[00:01.020 --> 00:04.340] Thanks so much, everyone, for coming out in this noon panel. [00:05.220 --> 00:10.080] First, before we get into who we are, I wanted to cover a little bit of who EFF is. [00:10.200 --> 00:15.760] I know you're all here and you all know this already, but cover a few basic factoids and introduce our organization. [00:17.220 --> 00:19.160] We are the Electronic Frontier Foundation. [00:19.600 --> 00:21.980] We are a subset of the EFF. [00:22.320 --> 00:28.860] We can't cover every single topic that you might have questions on, because we're a vast organization, we cover a lot of things. [00:30.000 --> 00:52.900] But some of the historical high points of us, our formulation is in 1990, in a case called Steve Jackson Games, where the Secret Service, who is kind of tasked with cybersecurity at the time, when there was kind of an interdepartmental kind of who is in charge of cyber, [00:53.100 --> 00:58.740] this new cyber realm, the Secret Service kind of tried to stake a claim in that. [00:58.740 --> 01:04.800] And sued Steve Jackson Games for a GURPS gaming system, which included hackers. [01:05.200 --> 01:07.940] Because it included hackers, it must be teaching hacking, right? [01:09.320 --> 01:11.220] Well, he said, we called bullshit on it. [01:11.320 --> 01:16.480] We said, hey, no, this is not actually some dangerous tool in the hands of hackers. [01:16.700 --> 01:20.240] This is just a tabletop game. [01:20.240 --> 01:30.180] And, you know, this is not, you know, spreading something like a mine virus or whatever they thought at the time. [01:31.260 --> 01:33.040] So that was in 1990. [01:33.640 --> 01:36.520] We grew our legal team in the 90s. [01:36.700 --> 01:41.540] One of the landmark cases we were involved with was Bernstein versus the DOJ. [01:41.540 --> 01:51.240] In the 90s, originally, strong cryptography was considered a munition and liable for export law. [01:51.540 --> 02:10.900] And so, in Bernstein versus DOJ, Daniel Bernstein produced a white paper detailing cryptography and the Department of Justice sued Daniel Bernstein and basically said that he was passing out munitions. [02:10.900 --> 02:18.940] And we, again, called BS on this and served as counsel for Daniel Bernstein. [02:18.940 --> 02:28.060] And that resulted in a decision at the federal level considering code a form of First Amendment protected free speech. [02:28.060 --> 02:47.420] And as a result, made cryptography legal and widespread for everyone to the point now that we have it on our devices, every single, you know, not only signal, but also just in the cryptographic protocols that we communicate with every day. [02:47.420 --> 03:09.240] So, the last decades, we have been involved in a number of issues ranging from free speech, defending innovation against patent trolls, making sure that your privacy and security is protected online. [03:09.240 --> 03:31.280] We hired the first public interest technologist by the name of Seth Schoen and were involved in developing HTTPS Everywhere, which, well, I can get into if people have questions about, but it was basically something that made it so that encrypted... [03:31.280 --> 03:47.600] your communication with sites were encrypted if it was available, involved in different browser plugins that protect your privacy, like Privacy Badger, and different legal and activism cases that we'll all get into. [03:47.600 --> 03:47.660] Thank you. [03:49.000 --> 03:49.300] Thank you. [03:49.300 --> 03:53.400] So, a quick five-minute summary of our work. [03:54.740 --> 03:57.020] For me, I'm Bill Buddington. [03:57.460 --> 04:06.780] I've been with EFF for 12 years, and I'm a senior staff technologist at EFF. [04:07.020 --> 04:11.280] I worked on HTTPS Everywhere, was the lead for that from 2015 to 2018. [04:12.340 --> 04:14.940] I do some reverse engineering. [04:14.940 --> 04:39.940] I do a lot of cybersecurity policy and formulating kind of a sane policy, suggesting, veering some legislators off from bad language that could have bad implications for security researchers or open-source developers, and just generally developing privacy enhancing and security technology. [04:39.940 --> 04:44.460] So, that's the five-minute wrap-up for me. [04:47.790 --> 04:48.230] Hi. [04:48.650 --> 04:50.050] I'm Cara Gagliano. [04:50.530 --> 04:53.390] Already kind of losing my voice from yesterday. [04:53.390 --> 04:54.650] So, sorry. [04:56.210 --> 04:58.550] I'm an attorney at EFF. [04:58.950 --> 05:03.350] This coming week will be my six-year anniversary with EFF. [05:03.350 --> 05:06.690] So, yes, I've got halfway to you, Bill. [05:08.990 --> 05:25.750] I think probably most relevant to this crowd am on our Coders Rights Team, which is a team of a few attorneys that is really focused on providing legal advice to security researchers and hackers. [05:26.910 --> 05:30.810] So, y'all can come to us at different stages. [05:31.650 --> 05:41.910] You know, sometimes we're talking to folks who have just found a vulnerability and they're not really sure how to report it, what to do. [05:41.910 --> 05:52.610] They're not sure if they might have actually broken a law in the way that they found it, or they're more concerned about how a company is going to react. [05:52.870 --> 06:09.910] And sometimes we hear from people who have disclosed and did not like how the company reacted, whether they're being threatened with a defamation lawsuit or the company is just not responding at all. [06:09.910 --> 06:21.830] We try to help them work through at least the legal side of things, you know, what the implications could be for different paths forward and how to weigh that risk. [06:21.830 --> 06:41.010] So this is actually, this is work that I think people are often familiar with at HOPE, DEFCON, Black Hat, but is maybe less visible to the general public than some of our work because if everything goes right, there isn't really a big story. [06:41.010 --> 06:44.370] It's just our client is not getting sued. [06:45.350 --> 06:53.390] And I would say that is pretty much all the time what happens clearly because we're so great at it. [06:54.410 --> 07:07.050] But apart from that, I have as my sort of focus area trademark and copyright law, particularly where they intersect with free speech issues. [07:07.050 --> 07:31.190] So I do a lot of representing artists, activists, parodists, who are critics who are faced with threats from people they are criticizing or parodying over use of at least what those people see as their IP. [07:31.970 --> 07:47.050] So get to send a lot of fun snarky letters back to people telling them why their claims are BS and also are more likely to backfire on them with Streisand effect type consequences. [07:47.810 --> 08:13.030] And then other than that, actually, what I've been spending the most of my time on for the past two years is a case that we have against San Mateo County, California over a policy in their jails where people who are incarcerated in San Mateo jails are no longer allowed to receive physical mail at all. [08:13.230 --> 08:40.990] If you want to send a letter to your brother, your son in San Mateo jail, you have to send that letter to Smart Communications, a carceral tech company based in Florida, and they will scan your letter, shred your letter, and upload the scan into a database so that the recipient can access it on a [08:40.990 --> 08:41.810] shared tablet. [08:45.770 --> 08:57.590] can't print it out, can't print it out, can't print it, can't print it out, can't really engage with it, can't pull it out while they're lying in bed at night needing something to make them feel like it's worth going on. [08:58.330 --> 09:04.410] And that has been really hard for a lot of people, including our clients. [09:04.410 --> 09:11.670] So we have claims based on the California constitutional analogs of the first and fourth amendment. [09:11.990 --> 09:19.370] And that case has been going on about two years now, still going, but we are sticking with it. [09:22.340 --> 09:23.640] Hi, everyone. [09:23.860 --> 09:24.440] I'm Lena. [09:24.840 --> 09:27.840] I've been at EFF a little over a year. [09:28.160 --> 09:37.980] I primarily work on Privacy Badger, which is EFF's free browser extension that blocks online trackers. [09:37.980 --> 09:44.780] I highly recommend everyone use it to stop companies from spying on you as you browse the web. [09:46.260 --> 09:53.500] There's two EFF developers working on Privacy Badger, and it's used by about 4 million people. [09:53.500 --> 09:57.520] So that involves a lot of maintenance. [09:58.060 --> 10:04.560] We are slowly working on getting Privacy Badger onto Safari. [10:04.560 --> 10:15.440] We're working on a feature to automatically handle those annoying cookie consent banners that don't even respect people's choices for the most part. [10:15.440 --> 10:33.200] And we're also just working on ways to make Privacy Badger more usable and accessible, especially to low, I don't know, low tech audiences or, you know, people who might not even realize the dangers of online tracking. [10:33.200 --> 10:57.060] Outside of Privacy Badger work, I do general advocacy and writing and working with EFF lawyers and activists on issues around corporate surveillance, the data broker industry, online tracking, and a lot of the links between advertising technology and the surveillance industry. [10:57.720 --> 11:09.180] And also just, like, writing about shitty things that big tech companies like Meta and Google do with your information. [11:09.960 --> 11:10.660] So, yeah. [11:12.320 --> 11:13.180] Hi, everybody. [11:13.380 --> 11:14.080] My name is Jose. [11:14.420 --> 11:15.720] This is my third time at HOPE. [11:15.900 --> 11:23.800] My second time was last year, and my first time was 20 years ago with people from the Anarchist Village back in the day. [11:25.340 --> 11:38.780] And I have been... I'm a senior grassroots advocacy organizer in the activism team, a team of people who are not technologists or lawyers, but most of them do incredible work. [11:39.180 --> 11:40.280] And then there's me. [11:40.440 --> 11:47.500] I've been at EFF for a little over four years, although I've had Privacy Badger on my browsers for at least, you know, 15, 20 years. [11:49.420 --> 11:55.880] And the things that I work on principally are... I work with what we call the Electronic Frontier Alliance. [11:56.080 --> 11:58.540] So the activism team mostly focuses on stuff. [11:59.180 --> 12:03.740] There is an international team, and then a lot of us work on domestic issues only. [12:03.740 --> 12:20.900] So I work on domestic issues with members of the Electronic Frontier Alliance, a network, a very loose network of local groups across the United States that do popular education, lobbying, advocacy, promote best practices on a wide variety of issues. [12:20.900 --> 12:28.020] Some of them are campus-based, some of them are professional-based, some of them are just activists in the community that want to get things done. [12:29.560 --> 12:32.300] And, you know, and we're always looking for new recruits. [12:32.380 --> 12:48.760] You can find out more at EFA.EFF.org or you can talk to me if you are a member of a local group somewhere in this country that wants a very, very, very decentralized network to align with that is connected to EFF. [12:48.760 --> 12:57.240] My personal issue areas tend to focus around what we call SLS, street-level surveillance. [12:57.580 --> 13:04.620] So that is police tech issues, carceral tech issues, and border tech issues. [13:04.620 --> 13:16.560] And then I also work a lot around what we and a lot of other organizations also call bossware, which is a combination of surveillance in the workplace as well as algorithmic decision-making tech and products. [13:16.560 --> 13:24.940] It's a very big marketplace and there's a lot of shoddy products that are being sold to management across the country right now. [13:25.080 --> 13:34.800] So those are some of the types of issue areas that I work on, but obviously the rest of the activism team works on all these other types of issues, intellectual property issues and right to repair. [13:35.380 --> 13:41.380] You know, other algorithmic decision-making questions, broadband access, online privacy access. [13:41.600 --> 13:48.580] And we do it through a wide variety of public pressure campaigns, some lobbying at the municipal and state level. [13:48.720 --> 13:55.680] We mostly do municipal and state level lobbying and advocacy, as well as working with local groups that are doing campaigns. [13:56.380 --> 14:07.120] Sometimes, for example, to, in my case, prevent police surveillance technology contracts at the local level that EFF might agree police shouldn't have. [14:07.260 --> 14:21.660] So for example, face recognition, we sometimes get contact from EFA members or from non EFA members and members of my team will work with them on these kinds of local advocacy fronts, give them help and support on strategy. [14:23.480 --> 14:32.760] And, you know, you know, talk to the to the municipal or the state legislature as experts or otherwise try to offer support in those kinds of ways. [14:32.880 --> 14:34.900] So that's that's a lot of what I do. [14:35.420 --> 14:44.860] Again, my name is Jose and I'll turn it back over to Bill, our emcee, and, you know, get y'all's questions. [14:45.500 --> 14:47.720] Just a few pieces of stage setting. [14:49.200 --> 14:56.760] We have two hours allocated to us, but I think our energy might run out at about the one hour, 30 minute mark. [14:58.160 --> 15:00.060] So just keep that in mind. [15:01.340 --> 15:04.020] And yeah, another piece of kind of housekeeping. [15:05.900 --> 15:06.420] Yeah. [15:06.680 --> 15:11.660] So do you want to be clear that this is not a forum to get legal advice? [15:12.480 --> 15:20.580] If you need legal advice, you should email info at EFF dot org and our incredible intake coordinator. [15:20.780 --> 15:26.500] Haley will set you up with either me or one of our other lawyers. [15:26.720 --> 15:34.260] She always knows who is going to be the actual best person to help you even better than I might know sometimes. [15:35.960 --> 15:40.760] So just to be clear, I'm not anyone's lawyer here, not representing any of you guys. [15:41.240 --> 15:48.300] I'm not going to give specific legal advice, but can, you know, talk about legal issues that we are working on. [15:50.300 --> 15:54.040] And with that, I would like to open up the floor. [15:54.040 --> 15:56.180] If anyone has any initial questions, don't be shy. [15:56.720 --> 15:58.460] We got two mics up front. [15:58.880 --> 16:02.820] So come on up and ask your questions. [16:03.940 --> 16:04.660] Good afternoon. [16:04.840 --> 16:05.420] Thanks for coming out. [16:06.140 --> 16:07.720] I wonder if you could speak a little bit. [16:07.820 --> 16:18.020] Of course, there are so many people in the hacker world, the technical world and stuff, who fully agree with EFF on things like protecting your rights in and around and with technology. [16:18.640 --> 16:26.760] I wonder if you would want to speak about maybe mistakes people are making, things that people could be doing better before they have to come to you. [16:27.900 --> 16:30.640] What are the bad ideas you've seen people have? [16:31.120 --> 16:32.060] Stuff like that. [16:34.920 --> 16:36.680] Do you want to talk about what's possible? [16:39.000 --> 17:04.860] Yeah, from a kind of legal perspective, really mostly just if you are doing like security research and maybe especially if you're someone who's new to it and you're not really sure, you know, what the conventions are or whether you're doing something that might be legally questionable, [17:05.280 --> 17:06.260] come to us early. [17:07.120 --> 17:16.820] It's better to come to us and ask, you know, is there a way I can do this that would be more or less legal? [17:17.900 --> 17:27.420] We can help you at that stage, ideally, rather than coming to us and saying, OK, I want to disclose this. [17:27.600 --> 17:37.720] And we take a look and go, well, OK, let's figure out if there is a way we can disclose this that doesn't make it very clear to the laws that you broke. [17:39.160 --> 17:41.980] So I guess that's one thing to keep in mind. [17:43.000 --> 17:52.200] But I don't know that we see a lot of like really big mistakes people are making legal wise. [17:52.600 --> 18:00.960] I don't know if you were also kind of asking about like things people should be doing to protect themselves privacy wise. [18:02.660 --> 18:14.600] Yeah, I mean, I think that the issue is that a lot of the technologies we use on a day to day basis are created by companies who have the incentive to surveil us. [18:14.600 --> 18:30.360] So if you use the technologies you purchase with their default configurations, you're giving up a lot of privacy and potentially exposing yourself to different types of risks. [18:31.000 --> 18:40.020] I feel like people get overwhelmed when they hear that, though, and think that like they become privacy nihilists and think there's nothing they can do to keep their information safe. [18:40.020 --> 18:54.080] And I think there's a spectrum of different steps you can take to protect your privacy depending on your threat model or the you know, and how vulnerable you are to different sorts of surveillance threats. [18:54.280 --> 19:02.960] And I think for most people, there are, you know, pretty easy things you can do that will make a difference. [19:03.140 --> 19:06.680] They won't protect you from all forms of corporate or government surveillance. [19:06.680 --> 19:15.600] But like, for example, using some sort of tracker blocker like Privacy Badger and disabling your advertising ID on your phone. [19:15.780 --> 19:28.380] Your advertising ID on your phone is an identifier that a lot of data brokers and ad tech companies use to, like, connect you to the data they collect about you. [19:28.380 --> 19:31.140] And it takes, like, two seconds to turn off. [19:31.300 --> 19:37.080] Most people with iPhones have turned this off already because Apple took the, like, proactive... [19:37.700 --> 19:41.960] A few years ago, like, asked people if they wanted apps to track them and most people said no. [19:42.220 --> 19:45.800] I feel like those are very two small things that people could be doing. [19:45.800 --> 19:56.160] But I think that, like, EFF's street-level surveillance guides have much more detailed advice targeted to different audiences. [19:56.160 --> 20:02.560] Like, I think people receiving or providing reproductive care, activists. [20:03.180 --> 20:03.320] Yeah. [20:04.060 --> 20:05.260] Do you have anything? [20:05.440 --> 20:05.940] Yeah. [20:06.220 --> 20:11.300] First of all, the street-level surveillance guides that Lena was mentioning were... [20:11.300 --> 20:14.120] You can find it at sls.eff.org. [20:14.780 --> 20:17.020] And I would just say a couple of things. [20:17.580 --> 20:26.160] One, a lot of people contact us really panicked about things that they've seen kind of scare tactics and scare fear-mongering around. [20:26.380 --> 20:29.620] And not necessarily things that are real data threats to them. [20:30.080 --> 20:33.540] And so, you know, think about, is this a real threat? [20:33.700 --> 20:41.260] Think about your threat model and try to give yourself a real risk assessment first before necessarily coming for advice. [20:41.260 --> 20:44.720] Because it kind of helps you clarify your questions before you approach. [20:45.220 --> 20:51.940] And then I think one of the other things to know about EFF is we don't generally suggest specific software. [20:52.440 --> 20:54.840] Or at least officially as EFF. [20:54.980 --> 20:58.700] We don't suggest specific software with some exceptions here and there. [20:59.000 --> 21:01.300] Obviously, Privacy Badger being one of the big champs. [21:01.940 --> 21:03.140] But that's different. [21:03.700 --> 21:06.960] So, you know, people will tend to... [21:06.960 --> 21:10.160] And a lot of the people who come to us do tend to do their own research. [21:10.160 --> 21:14.300] That's one of the places that you're going to have to do your own research rather than coming to us. [21:14.660 --> 21:18.440] Usually, most of the time is figuring out what kinds of software you trust. [21:19.060 --> 21:27.120] What is secure in that kind of way rather than, you know, expecting us to kind of tell you, well, this is the best thing on the market right now. [21:28.820 --> 21:32.700] I think we'll do a cadence of the stage right. [21:32.980 --> 21:34.140] Love your shirt, by the way. [21:36.140 --> 21:36.880] Thank you. [21:38.160 --> 21:42.520] Thank you for coming out here today and doing this panel. [21:43.220 --> 21:52.500] Just a quick question about the legislation that is, I think, currently on the books in the UK and is being proposed in the U.S. as well. [21:53.180 --> 21:56.500] That would mandate websites verify identities. [21:58.360 --> 22:01.540] Has the EFF responded to that? [22:01.760 --> 22:09.060] And what can we do to protect ourselves from this kind of legislation in the U.S. and in individual states? [22:10.320 --> 22:18.800] Yeah, you're referring to the Online Safety Act in the UK and the age verification mechanisms that are at play. [22:18.800 --> 22:27.580] And this is kind of an increasing problem that's appearing in a lot of contexts across the world, right? [22:28.900 --> 22:33.700] There's a myriad of problems with the Online Safety Act in the UK. [22:33.700 --> 22:43.820] One of which is that the mechanism by which they are demanding that people verify their age is sending private information to U.S. companies. [22:43.820 --> 23:05.700] And so national security is being compromised in this way where there's just a bunch of UK citizens' information mandatorily being delivered to data silos in the U.S. in order to perform just basic online browsing. [23:05.700 --> 23:14.080] You know, some of the forums that we've seen banned in the UK unless you do some form of age verification. [23:14.680 --> 23:18.520] You know, include just basic health information. [23:19.340 --> 23:24.640] You know, just a number of... have some of the forums here. [23:25.860 --> 23:27.020] One moment. [23:29.990 --> 23:30.630] Yeah. [23:31.710 --> 23:33.590] So, like, reddits are poker. [23:34.210 --> 23:37.110] Reddits are World War II earwax. [23:38.250 --> 23:41.790] Reddits are popping, which is the home of Bruce Lee satisfying. [23:42.210 --> 23:43.030] Oh, okay. [23:43.630 --> 23:45.350] That's pimple popping, I guess. [23:47.010 --> 23:48.950] And r slash rick roll. [23:48.950 --> 24:04.110] So, like, these are not, you know, particularly controversial, you know, forums that they're banning basically until you are forced to verify your age with a U.S. company. [24:05.130 --> 24:14.870] So, and then a lot of people in the UK didn't realize this until it actually was implemented, until they started affecting their actual browsing, right? [24:14.870 --> 24:23.450] I think there's going to be a lot more outrage, hopefully, around these age verification and age estimation, you know, technologies. [24:25.370 --> 24:36.850] And, you know, this has come up in the context of, you know, the EU and their Digital Services Act and also Digital Fairness Act. [24:36.950 --> 24:38.470] That's kind of in formulation. [24:38.470 --> 24:56.490] And the age estimation technology, they're just not... they're not vetted at all and do terrible jobs generally at, like, trying to... and often very biased jobs in estimating someone's age. [24:56.670 --> 25:06.450] If they have some sort of disability that has affected, you know, their facial features, for instance, then that age estimation is often incredibly off. [25:06.730 --> 25:13.910] There's just no good objective criteria by which you can do that kind of estimation. [25:14.250 --> 25:23.010] And now it's just becoming law because it's politically salient for politicians to say, oh, we protect the children. [25:24.430 --> 25:39.370] So, in terms of your question about what EFF has been doing in response to this, in part in the U.S., in particular, a number of these laws have already been passed at state levels. [25:39.820 --> 25:52.290] And there have been lawsuits against those wherever they've popped up, which EFF has been filing many amicus briefs in and following as they go. [25:52.290 --> 26:05.250] I know right now, two of the major ones that have kind of split from each other, I mean, a circuit split are one in Florida where the court struck down age verification law. [26:05.350 --> 26:31.270] Then in Texas, the first court struck down their age verification law, but then the fifth circuit, notorious fifth circuit court of appeals, just without really giving any reasoning, said we're going to essentially press pause on that decision and let them keep enforcing the law until we decide it ourselves. [26:33.070 --> 26:42.090] And the Supreme Court just said the other day, we're not going to interfere with that stay. [26:42.310 --> 26:47.570] It's called a stay when a court basically says, okay, put pause on that decision. [26:49.030 --> 26:56.930] So it's kind of like a race right now, seeing which of those cases is going to get to the Supreme Court first and what is going to happen there. [26:58.730 --> 27:02.110] So we're in the courts, we're doing a lot of amicus briefs. [27:02.130 --> 27:11.230] And then I think we're also doing a lot of legislative lobbying work and trying to get folks to know what they can do to help. [27:11.230 --> 27:14.090] A lot of it is right to your legislators. [27:14.970 --> 27:17.250] We have EFF's action center. [27:17.650 --> 27:34.690] I think, I don't know for sure, but I think very likely has some active actions right now related to these age verification bills, because as Bill mentioned, really the line that is being taken is, this is about protecting the children. [27:34.810 --> 27:40.250] And when that's all you're hearing, like, yeah, that sounds like a good idea. [27:40.250 --> 27:41.650] to protect children. [27:41.910 --> 27:44.890] Why would we want to not protect children? [27:45.850 --> 27:53.570] So you really need people who are informed speaking up and telling their legislators, actually, no, I don't want this. [27:53.650 --> 27:55.870] I don't agree that it does protect children. [27:55.870 --> 28:00.330] I think it will actually hurt children and hurt everyone else in the process. [28:01.190 --> 28:01.750] Right. [28:01.890 --> 28:09.310] There's a lot of, there's certainly a lot of evidence of how bad this, this kind of legislation has been already. [28:09.310 --> 28:19.150] And it's almost useful because a lot of the people who've been arguing against it at the policy level, internationally and domestically, were saying that these kinds of things were going to happen. [28:19.330 --> 28:37.010] That thing, that if you're trying to, you know, put age verification walls up around, for example, you know, obscene material, the broadening of what is obscene, is considered obscene material is going to mean that young people are going to have a lot less access to very basic stuff that they need [28:37.010 --> 28:39.570] for, for their educations and for their lives. [28:40.690 --> 28:47.450] So there's, you know, we have a year, we have a international team in Europe that has been active around this. [28:47.590 --> 29:00.830] And then on the domestic front, we also have a state legislation team that has been tracking and also pushing back very hard on, you know, there are tons of laws that, and tons of bills across the country that have been proposed. [29:00.990 --> 29:02.790] And as you've heard, a few that have been passed. [29:03.450 --> 29:20.210] I want to say that one of the things that we've noticed on the kind of legislative advocacy and lobbying side is that there, you know, there's a lot of lawmakers and there's a lot of stakeholders who have nefarious, you know, they have very bad intentions, right? [29:20.730 --> 29:27.330] Some of that is data collection, some of that is censorship, and it's, you know, an attack on free expression, free speech. [29:27.490 --> 29:30.130] And there's also a competence issue, right? [29:30.250 --> 29:35.310] There's a lot of incompetence in legislatures across the world and certainly across the country. [29:35.310 --> 29:42.970] Some of this is simply an issue of you get a big amount of hype and then, you know, a lot of fear-mongering. [29:43.110 --> 29:53.010] And then state legislatures don't understand how these mechanisms work, how they function for normal people, for people who are not children or for people who are not underage, as well as for children. [29:53.270 --> 30:07.610] And so making sure that your comments to state legislatures, because it's mostly at the state level, although they certainly are pushing this at the federal level as well, making sure that they understand how this tech works, how it actually directly affects people. [30:07.850 --> 30:25.610] The case examples that are happening in the UK of adults not being able to access sites that they should be able to, or of all sorts of, you know, data collection on adults, as well as all of the ways that it's actually adversely affecting minors in terms of keeping them from gender-affirming care, [30:25.790 --> 30:30.730] you know, websites, reproductive health websites, even just basic sex ed websites. [30:30.990 --> 30:49.470] And even, you know, far, far beyond that, we have a website called the Red Flag Machine, which is a little bit related to this, where you can go and you can see what various kinds of software that are used by municipal school districts are censoring. [30:49.770 --> 31:09.030] And the way that they censor things in obscenity means that they will just, you know, there's a massive amount of stuff that has nothing to do with sex or drugs or the things that usually legislatures are being fear-mongered around that is getting censored in schools or getting censored in school [31:09.030 --> 31:16.330] hardware that is given to students just because of the wrong buzzword or is included or something to that effect. [31:16.530 --> 31:18.750] So it's really having a big effect. [31:18.770 --> 31:23.570] And a lot of it is that, you know, some of these legislatures aren't actually completely nefarious. [31:23.690 --> 31:24.710] They're just incompetent. [31:24.790 --> 31:26.650] Their offices don't understand these things. [31:26.730 --> 31:33.910] And it requires technologists and people who understand this tech to communicate this is how it's, this is how it's actually affecting people. [31:33.990 --> 31:35.030] And this is how it actually works. [31:36.690 --> 31:37.910] Age left mic, please. [31:38.970 --> 31:39.450] Yeah. [31:39.650 --> 31:49.190] So my question is, as like, I guess, like a legal, legal, like advocacy group that has actually, like, sort of had to do the work of like arguing legal cases. [31:49.690 --> 32:03.830] I'm curious whether or not, like in your experience, like specifically in the U.S., whether you feel as if like there is a sort of consistent logic to court decisions where you feel as if like the legal argument you make, like actually have weight or actually, [32:03.830 --> 32:11.030] or actually feel like there is, there is a route whereby you can argue these things on legal terms and actually like effect change. [32:11.050 --> 32:16.270] Or if it feels like you're kind of just, I'm kind of just betting on politics to swing the right way. [32:17.370 --> 32:18.930] Yeah, you're tapping into something. [32:20.930 --> 32:41.170] You know, that is part of what drew me to law and the judicial branch rather than legislative branch was this at least theory that I should be able to use logic to prevail something which I think might also resonate with folks in this crowd. [32:41.170 --> 32:47.510] Like if, if it's logically correct and I can like set up my argument, I should win. [32:47.810 --> 32:50.210] It does not always work that way. [32:50.590 --> 33:01.170] But I think it does certainly more often than in the legislative realm or regulatory realm a lot of times. [33:01.370 --> 33:02.610] Kind of a low bar though. [33:02.610 --> 33:03.090] Yeah. [33:03.250 --> 33:03.550] Yeah. [33:03.670 --> 33:03.810] Yeah. [33:03.810 --> 33:09.630] It's a, it's a low bar, but I mean, it is, you know, it is something that varies a lot too. [33:09.790 --> 33:26.050] Like I mentioned the notorious fifth circuits, the federal appellate courts in Texas are notorious for reaching decisions that don't seem at all consistent with law and seem totally politically motivated. [33:27.210 --> 33:30.490] You know, and you can see that going both ways. [33:30.810 --> 33:42.490] Like, I mean, you certainly always hear conservatives talking about activist judges on the left and how really you need to stick to the original text. [33:42.690 --> 33:53.310] And yet somehow the original text always seems to favor their position as they read it, because that's not really how text works. [33:53.310 --> 33:54.130] Right? [33:54.390 --> 33:59.630] There isn't just like an objective truth that you can reach in and pull out of it. [33:59.630 --> 34:02.750] It's always going to be colored by your perspective. [34:03.370 --> 34:16.550] So it, you know, that is certainly a source of some disillusionment and frustration, but, you know, I think there is still plenty of reason for optimism. [34:16.550 --> 34:40.190] I still think that is a, one of the advantages of working through litigation and the fact that, you know, you have like, there is an appellate system, you know, so if you have one bad judge, at least you get to go up and say, hey, this is totally wrong, [34:40.510 --> 34:45.390] do something about it, and then you have three judges, at least. [34:45.590 --> 34:55.910] And, you know, you're, you're hoping you're playing the numbers a little bit, but I, I do think there's, you know, we're not giving up on litigation. [34:55.910 --> 35:06.170] How is like, I guess, like specifically like the Supreme Court been when it's come to like, I guess, like the FF and just like generally being able to make those legal arguments and like being able to find like a consistent train of logic you can appeal to? [35:07.930 --> 35:11.190] I think that's another one where it, it varies a lot. [35:11.190 --> 35:16.470] Um, and it can kind of vary based on the subject matter too. [35:16.810 --> 35:28.770] Um, in that it is interesting with our issues, you know, traditionally, it's not always split along ideological lines, actually. [35:29.010 --> 35:39.850] Um, you know, so certain kinds of first amendment cases, actually, like I think justice Roberts has been one of the better justices on. [35:39.850 --> 35:46.630] Um, and then when you get to like copyright and trademark, you know, all bets are off. [35:47.110 --> 35:57.290] But it's, uh, actually justice Ginsburg, wonderful on many things, but was like one of the worst on copyright from an EFF perspective. [35:57.670 --> 36:06.650] Uh, so, you know, it, it really changes with the makeup of the court and the specific type of case you're dealing with. [36:07.190 --> 36:07.610] Okay. [36:07.930 --> 36:08.310] Thank you. [36:10.070 --> 36:16.530] One good decision that we got, um, before the current makeup of the Supreme Court, um, was Carpenter. [36:16.930 --> 36:28.010] And that was, um, the storing of, uh, of basically on your cellular location data based on which cell phone towers that you've connected to. [36:28.010 --> 36:29.830] Um, you know, um, understand it. [36:29.990 --> 36:39.690] Um, and that, uh, being a, uh, fourth amendment protected or, uh, uh, you know, unreasonable search. [36:39.690 --> 36:43.610] If, um, if, um, if, um, if that is, uh, requested, I am understanding the law. [36:43.750 --> 36:43.810] Right. [36:44.490 --> 36:45.510] Um, yeah. [36:45.610 --> 36:49.730] So, so that's, uh, uh, decision that came down. [36:49.730 --> 36:58.430] And, uh, I want to say 2020, like one or something, or maybe before that, but, um, that was one good decision. [36:58.430 --> 37:05.290] Um, um, um, um, anyway, um, yeah, uh, stage right. [37:05.630 --> 37:05.910] Mike. [37:05.910 --> 37:05.950] Mike. [37:10.180 --> 37:10.660] Mike. [37:10.660 --> 37:10.680] Hello. [37:11.100 --> 37:15.800] Thank you for, uh, coming to this panel and thank you for all the work on the EF that you've been doing. [37:16.420 --> 37:22.740] I was wondering if you could speak to the Internet archive, um, case if you've been, um, following that. [37:22.900 --> 37:34.200] I don't know any updates, uh, as of recent, and if you can also speak to some of the ramifications that could come of that case and what resources we might have as people who are users of that, uh, service. [37:36.020 --> 37:36.500] Yeah. [37:36.500 --> 37:40.940] Um, so the Internet archive case, I, I worked on that one. [37:41.220 --> 37:53.760] Um, for those who don't know, this was a case filed by a number of book publishers against the Internet archive over their controlled digital lending program. [37:54.400 --> 38:09.000] Um, where essentially what they did was get physical copies of books, make high quality scans of them, put the physical copies in storage or no one had access to them. [38:09.280 --> 38:30.980] And then let people check out the digital copies, just like you would from a library checking out eBooks, um, maintaining that ratio of, okay, only like, if we have three copies of the book, only three people can have it checked out at a time. [38:31.480 --> 38:35.400] So trying to maintain that same own to loan ratio. [38:36.060 --> 38:41.120] Um, and that was, that was not one of our wins, sadly. [38:41.120 --> 38:54.100] Um, you know, so it was a copyright lawsuit saying, you know, this is infringement is we didn't give permission to make these copies, uh, or distribute them or display them to people. [38:54.280 --> 38:58.340] And something called first sale doctrine does not apply. [38:58.340 --> 39:07.560] So first sale doctrine says essentially when you buy a physical book, that's yours now, right? [39:07.560 --> 39:11.880] If you finish the book and you don't want it anymore, you can sell it to someone. [39:11.920 --> 39:13.460] You can lend it to someone. [39:13.840 --> 39:17.840] You can basically do what you want with that book. [39:17.840 --> 39:24.740] As long as it's not, you know, you can't like make a movie out of it, but the actual physical copy of the book is yours. [39:25.960 --> 39:37.760] And with digital copies, uh, courts have said it doesn't work that way because how do we know you're not making extra copies basically. [39:37.760 --> 39:42.140] And that's just not how the first sale doctrine was written. [39:42.480 --> 40:07.200] Uh, so this is, this is one of the really frustrating things about copyright in the digital age is it's, it's become a very convenient way, uh, for publishers to improve their profit margins at the expense of everyone else who, you know, would like to be able to like buy used textbooks. [40:07.560 --> 40:13.820] But if you're moving to digital only textbooks, well, the used bookstore isn't going to help you anymore. [40:13.820 --> 40:23.760] Um, they are going to get the full benefit of every single person who needs access to that textbook. [40:24.360 --> 40:31.360] Um, and so we did, we, we lost in the Internet archive case. [40:31.620 --> 40:35.380] Uh, the court said it was not fair use. [40:35.680 --> 40:46.500] Uh, and, and so because of that, the Internet archive had to, you know, shut down that program, at least as applies to in copyright books. [40:47.160 --> 40:54.440] Um, I mean, in terms of ramifications, I think it, it's kind of what I was just talking about, right? [40:54.600 --> 41:03.060] So it reaffirms this idea of digital books or any digital media, really. [41:03.280 --> 41:07.180] Like you also can buy used vinyl, use CDs. [41:07.180 --> 41:10.080] You can't buy used MP3s, right? [41:10.320 --> 41:12.250] Uh, you can buy used DVDs. [41:13.060 --> 41:17.080] You can't buy, you know, use streaming video. [41:17.480 --> 41:39.280] Uh, so I think by, by reinforcing that divide, um, I, that, that's going to affect how our, you know, our media markets are structured and how, how we can engage, uh, with media as, as things go forward. [41:39.660 --> 41:46.640] Um, so it feels like this is one that kind of needs a legislative solution. [41:47.600 --> 41:48.540] Most likely. [41:48.700 --> 41:53.920] I mean, again, the thing with our assistant, like the, the Supreme Court hasn't weighed in on this. [41:53.920 --> 42:05.260] So courts in other jurisdictions can disagree, but you know, this was like such a, a huge undertaking, uh, dealing with this lawsuit. [42:05.260 --> 42:10.340] And it was such a huge undertaking for the Internet archive to set up this program. [42:10.520 --> 42:10.920] Right. [42:11.120 --> 42:15.060] And then to have that, you know, be essentially wiped out. [42:15.340 --> 42:23.480] Um, you know, it's, it's asking a lot for someone else to hope that they would end up in a different jurisdiction. [42:23.480 --> 42:26.500] Uh, that, that would have a better outcome. [42:28.220 --> 42:50.660] As an interesting follow-up to that, um, a separate case, um, discussed on 404 Media's podcast, uh, not too long ago, uh, was kind of raising this issue of where publishers had sued the large, large language models, um, for, in, for basically like pirating millions of copies of books, [42:50.820 --> 42:56.480] and then, uh, and mass ingesting those books into the large language models. [42:56.800 --> 43:14.400] Um, and the courts decided in that particular case, I, the case name isn't coming up to me right now, but, um, it's, uh, that the pirating of the content was illegal, but the ingestion of that content, uh, uh, Intel large language models, uh, wasn't. [43:14.740 --> 43:19.460] So kind of interesting, you know, implications, but, um, but, uh, it's a separate case. [43:20.660 --> 43:21.560] Um, yeah. [43:21.800 --> 43:22.280] Stage right. [43:23.780 --> 43:24.120] Stage right. [43:24.620 --> 43:26.800] Hey, thanks for, uh, thanks for being here. [43:27.240 --> 43:29.900] Um, everyone remembers that guy, James Comey, right? [43:29.980 --> 43:31.380] And what was his big thing, right? [43:31.780 --> 43:36.380] Uh, basically backdooring encryption, um, back in the day. [43:36.380 --> 43:49.420] Well, now in the PQC world, the quantum encryption world, and we're, we're now reviewing, uh, new PQC, uh, or quantum, uh, uh, protected, uh, encryption algorithms. [43:50.560 --> 43:52.900] Why is this not a concern anymore? [43:52.900 --> 43:54.380] Or is it a concern? [43:55.300 --> 44:01.180] I think, so my knowledge of quantum cryptography is pretty limited. [44:01.520 --> 44:26.240] But, uh, as I understand it, I think it's Schor's algorithm that, uh, uh, basically makes a brute force attack against a, uh, a symmetric, uh, cipher Over to the order of a square root of what the bit size is. [44:26.460 --> 44:34.660] So if it was like AES 128, it would be equivalent of AES 64 at that point in post-quantum. [44:36.680 --> 44:39.380] I know that's like a gross simplification. [44:39.380 --> 44:48.140] There are other various, you know, like quantum-resistant algorithms that have been developed. [44:48.140 --> 44:52.400] And I think that it is a concern still. [44:52.720 --> 45:09.080] I think that it's seemingly always on the horizon, but we have seen some practical examples of quantum computing milestones being achieved. [45:09.880 --> 45:32.940] So I think that it is... and I think that traditional encryption algorithms do certainly still have a place if, you know, and also post-quantum cryptography, like quantum-resistant cryptography is always, you know, has always kind of emerging protections. [45:33.700 --> 45:42.560] So I think that that is definitely still a relevant topic and relevant protection. [45:42.720 --> 45:51.120] I think it's more relevant because if you take away the brute force aspect, right, that goes away, then really the only way of getting in is having a backdoor. [45:52.300 --> 45:58.680] Yeah, or some breakthrough cryptographic analysis that will discover the role really in like a algorithm. [46:03.280 --> 46:04.940] Does this work? [46:04.940 --> 46:05.780] Yes. [46:06.320 --> 46:19.540] Most people are very familiar, most people here are very familiar with the fact that a lot of environmental climate data, consumer data, financial data disclosures have been eliminated on federal government websites. [46:20.040 --> 46:30.840] And some people may even be familiar with the fact that the freedom of information offices in most agencies have been decimated and in some cases eliminated, supposedly folded into other offices. [46:31.140 --> 46:33.580] But those requests are just basically been abandoned. [46:34.140 --> 46:48.300] And, but what very few people seem to be aware of in the last couple of months, which I've noticed is that the freedom of information reading rooms, the electronic reading rooms, and which are broader than just FOIA, there are all sorts of data that the agencies have put in there. [46:48.460 --> 46:57.400] This was an agreement over decades that they would close the statutorily required physical reading rooms, which makes sense, and put them all up online. [46:57.400 --> 46:59.520] And now they've been wiping those out. [46:59.660 --> 47:01.640] In some agencies, they've been eliminating them. [47:01.860 --> 47:10.680] Like the office of the director of national intelligence had a very large FOIA reading room, and they just eliminated it in the last three or four weeks. [47:11.400 --> 47:14.760] Now, some of these things you can go back and see on the Internet archive. [47:15.460 --> 47:19.360] Others, it's not so easy because they're, they were dynamic sites. [47:20.200 --> 47:23.480] But, and I know this is not, you guys do wonderful work, wonderful work. [47:23.560 --> 47:35.440] And this is not your primary turf area, but I was going to ask if you're a lot of the agent, a lot of the organizations that did protect freedom of information have sort of gone by the wayside. [47:35.580 --> 47:39.180] It was an old guard and the generations have changed and the organizations have gone out. [47:39.340 --> 47:42.540] You guys are, are still standing, but a lot of the others are not. [47:42.620 --> 47:58.080] And I was wondering whether there might be more of a role for FOIA protection because of its criticality now, more than ever in an electronic FOIA world, that EFF may take a more of an increased role in freedom of information. [47:58.260 --> 47:59.820] And I know that you have done a lot already. [47:59.960 --> 48:04.680] It's not saying you're not, but I'm just saying maybe it's more, it's time to look at it a little more closely. [48:05.840 --> 48:14.240] Yeah, we definitely, we do have some real FOIA gurus who just don't happen to be on this panel. [48:15.620 --> 48:25.480] And I do think that for whatever reason, uh, our FOIA work might tend to be less, some of our less visible work. [48:25.620 --> 48:35.060] I don't know if it's just like less flashy, uh, than some of our work, but we, we definitely appreciate the importance of it. [48:35.180 --> 48:46.160] And a lot of it, you know, we do like FOIA cases, but also use FOIA ourselves very liberally, um, to get information. [48:46.520 --> 48:51.840] So, you know, I'm, I'm not one of the folks that does the most FOIA work. [48:52.040 --> 49:00.560] Um, I suspect that probably this is on the radar of our folks who do, but I will make sure that it is. [49:00.660 --> 49:04.780] Who are the key people who do FOIA at EFF and work on those issues? [49:05.560 --> 49:11.100] Uh, Aaron Mackey is our transparency legal director. [49:11.600 --> 49:16.420] Um, so he's a lawyer who does the most of it. [49:16.560 --> 49:27.490] Um, we also have attorney, David Sobel, who is not like a, a full EFF employee, but just specifically works with us on FOIA cases. [49:27.710 --> 49:40.150] Um, and then on our research and investigations teams, uh, we have Dave Moss and Beryl Lipton are like the FOIA whisperers. [49:40.510 --> 49:43.910] Um, yeah, they're, they're true experts. [49:44.430 --> 49:47.390] And they, every year, write the FOILies, right? [49:47.570 --> 49:55.330] Which are like, uh, uh, a joke, uh, awards list of the worst, uh, responses to FOIA requests. [49:55.570 --> 49:57.850] And they're, they're comically bad. [50:01.430 --> 50:01.990] Yeah. [50:02.170 --> 50:10.110] And then, uh, there are other like sunshine, uh, laws that are applicable in various states as well. [50:10.390 --> 50:23.550] Um, um, we use a service called MuckRock, um, that, uh, does a lot of great state and federal privacy, uh, transparency kind of requests. [50:24.610 --> 50:25.590] Um, yeah. [50:25.870 --> 50:26.570] On stage left. [50:28.470 --> 50:30.890] Uh, maybe a bit non sequitur. [50:30.990 --> 50:35.930] I wanted to follow up on yesterday's Prezi with, uh, uh, uh, location tracking. [50:36.550 --> 50:49.230] Um, uh, you talked about the, uh, sort of, um, the efficacy of, uh, you know, people's individual OPSEC. [50:49.590 --> 51:07.450] But, um, I was actually wondering, uh, if you were to take that a step further, are there any, uh, projects of trying to inject bad data into the system to devalue the, you know, the location data in the first place? [51:07.690 --> 51:15.270] Like I'm thinking of the guy who walks around on his street with a wagon full of burner phones to keep traffic away. [51:16.250 --> 51:24.810] Is there a, I don't know, an app I can download from F droid to, you know, screw with it. [51:26.110 --> 51:33.550] I'm not familiar with like a particular project like that targeting location data brokers. [51:33.730 --> 51:36.430] I think that would be something that's really cool. [51:36.590 --> 51:45.170] I do think that, um, the risk of that is that, you know, it could devalue a lot of people, a lot of data in a good way. [51:45.370 --> 52:06.970] Um, but for maybe like, um, for individual cases where a police is using a location data broker to track down an individual and knows that person's, uh, can acquire that person's device ID and search for their location data among data brokers. [52:07.250 --> 52:16.750] Like I don't necessarily think a project like that would fuzz or obscure, like an individual's data that is already present in the data set. [52:16.890 --> 52:22.830] Um, unless it were a really wide ranging project, but I would, I would love to see attempts at that. [52:23.010 --> 52:45.230] It's hard to quantify, I think, success when, uh, I think after getting a lot of bad press, data brokers and location data brokers, uh, are more hesitant to like, you know, to, to give anyone access to their data. [52:45.350 --> 52:49.930] Like obviously their business model is selling data and they want to make as much money as possible. [52:50.070 --> 52:55.710] So they're not, they're not necessarily vetting their, their buyers, um, to keep us safe. [52:55.770 --> 53:02.610] Um, but they're, it's a lot harder as a researcher or a journalist to get access to like data brokers, data sets. [53:02.690 --> 53:08.490] And it used to be, I think more of them used to give free demos and free data sets. [53:08.590 --> 53:16.890] Um, so I think that is also a challenge in developing that sort of tool is like having any sense of how effective it is. [53:17.050 --> 53:35.890] Um, because that would require maybe tricking, having a lot of money and tricking a location data broker into giving you access to their data set, even though like you might have privacy advocate or researcher, um, in your, like associated with your profile. [53:36.710 --> 53:37.210] Yeah. [53:37.370 --> 53:43.650] Like you mean like how many IMEI's does it take to turn the yellow line into the red line on my traffic map? [53:43.650 --> 53:44.370] Yeah. [53:44.650 --> 53:45.030] Yeah. [53:45.250 --> 53:45.710] Yeah. [53:45.910 --> 53:46.630] I think so. [53:46.770 --> 54:03.590] I, I mean, I haven't, I, I think, I think that would be a really cool project idea and something that like people in this, and I would be excited to see hackers and researchers working on, um, I... Quick review of stage direction. [54:03.870 --> 54:08.590] It's you as the talent, subjective, stage left, stage right. [54:09.350 --> 54:11.810] Wait, uh, stage left, stage right, right? [54:12.090 --> 54:13.650] No, stage right, stage left. [54:13.870 --> 54:14.230] Oh, it's for us. [54:14.450 --> 54:16.170] It's like, it's like a doctor. [54:16.470 --> 54:16.530] Oh, okay. [54:16.830 --> 54:21.230] Like from this patient's, patient's subjective left eye, you're the talent, subjective. [54:21.410 --> 54:21.810] Okay. [54:22.210 --> 54:22.450] Okay. [54:22.450 --> 54:22.590] Yeah. [54:22.870 --> 54:26.150] For us on the house side, it would be house left, house right. [54:26.190 --> 54:26.990] Why don't we just point? [54:27.170 --> 54:27.230] Yeah. [54:27.570 --> 54:29.390] I was in stage crew in high school. [54:29.590 --> 54:30.370] I should know this. [54:31.210 --> 54:32.490] That was a long time ago, Bill. [54:36.090 --> 54:37.190] Stage, stage left. [54:38.630 --> 54:39.270] Thank you. [54:39.470 --> 54:41.110] Um, and for getting that correct. [54:41.410 --> 54:43.210] Um, yeah. [54:43.410 --> 54:45.690] Um, so you briefly touched on this earlier. [54:45.990 --> 54:54.990] Uh, one of the four horsemen of, uh, scaring people on the Internet, uh, child pornography, uh, being a tool that, uh, legislators use to take away rights. [54:55.230 --> 55:05.390] So right now in Europe, if I understand correctly, um, we have, uh, legislation going through in the EU that is designed to, uh, do away with encryption and chats. [55:05.790 --> 55:07.830] Um, I'm not well read on it. [55:07.970 --> 55:09.810] I'm an American citizen. [55:09.810 --> 55:15.770] I don't, you know, I, I don't want this to happen though, because I feel like, um, there could be a domino effect. [55:16.030 --> 55:18.310] And also I don't want Europeans to lose their rights. [55:18.810 --> 55:23.870] Um, what are your thoughts on it and how do you feel the tide is, uh, going right now? [55:23.990 --> 55:26.710] Cause it seems like this time it's going to pass. [55:26.830 --> 55:41.770] And then the second follow-up to that is, um, how do we defend ourselves when legislators can continually bring these things, uh, you know, up for a vote and like every time we have to defeat it and, and we don't get a break or you don't get a break. [55:41.990 --> 55:44.530] Um, you know, that's, it kind of sucks. [55:44.690 --> 55:47.870] So anyway, um, yeah, thanks. [55:48.750 --> 55:51.310] We're going to keep on fighting it every time it comes up. [55:51.530 --> 55:59.510] Um, this is something that perennially comes up, uh, Hey, the, uh, encryption is bad. [55:59.830 --> 56:08.930] It lets us, it doesn't let us do our investigatory work or, um, you know, it protects, uh, child pornographers or, you know, whatnot. [56:09.190 --> 56:12.730] And these arguments have been fought against time and time again. [56:13.130 --> 56:29.850] Uh, you know, first on the level of, you know, the keys under doormats, um, paper where the authors demonstrated there is no way to provide a golden key that is just for the good guys and not for your, you know, hacker down the street. [56:30.070 --> 56:33.850] Um, and we'll compromise the communication of everyone. [56:34.170 --> 56:43.190] So, and then, you know, uh, more lately it's been, uh, trying to, um, figure out ways in which classes of content can be flagged. [56:43.770 --> 56:51.890] Um, and that fundamentally also, uh, attacks the underlying cryptography, um, that that's being used. [56:52.070 --> 57:04.750] So, and you know, even, uh, technologists are like, well, maybe there's this one way which I can do it that, that, um, and it never pans out, like because of the fundamentals of how cryptography works. [57:05.450 --> 57:15.710] So, this is a fight that comes up perennially and we will keep on making sure that cryptography is protected as we always have. [57:15.930 --> 57:36.010] Um, you know, both on the legal side and, um, you know, promoting technologies which have strong encryption and on the education side with SSD saying, like telling people that, Hey, if you use signal, then there are strong defaults at play versus, yeah, [57:36.150 --> 57:49.030] yeah, there are, there is good encryption in WhatsApp, but some of the loopholes that are at play are concerning, you know, kind of making sure that that nuance is communicated in a way that doesn't put people in danger. [57:49.290 --> 57:58.090] Um, so we fight in the courts, we fight as technologists and we fight as activists, uh, to protect those, those, you know, privacy and, and, and encryption, uh, there. [57:59.470 --> 58:20.090] Also cryptography is not my issue area, but I feel like, um, salt typhoon or like, I feel like there are, I think some of the compelling, um, I think that the, there are the examples of encryption backdoors being like abused by hacker. [58:20.290 --> 58:34.910] Yeah, anyone, but like the, I think there are high profile examples that, uh, we can try to more loudly communicate about how encryption backdoors threaten national security and the sorts of issues that legislators might find more compelling. [58:35.230 --> 58:46.770] Um, I think that hopefully, like examples, uh, like salt typhoon will keep some of these bad bills at bay. [58:46.930 --> 58:54.790] I don't know where the tide is turning, but I thought that was like, yeah, the context being that salt typhoon, uh, was, I think that's salty typhoon. [58:54.930 --> 59:09.010] I'm not sure if there's something else, uh, that's, but like, um, it was where, uh, there was, um, a compromise of communications that were between individuals, uh, in the U.S. [59:09.230 --> 59:24.070] Um, but I was using the CALEA, uh, communications assistance for law enforcement loopholes built into the law that allows law enforcement to have access to unencrypted communications between people. [59:24.750 --> 59:33.630] Um, and so using that, uh, surveillance system that's built into unencrypted communications in the U.S. [59:34.170 --> 59:43.830] Uh, well, lo and behold, uh, you know, Chinese hackers were able to exploit that and, uh, gain widespread access to, uh, our communications. [59:43.990 --> 59:45.430] And this is what happens. [59:45.450 --> 59:57.090] Like, look, this is what fucking happens when like you build in these, uh, uh, you know, surveillance technologies, it's not going to be just who you want it to have access to. [59:57.370 --> 01:00:00.070] Um, it's going to be nefarious. [01:00:00.310 --> 01:00:11.610] Uh, even if you believe that law enforcement in the U.S. is not nefarious, um, there's, uh, going to be other people that you do consider nefarious that are going to be able to get in. [01:00:11.750 --> 01:00:17.010] Uh, I'll just tack on, I think ours also had some, but like, I'll just tack on that. [01:00:17.130 --> 01:00:35.290] I think, um, education is incredibly important to the press and to, uh, to legislators offices, because it is very easy for the fear mongers and the, the, the lobbyists from other sides to come in with misinformation or no information about how the tech works and how it, [01:00:35.450 --> 01:00:38.670] you know, who it really affects the effects and all of the different effects it can have. [01:00:39.010 --> 01:00:46.670] Um, but making sure that local reporters, uh, and local, uh, uh, congressional or, or legislative offices understand these things. [01:00:47.030 --> 01:00:51.010] Um, it's really, it, it's more than just EFF can do, right? [01:00:51.110 --> 01:00:57.990] It requires local groups across the country and local activists across the country to be informing their own legislators and their own press and reporters. [01:00:58.230 --> 01:01:13.210] Um, so if you see somebody who's new on the tech beat, if you see a new, uh, member of your state legislature or, or, uh, Congress, uh, you know, consider trying to inform that office, um, consider trying to inform that reporter, uh, at the front end, [01:01:13.210 --> 01:01:16.670] um, and, you know, letting them understand that the issues a little bit better. [01:01:19.570 --> 01:01:38.830] I was just going to say in terms of EFF being able to keep up and take breaks, y'all can visit our table and donate to EFF so we can afford more people working on these issues or go to EFF.org slash donate stage. [01:01:39.390 --> 01:01:39.450] Right. [01:01:40.450 --> 01:01:41.050] Thank you. [01:01:41.210 --> 01:01:43.910] Uh, thank you all for being here and thanks for everything that you do. [01:01:44.050 --> 01:01:54.870] Uh, my questions are about the web platform and, uh, sort of the chaos going around there now, uh, two big companies that own the most prevalent browsers. [01:01:55.250 --> 01:02:02.050] Uh, Google, uh, has been rolling out, uh, maybe they're going to, uh, stop third-party tracking cookies. [01:02:02.190 --> 01:02:10.290] Maybe they're not, um, manifest v3 is going to shut down a lot of tracking blocking technology, but when are they gonna roll it out? [01:02:10.470 --> 01:02:12.930] And then maybe they'll have to sell Chrome anyway. [01:02:13.530 --> 01:02:19.110] Uh, meanwhile, Apple is, uh, they lost a case that says you need to allow real browsers. [01:02:19.310 --> 01:02:24.890] And then they're maliciously complying with that, uh, by kind of not really allowing it to happen. [01:02:25.330 --> 01:02:28.510] Uh, and who knows what's going on with Mozilla. [01:02:28.830 --> 01:02:32.710] So there is a question about the future of browser diversity and user choice. [01:02:32.890 --> 01:02:35.650] Uh, so what are y'all tracking in that? [01:02:35.790 --> 01:02:38.650] Uh, what do you have cooking and what should we be looking out for? [01:02:38.870 --> 01:02:39.170] Thanks. [01:02:40.490 --> 01:02:41.010] Yeah. [01:02:41.490 --> 01:02:51.790] Um, I'm also very interested to see what happens with a potential divestiture of Chrome from Google. [01:02:52.190 --> 01:03:10.370] Um, I'm not necessarily optimistic that Chrome wouldn't be sold to say an AI company that's gonna, um, make it worse or, um, or I'm, you know, I'm, I'm, I'm, I don't know what's going to happen there, but I'm very eagerly watching the space. [01:03:10.590 --> 01:03:17.890] Um, I think that that big picture, like Chrome, Chrome is the most popular browser. [01:03:17.890 --> 01:03:20.650] Uh, it's also owned by an advertising company. [01:03:20.650 --> 01:03:26.130] So it has the least, um, privacy protections built into it. [01:03:26.250 --> 01:03:33.410] You can customize it with extensions, um, tracker blockers, like privacy badger that offer some improvement. [01:03:33.410 --> 01:03:44.990] Um, and you mentioned like the manifest v3 changes, like Chrome, Chrome has already forced all extensions to use this new MV3 system. [01:03:44.990 --> 01:03:49.750] It was a lot of wasted work. [01:03:49.950 --> 01:03:57.050] Um, most ad blocking and tracker blocking extensions have evolved, um, and so that they could stay on Chrome. [01:03:57.270 --> 01:04:16.410] Um, but the APIs available to extensions for blocking requests are worse, um, and it, it leads to a lot of invisible maintenance work, um, and annoying edge case bugs in terms of Chrome and third-party cookies. [01:04:16.770 --> 01:04:30.170] Um, I, I think that third-party cookies are, I think they're here to stay on Chrome, even though they promised they were going away for a long time because of the competition, um, concerns. [01:04:30.610 --> 01:04:30.930] Just kidding. [01:04:31.110 --> 01:04:31.290] Yeah. [01:04:31.890 --> 01:04:52.430] I think, um, oh man, I have a lot of thoughts about browsers, but I guess I think that like switching to Firefox or Brave or like a browser that has more, uh, protections by default is an easy way to have a, a big boost in privacy while you're browsing online. [01:04:52.570 --> 01:05:07.650] I think in terms of like big picture threats to browser choice, I think it's important that people keep, um, supporting alternative browsers and not defaulting to Chrome and also like privacy Badger's a team sport. [01:05:07.890 --> 01:05:15.950] So spreading what you know about, uh, online tracking and safety to people who like don't follow tech. [01:05:16.230 --> 01:05:27.550] Um, I think that like what browser should I use is one of the most common questions I get to like older family members who I tell I like work on privacy issues. [01:05:27.790 --> 01:05:38.750] Um, and I think it's easy for people who aren't, uh, following this issue closely to just, uh, install, install a new browser and enjoy more protections by default. [01:05:38.890 --> 01:05:44.650] That's often a little easier than telling them about a extension that they should add to their browser. [01:05:44.810 --> 01:05:49.830] I think like maybe, maybe Bill, do you want to talk about like finger printing? [01:05:50.250 --> 01:06:10.650] Well, maybe that's outside the scope of your question, but I think that, um, Brave does some cool things to fight, um, fingerprinting, which is a method that ad tech companies use to track and identify people in the absence of third-party cookies and other identifiers. [01:06:11.130 --> 01:06:11.230] Yeah. [01:06:11.370 --> 01:06:33.750] And the technique that we discovered in the original panopticlic research, uh, we launched a site in 2010, uh, that was called panopticlic, which asked for people to volunteer their browsers and to take a test, um, to determine how trackable their browsers were from the unique characteristics that [01:06:33.750 --> 01:06:35.790] your browsers are leaving behind. [01:06:36.250 --> 01:06:59.430] Um, you know, for instance, a combination of your language and your, um, uh, web GL, uh, fingerprint and, uh, the content accepted in your browser and your user agent can be uniquely, uh, identifying your browser. [01:06:59.630 --> 01:07:07.930] We found it for, I think it was, uh, 85% of browsers were uniquely identified in initial tests. [01:07:08.110 --> 01:07:18.630] If you had, um, a, uh, browser plugins installed at the time, which were popular in 2010, um, like 95, that number was pushed up to 95. [01:07:19.290 --> 01:07:40.430] Um, so these unique characteristics when combined can act as surrogate cookies, basically, um, subverting the normal mechanisms and built into the browser to, um, for you to clear your cookies, for instance, um, if they are both unique enough, which most were and persistent enough, [01:07:40.430 --> 01:07:54.150] um, so that the browser fingerprint that you, that is derived from the characteristics, isn't, you know, constantly changing, um, then that could be used as a way to track browsers. [01:07:55.070 --> 01:08:07.390] And, you know, 15 years on from that original panopticlic test, we still have, uh, that, uh, in the form of cover your tracks, um, cover your tracks is the new branding for panopticlic. [01:08:07.650 --> 01:08:11.950] Um, you can go to coveryourtracks.eff.org to test your own browser. [01:08:12.190 --> 01:08:31.250] Um, but we have found, um, that in recent years, advertisers are using browser fingerprints in order to uniquely track, uh, users without when they are trying to assert their privacy by, say, clearing cookies. [01:08:31.530 --> 01:08:34.590] Um, so we've seen that technique in the wild. [01:08:34.910 --> 01:08:44.430] Um, and it's, it's a big danger, and we're, we're working to, um, to raise awareness on this issue and also fight back against it, so. [01:08:44.960 --> 01:08:58.610] And, sorry, one last thing on, I feel like fingerprinting is a good example of why, like, um, um, browse, like, you know, browsers should do more to protect you from online tracking by default. [01:08:58.790 --> 01:09:02.750] Like, browsers should be on the user's side, not the advertisers and data brokers side. [01:09:02.890 --> 01:09:09.790] Um, but at the same time, like, technical improvements to browsers aren't gonna fix our online privacy problems. [01:09:09.790 --> 01:09:23.050] Uh, every, you know, when Safari and Firefox, uh, did get rid of third-party cookies, um, advertisers and online tracking companies adapted. [01:09:23.050 --> 01:09:31.730] They still had the exact same financial incentives to collect your data, and so they adopted, um, sneakier ways to identify you. [01:09:31.910 --> 01:09:52.130] They relied more on fingerprinting, and they also, uh, relied on identity resolution data brokers that, um, you know, when you enter your email into a site to access it, they might be converting your, hashing your email and converting it into some proprietary identifier that is, [01:09:52.190 --> 01:10:01.430] uh, shared, shared between lots of different companies, and that is a way to track you across the web, even without third-party cookies. [01:10:01.550 --> 01:10:13.430] So I think that's why, like, fundamentally, we need strong privacy legislation that changes the incentives shaping the technologies we use, and not just, like, incremental browser improvements. [01:10:14.530 --> 01:10:22.270] I can't help but think about the, uh, advertisements by DuckDuckGo and only find out that Microsoft partnered with them to gather the data. [01:10:22.450 --> 01:10:24.590] Uh, I have questions from the, uh, Matrix chat. [01:10:24.750 --> 01:10:26.390] I, I'm not gonna ask all of them. [01:10:26.830 --> 01:10:30.630] Uh, there's some that are asking you to, uh, work with them on different groups. [01:10:30.810 --> 01:10:32.830] I'll leave that to you to do offline. [01:10:33.090 --> 01:10:34.890] Um, but I do have a question here. [01:10:35.150 --> 01:10:38.390] Um, what protections or recourse do I have as a foreigner? [01:10:38.570 --> 01:10:39.110] Not me. [01:10:39.530 --> 01:10:42.570] Um, if I'm detained in an airport when entering the U.S. [01:10:42.650 --> 01:10:45.550] and what recommendations do you have for visitors to the U.S. [01:10:45.670 --> 01:10:49.190] to protect themselves from invasive search searches and device seizure? [01:10:51.290 --> 01:10:57.990] This one, I'm afraid, is more a specialty of other colleagues on the legal team. [01:10:58.310 --> 01:11:11.950] Um, in terms of general advice, I know that we do have, I, I think, guides on our website for, um, you know, device privacy at the border. [01:11:12.470 --> 01:11:15.530] Um, so I would encourage checking that out. [01:11:15.690 --> 01:11:20.730] It looks like our border pocket guide is still up to date. [01:11:21.250 --> 01:11:27.530] Um, we are working to update our border guide in general, which is a longer guide. [01:11:27.730 --> 01:11:31.210] Uh, general principles still apply. [01:11:31.610 --> 01:11:45.010] Um, data minimization, uh, not carrying with you what you don't want divulged at the border, um, is a good protection against getting it divulged, right? [01:11:45.290 --> 01:11:45.930] Basically burner everything. [01:11:46.250 --> 01:11:58.790] Well, yeah, I mean, but also it's, uh, a little bit of a more complicated calculus because we know that for instance, celebrate devices and great key devices are used, uh, in border contexts. [01:11:59.330 --> 01:12:28.110] And so what we know from revelations, uh, uh, in tech media are that if you have a relatively updated, uh, Android or iOS version or relatively updated Android or iOS phone, uh, combination, then you are much less likely to have that device be vulnerable to unlocking and as a result, [01:12:28.550 --> 01:12:29.350] uh, physical imaging. [01:12:29.790 --> 01:12:47.610] And so, um, um, generally it's good practice to have a really new, a new updated flagship Android or iOS device that has those updated, uh, that, uh, security updates applied. [01:12:48.110 --> 01:13:06.050] Um, so yeah, whether you want to bring that with all your data or just, you're going on, you say you're going on vacation and you don't need all of your signal groups to be carried with you across a border context, then you can bring a separate device, [01:13:06.130 --> 01:13:20.310] um, that still has, you know, a few contacts that you need to get in touch with in case of emergency, but doesn't have like, uh, your work product and all your contacts and your signal communications on it. [01:13:20.630 --> 01:13:25.570] Um, that might be a good, uh, a good thing to keep in mind. [01:13:25.790 --> 01:13:27.610] Data minimization and incursion. [01:13:27.830 --> 01:13:47.510] And, uh, we have, if you look up EFF digital privacy at the U.S. border, protecting the data on your devices, we have a long version and a short version of our technical and I believe legal, um, advice when crossing the border with devices. [01:13:47.910 --> 01:13:52.010] Um, we, it's translated into Spanish and Arabic. [01:13:52.230 --> 01:14:01.830] Um, and I think we also have specific advice on our website for journalists crossing the U.S.-Mexico border. [01:14:01.830 --> 01:14:02.530] Yeah. [01:14:02.790 --> 01:14:31.010] So, um, our, uh, uh, head of investigations, uh, Dave Moss at, uh, worked with freedom of the press foundation, um, and, um, uh, Martin Shelton to come up with a presentation for, uh, J school, journalism school, professors to teach students of journalism, [01:14:31.010 --> 01:14:43.510] uh, what to do in border contacts, especially if you're, they're going across the U.S.-Mexico border, um, and, uh, have, you know, journalism material, uh, in their possession and those different considerations. [01:14:43.850 --> 01:14:46.570] So yeah, that's, uh, that's a really good thing. [01:14:46.690 --> 01:14:47.990] I, those people would check out. [01:14:48.350 --> 01:14:59.170] Uh, I'll just also note that, um, uh, there are a lot of legal gray areas, both for citizens and non-citizens in entry and, and, uh, exiting the United States. [01:14:59.450 --> 01:15:18.690] Um, but, uh, the, uh, the Eastern, uh, district court, I think in, in New York, um, is a little bit, uh, uh, made a decision that, uh, that the search and seizure of devices of, uh, I believe it was citizens, um, last year, uh, would require probable cause. [01:15:18.830 --> 01:15:20.070] And so it's very jurisdictional. [01:15:20.370 --> 01:15:24.490] Um, very few, that's, that's almost none of the country as you can tell. [01:15:24.670 --> 01:15:28.370] Uh, but it also means that I prefer to fly out of New York city, not out of Newark. [01:15:28.690 --> 01:15:36.530] Um, and, uh, so, uh, that's just kind of like, you know, the, the courts are deciding some of these things. [01:15:36.670 --> 01:15:43.370] It's, it's very, very living in the law and, uh, very, very, uh, subject to change, um, sometime soon. [01:15:43.610 --> 01:15:43.690] So [01:15:47.310 --> 01:15:48.070] stage left. [01:15:49.970 --> 01:15:50.210] Hey guys. [01:15:50.490 --> 01:15:51.170] Thank you for being here. [01:15:51.570 --> 01:15:52.450] Love all the work you did. [01:15:53.330 --> 01:15:55.250] Um, just donated to you guys upstairs. [01:15:56.330 --> 01:16:01.110] I put all the information in the entirely optional information fields. [01:16:01.270 --> 01:16:10.030] And it made me think because I said, you know, you don't have to fill any of this out, but I'm proud to support you guys, you know, happy to have my name in this database. [01:16:10.030 --> 01:16:16.670] And then I was thinking about DOGE and like how retaliatory our current administration is against groups like yours. [01:16:16.790 --> 01:16:21.170] Have you guys seen any efforts by the current administration to retaliate against the EFF? [01:16:24.750 --> 01:16:31.890] I don't think we have so far, but it is very much something that you guys think about. [01:16:32.230 --> 01:16:32.510] Yeah. [01:16:32.910 --> 01:16:37.910] Um, and honestly, I mean, this isn't the first time we've had to think about it. [01:16:37.950 --> 01:16:53.030] Also, including our, um, lawsuit, uh, against NSO group was another one where we thought like, okay, we need to lock our OPSEC down, uh, particularly well here. [01:16:53.230 --> 01:17:01.950] Um, you know, make sure our people aren't getting doxxed, uh, have contingency plans, but... Yeah. [01:17:02.150 --> 01:17:19.630] I mean, also one of the reasons why we're not as affected as a lot of nonprofits are in our area, um, and, and other areas that are just protecting rights in general is that we don't accept federal money and or government money basically. [01:17:19.970 --> 01:17:32.770] And so we aren't as affected by cuts to, uh, social good programs, uh, as you know, like other organizations are. [01:17:33.530 --> 01:17:37.950] Um, a lot of the local groups that we work with are certainly paying attention to this as well. [01:17:38.070 --> 01:17:40.070] Some of them are incorporated and some of them are not. [01:17:40.270 --> 01:17:50.350] Um, obviously, uh, you know, this administration or any administration could certainly go after law firms as they have in executive orders, um, can go after nonprofits. [01:17:50.350 --> 01:18:04.330] And so a lot of groups are trying to play it a lot more safe with, with regard to lobbying, um, rules and a lot of other kinds of rules and disclosure, as well as, uh, pulling back on the data collection that they have of their own members or, uh, or, [01:18:04.590 --> 01:18:09.450] you know, retention of that data because, um, just in case, you know, so. [01:18:09.570 --> 01:18:09.630] Absolutely. [01:18:10.050 --> 01:18:18.990] Also, um, this might be a little tangential, but like EFF actually takes its privacy values seriously internally too. [01:18:19.270 --> 01:18:33.130] And so we, I know from our like development and fundraising team that, like, we don't use a lot of the practices that most other nonprofits use that we consider to, um, invade people's privacy. [01:18:33.130 --> 01:18:38.250] Like a lot of other nonprofits, uh, trade donor and member lists. [01:18:38.390 --> 01:18:40.010] Like we never share our member lists. [01:18:40.110 --> 01:18:43.330] We don't, um, buy other nonprofits member lists. [01:18:43.390 --> 01:18:53.030] So like we, we, we, we take our members privacy as seriously as we take like the, the public's privacy when we're fighting the government and corporations. [01:18:53.750 --> 01:18:54.690] I appreciate that. [01:18:54.770 --> 01:18:56.190] And it'd be a little ironic if you didn't. [01:18:56.270 --> 01:18:56.470] Yeah. [01:18:57.890 --> 01:18:58.290] Thank you guys. [01:18:58.450 --> 01:19:00.830] Although if you catch us on it, then feel free to let us know. [01:19:01.430 --> 01:19:06.570] We try to, for example, take trackers out of emails, but you know, if there's a mistake, there's a mistake and let us know. [01:19:11.130 --> 01:19:18.070] I wanted to ask the population and, um, I think we can all agree that some technologies should not be open-sourced. [01:19:18.410 --> 01:19:20.190] Some should remain closed sourced. [01:19:20.550 --> 01:19:25.270] Um, like PTP, for example, or the Red Hat ecosystem is closed sourced. [01:19:26.450 --> 01:19:32.930] On the open-source side, the open-source organizations, companies will get really legally behind you. [01:19:33.050 --> 01:19:53.230] And I appreciate your advice, but is there a liquid conversation with EFF or another organization on closed source export controlled software like, like PGP, um, because like PGP had difficulties back in the eighties and nineties. [01:19:53.230 --> 01:19:55.230] And I have questions. [01:19:56.490 --> 01:20:02.010] I know that we have colleagues who work on export controls. [01:20:03.810 --> 01:20:06.690] Unfortunately, that's about as far as it goes. [01:20:06.970 --> 01:20:27.030] What I know, I think it's, it's one of our more, uh, kind of niche, uh, areas within EFF, as in like, there are, I think a couple of people who know a lot about it, um, but isn't as big a part of, uh, like our, our docket. [01:20:27.410 --> 01:20:29.750] So yeah, EFF is pretty far from D.C. [01:20:30.190 --> 01:20:31.770] Oh, intentionally. [01:20:32.170 --> 01:20:36.830] So, um, so PGP software is closed source. [01:20:37.150 --> 01:20:48.690] The protocol open PGP is open-source, um, uh, and GPG, uh, dry, or which uses the open PGP protocol is, uh, open-source. [01:20:49.150 --> 01:21:00.070] Um, uh, we don't necessarily have a problem with, uh, people having closed source software that they don't share it with the world. [01:21:00.490 --> 01:21:20.010] Um, but as a general principle, I think that, um, you know, uh, having open-source software, uh, having open-source is having the code for, uh, encryption available and embodies trust in that, um, software. [01:21:20.830 --> 01:21:29.070] And, uh, for instance, you have signal for instance and signal the client software is open-source. [01:21:29.150 --> 01:21:34.830] So you can verify that it's working as purported, but the server software is closed source. [01:21:34.830 --> 01:21:43.390] So there are liminal areas, but generally you can verify, uh, and security researchers have that it works as intended. [01:21:43.930 --> 01:22:01.510] Um, so yeah, there's some gray areas, but I think that, you know, as long as you are, as long as the, the software that you're using, you're able to vet it, it's a good kind of standard for trusting that software. [01:22:02.690 --> 01:22:03.310] Thank you. [01:22:03.670 --> 01:22:03.750] Yeah. [01:22:06.890 --> 01:22:07.290] Hi. [01:22:07.530 --> 01:22:17.290] So in the context of like this law in the UK, banning miners from going to websites, and then maybe even going into the future where websites will try to ban AI from posting and stuff like that. [01:22:17.490 --> 01:22:22.910] I was curious, do you guys work with the governments at all to create legislation that would protect people's privacy? [01:22:23.150 --> 01:22:25.610] Like, cause in theory, maybe this could be done in a different way, right? [01:22:25.690 --> 01:22:28.430] Like maybe you get a security key if you're over 18 or something, right? [01:22:28.990 --> 01:22:36.790] But for, for, sorry, for what issue specifically or for say the, this law in the UK, right? [01:22:36.830 --> 01:22:39.950] Are you doing work to try and say minimize potential impact? [01:22:40.150 --> 01:22:43.590] Like even just moving the data silo to the UK would be a big improvement, right? [01:22:43.910 --> 01:22:45.050] And that's theoretically possible. [01:22:45.650 --> 01:22:56.270] Well, so yeah, there are like kind of, uh, halfway things that work for some people, but they're always leaving out certain, like they're embodying certain assumptions. [01:22:56.630 --> 01:23:12.170] For instance, you know, you have, uh, age verification mechanisms, which would assume that every, uh, you know, there's a one-to-one, uh, uh, mapping between a device and a owner of a device. [01:23:12.550 --> 01:23:18.530] And that doesn't take into account contexts where you have a shared computer. [01:23:18.910 --> 01:23:29.730] Um, there's, uh, all sorts of gray areas which aren't captured by laws and those laws have unintended consequences. [01:23:30.330 --> 01:23:39.930] Um, and it is politically driven, like this specific issue is politically driven, the protect the kids, um, kind of a thing. [01:23:40.270 --> 01:24:02.110] And then they can claim victory if it, uh, if a law is enacted that, uh, purportedly protects kids, but then it, you know, has all these, uh, gray areas where gray areas, um, you know, which, you know, maybe should, but like also encompasses all this swath of the Internet that clearly shouldn't be, [01:24:02.110 --> 01:24:09.930] uh, encompassed by, um, kids online safety act or, uh, me in the UK, the online safety act. [01:24:10.570 --> 01:24:23.770] So, um, um, I think that at this moment, it's a politically driven campaign and that should be fought against, uh, rather than working with to see how it might work for them. [01:24:24.030 --> 01:24:25.770] Um, that's not our job. [01:24:27.370 --> 01:24:42.210] Uh, on the other end, uh, you know, the international team does work, um, on policy on consumer privacy issues, for example, uh, in the European Union, um, in, uh, in Latin America and with certain international agencies. [01:24:42.370 --> 01:24:56.010] And, you know, we do kind of look at legislation at the state level that's around consumer privacy issues, healthcare privacy, and other kinds of things that could, um, undercut that kind of, uh, that kind of age verification legislation. [01:24:56.310 --> 01:25:09.310] Um, although most of it, you know, it's either weak, there's a lot of exemptions, and there's a lot of weak points in it, or it is, um, uh, very frequently, uh, the technology just moves very fast. [01:25:09.650 --> 01:25:19.370] And so even if you, uh, have fairly strong consumer privacy, um, legislation that, that passes at the state level, the, the, you know, it may not keep up with the tech. [01:25:21.170 --> 01:25:33.390] Um, my, our colleague Alexis just wrote an EFF blog about, uh, why zero knowledge proofs are not, um, the solution to age verification. [01:25:33.390 --> 01:25:51.510] Like, there are proposals, uh, to make age verification technologies a little more private, um, but that doesn't address their big picture threats to, like, privacy, anonymity, security, free expression, access to information online. [01:25:51.810 --> 01:25:59.330] Um, and they, they don't address those issues for, like, people who might not have documentation, people who might share devices. [01:25:59.410 --> 01:26:06.530] Um, so I feel like at this stage, these age verification laws that are spreading across the U.S. [01:26:06.530 --> 01:26:09.530] and in other countries are a threat to so many issues. [01:26:09.530 --> 01:26:14.430] And there's not like a, there's not a technical solution to all of those. [01:26:14.430 --> 01:26:17.890] So we're, we're just, like, working against these bills, not with them. [01:26:18.430 --> 01:26:41.250] And, um, yeah, I think that for each, um, sometimes, like, zero knowledge proofs and other suggestions for, like, how to make these systems more private, um, are, um, if, like, legislatures believe that they do more than they actually do, and legislatures who are looking to maybe, [01:26:41.470 --> 01:26:53.290] like, you know, censor queer content from kids online just, like, want to be able to point to a technological silver bullet that will make their censorship law, private. [01:26:53.670 --> 01:27:01.330] Um, and EFF is trying to be very clear that, like, uh, the technology is not there yet, and will not be there yet. [01:27:01.490 --> 01:27:13.050] Um, and we can't pass these laws, um, expecting a private solution to, um, yeah, to, to be created, like, after the law is enacted. [01:27:14.110 --> 01:27:21.890] I think also worth mentioning it at a higher level, so not specific to the age verification laws. [01:27:21.890 --> 01:27:41.690] I think it's really case by case for EFF on bills and proposals that we think are bad, whether we want to engage and, like, suggest ways to improve it, different ways to approach it, ways to change the language. [01:27:42.190 --> 01:27:48.030] Um, I think is something that sometimes it's a hard call, sometimes it's an easy call. [01:27:48.230 --> 01:28:07.850] If one factor is, like, Bill said, I think whether if, like, if it's something that we think is not really a good faith effort even, and it's just politically motivated, like, we're, we're not going to engage with, okay, let's try to tweak the language to make it a little less bad. [01:28:08.170 --> 01:28:18.450] But then if there's something where it's, like, Bill, and we think, okay, we get what they're trying to do, like, maybe it's supposed to be a consumer protection bill. [01:28:19.150 --> 01:28:30.870] Um, and we think, okay, you know, I get why you're trying to do this, but say, like, you've defined these terms way too broadly, so it's going to have consequences. [01:28:31.350 --> 01:28:41.410] We don't think the person proposing it even realizes, then we might try to work with them on that and help them see a better way to do it. [01:28:41.770 --> 01:28:52.350] But if the problems we see are, like, by design, then I think that is an example of one we're not going to engage. [01:28:52.750 --> 01:29:07.950] Yeah, one good example of this, uh, was some recent feedback we had for a piece of legislation that was, um, you know, not to get into too much of details, uh, between kind of personal communications between legislators and ourselves, but, like, it was, [01:29:08.030 --> 01:29:35.330] um, it was having to do with, um, liability and making products more, uh, you know, ensuring products are more private or, uh, and it would have made open-source, uh, developers unduly liable if their code was adopted by a, um, you know, program, uh, or some piece of software that, [01:29:35.330 --> 01:29:42.310] um, didn't incorporate and it didn't, uh, you know, um, make sure that it was doing it in a private way. [01:29:42.750 --> 01:29:47.730] And these are kind of solutions where we can have a good influence. [01:29:47.970 --> 01:29:51.350] We, we can actually like, Hey, this is something that happens. [01:29:51.490 --> 01:29:55.050] Sometimes open-source software is adopted by a product. [01:29:55.250 --> 01:30:03.630] Um, and, and then it's, it's not the fault of the open-source developer, um, that they did it wrong when they went out and sold that product. [01:30:03.990 --> 01:30:10.290] Um, so those are kind of solutions where they're, you know, we can, we can work with that legislator. [01:30:10.290 --> 01:30:20.070] We can make sure that the language is doesn't unduly, uh, you know, uh, affect good faith, open-source developers, for instance. [01:30:23.830 --> 01:30:24.330] All right. [01:30:24.430 --> 01:30:29.030] So another question from the matrix chat and sorry, I didn't get this earlier, but it's going to be a bit of a left turn. [01:30:29.210 --> 01:30:36.390] All around New York city, we have 2,200, uh, free Wi-Fi kiosks that have replaced pay phones, each with three counts cameras for surveillance. [01:30:36.630 --> 01:30:41.570] In our current political climate and with the threats to take over sanctuary cities, these are these as threat. [01:30:46.680 --> 01:30:53.940] Uh, there used to be a, a group in New York that worked, um, specifically exclusively on this issue. [01:30:54.100 --> 01:30:58.300] Uh, and, uh, they have kind of, uh, folded as far as I know. [01:30:58.620 --> 01:31:03.440] Um, it was, uh, something like NYC, uh, free link or something to that effect. [01:31:03.660 --> 01:31:17.080] Um, but, uh, in New York in particular, one of the groups that's, um, paying a lot of a close attention to this and as a member of the electronic frontier Alliance is stop, um, the surveillance technology, uh, uh, oversight project. [01:31:17.300 --> 01:31:36.480] Um, and so they, they have been paying attention to, to this in particular, um, you know, and I think generally are, uh, uh, nauseated by, uh, any kind of attempt to get people to connect to, um, to government, uh, sources or to, to our codes or other kinds of things that may, [01:31:36.620 --> 01:31:40.500] um, may, uh, put privacy, um, into the wrong hands. [01:31:40.680 --> 01:31:47.420] So I, you know, that's, I think, you know, look up stop and what stop is doing, um, the surveillance technology oversight project here in New York. [01:31:47.820 --> 01:31:59.600] Um, and, uh, certainly there is a lot of, um, there are a lot of municipalities that are also thinking about privacy legislation to protect, uh, the things that they claim that they're trying to protect. [01:31:59.760 --> 01:32:05.640] That may be, um, immigrant, uh, documented or undocumented at this point, immigrant residents. [01:32:05.980 --> 01:32:15.340] It may be, you know, uh, uh, uh, you know, people seeking gender-affirming care and reproductive care, whatever a municipality has been claiming that it's attempting to protect. [01:32:15.760 --> 01:32:33.040] Um, there's very frequently something else that they're doing that's data collection, that that data can then go to the fusion centers in their state and then go to the feds, um, and be used by other states or, or, uh, municipalities for enforcement against things that that municipality is trying to [01:32:33.040 --> 01:32:33.280] protect. [01:32:33.500 --> 01:32:47.200] So, um, um, I would say stop is doing the, the, the most locally around that, but, um, but yeah, we constantly see these kinds of problems of cities claiming to protect, uh, certain communities and not doing so at all with their data collection policies. [01:32:47.200 --> 01:32:49.080] Yeah, it reminds me of the Clearview AI issue, right? [01:32:51.060 --> 01:33:00.480] I think we have time for maybe one more question and then we'll, uh, we'll be available, um, all weekends, uh, at the EFF booth upstairs. [01:33:01.240 --> 01:33:03.780] So you can come and ask questions there as well. [01:33:04.020 --> 01:33:06.400] Uh, any, any last takers? [01:33:10.800 --> 01:33:12.080] I have a quick question. [01:33:12.280 --> 01:33:17.180] I've noticed that often when privacy policies passed, the companies just turn off the futures in those places. [01:33:17.680 --> 01:33:26.320] And so I was wondering if there's anything that can be done about that, like whether it's just the communications off or what, you know, but it seems like it's sort of kind of gone. [01:33:27.600 --> 01:33:29.540] Although, of course, it's good because the data is private now. [01:33:31.300 --> 01:33:31.840] Wait, sorry. [01:33:31.960 --> 01:33:35.320] Could you give an, like, privacy legislation is passed? [01:33:35.660 --> 01:33:38.620] So like when California passed some GDPR stuff, Google just turned off search features. [01:33:41.780 --> 01:33:58.640] I mean, I think that one of the, I think that there are certain, um, I, I think I would have to, it probably depends on a case-by-case basis, of like what the feature is and what the privacy policy is. [01:33:58.760 --> 01:34:10.680] Um, but I think a lot of the times, like a company, um, as big as Google could find a way to provide, uh, the same feature and comply with, uh, privacy laws. [01:34:10.760 --> 01:34:28.660] And often, yeah, at times they're trying to like, uh, prove a point or, or fight privacy legislation and stop it from spreading when they, uh, choose to like, to, you know, take away the features from people, uh, in order to give them privacy. [01:34:28.840 --> 01:34:46.400] We also see, um, we also really, um, fight against companies, uh, creating like pay for privacy, um, schemes where, uh, they only give you privacy if you pay, if you pay more for a feature. [01:34:46.600 --> 01:34:49.500] And we don't think that, like, privacy should be a luxury. [01:34:49.500 --> 01:34:52.300] It should be a right that everyone enjoys by default. [01:34:52.540 --> 01:34:58.760] Um, that's another thing that I see companies doing that, um, good privacy laws ban. [01:34:59.200 --> 01:35:12.220] Um, there was also, you know, this can also happen in, in more subtle ways, um, where companies really make people, like, fight and sacrifice for their privacy rights. [01:35:12.400 --> 01:35:31.380] Like, there was a study, I think, done by some researchers at NYU, whose name I'm forgetting, that was presented at PETS, uh, the Privacy Enhancing Technology Symposium about a month ago, um, where they found that when people, uh, selected all of the privacy settings they could on YouTube, [01:35:31.380 --> 01:35:43.540] they were shown more ads and worse ads, um, than when they were, like, letting YouTube use and share more of their data. [01:35:43.740 --> 01:36:02.520] So I think it takes, like, researchers and community members, like, keeping an eye out for, uh, dark patterns and maybe, um, manipulative behavior that companies are using to nudge people towards less private options. [01:36:04.880 --> 01:36:11.420] So for the last question, um, there's been a lot of talk about Peter Thiel's Founders Fund having invested in Brave. [01:36:11.680 --> 01:36:12.700] How accurate is this? [01:36:12.800 --> 01:36:14.420] And should it be a concern for users? [01:36:16.440 --> 01:36:17.960] Uh, I'm not aware of that. [01:36:18.160 --> 01:36:26.040] Um, I do know some of the technologies that are employed by Brave that are effective. [01:36:26.040 --> 01:36:32.180] Um, they do randomization of canvas fingerprinting. [01:36:32.420 --> 01:36:38.060] Um, they do have a tracker blocker that is built into the Brave browser. [01:36:38.500 --> 01:36:40.260] They are a for-profit. [01:36:40.460 --> 01:36:41.940] That's something that to consider as well. [01:36:42.440 --> 01:36:48.600] Um, so it's kind of a choose your own adventure in terms of the browser market right now. [01:36:48.940 --> 01:37:05.560] Um, as Lena mentioned earlier, uh, you know, there's, it's kind of harder to explain to a family member, for instance, um, to install Firefox with these extensions, uh, versus maybe a browser that protects them out of the box. [01:37:05.800 --> 01:37:26.020] Um, but, you know, um, you might want to do that if you feel that, you know, for instance, open-source, uh, uh, and a non-profit, um, driving your browser experience is, um, a priority for you. [01:37:26.380 --> 01:37:32.500] So yeah, there's a lot of nuance in the choices right now of what browser to choose. [01:37:32.900 --> 01:37:36.420] Um, so I, that's the best answer I can give. [01:37:36.420 --> 01:37:36.600] Yeah. [01:37:36.880 --> 01:37:39.080] I think that same question can go for AI these days too. [01:37:41.540 --> 01:37:49.740] I think it's also, you know, one of the frustrating things is just, you might find a new browser that it's like, oh, great. [01:37:49.860 --> 01:37:53.020] This is an amazing privacy protective browser. [01:37:53.140 --> 01:37:57.200] And then that can just change at any time, right? [01:37:57.680 --> 01:37:59.040] Companies do this all the time. [01:37:59.460 --> 01:38:05.020] They do one thing you like and then decide, no, we're going to make our policies terrible now. [01:38:05.020 --> 01:38:09.720] Um, and there's not a whole lot to do about that. [01:38:09.900 --> 01:38:19.560] So I think it, it just reinforces how, you know, the amount of work that is required just to protect your privacy. [01:38:19.560 --> 01:38:35.500] It's like not even just, you need to do your research first and choose the right tools, but you need to stay on top of knowing, like, is it still doing what it was doing in the first place or has something changed? [01:38:36.180 --> 01:38:36.760] All right. [01:38:36.840 --> 01:38:37.560] Last, last question. [01:38:38.200 --> 01:38:38.860] Go ahead. [01:38:39.040 --> 01:38:40.660] It'll be difficult as I have one and a half. [01:38:41.940 --> 01:38:51.320] Um, so one of the questions is that there's increased cross-border cooperation with e-evidence warrants and things like that being developed in the European Union. [01:38:51.320 --> 01:39:01.660] Uh, the cloud act in effect for, uh, cooperation between the European Union and the United States for cross-border, uh, subpoenas basically. [01:39:02.520 --> 01:39:22.180] Um, given especially, uh, the changing political circumstances in a number of EU countries and in the United States, uh, and also the particular, uh, decrease in the respect for fundamental rights when it comes to issues of free speech around Palestine or anything else. [01:39:22.360 --> 01:39:42.000] Um, what can be done legislatively and also, or in any way, uh, and, uh, what are the interactions between these existing schemes like the new e-evidence mechanism in Europe, uh, and the cloud act, uh, between, across the continent? [01:39:42.140 --> 01:39:43.060] There is a follow-up question. [01:39:45.280 --> 01:40:11.620] So one other than the cloud act where we are working on defeating basically the UN cybercrime treaty, uh, and the UN cybercrime treaty is a great example of a, uh, piece of trans national policy, uh, which is being formulated that would require, uh, countries around the world to cooperate for, [01:40:11.620 --> 01:40:36.800] uh, law enforcement purposes, um, that, uh, would enable, say, uh, investigators in Russia that are looking into a group that is composed of, uh, homosexual people to like, um, you know, to investigate those, uh, that group across, like using U.S. law enforcement. [01:40:37.080 --> 01:40:57.880] Um, and so we are, uh, working against that being adopted in the U.S., um, defeating that treaty both in negotiations on the UN floor, um, and also like against adoption by, by the U.S., uh, currently. [01:40:58.060 --> 01:41:02.380] And what of existing mechanisms that already achieved that between Western countries, right? [01:41:02.460 --> 01:41:11.960] A lot of the discussion about this relies on a sort of assumption of a divide that there's democratic countries with due process and there's others that aren't, but we're seeing that that's not the case right now. [01:41:12.220 --> 01:41:25.340] Many countries that were previously assumed to be, uh, countries where if you got a subpoena from there as a company, you fought it a little bit, but you expected that that country to have due process are no longer trustworthy in that sense, right? [01:41:25.500 --> 01:41:39.180] You could be in Ireland and receive a subpoena about a posting on social media of the phrase, from the river to the sea, from Germany, and you would be obliged as of next year to respond in spite of the fact that the Guardi really don't care. [01:41:40.080 --> 01:41:41.860] So what of existing mechanisms? [01:41:42.120 --> 01:41:43.580] How do those interact? [01:41:43.860 --> 01:41:48.160] How does that affect digital rights in the U.S. and what can be done about it? [01:41:48.420 --> 01:41:49.560] That's not a follow-up question. [01:41:49.680 --> 01:41:50.100] It's the same question. [01:41:50.420 --> 01:41:50.780] Yeah. [01:41:50.880 --> 01:42:05.520] I mean, those questions and the logistics to which different countries operate or have leeway in rejecting your requests, uh, is something that we sometimes have insight into, sometimes don't. [01:42:05.920 --> 01:42:34.940] Um, and we try to exert pressure where we can to make sure that at least on the treaty level and legal level and, um, and in the courts, those that they have, that citizens have more leeway to, uh, escape surveillance, escape, uh, those, you know, really, [01:42:35.180 --> 01:42:43.640] um, kind of the, those instances where their rights will be abridged by those treaty obligations or policies. [01:42:44.040 --> 01:42:46.800] Um, I don't know if that answers the question. [01:42:47.420 --> 01:42:50.300] It doesn't, but I'd, I'd love to have a conversation with one of your attorneys later. [01:42:50.380 --> 01:42:50.460] Yeah. [01:42:50.700 --> 01:42:50.920] Thank you. [01:42:51.400 --> 01:43:04.020] Um, the, uh, other question is, um, there have been a wide variety of legislative attempts to strip section 230 of the communication decency act protections for companies that don't backdoor their stuff. [01:43:04.800 --> 01:43:14.820] Um, what is civil society's fallback, both as end users and as organizations like yours, if one of those were to actually pass? [01:43:14.940 --> 01:43:18.220] Is there a constitutional argument that you find likely to prevail? [01:43:18.560 --> 01:43:23.880] Uh, or is it a matter of moving things out of jurisdiction? [01:43:25.020 --> 01:43:26.300] And if so, where? [01:43:31.890 --> 01:43:33.410] Hard hitting questions. [01:43:34.150 --> 01:43:36.510] Um, and not a quick one. [01:43:37.510 --> 01:43:56.210] Um, I think, you know, there's, there's good reason that these types of proposals are ones that EFF will always like jump to pushing back on and work really, really hard on pushing back against because it is difficult. [01:43:56.210 --> 01:44:24.390] I mean, I think in the area of section 230 related issues, I think main fallback is first amendment, um, trying to argue that there are, you know, and like when you try to condition one protection on doing something else that the government wants, if that implicates speech that can have first [01:44:24.390 --> 01:44:26.970] amendment, first amendment implications. [01:44:27.550 --> 01:44:34.190] Um, but that's, uh, I will say not, uh, one of my expert areas, though. [01:44:34.650 --> 01:44:39.790] It is an area that we have a lot of people who work on a lot. [01:44:41.510 --> 01:44:57.130] I would just, in terms of what civil society can do, I think one of the other things is, uh, that there are an increasing number of collectives around the world and around the country that are trying to think about movement infrastructure in terms of software and app development and, [01:44:57.370 --> 01:45:02.610] you know, how to create your own stuff from within the movement, within various social movements. [01:45:02.970 --> 01:45:20.090] Um, and then, you know, obviously that is with, uh, non-profit collectives that are willing to go to court and even willing to, um, you know, face, uh, uh, criminal sanctions and civil sanctions by, you know, kind of, uh, removing data or not collecting data or refusing, [01:45:20.090 --> 01:45:26.530] um, you know, requests, uh, and then also refusing administrative warrants and then also refusing judicial warrants. [01:45:26.750 --> 01:45:41.090] Um, so, you know, I think that a lot of it is also just, it's incumbent in, uh, in movements and in movement, um, uh, movement-minded kind of software developers to keep doing that, to keep building that kind of infrastructure. [01:45:41.710 --> 01:45:43.710] May 1st, uh, and rise up. [01:45:43.810 --> 01:45:45.230] May 1st is a member of EFA. [01:45:45.410 --> 01:45:47.510] I keep shouting out EFA members. [01:45:47.710 --> 01:45:50.610] Um, you know, the Calix, uh, Institute. [01:45:50.790 --> 01:46:00.550] There's, there's a lot of other, uh, groups that are certainly trying to think about that and are, and a lot of them are kind of, um, crawling out of the woodwork because, uh, you know, because you're right. [01:46:00.630 --> 01:46:05.950] I mean, how many protections can people really expect at the legislative or judicial level, uh, these days? [01:46:06.170 --> 01:46:06.410] Yeah. [01:46:06.650 --> 01:46:23.270] As a, as a follow-up to that too, just, you know, as a practical matter, um, in addition to fighting in courts, we want to see a landscape where practically information isn't siloed into large databases that could be compromised. [01:46:23.330 --> 01:46:27.970] So, or asked for under legal order, um, for instance. [01:46:28.310 --> 01:46:46.330] So there are a number of very cool technologies that are emerging right now that I'm very excited about personally, but I think that, uh, EFF is, um, as a decentralization principle, excited about, um, things like MASH-TOSIC. [01:46:46.390 --> 01:47:09.950] There's a great, uh, technology that, um, I blogged about recently called Reticulum, uh, and Reticulum uses long-range, um, uh, long-range radios in order to create a communications infrastructure that's separate from the Internet, but, uh, has anti-circumvention or anti-censorship, [01:47:09.950 --> 01:47:15.210] um, properties that are embedded in it, um, at a very low level. [01:47:15.210 --> 01:47:18.990] And that's some really exciting technology that I've been playing with myself. [01:47:19.330 --> 01:47:35.170] Um, and so I think that that is something that can be adopted by social movements, um, uh, street protests, um, in ways that are really creative and can circumvent, um, some of the state controls that we hate to see. [01:47:38.630 --> 01:47:39.650] Thanks everyone. [01:47:39.990 --> 01:47:47.510] Uh, and again, we'll be available upstairs, um, to take any questions slash donations that you have available. [01:47:47.830 --> 01:47:50.010] Um, and, uh, yeah, thanks again.