[00:57.520 --> 00:58.000] No? [00:58.680 --> 00:59.100] Now? [00:59.360 --> 00:59.800] Okay. [01:05.950 --> 01:07.350] Welcome again to A New HOPE. [01:08.230 --> 01:14.810] As a reminder, everyone in the room, if you have any questions, you can always check through the Matrix chat to ask any questions. [01:15.010 --> 01:16.130] Same with our virtual attendees. [01:16.250 --> 01:21.430] That is the only way that someone outside of the event will be able to ask any questions. [01:23.370 --> 01:26.810] So, allow me to introduce our next speaker with a simple question. [01:27.690 --> 01:32.870] Who here has not had some of their data found in some kind of a breach? [01:35.720 --> 01:40.560] Well, I mean, obviously the question is, why isn't it simply encrypted? [01:40.960 --> 01:45.180] However, according to our next speaker, Philip Hallenbaker, that's the wrong question. [01:45.180 --> 01:46.350] Okay. [01:46.700 --> 01:47.040] Hello. [01:47.540 --> 01:54.220] So, today I'm going to be announcing three open infrastructures. [01:54.700 --> 02:01.200] The first is an infrastructure that secures data at rest. [02:01.200 --> 02:15.420] The second is an infrastructure that binds together a collection of devices and makes them function like they're a single device that belongs to you, the owner. [02:16.290 --> 02:26.280] And the third is a mechanism that allows us to take back control of our Internet services we depend on. [02:27.120 --> 02:31.070] But, of course, these are not three separate services. [02:31.640 --> 02:32.560] They're one. [02:32.670 --> 02:34.500] And they're called the mathematical mesh. [02:35.060 --> 02:44.840] Now, this is an open specification, open reference code, and open applications based on that code. [02:45.000 --> 02:52.380] Today, I'm going to be showing you the line mode applications, which are the ones that are finished. [02:52.380 --> 02:54.600] But there are GUI... [02:56.620 --> 02:57.980] I'm going to explain. [03:00.280 --> 03:05.440] As I'm going to explain, the applications are not really the point. [03:05.900 --> 03:14.480] The point is, this should be infrastructure, and this should be part of all the applications we use in our everyday lives. [03:14.940 --> 03:18.940] So, let's start with the first of those problems, securing data at rest. [03:18.940 --> 03:26.600] And, of course, every time we have a breach, and to do this, you know, this is a billion dollars' worth of breaches. [03:27.020 --> 03:33.740] I just did the local... searched on breach for news, and these were just the first five hits. [03:34.320 --> 03:39.380] And it's basically been like that every day for the past ten years. [03:39.640 --> 03:45.080] And every time the question comes up, why didn't they just encrypt? [03:46.160 --> 03:47.040] Encryption is easy. [03:47.220 --> 03:49.940] I mean, this is how we encrypt using the mathematical mesh. [03:50.660 --> 03:51.990] Alice creates an account. [03:52.440 --> 03:55.240] So, she's got an account, alice at example.com. [03:55.800 --> 03:59.270] She's going to... she's got a little diddly file here. [04:01.080 --> 04:02.800] Just a text file, in this case. [04:02.920 --> 04:07.680] But, of course, it could be Word, it could be SolidWorks, Inventor, PowerPoint, whatever. [04:08.580 --> 04:12.360] And she's just going to encrypt it, and then she's going to decrypt it. [04:12.360 --> 04:14.140] And it's all going to work as you would expect. [04:14.330 --> 04:16.620] So, there's our file. [04:16.920 --> 04:17.960] Let's encrypt it. [04:19.270 --> 04:29.740] And the encryption that you're going to see here, it's all fairly straightforward stuff that we've been doing now for 25 years. [04:31.600 --> 04:37.140] In this case, it's all JSON using the ITF-Jose approach. [04:37.140 --> 04:39.500] But, you know, really straightforward stuff. [04:39.800 --> 04:41.800] Have a bunch of recipients. [04:42.270 --> 04:44.920] The actual encrypted payload is in the middle there. [04:45.330 --> 04:47.180] And we have a signature at the end. [04:47.270 --> 04:48.500] Yeah, yeah, it's easy. [04:50.080 --> 04:51.200] Encryption, easy. [04:51.600 --> 04:53.120] So, what's the problem? [04:54.320 --> 05:01.580] Well, the problem is, when you encrypt your data, you can't get it back unless you can decrypt it. [05:01.580 --> 05:07.420] And just being able to decrypt it on one machine doesn't cut it. [05:07.640 --> 05:16.180] Not if you're going to be able to use that data in an enterprise or to share it with your colleagues. [05:16.500 --> 05:21.280] Or even if you're going to just use it on your own. [05:22.100 --> 05:23.720] Encryption is easy. [05:23.720 --> 05:28.340] It's the managing the decryption of the data that is hard. [05:29.220 --> 05:34.140] And see here, we've just decrypted the data and we get the text back. [05:34.320 --> 05:35.400] You know, just like we've done. [05:35.780 --> 05:43.100] So, you know, here the meshes rounded off a few of the rough corners that PGP and S-MIME expose. [05:43.640 --> 05:47.560] You notice you didn't need to do the usual muscling around with key rings. [05:47.560 --> 05:48.460] It was done for you. [05:48.600 --> 05:50.760] But, you know, we've got to do better. [05:52.740 --> 06:02.340] Before I can encrypt by default, I've got to be able to access my data on all my devices I might want to use it on. [06:02.780 --> 06:04.780] And, you know, I have a lot of devices. [06:05.660 --> 06:12.760] I've got to be able to share that data with all my colleagues, past and future. [06:14.480 --> 06:18.480] And also, you know, what happens if I have a disaster? [06:18.660 --> 06:20.260] What happens if the house burns down? [06:20.800 --> 06:24.320] Now, this is something I've not got time to go into here. [06:24.800 --> 06:32.640] But, you know, I have spent a lot of time thinking about how do you recover the keys if a personal disaster happens? [06:32.820 --> 06:34.260] And also survivability. [06:34.260 --> 06:44.460] What happens if you've died and all your data is encrypted and now the family is trying to get hold of your bank accounts? [06:45.340 --> 06:45.900] Okay. [06:46.180 --> 06:51.400] So, at this point, you know, why am I wearing the Steve Jobs black sweater? [06:51.520 --> 06:52.920] Well, there's actually two reasons here. [06:54.460 --> 06:59.900] The first is, if you, you know, Steve is showing a bunch of... [06:59.900 --> 07:01.060] This is the iPhone launch. [07:01.320 --> 07:04.320] And Steve is showing a bunch of the previous smartphones. [07:04.540 --> 07:06.300] Did anybody here use one of those? [07:08.340 --> 07:09.940] They sucked, didn't they? [07:10.420 --> 07:12.720] They really, really sucked. [07:16.020 --> 07:17.940] iPhone raised the bar. [07:18.820 --> 07:21.480] And that's what we've got to do for cryptography. [07:21.820 --> 07:31.560] The reason that people aren't using PGP and S-MIME and so on to secure their data at rest is that it is too damned difficult. [07:32.520 --> 07:35.440] We've got to make it effortless. [07:36.220 --> 07:38.280] Zero-click encryption. [07:38.660 --> 07:40.680] Zero-click decryption. [07:40.680 --> 07:50.280] And that's why, in order for the mesh to really succeed, it has to be integrated into all the applications we use on a daily basis. [07:51.020 --> 07:51.480] Yeah. [07:51.820 --> 07:53.780] That's why it has to be an open standard. [07:54.980 --> 08:17.000] Because the only way that it can happen in a way that we can all make use of it without some god-and-awful, you know, wall-garden situation, is if there's an open standard that every vendor of application software, every open-source provider can implement and we can all use. [08:17.400 --> 08:18.220] So, yes. [08:18.540 --> 08:20.340] The second reason is this woman. [08:24.120 --> 08:26.840] Trust nobody absolutely. [08:27.960 --> 08:29.900] Security is risk management. [08:30.240 --> 08:31.880] It isn't risk elimination. [08:32.860 --> 08:34.760] It isn't trust elimination. [08:34.760 --> 08:36.460] Forget the zero... [08:36.460 --> 08:38.520] Zero-trust is a stupid slogan. [08:38.920 --> 08:42.200] It's almost as stupid as deperimentarization, which is the last one. [08:43.220 --> 08:45.240] You've got to trust somebody. [08:46.060 --> 08:52.260] But the key thing is to control who you trust and to how... what extent. [08:53.180 --> 09:06.400] And one of the mistakes I made in the previous incarnations of PKI that I had something to do with, was we tended to concentrate trust too much in certain nodes. [09:06.540 --> 09:07.800] And you all didn't like it. [09:07.960 --> 09:08.540] You know, CAs. [09:10.040 --> 09:13.480] The mesh is based on two principles. [09:14.240 --> 09:18.500] Least privilege and separation of duties. [09:19.100 --> 09:24.080] And it uses threshold cryptography to enable that to happen. [09:24.480 --> 09:26.940] You know, even I don't trust me completely. [09:27.140 --> 09:35.440] I mean, like, if you do crypto for a long... for any length of time, you spend your time wondering, did I leave a test stub in? [09:36.540 --> 09:38.640] Did I miss out that signature validation? [09:39.100 --> 09:40.840] You know, it's really grueling stuff. [09:42.180 --> 09:46.440] Okay, so let's go on to the first of those things that we have to meet. [09:46.440 --> 09:55.080] In order to use this data on any of Alice's devices, she's got to glue them all together so they function as one. [09:55.240 --> 09:57.880] And this is something that we need for applications as well. [09:58.040 --> 09:58.940] I mean, yeah. [10:00.200 --> 10:02.040] You buy your first laptop. [10:02.280 --> 10:04.940] You install a bunch of applications on it. [10:05.060 --> 10:08.740] You know, Mail, Contacts, Twitter, Flying Spaghetti. [10:09.380 --> 10:10.720] Yeah, you've got all of them running. [10:10.920 --> 10:12.460] And then you buy your second one. [10:12.700 --> 10:21.220] And then you spend, you know, half an hour installing the apps and then copying all the accounts from one to the other. [10:21.580 --> 10:24.640] And yes, Apple promises to do that for you. [10:24.740 --> 10:29.400] But only if you enter into Club Apple and give your application. [10:29.620 --> 10:30.940] Yeah, so that never really worked. [10:31.160 --> 10:33.060] And then you do the second and the third. [10:33.200 --> 10:34.740] And so you end up with a bunch of devices. [10:35.720 --> 10:40.160] And you don't know quite which of them you can use for which application. [10:42.660 --> 10:53.100] So the solution that I want to have is I want to join all of my devices and all of the applications to what I'll call a Mesh account. [10:53.700 --> 10:57.020] And have that be something that belongs to me. [10:57.720 --> 11:00.600] Something that cannot be taken away from me. [11:00.740 --> 11:04.320] Something that I can move from one service provider to another. [11:04.320 --> 11:08.860] So that I don't have to change this at any time in my life. [11:09.000 --> 11:14.340] No matter how many laptops, desktops and mobile phones I change between. [11:15.740 --> 11:20.480] So let's just look at how we can join two devices together. [11:21.400 --> 11:23.680] So what we're going to do here is... [11:23.680 --> 11:24.680] Oh, thank you very much. [11:29.670 --> 11:31.510] So I've got a second device here. [11:32.870 --> 11:37.050] And it's going to get that file that we tried to decrypt earlier. [11:37.310 --> 11:39.910] And we can't decrypt it, of course, because... [11:39.910 --> 11:43.430] Yes, it belongs to me, but I've not given it the decryption key yet. [11:46.150 --> 11:53.250] So what I'm now going to do is to request a connection between this device and Alice's Mesh account. [11:53.250 --> 12:01.310] So she just posts the request and you can see nothing hideously complicated there. [12:01.470 --> 12:04.770] Just request to alice at example.com. [12:05.310 --> 12:11.830] And then the device in the background here is going away and generating a small PKI just for this device. [12:13.070 --> 12:16.230] There's a lot of crypto going on behind the scenes here. [12:17.070 --> 12:20.970] Much more crypto than used to happen with PGP or S-MIME or whatever. [12:21.890 --> 12:29.230] And then on the original device, which is Alice's administrative device at the moment, she checks for pending messages. [12:29.730 --> 12:32.390] You see here that there was a witness value given out. [12:32.770 --> 12:37.450] We're going to compare the two witness values to check that they are the same. [12:37.450 --> 12:38.670] They are. [12:38.850 --> 12:45.790] And that gives us a work factor of 2 to the power 120 that secures that connection between them. [12:46.410 --> 12:50.190] First time we accept it doesn't work because... [12:50.190 --> 12:52.770] And the reason for this is that this is a least privileged system. [12:53.750 --> 12:55.450] I can't just say connect. [12:55.590 --> 12:58.950] I've got to say what privileges I'm going to connect it to. [12:59.150 --> 13:01.110] I'm connecting another laptop here. [13:01.110 --> 13:07.290] If I was connecting a food blender, I probably wouldn't want to allow it to have email. [13:07.890 --> 13:13.030] And you're all probably asking, who on earth has an Internet connected food blender? [13:13.270 --> 13:14.370] In the audience, anybody? [13:15.310 --> 13:16.170] I do. [13:17.730 --> 13:18.370] Yes. [13:18.990 --> 13:20.350] Stupidest idea ever. [13:20.510 --> 13:21.770] I just had to buy it. [13:21.930 --> 13:23.010] It was in Costco. [13:23.430 --> 13:24.210] Internet connected. [13:24.570 --> 13:28.210] Okay, so we've accepted the request. [13:28.210 --> 13:33.350] And now we're just going to synchronize this laptop up to the original. [13:33.610 --> 13:39.390] And again, this is actually something that if we were in production code, I probably will get rid of it. [13:39.770 --> 13:41.070] So we device complete. [13:41.230 --> 13:43.110] And now we can decode the file. [13:43.270 --> 13:44.670] See, it just worked this time. [13:44.850 --> 13:47.030] And we can read that file back again. [13:47.690 --> 13:55.090] So what we've solved here is we've solved the problem of encryption and decryption for Alice. [13:55.090 --> 13:55.190] Yes. [13:55.350 --> 14:03.150] She can encrypt her data on one device and use it on any of her connected devices. [14:07.370 --> 14:11.050] Now, obviously, this is not an ideal thing. [14:11.490 --> 14:22.750] You know, if we're talking about, you know, medium term, yes, the specifications, but not the current code, supports using QR code connections. [14:22.750 --> 14:26.270] You can just scan a QR code, and that does all the connection. [14:26.530 --> 14:33.650] Again, the 120-bit connection key is hidden inside the QR code. [14:35.430 --> 14:42.390] The reason that we've not done that yet is Microsoft isn't delivering that code until August or whatever. [14:43.250 --> 14:45.730] Okay, so what just happened behind the scenes there? [14:45.930 --> 14:52.350] Well, the connecting device generated a public key pair. [14:52.470 --> 14:54.210] This is elliptic curve cryptography. [14:55.090 --> 15:02.910] The private key is a scalar, and the public key is a point multiplied by that scalar. [15:02.910 --> 15:10.470] And so we send the public key, x.p, off to Alice's mesh service provider. [15:11.010 --> 15:15.890] And there it waits until it's picked up by the administration device. [15:16.010 --> 15:20.130] And that generates a second public key pair. [15:20.130 --> 15:22.470] In this case, y, y.p. [15:23.310 --> 15:38.170] And what the administration device then does is it adds the two public keys to get a new public key, which I'm going to call a.p, where a equals x.y. [15:38.470 --> 15:50.370] And we create all the certificates, all the credentials that we're going to need to make use of this device within the context of Alice's mesh account on the administration device. [15:50.370 --> 16:02.150] So the administration device can calculate the public key from knowledge of the public key shares, but doesn't have any knowledge of the private key because it only knows y. [16:02.170 --> 16:03.770] It doesn't know x. [16:04.010 --> 16:09.590] So it then sends back y and the certificates back to the connecting device. [16:09.870 --> 16:18.150] And the connecting device can then calculate a, which equals x plus y, which is the private key for the composite key. [16:19.010 --> 16:32.950] So what we've just done here is we've onboarded this device and provisioned it with all the public and private key information it needs to act in the context of Alice's account. [16:36.820 --> 16:42.300] And, yes, I've highlighted a lot of details cryptographically, but that's the principle. [16:43.140 --> 16:48.920] Okay, so what we've been able to do here is to share the key generation role between the two devices. [16:49.540 --> 17:01.980] And the reason that that's important is that if either of the devices does the key generation properly and securely, the final key will be secure. [17:03.820 --> 17:08.800] It requires both of them to mess up to have a problem. [17:09.020 --> 17:12.080] And we can actually divide it further if we wanted to. [17:12.160 --> 17:13.740] We can have as many shares as we like. [17:15.760 --> 17:32.820] And we can also, if we had cryptographic hardware that was built into a device during manufacture, we can now make use of that cryptographic hardware even though we cannot trust the manufacturer private key. [17:32.820 --> 17:38.960] You know, what you typically want to do with private keys is to device bind them. [17:39.240 --> 17:47.260] You know, I've got my phone, I want to layer some keys onto that so that they can be used on this phone and no other device. [17:48.300 --> 17:58.160] With threshold cryptography, I can do that without ending up being reliant on a little black box that the manufacturer provided for me. [17:58.160 --> 18:03.020] And again, the full protocol has more controls as possible. [18:03.740 --> 18:10.220] Okay, so we've solved quite a few of the problems for Alice using encryption and decryption for her own use. [18:10.760 --> 18:23.080] One that I'm not going to deal with quite yet is what happens if she is passing through customs somewhere and her device might be subject to seizure. [18:23.080 --> 18:52.000] And we can actually provision a key share onto Alice's device so that we can turn the decryption ability on or off at an external key server so that Alice can use this device to do her work for the whole flight, turn her decryption capability off when she's going through customs and only re-enable it when she gets to her destination. [18:54.910 --> 19:02.130] I've not got time to go into how we connect up applications, but we can do that as well. [19:02.350 --> 19:12.590] The existing tools will automatically provision SSH, PGP, S-MIME keys to a device, to an account. [19:12.590 --> 19:28.850] And so, once we've got the keys provisioned to one device, all the other devices that are connected to that account with the relevant set of rights can now have access to those private keys. [19:28.850 --> 19:49.330] And so, you provision your SSH key to one device and now all of your devices that you might need to use SSH on can have access to that private key without you needing to go through the usual business of how you transfer private keys across devices. [19:52.520 --> 19:57.140] It also provides a set of end-to-end encrypted catalogues. [19:57.280 --> 20:10.440] So, bookmarks, passwords, network settings, all the things that you really want to share across your web browsers, but you don't want Google rifling through. [20:11.720 --> 20:19.360] All that can be stored in a mesh catalog and it is stored end-to-end, so the service provider doesn't see it. [20:19.680 --> 20:23.420] And the contacts catalog I'm going to be coming up to in the next piece. [20:24.920 --> 20:43.820] Mesh contact assertions overcome a mistake I think I made in first-generation PKI where we thought the idea of X.509 PKI was we were going to provide a certificate that would be how you used email or how you used SSL. [20:44.220 --> 20:49.000] And yes, that kind of worked, but it wasn't a good solution. [20:50.060 --> 21:06.020] What I now think we want to have is a contact assertion where we can provide all the information you need to contact a particular person via any of the modalities that that person has granted to you. [21:06.180 --> 21:15.140] So, you can have a contact assertion that says, here's how you get hold of me through the mesh, through Skype, through Signal, through WhatsApp, etc. [21:15.620 --> 21:29.660] And you probably would end up having more than one of these contacts and hand out slightly different versions to your work colleagues, to your friends, to your families, to your golf club members and so on. [21:30.220 --> 21:42.780] And because we've got a full PKI, a full personal PKI backing this whole system, the contact assertion is signed and is authenticated. [21:42.780 --> 21:53.980] So, once we've gone through an initial contact exchange, we've got the route of trust for the other person and we can validate any updates to that contact. [21:54.620 --> 22:19.620] And so, what this means is that once we meet somebody, we bump phones, we've exchanged contacts, we've got a connection for life now, because that connection is between the mesh accounts, which persist, rather than to the messaging provider or the telephone number or the address they might happen to be using at that particular time. [22:23.200 --> 22:28.380] Trust management, yeah, I spent most of my career working on PKI. [22:28.780 --> 22:44.740] So, I think that one of the mistakes that was made in PCIX was, we thought that the idea of PCIX was, you want to go to get a key, you go to the CA every time and you see if that key is valid. [22:45.020 --> 22:46.780] And that wasn't a good model. [22:47.560 --> 22:54.440] The way that I think that we should be doing it is we divide the trust management problem up into two. [22:55.540 --> 23:05.280] The hard part, the part that CAs and so on can contribute to, is the problem of establishing trust relationships in the first place. [23:05.820 --> 23:19.860] If I meet somebody in person, we can bump phones, I can read a QR code off a business card, I can go through the remote request protocol, looks a bit like the device request protocol, or a trusted third party can give me that key. [23:20.160 --> 23:25.580] You know, if I'm talking about a bank or a business or whatever, CA broker trust is probably the way to go. [23:26.480 --> 23:38.800] But once Alice has decided to trust a particular person, what she's really interested in is not going through that whole establishing trust every time she uses it. [23:39.400 --> 23:44.420] She wants to see, is this party the same party I dealt with last time? [23:44.420 --> 24:06.560] And so what we need to do is for Alice to be able to track her contacts herself in her own contact catalogue, and then she's got Bob's public key, she knows she's got Bob's contact, and she can use that to verify Bob, regardless of which service providers, [24:06.800 --> 24:10.860] which protocols, which addresses whatever happened in the future. [24:14.780 --> 24:19.240] Okay, so let's just see that happening. [24:19.600 --> 24:21.540] So, you know, it's crypto. [24:21.720 --> 24:23.400] We've got to do an Alice and Bob example. [24:23.780 --> 24:26.600] I've already done the connection protocol. [24:26.600 --> 24:29.000] It looks pretty much like the device one. [24:29.000 --> 24:33.320] And again, it's something that I want to get rid of and put QR codes around. [24:33.820 --> 24:38.520] Alice has encrypted a file, and now Bob is going to decrypt it. [24:40.360 --> 24:45.680] Okay, well, that's just what we've been able to do with PDP and S-Mine forever. [24:46.160 --> 24:49.100] So, you know, nothing changed here yet. [24:50.180 --> 24:54.280] The problem is, decryption needs are dynamic. [24:54.940 --> 25:08.000] And this is one of the things that got me, you know, when I was working for VeriSign, and even in a company that is all about public key encryption, we weren't encrypting files. [25:08.000 --> 25:20.080] And the problem was that if I encrypted a file and somebody else joined the key team, I would then have to add them to the distribution list of that file. [25:20.500 --> 25:25.480] And if I didn't, well, that file has just disappeared as far as they're concerned. [25:26.200 --> 25:41.140] And so, if you're trying to use encrypted data in a work environment, you need to be able to share it with all your colleagues, including the colleagues that you haven't yet met. [25:41.140 --> 25:52.100] And this is something that doesn't really work within the canon of public key cryptography that we started with in the early 90s. [25:52.100 --> 25:59.440] So, what I'm going to do here is, Alice here has created an encryption group. [25:59.600 --> 26:02.500] It's groupw at example.com. [26:02.640 --> 26:06.940] And she's encrypted a file through .text again. [26:07.740 --> 26:13.000] And encrypted it to that group, groupw at example.com. [26:14.020 --> 26:19.820] And if you can see here, Alice has tried to decrypt it, and it won't let it hurt. [26:20.260 --> 26:28.060] And the reason for that is that even though Alice is the administrator of the group, she hasn't been added into the group yet. [26:28.060 --> 26:30.840] She doesn't have the decryption capability yet. [26:32.300 --> 26:37.180] Since Alice is the sole administrator of the group, she can add herself to it. [26:37.360 --> 26:45.460] But we could actually use threshold cryptography again to split the group administration process. [26:45.760 --> 26:51.880] So, it might take two administrators out of five to add somebody to the group. [26:52.380 --> 26:57.340] The fact that Alice is the administrator doesn't necessarily mean she is allowed to decrypt. [26:57.340 --> 27:02.660] So, let's just go through and show that we can decrypt that. [27:06.080 --> 27:10.020] And so, we've added Bob to that group. [27:10.400 --> 27:13.900] And now, Bob is going to synchronize his account. [27:14.220 --> 27:17.500] And this time, he can decrypt the document. [27:21.200 --> 27:25.060] Yeah, the recordings on the... [27:26.480 --> 27:28.440] Okay, and we've got the file back again. [27:30.220 --> 27:32.840] So, this is powerful. [27:33.300 --> 27:41.620] We've got the ability to encrypt files and decide, after we've encrypted them, who we're going to share them with. [27:41.780 --> 27:49.460] And we can also delete Bob from that encryption group, and now he can't decrypt. [27:49.460 --> 28:03.400] Or, the key server could have logic built into it like, okay, if somebody tries to decrypt more than 20 documents in an hour, then call their supervisor because something bad might be happening. [28:06.280 --> 28:08.660] Okay, so what just happened behind the scenes? [28:09.800 --> 28:24.260] Well, the first thing that happened was that Alice generated a standard public-private key pair, call it G this time, and sent the contact, which is the public key, off to somebody who encrypted a file. [28:24.260 --> 28:36.260] It's standard ElGamal encryption, the generate an ephemeral, and multiply the ephemeral by the public key, and... [28:36.260 --> 28:39.540] So, now, Bob wants to decrypt that file. [28:39.860 --> 28:52.060] What he's got to do is that, given the public ephemeral E dot P, he's got to find the value G dot E dot P. How does he go about it? [28:52.200 --> 28:58.440] Well, first thing that happens is that Alice is going to create a key share. [28:58.440 --> 29:05.120] First part of that is that Alice adds bot... Alice just creates a random number. [29:05.540 --> 29:10.060] Doesn't have anything to do with the private key of the group at all. [29:10.220 --> 29:13.000] Can be generated before the group's even been created. [29:13.340 --> 29:18.260] And sends that off to her mesh service provider. [29:18.740 --> 29:26.260] So now we've got the value Scalar Bob is stored at that mesh service provider. [29:26.260 --> 29:34.220] She then sends the difference between the group private key and the Scalar for Bob to Bob. [29:34.700 --> 29:41.880] And then when Bob wants to decrypt, what he does is sends an operate instruction off to the mesh service provider. [29:42.160 --> 29:47.080] And it can perform one half of the key agreement process. [29:47.880 --> 29:52.200] Bob uses the value he was given to provide the other half. [29:52.200 --> 29:59.600] Add the two together and we get the key agreement value that we need to decrypt that document. [30:01.660 --> 30:04.500] I'm taking this at high speed. [30:05.220 --> 30:09.000] There is a series of podcasts that go through it much slower. [30:09.540 --> 30:19.020] The key point at this point is we're separating out the role of decryption into two. [30:19.020 --> 30:25.760] We've shared that role between Bob's device and that key service. [30:26.140 --> 30:28.540] The key service cannot be breached. [30:29.100 --> 30:34.000] Because all the key service has is a set of random numbers. [30:34.920 --> 30:39.340] It can control the use of decryption, but it cannot decrypt. [30:39.340 --> 30:46.460] And as I said, we can split the administration role and the full protocol does have more encryption going on. [30:47.160 --> 30:47.740] Okay. [30:48.460 --> 30:50.080] So, yes. [30:50.480 --> 30:53.460] I'm saying this ease of use is critical here. [30:53.760 --> 30:56.680] This is all better integrated into applications. [30:56.680 --> 31:10.620] And ideally what I would like to be able to show you here is an Edge or a Chrome extension that would allow me to show you the mesh running in a web browser. [31:11.560 --> 31:13.620] I just didn't have time to do that. [31:14.260 --> 31:15.740] So I wrote a web browser. [31:19.400 --> 31:20.000] Okay. [31:20.360 --> 31:22.340] This is a serious web browser. [31:22.580 --> 31:24.660] It's basically... [31:24.660 --> 31:33.040] It uses WebView 2, which is a layer, a wrapper around Chrome that Microsoft is putting together. [31:33.780 --> 31:44.340] And it basically allows us to take back control of the browser and do all the things in the browser that certain companies are not letting us do of late. [31:45.060 --> 31:53.920] So what I've done is I've already encrypted a file and put it out onto the server. [31:54.380 --> 32:02.860] And I've added the browser account to the decryption group. [32:03.000 --> 32:06.800] And so now let's just see what happens when we run the example. [32:07.140 --> 32:09.420] And we can read the document. [32:10.220 --> 32:10.920] Okay. [32:10.920 --> 32:14.060] Now let's take the browser out. [32:14.500 --> 32:16.660] Nothing changes on the server. [32:17.800 --> 32:19.680] And we can't read it. [32:20.580 --> 32:32.480] So we can grant and remove the authorization to view documents on one website on a completely separate key service. [32:32.480 --> 32:41.440] This is powerful and the full protocols allow us to go as far as end-to-end encrypted social media. [32:42.060 --> 32:43.800] You could have Twitter. [32:44.140 --> 32:50.540] You could have Facebook where all the data on the service is encrypted. [32:50.540 --> 32:52.000] And the server... [32:52.540 --> 32:53.520] And the server... [32:53.520 --> 32:56.420] And the service has no idea what the users are doing. [32:58.280 --> 32:58.880] Okay. [32:59.740 --> 33:00.640] Oh, yes. [33:01.860 --> 33:05.120] Since I'm imitating Steve, I've got to do one more thing. [33:05.320 --> 33:08.420] There's also a second factor authentication scheme built in. [33:11.360 --> 33:13.940] But it's not like these stupid numbers. [33:16.080 --> 33:18.580] You know, if I'm going to do... [33:18.580 --> 33:19.460] You know, I... [33:19.460 --> 33:22.460] Well, I think the second factor authentication is the wrong idea. [33:23.160 --> 33:27.980] What I really want is a confirmation when I'm about to do something stupid. [33:27.980 --> 33:34.660] You know, I think I should be able to log on to my brokerage account with a password. [33:35.400 --> 33:44.080] But I would like to have it come back and ask me for some confirmation before I say, Buy 2,000 shares of Ponzi. [33:45.820 --> 33:48.480] So what I really want is a scheme like this. [33:48.840 --> 33:50.400] I try to do that. [33:51.240 --> 33:58.060] And back comes a message on my screen saying, Do you want to buy those 2,000 shares in Ponzi? [33:58.580 --> 34:01.460] And I accept it or I reject it. [34:01.720 --> 34:13.900] And the acceptance or rejection is signed by the device, goes back, and we have a complete audit trail of, Phil was stupid enough to buy Ponzi. [34:15.580 --> 34:18.780] That's what I think second factor authentication should be. [34:20.580 --> 34:25.620] Okay, so the reason I'm here at HOPE is that I need your help. [34:26.180 --> 34:30.340] I've spent the past five years building this system. [34:30.900 --> 34:32.620] I have no external funding. [34:35.140 --> 34:38.860] You know, I was Web 1.0, so... [34:39.600 --> 34:47.860] I've been carrying this so far by myself, but if we're going to make this work, I need to have more people involved. [34:47.860 --> 34:53.140] There's a ton of good stuff we can do with this technology. [34:53.660 --> 34:56.840] And, you know, the possibility is limitless. [34:57.100 --> 35:01.220] And I'm only just showing you the raw technology here. [35:02.580 --> 35:08.940] What we can do applying this technology is far more important. [35:09.720 --> 35:15.160] An end-to-end secure messaging system that isn't a walled garden. [35:15.740 --> 35:25.000] Yes, I know Signal is an open protocol, but it is a walled garden as far as talking to users. [35:25.000 --> 35:28.300] I can only connect to other Signal users. [35:29.260 --> 35:44.400] Why don't we have an open mechanism for a messaging system, where anybody can choose their service provider and can talk to anybody else, regardless of which service provider they use. [35:46.200 --> 35:52.000] There's more work to be done on the browser, hooking up the bookmarks, the catalogues and so on. [35:52.000 --> 35:54.940] Did anybody here use Delicious back in the day? [35:56.040 --> 35:57.280] Wasn't it great? [35:57.960 --> 36:00.060] And it was taken away from us. [36:00.960 --> 36:01.700] Why? [36:02.260 --> 36:05.580] Because we didn't control the service. [36:06.740 --> 36:18.280] Wouldn't it be nice if we had an open version of Delicious, where we could browse, share our bookmarks with other users and collaborate with them? [36:19.260 --> 36:21.920] End-to-end secure social media. [36:22.160 --> 36:23.580] It's possible. [36:24.700 --> 36:32.640] The DARE formats are designed not just for incremental authentication like you get with a SOC chain. [36:34.020 --> 36:36.860] It also provides incremental encryption. [36:38.320 --> 36:41.420] And finally, IoT. [36:44.020 --> 36:51.520] Well, this is the model that every IoT user is trying to foist on us. [36:51.640 --> 36:54.160] It is called Razor and Blades. [36:54.520 --> 36:57.800] We connect up all our devices to their service. [36:57.800 --> 37:02.880] We pay for the service, and then all our devices connect into our service. [37:03.940 --> 37:10.080] And, of course, it doesn't even work because we don't buy from a single vendor. [37:10.340 --> 37:11.600] The vendors squabble. [37:12.340 --> 37:18.160] Some days you can connect to your Nest thermostat with one stack, and the other day you can't. [37:20.540 --> 37:23.020] That is not a model that's working for me. [37:24.200 --> 37:29.820] And anybody following Adam Savage's build of the Ecto-1 Ghostbusters mobile? [37:31.480 --> 37:33.660] It was really great as long as it lasted. [37:34.740 --> 37:36.500] I bought into it. [37:36.620 --> 37:40.060] You know, I'm 70 parts into this 140-part thing. [37:40.380 --> 37:41.460] Almost $1,000. [37:43.420 --> 37:45.120] Eagle Moss has gone bankrupt. [37:46.620 --> 37:50.200] So, I now have half the parts for an Ecto-1. [37:51.960 --> 37:54.260] And that reminds me of this. [37:55.160 --> 37:56.780] I bought a Revolve Hub. [37:58.040 --> 38:00.820] Built my entire smart home around it. [38:01.520 --> 38:04.340] Google bought Revolve and shut them down. [38:05.680 --> 38:13.720] And now I have $2,500 worth of redundant smart home equipment in my walls. [38:13.860 --> 38:19.880] It was three years before there was another vendor that came up with a Hub that replaced the Revolve one completely. [38:20.880 --> 38:22.580] That doesn't work. [38:23.040 --> 38:24.240] And you know what? [38:24.400 --> 38:32.120] If you start to read IoT forums, you will see that a lot of people are getting burned and getting fed up. [38:33.640 --> 38:36.080] This is the model that I believe we need. [38:36.400 --> 38:45.120] All the devices connect to the user's mesh account, which they control, which they own, and is theirs for life. [38:47.180 --> 38:50.540] And no razors and no blades. [38:51.420 --> 38:53.600] Just stuff working. [39:00.130 --> 39:05.830] When we built the Net, it was intended to be... [39:05.830 --> 39:07.590] Yes, it was Arthur Merney. [39:07.890 --> 39:11.150] But the objective of Vint Cerf & Co. [39:11.410 --> 39:15.270] was to provide a communications resource for everyone. [39:15.670 --> 39:19.570] Something that everybody could use to communicate. [39:21.710 --> 39:28.250] When I worked with Tim Berners-Lee at CERN on the web, the web was a gift. [39:28.250 --> 39:30.670] It was Tim Berners-Lee's gift. [39:31.090 --> 39:31.770] It was Tim Berners-Lee's gift. [39:31.770 --> 39:37.530] And it wasn't a gift to corporations to collect rents, to sell our privacy. [39:37.950 --> 39:41.750] It wasn't a gift to the Ponzi token grifters. [39:42.290 --> 39:47.790] And it certainly wasn't a gift to governments to help them control populations. [39:49.130 --> 39:52.510] The gift, the web, was a gift to you. [39:52.870 --> 39:54.450] A gift to all of us. [39:54.630 --> 40:00.170] And I'm asking you today, please help me to help you to take it back. [40:00.550 --> 40:01.910] Because you know what? [40:02.110 --> 40:07.250] Privacy matters, the Net matters, and our freedom matters. [40:07.530 --> 40:15.100] And I believe that making use of threshold cryptography is an important tool that can make that happen. [40:15.260 --> 40:15.780] Thank you. [40:26.900 --> 40:29.720] Okay, I think that we do have time for some questions. [40:30.840 --> 40:31.320] So... [40:40.180 --> 40:42.260] Yeah, there's a microphone coming to you. [40:47.120 --> 40:48.520] The microphone with your question. [40:50.660 --> 40:51.140] Hello. [40:51.600 --> 40:52.560] Hi, I'm Xander. [40:52.760 --> 40:57.300] I have so many questions, I will probably have to talk to you afterwards, but I could ask a few of them. [40:57.520 --> 41:04.280] I'm curious what kind of threshold cryptography you're using threshold ECDSA, threshold BLS. [41:04.440 --> 41:17.680] I'm curious if you could give an example, a practical example of who the mesh providers would be and how we think about potential collusion between the mesh providers. [41:17.980 --> 41:25.420] And I'm curious if you've given any thought to proactive security of the private key shares. [41:25.420 --> 41:33.840] If you have anything in mind in terms of periodically resharing, and do you maintain the same public key through that? [41:34.020 --> 41:35.240] I'll limit myself to three. [41:35.480 --> 41:35.800] Thank you. [41:36.640 --> 41:37.480] Okay, so... [41:37.480 --> 41:39.140] I will be in the... [41:39.140 --> 41:43.840] So to answer the first part, I'll be in the coffee shop most of the conference, so just hit me up. [41:45.260 --> 41:46.680] I'm here to make contacts. [41:47.900 --> 41:49.920] In terms of... [41:50.800 --> 41:51.280] Okay. [41:51.280 --> 41:55.440] In terms of who can be a mesh service provider... [41:56.520 --> 41:59.080] Well, I had to take it out because of time constraint. [41:59.500 --> 42:01.740] You can be your own mesh service provider. [42:02.240 --> 42:08.180] All you need is an external static IP address and a domain name. [42:08.800 --> 42:14.580] Now, obviously, at the moment, that's $10 a year for the domain name, plus $5 a year for hosting. [42:15.020 --> 42:18.640] So, you know, that's like $70 a year. [42:18.640 --> 42:20.980] That's probably more than... [42:21.620 --> 42:22.160] But... [42:23.320 --> 42:27.540] What I'm hoping for is that in the... [42:27.540 --> 42:34.060] In the near term, we will see some free providers coming up to build the community. [42:35.200 --> 42:44.940] And, you know, if you were doing this at scale, if you're hosting a hundred or a thousand, you know, you're looking at a few pennies per customer to support them. [42:45.920 --> 42:48.780] So, I think that that will happen in the short term. [42:49.020 --> 43:00.620] But, longer term, you know, most people have either a cloud storage device or an antivirus subscription or an email subscription or whatever. [43:01.480 --> 43:16.780] And, looking at the additional effort that it takes to add the mesh service provision as a layered service, my hope would be to persuade those people in that space to step up and start offering it. [43:17.080 --> 43:25.760] And the sector that's probably the ripest for that is virtual private network vendors in that they're all about personal privacy. [43:26.160 --> 43:31.400] But, you know, what does a secure pipe to their data center really do for me? [43:31.700 --> 43:33.100] Not a great deal, I'm afraid. [43:33.100 --> 43:38.460] But, if I could have that plus the mesh, that would be starting to look interesting. [43:40.860 --> 43:41.420] Yeah. [43:42.300 --> 43:43.060] Oh, yes. [43:43.180 --> 43:53.380] In terms of trusting the mesh service provider, when I first designed the mesh, I was seeing the mesh service provider as being a zero-trust service. [43:53.800 --> 43:58.240] I did actually start using that term for a while before it became popular. [43:58.240 --> 44:01.420] I don't use that term anymore. [44:03.340 --> 44:12.780] The mesh service provider never has access to any of the encrypted data of the user. [44:12.900 --> 44:18.200] And all the, you know, all the contact catalogues, the bookmarks, et cetera, it's all encrypted end-to-end. [44:18.980 --> 44:23.560] But it is trusted to withdraw the ability to threshold decrypt. [44:23.900 --> 44:26.420] So it's not purely zero-trust. [44:26.420 --> 44:27.360] And, yeah. [44:27.560 --> 44:45.920] I mean, this is where I started to realize that zero-trust is impossible because if you have a service out there and you have threshold cryptography that allows you to spread a role between multiple pieces, you're going to start giving that service somewhere something to do. [44:46.300 --> 44:46.940] So, anyway. [44:50.360 --> 44:52.400] So, first is a comment. [44:52.400 --> 45:04.820] So, you mentioned that PKI or public key encryption doesn't allow for the fact that if you want to decrypt something and the user does not exist yet, like, you can't do that. [45:04.980 --> 45:08.400] Like, you can't encrypt something for future purposes. [45:10.860 --> 45:25.820] But if you think about, like, attribute-based encryption, in particular, like, ciphertext-based attribute-based encryption, you can, in fact, encrypt things for, like, sets of users or have, like, arbitrary policies. [45:26.580 --> 45:26.920] OK. [45:27.220 --> 45:35.380] So, when I was talking about public key encryption, I was talking about, you know, the canon of cryptography was established when OpenPGP launched. [45:35.740 --> 45:39.020] And one of the sad things is that it closed. [45:39.700 --> 45:55.200] There's an incredible amount of stuff like, you know, attribute-based encryption, you know, re-cryption, threshold cryptography, structured cryptography. [45:55.200 --> 45:57.000] we wouldn't use because of the patents, of course. [45:57.520 --> 46:06.360] And so, you know, what I'm saying, you know, you need something else beyond that original canon of OpenPGP. [46:06.880 --> 46:18.660] And when you start to drill down, I mean, originally, when I presented this the first time, I presented it as using proxy re-encryption. [46:19.700 --> 46:27.320] I was only afterwards that I realized that what I had actually done was to refactor proxy re-encryption, so it became a threshold screen. [46:27.800 --> 46:32.240] So, actually, when you start to drill down, it all looks very much to the set. [46:32.420 --> 46:34.440] What is important is the set of capabilities. [46:35.340 --> 46:58.360] And the reason that I'm focused on threshold is, we don't have a standard yet for quantum-resistant threshold scheme, but there are candidates that are threshold capable, that could be adapted. [46:58.760 --> 47:04.000] And so that's a route that I know that I can go through to my quantum secure if I need to. [47:04.780 --> 47:09.980] But, you know, there's a limited amount I can bring to the table at once. [47:09.980 --> 47:10.620] Yeah. [47:11.040 --> 47:25.140] And then, quickly, the second question is, if you, from, like, a business application perspective, would you say this is similar to what Okta does with, like, single sign-on for, like, a variety of resources? [47:28.000 --> 47:33.700] Especially if you combine it with, like, you know, say, zero-trust, quote-unquote, networks? [47:34.920 --> 47:38.920] I thought that Okta's a SAML vendor, are they? [47:39.520 --> 47:43.840] Just from, like, an application layer, not, like, the internals. [47:49.980 --> 47:51.100] I think... [47:52.620 --> 47:56.120] Yeah, I don't know enough about their product to comment. [47:56.900 --> 47:58.340] You know, maybe we can take it offline. [47:58.880 --> 47:59.080] Cool. [47:59.300 --> 47:59.520] Thanks. [48:03.640 --> 48:05.060] Is the code available today? [48:05.340 --> 48:05.680] What? [48:05.920 --> 48:07.140] Is your code available today? [48:07.400 --> 48:08.260] Oh, yes, absolutely. [48:08.460 --> 48:09.700] It's all up there on GitHub. [48:11.280 --> 48:18.860] If you go to mathmesh.com, you can download the code, the command line tools I've been showing here. [48:19.640 --> 48:23.140] They run on Windows, Mac, and Linux. [48:23.140 --> 48:26.200] All the code is in C Sharp. [48:26.380 --> 48:30.040] C Sharp itself is now under an MIT license. [48:30.300 --> 48:32.620] All my code is under an MIT license. [48:33.060 --> 48:44.700] And the build tools that are used to generate the code are also on GitHub and are also under an open-source license. [48:45.780 --> 48:46.640] Thank you. [48:57.270 --> 48:59.410] Reminders, again, please stay hydrated today. [48:59.410 --> 49:02.110] It is a scorcher out there also as a friendly reminder. [49:02.730 --> 49:08.270] Please remember that in indoor masks, in indoor spaces at the conference, please wear your mask. [49:08.390 --> 49:12.370] The only exception is when people are at a lectern or speaking like this. [49:12.590 --> 49:13.170] Thank you.