[00:00.770 --> 00:02.630] So, I'm Mallory Nodal. [00:03.050 --> 00:10.570] I work at the Center for Democracy and Technology in Washington, D.C., and I'm super happy to be here again after quite a long time. [00:10.790 --> 00:18.710] And for folks who might remember, we have done this for a few HOPEs now, where it was mostly a panel of me and my colleagues. [00:20.110 --> 00:21.790] And this year, it's just me. [00:22.110 --> 00:27.690] So, I wonder if anybody in the room has been to a standards organization. [00:27.910 --> 00:28.870] I know PHB has. [00:29.090 --> 00:29.650] Who else? [00:29.850 --> 00:30.070] Yeah? [00:30.770 --> 00:36.490] Okay, so you might not be following all of these bodies, which is why I'm here. [00:36.730 --> 00:49.750] Hopefully, I can condense some of what I find to be most interesting discussions in a variety of different spaces into one talk, which will be hard, because a lot has happened in the last four years. [00:51.330 --> 00:53.270] Try to keep really good time. [00:54.250 --> 00:54.810] Right. [00:55.210 --> 00:58.930] I'm going to start... Let me explain the ISTAR. [00:58.930 --> 01:05.010] Almost all the acronyms start with the letter I, except for the first one I'm going to talk about, which is the World Wide Web Consortium. [01:05.630 --> 01:15.650] So, the W3C standardizes, obviously, the web from its name. [01:15.650 --> 01:22.750] You can tell, you might be interested to know, that the W3C does not, in fact, standardize HTTP. [01:23.230 --> 01:26.930] That is a separate working group that is its own body. [01:26.930 --> 01:31.650] It is related to the W3C, but just to give you an idea, they do many other things. [01:32.490 --> 01:37.030] So, a few things that have been happening that you might want to talk about, or hear about. [01:37.670 --> 01:39.190] Global Privacy Control. [01:39.630 --> 01:55.070] So, this is the idea that, rather than clicking through cookie banners every single time you visit a website, maybe you could do this at the browser level, where you set a control in your browser, and it remembers. [01:55.090 --> 01:57.870] It remembers for the same website over and over again. [01:57.870 --> 02:00.030] It remembers for all websites over and over again. [02:00.330 --> 02:03.830] It's such a good idea, but why doesn't it exist yet? [02:03.950 --> 02:15.070] There's plenty of people who have solved this from a technical perspective, in the place where it should be solved, at the browser level, in the browser, sensibly browser and web standards body. [02:15.070 --> 02:23.810] It hasn't been accepted or implemented yet, because there's been pushback from companies that haven't invested interest in tracking it. [02:24.010 --> 02:26.470] So, that's the short story there. [02:27.410 --> 02:32.350] But it is getting much closer, I would say, that this is now something that folks are talking about quite a bit. [02:32.570 --> 02:41.810] And so again, like, technical problem solved, it's now more of a business and implementation side argument that needs to be made. [02:42.290 --> 02:43.250] But that's really good. [02:43.270 --> 02:44.030] We really love that. [02:44.770 --> 02:52.670] Um, also, there is a new, uh, working group of the W3C that maybe some folks wanted to hear a little bit about. [02:52.870 --> 03:00.870] This is on, um, federated identity, and has, I think, the unfortunate, um, acronym FEDID. [03:01.390 --> 03:04.350] Just because we also see this in the FEDiverse, right? [03:04.450 --> 03:08.930] Because people either think you're saying, like, FEDA, like the cheese. [03:08.930 --> 03:14.130] But I live in Washington, and people think you're talking about the federal government. [03:14.470 --> 03:17.810] Um, and so FEDID is not super great. [03:18.050 --> 03:19.070] But that's just my take. [03:19.390 --> 03:21.150] No offense to the people who came up with the acronym. [03:21.310 --> 03:21.950] Acronyms are hard. [03:22.450 --> 03:35.350] Um, but yes, um, Federated Identity Working Group is of interest to anybody who cares a lot about how you craft identity online, which is a wide open space, right? [03:35.450 --> 03:37.070] There's so many different elements of that. [03:37.170 --> 03:38.310] Is it just about authentication? [03:38.370 --> 03:39.910] Is it replacing a password? [03:40.170 --> 03:46.870] Is it your entire, um, you know, profile, including your name, including your vaccination status? [03:46.870 --> 03:50.930] Like, what is Federated ID, and how should it operate? [03:51.170 --> 04:02.830] Um, and how, maybe most importantly, can it center the needs of users and their privacy, rather than other competing and often conflicting interests in your personal data? [04:03.130 --> 04:06.070] So track that if you find it interesting. [04:06.650 --> 04:19.730] Um, so another really common thing folks associate the W3C with is, uh, social web, the open social web, like ActivityPub, for example, Mastodon is, is made on, on that. [04:20.250 --> 04:22.970] Um, that is, that spec is finished. [04:23.210 --> 04:25.610] I mean, ActivityPub was standardized a while ago. [04:25.750 --> 04:28.410] Um, but there's continuing work to extend it. [04:28.590 --> 04:32.290] So that's happening at the Social Web Incubator Community Group. [04:32.430 --> 04:41.050] It's no longer a working group, but the community group is, uh, has a number of task forces that are, um, extending the work. [04:41.050 --> 04:52.950] One that I'm briefly or interestingly involved in is trying to get, um, intend encryption in the direct messages, um, that ActivityPub can send and receive. [04:53.470 --> 04:55.970] Um, and there's, there's a variety of other things, right? [04:56.430 --> 05:05.450] Um, making sure that, um, ActivityPub as a federated service is less vulnerable to cyber attacks based on the way that it works or other kinds of things. [05:05.590 --> 05:09.270] So, you know, if you're interested in any of that stuff, you can certainly check it out. [05:09.270 --> 05:16.750] And because it's a community group, um, I think the, the, um, boundaries of engagement are, uh, a little bit different. [05:16.750 --> 05:21.470] So you can be invited in as an expert of a community group, even if you're not a member. [05:21.830 --> 05:34.450] Um, so maybe, let me, let me go back for a second and talk about, I'm going to try to be, um, I'm going to try to hold myself accountable to talking about the, the, the bodies themselves a little bit before I jump into the work. [05:34.450 --> 05:38.770] Um, but so each of these are different, each standards body operates a little bit differently. [05:39.070 --> 05:54.390] And the main difference between all of them is sort of how they, um, how they standardize, but also they have to consider how they deal with intellectual property rights and, um, anti-competition concerns because they are mostly all fora where, uh, [05:54.570 --> 06:01.630] companies who should be in competition with one another are actually cooperating on building technology, which from an antitrust perspective can get really tricky. [06:01.890 --> 06:10.190] Um, and so they, you know, they, they have to confront intellectual property concerns very, uh, directly and also transparently. [06:10.190 --> 06:13.710] So most of the bodies have some degree of transparency. [06:14.130 --> 06:21.090] Um, and then I think a third difference that I want to mention is around memberships or, or how you participate. [06:21.090 --> 06:27.450] So in the case of the worldwide web consortium, you have to be a member and it's an annual, uh, membership fee. [06:27.630 --> 06:35.290] Um, my organization, the center for democracy and technology is one of the very few, um, non-profit organizations that's a member. [06:35.450 --> 06:38.770] They do have a special rate, but it's still quite expensive. [06:39.190 --> 06:46.970] And that, and maybe some of the past controversies of the worldwide web consortium are why like they're very, there aren't very many, um, like CDT. [06:47.330 --> 06:49.790] I think that's all I wanted to say about W3C. [06:51.290 --> 07:03.110] I'll also in, in, in the vein of holding myself accountable, just mentioned that I, there are a lot of acronyms that are going to happen and I've done my very best to try to unfurl all of them for you. [07:03.270 --> 07:12.110] But if you hear me say an acronym and I don't explain it, come to the mic afterwards and tell me that I didn't, and I will give you a prize. [07:13.030 --> 07:15.370] Um, so yes, uh, there's a lot of acronyms. [07:15.510 --> 07:26.090] The acronyms I've, I've are important because a lot of times you can't even find the work online if you don't also know the acronym in addition to like the unfurled part of the acronym. [07:26.430 --> 07:27.910] Um, right. [07:28.150 --> 07:30.090] The Internet research task force. [07:30.410 --> 07:42.210] So, um, part of my work is to run a, or co-chair, I guess, the, uh, a research, um, group, which puts me on the, um, Internet research steering group. [07:42.270 --> 07:51.490] Um, and there are a variety of working, uh, research groups, sorry, um, that, uh, that exist and they range in, uh, wide scope. [07:51.690 --> 08:00.370] The one thing they all have in common is they're trying to solve sort of long-term, um, issues related to, uh, the Internet. [08:00.570 --> 08:07.610] So they're not specifying anything, uh, but they are creating information and they are obviously doing research on sort of these long-term issues. [08:07.830 --> 08:10.570] Uh, so some of them are interesting. [08:10.570 --> 08:16.450] I would like to think this is the one I chair, the human rights protocol considerations research group. [08:16.950 --> 08:21.810] Um, it as a group right now, it is not hugely active. [08:21.810 --> 08:24.490] I'll just say that we have a couple of documents. [08:24.830 --> 08:27.070] Um, we've had a couple of documents over time. [08:27.730 --> 08:39.150] Um, the one that's active right now are actively being drafted and discussed by members of the research group, um, uh, is about intimate partner violence considerations. [08:39.150 --> 08:53.750] So just to explain why that is important and why it's happening, um, at, at this, uh, standards body is much of the sort of Internet standardization and networking work, um, is really obviously focused on the network itself. [08:53.750 --> 08:56.570] That is largely what's being specified, what's being discussed. [08:56.890 --> 09:03.390] And, but then that sometimes excludes or forgets the, uh, material reality of the endpoints. [09:03.390 --> 09:16.830] And so, um, um, the attacker, you know, is not part of the threat model necessarily of, uh, a lot of folks working very, very hard, um, in these bodies for user privacy and so on. [09:16.930 --> 09:33.250] So we're trying to introduce the idea that, you know, we're not going to change the mandate of the, um, of this standards body to dealing with endpoint, uh, software, but we are trying to expand the idea of a threat model to those places so that the [09:33.250 --> 09:35.110] networking can improve. [09:35.350 --> 09:49.670] Um, like, for example, if someone has access to your home router, then threats change substantively, even if like, you know, we're not actually dealing with an end user endpoint. [09:49.890 --> 09:54.530] That's like just a minor consideration that we can elaborate quite a bit. [09:54.650 --> 09:55.570] And so we've done that in a document. [09:55.930 --> 10:09.610] Other things we've worked on in the past, and maybe I should pause to talk about like why we're talking about human rights, um, as opposed to other things, like why not public interest or, uh, social justice or other things. [10:09.810 --> 10:28.270] Um, so I've worked for my whole career in human rights organizations, and I will say that it's not, it's certainly a, uh, a framework for articulating harms or articulating, um, benefits or, you know, that are, that is orthogonal, or orthogonal, but [10:28.270 --> 10:31.990] also comparative to those other framings like public interest and social justice. [10:32.230 --> 10:37.610] But the human rights framework is the only one that has a global structure for accountability. [10:38.190 --> 10:44.470] So the human rights, uh, the, the universal declaration of human rights is in many ways a standard itself. [10:44.750 --> 10:55.910] Actually, Kofi Annan, who was the UN secretary general when the UDHR was published, um, was really fascinated by and understood, um, and, and borrowed from standards bodies. [10:56.210 --> 11:04.350] Um, and so it's written in a way that is also comparable to, um, you know, the way we think of standardization in a framework style. [11:04.490 --> 11:15.510] And then also when we're talking about how states, um, governments have obligations, and then also companies in those jurisdictions have responsibilities. [11:15.550 --> 11:19.370] Um, it's actually pretty actionable, and so that's why we talk about human rights. [11:19.770 --> 11:31.950] Sorry for that, um, the departure, but I am definitely interested in, um, bringing more talks and more experts into that research group, um, and hopefully more work as well. [11:33.270 --> 11:36.730] Um, broadly for a moment, I'm going to talk about censorship. [11:37.490 --> 11:51.530] Um, there is no, uh, research group or working group that I know of that is taking head-on the issue of censorship in, um, the Internet research task force, or I'm about to start talking about the Internet, um, engineering task force. [11:51.690 --> 11:54.830] And I think that is for a variety of different reasons. [11:54.990 --> 12:02.270] Um, but I would just say that because of freedom of expression as a human right, um, I'd like to be thinking about it a lot more. [12:02.490 --> 12:11.790] So, um, one of the reasons I think it's not so prominent there is that you get a lot of censorship circumvention when you have more privacy. [12:11.970 --> 12:16.010] It's sort of like circumvention and privacy are two sides of the same coin. [12:16.130 --> 12:24.650] If you can't, um, know who someone is or what they're looking at, you can't interrupt that, uh, connection. [12:24.910 --> 12:27.170] So that's, that gets you quite far. [12:27.390 --> 12:38.370] Um, I do think that there are ways, um, that circumvention or explicit goals of baking circumvention into Internet protocols, um, are required, right? [12:38.410 --> 12:41.470] You don't get all the way with just, just thinking about user privacy. [12:41.470 --> 12:49.630] Um, and then I think the second reason that I suspect, um, it's not talked about enough, um, is that companies don't want to talk about it. [12:50.010 --> 12:56.170] Companies are averse to talking about censorship circumvention because they feel it's a liability. [12:56.170 --> 13:09.410] It's a legal liability in some of the jurisdictions they work in where censorship is actually codified in law or is, um, a purview of the state where the state is the one ordering the blocks. [13:09.730 --> 13:14.590] And so they don't want to be seen as enabling, um, getting around those blocks. [13:14.750 --> 13:25.170] But I think if we look back at history, um, privacy was also seen as a challenge to sort of state authority over the network. [13:25.170 --> 13:31.890] And it was controversial to try to hide from the state and some places still very much is. [13:32.390 --> 13:48.570] So I think, um, I, again, suspect this is just a suspicion that if we can get companies that do work on privacy technology that could be extended to censorship use cases or censorship circumvention, excuse me, use cases, um, that, and they all kind [13:48.570 --> 13:55.690] of work together on this more or less at the same time, then no one company or tool or whatever is kind of sticking their neck out. [13:57.310 --> 14:05.410] And, and, and, you know, as a, as a sort of community, we can, we can all start to, uh, more publicly confront the issue of, of censorship. [14:05.710 --> 14:06.570] So that's a hope. [14:06.930 --> 14:12.210] Again, it's not reality, but it's something I would like to see, um, uh, emerge in this space. [14:12.390 --> 14:21.550] There was also, um, an Internet architecture board is another body that's related to this cluster here of Internet research task force, Internet engineering task force. [14:21.830 --> 14:25.390] Um, they held a workshop earlier this year, earlier last year. [14:25.890 --> 14:32.070] No, it was earlier this year on, um, access to, on barriers to access the Internet. [14:32.230 --> 14:36.470] So one was about like, you know, just a lot of places still don't have the Internet. [14:36.750 --> 14:38.870] Another was about, um, censorship. [14:39.390 --> 14:45.270] Um, and then, gosh, lastly, I think it was about, actually forgot the last thing. [14:45.390 --> 14:45.770] That's so funny. [14:45.890 --> 14:46.830] Oh, community networks. [14:47.010 --> 14:49.610] So it was an access issue that was solved by community networks. [14:49.810 --> 14:57.170] So, you know, they, they did, there was some discussion about this in the community, and hopefully it translates into more work in the research and working groups. [14:57.850 --> 14:58.310] Right. [14:58.630 --> 14:59.450] Moving on. [14:59.690 --> 15:04.270] So the Internet research task force, the Internet engineering task force are related. [15:04.530 --> 15:05.930] They meet at the same time. [15:06.110 --> 15:10.250] I think everybody's getting together in Vancouver in about a week or two, two weeks. [15:10.670 --> 15:13.690] Um, for the next meeting, they meet three times a year. [15:13.870 --> 15:17.870] Um, to continue my trends, I want to tell you a little bit about the body itself. [15:18.190 --> 15:20.130] You don't have to be a member. [15:20.410 --> 15:22.110] You can just participate. [15:22.370 --> 15:26.690] It's openness is probably on the sort of spectrum of all these standards bodies. [15:26.810 --> 15:30.750] It is the most open because you don't have to, well, maybe ICANN is more. [15:30.850 --> 15:31.130] I don't know. [15:31.350 --> 15:31.890] We'll talk about it. [15:32.010 --> 15:36.230] But the, um, you know, you don't have to be a member officially. [15:36.230 --> 15:41.690] You can find these working groups and these research groups that I've mentioned on the Internet. [15:41.690 --> 15:47.810] You can join their mailing list without anyone telling you, you can't, so you don't have to create an account. [15:48.190 --> 15:51.550] Um, and you can participate in discussion and you can go to the meetings. [15:51.830 --> 15:54.250] Um, you don't have, you can, you have to register for the meeting. [15:54.510 --> 15:56.910] Um, but other than that, it's, it's very, very open. [15:57.250 --> 15:58.790] Um, let's see what else. [15:59.550 --> 16:05.250] I think that's the main, the main, the main difference, uh, with all these other SDOs that I wanted to mention. [16:06.030 --> 16:08.590] Standard development organization, SDO. [16:09.450 --> 16:10.430] Um, okay. [16:10.730 --> 16:16.070] So broadly speaking, there's a lot of work on encryption that happens at the IETF. [16:16.430 --> 16:25.310] Um, and so I want to take a bit of time to kind of go through that without forgetting anything again. [16:25.310 --> 16:27.790] Like it's been four years, so much has happened. [16:28.170 --> 16:36.210] Um, I think I'll actually start with, if you'll allow me to connect this to the real world for a second, because I think we've all, we're all somewhat aware. [16:36.530 --> 16:43.870] Um, maybe, um, I am assuming at HOPE most people are aware that it's, that encryption is like perennially under threat. [16:44.090 --> 16:52.050] Like a lot of, a lot of states, a lot of, I mean, the United States, for example, even, um, are sort of attacking encryption at the policy level. [16:52.210 --> 16:57.450] Um, again, it's kind of reasserting the, you know, the control of the state, the ability to access data. [16:57.710 --> 17:11.730] Um, and so those, um, those kinds of actions can either be a symptom of, or just an indication of the fact that, um, in this, in the technology world, we're sort of making progress, right? [17:11.830 --> 17:24.070] Or there's kind of this, um, from where I sit in both the policy and the technology world, this sort of tussle that you can see kind of swaying back and forth, where encryption becomes really popular and ubiquitous. [17:24.570 --> 17:25.530] Everyone's using it. [17:25.990 --> 17:34.230] And then you see a lot of policy proposals that are trying to, um, interrupt that, um, disrupt it, trying to put guardrails around it. [17:34.650 --> 17:45.410] Um, and so I think that the work that, um, is happening in, uh, the IETF can, can be in parallel with, with some of the work that, or with some of the policy threat. [17:45.670 --> 18:04.130] So, um, in the UK, there is now on the books, um, something called the Online Safety Act, uh, which has given the regulator in the UK, Ofcom, power to demand a, an end-to-end encrypted service, um, modify its service. [18:04.130 --> 18:08.650] I mean, to the extent that it has to modify its software and how it works. [18:08.810 --> 18:20.730] And, um, so under, uh, under an order from the court and that Ofcom also, um, can define to the company how that happens as well. [18:21.470 --> 18:26.450] Um, so we don't know that it's, and they, they also, we asked them directly, uh, about this. [18:26.550 --> 18:27.310] It's not in the law. [18:27.850 --> 18:33.610] Um, they also can do this without revealing that they've done it, who, who they talked to, or how it's been achieved. [18:33.810 --> 18:36.330] So it's, it's kind of a terrible situation. [18:36.670 --> 18:39.670] Um, we might just need to, you know, like, let it fail. [18:39.670 --> 18:46.850] And then, um, when the headlines hit that, oh, this has gone terribly wrong as we thought it would, we can just sort of say, okay, I told you so, and we can clean it up. [18:47.110 --> 18:50.250] That's, that's the sort of vision now. [18:50.750 --> 18:55.710] Um, Australia has gotten a marginally bit better. [18:55.930 --> 19:09.190] So Australia was the first and for a long time, the only country to have a anti-encryption law on the books, where if you are an Australian company, you are not allowed to build end-to-end encrypted services without also giving the Australian government access. [19:10.270 --> 19:11.610] Um, it's called TOLA. [19:11.790 --> 19:13.230] I don't know the acronym. [19:13.490 --> 19:17.030] Um, the, and they have rolled this back a little bit. [19:17.210 --> 19:23.650] So they're, and I think it's due to maybe be, uh, completely re-legislated now after about eight years. [19:23.830 --> 19:29.230] And the Australia Privacy Commissioner is someone that this community might know. [19:29.450 --> 19:31.750] She used to run Privacy International under the UK. [19:31.750 --> 19:32.690] Her name's Carly Kind. [19:32.950 --> 19:34.170] So that's good news. [19:34.670 --> 19:41.030] Um, Europe is also threatening encryption, um, but failing over and over again, which you love to see. [19:41.210 --> 19:45.530] They had something that people were pejoratively calling chat control. [19:45.930 --> 19:49.610] So this would, and it was under the guise of child protection. [19:49.610 --> 20:00.570] So it would require every end-to-end encrypted service to filter using perceptual hash matching, um, which was a service that the EC was going to manage. [20:00.990 --> 20:04.790] Um, and that continues to fail. [20:05.090 --> 20:08.150] Um, but mostly on very thin grounds. [20:08.230 --> 20:16.330] It's mostly, I think the most persuasive argument against it is that like a data-driven perceptual hash matching just isn't very good yet. [20:16.330 --> 20:19.030] And I say yet, because that will change. [20:19.150 --> 20:29.930] And that's, that's the one thing that, um, seems to be most persuasive to, um, the, the representatives in the, um, in the lawmaking body. [20:30.110 --> 20:44.510] I will say that the Internet Architecture Board's statement against chat control was, um, more persuasive, but not popularly more so, um, in that they sort of honed in on the, the idea that it would be mandated as the problem. [20:44.510 --> 20:56.590] So once you start mandating these kinds of checks, then you create a whole, um, you disrupt the whole ecosystem in the sense that, you know, you could easily see, um, other kinds of encrypted services getting around it. [20:56.710 --> 21:02.010] You could easily see how that would sort of erode, um, trust, but also the ability to like patch software. [21:02.410 --> 21:06.890] Anyway, I, you could read that statement to get a full blow by boat, but I think it was really good. [21:07.190 --> 21:13.550] Um, on, so moving on to just one more thing on a couple more things on encryption, the technology. [21:14.070 --> 21:23.510] So for folks who love open PGP email as much as I do, there has been a new version of that that's been published in the last four years, actually in the last year. [21:23.850 --> 21:25.710] So that's, um, pretty big. [21:25.850 --> 21:28.750] And then also, um, messaging layer security. [21:28.930 --> 21:34.270] So this is the sort of open standards, open license version of the signal protocol. [21:34.450 --> 21:37.810] This is a double ratchet algorithm called messaging layer security. [21:38.190 --> 21:41.990] And, um, that now is, um, published as a standard. [21:42.210 --> 21:51.830] Um, currently there is ongoing work in a research in a, sorry, a working group called more instant messaging interoperability. [21:52.450 --> 22:03.810] Mimi, Mimi, um, is main is trying to make it possible to use MLS in an interoperable environment where you have multiple different services, all interacting with one another. [22:03.830 --> 22:05.490] And that is interesting and useful. [22:05.490 --> 22:24.990] Um, also because the digital markets act in Europe, um, which is, uh, really an antitrust, um, competition driving regulation, uh, is requiring WhatsApp and maybe in the future other ones, um, to interoperate with any like service, um, that requests [22:24.990 --> 22:25.170] it. [22:26.050 --> 22:30.950] So Mimi would be, um, is, is a, is a, is a very on-time specification. [22:32.110 --> 22:32.590] Right. [22:33.050 --> 22:33.130] Okay. [22:33.270 --> 22:34.310] Finally, through encryption. [22:34.550 --> 22:36.370] Um, and we're about halfway done. [22:36.870 --> 22:39.690] So, um, and this is a different research group. [22:39.890 --> 22:40.050] Sorry. [22:40.270 --> 22:43.110] This is a different working group at the IETF. [22:43.230 --> 22:45.690] It's called Detecting Unwanted Location Trackers. [22:46.170 --> 22:48.670] Um, folks are maybe familiar with this. [22:48.770 --> 22:51.390] I think there's another session here about it. [22:51.550 --> 22:55.050] Maybe not, but Electronic Frontier Foundation folks also work on this. [22:55.050 --> 23:08.050] The location trackers are these devices that you can now buy in airports and like, I don't know, bodegas that, that allow you to track things, but also you can track people. [23:08.310 --> 23:15.550] Um, and so if you are using them to illegally stalk people, um, that's obviously a huge problem. [23:15.710 --> 23:17.230] There's been a lot of news about it. [23:17.230 --> 23:22.090] Um, and now at the technical level, there may be ways to mitigate that. [23:22.290 --> 23:25.710] So, um, maybe for a second, oops, sorry. [23:25.930 --> 23:29.570] We also missed in the last four years, a whole pandemic. [23:29.570 --> 23:30.650] So that happened. [23:30.770 --> 23:39.890] Um, and folks, maybe we'll remember that, um, that Apple and Google partnered to use the Bluetooth specification to contact trace. [23:40.310 --> 23:41.570] That was a big deal. [23:41.690 --> 23:42.870] It didn't hit the standards world. [23:43.050 --> 23:50.130] Um, so I'm not going to talk about it here, but I bring it up in this case because it's similar on a couple of different levels. [23:50.390 --> 23:53.430] One is that Apple and Google are working together again. [23:53.790 --> 24:04.430] So the tracking network over Bluetooth, another commonality, um, now is sort of across the industry and it makes the network wider. [24:04.650 --> 24:07.730] It makes, um, you know, the network work better. [24:07.890 --> 24:18.250] Um, but when we're trying to deal then with specifying how to detect them, if you don't want to be stocked, um, then they also have to work together. [24:18.370 --> 24:22.270] And so that's happening, um, at the, at the IETF. [24:22.430 --> 24:23.630] Um, and it's really important work. [24:23.630 --> 24:39.010] And what I want to shout out about it is I think it's one of these, I think it's going to be a really great example for a long time where end users or communities that are most affected by a technology have been able to come into the standards body to talk about that experience and to explain why this work is needed. [24:44.710 --> 24:53.650] So one of the co-chairs of, uh, detecting the, the adult, um, working group actually works at the national network to end domestic violence. [24:53.850 --> 24:55.730] So that's quite cool. [24:57.410 --> 24:58.750] This is a similar one. [24:58.910 --> 25:04.110] Um, so digital emblems, folks are familiar with the red cross, red crescent, red crystal. [25:04.370 --> 25:07.830] Um, that is an emblem that exists in the world. [25:07.830 --> 25:10.970] So you can paint it on a tent, you can put it on hospital. [25:11.170 --> 25:13.010] This is an example of it being on an airplane. [25:13.410 --> 25:16.510] Um, and for a long time, there have been discussions. [25:16.630 --> 25:28.110] Now, this is years now that folks have thought, well, why don't we also do this for digital assets, for websites, for, I don't know, cloud services, whatever. [25:28.790 --> 25:30.030] Uh, it's not a bad idea. [25:30.310 --> 25:31.770] I think it's, it's definitely necessary. [25:31.970 --> 25:39.350] And so that work has, it's not even started actually, but there is a discussion that's planned for the next IETF meeting. [25:39.590 --> 25:46.970] Um, like I said, it's in two weeks in Vancouver, uh, where folks are going to get together to talk about what is the actual problem space here? [25:47.070 --> 25:52.650] Is there something that the IETF should do to standardize how digital emblems work? [25:52.970 --> 26:04.330] Uh, and maybe because I think I'm doing good on time, I'll just pause to say, um, you know, I am generally a technical, I'm a, I'm a tech skeptic. [26:04.950 --> 26:15.250] When it comes like being, being a person who sits at this intersection of like human rights and tech, I almost more often than not am like, you know, this is not a technology problem. [26:15.430 --> 26:16.530] This is very much a social problem. [26:16.550 --> 26:20.270] And I had that reaction initially, um, to the digital emblems work. [26:20.390 --> 26:23.970] I thought, why, like, why would we, why would we do that? [26:24.270 --> 26:40.390] Um, and I, and I was very, very quickly convinced because the, um, again, an example of the real stakeholders being in the discussion, the ICRC themselves said, we are not interested in this as a security feature. [26:40.570 --> 26:42.170] This is not a security feature. [26:42.330 --> 26:45.030] All it is, is, um, it's just an emblem. [26:45.250 --> 26:52.890] It, just like painting a cross on a tent doesn't stop that tent from getting destroyed. [26:53.210 --> 27:07.050] So too, would a digital emblem not do anything other than be an emblem, something that you can detect, something that you should be able to detect without knowing that someone's looking at it, or, um, and, and that, I think that, that narrow scope as [27:07.050 --> 27:23.710] to what it is, it's not a security feature, I think sold me on, um, the importance of this work and just having that, um, uh, the idea of, uh, you know, do not mess with this asset in the real world or in the virtual world as an important thing to do. [27:24.730 --> 27:25.950] Um, yeah. [27:26.310 --> 27:37.630] And I think I'll also say that historically, in the history of Internet governance, so this also is true in, um, ICANN, which I'll get to in a second and I'll unfurl the acronym then. [27:37.930 --> 27:44.810] Um, and as well, uh, that, that, that the ICRC actually has had special status all throughout. [27:45.010 --> 27:50.850] So there's a ton of like domain stuff that's all protected, um, because, um, it's a protected thing in the real world. [27:52.210 --> 27:53.070] Um, okay. [27:53.390 --> 27:58.690] So this is, I think the last, uh, working group that I'm going to talk about. [27:58.830 --> 28:05.590] There are, as you can imagine, so many other things that we could talk about, um, with regards to the IETF. [28:05.690 --> 28:10.290] Another one, I will just say in passing, privacy pass for folks who are interested in that stuff. [28:10.530 --> 28:13.790] This is the, um, answer to CAPTCHA. [28:13.970 --> 28:20.670] Um, that has just a series of, uh, RFCs from that, um, working group has all been standardized. [28:21.070 --> 28:21.150] Right. [28:21.290 --> 28:22.230] Finally published. [28:22.470 --> 28:24.950] Um, but I want to talk for a second about this. [28:25.070 --> 28:25.690] So SCONE PRO. [28:26.790 --> 28:31.110] Um, this, um, this is a net neutrality issue. [28:31.410 --> 28:36.050] Um, it's another thing similar to circumvention, um, censorship circumvention. [28:36.370 --> 28:39.430] Net neutrality is not something that the IETF confronts well. [28:39.970 --> 28:46.350] Um, and it's again, because a lot of interests in that room are not so keen on net neutrality. [28:46.570 --> 28:48.610] It seemed to sort of prevent innovation. [28:48.610 --> 29:06.150] And I mean, really it's just holding companies accountable, but nonetheless, um, this is, um, this, what this is, what this is, the work that this is proposing would allow the network to talk to a service about, um, its speed of service. [29:06.150 --> 29:10.030] So it's a, it's a like opt in net neutrality, if you will. [29:10.490 --> 29:12.510] Um, which has some implications, right? [29:12.590 --> 29:18.670] Because of course, um, opt in like net in neutrality sounds like, well, why not? [29:18.790 --> 29:27.730] It's a, it's a fine idea if the service and the network want to agree to slow a speed for a user or to do something else into preference and so on. [29:27.830 --> 29:29.070] Like if you're opting in, it's cool. [29:29.190 --> 29:29.290] Right. [29:29.430 --> 29:35.430] But I think we have to remember that, um, not all companies are the same size, right? [29:35.630 --> 29:38.170] And not all companies have the same power and leverage. [29:38.410 --> 29:48.190] So yes, it might be, um, you know, if the, if the, if the service is okay with a degradation of service, uh, of, of network speed and that sort of thing, that's all right. [29:48.330 --> 30:07.710] But I think it does have standardizing this and facilitating this, uh, negotiation between the service and the network in this way might end up, um, really harming small providers and, and small services that have kind of no choice but to go along with, um, this. [30:09.330 --> 30:10.450] So that's just something to think about. [30:10.610 --> 30:22.030] It's maybe, um, not totally fair assessment, but it's definitely something that I'm watching and that others in, um, the public interest and human rights space are as well. [30:22.830 --> 30:23.370] Okay. [30:23.810 --> 30:26.850] We're moving on to a different standards body. [30:26.990 --> 30:33.950] So the International Telecommunication Union, there is no S in that name, just so you know. [30:34.350 --> 30:35.390] I have to remember that myself. [30:35.950 --> 30:42.150] Um, so this is actually, this is again, very different in its model from the rest of the standards development organizations I've been talking about. [30:42.370 --> 30:46.930] It is a state member only, um, standards body. [30:47.030 --> 30:48.390] It is the oldest standards body. [30:48.470 --> 30:52.410] It is also the oldest UN body, um, from the 1800s. [30:52.410 --> 30:55.010] It was originally telegraph, not telecommunication. [30:55.350 --> 30:57.050] Anyway, it's a super interesting space. [30:57.330 --> 31:01.150] Um, all meetings all the time are happening in Geneva. [31:01.390 --> 31:05.010] They have their own building and it's right across the street from the human rights building. [31:05.370 --> 31:09.330] Um, and so, you know, that's an interesting, uh, visual, right? [31:09.830 --> 31:11.530] Um, let's see what else they do. [31:11.670 --> 31:13.670] They do have sector members. [31:13.910 --> 31:16.410] I think this was, uh, it's a fairly recent update. [31:16.490 --> 31:27.510] It's probably something we talked about in previous iterations of this because I think it was maybe close to 10 years now that they opened up membership for observers who are organizations. [31:27.510 --> 31:28.710] So you have to apply. [31:28.950 --> 31:31.490] Um, and I think it's also restricted by sector. [31:32.170 --> 31:35.370] Something also to mention then about the ITU, it has three sectors. [31:35.690 --> 31:37.610] Only one of them does standardization. [31:37.610 --> 31:38.730] That's the T sector. [31:39.910 --> 31:43.390] Um, then there is the radio sector. [31:43.570 --> 31:45.850] So that's spectrum, all that, that's the R sector. [31:46.050 --> 31:47.890] And then lastly is the development sector. [31:48.210 --> 31:59.070] Development sector is not really standardizing anything, but it's sharing best practice company blueprints for procurement from states to do development related things. [31:59.310 --> 32:07.190] Development meaning like it's mostly global South countries that are recipients or folks who are really coming to the table over, um, technology issues. [32:07.910 --> 32:11.850] Uh, so the ITU works very much like a lot of UN agencies. [32:12.050 --> 32:15.750] It's governed by a select number of states that rotates. [32:15.990 --> 32:17.390] And this is called the council. [32:17.670 --> 32:23.010] Um, and then the council of the ITU, however often it changes, typically has a slate of work. [32:23.210 --> 32:28.690] And so the reason there is no, like I said, there is no shortage of ITU meetings. [32:28.830 --> 32:30.990] It is literally meeting all the time. [32:31.210 --> 32:36.610] Um, and so you can imagine the volume of, uh, documents of discussions. [32:36.790 --> 32:44.970] And so for someone like me who is participating in all of these things, um, or anyone else that I work with, we have to be very judicious about what we follow. [32:45.130 --> 32:52.730] But one of the reasons I follow the council working group is that it is kind of a top-down purview of what the ITU at large thinks is important. [32:53.350 --> 33:00.770] Um, and so they have a council working group on the Internet, um, which right now is really worried about multi-lingualization. [33:01.590 --> 33:04.310] And that's also related to work in ICANN. [33:04.730 --> 33:07.490] Um, and then, um, let's see what else. [33:07.490 --> 33:25.230] I mean, that's really the universal access is, is something that means multi-lingualization, um, of all Internet and web services where all domains and everything, all software even can all be now written in a variety of different scripts. [33:26.170 --> 33:41.590] Um, before I forget, I wanted to add a really fun fact that I did not know until I started looking into universal access, which is our multi-lingualization version of the domain name system, which is that, um, the dots in a domain, for example, are [33:41.590 --> 33:42.910] not the same in all scripts. [33:43.170 --> 33:46.930] Some of them are just totally different characters and that blew my mind. [33:47.350 --> 33:49.110] Uh, it's really cool. [33:49.350 --> 34:00.510] Um, it's a really cool area of work and something that's going to require a ton of effort from governments to, um, to make happen. [34:01.690 --> 34:12.910] Another thing that ITU does, um, aside from all the three sectors is it also tries to just push itself as a convener, um, a global convener of technology. [34:12.950 --> 34:20.850] And so it has for, I think, four years now, um, done an annual event that they call the AI for good summit. [34:21.190 --> 34:24.310] Um, and this year it happened in May. [34:24.410 --> 34:28.310] It was, it had some big names from the AI world in it. [34:28.310 --> 34:40.610] Um, and I mention it just because I think, um, the ITU is, yes, it's a bit, uh, you know, folks hesitate when they realize it's only governments. [34:40.830 --> 34:44.950] But at the same time, there are a lot of technology-related problems that only governments can solve. [34:45.250 --> 34:56.710] And I think also there's folks who've been engaged in the ITU for a very, very long time that sort of do thankless work that's just grinding away at stuff and doesn't necessarily feel very hype-y. [34:57.270 --> 35:04.070] And so for AI, um, they've, I mean, there've been AI standards happening at the ITU for a while now. [35:04.210 --> 35:05.650] And I'm talking decades. [35:05.650 --> 35:08.110] It's not like a new thing for them. [35:08.370 --> 35:11.550] Um, the AI summit for good is relatively new, but yeah. [35:11.850 --> 35:20.350] And this is also largely driven by a new president of the ITU, or new secretary general, excuse me, of the ITU, which I didn't mention but is significant. [35:20.870 --> 35:25.650] Um, she is the first woman to ever run the ITU, and she's also American. [35:25.830 --> 35:27.030] Her name's Doreen Bogdan-Martin. [35:27.170 --> 35:34.010] Um, and she was elected at the last Planet Potentiary Conference, um, that was in 2022. [35:34.930 --> 35:38.930] Um, the, the sectors all meet every year. [35:39.050 --> 35:44.890] So one, two, three, and then the fourth year is called the Planet Potentiary, where it's like the whole ITU gets together. [35:46.350 --> 35:49.310] Okay, the World Radio Conference, just checking time. [35:49.490 --> 35:52.730] I wanted to mention, it's not that kind of radio, unfortunately. [35:52.870 --> 35:54.510] We're not, not exclusively that kind of radio. [35:54.670 --> 35:58.850] Mostly what the WRC does these days is they worry about satellites and space. [35:59.010 --> 36:04.930] That is like the number one, um, discussion topic for the WRC. [36:05.230 --> 36:14.810] And to that end, I wanted to mention that for the first time, let's say between, uh, so WRC last met in, uh, November, December. [36:15.110 --> 36:30.630] Um, and as a result of that, um, there are now, um, ways in which states can articulate a policy around Starlink or, well, it's all about Starlink actually, but in general, like satellite Internet, which didn't exist before it. [36:30.850 --> 36:38.230] If you, um, you know, if you could get a receiver anywhere in the world, you could ostensibly use these satellite Internet networks. [36:38.710 --> 36:43.350] Um, but it was a really fantastic way to get around Internet blocks. [36:43.670 --> 36:51.650] And so there are some states who are highly motivated to continue to block their Internet and are very, very active in the ITU. [36:51.810 --> 37:08.770] Um, and so they've made it so now, um, you can through, uh, the telecoms regulation framework, the radio regulation framework, uh, not as at a state level participate in the, um, these, these Internet satellite networks. [37:08.910 --> 37:18.150] So very concretely, it was Iran who said to the U.S. and Norway, um, we don't like that people are using Starlink in Iran. [37:18.530 --> 37:27.610] Um, please make it, please make Starlink comply with our request to not service anyone with a receiver in our country. [37:27.730 --> 37:31.670] Um, and this was mostly ignored as long as possible. [37:31.930 --> 37:35.870] Nobody actually wanted to action this, but the WRC conference. [37:35.870 --> 37:38.470] Now there's a resolution that sort of forces that. [37:38.570 --> 37:42.650] And so it's not just, um, um, and, and it isn't just sensors. [37:42.790 --> 37:55.890] That's actually, there are other folks who feel like it's, uh, very hegemonic of another state with a, uh, a company like Starlink to be coming into its market without asking and like serving its citizens. [37:56.250 --> 38:01.710] And, and so even South Africa, I think has, um, said that Starlink can no longer work there. [38:01.910 --> 38:06.090] Um, anyway, so there's some complicated around it, but, but anyway, states get to decide now. [38:06.710 --> 38:09.990] Uh, so I wanted to mention that, uh, coming up this year. [38:10.150 --> 38:13.470] So 2024 is a WTSA year. [38:13.490 --> 38:15.450] So the T sector is meeting. [38:15.650 --> 38:17.950] This is the World Telecommunication Standardization Assembly. [38:18.230 --> 38:21.370] Um, and there's, of course, as you can imagine, a whole lot going on. [38:21.770 --> 38:29.910] Um, one thing that is kind of great for all of us is in the last four years, we completely missed the metaverse. [38:31.010 --> 38:35.550] It, like in the last four years, it cropped up and it is now gone again. [38:35.830 --> 38:38.830] So there's not a lot of standardization happening around the metaverse anymore. [38:38.830 --> 38:43.330] It did have a focus group for a while at the, uh, ITU. [38:43.810 --> 38:45.550] Um, there's been a proposal. [38:45.730 --> 38:47.990] This is why I might, in my world, I care about it. [38:48.090 --> 38:58.770] There's been a proposal to create a focus group on human rights, which would be similar to the way that the human rights protocol considerations research group works in the IETF. [38:58.910 --> 39:09.010] It would try to look across the organization and to see, you know, what are some of these, um, standards that might be of interest or of concern to, uh, human rights advocates. [39:09.090 --> 39:15.690] And it's especially exciting because the HRC and the ITU, um, share basically the same plaza. [39:15.870 --> 39:16.910] They're across the street from each other. [39:17.010 --> 39:23.730] And the people at the Office of the High Commissioner on Human Rights, um, are keen to get involved in the ITU. [39:23.870 --> 39:35.630] So I think when you have that kind of center of gravity where it's like the work and the attention is being done by the human rights experts within the standards body, I think that's a really good combo. [39:35.770 --> 39:44.030] So hopefully we see movement on that, but it's up to, um, it's up to, um, 190 countries to agree that that would be a good thing to do. [39:44.410 --> 39:51.650] So that's kind of, that's going to be a challenge, but I think I need to move faster so that I have time for your questions. [39:51.970 --> 39:54.770] Um, so I'm going to breeze through this really quick. [39:54.850 --> 39:59.890] So another one that I pay attention to is the Institute of Electrical and Electronics Engineers. [40:00.410 --> 40:04.050] Um, this again, its own model is, um, paid. [40:04.230 --> 40:07.610] You have to pay to be a member of the Standards Association. [40:07.810 --> 40:10.410] So IEEE does a whole lot of stuff. [40:10.550 --> 40:14.950] You've probably been to an IEEE conference of some kind, but they have a Standards Association. [40:15.130 --> 40:17.150] In the Standards Association, you have to be a member. [40:17.330 --> 40:19.010] You can be an individual member like I am. [40:19.110 --> 40:21.390] You can be an organizational or a corporate member. [40:21.790 --> 40:27.470] Um, I'm in a, uh, group that has been working on inclusive language for a long time. [40:27.990 --> 40:30.490] Um, we, we balloted this. [40:30.650 --> 40:38.430] Um, it just specifies, like, here are a bunch of words people don't use anymore because they're really old fashioned and you sound insensitive when you use them. [40:38.590 --> 40:44.030] Um, here's the guidance for the whole of the essay to follow in its document editing. [40:44.270 --> 40:54.330] Um, we balloted it once and it failed and so we're working through the volume of comments that have come in about that work and hopefully we'll ballot it again soon. [40:55.090 --> 40:57.450] Um, there's another one that I think is interesting. [40:57.610 --> 41:02.390] It parallels the work on intimate partner violence that we're doing in the, um, IRTF. [41:02.630 --> 41:05.210] This is on tech-assisted interpersonal control. [41:05.470 --> 41:11.970] This is when you have, yeah, tech that can be used for stocking, tech that can be used for whatever. [41:12.170 --> 41:23.590] And so this is pretty nascent in the sense that we don't actually have any fully drafted documents yet, but there's, um, different working groups that are meeting regularly to figure out what the problem space is. [41:25.090 --> 41:25.610] ICANN. [41:25.670 --> 41:39.050] I do want to talk to you about ICANN and I'm sorry if it comes to the cost of questions because the Internet Corporation for Assigned Names and Numbers has always been a popular topic at these, um, at these, uh, these sessions because there's just so [41:39.050 --> 41:41.110] much going on in ICANN in the domain namespace. [41:41.850 --> 41:46.350] Um, we, I remember ranting for years about who is. [41:46.590 --> 41:52.750] So who is, you know, being the, um, the place you could go to look up who's registered what domain. [41:53.190 --> 41:55.330] Massive, massive privacy violations. [41:55.770 --> 42:05.510] Um, they were immediately in violation of the GDPR, the global, um, digital privacy regulation in Europe, the moment it came out in 2018. [42:05.870 --> 42:16.030] Um, and so they have taken four, five, four years to, no, six years to, um, come up with an alternative. [42:16.050 --> 42:18.810] It's called the registration data request service. [42:18.910 --> 42:26.750] It is not required that any domain, that any registry or registrar or CCTLD actually implement it. [42:26.990 --> 42:30.230] But in theory, you could now request this service. [42:30.530 --> 42:35.850] Um, you can request this data from a registry or registrar if you really, really want it. [42:35.950 --> 42:46.410] And they also have, I think, quick automated plugins for cops, for example, who could just, like, get a bunch of data really easily without a lot of friction. [42:47.090 --> 42:48.730] Um, DNS abuse. [42:49.070 --> 43:06.950] So this is like when, you know, at the domain level, like, there's just a top-level domain that a country is not really paying attention to, or there's a variety of ways that you can kind of, at scale, use the DNS to send a bunch of spam, send a bunch of malware, like, for sure, right? [43:08.750 --> 43:09.630] We can all picture that. [43:10.090 --> 43:21.570] Um, and so for a long time, like, good registries and good registrars have been dealing with reports of DNS space being used at this, in this way, at this scale, um, which has been great. [43:21.750 --> 43:27.070] There was many years of those good registries and good registrars sharing information on how to do that better. [43:27.210 --> 43:38.610] But now there is actually a requirement in the contractor that I can, if you are a registry or a registrar, they can't tell the top-level, country code top-level domains what to do. [43:38.730 --> 43:47.890] But you can, for the rest of the top-level domains, um, in the contract with ICANN, require mitigating DNS abuse once it is reported to you. [43:47.970 --> 43:51.150] And if you don't, you can lose your domain space. [43:51.170 --> 43:53.230] So that's kind of a big deal, in my view. [43:53.590 --> 44:00.050] Everybody says that this is about spam and this is about malware, but I'm a free expression activist. [44:00.070 --> 44:03.730] And that is, I mean, the balance is fine, right? [44:03.810 --> 44:08.850] And you can imagine this sort of thing being used, um, in the wrong way. [44:08.950 --> 44:10.950] So we are watching that space. [44:11.210 --> 44:16.470] Um, I wanted to mention that this is the, um, this is the acronym for RIPE in CC. [44:16.770 --> 44:23.170] They're not, they're, they're under ICANN in the sense that they allocate IP addresses and, and, um, autonomous system numbers. [44:23.610 --> 44:25.950] Um, and they have gone through a lot. [44:26.250 --> 44:30.070] RIPE is where both Ukraine and Russia are. [44:30.230 --> 44:32.090] Um, and it's also where the Middle East is. [44:32.230 --> 44:36.390] They're responsible for a big chunk of the world that has been in conflict. [44:36.730 --> 44:38.430] And two things that I thought were interesting. [44:39.350 --> 44:40.850] Maybe I can't remember the second thing. [44:41.050 --> 44:51.870] One thing I thought was interesting that happened is that because when Russia invaded Ukraine, they also started taking IP space and they were taking autonomous system numbers, like taking them, like they're ours now. [44:52.070 --> 44:54.210] They don't belong to you anymore Ukraine. [44:54.570 --> 45:05.410] RIPE had to develop a policy about when you abuse your, when you abuse the IP AN allocation system, we can action you. [45:05.530 --> 45:07.550] And so that is a very important policy. [45:07.550 --> 45:15.090] And it was in very excellent RIPE fashion, totally, um, swept under the rug and just issued as a policy. [45:15.490 --> 45:19.630] Um, I guess I need to stop, but I just wanted to very quickly run through. [45:19.790 --> 45:24.110] I talk about this every week in a newsletter that you can subscribe to. [45:24.530 --> 45:27.510] Um, and I try to cover all of this stuff. [45:27.810 --> 45:41.610] Uh, and there's, you know, I did do my best to think with the acronyms, you can let me know at the mics, but if you want to know more about each of these bodies, you can go to Article 19's Internet Standards Almanac and look up, um, in a playful way, all this information. [45:43.030 --> 45:53.070] And lastly, I wrote a book about a lot of this stuff and how the Internet works and why it's important to pay attention to censorship and, uh, net neutrality, et cetera. [45:53.410 --> 45:54.750] And, uh, you can buy it. [45:54.970 --> 46:02.670] And NoStarchPress aren't here at HOPE this year, but they did give me a discount code so you can get 30% off the book if you want. [46:03.030 --> 46:04.750] Um, and I'm sorry I went over time. [46:04.910 --> 46:06.030] I just had so much to tell you. [46:06.210 --> 46:07.030] Thanks so much. [46:08.210 --> 46:19.630] Um, on the topic, uh, early with the, uh, browser privacy, there was an old standard called the P3P policy, um, that seems to have gotten abandoned for a variety of reasons. [46:19.630 --> 46:24.490] It was, it was driven by the domain, not the browser, but the browser could act upon it. [46:24.730 --> 46:30.510] Did that ever come up, uh, when it, when they started talking about some kind of new protocol entirely? [46:30.510 --> 46:34.410] I wonder, I don't actually, I'm not familiar with that, but I'll have to look it up. [46:34.550 --> 46:47.890] I, I mean, I do think that, uh, and I'll just make a general comment here about a lot of different things, but in specifically the browser, I think putting more things in a user agent, like a browser setting, is the right way to go. [46:48.210 --> 47:02.670] I think we're also seeing that with like messaging and other things where like, if you can surface these decisions to the user through an agent that they're already familiar with, then that is closer and you can get things like meaningful consent and [47:02.670 --> 47:03.070] other stuff. [47:03.210 --> 47:15.890] So I think the issue with doing it in the stack too deeply from a technical perspective, it can be elegant, but then the user also doesn't know like how the tech is working in their best interest. [47:16.270 --> 47:21.070] So I don't know if that exactly answers your question, but it's mostly because I'm not familiar with the P3. [47:21.290 --> 47:21.690] What was it? [47:21.830 --> 47:22.270] P3P? [47:22.870 --> 47:23.310] P3P. [47:23.410 --> 47:23.590] Okay. [47:24.610 --> 47:25.490] Privacy policy. [47:25.670 --> 47:25.750] Right on. [47:25.970 --> 47:26.910] I'll look, I'll look into it. [47:26.990 --> 47:27.290] It sounds cool.