930] They want to identify you so they can hunt you down and arrest you and your family and maybe kill you, right? [32:17.930 --> 32:23.370] And it's even worse if they're trying to read U.S. websites or use U.S. service potentially because then they look like spies. [32:23.770 --> 32:24.810] And they're probably not. [32:24.970 --> 32:31.270] They're probably people that are just trying to get the outside perspective on what's happening during the media blackout in their particular part of the city. [32:31.510 --> 32:31.810] Right? [32:31.930 --> 32:32.870] So this is super dangerous. [32:33.530 --> 32:41.610] It says, if they continue, those who organize or issue appeals about opposition protests have committed a crime worse than those who take to the streets. [32:42.390 --> 32:43.950] Like, just like, think about that, right? [32:44.070 --> 32:44.950] That's crazy. [32:44.950 --> 32:48.990] That is the national police chief of Iran saying that. [32:49.410 --> 32:50.650] So those are the circumstances here. [32:50.790 --> 32:53.130] And so it's why privacy by design is so very important. [32:53.550 --> 32:57.890] Because basically, the situation for a lot of people is actually that dire. [32:58.210 --> 33:03.250] I mean, Iran is, I think, a pretty good example, but it is not the only example by any means. [33:03.450 --> 33:03.530] Right? [33:03.650 --> 33:05.970] The United States is clearly different than that. [33:05.970 --> 33:08.670] And I think it is important to not say that they are the same. [33:08.970 --> 33:13.910] But it is also the case that it's with the NSA wiretapping that we have. [33:14.110 --> 33:17.510] One might ask oneself, what did they do with all of that data? [33:17.650 --> 33:20.230] And what will they do with that data later when you do something? [33:20.490 --> 33:26.970] What happens when they decide you're affiliated with a group or you've done a thing and that information is somehow used against you? [33:26.970 --> 33:27.890] What will you do then? [33:28.270 --> 33:28.310] Right? [33:28.550 --> 33:39.010] And the answer is you will probably be in a lot of trouble and there won't be much for you to do because they will have built a dossier on you that, you know, that basically that the East German government would have killed for. [33:39.730 --> 33:40.090] Right? [33:40.250 --> 33:45.870] But they don't even need to have that kind of oppressive regime because they have a passive aggressive regime, if you will. [33:45.870 --> 33:57.130] There was a great line, I wish I had it here, in a friend of the court brief that AT&T filed in the Olmsted case many decades ago about the legality of wiretapping. [34:01.130 --> 34:08.930] And I think they said this telephone system, oh, it was great. [34:09.250 --> 34:22.750] They basically said that the telephone system was much more privacy invasive than what the British did to the colonists before the Revolutionary War with the writs of assistance and general warrants. [34:25.230 --> 34:26.170] We should look that up. [34:26.290 --> 34:26.530] It was great. [34:26.670 --> 34:28.210] It was AT&T in the Olmsted case. [34:28.670 --> 34:33.250] We should power through some more of these slides because we've got only a little bit under half an hour and I want to take some questions. [34:34.030 --> 34:34.910] So real quick, Tor. [34:35.190 --> 34:35.830] It's free software. [34:36.150 --> 34:40.170] Free software is super important in this case because we don't want you to trust us. [34:40.270 --> 34:41.930] We want you to be able to audit the source code. [34:42.070 --> 34:43.950] We want you to be able to do anything you want with it. [34:44.050 --> 34:47.190] It's a BSD license so you can repackage it and do whatever you want with it. [34:47.530 --> 34:48.330] It's fantastic. [34:48.770 --> 34:49.610] You should use it. [34:50.290 --> 34:58.070] We have a specification which is similar to an RFC style or an IETF style type thing but avoiding all of the committees and meetings involved with those trappings. [34:59.190 --> 35:04.610] We also, as a result of having those specifications, have a bunch of different independent client implementations. [35:04.770 --> 35:05.870] And we would like more, right? [35:05.970 --> 35:14.670] We want as many people as possible to write Tor-related software because we think that it will not only help us find bugs in our specification but also in our implementation. [35:14.670 --> 35:16.310] Do you want some mate? [35:17.390 --> 35:18.450] You're falling asleep there? [35:20.270 --> 35:21.230] Sorry to bore you. [35:23.250 --> 35:27.410] In any case, we have approximately 2,000 active relays. [35:27.610 --> 35:30.610] About one third of those are exit relays. [35:31.170 --> 35:36.470] And so what that means is that one third of them allow you to connect outside of the Tor network to the general Internet. [35:36.470 --> 35:37.810] And there are some restrictions on that. [35:38.630 --> 35:41.930] And we have about a quarter of a million users at any given point in time. [35:43.050 --> 35:43.670] Count this. [35:43.830 --> 35:46.710] We have to do some statistical... I don't want to say magic. [35:46.950 --> 35:55.730] But Karsten Losing, the nice German who does our counting, he has a little bit of trouble in counting this because we don't have logins and passwords. [35:55.890 --> 35:59.190] We don't have any of this crap that would allow us to violate a policy, right? [35:59.190 --> 36:01.210] So we have to make best guesses at this. [36:01.370 --> 36:05.790] So we have, at best guess, about a quarter of a million users that are returning on a daily basis. [36:05.930 --> 36:08.810] And this is based entirely on volunteer efforts, right? [36:09.050 --> 36:13.250] The Tor project itself just writes the software and promotes the use of it. [36:13.870 --> 36:18.530] Everybody here in this room, if everybody runs a Tor server, we double the size of the Tor network tomorrow. [36:19.110 --> 36:19.370] Right? [36:19.490 --> 36:20.310] That's how this works. [36:20.510 --> 36:22.650] And that's why we have 2,000 relays. [36:22.650 --> 36:34.910] So you should really consider using your privilege to help other people if you have a computer and a network, especially considering the fact that you can control whether or not you're an exit, which means you get to control basically how much you risk, [36:35.210 --> 36:37.690] which is to say you get to choose your own level of involvement. [36:39.370 --> 36:39.730] Right. [36:40.610 --> 36:43.910] The network is approximately greater than 3 gigabits a second. [36:44.270 --> 36:46.110] And we're a 501c3 nonprofit. [36:46.170 --> 36:50.930] So if you want to give us money, we're happy to take it and you get a tax write-off, which is pretty fantastic. [36:50.930 --> 36:53.850] We believe that you can't save the world by making a profit. [36:54.090 --> 37:02.170] And we don't really think we're saving the world, but we're trying to build a viable alternative for the way that things are going now, which is super important, right? [37:02.390 --> 37:05.870] If you want to see change, you have to be the trouble you want to see in the world. [37:07.270 --> 37:07.630] So... [37:08.230 --> 37:08.850] Hold on. [37:09.010 --> 37:09.890] We've got some more, right? [37:10.830 --> 37:12.470] We have a bunch of funded developers. [37:12.670 --> 37:13.610] I work full-time on Tor. [37:13.830 --> 37:16.170] There's a whole bunch of other people that work full-time on this. [37:16.270 --> 37:19.990] People dedicate their lives to this because we believe that we have to build this alternative. [37:19.990 --> 37:25.770] And we are the only group that I know of that has been funded by both the Department of Defense and the Electronic Frontier Foundation. [37:29.950 --> 37:32.690] And I want to say, you know, there's a lot of corporate bashing. [37:33.630 --> 37:40.650] Google, despite the fact that they could probably overthrow every single government in the world tomorrow, hasn't done that to my dismay. [37:42.510 --> 37:49.070] But they do fund us from time to time because they really actually do put their money where their mouth is when it comes to privacy. [37:49.430 --> 37:51.450] Like, it sounds like they don't, but they really do. [37:51.630 --> 37:52.390] They gave me this phone. [37:52.670 --> 37:53.590] This Nexus One phone. [37:53.970 --> 37:55.230] Feel free to try to own it remotely. [37:55.850 --> 38:02.090] And the thing is that they did that so that we could port Tor to Android because they really actually do want to support viable alternatives for people. [38:02.190 --> 38:07.990] They know that they can't get ad revenue from anonymized streams, but they know some people need access to information, and that is really important. [38:07.990 --> 38:25.690] And they have super, super smart people like Adam, Imperial Violet, who works on Tor occasionally, or SSL-related things, working on privacy-enhancing technologies because they really believe that access to information and really being able to produce and consume information is essentially a fundamental human right, [38:25.710 --> 38:27.590] as outlined in the United Nations Declaration. [38:28.390 --> 38:36.210] And while some people might not agree with that, and I obviously don't speak for Google, I think it's quite clear that we should move in that direction as if that is true. [38:36.210 --> 38:38.790] Because I think it is true, and I think it's a reasonable thing to do. [38:39.510 --> 38:42.170] So, real quick crash course in Tor. [38:43.650 --> 38:46.250] It is not TCP over TCP. [38:46.670 --> 38:55.010] So just in case you were wondering, we transport streams, and it's for TCP connections, but the way that it works generally is that you have a SOX proxy locally. [38:55.290 --> 38:56.530] You make a connection to it. [38:56.650 --> 38:58.510] It builds the circuit I mentioned previously. [38:58.730 --> 39:00.790] You attach a stream to a given circuit. [39:01.210 --> 39:02.390] You leave the Tor network. [39:02.510 --> 39:05.710] The TCP connection is actually created at the edge of the Tor network, right? [39:05.710 --> 39:07.190] So, it's pretty straightforward. [39:07.790 --> 39:09.330] It has limited DNS query support. [39:09.490 --> 39:11.830] Although, lately, Colin Molnar and I have been working on this. [39:11.990 --> 39:14.110] We built a small DNS shim. [39:14.190 --> 39:16.790] He originally wrote it about, like, three years ago and abandoned it. [39:16.910 --> 39:18.550] And I spent the last month and a half working on it. [39:18.650 --> 39:20.010] It's called TTDNSD. [39:20.730 --> 39:23.450] That's the TCP Tor DNS daemon. [39:23.450 --> 39:28.610] And the idea is that you can make any arbitrary query type you'd like for DNS locally. [39:29.270 --> 39:33.110] And it'll make a TCP connection, say, to, like, 8.8.8.8. [39:33.890 --> 39:35.470] And it'll do recursive DNS. [39:35.750 --> 39:36.070] Lucky number eight. [39:36.270 --> 39:37.170] Lucky number eight. [39:37.510 --> 39:39.050] Probably not chosen on accident. [39:39.810 --> 39:42.170] And you can use any recursive server you'd like. [39:42.330 --> 39:43.830] And the idea, then, is that you can do anything. [39:43.830 --> 39:45.930] So, you can have a fully transparently Torified network. [39:46.110 --> 39:48.610] You can make requests for serve records, MX records, et cetera. [39:48.970 --> 39:51.110] And you get all the normal protections you would get otherwise. [39:51.370 --> 39:53.910] It also allows you to do DNS sec, I believe, if you need. [39:54.230 --> 39:56.470] You might need a different recursive resolver for that. [39:56.850 --> 39:59.050] We also support basic DNS stuff. [39:59.150 --> 40:01.010] There's a paper that I just wrote about this. [40:01.470 --> 40:04.170] Which is basically state of Tor and DNS union. [40:04.170 --> 40:07.510] And it's worth reading if you care about anonymized DNS. [40:07.850 --> 40:10.310] Because DNS is a great way to de-anonymize someone, actually. [40:12.470 --> 40:17.350] Basically, everybody that runs a Tor relay in this room, when they go home tonight, will publish their server descriptors. [40:17.450 --> 40:22.310] That means your IP address, your public key information, a couple other bits of information, maybe an email address. [40:22.830 --> 40:24.590] You publish it to some directory authorities. [40:24.850 --> 40:27.270] There are currently eight directory authorities run in the world. [40:27.410 --> 40:28.290] There's one in Sweden. [40:28.490 --> 40:31.270] There's a couple in the United States, Austria, Germany, et cetera. [40:31.910 --> 40:34.010] They're run by different people that really believe in this. [40:34.010 --> 40:35.310] Enough to put their name on it. [40:35.710 --> 40:41.330] And while a centralized authority has some problems, we currently don't believe that we are running into any of them. [40:41.650 --> 40:49.430] And maybe that doesn't work well in the long run, but it works really well right now for not only stemming abuse, but also monitoring the network, understanding the network, and growing it. [40:49.870 --> 40:58.390] So a client basically bootstraps this by going to a directory authority or to any Tor server and downloads a list of all of the possible server relays. [40:58.830 --> 41:02.170] We call them ORs, you know, as in an onion router. [41:02.910 --> 41:05.590] And basically clients choose their path on the network. [41:05.750 --> 41:18.890] And this is super important because it's essentially a private information retrieval system at its most basic point, which is that you want to choose a hop through the network that no one else knows or a path through the network by choosing hops in that selection. [41:19.650 --> 41:20.970] And you do that. [41:21.090 --> 41:23.610] And when you have done that, you exit the network. [41:23.610 --> 41:29.070] And it's super important that no one else knows what you chose, or they can de-anonymize you and link your communications. [41:29.450 --> 41:30.710] So you have to download the whole list. [41:30.830 --> 41:34.470] This sucks if you're on a 9600 baud cellular telephone in Zimbabwe. [41:34.810 --> 41:36.910] Works pretty good a lot of other places. [41:37.670 --> 41:40.690] Nice thing is you don't have to download your list of descriptors. [41:40.870 --> 41:43.250] Every single time you want to use it, you download it and it's good for a while. [41:43.490 --> 41:45.430] And the network stays pretty fresh. [41:46.610 --> 41:48.990] But as I said previously, there are no logins. [41:49.170 --> 41:50.110] There are no passwords, right? [41:50.190 --> 41:50.750] You install it. [41:50.870 --> 41:52.610] And yeah, it sometimes can be kind of slow. [41:52.850 --> 41:56.450] I regularly download things at 250 kilobytes a second over Tor, though. [41:56.650 --> 41:59.870] So your mileage may vary and your throughput may vary. [42:02.290 --> 42:02.690] And... [42:02.690 --> 42:05.250] I skipped over the there's a lot more to this protocol. [42:05.450 --> 42:05.730] Right. [42:05.730 --> 42:06.130] There sure is. [42:06.350 --> 42:07.830] There is a lot more to the protocol. [42:08.050 --> 42:13.830] But the most important thing to remember is that you are as secure using Tor as you are using the Internet anywhere. [42:14.770 --> 42:15.970] Sometimes more secure. [42:16.370 --> 42:20.290] There has been some controversy about this, that you can sniff an exit node, for example. [42:20.890 --> 42:24.290] Well, news flash, the Internet is not secure. [42:25.790 --> 42:26.230] Okay. [42:26.650 --> 42:27.730] So, moving along here. [42:27.850 --> 42:32.610] If you use Tor, it's possible that you'll be more secure because the people targeting you are probably local to you. [42:33.170 --> 42:45.350] It is almost certainly that that is the case, especially in the case of Iran, especially in the case of other repressive regimes like the United States or Canada or Germany or the United Kingdom, which all pervasively censor in some way or another, depending on where you are. [42:46.450 --> 42:53.970] So, anonymity is important, but it's pretty difficult to talk about anonymity with my grandmother, aside from the fact that she's blind and cannot use a computer. [42:54.470 --> 42:57.750] She does not actually know what that word really means in a technical sense. [42:57.850 --> 43:00.850] So, instead, I tell her privacy, like curtains or pants. [43:02.390 --> 43:02.950] Right? [43:03.270 --> 43:04.550] Everybody understands that. [43:04.790 --> 43:06.070] Who here has nothing to hide? [43:06.210 --> 43:07.130] I challenge you to streak. [43:08.650 --> 43:08.990] Right. [43:09.750 --> 43:10.130] Okay. [43:10.570 --> 43:11.990] Businesses don't care about privacy. [43:12.290 --> 43:16.030] They usually want to do something, you know, securely. [43:16.350 --> 43:20.590] That's what they care about because that's what sells widgets and who does it and so forth. [43:21.510 --> 43:30.650] Governments, generally, as it says there, they care about traffic analysis resistance because they've got privacy, they've got security up the wazoo, they've got everything else you could want. [43:30.930 --> 43:35.730] But they don't have traffic analysis resistance, which is another fancy way of talking about anonymity. [43:36.110 --> 43:40.510] And, of course, what we're really talking about mostly today is this idea of blocked users. [43:40.690 --> 43:43.050] And they're like, oh, my God, I can get my Facebook. [43:43.590 --> 43:56.050] And it sounds super trivial until you think about things like what Moxie Marlin Spike has said, where you have a network effect with things like Facebook, where when you're no longer able to reach it, you no longer have a network, you no longer have the ability to communicate, [43:56.230 --> 43:57.810] you don't get invited to parties, whatever. [43:58.090 --> 44:01.450] I mean, I don't really go to those parties, but if you do, then you care about that. [44:01.810 --> 44:06.530] And a lot of people do care about that, especially because it's hosted outside of their country in a lot of cases. [44:06.710 --> 44:07.630] And that is very powerful. [44:08.030 --> 44:11.650] Iceland, for example, has a ridiculous penetration rate when it comes to Facebook. [44:11.850 --> 44:14.010] I think like almost everybody in Iceland is on Facebook. [44:14.710 --> 44:16.970] And that means that it's really important to be able to reach it. [44:17.050 --> 44:22.550] And if someone were blocking it, I mean, obviously, it's not tenable if everybody in the entire country has to hop a firewall. [44:22.810 --> 44:25.890] But it's nice to build an alternative that allows you to do that if you need it. [44:26.070 --> 44:28.170] And hopefully you'll use it for something more radical than Facebook. [44:29.050 --> 44:29.230] But... [44:29.990 --> 44:30.310] Oops. [44:31.130 --> 44:32.050] Can I go on to this one? [44:32.170 --> 44:32.570] Yeah, sure. [44:32.690 --> 44:32.970] Why not? [44:34.010 --> 44:34.710] We're pretty late. [44:35.070 --> 44:35.390] Yeah, we are. [44:35.530 --> 44:35.710] Wow. [44:35.930 --> 44:36.370] That's incredible. [44:36.730 --> 44:39.490] Okay, so just real quick, lots of legitimate people use Tor. [44:40.210 --> 44:41.070] That's pretty much... [44:41.070 --> 44:46.170] You know, a lot of people will say like, you know, it's because of you that bad people are allowed to do things in the world. [44:46.290 --> 44:51.670] And my response is, you might be that bad person, and I still think we should run this network despite you. [44:52.570 --> 44:53.130] Pretty much. [44:53.390 --> 44:56.470] Because there are a lot of people out there that don't have the privilege that a lot of us have. [44:56.610 --> 45:01.310] And there are a lot of people out there that need it and can't even speak up and say that they need it for the reasons that they need it. [45:02.770 --> 45:06.550] And yeah, there are a lot of sick people and in the real world. [45:07.750 --> 45:08.070] Right? [45:08.370 --> 45:09.810] The thing is that we're all in this together. [45:10.170 --> 45:11.210] So we have a choice. [45:11.430 --> 45:22.490] We can decide that we can live in a network police state because of a couple bad actors, Or we can decide that we would like freedom and liberty on the Internet as we have in real life because we balance these things reasonably. [45:22.830 --> 45:24.490] And some people don't agree with that. [45:24.630 --> 45:25.490] And f*ck those people. [45:29.340 --> 45:31.540] And I'll tell you one more thing. [45:31.720 --> 45:37.660] I mean, not to be too colorful about it, but the FBI's Innocent Images Division uses Tor to find child pornographers. [45:37.920 --> 45:44.180] So when the police use Tor to find those sick people, you have to remember that content doesn't include intent. [45:44.180 --> 45:53.560] If someone is uploading those images or downloading those images to build a sting operation or to arrest people, who are you to tell me that I am doing the wrong thing? [45:54.100 --> 45:59.100] Because I think that actually pretending that these things don't exist actually doesn't make them go away, right? [45:59.280 --> 46:01.760] Ostrich's head in the sand doesn't change the world one bit. [46:03.240 --> 46:03.720] Sorry. [46:04.720 --> 46:07.680] So I'm trying to skip a bit because we haven't even mentioned bridges. [46:08.120 --> 46:08.300] Right. [46:08.660 --> 46:10.620] So essentially you've got these servers. [46:10.800 --> 46:11.760] Alice wants to reach them. [46:11.760 --> 46:13.760] The trusted directory has all the IP addresses. [46:14.440 --> 46:14.980] You've got a firewall. [46:15.080 --> 46:17.000] The firewall loads up those 2,000 IP addresses. [46:17.180 --> 46:17.260] Boom. [46:17.380 --> 46:17.700] It's blocked. [46:18.080 --> 46:18.240] Okay. [46:18.780 --> 46:19.500] That's a problem. [46:19.980 --> 46:23.000] So you see this in China, Iran, Lebanon, Lebanon. [46:23.520 --> 46:23.620] Wow. [46:24.520 --> 46:25.740] Lebanon, Qatar, right? [46:25.900 --> 46:27.040] Every day you see stuff like this. [46:27.180 --> 46:31.260] It is usually the case that these websites are blocked, right? [46:31.640 --> 46:34.760] And these websites being blocked, that sucks. [46:34.980 --> 46:36.060] We have a solution for that, though. [46:36.060 --> 46:37.500] What we do is... [46:39.460 --> 46:41.820] We do what wares people used to do back in the day. [46:42.040 --> 46:43.580] We deliver Tor via email. [46:44.080 --> 46:47.100] So you send us an email and we'll give you some binaries and some signatures. [46:47.300 --> 46:51.360] So all you have to be able to do is find our GPG key information and you can verify that you got it. [46:51.540 --> 46:56.540] And it just so happens that because people haven't solved the spam problem, they also haven't solved this problem. [46:57.040 --> 46:59.080] So now you get that and you get around it. [46:59.580 --> 47:02.180] And the software for delivering this is pretty useful. [47:02.180 --> 47:03.020] Here's an example. [47:03.460 --> 47:05.100] This is a slightly older graph. [47:05.200 --> 47:09.580] In April, we had about 400 people a day at a peak downloading Tor via email. [47:09.940 --> 47:14.260] I was in China in Hong Kong doing a training with some people from mainland China. [47:14.600 --> 47:23.040] And one day we had, like, I think 10 or something thousand people, 10,000 people or so, that used this because they heard that the Chinese government was about to block Gmail. [47:23.320 --> 47:26.080] And so they were like, oh, my God, I got to get myself a copy of Tor. [47:26.220 --> 47:33.640] And someone Twittered or the internal China version of Twitter, you know, use this email address and all of a sudden we just saw tons of requests. [47:34.180 --> 47:37.980] And that means that their censorship system was not even remotely set up to deal with that type of filtering. [47:38.260 --> 47:42.100] And sometimes mail servers use start TLS, which means that they got dynamic encryption. [47:42.540 --> 47:45.040] I mean, they got opportunistic crypto and that was pretty helpful. [47:45.200 --> 47:45.720] So they got it. [47:45.800 --> 47:52.140] They were able to verify the signature because social networks allowed people to post the right signatures and the keys for verification and people got it. [47:52.140 --> 47:56.740] And so it is pretty rare, though, that the actual network is blocked. [47:56.940 --> 48:07.440] But China and Tor are sort of in this cat and mouse game, which is stupid, and we don't really want to play it, but we're doing it anyway, which is that they download the list of descriptors and they block the website. [48:08.040 --> 48:13.440] So the firewall, if you happen to run a Tor server, you can't visit Baidu, for example, because your IP address is in the filter. [48:13.560 --> 48:16.720] And if you try to go to Baidu, then boom, you get kicked off. [48:16.880 --> 48:18.960] You get bi-directional TCP resets, for example. [48:18.960 --> 48:22.860] That's a big problem and it happens all over the place in China. [48:23.080 --> 48:27.200] It also happens in some other places, like on small corporate networks, because they download this list. [48:27.480 --> 48:35.200] And we also actually provide an API for downloading a list of all of these things for people like the Wikipedia that want to be able to treat Tor users differently. [48:35.500 --> 48:36.460] But in general... [48:36.460 --> 48:40.780] They want to block people who are exiting from Tor, rather than people who are entering into Tor. [48:40.940 --> 48:44.620] So in general, the idea here is that we want to get around that, right? [48:44.760 --> 48:47.380] So we want to build a viable alternative and it's called a bridge. [48:47.940 --> 48:56.380] And a bridge is essentially a way to use mutual aid and solidarity as principles for working around this type of network fascism. [48:56.740 --> 49:05.420] And the idea is you send an email to bridges at torproject.org or you are a friend on one of our Twitter accounts or something like this, and we give you some information. [49:05.620 --> 49:12.560] So we take the problem, which is how do we keep 2,000 relays out of the hands of the Chinese government or any other government. [49:13.940 --> 49:17.180] And then we give, basically, access to this network, right? [49:17.280 --> 49:17.880] So how do we do that? [49:18.020 --> 49:18.560] Well, we can't. [49:18.660 --> 49:19.560] That's an impossible problem. [49:19.720 --> 49:25.820] So instead, what we do is we segment these things that are called bridges and we give them out selectively to different buckets. [49:26.100 --> 49:30.040] So someone from one Gmail address always gets the same set of bridges. [49:30.040 --> 49:35.340] So you have to basically break Google's capture system in order to be able to get all the bridges. [49:35.580 --> 49:42.380] Or you have to visit bridges.torproject.org from every different geographic location in the world to get all of the bridges. [49:42.540 --> 49:54.300] And then we still have a reserve that we hand out to social networks so that important key players in places that have told us they're working for social change, those people still have access because they're not doing actual network fingerprinting in this case. [49:54.300 --> 49:56.720] They're usually just doing IP and port address combinations. [49:57.100 --> 50:00.440] And so here's a great example of graphing network fascism. [50:00.760 --> 50:00.840] Okay? [50:01.100 --> 50:05.100] So this is China, just before the 60th anniversary of some dude taking over the country. [50:05.600 --> 50:07.280] And it goes like this. [50:07.380 --> 50:08.560] 10,000 users were connecting. [50:08.740 --> 50:14.020] I have a box in Amsterdam that's graciously donated by the founder for XS4ALL, Rop Gonggrij. [50:14.360 --> 50:15.620] And he's a fantastic guy. [50:16.120 --> 50:17.320] He gave me this box. [50:17.400 --> 50:20.440] It pushes somewhere between 100 and 300 megabits of tour traffic a day. [50:20.740 --> 50:23.780] One day, we noticed that we had about 10,000 users from China. [50:23.780 --> 50:26.660] And then we noticed around that anniversary, we had zero. [50:27.420 --> 50:27.820] Right? [50:28.040 --> 50:30.360] They effectively blocked people connecting to that box. [50:30.640 --> 50:31.540] Here's the next day. [50:32.460 --> 50:33.820] This is people using bridges. [50:34.040 --> 50:34.880] They adapted instantly. [50:35.780 --> 50:36.140] Right? [50:36.440 --> 50:39.280] So bridges really are a viable alternative when people are blocked. [50:41.260 --> 50:49.220] So Jake's been, as we said, around the world, I think we probably have to rush through this a bit because even counting questions, we have like five minutes. [50:50.880 --> 50:54.140] Maybe you can say like four seconds about each slide. [50:54.280 --> 50:54.680] Sounds good. [50:54.820 --> 50:55.060] Let's go. [50:55.420 --> 50:55.580] Okay. [50:55.820 --> 50:59.180] So he went to these countries and he tested their networks and saw some of the censorship. [50:59.480 --> 51:02.800] It was often done with the help of companies from the U.S. [51:03.940 --> 51:04.380] China. [51:05.240 --> 51:09.080] Every quarter or so, they block, download lists, and they come after Tor. [51:10.460 --> 51:13.260] Just so happens that they also take that list directly from us. [51:13.400 --> 51:18.420] So maybe it's a good idea to, for example, start putting in websites that grant visas to people in China. [51:18.640 --> 51:20.680] Maybe then that will disrupt their network communication. [51:20.940 --> 51:21.100] Nah. [51:21.480 --> 51:21.860] Who knows? [51:22.580 --> 51:25.280] Here's an example of another squid proxy. [51:25.280 --> 51:26.460] This is Lebanon. [51:27.560 --> 51:27.960] Here. [51:28.460 --> 51:28.860] Okay. [51:28.980 --> 51:29.400] I'll make it easier. [51:29.780 --> 51:29.960] This one. [51:30.320 --> 51:30.920] So Ogero. [51:31.080 --> 51:33.980] They run squid proxies, 2.5 stable 11. [51:34.240 --> 51:35.080] Those are the IP addresses. [51:35.240 --> 51:36.280] These slides will be online later. [51:36.380 --> 51:37.380] Feel free to take a look at those. [51:40.260 --> 51:41.860] Ogero does some pretty nasty stuff. [51:41.920 --> 51:42.620] I was in Beirut. [51:42.720 --> 51:48.420] I was actually detained and forcibly ejected from Lebanon when I was there. [51:48.540 --> 51:49.180] So I was deported. [51:49.780 --> 51:51.160] They did not appreciate me. [51:52.120 --> 51:56.260] It was a little bit frustrating, actually, because I don't think that I was doing anything wrong at all. [51:56.420 --> 51:58.080] And I think it was mostly because of my last name. [51:58.340 --> 52:00.080] I don't think they knew that I was gay, but... [52:00.080 --> 52:00.400] Sorry, ladies. [52:00.940 --> 52:02.400] And the thing is that... [52:02.400 --> 52:03.280] Well, not too sorry. [52:03.880 --> 52:04.200] But... [52:06.500 --> 52:08.020] You know, they were not too nice. [52:08.180 --> 52:10.760] But you can see here they don't do DNS spoofing. [52:10.860 --> 52:11.660] That's the right AP address. [52:11.920 --> 52:16.720] There's no DNSSEC here involved, though, so you don't know that that's the right AP unless you already know, in which case you don't ask. [52:16.720 --> 52:17.520] But... [52:17.520 --> 52:20.800] You can see here, for example, that four hops to Austria. [52:21.120 --> 52:24.820] You can tell they're tampering with the network by just doing a basic trace route, right? [52:25.000 --> 52:26.380] And this is pretty simple. [52:26.480 --> 52:28.060] This is TCP trace route on port 80. [52:28.360 --> 52:30.280] You can see four hops, 86 milliseconds. [52:30.660 --> 52:34.420] That is a box that is probably four hops away from me, and it's really overloaded. [52:34.940 --> 52:36.520] You can also see this here. [52:36.640 --> 52:41.360] When you use port 443, then it actually does go out of their country and it just bypasses their filter entirely. [52:41.360 --> 52:44.160] So one of those is hijacking the connection and the other one is not. [52:46.600 --> 52:54.700] It's pretty incredible how much hijacking is actually taking place, though, because basically that means everybody's traffic is being inspected by these old unpatched squid boxes. [52:55.180 --> 52:56.360] Like, think about how bad that is. [52:56.460 --> 52:57.020] That's really bad. [52:58.380 --> 52:59.840] You can also see the same thing. [52:59.940 --> 53:02.240] Worst ISP name ever for the Middle East, by the way. [53:02.360 --> 53:04.720] I mean, I understand what they're trying to get at, right? [53:04.720 --> 53:06.020] Like they're trying to say EarthNet. [53:06.620 --> 53:09.200] But the thing is that that's really a bad name in English. [53:09.760 --> 53:13.540] I mean, it's not doing anything for, like, inter-country relations, I'm sure. [53:13.920 --> 53:16.400] We've had another cyber attack from Terranet. [53:18.200 --> 53:18.820] Same thing. [53:19.060 --> 53:19.780] Two hops. [53:20.120 --> 53:20.560] Not the case. [53:20.940 --> 53:21.580] Here's Qatar. [53:21.940 --> 53:27.120] You can see here in the top a bunch of information about the actual proxying. [53:27.620 --> 53:29.020] You can take a look at that URL. [53:29.220 --> 53:35.120] You'll notice that there's filtering information and the IP address of the user and the flags that they have, which means you can just frame people. [53:35.300 --> 53:37.340] You can say, oh, yeah, that guy in the hotel next to me. [53:37.680 --> 53:39.900] Yeah, he was going to some website he shouldn't have been. [53:40.380 --> 53:40.640] Boom. [53:40.780 --> 53:42.500] Now you've got a log that generates an event. [53:42.640 --> 53:44.620] Maybe the event is the police kicking down someone's door. [53:44.980 --> 53:47.500] I had some pretty weird shit happen to me when I was in Qatar. [53:47.840 --> 53:52.000] And I, you know, I don't want to mess with that government, certainly not while I'm there. [53:52.460 --> 53:57.160] And I think that it's kind of a little bit interesting that this is, like, the level of sophistication. [53:58.480 --> 54:01.200] So those are the IP addresses and names for the proxies in Qatar. [54:01.200 --> 54:03.240] And you can take a look at those boxes as well. [54:03.820 --> 54:03.920] Okay. [54:04.220 --> 54:05.440] Quickly moving on to Iran. [54:05.720 --> 54:07.520] We have, like, maybe 30 seconds. [54:08.160 --> 54:08.420] Yeah. [54:08.700 --> 54:08.840] Okay. [54:09.040 --> 54:12.180] So Iran basically has a lot of problems. [54:12.500 --> 54:15.040] And they basically have some dials for turning the network up and down. [54:15.160 --> 54:17.680] They don't usually do as much of the blocking as other places. [54:19.740 --> 54:26.200] Nokia Siemens essentially says that the reason that they are doing this is because the West has forced them to build lawful interception. [54:26.200 --> 54:31.720] So ask yourself when you think you need wiretapping about the trickle-down effect that your actions have on other countries. [54:32.020 --> 54:32.740] Because there is one. [54:34.680 --> 54:36.760] Ironically, this is one of those bug doors I was talking about. [54:37.000 --> 54:38.700] Get is censored for certain requests. [54:38.840 --> 54:42.360] But G space E space T space is a bug. [54:42.540 --> 54:43.780] And it gets you past their filter. [54:44.400 --> 54:46.840] So if you make a get request, you get filtered. [54:46.960 --> 54:48.980] And if you don't, you make this other one, then you get passed. [54:48.980 --> 54:51.020] Unless it's Facebook, which is hard coded and blocked. [54:53.460 --> 54:56.140] So I think that it's important to say that it's effective. [54:56.800 --> 55:00.020] But I think that it's mostly socially effective, which is the scary part. [55:00.900 --> 55:04.320] And Burma is an example of a country... we had way too many sleds, right? [55:04.600 --> 55:05.680] But this is mostly for later. [55:06.000 --> 55:11.180] So Fortinet was caught selling and they tried to deny it. [55:11.300 --> 55:17.160] Well, here you see one of their salesmen shaking hands with the military dictatorship on television. [55:17.740 --> 55:20.920] So it's a little hard to deny that they were doing this, right? [55:21.000 --> 55:21.420] They're complicit. [55:21.640 --> 55:22.340] Here's the problem. [55:22.560 --> 55:24.420] They stopped using Fortinet and now they use Cisco. [55:24.780 --> 55:27.400] We affected some change by attracting some attention. [55:27.780 --> 55:29.540] But what did we actually change? [55:30.320 --> 55:31.400] We changed their vendor. [55:32.760 --> 55:33.680] That's not so great. [55:36.000 --> 55:37.020] Apparently we're out of time. [55:37.220 --> 55:37.920] We're out of time. [55:52.070 --> 55:53.550] One last thing before you go. [55:54.090 --> 55:55.530] Just one last thing before you go. [55:56.490 --> 55:57.770] So actually two last things. [55:58.350 --> 56:03.570] Everybody now can go home and run a Tor relay or a Tor bridge and you can actually work to change this, right? [56:03.690 --> 56:11.650] Like you should not have outrage fatigue because you can actually directly affect the outcome of this situation for every person in the world by contributing to this network. [56:11.810 --> 56:13.910] By checking a box in some software. [56:14.090 --> 56:14.770] That's all it takes. [56:14.930 --> 56:16.470] It'll even punch through the firewall for you. [56:17.150 --> 56:18.930] And it's up to you to do that. [56:19.050 --> 56:24.590] Especially if you're the ones that build that filtering system that is used by one of these countries or one of these corporations. [56:24.590 --> 56:25.890] So thanks. [56:26.510 --> 56:27.210] Thank you. [56:30.990 --> 56:32.770] I guess we don't have time for questions. [56:33.250 --> 56:33.650] I guess not. [56:38.080 --> 56:39.280] Oh, thanks. [56:40.140 --> 56:40.580] Coming up. [56:42.760 --> 56:43.700] There we go. [56:43.880 --> 56:44.520] Coming up next.