[00:00.000 --> 00:20.240] A project that is trying to put a whole bunch of circumvention tools on one box to make it easy for people to use and to get that distributed to as many people as possible and I also work with the Open Internet Tools Project which is a relatively new initiative that is designed to support all the people who are making tools in this area because there are tons of people who have started making [00:20.240 --> 00:32.800] tools in this area and there are tons of projects that are getting underway and gathering steam and we're trying to make life easier for them as well as for the users who are I'm just now trying to figure out that they need tools of this nature. [00:33.120 --> 00:34.360] So that's the kind of work I do. [00:34.460 --> 00:40.900] I work in software freedom, I work in tech freedom, I work in privacy, and these are my organizational affiliations. [00:43.600 --> 00:49.960] What I'm going to try to do in this talk is describe a little bit, and very briefly, the threat that we're facing. [00:51.140 --> 01:00.440] This is a rather sophisticated audience, so I'm not going to get into too much detail here, but I want to highlight the complexity of the threat that we are addressing with circumvention tools. [01:00.940 --> 01:04.580] Then I'm going to talk about how the tools we have failed to address that threat. [01:05.120 --> 01:10.500] Right now we have tons of really good options, but no excellent options. [01:10.500 --> 01:17.140] No options that are getting widespread adoption, and changing the world for as many people as we would like them to be. [01:17.520 --> 01:20.280] So I want to talk about the reasons why that exists. [01:20.760 --> 01:35.320] I'm going to talk about solutions to these problems, and then I'm going to talk a little bit about what OpenITP and FreedomBox and me, and hopefully all of you, are going to do to try to chip away at these problems, and to build these solutions piece by piece. [01:36.840 --> 01:41.600] So the need for circumvention tools is something I think everybody in this audience accepts. [01:42.160 --> 01:56.120] I think everybody who would attend a conference like this is sophisticated about censorship and about surveillance, in the sense that you understand what the threat looks like, and you understand why people might want privacy and security and anonymity even. [01:57.500 --> 02:00.280] But it's worth it to go into a little bit of detail. [02:01.160 --> 02:08.000] The first thing I want to talk about is who is it that we are trying to get privacy from and security from. [02:08.360 --> 02:16.980] When we talk about circumvention tools and we talk about censorship and surveillance, the entities that are censoring and surveilling us, really, it starts with government, right? [02:17.040 --> 02:22.640] That is the big thing that most people think of, the big threat that a lot of people are worried about. [02:22.940 --> 02:35.500] Government has the biggest hand, the biggest fist, the biggest ability to harm us, and the biggest resources to discover our communication and monitor our communication and to take action when they see what we have. [02:36.920 --> 02:42.520] Government censorship is probably one of the biggest informational problems in a lot of societies. [02:42.880 --> 02:48.220] Not just in America, where government censorship is relatively lightweight, but especially internationally. [02:48.220 --> 02:53.000] In a lot of countries where access to information, basic access to information, is threatened. [02:54.720 --> 02:58.200] If we step down from the governmental level, we get to the corporate level. [02:58.200 --> 03:11.460] And as a room full of rather, you know, privileged Americans and Europeans, when I look around this room, we have a lot more censorship at the corporate level than we do at the governmental level in terms of our daily lives. [03:11.620 --> 03:22.300] We use a lot of communication tools that require us to only communicate in ways that are acceptable to the corporations whose tools we are using, whose platforms we are using. [03:22.300 --> 03:37.420] And those corporations, those entities whose primary goal in life is not to foster community, is not to foster communication, but instead to foster profits and advertising and business, have very different needs than our communication does. [03:37.600 --> 03:47.420] And so that leads to censorship of things like pictures of women breastfeeding, to things like people trying to talk about revolution in countries where these companies need to operate. [03:47.420 --> 04:00.220] So corporate censorship is a thing that happens at a very tangible level to people on a daily basis in ways that is not as heavy-handed as government, but affects their ability to actually communicate with their audience and their communities. [04:01.140 --> 04:08.480] And then we have a more personal form of censorship, a more personal form of surveillance, which is parents. [04:08.820 --> 04:09.100] Right? [04:09.240 --> 04:14.550] If you're a kid, your adversary in the world of privacy is not Facebook. [04:14.550 --> 04:16.070] You'll tell Facebook anything. [04:16.450 --> 04:20.770] It's not government, because nothing you do is of any interest to government. [04:21.050 --> 04:23.930] But everything you do is really interesting to your parents. [04:24.730 --> 04:29.910] And your privacy model isn't, oh, gee, I need to protect myself from government intrusion. [04:30.230 --> 04:33.130] Your privacy model is, I really don't want my mom to know what I'm doing. [04:33.470 --> 04:36.650] And so that's what privacy looks like at various levels, right? [04:36.730 --> 04:44.190] There's the threat, the adversary that we're worried about changes from moment to moment or from context to context, and especially from person to person. [04:45.430 --> 04:51.430] The consequences of a privacy intrusion are really very as well, right? [04:51.690 --> 04:53.730] In the parental sense, it's you're grounded. [04:54.330 --> 05:02.070] If you do something at work that you wish your boss didn't know, if you say something at work that you wish your boss didn't know, you might get fired. [05:02.390 --> 05:06.190] But if you go up the adversary chain to someone as powerful as, say, a government, [05:10.520 --> 05:13.160] losing your job might be the least of your concerns. [05:14.360 --> 05:17.400] Now, this is a picture of a predator drone. [05:18.060 --> 05:21.220] And that sort of implies that it's the U.S. government we're talking about. [05:21.360 --> 05:24.860] But we all know that there are lots of governments that are threatening to people. [05:25.400 --> 05:32.420] And there are lots of ways in which governmental intrusion on your specific communication could subject you to all kinds of risk. [05:34.320 --> 05:47.160] There's so many ways in which the adversary model differs from person to person and from situation to situation that that kind of complexity makes it almost impossible for us to know what tool is going to be right for what job. [05:47.240 --> 05:49.160] And I'm going to talk a little bit more about that later. [05:49.680 --> 05:55.180] The effects of censorship are really also varying, right? [05:55.280 --> 06:00.740] In some instances, it's the general effect of the feeling that you can't do what you want to do. [06:02.600 --> 06:10.380] In some senses, it is not when government takes direct action or corporations take direct action that we are actually prevented from communicating with each other. [06:10.560 --> 06:12.640] In a lot of instances, we self-censor. [06:12.860 --> 06:14.740] We decide not to engage in behavior. [06:14.960 --> 06:19.600] We decide not to engage in communication because we're worried about what the effects of that might be. [06:19.900 --> 06:23.780] And the reason we're worried about that is because we never feel like we're unmonitored. [06:24.100 --> 06:28.000] Everything we do is something that we know somebody is going to be watching. [06:28.720 --> 06:30.800] And usually, that's rather innocuous, right? [06:30.920 --> 06:32.980] Usually, that has rather minor effects. [06:33.200 --> 06:34.220] But not always. [06:34.700 --> 06:49.620] In some senses, the intrusion can be passive, it can be intrusive, or it can really be abusive, as was the case with Martin Luther King, who was a man who was extremely highly surveilled and subverted by active forces. [06:49.620 --> 07:03.580] So, when we talk about what is happening in the world of surveillance, in the world of censorship, we're talking about a variety of different people we are worried about, a variety of different vulnerable targeted populations. [07:04.140 --> 07:10.300] These populations are always people who are at the wrong end of a power dynamic. [07:11.400 --> 07:14.300] People who are powerful tend to have privacy. [07:14.300 --> 07:16.780] People who are knowledgeable tend to have privacy. [07:17.660 --> 07:19.920] People who are vulnerable tend not to. [07:20.260 --> 07:30.860] Every time you step down the power spectrum, you find a person who is more censored, less free to speak, less free to act, and less free to be. [07:32.400 --> 07:34.880] Minority populations, workers, right? [07:34.980 --> 07:37.860] People who are in an office where they are not the boss. [07:38.040 --> 07:40.320] Those are the people who have to worry about what they say at work. [07:40.320 --> 07:43.580] We all know that our bosses get to say whatever they want, whenever they want. [07:43.780 --> 07:44.400] We don't. [07:45.540 --> 07:47.440] People who lack financial resources. [07:47.720 --> 07:49.680] These are the kinds of people who worry about things. [07:50.260 --> 07:52.700] And again, activists, kids. [07:53.300 --> 07:59.760] Kids are the sort of prototypical case of people who have zero privacy and get impinged on at every turn. [08:01.300 --> 08:06.080] So, in the context of all these people, right, you have lots of different situations. [08:06.260 --> 08:16.120] Lots of actors, lots of vulnerable target populations, lots of different kinds of consequences that would flow from your sense of your being, your privacy being violated. [08:16.620 --> 08:26.300] And against that backdrop of immense complexity, we have a bunch of different projects that have sprung up to try to address specific instances of privacy problems. [08:26.440 --> 08:27.400] Specific use cases. [08:27.600 --> 08:28.320] Specific threats. [08:29.160 --> 08:31.280] And these are just a few examples, right? [08:31.320 --> 08:36.320] We have the Tor project that tries to make your networking as anonymous as possible. [08:36.320 --> 08:41.760] We have the Freedom Box, which is trying to collect a bunch of different projects and make them easier for users to access. [08:42.160 --> 08:45.600] We have Cryptocat, which does direct encrypted text messaging. [08:46.280 --> 08:48.240] We have the TrackMeNot plugins. [08:48.840 --> 08:55.080] Those just try to hide you from all of the corporate surveillance that you get through cookies as you use the Internet. [08:55.440 --> 09:04.120] We have Telecomics, which is actively engaged in trying to prevent governments, especially governments in the Middle East from doing abusive things to their own populations. [09:04.640 --> 09:08.840] And then we have, you know, basic encryption, which we get from the GNU Privacy Guard. [09:09.240 --> 09:14.100] The range of responses to the privacy threat is huge. [09:14.700 --> 09:15.840] It is extremely wide. [09:16.080 --> 09:21.280] There are way more projects than we could list and talk about in one session. [09:21.280 --> 09:30.820] And the reason why there are so many projects, a dizzying array of projects out there, is that the privacy threat that I described earlier is as complex as I described it. [09:30.880 --> 09:32.400] It is more complex than I described it. [09:33.400 --> 09:44.480] So trying to figure out how to make your way through that thicket of many different projects addressing many different needs is one of the main problems that we are going to have to figure out as we try to move this area forward. [09:46.340 --> 09:50.320] Ultimately, no one tool is going to need every possible need. [09:51.400 --> 10:05.000] Every time we try to figure out how we are going to address the situation, we are going to be dealing with a situation that is complex enough, that is enough different adversaries and enough different threats, that we are going to need a lot of different ways to approach it. [10:05.060 --> 10:10.440] And it is ultimately going to translate into solutions that require a multitude of tools for every user. [10:11.320 --> 10:15.840] It would be really great if we could just tell everybody, hey, install Tor and you are done. [10:16.440 --> 10:18.420] Because, you know, Tor is awesome, right? [10:18.800 --> 10:24.340] Tor is the gold standard in terms of how a project is run, in terms of what it does, in terms of how good it is. [10:24.700 --> 10:29.460] But if all you ever did was install Tor, you wouldn't actually have privacy or security. [10:31.240 --> 10:34.560] And that leads us to what this talk is really about. [10:34.960 --> 10:36.540] Why the tools don't work. [10:37.220 --> 10:38.640] We have got all these tools. [10:38.640 --> 10:42.460] We've got so many different responses to so many different threats. [10:42.800 --> 10:45.680] So many ways of addressing the problems that we face. [10:45.960 --> 10:52.360] Projects that have been worked on for years by extremely smart, extremely committed people. [10:52.880 --> 10:59.020] Activists, coders, trainers, people who have dedicated their lives to solving this problem. [10:59.660 --> 11:01.620] And we haven't even remotely solved it. [11:02.380 --> 11:11.020] We're not even close to providing comprehensive, effective security for even average people, let alone people under threat. [11:11.840 --> 11:16.300] Let alone people under, you know, threat of specific interest by a hostile government. [11:16.560 --> 11:20.000] This is a really hard problem and we have not solved it. [11:20.160 --> 11:22.380] We've certainly not solved it on a widespread basis. [11:23.260 --> 11:36.720] And so, I want to talk a little bit about where the gaps are between these awesome people who have done such good work and the practical results of getting the tools into the hands of users in a way that actually gives them security. [11:38.720 --> 11:41.840] Our tools have failed us in a variety of ways. [11:42.560 --> 11:49.680] First of all, there's a sense among certain user populations that surveillance is omnipresent and indefeatable. [11:51.240 --> 11:58.420] That's a hard thing to overcome because those are people who probably could use tools and should use tools but don't seek them out. [11:58.640 --> 12:02.260] Aren't willing to take steps to protect their own privacy and security. [12:02.440 --> 12:07.700] Even if they care very much about privacy and security, they don't actually feel like that is a problem they can overcome. [12:09.300 --> 12:19.080] Among those people, even people who decide they want to take steps, it's practically impossible to pick a tool that will apply to your situation without expert knowledge. [12:20.040 --> 12:26.100] We have a lot of expert knowledge in this room but try to imagine for a moment if all you know is that you want privacy. [12:26.440 --> 12:28.500] And you're not quite sure who you need privacy from. [12:28.840 --> 12:34.720] You're not quite sure what the network effects are, what the actual encryption model of anything is. [12:34.720 --> 12:38.220] You have no idea what privacy guarantees you're getting when you get a tool. [12:38.560 --> 12:40.140] A, because tools don't tell you. [12:40.500 --> 12:43.360] And B, because if they did, you probably wouldn't understand them. [12:43.760 --> 12:46.080] So we have a knowledge gap. [12:46.280 --> 12:54.320] We have tons of great tools that could be used more widely by people who are willing to use them but they're unable to find them. [12:54.500 --> 12:59.700] And along the way, as they're looking for tools, they're encountering a lot of bad tools. [12:59.700 --> 13:01.580] And I'll talk a little bit about that later. [13:03.780 --> 13:14.300] The fact is, even people who manage to get their hands on tools find them difficult to use, find them difficult to set up, difficult to install, difficult to actually manage and use in a secure manner. [13:15.000 --> 13:31.960] When we talk to users, when we talk to people who train users, what we discover is that users, even motivated users in bad circumstances, who really need our tools, find it very difficult to engage in effective communication. [13:31.960 --> 13:34.400] And this is for a lot of reasons. [13:34.620 --> 13:39.320] For one problem, tools are generally single channel. [13:39.920 --> 13:48.260] You take a great piece of software, like Nadim's CryptoCat software, and it is just an IM solution. [13:48.660 --> 13:54.440] But most of us who communicate with other people don't only communicate with them over instant messaging. [13:54.860 --> 13:57.160] We talk to them across multiple channels. [13:57.940 --> 14:04.420] And if we are going to try to actively have conversations with other people, we're going to need to talk to people over multiple channels, right? [14:04.480 --> 14:06.820] We need the tools to fit our pattern of human communication. [14:07.500 --> 14:25.360] And the result of this attempt to talk to multiple people means that anybody who installs a one-channel tool, which is to say almost all the tools out there, is going to have a tool that won't actually cover all their needs, which means there's going to be a need for multiple tools. [14:26.120 --> 14:28.860] And once you have multiple tools, you have gaps between the tools. [14:29.600 --> 14:32.620] And that's a thing that most users are not capable of managing. [14:32.780 --> 14:40.160] It's a thing that most users are not capable of sussing out or understanding where those gaps are and how to use tools effectively in security. [14:40.680 --> 14:42.280] So, tools are difficult to use. [14:42.420 --> 14:42.900] They're confusing. [14:44.220 --> 14:45.820] They're also a pain. [14:46.640 --> 14:49.080] I don't know if you've ever tried to use Tor. [14:50.280 --> 14:51.140] It's slow. [14:51.860 --> 14:52.580] It's slow. [14:52.800 --> 14:56.560] And if you use it, your bank will stop talking to you. [14:56.880 --> 15:01.220] PayPal will shut down your account because you're going to look like a person who is trying to subvert them. [15:01.400 --> 15:02.840] You're going to look like a bad actor. [15:03.340 --> 15:03.420] Right? [15:03.480 --> 15:09.580] So, even when you're trying to use tools in a responsible way, there's a higher barrier. [15:10.540 --> 15:13.880] And that's a big problem for users who just want to talk to their friends. [15:14.240 --> 15:16.420] A journalist who just wants to talk to a source. [15:16.920 --> 15:19.640] A person in a bad place who just wants to reach out to their family. [15:20.520 --> 15:21.660] If you have bad tools... [15:22.380 --> 15:22.920] I'm sorry. [15:22.980 --> 15:26.640] If you have good tools that are hard to use, people are going to slip up. [15:27.000 --> 15:29.860] They're going to use them almost all of the time. [15:30.720 --> 15:35.660] And imperfect tool use in a world of perfect surveillance is not much better than no tool use at all. [15:36.660 --> 15:42.580] There are several instances of people who have used secure tools for almost all of their communication. [15:45.220 --> 15:54.200] But when all of their communication was recorded, when all of their communication was surveilled, the one time they didn't was the time that their IP address was given up. [15:54.300 --> 15:55.780] The time that their identity was given up. [15:56.040 --> 15:59.760] And that's a common thing that happens more often than we would like to think about. [15:59.760 --> 16:10.800] But if you are cloaked most of the time, and then sometimes not, there's not really a whole lot of point in using it if you are facing anything that looks like a determined adversary. [16:11.160 --> 16:14.100] Certainly anything that looks like a computerized adversary. [16:15.980 --> 16:20.280] And the final really big problem with tools is that some tools are just shoddy. [16:22.280 --> 16:24.520] We have tools that don't work very well. [16:24.520 --> 16:27.420] We have tools that make security guarantees that they can't back up. [16:27.600 --> 16:34.520] We have tools that pretend to keep you safe, but then do things like send your messages in clear text. [16:34.780 --> 16:44.800] We have tools that log your passwords in clear text on your system, so that anyone who looks at your computer is going to get access to secure information. [16:45.440 --> 16:46.540] That's a big problem. [16:46.540 --> 16:52.280] So we have users who are facing this landscape, this landscape of tools that they don't understand. [16:52.720 --> 16:54.920] And it's a major headache, right? [16:56.980 --> 17:08.740] So let's step through these one by one, talk about them very briefly, and then get into what we really care about, which is steps we can take to solve these problems. [17:09.500 --> 17:12.560] So people don't expect security. [17:13.120 --> 17:14.740] People don't expect privacy. [17:15.500 --> 17:17.480] They expect their tools to subvert them. [17:17.540 --> 17:19.560] They don't trust the tools that they have in front of them. [17:19.640 --> 17:25.120] They don't expect that when they use their computers or their phones, that that information won't get shared. [17:25.320 --> 17:32.780] Or if they do expect that they're going to get privacy, they're sort of fatalistic about the fact that those expectations won't be met. [17:33.780 --> 17:43.260] Our response in the security community has very often been I've been to attempt education, but whenever I look at that education, it looks like scaremongering to me. [17:44.140 --> 17:47.100] And it's a little bit short on solutions, right? [17:47.260 --> 18:00.080] So what we have is a situation where we have users who are scared to use their tools, and they get lots of scary information about how those tools are scary to use, but the solutions are not reachable by them. [18:00.540 --> 18:03.340] And so they are paralyzed, right? [18:03.400 --> 18:06.700] They have a situation where they can't actually act to protect their communication. [18:06.700 --> 18:10.760] All they can do is choose to communicate insecurely or not at all. [18:11.220 --> 18:23.020] And in a situation where we are faced with not talking or talking insecurely, almost every one of us is going to talk insecurely because we care enough about communicating with fellow people. [18:23.120 --> 18:29.900] We care enough about reaching out to other people that the impulse to connect with our communities is too strong. [18:31.940 --> 18:34.980] People don't have a place where they can go to for solutions. [18:34.980 --> 18:40.700] People don't have knowledge of what the array of products out there that could help them are. [18:40.940 --> 18:45.360] The products that exist are many, and they have no idea what their own use case is. [18:45.440 --> 18:50.560] They have no idea what they can do to actually find the tools that they need to protect themselves. [18:50.860 --> 18:56.640] If you try to think up a use case, imagine if you are a journalist in Syria. [18:57.460 --> 18:59.040] What would you do to protect yourself? [18:59.340 --> 19:00.100] Go to Google. [19:00.420 --> 19:03.740] Try to figure out what tools you would use from a naive user's point of view. [19:03.960 --> 19:05.380] It's incredibly difficult. [19:05.800 --> 19:14.260] To the extent that you find options that you think are viable, choosing between them will be absolutely impossible without information that you don't have access to. [19:17.100 --> 19:22.960] As a community, we have been relatively bad about user interface design, about user experience design. [19:23.240 --> 19:25.740] And I don't necessarily think that that's our fault. [19:26.680 --> 19:32.240] We don't have that skill in our community, and we have not had a lot of success in recruiting that skill. [19:32.820 --> 19:43.060] And everywhere I see user experience experts talking to projects that are doing circumvention, integrating those people into the design process has been a major hassle. [19:43.320 --> 19:46.960] So we're trying to do it, but we failed at it. [19:47.160 --> 19:53.400] And in the specifics of getting good user experience design, most projects don't have the resources to do it. [19:53.460 --> 19:56.920] They don't have them in project, and they have not had a lot of success in recruiting it. [19:57.660 --> 20:00.360] And that's every project, including my own projects. [20:00.500 --> 20:03.740] I'm not saying that I am better at this than anybody else. [20:04.640 --> 20:06.440] We're really bad at installing tools. [20:06.640 --> 20:09.180] If you're on a Linux box, installing a tool is very easy. [20:09.580 --> 20:21.080] If you are one of the unlucky and yet dominant majority of users who runs Windows, installing a privacy tool is very hard. [20:21.280 --> 20:28.380] Finding the just finding the right thing to download that isn't rooted with malware is a problem. [20:28.600 --> 20:30.620] Finding a thing that isn't a threat to you is a problem. [20:30.820 --> 20:40.120] If you're the typical user who Googles for stuff and downloads it from two cows or whatever, without any sort of authentication mechanism behind it, you have no idea what you're downloading. [20:41.280 --> 20:50.040] And even when you do download it, installing it is a major hassle, because it's usually three different libraries and sigwin, and by the time you're done with it, you don't know how to proceed. [20:51.720 --> 20:58.260] And the last thing that comes under confusion is just this notion that I mentioned earlier about covering the gaps between tools. [20:58.680 --> 21:10.840] Tools are so difficult to use in their one instance of intended use, that trying to cobble together five different tools to cover all the different ways you communicate is a problem that is beyond the reach of the vast majority of tools. [21:10.960 --> 21:12.760] And there's a few projects that are trying to do this. [21:13.120 --> 21:26.420] But most users are not successful at finding those projects, and most users are not successful at assembling multiple tools to cover their own bases, to cover all the ways they need to communicate and connect with the community they're trying to reach in a secure manner. [21:28.060 --> 21:32.320] The truth is, at the end of the day, our tools prevent communication. [21:32.780 --> 21:34.420] We're not enabling communication. [21:34.940 --> 21:41.880] What we're doing is we're providing alternatives to easy-to-use tools that have one additional feature. [21:41.880 --> 21:43.560] That feature is security. [21:44.040 --> 21:46.400] But our tools have major costs. [21:46.620 --> 21:55.840] And the costs come in the form of usability, lack of documentation, no user support group around it, no community of people that you can ask for help. [21:56.400 --> 22:00.320] Our tools are just not compelling to most users. [22:00.500 --> 22:05.420] Even users who are in dire circumstances where the very fact of security should be compelling. [22:05.660 --> 22:10.320] The fact is that if people cannot use them, we're not going to be able to deliver our tools effectively. [22:13.120 --> 22:20.900] I want to say one more note about shoddy tools, which is that from a user's perspective, it's not just determining good tools from bad tools. [22:21.100 --> 22:24.000] It's determining good tools from bad tools from subverted tools. [22:24.240 --> 22:29.080] There are projects right now that are downloading security tools from shareware websites. [22:29.760 --> 22:34.840] And because we work in the open-source model, anyone can download our code and stick whatever they want in it. [22:35.020 --> 22:41.360] And you can find popular tools, copies of popular tools with back doors in them everywhere. [22:42.260 --> 22:44.840] And that's a major threat to average users. [22:44.960 --> 22:50.100] And users currently have no good way to distinguish between the good, the bad, and the subverted. [22:53.160 --> 22:54.240] That's the landscape. [22:54.540 --> 22:55.600] That's what we're facing. [22:55.960 --> 23:13.500] We're facing users who are difficult to reach, who are relatively unsophisticated, who need better interfaces, who need us to have deliverable tools that we can guarantee in some way, that we can describe with some way of telling them exactly what it is for and when they should use it and when they should not. [23:13.980 --> 23:15.100] And we're not doing that. [23:18.100 --> 23:21.900] What I want to do is change the way we construct tools. [23:22.380 --> 23:29.500] I want to change the way we talk about tools and change the way we figure out how to deliver tools to end users. [23:32.420 --> 23:35.760] As a community, we have to have standards. [23:35.980 --> 23:40.240] We don't currently have a way to communicate standards. [23:40.400 --> 23:46.600] We don't currently have a way to assemble everyone to agree on what the minimum things we're going to do before we push code out the door is. [23:46.800 --> 23:48.980] We have a lot of people with opinions about this. [23:49.120 --> 23:57.300] But we have absolutely no way to get together and enforce those opinions in the peer pressure sort of way that community standards normally get enforced. [23:57.920 --> 24:03.240] This is a thing that we've been trying to do, that various people in the community have been trying to do for a long time. [24:03.420 --> 24:05.400] But we haven't done a very good job of it. [24:05.480 --> 24:18.200] Because if you look around, you see all kinds of tools released by enthusiastic people, even people who are honest and trying to help, that don't meet anything like a minimal, acceptable standard for quality and security. [24:18.900 --> 24:24.040] You see tools that do not adhere to just basic good practices. [24:24.820 --> 24:27.160] You see projects without public bug trackers. [24:27.280 --> 24:30.900] You see projects that release code that depend on proprietary backends. [24:31.120 --> 24:35.320] You see projects that don't actually provide the encryption they claim to provide. [24:37.780 --> 24:39.860] We need an ethical standard. [24:40.460 --> 24:54.880] A way for people to be convinced that if they are not meeting some minimum quality guarantees and some minimum steps, they are not actually providing a tool that should be released to the public or recommended for use by actual people in difficult circumstances. [24:55.640 --> 25:04.020] So that's the first thing that we sort of need to do to come to a place where we can release tools that we have confidence in. [25:05.040 --> 25:09.180] And the way we test that confidence is by doing things like peer review. [25:09.640 --> 25:14.120] Peer review is the big thing that most tools are not doing. [25:14.440 --> 25:22.100] It is the one thing we could do to improve quality as a community that we are by and large not doing. [25:22.620 --> 25:31.900] I talked to a bunch of projects a couple months ago, about 20 different projects, and I asked them why... I asked them if they were doing peer review. [25:32.060 --> 25:34.600] And the answer was, in almost all instances, no. [25:36.360 --> 25:37.740] And asked them why they weren't. [25:40.040 --> 25:41.500] I got several responses. [25:42.100 --> 25:47.520] The first was that the code is open-source, and so anyone can look at it. [25:48.560 --> 25:51.440] And so we don't need to subject it to formal peer review. [25:51.600 --> 25:58.420] We don't need people to look at it in a... We don't need to get people to look at it, because the code is open, and anyone can look at it at any time. [25:58.560 --> 26:04.580] And anyone who has a need to depend on it can verify whatever security guarantees we care to make. [26:05.680 --> 26:10.660] And the problem with that attitude has always been that, at the end of the day, no one actually does look at it. [26:11.300 --> 26:17.160] At the end of the day, when people put code up on a website and say, it is open, you can look at it. [26:17.740 --> 26:23.800] If they are not guaranteeing that somebody qualified to review it does look at it, then it hasn't been reviewed. [26:24.240 --> 26:26.120] Reviewable and reviewed are not the same thing. [26:26.520 --> 26:38.980] So that's one problem, is that the view that because the work we do is open-source, that it somehow magically, automatically gets reviewed by a community of people who need to rely on it. [26:39.300 --> 26:40.480] So that doesn't happen. [26:42.220 --> 26:47.940] The second big obstacle was really resources. [26:49.120 --> 26:55.080] Open-source projects are strapped for attention, strapped for cash, strapped for labor, strapped for hours to write code. [26:56.000 --> 27:04.080] Most of the people who work on free software projects really want to work on those projects and make them better and build them out and make them more capable. [27:04.840 --> 27:12.580] But they don't spend a lot of time doing the hard things, the boring things like writing documentation and auditing code. [27:13.060 --> 27:24.840] And so when we, when we see projects that don't have extra cycles, they don't have people who are dedicated They don't have people who are dedicated to doing the peer review and the auditing. [27:25.880 --> 27:33.840] And even if they do have extra cycles, none of those extra cycles reside in people who have the requisite skill to do peer review and auditing. [27:34.960 --> 27:42.240] So that's one of the major obstacles to getting it done is that even if a project thinks it's really important, they don't know how to go about getting it done. [27:42.460 --> 27:56.700] They have no money to hire someone to do it, and they have no people on staff who are capable So they're going to do the best they can to write the best code they can, to do the best design they can, and subject it to whatever internal review they can give it, [27:57.180 --> 28:02.740] but they're not going to do peer review for the simple reason that they don't quite have the ability. [28:04.760 --> 28:12.220] What I would like to do, in terms of peer review, is to provide community-based structures to do peer review for each other. [28:13.600 --> 28:18.620] There are tons of people who have the ability to do this sort of work within our community. [28:19.780 --> 28:27.000] We haven't organized those people to attach them to projects on a serial basis, on a long-term basis, to actually do peer review. [28:27.200 --> 28:45.140] We haven't tried to get those people to do it in a manner that will give projects turnkey peer review, that will give projects basic education in simple things like threat modeling, that will teach projects how to take code, put it in a repository, and say exactly what it is they expect it to do, [28:45.660 --> 28:49.700] and then to hand it to someone and say, guarantee that it does actually do those things. [28:51.160 --> 28:53.220] To test it to see that it does those things. [28:54.560 --> 28:55.980] We can assemble that talent. [28:56.140 --> 28:57.040] We have that ability. [28:57.180 --> 29:01.940] We have people in our community who care, who have the time, and who would be willing to do it. [29:01.940 --> 29:08.960] It is going to take some organization, and I am right now looking for people who are willing to take that time with me. [29:09.180 --> 29:16.800] Who are willing to put some energy into organizing a project to do peer review and to make it available to as many projects as we can. [29:17.300 --> 29:24.700] From things low level in the stack, like SSL and SSH, on up to things that people rely on on a daily basis. [29:27.900 --> 29:35.880] The next thing that we are trying to do within our community is create a central place for people to find this software. [29:36.040 --> 29:40.500] I said earlier that we don't have reputable distributors of software, certainly not centralized ones. [29:40.760 --> 29:42.880] But the truth is, we can make that. [29:43.340 --> 29:47.000] We can make an app store for security tools, for circumvention tools. [29:47.160 --> 29:51.540] We can do one-stop shopping that installs with one click, suites of tools. [29:51.980 --> 29:54.820] This is not a thing that we are unable to do as a community. [29:54.820 --> 30:01.560] The reason we have never done it is that projects are working in silos and projects don't have the spare cycles to get it done. [30:02.740 --> 30:07.340] But if we start assembling people who are specifically tasked to do just that, we can do it. [30:07.420 --> 30:12.600] There are several volunteers who have started pulling together a centralized repository of these tools. [30:12.620 --> 30:16.940] A place where we can distribute tools that we know aren't filled with malware. [30:18.500 --> 30:20.100] That project needs volunteers. [30:20.360 --> 30:25.320] That project needs people who are willing to help design, code, and promote. [30:25.700 --> 30:26.140] Right? [30:26.380 --> 30:30.520] And an app store is a thing that would connect up to the peer review. [30:31.260 --> 30:48.860] Because if you are running an app store that wants to connect users with solid tools that have a good reputation, you would give users information about which of those projects have gone through formal review, and have been tested to apply to specific use cases. [30:49.240 --> 30:58.940] And you would allow users to specify their own use case, and have the app store recommend tools that apply to them, possibly even in their locale. [31:00.120 --> 31:04.080] This is rather sophisticated stuff, but it's not actually that difficult. [31:04.440 --> 31:04.520] Right? [31:04.720 --> 31:06.840] It's just some front end work and some database work. [31:08.160 --> 31:10.480] And it's something users desperately need. [31:10.600 --> 31:16.440] It is the missing step between making good tools and users actually getting those good tools. [31:16.680 --> 31:20.340] It's providing them an interface for finding those tools. [31:21.000 --> 31:22.640] This is the project to do that. [31:22.900 --> 31:24.780] An app store would do it. [31:24.780 --> 31:29.920] You couple that with effective user support in real time via chat. [31:30.680 --> 31:32.660] You couple that with user training. [31:33.320 --> 31:38.160] And you start to have a solution that can actually get tools into people's hands in a usable way. [31:38.420 --> 31:45.460] You start to have a solution that will result in people being able to solve their own problems using information that we provide. [31:46.940 --> 31:50.900] The last thing that I think is really important is frequent in-person collaboration. [31:52.500 --> 31:54.960] This event, HOPE, brilliant. [31:55.420 --> 31:55.500] Right? [31:55.980 --> 32:04.720] There are other events where we get people together to do design work, to do planning, to work on the hard problems in this area. [32:05.160 --> 32:13.360] I was talking to some other people in the community about starting a monthly meet-up for people who want to work on these issues in New York. [32:14.000 --> 32:27.580] If you are interested in getting together to figure out how we can build an app store, to figure out how we can promote peer review, establish ethical standards and community standards, this is how you can reach me. [32:28.080 --> 32:33.000] We have a ton of ways in which we can move the ball forward. [32:33.160 --> 32:33.240] Right? [32:33.340 --> 32:41.920] There are so many different ways in which we are lacking, that we have so many different opportunities to improve the landscape for circumvention tools. [32:41.920 --> 32:47.120] If you are interested in improving that landscape, there are a million things that we could be doing. [32:47.680 --> 33:04.420] We are going to start trying to get people together in this town to talk about these specific issues on a regular basis, to attach new projects, to establish these standards, and to create effective ways to connect users with the awesome tools we already have, [33:04.420 --> 33:10.540] and effective ways for developers to improve the tools that already exist, and to create new tools. [33:11.500 --> 33:16.720] So at this point, I'd like to talk to you as an audience, and find out where you stand. [33:17.040 --> 33:22.520] What are your thoughts on what is lacking in the area of effective tool making and usage? [33:22.860 --> 33:26.360] What is it that you have done that has worked, and what is it that you have done that hasn't worked? [33:26.360 --> 33:27.280] Thank you. [33:39.720 --> 33:42.700] Okay, I don't have answers to those last questions, but... [33:42.700 --> 33:43.540] I want answers. [33:45.260 --> 33:46.520] I can handle the truth. [33:47.680 --> 33:48.940] You'll need thumbscrews. [33:50.160 --> 33:53.280] No, but it did shake a number of thoughts loose. [33:54.460 --> 34:06.800] One of the things that has helped with open-source, in being able to believe that something is open-source, is the existence of an organization like the Open-Source Institute, that certifies open-source licenses, and has a mark. [34:07.460 --> 34:16.120] So, you might consider having some kind of an organization that has a mark, so that people can trust that mark. [34:17.640 --> 34:21.040] Another is, when you're talking about peer review... [34:21.040 --> 34:23.200] Well, peer review is a big thing in academic circles. [34:23.980 --> 34:33.300] Only, you don't get peer review for... necessarily for reviewing the kind of software that you're talking about creating, unless it's within a narrow academic niche. [34:33.960 --> 34:53.360] You might be able to work through professional societies, like IEEE or ACM, to try to begin to change some of those standards of professional service to the community, because that is often an important component of what universities are looking for, say, [34:53.460 --> 34:53.860] for tenure. [34:54.360 --> 35:01.020] And you want to be able to say, I have participated in peer review that is meaningful within my professional community. [35:02.920 --> 35:07.300] So, that may be another avenue where you can get more people. [35:07.840 --> 35:18.420] Also, you may even be able to work out some kind of program where students of sufficient ability can get some kind of credit or recognition for auditing code. [35:18.840 --> 35:22.640] And that's a great way, by the way, to teach students to comment their own code. [35:23.660 --> 35:24.240] Okay. [35:25.720 --> 35:42.700] And last comment here is, one of the most important things that occurred to make Linux and free and open-source software usable and acceptable to a wider audience was the establishment of distributions, distros. [35:43.240 --> 35:48.280] Basically, you get all the pieces together, and then you make them play nice and give a unified user experience. [35:48.280 --> 35:55.860] We may want to think about encouraging or doing the creation of what are essentially security tools, distros. [35:56.220 --> 36:00.960] We might have, you know, whatever the name might be. [36:01.100 --> 36:04.080] There's this distro, there's that distro, there's that distro. [36:04.700 --> 36:22.060] And instead of having to pick and choose from an app store and its recommendations, you might have one that's like, you know, the Middle East, you know, the Middle East distro for people working in a place like Syria with a highly technical government coming down on you. [36:22.380 --> 36:23.940] You pick that, download it, and there you go. [36:24.040 --> 36:25.620] You've got all the tools nicely integrated. [36:26.940 --> 36:27.340] Sure. [36:27.360 --> 36:29.380] I think those are all really good ideas. [36:30.220 --> 36:45.220] The app store, as it has been currently proposed by Harlow Holmes from the Guardian Project, includes this notion of installing suites of tools, which I think might amount to something like a distro. [36:45.980 --> 36:53.440] Perhaps even images from USB keys that you could reboot to, to put your computer in a state that would provide secure communication. [36:53.440 --> 36:55.760] And I think, I do think that's a really good idea. [36:55.960 --> 37:00.860] And I hope that we will eventually get to the point where that becomes as easy as I think it should be. [37:01.180 --> 37:01.720] Thank you. [37:03.920 --> 37:09.480] So for some undergrad coursework, I recently had a group project with a Chinese MSIT student. [37:10.240 --> 37:15.680] And I thought it'd be a great idea to teach him how to use Tor, because I knew he'd be going back to China soon. [37:15.680 --> 37:26.520] And I found it really difficult to explain to him why he needed to use Tor, which I thought would be actually pretty easy, considering China's reputation with censorship. [37:26.980 --> 37:32.580] And the only way that I could convince him to use Tor would be to say that it would get him to Facebook. [37:32.880 --> 37:42.000] So I found it both interesting and frustrating what it takes to convince someone who is even as technical as an MSIT student, why they need to care about privacy. [37:42.640 --> 37:58.700] And to use these tools, so my suggestion is that we, for a project like this, would have to really focus on convincing people, either end users or even technical users, to care about their privacy and put it in the proper context of what it will do, even if it's as simple as this will get you to Facebook. [37:59.340 --> 37:59.700] Sure. [38:00.080 --> 38:12.580] You know, the interesting thing about the use case in China is that for the vast majority of users, the penalty for trying to get to CNN.com is that sometimes you can't get there. [38:14.580 --> 38:28.080] Most users in China, when I talk to Chinese activists, most users who are sort of day-to-day, just trying to get information about the world users, really just want access and don't actually care about privacy. [38:28.400 --> 38:37.760] They don't feel like there are any penalties to trying to access that information, to even having government know you're trying to access that information. [38:38.140 --> 38:50.500] And when I talk to people who are trying to aid people in China as a broad class, most of the time what they ask me for are tools of access, not tools of anonymity or tools of privacy. [38:51.000 --> 38:59.500] There is, of course, a strong subsection of true activists, as we think of them as daily activists, who do need anonymity and privacy. [38:59.860 --> 39:07.040] But those people, by and large, are focused on a different set of tools than their neighbors. [39:07.580 --> 39:15.100] And so this goes back to the really important consideration of knowing what is the threat model that your users are facing. [39:15.360 --> 39:19.420] What are you actually trying to get them accomplished, right? [39:19.900 --> 39:21.340] Am I worried about my mother? [39:21.460 --> 39:22.700] Am I worried about my neighbors? [39:22.860 --> 39:23.900] Am I worried about my government? [39:23.900 --> 39:28.620] And once you know who you're worried about, then you have to know what are you worried about them doing? [39:28.880 --> 39:30.180] What are you worried about them preventing? [39:30.600 --> 39:39.340] And in the case of Chinese users, you have a few different use cases, but the vast majority of people really just want uncensored, unblocked access. [39:39.620 --> 39:46.080] And we can provide them tools that are less heavyweight than Tor, and a lot of those people are going to be just fine. [39:46.080 --> 39:56.800] And so the interesting thing about trying to teach a Chinese grad student how to get to Facebook is that Tor is actually a good tool, but maybe not the best tool. [39:56.980 --> 40:02.160] There might be a better tool out there for him that would get him what he needs without the penalties that come along with Tor. [40:02.840 --> 40:05.040] But yeah, definitely an interesting situation. [40:05.260 --> 40:05.620] Thank you. [40:06.180 --> 40:06.740] Thank you. [40:08.180 --> 40:09.120] Thanks for the talk. [40:09.380 --> 40:15.400] So I'm a coder, but my academic background is really UI and design and art, really. [40:15.400 --> 40:20.980] And I'm constantly frustrated by basically all these things that you've been talking about. [40:21.240 --> 40:33.800] And I'd love to help, but I'm wondering specifically what those vocabulary differences, issues are around, as you see it, or anyone else who does consider themselves a hacker more than an artist. [40:34.260 --> 40:36.120] What are those barriers? [40:36.320 --> 40:39.060] How do we start breaking down those divides? [40:39.060 --> 40:43.200] So there's a few places where the breakdown happens. [40:45.000 --> 40:46.840] One is in recruiting, right? [40:46.960 --> 40:52.080] Just getting people who have design and UX chops into projects. [40:52.320 --> 40:54.100] The recruiting looks a little bit different. [40:54.220 --> 40:55.800] The value proposition looks a little bit different. [40:55.800 --> 41:11.940] If you're trying to pull people in who are not from our subculture, you're approaching people who are oversubscribed in terms of work opportunities, and turn down requests for all kinds of free this, that, and help this, that every day. [41:12.860 --> 41:15.940] And so you're already approaching people who are primed to say no. [41:17.340 --> 41:24.500] The first step in recruiting is helping a person understand why this area is a place to put time and energy. [41:25.480 --> 41:33.880] And once you can sort of convince somebody that this is a charitable thing to do, a lot of times pulling them in and showing them how fun our world is becomes the second step. [41:33.880 --> 41:39.500] And typically, as hackers, we approach people the other way around where we bring people in socially. [41:39.660 --> 41:49.840] And it's interesting because I've seen both things work, but with a lot of UX people, the conversation has started with how important this work is and how urgent this work is. [41:49.940 --> 41:51.160] And that's been rather effective. [41:52.720 --> 41:58.360] In terms of integrating UX people into projects, that is a hard thing to do. [41:58.440 --> 42:02.380] And I'm not going to pretend that I know how to do it because I have tried and failed several times. [42:02.380 --> 42:16.340] But what I've seen work in other projects is finding people who have both UX design experience, but also have some technical ability and are willing to engage with the technology a little bit to learn it. [42:16.540 --> 42:21.320] Layering UX people on top seems to fail more often. [42:21.680 --> 42:31.300] Layering UX people on top and trying to describe this as a user product that needs to be engaged from that perspective often fails. [42:31.300 --> 42:45.160] There is a crucial step in teaching the user experience person how the product works at a technical level that enables them to translate that into a language that users can understand. [42:45.780 --> 42:50.420] And so there are a few tools that have pretty good user interface and user experience design. [42:50.420 --> 43:02.520] And when I run them down and try to talk to the people who are actually doing that work, those people always seem to have a higher degree of sophisticated knowledge about the tool than I've seen in other projects. [43:02.860 --> 43:04.840] So that seems to be the key to me. [43:04.940 --> 43:07.140] But again, I'm not going to say that I have answers. [43:07.500 --> 43:08.560] That makes a lot of sense. [43:08.760 --> 43:08.980] Thanks. [43:09.200 --> 43:09.460] Thanks. [43:14.200 --> 43:14.640] Hi. [43:14.920 --> 43:21.420] So I'm an activist and I spend most of my time around people who really have no clue what they're doing with technology. [43:21.420 --> 43:35.860] And so my experience in terms of the tools that activists need is like first and foremost, they need to actually understand the technology they're using before they can even get to the point of being able to use it securely. [43:36.220 --> 43:47.240] And I think that very, very frequently with a lot of the tools, even if we tell them how to use it, that there's no chance they're going to be able to because they just don't get it. [43:47.440 --> 43:53.820] I mean, I think a good example is you mentioned that installing a lot of these tools in Windows can be cumbersome and a long process. [43:54.080 --> 44:00.000] But even more than that, it's frequently going to be the first time that many of these people have tried to do anything like it. [44:00.000 --> 44:03.000] So they have no idea if it worked, really. [44:03.420 --> 44:09.440] And if it didn't work, they have no clue where it failed because it is completely outside of their experience. [44:09.760 --> 44:21.720] So I guess, is there any kind of effort to do education supporting these tools that's really much, much more basic education to get people up to that point? [44:23.780 --> 44:31.700] So, some projects are really good at providing user support, even real-time user support. [44:32.720 --> 44:39.800] Unfortunately, a lot of that takes the form of chat through IRC, which is not a thing that most Windows can get to. [44:40.460 --> 44:44.480] So, you know, Windows users have never used IRC by and large. [44:44.600 --> 44:45.560] So that's a problem, right? [44:45.600 --> 44:47.580] We have a gap in user support. [44:48.720 --> 44:58.060] I don't know how to close that gap except to say that we need to recruit people whose job it is to just close that gap, right? [44:58.080 --> 45:00.200] That's not a gap that's going to be closed by developers. [45:00.200 --> 45:06.380] That's a gap that is going to be closed by other people associated with projects that decide that it's their mission to close that gap. [45:07.960 --> 45:14.400] And you've seen projects that some of them have good documentation, but they're not doing what you're describing, right? [45:14.400 --> 45:21.220] They're not describing all the different ways it could fail and all the different responses to those failures and ways to gain more information about it and then overcome those failures. [45:21.420 --> 45:25.120] Because that's a thing that we don't tend to document on almost any project. [45:26.500 --> 45:28.820] So that's... those are problems. [45:29.020 --> 45:31.280] Again, I do not have solutions to those problems. [45:31.280 --> 45:46.120] If there are people who want to create a real-time chat support mechanism, you know, might be based on IRC, but doesn't require anybody to download an IRC client, then we've got the start of something. [45:46.380 --> 45:50.660] But until then, we're going to have lots of people fail out at the installation level. [45:50.900 --> 45:52.580] And again, that's going to be a shame. [45:52.580 --> 46:01.740] So one response to this problem has been live CDs, USB keys that you can reboot and everything's all installed for you. [46:02.380 --> 46:10.580] And if you can convince people that it is worth rebooting their computers to have secure communication, you can skip over all of the installation steps. [46:10.860 --> 46:16.320] Now, there are massive problems with usability associated with taking users out of their own environment and sticking them into a new one. [46:16.320 --> 46:20.060] And leaving behind all their data and all their known applications. [46:20.680 --> 46:22.240] But you do solve that problem. [46:22.540 --> 46:29.400] So the approach, really, is to do this other thing, which I don't actually think is always the best approach. [46:29.840 --> 46:30.680] So thank you. [46:33.810 --> 46:38.570] Yeah, so you are part of the Freedom Box project, or you're involved with that as well? [46:38.870 --> 46:39.130] Yes. [46:39.570 --> 46:43.470] I mean, what are the possibilities of having, like, a privacy box, right? [46:43.470 --> 46:45.650] I mean, something that's specifically... [46:45.650 --> 46:47.910] I mean, I can see my grandmother, right? [46:48.050 --> 46:52.110] Like, she's not going to take a CD, she's not going to install something, but she'll plug something in. [46:52.410 --> 46:57.350] So what, you know, what kind of possibilities revolve around that having, you know... [46:57.350 --> 47:02.770] You could even have particular devices for particular types of threat levels or particular areas, et cetera, et cetera. [47:03.090 --> 47:10.530] Yeah, the problem with that is that it's really, really hard to do that in an effective and comprehensive way. [47:11.910 --> 47:14.150] Privacy means so many different things to so many people. [47:15.170 --> 47:26.550] That for me to magically intuit what privacy means in terms of your family member, who you can magically see, I don't know how we would do that, right? [47:26.670 --> 47:42.430] So the best we can do is sort of describe ways in which people might want privacy, and then provide mechanisms they could get it, and the number of permutations you could get out of that to stick them in one place and have somebody say, I just plug this in and I have privacy, [47:42.870 --> 47:44.650] that I don't think we're ever going to get there. [47:44.750 --> 47:50.170] I think we're always going to have some branching that's going to need to get done in order to provide people with stuff. [47:50.290 --> 47:57.130] Now, we can sort of identify a universal subset and try to provide that, but I don't think that quite gets us there. [47:57.590 --> 48:00.770] Well, in terms of, let's just bring it down to one audience then. [48:00.890 --> 48:06.710] Let's say that the completely non-technical person who will never do anything to their computer, right? [48:06.810 --> 48:09.030] The person who's never going to install anything and never do anything else. [48:09.030 --> 48:10.630] What do you do for that subset? [48:10.790 --> 48:16.430] Which is, those are all the people who are going to get taken off, you know, with the DNS changer thing. [48:16.550 --> 48:18.130] Those are all the people who are going to have zombie PCs. [48:19.150 --> 48:21.630] Those are all the people who, you know, all they do is turn it on and off. [48:21.630 --> 48:27.490] Like, that's a big subset of people who are at the back end of the bell curve of technology adoption. [48:27.750 --> 48:30.850] So, can we do something to solve that problem? [48:32.210 --> 48:37.390] Yeah, I mean, I think those are the people that Freedom Box is aimed at to some degree. [48:39.250 --> 48:45.430] The closer we look at it, every time we peel back a layer, we discover five more branches and more complexity. [48:45.670 --> 48:46.770] It's a very hard problem. [48:46.770 --> 48:56.690] So, we are trying to chip off pieces of functionality one by one and put privacy and security pieces in place, right? [48:56.870 --> 49:05.030] So, we can provide a transparent HTTP and HTTPS proxy that will do things like remove tracking cookies. [49:05.270 --> 49:06.310] We can do that. [49:06.430 --> 49:09.670] We can try to upgrade your connection to SSL wherever possible. [49:09.670 --> 49:11.870] So, we can chip off these individual pieces. [49:11.870 --> 49:21.530] But, one of the interesting things is that without access to direct computers, there's only so much that intermediary servers can do. [49:21.790 --> 49:29.370] So, for example, it would be really great if a privacy box or a Freedom Box could munch your browser fingerprint. [49:30.150 --> 49:30.750] Right? [49:30.810 --> 49:38.290] You've all seen Panopticlick, where we can uniquely identify your computer by its characteristics, by what's installed on it, the fonts and the plugins. [49:39.830 --> 49:49.750] And that stuff, you know, if you go to EFF and look at Panopticlick, you will discover that your browser is relatively unique down to one or two other browsers in the world probably. [49:51.910 --> 49:58.010] I sat down and I tried to figure out how the Freedom Box would change your browser fingerprint. [49:58.390 --> 50:00.690] Try to make you look like other boxes on the Internet. [50:00.690 --> 50:05.850] And it turns out that all that stuff happens in the browser and it's not stuff that passes through the HTTP stream. [50:05.990 --> 50:06.050] Right? [50:06.150 --> 50:08.290] It's your flash that's giving you up. [50:09.130 --> 50:17.210] And if somebody hits something over SSL, intermediary servers never have a chance to get in there and say, no, don't do this ugly flash thing. [50:18.850 --> 50:20.270] So, there's only so much we can do. [50:20.430 --> 50:25.390] We're going to provide protection for intermediary users wherever we can, but it's going to be really tough. [50:25.390 --> 50:33.550] If people have good ideas as to what that subset is and have implementations that will do it, we will stick it on a box and distribute it to everyone we can. [50:33.950 --> 50:35.490] But yeah, that's definitely the approach. [50:35.710 --> 50:42.170] Having a simple plugin thing that anybody can use, that is the thing that we would like more than anything else in the world. [50:42.750 --> 50:43.630] So, thank you. [50:44.970 --> 50:50.950] So, I'm out of time and I want to thank everybody for listening and for the great comments. [50:50.950 --> 50:54.810] And I hope that some of you will contact me afterwards and that there are ways we can work together. [50:55.030 --> 50:55.470] Thank you.