[00:01.980 --> 00:03.380] Good morning everybody. [00:03.800 --> 00:06.540] Welcome to the 15th edition of HOPE. [00:07.680 --> 00:10.900] For how many people in the audience is this their first HOPE show? [00:11.140 --> 00:12.520] Wow, you're kidding. [00:13.640 --> 00:14.560] That's amazing. [00:14.780 --> 00:18.880] I was here at the first one in 1994, believe it or not. [00:19.000 --> 00:19.840] That's how old I am. [00:20.020 --> 00:21.080] I was 15. [00:21.760 --> 00:22.040] It was amazing. [00:22.120 --> 00:23.120] You were here at the first one too? [00:23.280 --> 00:23.820] I love it. [00:24.220 --> 00:24.660] Fantastic. [00:24.660 --> 00:31.000] So we have got, I think, a really special and exciting program for you today. [00:31.220 --> 00:34.400] And we're going to jump right into it here. [00:34.500 --> 00:40.800] I'm going to tell you about some of the amazing people that we have on this panel are Cooper Quinton with the EFF. [00:41.040 --> 00:48.500] We've got Lorax Horn with Distributed Denial of Secrets, as well as the inimitable Emma Best from Distributed Denial of Secrets as well. [00:49.200 --> 01:01.260] Cooper, unfortunately, had an issue with a family thing and couldn't make it over here, but he is with us, as you can see on the screen, and will be beautifully interrupting us throughout the presentation. [01:02.140 --> 01:27.660] We have a really cool story to tell you here about the intersection of essentially cybersecurity, investigative reporting, lawfare, global legal issues, the misuse of process, you know, valiant, incredibly dashing reporters coming into this space and making sure that we're all getting the right [01:27.660 --> 01:41.040] information when it comes to threat intelligence and about this incredibly interesting espionage-as-a-service hacker-for-hire company that has been run out of India for some many years now, called Appin. [01:41.040 --> 01:53.340] And so, this all started with a Reuters investigation by a really extraordinary reporter from Reuters by the name of Raphael Satter, who's not only a colleague, but also a dear friend of mine. [01:54.320 --> 02:13.960] And Raphael published this investigative, this kind of really, I think, very powerful reporting that was based on a massive number of documents and sources that they had reviewed, and literally, quite literally, thousands and thousands of documents, about an Indian cyber espionage firm that grew up [02:13.960 --> 02:16.520] out of an educational startup. [02:16.720 --> 02:20.920] And we're going to talk a bit more about the origin story of this particular espionage-as-a-service company. [02:20.920 --> 02:37.140] But over the last ten years or so, this company and its progeny, the very many tentacles that have come off of the Appin service itself, they've targeted a huge number of executives, of companies, of politicians. [02:37.600 --> 02:44.720] They've targeted the military-industrial complex in the United States, government contractors, military officials, politicians, so many others. [02:44.720 --> 02:51.360] And their services were used not only within the United States, but in Switzerland, all around the world. [02:52.820 --> 03:01.260] It's pretty prolific how far that this Indian hacker-for-hire operation and espionage-as-a-service has really reached globally. [03:01.560 --> 03:10.900] And I think what's quite fascinating about this is, despite the really comprehensive reporting, the sources, the documentation, etc., the full measure and extent of the targets is unknown. [03:11.240 --> 03:23.500] And whether they are still operating in some form or another through a separate corporate entity or some kind of subsidiaries is really not entirely known right now, but in my opinion, it's quite likely. [03:25.380 --> 03:27.960] This was a really fascinating startup. [03:28.260 --> 03:33.300] And just like a lot of startups, they engaged in a pretty aggressive marketing campaign. [03:34.540 --> 03:38.220] And Reuters was able to identify 17 pitch documents. [03:38.360 --> 03:40.840] So like I mentioned, this wasn't the only stuff that they had reviewed. [03:41.020 --> 03:45.760] But these pitch documents were essentially their menus of services, and they were really kind of fascinating. [03:45.760 --> 03:51.480] And they offered these services to a huge number of private investigation firms around the world. [03:51.620 --> 04:00.580] And private investigation firms, as we all know, are very often hired by lawyers to investigate their opposition in some kind of litigation, especially in commercial litigation. [04:00.580 --> 04:08.520] We saw that happening very, very much with Appin in litigation in London and elsewhere around the world. [04:08.800 --> 04:15.920] So a lot of their services that they were marketing were for things like email monitoring, cyber warfare, spying, social engineering. [04:16.040 --> 04:17.920] They were really, really good at what they did. [04:17.960 --> 04:24.780] And what they created was this fascinating e-commerce platform for cyber-related criminal activity. [04:25.600 --> 04:26.940] And it got ahead to them. [04:27.040 --> 04:27.640] It was very innovative. [04:28.140 --> 04:29.060] And they did it. [04:29.120 --> 04:33.100] And they created this portal called My Commando. [04:33.660 --> 04:36.040] And by the way, I should mention, I'll just step back for one second. [04:36.240 --> 04:45.440] So all of the art that we have in the slides throughout this, it's all real art that you can find entirely at the Saatchi Gallery in London. [04:45.440 --> 04:52.700] So if you're thoroughly bored by anything we're saying, at least you have some real art to amuse you for the next 45 minutes or so. [04:53.260 --> 04:58.220] So this My Commando system was an espionage service. [04:58.220 --> 05:06.480] It allowed you to, like you were tracking an Amazon package in many respects, to follow your operative's activities online. [05:06.920 --> 05:10.180] And it was a very organized, very accessible platform. [05:10.180 --> 05:12.340] It seemed like the clients really liked it. [05:12.480 --> 05:26.640] And at the end of the process, after your operative had compromised whatever the target was, exfiltrated the data, archived it, then they would send you a handy link and you could download the package of this exfiltrated stolen data from your target. [05:26.640 --> 05:30.060] So it was all buttoned up for you and trackable. [05:30.720 --> 05:34.600] Kind of bizarre when you think about this, but very, very innovative. [05:35.180 --> 05:39.980] The other thing that was fascinating is that they targeted lawyers too. [05:40.240 --> 05:49.420] And I've often said this, that lawyers, and being a lawyer myself, I think that big law firms are very often the soft underbelly of their clients. [05:49.420 --> 05:58.340] And there were significant commercial litigations going on with this Appin Company, into which rather this Appin Company had peered. [05:58.520 --> 06:01.980] One of the more prominent ones was Berezovsky v. [06:02.200 --> 06:10.720] Abramovich, which was a commercial litigation that was happening in London at the time, in the British courts that pertained to the sale of an oil company. [06:11.280 --> 06:17.240] And it did seem like Berezovsky was, I believe, the party that was targeted. [06:17.520 --> 06:21.140] Abramovich wound up, I believe, prevailing in that litigation. [06:22.040 --> 06:30.900] And it's unclear, I think, to what extent Appin had influenced that litigation, but it does seem like they may have had some kind of involvement in it from the outset. [06:31.320 --> 06:36.380] Like I mentioned, you know, lawyers can be very much some of the easiest targets out there. [06:37.020 --> 06:43.400] So the name Appin itself comes from these two terms, approaching infinity. [06:43.680 --> 06:46.980] Sounds very futuristic in many ways, right? [06:47.160 --> 06:48.780] But they have this origin story. [06:48.940 --> 06:56.100] Like every good startup, these guys were scrappy and hungry, and they were looking for something better. [06:56.200 --> 06:58.560] They wanted to make the world a better place in some ways or another. [06:58.720 --> 07:03.860] And so they got together at, I believe it was a Domino's pizza joint in New Delhi. [07:03.860 --> 07:16.340] And on the basis of one of the founders of Appin, Rajat Khareg, you know, they claimed that India had so many smart people, but there just wasn't enough training out there. [07:16.420 --> 07:17.660] There wasn't enough IT training. [07:17.760 --> 07:18.920] There wasn't enough programming training. [07:18.980 --> 07:21.160] And so they wanted to change that. [07:21.420 --> 07:24.020] So they created these technical schools. [07:24.280 --> 07:33.120] And that was the whole idea, was to train Indian programmers, to train people to understand cybersecurity, to train them on various aspects of information technology. [07:33.120 --> 07:40.860] And at the time, it was really prescient as well, because IT outsourcing was becoming extraordinarily popular over in India. [07:41.620 --> 07:44.780] They then migrated into the cybersecurity space. [07:44.920 --> 07:51.360] And when they migrated into the cybersecurity space, my understanding is that they attracted the attention of the Indian government. [07:51.540 --> 07:57.460] And the Indian government realized there were a bunch of talented individuals working within and around the Appin sphere. [07:57.460 --> 08:05.580] And this eventually wound up with the Indian government employing Appin for various cyber espionage-related purposes. [08:05.580 --> 08:07.320] That's my understanding of it. [08:07.500 --> 08:23.260] To the point where many of these operatives that were working for Appin on these various projects, perhaps for the Indian government itself targeting its adversaries, Pakistan, et cetera, wound up living in safe houses that were prepared by the Indian government for these particular operatives that were essentially government contractors. [08:25.660 --> 08:36.440] So moving on, we find that after several years of this cyber espionage as a service, people started to think about Appin in very curious ways. [08:36.580 --> 08:39.040] They started to become the targets of various investigations. [08:39.040 --> 08:47.580] There was some Appin involvement in FIFA or, you know, football-related negotiations in Switzerland. [08:47.760 --> 08:53.380] There was a Swiss investigation that seemed to have crossed over with an FBI investigation in the United States. [08:53.660 --> 09:09.440] There was a Dominican case of, I believe it was a journalist who was utilizing the services of Appin, some kind of media organization over there that was looking for information on politicians in the Dominican Republic. [09:10.020 --> 09:22.200] And I believe that there was a case in the DR that actually named the founder Rajat Kari, as well as another breach in Norway for the telecommunications company called Telenor. [09:22.200 --> 09:43.700] And an investigation on the Telenor side led directly to IP addresses that were associated with Appin, which also makes you think how easy or how silly were they being in terms of their operational security if you can just simply take a look at an IP address and link it back to a particular threat actor. [09:44.040 --> 09:53.920] So I don't know the extent or the levels that they had to uncover, but maybe they were really good at offense and not such great operatives when it came to defense. [09:54.040 --> 09:55.480] That happens a lot, right? [09:56.880 --> 10:08.760] So the point of this, though, is that Appin had become very well known to a lot of the intelligence services around the world and a lot of the governments, and it was attracting a significant amount of attention. [10:10.300 --> 10:11.840] So there's a lot of attention. [10:12.100 --> 10:26.080] There's investigations, but there really doesn't seem to be any justice when it comes to whether or not Appin could be held to account or its operatives could be held to account for the cyber espionage as a service in which they had been engaging for quite a few years at this point. [10:26.480 --> 10:30.720] So several lawsuits were filed against operatives, but nothing really happened. [10:31.100 --> 10:39.060] One of the fascinating aspects of this is that there was a criminal case here in New York, just a little farther east on Long Island. [10:39.340 --> 10:42.660] And this was for operatives, as I understand it... [10:42.660 --> 10:56.480] I'm sorry, this was a criminal conviction against private investigators who had hired Appin to spy on what I believe was the Shinnecock Indian Reservation in eastern Long Island. [10:56.620 --> 10:59.140] And there were some negotiations with the Shinnecock Reservation. [10:59.140 --> 11:07.240] Which just goes to show you how far-reaching and how kind of bizarre some of these investigations that Appin crossed over with were. [11:07.700 --> 11:18.640] So these were two guilty pleas, I believe, of private investigators in front of a federal district court judge in Central Islip, which is part of the eastern district of New York in federal court. [11:19.160 --> 11:21.060] But the filings don't name Appin. [11:21.220 --> 11:22.400] They don't mention Appin. [11:22.460 --> 11:23.420] They don't name them at all. [11:23.420 --> 11:28.420] And it was at this time that Appin started to disband its operations. [11:28.840 --> 11:33.920] A lot of its employees started to remove information from their LinkedIn accounts that mentioned Appin. [11:34.160 --> 11:40.100] There was the removal of a lot of online information about Appin, its history, its sources, its clients, etc. [11:40.840 --> 11:42.620] So there began to be this purge. [11:43.060 --> 11:44.700] They knew things were going south. [11:45.540 --> 11:50.420] But there weren't, coincidentally, any repercussions at all in India. [11:51.000 --> 11:54.380] And I'm guessing we can all probably figure out why that is. [11:54.520 --> 12:02.220] You know, they had most likely some kind of cover from the Indian government based on the contracts that they had been working on for the Indian government for some time. [12:02.400 --> 12:07.300] I mean, this is speculation on my part, but I think an educated guess, nonetheless. [12:08.240 --> 12:22.160] So moving on from here, even though Appin itself had disbanded, and this is really what we're dealing with today and over the last several years, you have these new monsters that have spawned. [12:22.240 --> 12:35.360] All these employees that had this incredible training, starting with, you know, hanging out in the dominoes in New Delhi and then refining and cultivating their espionage skills and cyber activity, social engineering. [12:35.540 --> 12:42.160] I mean, they came up with some really amazing phishing scams that I had seen in some of my research, some really, really good stuff. [12:42.720 --> 12:45.580] So they started their own companies. [12:45.760 --> 12:51.960] There's lots of subsidiaries that exist that are spawns of the original monster, which was Appin. [12:51.960 --> 13:00.020] And one of the holding companies, I find it is just kind of the most bizarre name for some of these subsidiaries, was Sunkist Organic Farms. [13:00.540 --> 13:07.720] I mean, something, you know, you couldn't get farther away from cyber espionage as a service than Sunkist Organic Farms. [13:08.300 --> 13:23.440] And then I believe the new government contracting wing was named Adaptive Control Security Global Corporate, which is just like a mumbo-jumbo nonsense conglomeration of, you know, corporate speak here, right? [13:23.760 --> 13:35.700] But another subsidiary or spawn of the Appin, the original Appin monster here, was something called the CyberRoot Risk Advisory Service. [13:35.760 --> 13:40.800] And I believe that was the entity that was involved with the targeting of Instagram itself. [13:40.800 --> 13:50.100] And then another really interesting crossover here, and here's where I think we can bring in Cooper as well, to talk a little bit about this, was Beltrox. [13:50.400 --> 13:58.480] And Beltrox, together with Citizen Lab, well, I'm sorry, Citizen Lab was investigating Beltrox. [13:58.600 --> 14:00.500] Beltrox and Citizen Lab were not working together. [14:00.620 --> 14:01.480] That would have been weird. [14:02.240 --> 14:04.200] That would have been something for the papers, right? [14:05.440 --> 14:09.080] So Citizen Lab had been investigating Beltrox for some time. [14:09.080 --> 14:20.460] I had also been tracking a threat actor that had been targeting a massive number of critical infrastructure companies within the United States with a bogus employee satisfaction survey. [14:20.720 --> 14:25.800] And a lot of the DNS data started to point to a person. [14:26.740 --> 14:33.640] You know, many years ago, maybe 2015 or so, there were a bunch of domains that were registered under the name of Amanda Lovers. [14:33.640 --> 14:38.460] And this Amanda Lovers was also associated... I know, very strange, yeah. [14:40.160 --> 14:45.680] Privately, I can discuss with you some other strange names that were associated with these operations. [14:45.940 --> 14:54.160] But Amanda Lovers was directly involved in the targeting of the Electronic Frontier Foundation as well. [14:54.320 --> 14:56.880] And Cooper, do you want to jump in and talk a little bit about that? [14:58.360 --> 14:58.920] Yeah. [14:59.220 --> 14:59.420] Yeah. [14:59.420 --> 15:09.620] I mean, the way that they were actually first identified is that they had left the stream happening all over their mouth, on one of their malware, I think. [15:10.000 --> 15:17.980] Which, I think, was called Operation Hangover, and that was by Norman Sharp was the first report on them. [15:17.980 --> 15:26.880] And they, like, in addition to having the SGPs that links them back to the database or so, they had left their company name all over their malware. [15:27.100 --> 15:29.120] So they're not, like, the greatest actors. [15:29.740 --> 15:32.240] They're not the sharpest students in the shed. [15:32.580 --> 15:33.080] You know. [15:34.920 --> 15:39.000] But they, despite this, right, they've been really effective. [15:39.260 --> 15:40.720] They're not on the sphere of Pensovers. [15:40.860 --> 15:42.880] They're not on the sphere of Dark Matters or something like that. [15:43.020 --> 15:44.440] They're not sending out extra things. [15:45.040 --> 15:45.140] Right? [15:45.240 --> 15:47.000] They're not sending out those, like, exploits. [15:47.000 --> 15:50.000] But what they're doing is sending out phishing. [15:50.220 --> 15:52.560] And they are increasingly good at phishing. [15:53.260 --> 15:56.460] By which I mean, people are incredibly bad at stopping phishing. [15:56.720 --> 15:59.560] And if you're prolific enough of it, you can almost all get through. [16:00.980 --> 16:06.000] So EFF has started investigating this original Amanda Hubbard's case. [16:07.000 --> 16:11.780] Because we had, we had received some targeting and Fight for the Future have received some targeting. [16:15.240 --> 16:20.740] And some of which were really, I thought, really clever at first. [16:21.240 --> 16:21.300] Right? [16:21.420 --> 16:26.500] One of them was an email from Hornhub about videos that you might like. [16:26.740 --> 16:28.800] And then there was a link in the bottom that unsubscribe. [16:29.460 --> 16:33.020] One of them took you to a fake blogging page or your own email account. [16:33.020 --> 16:42.060] If you can imagine that on your work email, if you get any of your Ornhub email, you're going to really quickly click that unsubscribe rate. [16:42.420 --> 16:46.920] So, I mean, it's actually a really good target for them. [16:46.920 --> 16:49.980] But all of their, again, they're offset to shit. [16:50.200 --> 16:53.920] All of their accounts were reached to any of your Ornhub's email address. [16:54.200 --> 17:00.000] So, it was really easy to sort of correlate all of the attacks into something like that. [17:00.300 --> 17:04.300] And then after we published, we kind of asked if I was also working on this. [17:04.580 --> 17:06.600] And we had ruined our report a little bit, unfortunately. [17:06.600 --> 17:12.280] which, I guess, led to better defeat, basically, between the two months after that. [17:12.540 --> 17:17.040] But, yeah, they're not a little sophisticated attackers. [17:17.360 --> 17:18.360] But, yeah, we are affected. [17:19.480 --> 17:20.380] Yeah, yeah. [17:20.700 --> 17:29.320] I mean, and this just goes back to what we were saying a few minutes ago, which is about the good attackers not necessarily being good defenders and vice versa here, too. [17:29.780 --> 17:39.480] But it also bears mentioning, too, that the original Beltrox reporting here was from the same investigative cybersecurity reporter at Reuters, Raphael Satter. [17:40.160 --> 17:47.700] And so, both of these stories that were kind of massive breaking stories about these Indian hacker for hire operations came from the same reporter. [17:48.480 --> 17:55.580] And so, they might have had some kind of inclination that Raphael was up to something here. [17:56.380 --> 18:03.500] But this Beltrox strand that I had been tracking as well, you know, was really extraordinary, too. [18:03.500 --> 18:11.880] And we saw a direct link from the Amanda Lovers' domains over to more sophisticated attacks, where the operational security got better and better and better. [18:11.940 --> 18:21.980] But what I had seen was around 1,700 companies in the United States, United Kingdom, Canada, and Australia being targeted, many of which were considered to be critical infrastructure. [18:21.980 --> 18:33.460] Some of them were government agencies as well from, you know, top-up, like, federal agencies themselves, federal departments, right down to local school districts in some areas. [18:33.460 --> 18:45.840] So, really kind of fascinating targeting and very effective, it seemed like, bouncing from one organization to another, perhaps even leveraging one breach for an ultimately larger target. [18:45.840 --> 18:47.860] So, really fascinating stuff. [18:48.380 --> 18:58.400] And speaking of this journalist, along comes Raphael Satter, and he publishes this expose on Appin on the 16th of November, 2023. [18:58.820 --> 19:01.160] All right, so this is a little bit less than a year ago. [19:01.640 --> 19:03.860] Now, what's fascinating here is, I'm going to jump down for a second. [19:03.860 --> 19:21.880] Before this story was ever even published, Appin had filed a lawsuit in November of 2022 seeking a prior restraint from a court in New Delhi to prevent Reuters from publishing that particular, this article about Appin. [19:22.880 --> 19:26.820] The order was later clarified and said, oh, it only relates to defamatory material. [19:27.680 --> 19:36.040] Reuters publishes this story, this massive breaking story, on the 16th of November, and then on the 4th of December of 2023. [19:36.040 --> 19:41.500] So this past December, the district court in New Delhi said, hey, this stuff looks like it's defamatory. [19:41.800 --> 19:45.300] So we are going to enjoin the publication of this. [19:45.420 --> 19:47.580] So they issued this preliminary order, injunctive relief. [19:47.780 --> 19:51.700] There was an injunction against Reuters from publishing that article. [19:51.860 --> 19:55.960] So Reuters had to comply with the court's order and take it down. [19:56.260 --> 20:03.640] But Reuters is right now engaged in litigation and is appealing that order as of this moment. [20:03.840 --> 20:06.940] I think the case is still winding its way through the courts in India. [20:07.320 --> 20:11.440] The courts in India are a little packed and a little crazy. [20:12.380 --> 20:18.680] So what happens next is where Distributed Denial of Secrets comes in. [20:18.680 --> 20:39.180] And the Association of Appin Training Centers, which became this successor organization that had the Appin name and was associated with these training centers, perhaps even hearkening back to the Domino's Pizza origin story of, hey, we're just here training people. [20:39.180 --> 20:41.740] And so they capitalized on that story. [20:42.000 --> 20:59.880] So there are a lot of lawsuits and legal threats that have been thrown around to engage, to take this court order from New Delhi, that applied to Reuters, and use it for this aggressive global campaign of censorship. [20:59.880 --> 21:03.720] And they have engaged a law firm in D.C. [21:03.900 --> 21:22.520] that is known to be a quote-unquote defamation-focused law firm here, to throw around that order and to wave it in front of various media organizations and say, hey, there's an order here that prevents the publication of this particular story, so you shouldn't report on it. [21:22.520 --> 21:23.880] You need to take this down, etc. [21:24.400 --> 21:29.240] And I want to pass it over to Lorox and Emma to jump in on some of these issues as well. [21:30.340 --> 21:41.760] So, Mr. Gideon and I think it started as a place for reporters to put their difficult-to-house document collections. [21:44.200 --> 21:55.360] And it happens a lot that people come to us and they're like, I think this set of documents is in the public interest to preserve, but my publication doesn't want to host all of this. [21:55.760 --> 21:58.100] I can only use one piece of it. [21:58.360 --> 22:05.240] Can you host the rest so that others can cross-reference, look for documents related to their own stories? [22:07.320 --> 22:14.240] But we've never published the text narrative side of an investigation before. [22:14.240 --> 22:17.360] We've previously just published document collections. [22:17.860 --> 22:21.860] And we have experienced censorship a lot as well. [22:22.200 --> 22:26.840] We've lost servers to police action. [22:27.200 --> 22:28.960] We have been banned from Twitter. [22:29.420 --> 22:33.960] We have been censored on Reddit and elsewhere. [22:33.960 --> 22:43.420] And so, we are sympathetic to the issue of research and research material being taken offline. [22:44.300 --> 22:49.980] We see ourselves as a library of these sorts of hard-to-house documents. [22:50.500 --> 22:54.060] And then, do you want to talk about this project? [22:54.060 --> 22:55.360] Sure. [22:55.700 --> 23:05.460] So, when the Reuters article was censored, as Alex kind of mentioned, they went further than just Reuters. [23:05.800 --> 23:09.640] They started contacting everyone that did secondary reporting. [23:10.260 --> 23:13.740] And all of those stories started getting taken down too. [23:14.060 --> 23:21.700] Either completely or just huge blocks of text would be removed or replaced with, you know, X's. [23:21.700 --> 23:26.920] And so, we weren't just seeing the censorship of one story. [23:26.920 --> 23:30.800] It was the entire narrative, the entire investigation. [23:30.800 --> 23:35.580] And it was a huge chilling effect, which is really disturbing to see. [23:36.180 --> 23:43.000] And, I mean, we're sympathetic to the journalists that had their work taken down because lawyers are going to lawyer. [23:43.660 --> 23:47.880] But it... Is everything okay? [23:48.440 --> 23:49.640] Yeah, you keep going. [23:49.820 --> 23:50.020] Okay. [23:51.140 --> 23:53.940] But it was still disturbing to see. [23:54.000 --> 23:58.140] So, we decided to launch what we called the Greenhouse Project. [23:59.060 --> 24:03.260] And as part of that, we preserved the original Reuters text. [24:03.280 --> 24:06.500] We republished it on DDoSsecrets.com. [24:06.940 --> 24:11.980] And we took all of the raw materials that were published along with it. [24:11.980 --> 24:14.560] We don't have the complete archive that... [24:14.560 --> 24:15.380] We don't have the complete archive that... [24:16.120 --> 24:16.700] Reconnecting. [24:17.300 --> 24:17.420] That... [24:17.420 --> 24:20.980] Yeah, Raphael Satter and the other journalists working on it used. [24:21.280 --> 24:27.560] But everything that they published, we preserved and made that available for raw download. [24:27.740 --> 24:30.300] We put it on a torrent so that it's difficult to censor. [24:33.100 --> 24:37.020] And thankfully, after that, we began seeing more discussion about it. [24:37.260 --> 24:50.640] Some journalists that had really wanted to talk about it for a while, but then unable to convince their editors and the legal team that it was worth it, suddenly had a reason that they were able to. [24:50.640 --> 24:52.080] They had something they could point to. [24:52.460 --> 24:56.580] And the original research was not being disappeared into the memory hole. [25:00.340 --> 25:06.140] And the reason we called it the Greenhouse Project was, as I mentioned, it was a huge chilling effect. [25:06.140 --> 25:14.880] And it's not just important to counter the raw censorship, but to counter that chilling effect. [25:14.880 --> 25:21.380] And so we wanted to create a warming effect that would make it harder for people to censor things. [25:21.380 --> 25:23.760] Things that were already censored would be out there. [25:24.080 --> 25:29.980] And would-be censors would think just a little bit harder about whether or not it was worth it. [25:30.440 --> 25:36.000] Because if they try to censor something and they fail, it's an automatic strike-sand effect. [25:38.120 --> 25:38.680] Great. [25:40.720 --> 25:41.740] Thank you very much. [25:41.880 --> 25:45.700] Now that we've dealt with the Zoom issue, hopefully we'll get Cooper back in a second. [25:46.300 --> 25:54.640] So I think the takeaway from a lot of this is that what was happening here was a real danger to speech insecurity. [25:54.640 --> 25:56.380] And people needed to step up here. [25:56.680 --> 26:00.740] There were legal demands to what appeared to be dozens of media outlets. [26:00.860 --> 26:04.800] You had organizations like the New Yorker, the Internet Archive, various podcasts. [26:05.600 --> 26:14.520] Any kind of mentioning or public reporting on this story resulted very often in a legal threat or a demand or threat of a lawsuit. [26:15.900 --> 26:21.400] And for organizations that are receiving this type of thing, go over to a lawyer in an in-house legal department. [26:21.800 --> 26:24.380] And it becomes a difficult issue. [26:24.520 --> 26:30.720] You don't want to be the person who says, you know, I'm going to stick my neck out and keep this story up. [26:30.720 --> 26:32.180] Or I'm going to advocate for this. [26:32.180 --> 26:39.720] You know, when you get some kind of takedown request and you're in a media organization or you're on a platform or you're sharing it, you don't want to deal with that kind of threat. [26:39.860 --> 26:41.800] You don't want to deal with that kind of pressure. [26:41.820 --> 26:45.460] You don't want to be the person who got the organization in trouble and got them sued. [26:45.480 --> 26:51.920] So it's very easy to simply say, well, okay, it looks like there's a court order here. [26:52.220 --> 26:53.500] We might as well comply with this. [26:53.560 --> 26:55.400] It's just easier to take it down. [26:55.400 --> 26:57.460] You don't want to have the headache of this. [26:57.700 --> 27:06.940] There are a couple of organizations, though, like Muck Rock and TechDirt that refuse to comply with these takedown requests, saying this is not some kind of global takedown order. [27:07.040 --> 27:14.120] This is not the global takedown order that you are advocating it to be or what you want me to perceive it to be. [27:14.120 --> 27:15.640] It's just not the case. [27:15.800 --> 27:17.240] But you have to dig into these issues. [27:17.340 --> 27:18.240] You have to examine them. [27:18.460 --> 27:19.220] They're difficult. [27:19.400 --> 27:19.880] They're hard. [27:20.880 --> 27:22.640] And then you need to float them upwards. [27:22.640 --> 27:28.820] And it takes resources and time to not comply, as opposed to complying with these types of requests. [27:30.180 --> 27:39.340] Some of the recipients of these that we had mentioned were the New Yorker, even the Lawfare blog, the Internet Archive. [27:40.080 --> 27:42.560] And all of these have taken down the stories. [27:43.020 --> 27:50.860] Another really fascinating one, and I think this one is perhaps of particular interest to this audience, is Sentinel One. [27:50.860 --> 27:54.420] Sentinel One, a cybersecurity research firm. [27:54.760 --> 28:07.580] So here we have, for the first time, I think, in history, a court order preventing a cybersecurity research firm from publishing its findings with respect to a very persistent threat actor. [28:07.700 --> 28:12.020] I think something that you could quite literally call an APT, or an advanced persistent threat. [28:12.020 --> 28:18.600] So utilizing the legal system to prevent the dissemination of CTI, or cyber threat intelligence. [28:18.800 --> 28:20.980] That's the first time that we've seen that. [28:21.320 --> 28:23.340] That, to me, is crossing a Rubicon. [28:23.640 --> 28:39.760] And that is an extraordinarily dangerous place for us to be, when anybody who is on the receiving end of a negative news story, let's say, can go to some kind of far-flung jurisdiction, obtain a court order, and start waving it in the face of everybody else around the world, [28:40.020 --> 28:45.700] claiming that this is now licensed for them to demand you to take down that publication. [28:45.780 --> 28:47.400] That's a danger to free speech. [28:48.180 --> 28:52.380] So, Wired received some takedown requests. [28:53.000 --> 28:57.340] I believe that Wired had also been asked to modify one of their stories. [28:57.340 --> 29:06.540] Andy Greenberg wrote a really excellent story about this story, as well, and about the censorship of the reporting with respect to APT. [29:06.780 --> 29:11.480] The Risky Biz podcast also reported on this and received a threat yesterday. [29:12.260 --> 29:16.740] So, like I mentioned, TechDirt and MuckRock were the ones that had refused to comply. [29:18.060 --> 29:20.720] Now, we have this thing called the Streisand effect. [29:20.760 --> 29:27.540] And this is a perfect time for me to take a bit of a break and to pass it back over to Lorax and Emma to talk about this. [29:27.940 --> 29:30.420] I'll just preface it by telling you the Streisand effect. [29:30.720 --> 29:34.860] Believe it or not, the Saatchi Gallery actually had portraits of Barbara Streisand on there. [29:35.020 --> 29:37.860] So, this is kind of amazing. [29:38.980 --> 29:52.020] This comes from a 2003 or so case where there was a bunch of reporting about Barbara Streisand's, this cliffside mansion that she had in Malibu, and she didn't want people to know about it. [29:52.020 --> 29:56.740] So, she tried to file a lawsuit to suppress this article on the basis of her personal privacy. [29:57.160 --> 30:03.240] But the lawsuit itself actually wound up attracting a hell of a lot more attention than the story otherwise would have gotten. [30:03.420 --> 30:10.480] So, when you have the unintended consequence of bringing attention to something that you're trying to suppress, that's called the Streisand effect. [30:11.260 --> 30:14.460] And you guys want to talk about that for a second while I'll try to get Cooper on? [30:15.140 --> 30:25.720] Yeah, just before we dive into that, I do think it's worth mentioning that, because we were discussing the list of people that were threatened and did take stuff down. [30:26.940 --> 30:35.260] Hara, Aten, none of them attempted to contact us at DDoS Secrets after we published it to get us to take it down. [30:36.740 --> 30:39.440] Because many censors are almost the bullies. [30:39.620 --> 30:42.440] They know that they don't have anything to stand on. [30:44.940 --> 30:52.920] And just the fact that it was immediately being thrown back in their face, I think they were aware of that Streisand effect. [30:53.120 --> 31:02.400] They were aware that if they tried to get us to take it down, not only would we not comply, because we had essentially already said that, but we would use it to generate even more attention. [31:02.400 --> 31:19.060] Yeah, I think that it was surprising to me that they hadn't contacted us, but they did target some of the other podcasts and magazines that covered YouTube after we republished the writer's story. [31:19.060 --> 31:37.200] So it's not over in India to get results in other jurisdictions, and they might sue us for this talk, so that would be fun. [31:38.900 --> 31:46.060] But you're right, they are bullies, and I think that numbers helped. [31:46.840 --> 31:50.640] There was one slide, I'm not sure if we got to it, but it was about the Streisand effect. [31:51.000 --> 31:52.480] It doesn't just happen on its own. [31:52.920 --> 32:02.520] It takes a good collective effort to keep talking about a story, to use the documents from the story. [32:02.740 --> 32:13.760] There's, I think, 800 documents or so that have been released as a part of the writer's investigations that are worth looking at and following the leads on. [32:14.180 --> 32:17.920] There's more court documents to come. [32:18.120 --> 32:20.920] I'm sure the Caucasian India is not going. [32:23.620 --> 32:40.480] But, yeah, the story of what Athens is doing, and not just Athens, but the subsidiaries and Sunkist Organic Farms, and everything that has, that they have begun, is still worth following. [32:40.720 --> 32:46.460] And I think that when we first, when I first read the writer's story, I thought, this is an amazing darn. [32:46.900 --> 32:53.820] And then the censorship started, and we figured that this would be the best thing that we could do to help the story continue. [32:54.940 --> 32:58.360] So if you want to read the story, you can do so on distributed denial of secrets. [32:59.120 --> 33:07.840] You know, and obviously, distributed denial of secrets is a massive repository of really fascinating information for several years now. [33:08.060 --> 33:20.040] And I think it's so important to keep this type of work going, and so important, I think, to have Raphael's investigative work out there and available for us. [33:20.120 --> 33:22.380] And it's a really, really fascinating tale. [33:22.380 --> 33:26.800] And this story is very, very much ongoing at the moment. [33:26.800 --> 33:37.600] So, yeah, we're actually very happy to announce that we have chosen the next entry for the Greenhouse Project, and that should be available tomorrow when we launch our new website. [33:38.260 --> 33:50.960] But what we've decided to add next is the complete WikiLeaks archive, because with the plea deal, they did have to destroy copies of unpublished data. [33:50.960 --> 33:58.860] And for the last several years, the website has had considerable problems in staying available and things being searchable. [33:59.220 --> 34:08.600] So we've gone ahead and copied all of the material that they've released, including several hundred gigabytes of insurance files, not all of which are still circulated. [34:08.880 --> 34:14.680] And we're going to be making those available in a stable repository for anyone to access. [34:14.680 --> 34:17.700] So hopefully they get the website issues sorted out. [34:17.980 --> 34:24.580] But in the meantime, and for as long after as possible, that information should be available to everyone. [34:31.930 --> 34:39.950] So we're at your bit here, Cooper, about EFF and fighting for the future with the meowsils from Fortnite slide here. [34:40.310 --> 34:40.610] So... [34:40.610 --> 34:53.710] Yeah, so what EFF has done is helped defend a couple of the organizations that got targeted with lawsuits at some of those tick-out stories. [34:54.070 --> 35:04.310] We helped defend Mike Madzik at Tecker, who actually is the person who's pointing to the terminal of the problem, starting in effect. [35:05.050 --> 35:14.130] And we also helped defend Muckrock, who published their own story and published the subpoenas, I think, actually. [35:14.950 --> 35:18.650] And it's not only happening with the city, these guys, you know, probably in front of the person. [35:18.650 --> 35:23.250] It's also Rejankar, who is this leader of all of our, the former owner of the mapping. [35:24.970 --> 35:29.110] And he's actually been still really aggressive about getting the stories taken down. [35:29.270 --> 35:37.930] And we think that's good to start to clean up his image, probably in preparation for starting a more lucrative, legitimate cyber security company. [35:39.590 --> 35:45.330] But so we sent a response to Claire, which essentially did not aware to speak. [35:45.410 --> 35:47.510] I'm not aware, so I don't speak more. [35:47.990 --> 35:52.810] But essentially what it said was, no, fuck it all. [35:52.950 --> 35:54.070] This is fine. [35:54.370 --> 35:55.890] We're going to leave this up. [35:55.950 --> 35:58.510] And you all can go eat in the United States. [35:59.530 --> 36:01.050] And we love the stories, though. [36:01.150 --> 36:02.250] And they have a lot of sense. [36:04.970 --> 36:06.470] So this seems to have worked. [36:06.670 --> 36:07.390] It works with both of them. [36:07.590 --> 36:11.950] And like Dorax was saying, the Streisand effect doesn't happen on its own. [36:12.110 --> 36:14.190] It really does take a push. [36:14.310 --> 36:21.290] It takes a lot of people writing about this, and a lot of people specifically deciding to write about this story. [36:21.590 --> 36:25.030] You know, there were, there were, I think, what was the final count? [36:25.210 --> 36:28.970] Over 20 stories about, or there were like probably a hundred stories about this. [36:29.110 --> 36:30.990] I think like dozens of them got taken down. [36:31.130 --> 36:34.470] But as people kept talking about it, more people kept talking about it. [36:34.890 --> 36:38.610] EFF wrote an article, Wired wrote an article, and this just spreads the story further. [36:38.830 --> 36:50.370] But if you don't do this, right, if DDoS secrets doesn't archive the story, if all these other people don't write stories, this story could have just died, right? [36:50.570 --> 36:58.670] Like, it's possible that Kare could have successfully, and Appin, could have successfully killed this story if we hadn't all done our part to spread it. [36:58.850 --> 37:07.770] There was a really amazing anecdote that I want to share too, which is that, so Behind the Bastards is a podcast that a lot of people listen to, that I listen to myself. [37:07.770 --> 37:16.510] And they did a really amazing couple of episodes on Kare, which I think the title was Reject Kare is an Evil Hacker, or something like that. [37:16.650 --> 37:18.810] And those immediately got taken down, of course. [37:19.450 --> 37:25.890] Kare immediately threatened to sue Clear Channel and iHeartRadio, and they are cowards, and so immediately took it down. [37:26.310 --> 37:36.990] But the subreddit for this podcast has now started spreading a rumor that Reject Kare has sex with salamanders. [37:37.430 --> 37:47.090] And they've tried to spread that all over the Internet as much as possible, so that when you Google for Reject Kare, what you get is a result about how he has sex with salamanders. [37:47.670 --> 37:54.330] And that's just a really amazing example of... of something. [37:55.490 --> 37:57.070] I don't know what to call it. [37:57.850 --> 37:58.250] Yeah. [38:00.770 --> 38:07.210] But yeah, there's a... it's through the combination of... I can't hear you guys at all on the table. [38:07.290 --> 38:07.930] I'm sorry. [38:08.070 --> 38:08.630] I can't hear you. [38:08.750 --> 38:12.390] They have... I think that you can either have my audio or your audio, but not both. [38:12.970 --> 38:30.650] Anyway, but yeah, it's a really amazing example of how, like, I think, you know, lawfare, like what EFF is doing, and reporting, and journalism, like what Chris and DDoS Secrets are doing, and also activism, like what DDoS Secrets are doing, and what the folks on the subreddit are doing, [38:30.850 --> 38:34.450] can all come together to really make this blow up in their faces. [38:35.350 --> 38:36.830] And it's been beautiful to watch. [38:37.910 --> 38:39.970] Couldn't agree more with you, Robert. [38:40.350 --> 38:43.890] And yeah, I think it's absolutely right. [38:44.090 --> 38:59.710] And part of this whole process, and the reason why we are here talking about this right now is to continue to propel this Streisand effect, to continue to support distributed denial of secrets, and the people that are pushing back against censorship, like the Electronic Frontier Foundation, [39:00.010 --> 39:09.390] like DDoS, and Lorax, and Emma, that have put their livelihoods on their line, invested a tremendous amount of their lives and efforts to pushing back against censorship. [39:09.650 --> 39:14.490] So I think we all owe them a debt of gratitude for for this particular work today as well. [39:20.400 --> 39:40.760] And kind of tying this up here, we had also mentioned that the guy who wrote all of this, right, the guy, that amazing and inimitable cybersecurity reporter, Raphael Satter, who is helping to fight this in India, right at the center of this, who reviewed the thousands and thousands of documents, [39:40.940 --> 39:45.200] talked to all these sources, got himself kicked off of the Shinnecock Indian Reserve. [39:45.420 --> 39:48.640] I don't know if I'm allowed to say that, as he was reporting this. [39:49.960 --> 39:59.140] I'm happy to say, as I mentioned, that he's a dear friend of mine, also a colleague, and he happens to be right in the middle here as well. [39:59.340 --> 40:00.380] Raphael, you want to stand up? [40:05.390 --> 40:06.650] Right in the middle of the audience. [40:08.630 --> 40:11.010] Yeah, I think you did some excellent work. [40:11.270 --> 40:13.570] You are an exemplary reporter. [40:14.010 --> 40:20.570] And I think something that all journalists should strive towards is the type of fight that you bring to every story. [40:20.650 --> 40:22.490] So thank you, Raphael, for doing that. [40:22.990 --> 40:28.510] So with that, I think we have a few minutes for questions, if anybody has some. [40:28.550 --> 40:32.730] I'm amazed that we actually ended on time after all of these fiascos. [40:33.730 --> 40:42.330] And I should probably mention, too, because of the ongoing litigation in India, it's probably rather difficult for Raphael to talk about any of this himself. [40:42.630 --> 40:45.230] So you should probably direct the questions over to us. [40:45.530 --> 40:46.490] How about you, sir? [40:47.510 --> 40:48.630] Just a general question. [40:48.910 --> 40:51.570] So is this really just about fear? [40:52.130 --> 40:57.790] Because there's no... I mean, in my understanding, and I'm not a lawyer, that they had... [40:58.350 --> 40:59.290] We're in America. [40:59.930 --> 41:06.030] A ruling in a regional court in India, how does that have jurisdiction in America? [41:06.150 --> 41:12.650] Is there any standing in America for a journalistic organization that's based in America to obey a court? [41:12.770 --> 41:15.170] So that's an excellent question, I think. [41:15.270 --> 41:18.530] And the question is, you know, why are all these companies complying? [41:18.630 --> 41:20.010] Why are these media organizations complying? [41:20.090 --> 41:20.850] Is it about fear? [41:20.870 --> 41:31.350] Because obviously, this is a court order from India, what standing does an Indian court have to request that their order would have effect in the United States? [41:31.670 --> 41:41.990] I mean, there are certain ways, sir, that you can take a judicial pronouncement, an order from another court and another jurisdiction, and have it domesticated and enforceable in another jurisdiction. [41:42.110 --> 41:43.270] That's certainly possible. [41:43.390 --> 41:44.630] You can do that with court orders. [41:44.690 --> 41:46.070] You can do that with arbitral awards. [41:46.310 --> 41:49.030] But that hasn't been done here, to my knowledge. [41:49.090 --> 41:49.850] And so I think you're right. [41:49.950 --> 41:56.890] A lot of this is about fear and about it being easier to comply with the requests from, I think, a well-established law firm. [41:57.110 --> 42:05.870] It's kind of scary to put your neck out on the line and perhaps, you know, cause your organization to be on the receiving end of some kind of civil complaint. [42:06.250 --> 42:09.290] So I think it is about fear to a certain extent. [42:09.470 --> 42:12.530] And that's why we have to be fearless and being up here. [42:12.810 --> 42:20.450] I think it's also... I mean, Reuters does have an office in India, so they do have to follow the law in that sense. [42:21.210 --> 42:36.590] Some of the other targets of the legal level probably don't have staff in India, but yeah, for the original censorship action against Reuters, I think it makes sense to prevent pressure against employees who are in that country. [42:37.470 --> 42:43.550] In addition to that, there's also the order, it wasn't just saying, oh, you have to take it down. [42:43.770 --> 42:50.770] It was trying to get the URL delisted from search engines and possibly have everything censored. [42:51.250 --> 43:03.330] And many organizations are understandably weary of potentially having their entire domain blocked in large countries or in any region, really. [43:03.750 --> 43:14.830] I think also, ironically, what we've seen is that the bigger the journalistic outfit is, the less keen they are to fight this sort of thing. [43:15.530 --> 43:19.630] Like smaller companies have less money on the line and are more willing to risk it. [43:19.630 --> 43:21.310] MuckRock, TechDirt, right? [43:21.470 --> 43:33.110] They were more willing to risk it, whereas a bigger company like Reuters or like iHeartRadio, which is formerly Clear Channel that have all the money in the world, are less willing to risk it because there's more on the line for them. [43:33.390 --> 43:39.770] So this just speaks to the need for more independent journalism, more small outfits doing hardcore reporting like this. [43:47.520 --> 44:02.540] So it's interesting to notice that what began is like a cluster of people in groups that were doing cyber operations kind of started using the courts instead to kind of, you know, chill this work. [44:02.760 --> 44:21.080] Are you seeing any evidence that like as people are pushing back against the lawsuits that they're maybe pivoting back towards like targeting activism journalists with cyber ops or do you think maybe they just realize they're bad at anonymity and they're just going to kind of dig their heels in with lawsuits? [44:22.260 --> 44:23.180] That's a good question. [44:23.340 --> 44:24.460] I haven't seen any of that. [44:24.880 --> 44:33.040] The question was realizing that there is a Streisand effect and this pushback from the lawsuits and the lawsuits may not be as effective. [44:33.040 --> 44:36.160] Are the threat actors going to start targeting journalists again? [44:37.180 --> 44:39.680] I haven't seen any information about that. [44:39.760 --> 44:40.940] I haven't seen any intelligence about that. [44:41.080 --> 44:41.800] Others may have. [44:41.800 --> 44:42.500] I don't know. [44:43.020 --> 44:53.100] And I also think it may be difficult to figure out the actual answer to that question because there are so many tentacles that came off the original Hydra entity. [44:53.100 --> 44:58.820] It's probably hard to track all of these sophisticated cyber adversaries and what they're up to. [44:59.380 --> 45:04.640] They can change their TTPs, their tactics, techniques and procedures pretty easily and make it more difficult for them to track. [45:05.460 --> 45:16.160] I would hope, though, that if they do start targeting journalists and activists again, that they take better precautions about their operational security because, as Cooper mentioned, it really does suck. [45:16.400 --> 45:19.580] So I would guess that they would do that. [45:20.160 --> 45:21.760] I hope they don't do that. [45:22.020 --> 45:23.580] Yeah, I mean, that's a facetious hope. [45:23.740 --> 45:24.780] Yeah, it's a facetious hope. [45:25.620 --> 45:26.980] But excellent question. [45:27.580 --> 45:28.460] Any further question? [45:29.280 --> 45:30.300] I'll say this. [45:31.060 --> 45:39.660] It's really hard to... it's really rare that we get to actually trace back a cyber attack to a specific actor, right? [45:40.500 --> 45:44.800] Uncovering things linked specifically to Appin only happened because they had Appin in their source code, right? [45:45.200 --> 45:54.400] We were only able to link things specifically to Belltronics because of leaks within the organization... or not we, Citizen Lab, because of leaks within the organization, right? [45:54.500 --> 45:55.320] And it's actually really rare. [45:55.460 --> 46:01.700] Like, yes, EFF has gotten some what looks like targeted phishing emails that appear to be coming from India since then. [46:01.860 --> 46:03.240] Can I say that those are Appin? [46:03.320 --> 46:04.600] No, because I have no idea, right? [46:04.680 --> 46:07.560] There are certainly other people working in India, right? [46:07.560 --> 46:10.880] And it'll be hard to say exactly like what Alex said. [46:10.980 --> 46:14.020] It'll be hard to say, you know, but yeah, maybe we'll find out. [46:14.140 --> 46:16.040] I mean, I doubt these guys will stop, right? [46:16.160 --> 46:19.180] They keep pivoting and keep finding new business opportunities. [46:19.180 --> 46:24.400] And I don't see any reason why Appin or Regicare would stop that. [46:26.760 --> 46:27.500] Another question. [46:29.300 --> 46:33.220] Has there been any attempt to indirectly try to shut down the greenhouse? [46:33.540 --> 46:42.740] For example, to say, you know, you're committing this, this is your article, use your copyright, use your license, you know, tell them to shut it down? [46:44.820 --> 46:48.000] When you say them, how do you... So the question is... [46:48.000 --> 46:54.720] So Appin's lawyers in the U.S., they obviously told Reuters to take their article down. [46:55.360 --> 47:06.460] Can't they tell the lawyers also to, you know, use your copyright in this article to tell DDoS to take the article down as well? [47:06.760 --> 47:08.780] Oh, so that's an interesting question. [47:08.940 --> 47:10.280] So now I understand. [47:10.420 --> 47:27.960] But the question is, you know, has... have the lawyers responsible for the takedown requests tried to migrate those requests over to organizations like Distributed Denial of Secrets on the basis of saying, hey, this is the same article, it's the same copyright here, [47:27.980 --> 47:31.020] that's that issue, that's at play in the Indian court order. [47:31.820 --> 47:33.700] Therefore, you need to take that down, right? [47:33.860 --> 47:36.800] So I think this is really a question for Lorax and Emma. [47:37.360 --> 47:47.420] But if I'm going to jump in for one second and say they could absolutely say that, my guess is that the lawyers know that that would be met with absolute defiance. [47:48.600 --> 47:49.760] But I'll hand it over to you. [47:49.760 --> 47:57.440] Yeah, I mean, I'm not an actor, but I think the copyright holder has to make that request, and I mean, writers is a wide service, the one. [47:57.960 --> 48:00.140] So there are stories here in a lot of places. [48:00.340 --> 48:04.880] We don't have a license to writers, but we published it under fair use. [48:05.780 --> 48:10.000] And no, we haven't received anything like a copyright notice for... [48:13.600 --> 48:17.180] Yeah, it seems like Cooper can't hear the room for some reason, Joey. [48:18.860 --> 48:21.460] We haven't received a copyright name, not for that one. [48:21.540 --> 48:22.740] We have for others. [48:23.060 --> 48:29.000] When we published John Moulton's book, we've got a copyright name for that, but not for writers. [48:29.380 --> 48:29.940] All right. [48:30.320 --> 48:31.020] Yep, you got it. [48:31.120 --> 48:34.840] So yeah, like a DMCA-type takedown, as Nanko said, the question soon. [48:35.580 --> 48:38.680] Further, any further questions for us while we're up here? [48:38.740 --> 48:40.560] I don't know if we're totally out of time or not. [48:40.720 --> 48:42.220] We've got a couple of minutes, actually. [48:42.220 --> 48:43.000] Okay. [48:44.600 --> 48:45.540] All right. [48:45.880 --> 48:52.380] There being no questions, I want to thank everybody for attending and your patience and listening to this really important story. [48:52.760 --> 48:54.480] And Emma, Laura, and Raphael. [48:54.640 --> 48:55.320] Thank you all. [48:55.320 --> 48:55.420] Thank you very much. [48:55.560 --> 48:56.560] Thank you.