[00:00.440 --> 00:02.060] Ah, thank you. [00:03.880 --> 00:18.100] Okay, so, from the start, one of the things, the first thing I want to do here is to incorporate by reference Corey Doctro's keynote address on n-shittification. [00:19.240 --> 00:22.540] I'm not really contradicting anything that he's saying. [00:24.200 --> 00:30.500] The only difference being that n-shittification is an outcome. [00:31.660 --> 00:37.860] What I'm looking at is how we fix things, and so I'm looking at causes. [00:38.320 --> 00:47.060] And switching costs, not the only cause of n-shittification, but they're one of the prime causes that we've got to deal with. [00:48.200 --> 00:52.440] Second point I want to make is this is not really about the mathematical mesh. [00:52.600 --> 00:54.860] It's not about my code per se. [00:55.200 --> 01:07.140] If you're interested in mathematical mesh, I have a YouTube channel where I'm going to be describing the new release that will be coming out in a couple of months' time. [01:08.420 --> 01:19.720] But the problem is that if I come here and say, let's do this, and I don't have any code, well, people say, oh, he's all talk and no code. [01:20.780 --> 01:27.840] And then when I do come with code, oh, he's just protecting his code. [01:29.420 --> 01:31.440] Though, you know, you can't win. [01:32.480 --> 01:37.680] What I do want to use the mesh for, however, it's an existence proof. [01:37.680 --> 01:42.460] There is at least one way we can solve this problem. [01:42.780 --> 01:45.740] If you've got a better way of doing it, great. [01:47.100 --> 01:48.300] Really, I mean it. [01:48.440 --> 01:55.040] I mean, like, I have trampled over my own past work myself many times in my career. [01:55.700 --> 01:58.100] People kind of, like, get upset about it. [01:59.020 --> 01:59.280] No. [02:00.980 --> 02:04.620] Code, specifications, they're just a means to an end. [02:04.620 --> 02:07.540] When somebody's got a better tool, that's a win. [02:08.540 --> 02:15.500] And, of course, you know, I'm not going to come to a hacker conference and provide some proprietary code. [02:15.720 --> 02:19.580] The mesh, it's all open-source, it's all open specification. [02:20.640 --> 02:23.520] But it is also open service. [02:24.080 --> 02:27.220] And that's what I'm going to be getting into in the heart of my talk. [02:28.620 --> 02:33.480] And, thirdly, I'd like to ask, why are we here? [02:35.000 --> 02:36.160] And, no, no, no. [02:36.360 --> 02:41.000] I don't mean that let's ponder the ennui of the screaming void. [02:41.280 --> 02:43.420] I mean, why are we here at HOPE? [02:44.900 --> 02:45.980] What are we? [02:47.440 --> 02:48.320] We're hackers. [02:49.020 --> 02:50.760] And what do hackers do? [02:52.080 --> 02:55.380] Hackers challenge existing power structures. [02:56.180 --> 02:57.840] Hackers change the world. [02:58.240 --> 03:02.740] And the reason I'm here is that I need your help. [03:03.200 --> 03:08.760] I have an enormous amount of a steaming pile of code, one of my colleagues call it. [03:09.280 --> 03:17.840] I have an infrastructure that I built up that makes it really easy to layer security onto any application, does most of the work for you. [03:18.960 --> 03:28.900] And as I'm going to be showing you, there are many things we can apply it to, far more than any one single person could hope to make use of. [03:29.500 --> 03:31.500] Okay, so switching costs. [03:31.760 --> 03:33.480] What are they all about? [03:34.060 --> 03:40.380] Well, let's start with a few use cases and see what's going on there. [03:41.200 --> 03:43.180] First case study, Twitter. [03:44.160 --> 03:46.880] Okay, we all know about what happened to Twitter. [03:46.880 --> 03:58.220] And I don't want to go into how awful the sans-serif swastika incarnation of Twitter has become. [03:58.840 --> 04:01.120] Instead, I want to ask a different question. [04:02.280 --> 04:05.000] Why is anybody left there? [04:06.640 --> 04:08.760] And the answer is quite simple. [04:08.760 --> 04:14.940] For example, I've spent 15 years, I've invested 15 years into the Twitter platform. [04:15.540 --> 04:19.520] People know how to find me, I know how to find them. [04:19.900 --> 04:34.380] And all that effort I was investing into the platform was being siphoned off by the platform provider as an asset belonging to them, not an asset belonging to me. [04:35.080 --> 04:38.360] And the reason is, it's hard to switch away. [04:38.960 --> 04:42.040] You know, if I go to Mastodon, I have a Mastodon. [04:42.160 --> 04:48.400] I have very few of the friends that I had on Twitter that I'm following on Mastodon. [04:48.560 --> 04:50.380] And it's really hard to find people. [04:50.960 --> 04:53.060] It's very hard for people to find me. [04:53.820 --> 04:55.380] You know, it takes time. [04:56.200 --> 05:00.540] And so that's one example of switching costs. [05:02.740 --> 05:11.720] Now, I was going to go to show you how my Facebook feed has been enshittified with a whole series of posts. [05:11.860 --> 05:13.680] You know, I've subscribed to 50 groups. [05:14.020 --> 05:17.140] None of those groups managed to make it into my feed. [05:17.500 --> 05:21.000] A very few from the people I follow make it into my feed. [05:21.000 --> 05:33.160] Instead, 80% of my feed recently has been posts whistling Dixie, telling me what a great chap the rapist slaver Robert E. [05:33.320 --> 05:35.120] Lee was. [05:35.980 --> 05:37.540] I don't want that. [05:37.760 --> 05:49.500] But Facebook wants to shove that in my face to make me angry because an angry person is an engaged person and engaged people create clicks and create money for the zuck. [05:51.240 --> 05:53.660] Why don't I move away from Facebook? [05:53.980 --> 05:56.240] Because of the fixed switching costs. [05:57.240 --> 05:59.480] And finally, signal. [06:00.720 --> 06:04.820] And here the question is, why don't I want to use it more? [06:06.060 --> 06:09.260] And the reason is, it is a walled garden. [06:10.760 --> 06:14.540] Yeah, I'm really happy with their end-to-end messaging. [06:14.900 --> 06:20.600] And I'm really happy that right now, it is a not-for-profit company. [06:21.480 --> 06:24.880] But you know, I've been in the business for 35 years now. [06:24.880 --> 06:33.400] And I have seen a heck of a lot of not-for-profit companies wake up one morning and think, IPO. [06:35.580 --> 06:40.280] In fact, I can't think offhand of a single one that hasn't. [06:42.870 --> 07:04.810] And in fact, when I go through what signals should do in order to achieve their objectives, I could make a pretty good argument that what they should do is to go commercial, float off the messaging service, and put the $5 billion they get from the IPO into setting up a privacy foundation. [07:04.990 --> 07:06.610] It would actually make sense. [07:07.970 --> 07:08.690] Okay. [07:09.210 --> 07:11.230] So, switching costs. [07:11.630 --> 07:15.150] It's not just something that are good for you. [07:15.310 --> 07:21.190] Once people are aware of switching costs, it starts to hurt you because people avoid your product. [07:23.070 --> 07:23.790] Okay. [07:23.990 --> 07:27.710] Well, what if Internet accounts were portable? [07:29.070 --> 07:32.830] We've faced this problem before in the telephone system. [07:33.330 --> 07:35.410] And, you know, when MCI and co. [07:35.590 --> 07:47.370] were trying to get started, and people were trying to set up local telephone providers, the government stepped in and said, okay, you've got to make telephone numbers portable. [07:48.850 --> 07:55.450] And so now, I can move from, you know, when I originally bought this phone, I was on AT&T. [07:55.850 --> 07:57.490] Then I moved to T-Mobile. [07:57.750 --> 08:00.210] And, you know, I can move to Verizon if I want. [08:00.970 --> 08:07.450] I don't have the switching costs from telling everybody my new telephone number because of regulation. [08:07.950 --> 08:10.510] But we don't necessarily need regulation. [08:11.170 --> 08:16.430] All we really need is that ability to switch our accounts around. [08:18.890 --> 08:19.570] Okay. [08:19.930 --> 08:25.910] So, pushing on that a bit further, we get to the idea of an open service. [08:25.910 --> 08:31.150] And an open service, in my view, has three parts. [08:31.730 --> 08:40.450] Number one, users must be able to choose their service provider and change at any time without penalty. [08:40.950 --> 08:47.550] So, if I go to mesh service provider one, decide they don't like them, I can go to number two. [08:47.890 --> 08:51.150] I might go from free to paid, paid to free. [08:51.150 --> 08:53.050] I might set up my own service. [08:56.310 --> 09:00.530] Secondly, users don't need to use the same service in order to interact. [09:00.810 --> 09:03.930] And this is the second part of not having the switching costs. [09:04.070 --> 09:08.990] So, I don't need to be on Signal to talk to somebody else. [09:09.130 --> 09:10.350] I can be on Skype. [09:10.830 --> 09:15.110] All I need to do is to set up one service provider account. [09:15.110 --> 09:20.830] I don't need a hundred so that I've got coverage with all the people I might need to talk to. [09:21.550 --> 09:25.110] And thirdly, anybody can provide service. [09:25.390 --> 09:26.750] No gatekeepers. [09:27.070 --> 09:31.370] Just like SMTP was in the early days before spam. [09:32.150 --> 09:36.090] Yeah, you can still set up your own SMTP email server, if you like. [09:36.710 --> 09:39.950] But you'll find it really hard getting your mail delivered. [09:42.450 --> 09:44.670] You know, there's a cabal that you've got to join. [09:44.910 --> 09:51.350] And so, you know, as we think through these problems, you've also got to think through the problems of abuse and all that stuff. [09:51.630 --> 09:56.710] Because if you don't, what started off as an open service will become closed. [09:57.350 --> 09:58.470] Oh, and yes. [09:58.970 --> 10:04.310] We also want to put the least trust possible in that open service. [10:04.570 --> 10:07.230] I'm going to be showing you a contact manager. [10:07.230 --> 10:15.130] I don't want the service that is managing my contacts to know who any of my contacts are. [10:15.470 --> 10:26.470] I want to have full end-to-end encryption, including encryption of all the static data stored at the service. [10:28.730 --> 10:32.410] Okay, so, two challenges to set out then. [10:33.010 --> 10:36.490] Number one is how do we design open services? [10:37.670 --> 10:39.750] And that's actually the easy one. [10:40.690 --> 10:46.290] The hard one is how do we open up existing services? [10:46.610 --> 10:54.090] How do we take a crowbar to Facebook, to Twitter, to Signal, and open up their walled gardens? [10:55.610 --> 10:56.270] Okay. [10:56.730 --> 10:58.910] So, how to build an open service? [11:00.250 --> 11:02.170] It's not that difficult. [11:03.510 --> 11:10.270] The first principle you've got to accept is the account belongs to the user and not to the service. [11:10.270 --> 11:21.590] So, instead of getting an account at AOL, an account at CompuServe, you are going to get an account that belongs to you and is portable. [11:22.710 --> 11:23.850] Change of mindset. [11:25.430 --> 11:32.530] Secondly, the identifier that is used to refer to that account has to be controlled by the user. [11:32.730 --> 11:43.410] So, if I'm giving out my contact information, I can give that out confident that it's going to remain constant for, you know, 10, 15 years, whatever. [11:44.370 --> 11:46.050] A couple of approaches here. [11:46.050 --> 11:50.990] Approach one is everybody gets their own DNS domain. [11:51.410 --> 12:00.150] And this is the one that I was really pushing hard on in the early aughts when I was principal scientist for VeriSign. [12:03.360 --> 12:07.660] And, yes, having your own domain name is a win. [12:08.380 --> 12:17.120] The only problem is I'm paying $10 a year for hallenbaker.com, which really isn't a lot of money for somebody like me. [12:17.220 --> 12:19.780] You know, most of us here at HOPE, yo, yo. [12:20.140 --> 12:24.420] It's the price of going to Starbucks and getting a coffee and a pastry. [12:25.720 --> 12:34.320] But for large parts of the world, $10 a year is, you know, that's a week's salary for some people. [12:37.470 --> 12:40.770] So, that's not something that we can rely on for everybody. [12:41.910 --> 12:45.570] Second approach, use a cryptographic identifier. [12:45.570 --> 12:48.590] It's a generator, a public-private key pair. [12:48.750 --> 12:58.050] And you can always claim ownership of the public part of that key pair by use of the corresponding private key. [12:58.770 --> 13:00.650] And this is what I do in the mesh. [13:01.150 --> 13:05.650] The mesh builds a personal PKI for every user. [13:06.170 --> 13:08.030] User generates their own key pair. [13:08.270 --> 13:13.250] And the fingerprint of that key pair is their permanent user identifier. [13:13.250 --> 13:15.870] It's a user identifier for life. [13:16.030 --> 13:19.930] It doesn't have any mandatory expiry. [13:20.530 --> 13:30.130] And then because PGP fingerprint type technology isn't very user-friendly, we cover that up with layers of syntactic sugar. [13:30.330 --> 13:34.990] So, when we want to exchange contacts, we can do it by QR code. [13:35.130 --> 13:38.450] We can do it by reference to our current service address. [13:38.450 --> 13:45.090] But only as a hailing thing, not as a permanent contact end identifier. [13:45.950 --> 13:50.050] And I am considering possibly doing a call sign service. [13:50.190 --> 13:51.250] I've got specs for that. [13:51.810 --> 13:57.090] I believe that we could run that out at global scale for about 10 cents a name. [13:57.970 --> 13:59.990] Doing it on a small scale is easy. [14:00.790 --> 14:03.350] You know, and here's the problem with open services. [14:03.350 --> 14:11.250] Now, open-source software scales really well because the incremental cost of bringing in on another user is zero. [14:12.110 --> 14:15.290] Open services, your marginal costs add up. [14:15.610 --> 14:20.290] And so, if you're going to have a billion users, you've got to think about how you're going to pay for it. [14:21.590 --> 14:22.250] Okay. [14:22.570 --> 14:26.450] So, how do we open up the existing systems? [14:27.130 --> 14:32.270] Well, to answer that question, let's look at how did telephone numbers become possible? [14:33.010 --> 14:37.010] And, you know, this was a technological change that happened. [14:37.290 --> 14:48.290] And the way that we did it was, well, in the old telephone system, the Stroudia system, the telephone number was literally a path through the network. [14:48.290 --> 14:55.890] So, you had the exchange and then you had the, you know, the line. [14:57.590 --> 15:04.250] And, you know, that worked until we went to electronic with systems like SS7. [15:04.590 --> 15:07.830] And in SS7, we introduced a second number. [15:08.690 --> 15:14.050] Every endpoint in SS7 has a subscriber endpoint number. [15:14.050 --> 15:23.030] And SS7 is an enormous honking great database that maps the telephone number to the service endpoint. [15:23.930 --> 15:24.850] Okay. [15:25.150 --> 15:29.850] So, what we need to do is similar, but with security. [15:30.850 --> 15:34.130] The tricks that you can play on SS7 are really quite interesting. [15:35.470 --> 15:42.670] I used to be in the business of placing wiretaps and it's quite horrific how easy it is to do that. [15:43.450 --> 15:44.210] Okay. [15:44.550 --> 15:53.850] So, what we need to do is introduce a mechanism that allows people to have a permanent identifier, e.g. [15:53.890 --> 15:57.730] a mesh fingerprint that they use to refer to a person. [15:57.730 --> 16:07.910] And that permanent identifier can be mapped to whatever the service endpoints happen to be. [16:08.230 --> 16:21.090] So, what if you had a contact catalog that stored all your contacts, automatically shared itself across every device that you own without you having to think about it. [16:21.210 --> 16:23.950] So, I connect to Bob on my phone. [16:23.950 --> 16:29.530] I can connect to him from my laptop, my iPad, my desktop, etc. [16:30.450 --> 16:32.090] What if you could do all that? [16:32.170 --> 16:38.750] And what if all those contact assertions automatically updated whenever they changed? [16:38.750 --> 16:45.250] Well, what we've done there, we've achieved telephone number portability, but in reverse. [16:45.770 --> 17:01.910] Instead of the visible piece, the place that's visible to the user being the part that is constant, we introduce a new number, hit it, and that's now the part that's constant. [17:08.640 --> 17:10.560] And this... oh, no. [17:11.100 --> 17:11.940] Okay, can't do that. [17:12.200 --> 17:13.620] So, this is the result. [17:13.780 --> 17:14.720] Pardon the dust. [17:14.960 --> 17:17.220] This is reference code. [17:18.500 --> 17:20.340] As I said, I need people's help. [17:20.600 --> 17:25.360] If somebody would take this mess and make it look pretty, I'd be really happy. [17:25.540 --> 17:29.560] And, you know, you don't need to understand cryptography to know how to do that. [17:30.240 --> 17:33.400] Okay, so what we've got here is Alice's contact. [17:33.400 --> 17:38.660] And as you can see here, we've got a bunch of network addresses programmed in. [17:38.820 --> 17:41.800] So, mesh address is at example.com. [17:42.020 --> 17:45.580] Have the Twitter, have the Signal, have the Facebook. [17:46.500 --> 17:51.320] And so, she's then going to share that contact with Bob. [17:51.740 --> 17:57.360] And say they meet in person, they can, you know, wave phones at each other. [17:58.260 --> 18:00.260] Has anybody here used Bump? [18:02.640 --> 18:03.160] Yeah. [18:03.620 --> 18:05.020] It was a great product, wasn't it? [18:05.500 --> 18:06.780] You know what happened to it? [18:07.840 --> 18:08.980] Google bought it. [18:10.400 --> 18:12.100] Guess what Google did with it? [18:12.920 --> 18:13.680] Killed it. [18:14.300 --> 18:16.200] That's why we need open services. [18:16.840 --> 18:21.340] That's why we need to do this, but do it as an open service. [18:22.180 --> 18:27.800] Because if you, you know, yet another proprietary version is just making things worse. [18:28.380 --> 18:31.740] Okay, but say Bob and Alice are on different continents. [18:31.740 --> 18:33.120] They're trying to connect up. [18:33.760 --> 18:37.000] Well, Bob could send a contact request to Alice. [18:37.460 --> 18:42.280] And so, here we have a contact request in Alice's messages. [18:42.280 --> 18:44.000] She can accept it. [18:44.140 --> 18:45.060] She can reject it. [18:45.160 --> 18:48.760] If she accepts it, Bob will get Alice's contact information. [18:49.200 --> 19:00.240] And if they exchange contact information, they're also exchanging securely all the cryptographic context associated with all the applications. [19:00.240 --> 19:07.940] So, if Alice has PGP enabled for email, Bob has got Alice's PGP key. [19:08.140 --> 19:12.920] If he's got SMIME, he's got her SMIME certificate. [19:13.800 --> 19:17.060] Same for code signing, et cetera, et cetera. [19:18.740 --> 19:24.300] And if Alice decides to join Telegram, she adds it to her contact. [19:24.300 --> 19:27.400] Bob doesn't need to do anything additional. [19:27.740 --> 19:39.320] Next time he opens up his contacts, try to talk to Alice, the devices can automatically synchronize up, get the latest version, and go away. [19:39.840 --> 19:41.960] And this is a least trust service. [19:42.380 --> 19:46.120] The service cannot see any of Alice's contacts. [19:46.300 --> 19:48.040] They're all encrypted end-to-end. [19:48.920 --> 19:51.400] And the way that we do that... [19:51.400 --> 19:57.220] Yes, it's a form of public key cryptography, but it goes beyond the public key that you're probably used to. [19:57.420 --> 20:02.140] It's using threshold cryptography, where we split up the private keys. [20:02.600 --> 20:08.960] What this means is the service can control decryption, which is important. [20:10.320 --> 20:18.740] If I lose my phone, I want to be able to turn off this phone, stop it having any further access to any of my data. [20:19.840 --> 20:25.860] And I can do that by telling the service, don't allow this phone to do any more decryption. [20:26.940 --> 20:31.720] But the service doesn't have the ability to decrypt on its own. [20:31.920 --> 20:35.140] It only has a share of the key, not the key itself. [20:36.860 --> 20:48.520] We also want to have some other security properties, like not being able to impersonate Alice and present Alice with an invalid contact identifier address. [20:49.620 --> 20:52.940] Okay, so why didn't we do this earlier? [20:53.280 --> 20:59.460] You know, why didn't we do this in 1990s when we were building PGP and the web and all that stuff? [20:59.460 --> 21:06.760] Well, the amount of cryptography required to do it well is rather impressive. [21:07.160 --> 21:16.020] And when I was working on SSL before it became TLS, we couldn't do certificate chains of more than three. [21:17.100 --> 21:21.500] Because the machine would simply grind to a halt. [21:22.680 --> 21:31.280] You couldn't do this amount of cryptography on a 1990s-era 20 megahertz IBM PC. [21:32.380 --> 21:33.460] But you know what? [21:33.860 --> 21:41.060] You can do it on a Raspberry Pi one without it even be, you know, flickering an eye. [21:41.540 --> 21:45.200] So, you know, performance of the CPUs has moved on. [21:45.660 --> 21:47.160] Cryptography has moved on. [21:47.160 --> 21:48.600] We can now do it. [21:48.840 --> 21:55.270] And the other reason we didn't do it then was that a lot of the techniques I use were encumbered. [21:55.860 --> 22:03.440] I tried to buy out the surety patent, that's the patent on blockchain, in the early aughts. [22:03.620 --> 22:07.400] You know, five years before blockchain came out and they wouldn't deal. [22:08.800 --> 22:15.840] It's not post-quantum yet, but we've got a plan that should be in in a couple of months' time. [22:15.840 --> 22:19.160] And that's actually what's gating the public release. [22:20.360 --> 22:20.960] Okay. [22:20.960 --> 22:25.400] So, since we're on security, you know, we all like end-to-end encryption. [22:25.600 --> 22:26.740] Who likes end-to-end encryption? [22:27.600 --> 22:27.900] Yay! [22:28.240 --> 22:28.420] Woo! [22:29.400 --> 22:30.480] It's not enough. [22:31.600 --> 22:32.200] Seriously. [22:33.340 --> 22:37.880] Most of the end-to-end encryption systems are not end-to-end secure. [22:38.440 --> 22:44.180] And the reason for that is if I'm going to talk to Signal and say, Hey, how do I talk to Bob? [22:45.520 --> 22:47.880] Well, Signal has a database there. [22:48.160 --> 22:51.280] And it says, Bob's public key is this. [22:51.700 --> 22:52.960] And then I talk to Bob. [22:52.960 --> 22:54.340] Okay. [22:54.620 --> 22:58.280] Well, what if the boys in Fed? [22:58.640 --> 23:15.200] Or what if Putin's Novichok totin pedophile compromising spies get to Signal? [23:15.200 --> 23:18.940] Well, it's a Signal point of failure. [23:19.780 --> 23:25.460] And, you know, no matter what you try and do within the Signal protocol, they still have that database. [23:25.920 --> 23:30.880] They can always send a note to you, say, Hey, you need to update your client. [23:31.780 --> 23:36.120] And they can downgrade attack you to an insecure version of Signal. [23:36.120 --> 23:40.300] And so they can always tell you, here's Mallet's key. [23:40.520 --> 23:41.720] It belongs to Bob. [23:42.600 --> 23:50.800] And so we need to move beyond merely end-to-end encryption and move towards end-to-end trust. [23:51.300 --> 24:01.340] And to get to end-to-end trust, we've got to go right back to the original PGP model where every end user managed the public keys. [24:01.340 --> 24:04.500] And yes, I know Signal has safety numbers. [24:05.120 --> 24:06.160] Don't work. [24:07.540 --> 24:10.600] Sorry, anybody here use Signal safety numbers? [24:13.540 --> 24:18.080] What happens if the other person changes their device? [24:18.720 --> 24:22.760] You get a message saying, Safety number has changed. [24:27.320 --> 24:29.240] We've got to put the user in control. [24:30.040 --> 24:35.520] First thing we've got to do is to put them in control of the public keys that they rely on. [24:36.620 --> 24:48.420] One of the mistakes I think that we made in the WebPKI was that we saw digital certificates as a way of establishing a secure session. [24:49.280 --> 24:55.380] What it should have been was a way of securely introducing a key to the other user. [25:00.000 --> 25:05.660] So what I'm looking at is a model where users are always storing keys for trust after first use. [25:06.220 --> 25:19.700] And in the mesh, the model is that each user's contacts catalog that shares across all their device is their ground truth for interacting with other users. [25:20.280 --> 25:24.920] And the second part is each user controls their private key. [25:25.540 --> 25:33.080] So all your private keys on all your devices should be expressly under your control and nobody else. [25:33.320 --> 25:40.580] Make it really easy to provision keys to a new device when you add it to your personal mesh. [25:40.920 --> 25:46.860] Make it really easy to disable the ability of a device to work within your mesh. [25:47.780 --> 25:50.720] And we're not just talking about communications here. [25:51.400 --> 25:53.420] You know, how many people here are developers? [25:54.260 --> 25:55.440] How many use Git? [25:57.580 --> 26:00.140] Have you been managing a project at all? [26:00.740 --> 26:04.280] And you're trying to onboard somebody onto the project? [26:05.040 --> 26:09.340] And, you know, first of all, you need to get their SSH key so that they can talk to the repo. [26:10.920 --> 26:12.500] OpenPG, do you sign commits? [26:12.720 --> 26:15.380] Anybody here use sign-in commits? [26:15.660 --> 26:15.920] Yes. [26:16.300 --> 26:16.680] Great. [26:17.980 --> 26:36.100] You know, wouldn't it be nice if there was just a one-click way of Alice joins the project, we can add her mesh contact into the project and then all the stuff that she needs to interoperate as part of that project is now automatically logged in. [26:36.600 --> 26:41.560] And, you know, allow her to sign developer builds with her developer key. [26:42.400 --> 26:52.280] And now I can download her code, run it, not think about the fact that, you know, not need to tell my development machine anymore, hey, this is from Alice, it's trustworthy. [26:53.420 --> 26:58.840] And when Alice leaves the project, delete her contact, removes all the privileges. [27:00.840 --> 27:07.940] Now, okay, so I've, hopefully I've put out a compelling proposal here. [27:07.940 --> 27:10.740] The devil, however, is in the deployment. [27:11.660 --> 27:17.660] The system that I've described is a system that makes use of the network effect. [27:18.020 --> 27:19.140] Viral marketing! [27:19.960 --> 27:22.140] Well, you know what viral marketing is? [27:22.360 --> 27:23.780] Until you hit critical mass. [27:24.300 --> 27:24.980] Anybody? [27:27.260 --> 27:28.940] Chicken and egg problem! [27:30.940 --> 27:37.640] Until you reach critical mass, all that network effect is acting against you. [27:37.940 --> 27:48.880] And so what you want to do in order to deploy a new application is to combine single mover advantages with the network effect. [27:49.120 --> 27:50.760] And that's what we did with the web. [27:51.080 --> 28:02.660] The reason that the web originally got popular at CERN was it was a way of getting to the CERN phone book without having to log into the CERN VM mainframe. [28:03.640 --> 28:11.960] So, you could have it on your desktop instead of walking down the hall to the terminal that would talk to the IBM mainframe. [28:15.230 --> 28:18.810] So, the mesh does more than just manage contacts. [28:22.310 --> 28:28.630] So, here we have it offering the device connection dialogue, you know, QR code. [28:29.610 --> 28:43.350] So, it also has the ability to manage bookmarks, social media feeds, passwords, pass keys, calendar tasks. [28:43.350 --> 28:57.530] All the things that you want to synchronize between devices can be synchronized through a mesh catalog that is end-to-end encrypted and is entirely controlled by the user. [28:59.550 --> 29:01.630] So, that's the phase one. [29:01.970 --> 29:09.110] And to go further in phase two, which should come out this year, we're going to be adding general messaging. [29:09.590 --> 29:18.190] So, you'll be able to send a short message to other mesh users, send a mail message, or send a large file. [29:19.270 --> 29:24.430] Mesh messaging, which is necessary in order to exchange the contacts. [29:24.430 --> 29:32.250] I need a end-to-end secure asynchronous protocol to say, hey, here's my contact. [29:32.510 --> 29:34.050] Well, you can use that for other things. [29:34.830 --> 29:37.850] That's deliberately limited to 32 kilobytes. [29:39.330 --> 29:47.910] However, that 32 kilobytes could contain a message saying, hey, I want to send you the video for... to edit. [29:48.190 --> 29:50.650] The two terabytes of video is here. [29:51.370 --> 29:56.130] So, it's also large files, you know, your Dropbox-type functionality. [29:57.390 --> 30:04.970] It has a second-factor authentication already built in, and that's part of the password transition strategy. [30:05.730 --> 30:09.450] In phase three, we'll be adding interactive chat. [30:09.810 --> 30:14.630] So, add a presence service, and now you can chat like you do in Signal. [30:15.770 --> 30:23.210] If you add mock, then we can do voice, video, calling, and finally, IoT. [30:24.710 --> 30:32.810] If you've got a way of gluing all of Alice's devices together, you can open up those devices. [30:32.810 --> 30:50.990] So that if you want to have a doorbell, that instead of it being connected to a service provided by the doorbell salesman that you pay $10 a month for, you can have it going to an open service that you pay... [30:50.990 --> 30:57.310] It might be a paid service, but that can be one open service that does all of your IoT devices. [31:00.470 --> 31:06.030] So I believe that that's another area that might be able to garner some interest. [31:09.270 --> 31:12.250] Okay, so I started off with social media. [31:13.810 --> 31:16.690] So, yeah, we know that social media is awful. [31:18.330 --> 31:23.630] Question is, though, what do we switch to that isn't going to be quite so horrible? [31:24.830 --> 31:29.610] And I believe that the thing we need to do is to separate out the concerns. [31:30.310 --> 31:34.810] The problem with Facebook is that you go to... [31:34.810 --> 31:38.590] In order to read stuff on Facebook, you have to join Facebook. [31:40.190 --> 31:48.890] Okay, so imagine there's an open publisher model where I go to the publisher of my choice, and anybody can read my stuff. [31:49.090 --> 31:51.010] You know, like happens on media. [31:51.650 --> 31:53.510] Okay, so I make my post. [31:53.750 --> 31:57.370] It doesn't matter whether you're a Twitter junkie or a Facebook drunkie. [31:57.530 --> 32:05.830] That's still going to appear in your feed if you friend me, because each user can subscribe to curators. [32:06.570 --> 32:11.590] Separate out the curation function from the publishing function. [32:11.590 --> 32:40.470] So, when I publish a note, it automatically goes out, is seen by a universe of curators, and each user can choose the curators who provide them with the content that they want, not the content that the advertisers want to push into people's faces to make them mad so that they're engaged. [32:41.950 --> 32:58.210] And, of course, use feedback here so that when people comment on posts, all that feedback is being used to tell the curation algorithm, hey, this is Phil. [32:58.450 --> 33:00.270] Phil likes this sort of stuff. [33:00.790 --> 33:02.550] Find this sort of stuff. [33:02.690 --> 33:16.830] And then the curation algorithm, which has, say, maybe half a million people using that curation engine, looks, oh, look, people who match Phil's profile, they like this sort of stuff. [33:16.830 --> 33:18.110] I'll give him some of that. [33:18.550 --> 33:33.430] And then the way that you stop this from being shitified is the application that you're reading these feeds through, that application is constantly evaluating the performance of the curators. [33:33.430 --> 33:35.730] because you have accountability. [33:36.290 --> 34:03.010] So, if I have a curator that is constantly giving me nothing but post-whistling Dixie, or the sans-serie swastika for you feed, well, those just aren't going to appear in my recommendations because my client is going to decide, well, this is a curator that isn't worth following. [34:03.230 --> 34:06.830] Oh, and by the way, I'll unsubscribe you and stop paying the fee as well. [34:08.470 --> 34:08.990] Okay. [34:09.350 --> 34:12.970] So, hopefully, I've thrown out a lot of possibilities here. [34:13.830 --> 34:23.530] I think it should be obvious to all that this is not something that one person is going to be able to complete on their own. [34:24.570 --> 34:31.950] And so, the reason I've come here to HOPE is I'm looking for collaborators who are interested in building something better. [34:31.950 --> 34:34.570] You know, the web was great. [34:34.570 --> 34:43.450] In the early years, it really was a challenge to the model that Time Warner had for interactive TV. [34:43.630 --> 34:45.250] Does anyone remember interactive TV? [34:45.250 --> 34:45.270] See? [34:45.730 --> 34:57.130] This was this really... yeah, this vision of the future where everybody was going to have a 10-foot television in their living room. [34:58.110 --> 35:03.310] And the only interactivity was you could buy stuff. [35:06.840 --> 35:21.360] And one of the reasons the web was successful was that it hit at just the right moment because, you know, Time Warner, they put all this money into it and they discovered, oh, people don't really want this. [35:22.240 --> 35:24.940] Oh, we've got billion dollars to spend on it. [35:25.320 --> 35:26.260] What are we going to do? [35:28.580 --> 35:36.480] And so, all that money that was lined up to move into interactive TV, that all went into the web. [35:37.360 --> 35:42.540] And, you know, for a while there, you know, until the mid-aughts, we were winning. [35:42.940 --> 35:46.800] You know, the web was really owned by the people it was designed for. [35:47.200 --> 35:49.480] You know the Internet Society motto? [35:50.020 --> 35:52.440] The Internet is for everyone. [35:53.840 --> 35:57.480] Well, recent years, not so much. [35:58.340 --> 36:05.260] You know, recent years, it's kind of like being more the private property of eccentric billionaires. [36:05.260 --> 36:07.920] Oh, I'm using Twitter. [36:08.220 --> 36:17.280] Oh, I didn't realize that an eccentric billionaire fascist could just buy it up and fill my feed with... [36:18.520 --> 36:22.840] If we're going to take it back, it's going to require a movement. [36:23.080 --> 36:34.440] And we've got to start looking at how we limit the corporate owners' ability to control us. [36:34.440 --> 36:39.580] And the primary way I believe that we've got to do that is by addressing switching costs. [36:40.060 --> 36:47.500] As I said in the opening, if you've got a better way of killing this mouse, all power to you, I'll help you. [36:47.680 --> 36:49.340] You know, just sign me up. [36:50.980 --> 36:56.520] You know, back in the early days of the web, I had stuff that I was wanting to do. [36:56.800 --> 36:58.440] A new way of doing programming. [36:58.860 --> 37:04.400] I threw that over to join a guy called Tim Berners-Lee, who had this idea called the web. [37:04.860 --> 37:07.920] I'm more than happy of following somebody else's idea. [37:08.920 --> 37:11.560] But I've got one way of skinning this cat. [37:13.520 --> 37:17.240] Anybody who'd come and help me, that's what I'm looking for. [37:17.240 --> 37:18.620] Thank you very much. [37:20.120 --> 37:22.200] Oh, in conclusion, have hope. [37:22.500 --> 37:23.680] It is soluble. [37:24.260 --> 37:25.140] Any questions? [37:25.540 --> 37:29.180] Oh, contact information here, the YouTube, yeah. [37:30.020 --> 37:30.500] Questions? [37:30.860 --> 37:33.420] You have a mic on the stage there, which... [37:33.420 --> 37:34.340] Please go down to the mic. [37:34.700 --> 37:35.180] Let's do it. [37:36.480 --> 37:37.540] Oh, great. [37:39.220 --> 37:41.500] First of all, it was a great talk, so thank you. [37:42.600 --> 37:45.060] One of the printer stone of your mesh... [37:47.920 --> 37:50.900] It seems to be the unique identifier that rely on PKI. [37:51.140 --> 38:04.300] With the advance of cryptography that change and make cryptosystems broken every 10, 15 years, do you have any solution for when the PKI backend of the unique identifier need to change? [38:04.300 --> 38:07.120] I didn't hear that. [38:09.280 --> 38:09.920] PKI... [38:09.920 --> 38:17.500] So, your unique identifier is based on the cryptography and the PKI and the private key that is used, which is based by an algorithm. [38:18.420 --> 38:26.920] So, cryptography is evolving every 10, 15 years with cryptosystems that are now broken. [38:28.040 --> 38:28.480] So... [38:28.480 --> 38:30.720] Oh, are you talking about post-quantum cryptography? [38:31.840 --> 38:33.680] That's the new phase of it. [38:33.800 --> 38:35.220] There will be something else after that. [38:35.360 --> 38:40.120] But your unique identifier is based on that PKI key and the fingerprint in. [38:40.440 --> 38:40.880] Oh! [38:40.880 --> 38:44.340] So, if that's broken, what do we do? [38:44.420 --> 38:45.240] Do we lose that account? [38:45.440 --> 38:46.340] Do we need to change? [38:46.340 --> 38:47.700] Oh, okay. [38:48.020 --> 38:54.540] So, the question is about cryptography and, you know, is it... [38:55.340 --> 38:58.960] What's the cryptographic lifetime we can expect from this? [38:59.220 --> 39:03.180] All the cryptography that I'm using is industry standard. [39:03.980 --> 39:08.300] And I only ever use the highest strength ciphers. [39:08.520 --> 39:11.420] So, I don't use AES-128. [39:11.420 --> 39:14.600] I only ever use AES-256. [39:14.600 --> 39:18.160] AES-256 has a work factor... [39:18.160 --> 39:27.900] Well, AES-128 has a work factor against conventional cryptanalysis that is kind of like universe-sized. [39:28.760 --> 39:38.220] AES-256 has a work factor against quantum cryptography that is universe-sized. [39:38.220 --> 39:52.680] So, in terms of the cryptographic identifiers, the cryptography I'm using is all stuff that is rated by NIST for storing documents for 20-30 years. [39:52.680 --> 39:59.180] Now, when it... the fly that comes in the ointment there is quantum cryptanalysis. [39:59.860 --> 40:06.380] The current release of the mesh, it has the post-quantum algorithms in the build. [40:06.380 --> 40:11.480] I've not yet started making use of them in the code. [40:11.480 --> 40:14.660] That's something that I'm planning to do in the next few months. [40:15.120 --> 40:23.980] And with that, you should have an expected period, you know, at least 20-30 years against post-quantum. [40:25.160 --> 40:29.320] So, you know, it's always a possibility. [40:30.120 --> 40:38.140] And in the early days of cryptography, when we had really slow machines, we sailed close to the wind because we had to. [40:39.080 --> 40:40.500] Now we don't have to. [40:40.760 --> 40:44.920] We can use really strong algorithms and we can use them at the highest strength. [40:44.920 --> 40:51.060] So, I believe that it is secure for, you know, certainly for my lifetime and probably for yours as well. [40:54.210 --> 41:05.630] What sort of security features would this mesh that you've proposed have so that, like, if I were to apply for a job from Bob, that he wouldn't get my contact information and then see, like, here's his Grindr profile. [41:05.630 --> 41:07.730] Here's something else that you don't want to share with your employer. [41:07.870 --> 41:10.910] So, how do we keep accounts separate from people we don't want to see? [41:11.210 --> 41:12.270] Oh, great question. [41:12.270 --> 41:15.510] So, the question is about isolating identities. [41:16.410 --> 41:21.370] And, yeah, I've gone back and forth with different ways to do it. [41:22.170 --> 41:28.590] I mean, one way that you can do it is having separate contact identifiers for work and personal and so on. [41:28.890 --> 41:41.590] If you really want to keep those identities separate, however, the way that you need to do it is by creating separate mesh accounts and having clients that make that really easy to do. [41:41.850 --> 41:44.150] And that's what the current client does. [41:44.350 --> 41:49.670] You know, you can create as many mesh profiles as you like and run them independently. [41:50.470 --> 41:52.410] So, yeah. [41:53.990 --> 41:57.650] You mentioned earlier in the talk that we don't need regulation. [41:57.650 --> 42:00.610] We need, like, a technical solution. [42:01.510 --> 42:13.970] I'm just curious, even with a perfect technical solution, looking at how, like, Facebook's of the world and stuff have, like, cut away their APIs and, you know, don't produce things over RSS anymore and stuff. [42:13.970 --> 42:22.690] How do you imagine, or do you believe that it can be adopted without regulation? [42:23.330 --> 42:23.590] Oh. [42:24.650 --> 42:32.250] Well, one of the problems I have with people relying on regulation is I work with regulators a lot. [42:33.130 --> 42:37.270] In that one of my interests is security of critical infrastructure. [42:37.270 --> 42:44.970] And so, you know, we have absolutely no embarrassment about telling people running nuclear plants, you're going to do it securely. [42:45.350 --> 42:45.850] Yeah. [42:46.090 --> 42:47.130] And that's right. [42:47.370 --> 42:57.030] But the problem that I see with the current approach is the regulators have been told, make messaging open. [42:57.510 --> 43:03.190] But the technologists are not telling the regulators how to make it open. [43:03.190 --> 43:12.130] And, you know, if you're going to go to a regulator with a technical ask, you've got to go there with a technical solution as well. [43:12.490 --> 43:23.950] And so, yeah, if somebody was to go to the EU and say, hey, you want to make messaging open, this is how to do it. [43:24.750 --> 43:29.910] Yeah, I'm aware of the me-me group at ITF, and we can have an offline talk about that, yes. [43:31.650 --> 43:32.050] Yeah. [43:32.370 --> 43:33.810] Yes, this is a way of doing it. [43:33.910 --> 43:37.650] But you've got to give those regulators something to work with. [43:38.630 --> 43:43.270] And so, this is a technical thing on the table that can be turned into a demand. [43:44.590 --> 43:46.050] You've got this transition. [43:46.290 --> 43:58.570] I frequently work on acrimonious divorces, where someone's trying to revoke their soon-to-be former spouse's access to all of their contact information. [43:58.890 --> 44:01.850] Can you talk about how revocation works in the mesh? [44:02.770 --> 44:04.870] Oh, that's a great question. [44:05.190 --> 44:12.890] And so, I'd like to add in there the question of... [44:13.590 --> 44:15.010] Okay, do I have that? [44:15.150 --> 44:16.830] Oh, no, I don't have that screen. [44:17.350 --> 44:26.870] I'd also like to add in there, what happens if you are in a war zone and your house is destroyed and everything in it? [44:27.530 --> 44:28.170] Okay. [44:29.030 --> 44:35.430] I'm proposing that people start making use of encrypting data at rest. [44:36.050 --> 44:38.670] So that you have pictures of the kids, encrypt them. [44:40.010 --> 44:47.250] Now, if you're going to do that, you have got to have a really solid data recovery story. [44:47.730 --> 44:52.990] Because if you don't, well, you've just ransomware'd yourself. [44:52.990 --> 45:02.810] So, yes, there is a mechanism built into the mesh, Shamir secret sharing, where you can take your... [45:02.810 --> 45:08.070] The primary key that's used as a root for creating the PKI. [45:08.730 --> 45:15.750] And that can be split two out of three, three out of five is up to 16 shares. [45:15.750 --> 45:24.970] And then you end up with these ASCII character thingies that you distribute. [45:24.970 --> 45:32.010] And so, yes, we can recover from an absolute disaster. [45:32.930 --> 45:38.150] If we're looking at matrimonial, it's a little bit more complicated. [45:38.150 --> 45:45.410] Because you can only separate things if the parties thought about the separation at the outset. [45:46.530 --> 45:53.470] Yeah, but frequently you unfriend people and you don't want them to have all your prior contact information. [45:53.630 --> 45:54.850] Do you support that? [45:54.850 --> 45:59.870] Or is it only going forward that they no longer have access to future contact information? [45:59.870 --> 46:10.630] Okay, well, yes, shutting off updates is a lot harder than unsharing data. [46:11.490 --> 46:14.470] There is a mechanism that I could use. [46:14.470 --> 46:18.650] I could threshold secret share the actual contacts themselves. [46:18.650 --> 46:25.610] I'd be very leery about doing that, simply because it would be a huge overhead on doing that. [46:27.330 --> 46:38.870] What I would prefer there is, yes, with SMTP email, having somebody know your contact is a disaster because they can spam you. [46:39.230 --> 46:45.970] With messaging, every contact request, every communication request is access controlled. [46:45.970 --> 46:49.270] So if I don't want to talk to you... [46:49.270 --> 46:49.770] You can block. [46:49.970 --> 46:50.810] I can block. [46:51.050 --> 46:51.190] Right. [46:51.590 --> 46:54.110] And so the idea here is... [46:54.110 --> 46:56.930] Well, or I can push you off to my secretary. [46:57.310 --> 47:12.150] One of my goals here is Madonna or Hamilton can put their... Lewis Hamilton can put their mesh call sign on their business card. [47:12.150 --> 47:21.430] And they can use that for communicating with their close personal friends and their fans alike without getting spammed. [47:21.650 --> 47:22.690] It's a bejesus. [47:22.990 --> 47:23.170] So... [47:23.170 --> 47:25.790] Yeah, but also you're using this for credential sharing. [47:25.790 --> 47:29.610] So revocation becomes important in a case like that as well. [47:30.030 --> 47:39.510] Well, I see revocation as primarily being a authorization question rather than an authentication question. [47:39.510 --> 47:39.850] Okay. [47:40.170 --> 47:46.750] And that's something that I think we got wrong in PKI and that revocation is really revocation of authorization. [47:47.090 --> 47:47.890] Just one comment. [47:48.130 --> 48:00.570] If you had licensed the Belcorp patent on hash and sign, the charity used, you would have made a bad business investment because it got invalidated when they got sued. [48:00.570 --> 48:03.990] So, I think you can use it now freely. [48:04.370 --> 48:05.430] I was going to open it. [48:06.730 --> 48:07.790] Three quick questions. [48:08.010 --> 48:14.330] First, have you thought about latency in synchronous interchange between an open service mode? [48:14.530 --> 48:24.750] Second, are there micropayment implications for helping a lot of publishers who have lost their business models and people want to pay little amounts for stuff, but they don't want to subscribe or register for 400 publications? [48:25.410 --> 48:33.710] And third, is there lessons to be learned from telephone, cellular, portable numbers, how that actually happened? [48:33.870 --> 48:34.910] Was it consumer rights? [48:34.910 --> 48:36.630] Was it regulatory, legislative? [48:36.930 --> 48:39.690] Was it people getting pissed off that they couldn't bring their phone number? [48:39.850 --> 48:42.850] Maybe that mechanism could be used to help move this forward? [48:42.850 --> 48:44.950] Because it wasn't a technological thing. [48:44.990 --> 48:46.630] It was more of a consumer thing, I think. [48:46.630 --> 48:47.870] Okay. [48:48.350 --> 48:50.970] So, trying to... [48:51.470 --> 48:54.970] So, going back to the first one, which was... [48:57.490 --> 48:59.490] Oh, the interchange latency. [48:59.850 --> 49:00.270] Yeah. [49:00.730 --> 49:10.530] The reason that I switched from looking at WebRTC to looking at mock was one, much smaller vulnerability space. [49:10.870 --> 49:16.470] You know, 100,000 lines of code instead of tens of millions of WebRTC. [49:16.470 --> 49:24.090] But also, demonstrations of glass to glass of, you know, down there in the microsecond range. [49:24.430 --> 49:25.770] Really impressive stuff. [49:26.210 --> 49:35.890] Now, that would get worse, however, if you were to start to use mechanisms for traffic analysis avoidance. [49:36.410 --> 49:37.550] So, there's that. [49:37.730 --> 49:42.250] But the idea is, yes, you will have direct A to B communications. [49:42.250 --> 49:44.250] A second one was... [49:44.930 --> 49:45.430] Okay. [49:45.730 --> 49:46.330] Micropayments. [49:46.490 --> 49:46.790] Yes. [49:47.050 --> 49:51.970] I did actually write the first Internet draft on micropayments back in 95. [49:54.290 --> 49:54.890] Um... [49:54.890 --> 49:55.450] Yes. [49:55.830 --> 50:01.750] I am very keen on doing them, but I think that right now, I've got rather a large system. [50:01.750 --> 50:13.880] And one of the reasons that I don't want to go down any route that looks like payments right now is because there are so many Ponzi coins and crypto Ponzi's. [50:14.620 --> 50:16.340] And I'm sorry, but... [50:17.920 --> 50:20.160] Well, I, you know, I knew Hal Finney. [50:20.260 --> 50:20.900] He was a friend. [50:21.760 --> 50:23.400] And, yeah, I respect what he did. [50:23.560 --> 50:25.140] And cosplaying as Satoshi was great. [50:25.340 --> 50:26.640] Yeah, but... [50:26.640 --> 50:28.540] I am... [50:28.540 --> 50:32.200] I am deeply offended by the idea of proof of work. [50:32.620 --> 50:35.700] Proof of waste, I find, morally offensive. [50:36.260 --> 50:44.320] And I find what Marc Andreessen has done to be absolutely diabolical. [50:44.320 --> 50:46.060] He's a really... [50:46.060 --> 50:46.400] He's a really... [50:46.400 --> 50:47.380] He was a billionaire. [50:47.900 --> 50:50.180] And what's he spent his last five years doing? [50:50.520 --> 50:53.880] Trying to con poor people out of his money. [50:54.300 --> 50:56.560] What a real shit. [50:57.280 --> 50:57.800] Yeah. [50:59.080 --> 50:59.600] Okay. [51:00.160 --> 51:00.680] I'm... [51:01.700 --> 51:02.220] Yeah. [51:03.560 --> 51:04.080] Uh... [51:04.080 --> 51:04.380] Okay. [51:04.480 --> 51:05.420] Do we have time for one more? [51:05.920 --> 51:06.440] Or... [51:06.440 --> 51:07.240] Oh, I think we... [51:07.240 --> 51:08.020] Okay, let's... [51:08.020 --> 51:08.780] Very quickly. [51:09.020 --> 51:10.100] So, I love that very much. [51:10.280 --> 51:12.460] I'm trying to understand a little more about your revocation. [51:12.460 --> 51:14.780] So, maybe this is a continuation of the divorce question. [51:15.060 --> 51:29.880] But it sounded like if I lose access to a device, the quorum of shared keys has a key member, which is like a cloud service, that is not itself a quorate, but no quorum can exist unless it includes that cloud. [51:30.100 --> 51:38.780] So that I can always revoke my phone because if the phone is gonna ask the cloud, can I have your fraction of the key? [51:39.200 --> 51:45.580] Does that mean that if this trusted third-party disappears, or is blocked, or is unavailable, that I can't activate new devices? [51:45.800 --> 51:50.200] Or can I have a quorum of user-controlled devices that are outside of the cloud? [51:50.320 --> 51:54.440] And if so, how does that affect my ability to revoke one of those devices if I lose control of it? [51:54.440 --> 52:07.940] Okay, so in theory, in that this gets into the part where, yes, it's been tested, but whether it works in today's code is a good question. [52:08.520 --> 52:16.640] Yeah, basically, there's enough information in the administrator account to be able to reconstruct the whole system. [52:16.640 --> 52:33.460] If you move from one provider to another, what you would end up doing is effectively reconnecting each device to the new provider, and so that becomes the challenge. [52:33.460 --> 52:36.960] Yeah, how do you make sure that this doesn't become an orphan advice? [52:37.120 --> 52:38.500] Yeah, I have my toaster. [52:39.160 --> 52:42.060] How does my toaster know to know... [52:43.120 --> 52:46.300] know where to ask to find out where it's gone? [52:46.620 --> 52:50.280] I have strong feelings about connecting toasters to the Internet, but thank you very much, Ali. [52:50.320 --> 52:53.820] Yeah, I have a food blender that's Internet-connected because... [52:53.820 --> 52:54.280] why? [52:55.280 --> 52:57.040] Anyway, thanks very much. [52:57.040 --> 52:57.900] Give it up!