[00:00.000 --> 00:02.260] I thought we were gonna rock it metal style all night. [00:04.720 --> 00:10.140] So if you're... I could sing, maybe. [00:10.820 --> 00:13.580] Should I sing Let the Eagle Soar by John Ashcroft? [00:14.440 --> 00:14.960] Yeah. [00:16.640 --> 00:22.400] Anyhow, so I have promised a detailed and technical look in the abstract. [00:22.660 --> 00:28.640] And as I put this talk together and realized how little time I have, I can't get too far into the technology. [00:28.640 --> 00:34.600] So if you want more than a surface level, this is probably not the right talk. [00:34.820 --> 00:38.240] You should catch me after the talk, and we can go into more detail. [00:38.600 --> 00:42.120] But this is Twitter Revolution meets Surveillance State. [00:42.140 --> 00:42.700] Now what? [00:44.040 --> 00:45.480] So I'm T Profit. [00:45.820 --> 00:50.500] I've been writing for 2600 Magazine for the last 20 years now, believe it or not. [00:50.500 --> 00:53.680] I write the quarterly Telecom Informer column. [00:55.400 --> 01:00.240] And I'm happy to be here in New York from my home in Beijing. [01:00.880 --> 01:15.040] The talk today is actually about surveillance and the incredibly pervasive surveillance that we're now seeing on telephone and Internet networks around the world. [01:16.100 --> 01:25.160] So one of the things that's happened, and the previous talk got into this in some detail, is there's been a lot of political upheaval around the world. [01:25.680 --> 01:27.260] We've had an Arab Spring. [01:27.900 --> 01:39.540] And this gives us a pretty unique opportunity to actually see some of the effect of a revolution on telecommunications and Internet infrastructure. [01:39.540 --> 01:44.600] So before and during the Arab Spring, you know, these were not free countries. [01:45.160 --> 01:50.560] So Internet services were and continue to be in many cases heavily monitored. [01:52.360 --> 01:56.020] This is used to gather information and arrest dissidents. [01:56.360 --> 01:59.240] The Tunisian regime was particularly creative. [01:59.400 --> 02:01.700] They would actually read and change your email. [02:02.320 --> 02:10.220] So, you know, particular people that were targeted, they would do interesting things with mail to create subterfuge. [02:10.880 --> 02:15.180] And there were a lot of, there were and are a lot of sophisticated tools being used. [02:15.840 --> 02:26.740] Internet and phones began to be shut off as revolutions progressed because eventually the risk of letting people communicate actually exceeded the benefit of the spying. [02:27.060 --> 02:35.920] And finally, in the heat of the battles, threatening SMS messages were sent to citizens by the government. [02:35.920 --> 02:40.620] So the Egyptian military would send messages urging people to stay in their homes. [02:41.060 --> 02:43.480] And please just don't go out to the protests. [02:43.920 --> 02:48.320] The Libyan government encouraged people to just give up and go back to work. [02:48.600 --> 02:53.040] And we saw similar messages in Tunisia. [02:54.100 --> 02:56.840] So what's the aftermath of the Arab Spring? [02:57.080 --> 03:05.420] It, you know, transpired pretty similarly in Egypt, Tunisia and Libya with the overthrow of oppressive governments in all these places. [03:05.420 --> 03:07.160] But Libya is really special. [03:07.380 --> 03:10.260] Because there, the government entirely collapsed. [03:10.700 --> 03:16.480] Giving it a, giving us a rare look inside domestic and foreign intelligence services. [03:17.740 --> 03:29.080] Despite the spotty history that Libya has as a player in the international community, Western intelligence services were working closely with Libya at the time. [03:29.080 --> 03:33.940] Because there's a principle, the enemy of my enemy is my friend. [03:34.220 --> 03:36.560] And actually, Gaddafi opposed Al-Qaeda. [03:37.660 --> 03:38.880] The lesson learned? [03:39.740 --> 03:44.320] Surveillance is really more pervasive than most people can even imagine. [03:45.700 --> 03:50.340] So let's talk about what the landscape of, you know, current communication looks like. [03:50.580 --> 03:53.000] There's more ways to communicate than we've ever had. [03:53.000 --> 03:53.880] We have Twitter. [03:54.140 --> 03:54.840] We have Facebook. [03:55.100 --> 03:56.100] We have mobile phones. [03:56.220 --> 03:56.800] We have SMS. [03:57.700 --> 04:00.420] There's also more surveillance than ever. [04:00.940 --> 04:05.680] There's an incredibly creepy company most people have never heard of called Palantir. [04:06.560 --> 04:12.400] There's CALEA, which is the Communications Assistance for Law Enforcement Act. [04:12.540 --> 04:16.420] And that enables an incredible amount of surveillance of telephone switches. [04:16.420 --> 04:21.900] There's GPS monitoring that happens at a very large scale. [04:22.280 --> 04:34.620] And as anybody who saw William Binney's talk yesterday now knows, the National Security Agency is building an enormous data center in Utah with an incredible amount of storage. [04:35.960 --> 04:43.500] So, you know, this is actually kind of an interesting point that Krypton observed yesterday. [04:43.500 --> 04:47.260] Cities have physically been designed to limit access. [04:47.900 --> 04:51.960] And the reason that this is done is to conduct pervasive surveillance. [04:52.840 --> 04:57.820] If you look at the financial networks for a long time, there have been choke points in financial networks as well. [04:58.460 --> 05:01.660] And, you know, the reason for this is to control the flow of money. [05:02.040 --> 05:05.780] Well, the Internet actually has choke points as well. [05:05.920 --> 05:10.800] And for a long time, it was really hard to monitor these just because of the sheer amount of traffic. [05:10.800 --> 05:20.940] But the technology has caught up to the point that the Internet now can be considered fully monitored and controlled, just like telecom, just like telephone calls. [05:21.560 --> 05:27.680] Internet and telecommunications traffic is physically routed through a relatively small number of places around the world. [05:28.420 --> 05:33.160] Seventy percent, roughly, of Internet traffic still routes through the United States. [05:33.160 --> 05:36.360] And storage technology has grown incredibly. [05:36.740 --> 05:45.380] It's evolved to the point where, you know, literally everything, voice data, video, can be logged for really long periods of time and analyzed later. [05:45.600 --> 05:49.120] And so, you all have a permanent record. [05:50.160 --> 05:56.620] And it's sitting in a data center, you know, right now probably in Fort Meade, but soon in Utah. [05:58.260 --> 06:01.680] There are so many people to spy on for so many reasons. [06:01.920 --> 06:04.740] Everyone is a potential threat to someone else or some government. [06:05.340 --> 06:08.060] Everyone may have potentially useful information. [06:08.280 --> 06:13.860] There's, you know, espionage that may be useful to conduct by one government against another. [06:14.260 --> 06:19.920] If you're a company, you may want to conduct some sort of investigation against your competitors. [06:19.920 --> 06:24.760] If you're a government, you may want to know what your political dissidents are doing. [06:26.280 --> 06:31.300] And we're in this world where there's all this technology, but the legal constraints are really limited. [06:31.680 --> 06:34.760] And they were limited before, and they're even less limited now. [06:35.760 --> 06:39.060] Warrantless surveillance has become the norm in America. [06:40.100 --> 06:42.160] It's really easy to justify. [06:42.420 --> 06:44.460] There's always some terrorist to catch. [06:44.540 --> 06:45.660] There's always some emergency. [06:46.480 --> 06:48.740] There's always some reason to spy. [06:48.740 --> 06:55.620] And when it does happen illegally, there's been no penalty for overreach. [06:55.860 --> 07:07.500] When it finally comes out that the government is doing something that is unconstitutional, Congress just passes a retroactive law and cleans up after it. [07:07.580 --> 07:11.220] And this has happened multiple times in the last 10 years. [07:12.860 --> 07:15.280] So let's take a step back and look. [07:15.360 --> 07:16.280] Where did all this start? [07:16.280 --> 07:22.560] Because it's actually a fairly radical concept that literally every communication is logged forever. [07:24.060 --> 07:27.720] Because it used to actually take real work to tap your phone. [07:28.560 --> 07:35.460] Well, CALEA in the early 1990s built monitoring and surveillance into the telecommunications network. [07:36.920 --> 07:39.860] So instead, it no longer took real work. [07:40.260 --> 07:49.720] The FBI no longer, or local police, would no longer have to travel to a telecommunications switch, hook up to your phone line, and start a recorder. [07:50.020 --> 07:51.600] They could do all this remotely. [07:52.160 --> 07:56.580] There are updates that are currently being proposed for CALEA laws. [07:57.540 --> 08:02.420] And this will legitimate a lot of Internet spying that's already happening. [08:02.780 --> 08:09.580] For example, CALEA doesn't cover voice over Internet services like Skype, but the FBI would like it to. [08:10.340 --> 08:20.280] And it's very likely that we'll see in the next year or two CALEA extended to literally any way to communicate by voice and also by SMS. [08:20.280 --> 08:21.620] But there's more. [08:22.560 --> 08:30.700] There's already significant evidence that technology originally put in place by CALEA is now routinely used for intercepts that aren't court authorized. [08:31.080 --> 08:39.320] And probably the biggest example of this is doing tower dumps to determine the GPS location of particular cell phone numbers. [08:40.220 --> 08:51.860] And all of this doesn't even include national security activities, which are completely out of the purview of any court review at all, based on the Patriot Act, for the most part. [08:52.060 --> 08:55.940] So if you guys are interested in, you know, what's possible today? [08:56.280 --> 09:02.760] What is the FBI telling telecommunications carriers they need to be able to do to enable surveillance on their networks? [09:02.980 --> 09:09.480] And just to get an idea of the scope of this, there's actually a website the FBI runs called askcalea.com. [09:10.460 --> 09:20.800] You can go sign up and, you know, get into the forum and see all the technical documentation on exactly how this stuff works and what carriers need to do. [09:21.820 --> 09:29.800] You know, one of the best ways that I've found to social engineer things is to be purportedly interested in buying something. [09:29.800 --> 09:41.560] And you would be really amazed how much information you can get if you want to buy a switch or, you know, if you want to, you know, properly implement CALEA in your, you know, VOIP environment, for example. [09:43.360 --> 09:45.520] Well, where are the courts, you might ask? [09:45.560 --> 09:51.960] Because, you know, it seems like there's an awful lot of surveillance going on and you would think that there'd be some judicial review. [09:51.960 --> 09:55.040] Well, the reality is courts are mostly absent. [09:55.380 --> 10:00.540] The majority of surveillance today is being done without any warrants or court orders. [10:00.760 --> 10:02.960] And this just came out last week. [10:03.240 --> 10:07.440] 1.2 million intercepts were processed by mobile carriers last year. [10:07.620 --> 10:10.500] And that figure excludes national security letters. [10:10.680 --> 10:15.300] So what we're actually talking about is stuff that's not national security related. [10:15.300 --> 10:21.940] We're talking about 1.2 million intercepts happening, you know, at the request of local police departments. [10:21.940 --> 10:24.880] at the request of the FBI and so forth. [10:25.640 --> 10:32.160] And that means that the true figure, when you factor in national security, is much higher. [10:32.780 --> 10:36.940] And, you know, this kind of blew my mind. [10:37.120 --> 10:43.600] The number of intercepts processed just by spread alone exceeded the number of court orders issued nationwide. [10:44.040 --> 10:54.160] So, you know, one carrier and the intercepts that they did, that's a larger number than all of the court orders issued nationwide. [10:54.860 --> 10:58.620] So, you can see that really the police are just going around the courts. [10:58.940 --> 11:04.640] And there's really no... there doesn't seem to be any stopping it. [11:05.360 --> 11:10.560] So, it's not just credit bureaus in the corporate world spying on you. [11:10.560 --> 11:14.680] Because there's this incredible world of not just government surveillance, but corporate surveillance. [11:14.880 --> 11:16.500] And corporate surveillance is special. [11:16.860 --> 11:19.340] Because this is actually treated differently. [11:19.560 --> 11:23.840] You don't actually need warrants to look at most data that companies have on you. [11:24.820 --> 11:28.080] If the government wants to pull your credit, they do need a warrant for that. [11:28.480 --> 11:30.760] But they don't need a warrant for your axiom file. [11:30.760 --> 11:35.840] And, you know, that can actually have every piece of activity from shopping cards. [11:36.060 --> 11:47.940] You know, if you go to Safeway and you buy something with your Safeway Club card, chances are it will wind up in a database sitting in Little Rock that has a giant file on you and your purchasing habits. [11:48.120 --> 11:56.480] Frequent flyer activity, banking activity, whether you rent or whether you own, whether you might be interested in a mortgage. [11:56.480 --> 12:00.220] All of this stuff is used for marketing, but it can also be used to track you. [12:02.000 --> 12:05.400] You have a permanent record, and it's on a server in Arkansas. [12:06.500 --> 12:07.840] Internet service providers. [12:08.100 --> 12:14.320] So Time Warner, it just came out, logs the port numbers of wireless devices used behind wireless gateways. [12:14.480 --> 12:17.580] And they do this to help the police identify users. [12:17.820 --> 12:20.040] They're not required to, they just choose to. [12:20.320 --> 12:25.140] This is information companies have on you, and they can just give up without a court order. [12:25.820 --> 12:26.560] Data mining. [12:27.140 --> 12:32.560] So, you know, Palantir, the company I mentioned before, they do a lot of data visualization work. [12:34.080 --> 12:43.500] So one of the things that they can do is try to figure out if you're a criminal or a terrorist, based on the data trail that you leave in various databases, like, you know, Axiom. [12:43.500 --> 12:59.880] So maybe if you buy, you know, fertilizer from one store and you buy some diesel fuel, you know, from Shell, they can put the two together and decide that you're a terrorist when really, you know, you're a farmer and you needed it for your tractor. [13:01.720 --> 13:07.940] And, you know, again, this is stuff that you don't actually need a court order to look at. [13:08.040 --> 13:09.360] You don't need a warrant to look at. [13:09.400 --> 13:13.660] And many police agencies are using tools like these. [13:14.100 --> 13:15.840] And finally, even Facebook. [13:16.080 --> 13:21.500] Well, I kind of expect Facebook to be evil, but they're monitoring chats for suspicious behavior. [13:21.500 --> 13:24.000] And, you know, what they're really looking for is child predators. [13:25.020 --> 13:25.960] I get that. [13:26.340 --> 13:29.960] I have two nieces that I want to keep away from child predators. [13:30.200 --> 13:37.400] But, you know, if you happen to chat with younger people, you know, I'm a DJ and a lot of my fans are younger. [13:37.740 --> 13:44.540] So if there are keywords that pop up, you know, maybe I might be assumed to be something I'm not. [13:45.820 --> 13:54.140] So finally, let's take a look at a surveillance state postmortem and, you know, some technical details on what was found in Libya. [13:54.320 --> 14:03.180] And the reason that I want to do this is so that you can kind of infer what it may be possible that more advanced governments have. [14:03.400 --> 14:07.660] So there's a French company called Amesis, and that's a Group Bull division. [14:08.000 --> 14:10.600] Group Bull is a giant French IT company. [14:10.600 --> 14:14.820] And they provided the majority of the infrastructure that was used in Libya. [14:15.820 --> 14:26.460] The same EGLE monitoring systems that they had, and I'll show a short demo of the EGLE system, were sold to Morocco and also to Qatar. [14:26.860 --> 14:33.620] And it's also rumored to be used in France itself under a code name called the EHE DLP 1101. [14:34.100 --> 14:39.600] So far, the French government's refused to acknowledge whether this exists or if it does what it's used for. [14:41.020 --> 14:49.940] There was GSM spying mostly for geolocating provided by ZTE, a giant Chinese telecommunications carrier. [14:50.940 --> 14:56.760] They're also one of the prime contractors behind the surveillance system that Iran is building. [14:57.420 --> 15:06.580] And incidentally, they're currently under investigation for violating U.S. export controls because some of the software that was used in Iran came from here. [15:07.700 --> 15:11.060] There's a company called Neres, owned by Boeing. [15:11.880 --> 15:18.020] And these, they make the boxes that are believed to be used by the National Security Agency here in the U.S. [15:18.880 --> 15:26.780] They were solicited to provide content surveillance and filtering so they could build, you know, something akin to a great firewall in Libya. [15:26.780 --> 15:34.520] But to their credit, the revolution had already gone far enough that they thought it would be bad for PR, so they refused to proceed any further. [15:35.000 --> 15:36.720] Whether they have now, who knows? [15:37.800 --> 15:47.120] There's a company out of South Africa called VazTechSA that provided some traditional landline phone tapping gear called Zebra. [15:48.360 --> 15:58.240] And finally, so Libya had with this collection of tools the capability to monitor pretty much all unencrypted traffic. [15:59.280 --> 16:02.680] Email, instant messaging, SIP, VoIP, Web. [16:03.260 --> 16:04.960] They did deep packet inspection. [16:05.300 --> 16:07.360] There was, you know, full packet capture capability. [16:08.080 --> 16:10.540] They could do cellular triangulation and monitoring. [16:10.700 --> 16:12.420] And this is a country that was a pariah. [16:12.760 --> 16:13.880] You know, this is Libya. [16:14.040 --> 16:16.640] This is not a nice regime. [16:17.540 --> 16:21.300] You know, they bombed a plane over, an American plane over Scotland. [16:21.300 --> 16:25.160] This is, you know, these are not the best friends of Western countries. [16:25.520 --> 16:28.000] And this is the stuff they got their hands on. [16:29.120 --> 16:33.480] So, you can only imagine what other countries might have. [16:33.700 --> 16:37.740] So, let me bounce out a PowerPoint really quickly and hopefully this will work. [16:41.380 --> 16:46.060] The manual for the Eagle Glint system actually leaked. [16:47.300 --> 16:49.560] And, you know, has been put up on Scribd. [16:50.260 --> 16:51.800] And, you know, here's an example. [16:51.960 --> 16:53.720] This is one thing that I just wanted to show. [16:54.900 --> 17:02.200] So, you can actually... you feed this system people that you want to target and it starts gathering information about them. [17:02.440 --> 17:13.580] It gathers information from their cell phones, from their SMS, from social networks, from email, from their Internet connectivity, and starts logging all this stuff in databases. [17:13.900 --> 17:20.280] And so, at that point, you can start building visualizations around who are these people talking to. [17:20.540 --> 17:29.320] So, you know, if you're a regime and you want to smash a protest, you really want to figure out, you know, who the protest leaders are and then who they're talking to. [17:29.660 --> 17:32.640] Because that'll kind of tell you who's involved. [17:32.840 --> 17:35.420] And then you can, you know, make all those people disappear, right? [17:36.280 --> 17:38.960] So, here it is in a handy dandy little graph. [17:38.960 --> 17:41.720] All this information a computer just figures out for you. [17:43.260 --> 17:46.940] You can center the chart on particular IDs and suspects. [17:47.300 --> 17:54.840] You can... if you've done an investigation and you've determined that, you know, the pizza delivery guy for this guy is uninteresting, you can remove them. [17:55.820 --> 18:04.580] And, you know, it just goes on and on in terms of what kind of information you can target and track and how you can visualize it. [18:04.580 --> 18:07.940] So, back into PowerPoint. [18:09.440 --> 18:09.920] Yep. [18:11.400 --> 18:13.960] I should have to... [18:15.280 --> 18:16.100] There we go. [18:18.920 --> 18:19.400] Okay. [18:22.140 --> 18:25.100] So, if Libya had all this, what does the U.S. [18:25.220 --> 18:25.420] have? [18:26.160 --> 18:27.860] Unfortunately, there are not a lot of facts. [18:28.000 --> 18:29.000] There's only conjecture. [18:29.360 --> 18:30.940] You know, we pay for all this stuff. [18:30.940 --> 18:34.620] But even to Congress, it's a secret to most people in Congress. [18:36.220 --> 18:45.660] What we were looking at, we do know, at least through, you know, pretty good conjecture, that the NSA had most of this stuff 20 years ago with the Echelon program. [18:47.500 --> 18:51.080] We know that CALEA has remote interception capability. [18:52.060 --> 18:57.180] We know that there are secret NSA intercepts at Internet meet-me points. [18:57.180 --> 19:02.360] And so, it's safe to assume that all Internet traffic nationwide and passing through the U.S. [19:02.860 --> 19:04.220] is logged and analyzed. [19:04.680 --> 19:09.800] And it's also safe to assume that SSL and VPNs are compromised. [19:13.240 --> 19:17.040] SSL monitoring gear is routinely sold at trade shows. [19:17.040 --> 19:28.620] And my own experience traveling in countries that heavily filter and do deep packet inspection and have some firewall kinds of capabilities bears this out. [19:29.860 --> 19:38.640] The Utah Data Center and its tremendous storage capability wouldn't be being put in place if there wasn't a big plan. [19:39.020 --> 19:44.560] We know that there are carrier logs available even to local police departments. [19:44.560 --> 19:47.460] And so, when I say carrier logs, what are those? [19:47.700 --> 19:50.960] Well, that's logs of anybody that you might dial. [19:51.460 --> 19:52.960] Anybody who might call you. [19:54.260 --> 19:57.620] Any sort of details about your SMS conversations. [19:57.960 --> 20:01.460] All this stuff is available even to local police departments pretty easily. [20:02.560 --> 20:05.920] And this is one thing that just came out, you know, again last week. [20:05.920 --> 20:17.700] It turns out that for $75, if you're a law enforcement agency and you ask for it, AT&T will give you a dump of everybody who was at a particular cell tower at a particular time. [20:18.260 --> 20:20.360] And what their GPS location was. [20:20.940 --> 20:24.280] So, there's plenty of evidence of abuse. [20:24.740 --> 20:26.820] Warrants are now the exception. [20:26.840 --> 20:27.820] They're not the norm. [20:28.300 --> 20:33.980] There's massive use of warrantless emergency intercepts growing at 15% a year. [20:33.980 --> 20:39.920] So, I guess we just really have a lot of emergencies in the U.S. to grow at such a tremendous rate as crime is dropping. [20:41.480 --> 20:46.480] There are secret legal interpretations, which is kind of an interesting thing. [20:46.780 --> 20:50.120] So, the plain language of the law may say one thing. [20:50.780 --> 20:59.120] But then the executive branch, you know, whether it's Democrat or Republican doesn't matter, decides internally that it means something completely different. [20:59.120 --> 21:03.000] And so, they have their own legal interpretation, which they write down and use internally. [21:03.380 --> 21:04.620] And that's a secret. [21:05.060 --> 21:11.220] That's actually, you know, not even Congress necessarily knows what the interpretation is. [21:11.360 --> 21:23.840] And so, rules of how you implement that law are based on what the interpretation is, which is sometimes, you know, 180 degrees from what you would expect based on the plain language of the law. [21:25.000 --> 21:32.860] Ron Wyden, sitting congressman from Oregon, has been unable to get clear answers about the NSA's surveillance activities. [21:34.000 --> 21:45.300] Incredibly, they've said that if they were to give Congress more details, it would actually be a violation of the privacy of the people that they might illegally be spying on. [21:45.300 --> 21:49.740] So, it seems incredible, but it's true. [21:51.420 --> 21:52.820] National security letters. [21:53.020 --> 21:54.220] These are issued by the FBI. [21:54.520 --> 21:55.100] They care about their victims. [21:55.380 --> 21:59.420] Yes, they care about their victims. [22:00.480 --> 22:01.900] Somebody in the audience says. [22:03.120 --> 22:04.380] National security letters. [22:04.540 --> 22:07.760] So, these were put in place by the Patriot Act. [22:07.920 --> 22:23.200] And basically, if the FBI thinks that they want some information that might have to do with terrorism, they can send a national security letter, you know, essentially completely circumventing the courts and demanding information that previously would have required a warrant. [22:23.620 --> 22:27.260] And the best part is, you know, nobody can tell anybody that this has happened. [22:28.160 --> 22:30.900] They're growing at a very, very, very fast rate. [22:31.120 --> 22:35.400] All the FBI will say to Congress is just the number of these that they've issued. [22:35.840 --> 22:37.600] And that grows every year. [22:38.360 --> 22:40.560] And this is something that's kind of interesting. [22:40.560 --> 22:44.040] So, you might think that it requires a warrant to read your email. [22:44.760 --> 22:46.360] But actually, it doesn't. [22:47.020 --> 22:55.280] With just a subpoena, the government can read your Gmail or any online mail that you may have that's been stored for more than six months. [22:55.360 --> 23:01.580] And this is because the Electronic Communications Privacy Act actually only requires a warrant for the first six months. [23:01.760 --> 23:02.980] After that, it's fair game. [23:05.280 --> 23:07.900] So, let's talk about the American situation. [23:08.180 --> 23:19.440] And I really want to bring you back to, you know, the slide of what things looked like in Egypt, Tunisia, and Libya before the Arab Spring happened. [23:19.580 --> 23:30.280] Because, as I demonstrated, there was a lot of surveillance that was made possible and a lot of disruption that was made possible in those regimes. [23:30.280 --> 23:39.900] Well, July 6, 2012, a new executive order came out called the Assignment of National Security and Emergency Preparedness Communications Functions. [23:42.560 --> 24:02.480] So, what this actually will enable the government to do, based on preliminary interpretations by people who would know, is the government now can send you SMSs saying, stay in your homes, why don't you stop this protesting and go back to work? [24:04.660 --> 24:12.160] This will legitimate an Internet kill switch, similar to what happened in Egypt, Tunisia, and Libya. [24:13.700 --> 24:25.860] And we're already seeing, you know, even without this authorization, we saw cellular services interrupted during Occupy Wall Street protests in Oakland with the BART police doing that. [24:26.700 --> 24:30.320] Landline phones, you know, the technology's already there to easily shut them off. [24:31.640 --> 24:36.020] And, you know, this is all really routine stuff in authoritarian countries. [24:36.020 --> 24:46.240] I mean, you know, in many parts of the world, you know, Russia and so forth, we wouldn't even think twice whether the government, you know, should have the ability to do this. [24:46.440 --> 24:50.340] In the United States, maybe the government's been a little bit behind. [24:50.340 --> 25:02.700] But with this executive order, they've now caught up to, you know, great regimes like Syria and Sudan and Russia with the capabilities that the government now has in the United States. [25:05.220 --> 25:09.020] Whether that's a good thing really is up to citizens. [25:09.360 --> 25:11.440] So could a Twitter revolution happen here? [25:11.620 --> 25:17.280] And, you know, this is a really interesting question because we all saw what happened with Occupy Wall Street last summer. [25:19.440 --> 25:24.360] I have, you know, I've been sitting outside of the country for a couple of years. [25:24.360 --> 25:30.060] And so I have kind of a, you know, a skewed vision of what's actually happening. [25:30.240 --> 25:35.040] But from, you know, Americans who visited me in China, I've been told it was pretty big. [25:35.040 --> 25:41.200] And I've also been told the media kind of minimized what the, what this actually was. [25:42.340 --> 25:46.020] Well, I don't think that we should have a Twitter revolution necessarily. [25:46.020 --> 25:51.740] Not the same way as, you know, Libya or Egypt or Tunisia. [25:52.680 --> 26:00.920] Because unlike those countries here in the United States, we can in theory change our government non-violently through peaceful protests and elections. [26:00.920 --> 26:04.200] You know, the real question is, would this be allowed to happen? [26:04.600 --> 26:08.040] I think we should keep faith in democracy and try. [26:08.360 --> 26:09.600] However, the U.S. [26:09.700 --> 26:15.040] has a history of smashing the international workers of the world, also known as the Wobblies. [26:15.420 --> 26:19.380] The socialists with the presidential campaign of Eugene Debs. [26:19.380 --> 26:32.440] And, you know, bear in mind, I'm not a leftist by any means, but leftist groups have, have borne the brunt of a government very interested in maintaining the established order. [26:33.020 --> 26:46.180] We have some recent evidence that if things get too far away from, you know, the people who are in charge and the policies that are currently in place, they're likely to be smashed, democracy be damned. [26:46.180 --> 26:54.520] And we saw Occupy Wall Street protests smashed and DHS coordinated actions by a pretty militarized police force. [26:55.660 --> 27:00.740] We've seen strategic arrests of protest leaders at suspiciously strategic times. [27:00.960 --> 27:06.520] And what this does is it really points to a lot of data mining and surveillance, which probably is legal. [27:07.680 --> 27:12.020] And we're even seeing Twitter feeds being subpoenaed and Twitter direct messages. [27:12.540 --> 27:17.880] You know, to find out whether somebody organized protesters to walk across the Brooklyn Bridge. [27:18.300 --> 27:21.600] My God, how terrorist. [27:23.540 --> 27:30.220] So, I think that if you seek political change in the United States or really anywhere, tactics matter. [27:30.220 --> 27:35.140] So, groups seeking political change need to assume that they're infiltrated. [27:35.280 --> 27:41.580] They need to assume that they're being monitored by the same tools and government organizations that are used against serious hardcore terrorists. [27:42.120 --> 27:43.680] All this stuff is there. [27:44.680 --> 27:47.840] And it's just too easy to use it. [27:48.980 --> 27:54.080] So, we'll see anti-war movements infiltrated and smashed. [27:54.920 --> 28:02.800] I think that we're likely to see if we ever saw some serious independent political campaigns away from the Democrats and Republicans that run things now. [28:03.300 --> 28:06.660] I think that we would see similar activity. [28:07.440 --> 28:09.440] And so, I'd like to ask the questions. [28:09.440 --> 28:15.420] Well, if you combine the McCarthy era with today's surveillance tools and laws, what would the result have been? [28:16.160 --> 28:23.760] If you combine the government smashing of the Wobblies with the current landscape, what would have been the result? [28:23.760 --> 28:31.220] And, you know, what's happened is violence against peaceful protesters is really now the norm in America. [28:33.540 --> 28:37.180] So, I'd like to call people to action. [28:37.760 --> 28:44.840] And the call to action in the hacker community typically has been, we need strong, easy-to-use encryption everywhere. [28:45.120 --> 28:46.900] Well, I don't think so. [28:47.020 --> 28:47.520] Just kidding. [28:47.800 --> 28:49.420] The government's going to break it. [28:50.320 --> 28:58.000] The fact that we don't hear a whole lot of complaint over consumer encryption anymore says to me that breaking it is pretty trivial. [28:58.000 --> 29:21.760] And when small governments in parts of the world that are not particularly friendly can buy gear to break SSL, this is not something that's probably going to work if you want to maintain your privacy and if you actually want to be able to communicate controversial things with controversial people. [29:22.500 --> 29:29.840] Or, you know, in the United Kingdom, if you happen to forget your passphrase, then it's a four-year, you know, prison penalty anyway for contempt of court. [29:30.060 --> 29:31.180] You know, contempt is assumed. [29:31.760 --> 29:34.860] The same thing can and probably will happen here. [29:35.620 --> 29:39.920] Any bad idea that England has seems to become law in the United States. [29:41.700 --> 29:47.620] I think we need updated laws that really more appropriately balance the legitimate needs of law enforcement. [29:47.860 --> 29:54.260] And, you know, I have a lot of respect for people who are doing a really tough job in law enforcement. [29:54.440 --> 29:57.720] You know, there really are bad people out there and they really are doing bad stuff. [29:57.720 --> 30:00.000] And so I don't want to minimize that. [30:01.020 --> 30:02.980] There really are child predators. [30:02.980 --> 30:05.500] There really are people running guns that shouldn't be. [30:06.320 --> 30:09.140] We need to be able to stop that as a society. [30:09.440 --> 30:11.100] But there's a balance. [30:11.500 --> 30:14.940] And that balance is the legitimate privacy rights of citizens. [30:16.040 --> 30:25.760] So I think that, in particular, the Electronic Communications Privacy Act, the ECPA, really needs to be updated to reflect the world of social networking and long-term email storage. [30:26.340 --> 30:31.340] Your Facebook feed shouldn't necessarily be public domain if you don't want it to be. [30:31.340 --> 30:36.880] Your email shouldn't necessarily be very easy to get just because it's more than six months old. [30:37.060 --> 30:40.260] The technology's changed, but the laws haven't. [30:41.240 --> 30:45.420] It's really, really too easy for the government to conduct warrantless surveillance. [30:46.540 --> 30:51.540] So I think that, actually, if you're seeking political change, this is really important. [30:51.540 --> 30:55.640] Because the fact that it's so easy means that it probably will be done. [30:55.640 --> 31:00.320] And it also means, more likely, that your adversary is really lazy. [31:00.320 --> 31:07.080] So, if you happen to run an independent political campaign, use guerrilla tactics. [31:07.640 --> 31:08.660] Employ misdirection. [31:09.580 --> 31:17.940] And I think, actually, none of the above is really going to happen in the current, fundamentally corrupt political regime that we have now. [31:19.240 --> 31:23.900] So, fighting for change can really only happen by becoming the change. [31:24.620 --> 31:33.220] And with that, I'd actually, before I open this up for Q&A, like to encourage you guys. [31:33.220 --> 31:35.300] I've run for public office myself. [31:35.760 --> 31:47.780] And it takes around 10 years of working your way up from a local office to the point where you can actually credibly run for a serious federal office. [31:48.740 --> 31:50.560] And politics is really dirty. [31:51.820 --> 31:57.620] But, and it takes a really long time to be able to work your way up throughout the system. [31:57.780 --> 32:04.880] But the reality is that the kinds of people that are going into politics are not the kinds of people that probably, as hackers, we want there. [32:04.880 --> 32:10.320] So, complaining about what the government does isn't a strategy. [32:10.520 --> 32:12.380] Becoming the government is a strategy. [32:12.800 --> 32:22.280] And in the United States, unlike many places I've been and unlike where I currently live, we have the ability to change our government through elections. [32:23.000 --> 32:38.000] So, given that that's a right that we have, we really ought to not only vote for people that we want to be in Congress in Congress and making these laws, but seriously consider getting involved yourself. [32:38.320 --> 32:47.080] And even if you don't want to run for office yourself, if you're on a Congressional staff, you will have influence and access that ordinarily hackers don't get. [32:47.260 --> 32:48.780] So, please get involved. [32:49.020 --> 32:51.560] And with that, I'll open it for questions. [32:58.190 --> 33:00.710] Questions don't have to be about this subject, by the way. [33:00.870 --> 33:10.470] If you guys are interested in anything I've written about in previous columns, if you're interested in just anything in telecommunications in general, feel free to ask. [33:11.450 --> 33:11.970] Hi. [33:13.350 --> 33:20.710] You said that it's safe to assume that SSL and VPNs have been compromised. [33:21.930 --> 33:24.570] That's a very interesting and bold statement to make. [33:24.750 --> 33:26.390] Would you care to elaborate on it, please? [33:26.990 --> 33:27.350] Sure. [33:27.350 --> 33:33.550] So, there are markets where you can buy gear intended for what's called lawful interception. [33:35.110 --> 33:38.510] So, let's talk about a few of the things that have happened just in the last year. [33:39.970 --> 33:44.150] We've seen...so, first of all, let's talk about SSL just in general. [33:44.310 --> 33:50.750] And I think actually, you know, when you look at the vendors involved in VPNs, it's very similar. [33:50.750 --> 33:52.890] So, what is SSL fundamentally? [33:53.690 --> 33:54.950] How do you trust that? [33:55.130 --> 34:01.350] Well, what your browser is doing is it's looking at a website and seeing, does that website have a certificate? [34:01.850 --> 34:04.550] And is it issued by a trusted certificate authority? [34:05.210 --> 34:09.170] Well, then you have to look at who's a trusted certificate authority. [34:09.350 --> 34:11.890] And actually, like, it's a chain of trust, right? [34:11.890 --> 34:21.570] So, you can have a trusted root CA and then, you know, a couple of degrees of separation under that, you have, you know, a certificate that chains up to that. [34:21.730 --> 34:26.530] And your browser will actually be just fine as long as everything appears kosher. [34:27.210 --> 34:34.530] Well, there are governments, there are people...you know, this is a simplified explanation, right? [34:34.750 --> 34:39.010] So, you know, trust me, I'm an IT guy in my real life. [34:39.010 --> 34:40.790] I know it's a lot more complicated. [34:41.030 --> 34:41.930] We've got limited time. [34:42.130 --> 34:57.570] But the reality is, do you think that every certificate authority that chains up to a root CA really, really can't be influenced by government somewhere? [34:58.150 --> 35:00.390] And that's actually what you're up against, right? [35:00.530 --> 35:13.930] So, if you happen to be in some corner of the world that's a pretty dangerous corner, and you're dealing with an Internet that's using very sophisticated deep packet inspection software, do you think things can't strategically be replaced? [35:14.510 --> 35:18.910] I can tell you, based on my experience, they can. [35:19.390 --> 35:23.750] And if you look at VPNs, most VPNs are commercial VPNs, right? [35:24.590 --> 35:29.230] Commercial VPNs have lawful interception capabilities built into them in many cases. [35:29.230 --> 35:35.350] So, with OpenVPN, maybe you can trust that, but can you trust what's in between? [35:35.710 --> 35:41.210] And that's, you know, there's a whole host demand in the middle of tax that can and do work. [35:42.990 --> 35:43.770] Next question. [35:44.030 --> 35:44.330] Okay. [35:44.530 --> 35:45.190] Two things. [35:45.370 --> 35:47.910] One, just to address the SSL issue very quickly. [35:49.930 --> 36:01.950] HSTS and certificate pinning mitigate most of the risk that you've indicated in SSL, and as far as the commercial VPN vendor goes, typically the root certificate is issued by the corporate authority who's doing that. [36:02.210 --> 36:05.930] So, we don't have a problem validating and protecting the corporate VPN. [36:06.130 --> 36:08.310] Because the corporate VPN is chained to the root, which is the corporate root. [36:08.910 --> 36:10.670] So, but that's actually not my question. [36:10.970 --> 36:16.290] I just want to correct you on the SSL issue, because I don't think you have a full understanding of how SSL functions in reality. [36:17.790 --> 36:21.410] There are a lot of broken implementations of SSL, and that's one thing to keep in mind. [36:21.410 --> 36:24.930] So, we're not talking about protecting the people in this room, right? [36:24.930 --> 36:25.810] Well, no, but we're talking about protecting... [36:25.810 --> 36:33.590] You may be smart enough to do that, but do you think every implementation of SSL everywhere totally works and never is compromised? [36:33.950 --> 36:35.850] And, you know, if you can't say that, then... [36:35.850 --> 36:37.770] I don't think that invalidates the technology. [36:37.930 --> 36:38.350] That's the problem. [36:39.490 --> 36:39.850] Okay. [36:39.910 --> 36:40.370] I'll ask the question. [36:40.450 --> 36:40.530] Fine. [36:40.550 --> 36:40.690] Sure. [36:40.850 --> 36:41.490] Do you have a question? [36:42.770 --> 36:45.010] You know, reasonable people can disagree, right? [36:45.110 --> 36:48.830] I have a pessimistic view of this, and I actually think that we should always assume the worst. [36:48.830 --> 36:49.290] Right. [36:49.550 --> 36:51.950] You know, obviously hackers like to solve problems. [36:52.150 --> 36:52.190] Yeah. [36:52.190 --> 37:06.910] And if you can figure out a way to solve this problem where you're on a hostile network always, and you're up against adversaries with unlimited time and unlimited resources, and the ability to store traffic forever and bang on it with incredible, incredible computation resources, [37:07.470 --> 37:12.410] then, you know, I would very much invite everyone to solve that problem in a really easy-to-use way. [37:12.410 --> 37:12.870] Okay. [37:13.010 --> 37:27.170] So, my question is, as far as ECPA goes, did you actually find evidence that there was not a requirement for a warrant to get information about individuals? [37:27.370 --> 37:34.130] Because your comment regarding how you could get a user's call record, that's provided by a subpoena. [37:34.390 --> 37:38.990] But as far as my understanding of ECPA goes, you must have a warrant in order to actually get content. [37:38.990 --> 37:40.350] So, if you could address that, that'd be great. [37:40.630 --> 37:41.210] Oh, sure, sure, sure. [37:41.350 --> 37:43.670] So, you could get the...so, that's absolutely true. [37:44.190 --> 37:51.450] You can get the who's sending mail and who's receiving it in the subject line and the date and the time with the subpoena. [37:51.590 --> 37:55.010] If you want the actual content, that does require a warrant even after six months. [37:55.430 --> 37:59.090] The thing is, who you're talking to is most of the data that law enforcement wants. [37:59.250 --> 38:00.830] The content matters a lot less. [38:02.890 --> 38:03.390] All right. [38:03.930 --> 38:04.310] Hi. [38:04.610 --> 38:06.570] Eva Galperin, Electronic Frontier Foundation. [38:06.870 --> 38:07.010] Sure. [38:07.010 --> 38:11.010] You make a very interesting claim in the middle of your talk. [38:11.710 --> 38:16.410] You sort of titled one of your slides, Could a Twitter Revolution Happen Here? [38:16.730 --> 38:25.890] And I think that before you can really grapple with that question, you...can you demonstrate that a Twitter revolution has happened anywhere ever? [38:26.630 --> 38:29.370] Well, so, that's a very good point. [38:30.370 --> 38:41.550] The revolutions in, you know, when you look at popular media, the revolutions in Egypt, in Tunisia, and in Libya were called, largely called Twitter revolutions. [38:41.750 --> 38:43.190] And so, it's kind of become a catchphrase. [38:43.350 --> 38:44.950] Is it really a Twitter revolution? [38:45.190 --> 38:45.390] No. [38:45.990 --> 38:56.110] I will say that, especially in Egypt, Twitter and Facebook were organizing tools that were effectively used by protestors, at least in the early stages. [38:56.110 --> 38:59.730] Obviously, later on, when the Internet was shut off, they were less useful. [39:00.210 --> 39:08.610] But, at that point, you know, things had kind of gotten to the point where even shutting off the Internet and even shutting off cell phones still didn't stop it. [39:08.850 --> 39:09.430] So, no. [39:16.060 --> 39:16.540] Hi. [39:16.910 --> 39:17.140] Yeah. [39:19.080 --> 39:27.120] I kind of want to address your...I want to applaud you for the call to action at the end of the speech. [39:27.430 --> 39:27.890] Sure. [39:29.100 --> 39:41.520] But, you know, in Occupy politics land, when people talk about revolution and things, it's kind of...there's kind of this dichotomy between, you know, the reformers who are like, let's get into politics and let's change the system. [39:42.040 --> 39:47.160] And the, you know, people who are more interested in resistance, where it's like, take the streets, you know, tear it down. [39:47.410 --> 39:50.500] To be very clear, I'm not involved in Occupy at all. [39:50.660 --> 39:51.950] I don't even live in the United States. [39:52.160 --> 39:52.560] So... [39:52.560 --> 39:53.390] That's cool. [39:53.480 --> 39:55.270] But there's also, like, a third way. [39:55.620 --> 40:04.960] And especially when I think about, like, what people who have...who are very competent in, like, computer and software and server, you know, administration, things like that. [40:04.960 --> 40:15.810] There's a third way that's really important in gaining a lot of momentum in Occupy, which is the mutual aid portion of, like, technology, which is like, you know, there's open-source software for education. [40:16.040 --> 40:17.140] There's open-source software. [40:17.390 --> 40:22.480] You know, there's open-source software that can help schools, that can help hospitals, that can do all these amazing things. [40:22.600 --> 40:31.830] And most people in these bureaucracies that are dealing with, you know, the everyday work of, like, maintaining a school's technology infrastructure. [40:32.040 --> 40:45.700] Like, don't... aren't using the open-source options, and they aren't... they don't have... people aren't, like, making themselves available to help them see, like, an alternative way to, like, run, to, like, do, you know, to do, like, the basic services that people need. [40:45.870 --> 41:07.100] So I'm curious if... if you see... if you think that the hacker community had... like, what one would need to motivate the hacker community to kind of make themselves available to... or more available to, you know, local institutions that are providing education, [41:07.330 --> 41:22.350] health services, or, like, work with, you know, like, street medics and people like that to... to provide them, like, software solutions that they can use to do, like, to do revolutionary activity, to work more with non-profit organizations and maintain more websites. [41:22.520 --> 41:32.200] Like, how... how do we infuse social activism into hacker culture without it being about encryption, being it more about providing services to people? [41:32.620 --> 41:41.500] I think that it's a good point that, as hackers, if we're involved in our communities and people get to know us, that always gives us more visibility. [41:42.020 --> 41:51.450] The focus of my talk is actually governments largely doing things with technology and not thinking through the implications, right? [41:51.660 --> 41:55.250] We have a pretty massive surveillance infrastructure that's in place. [41:56.060 --> 41:57.500] It's getting more massive. [41:57.910 --> 42:07.810] And all of this has happened, really, without a huge amount of thought to what the long-term impact could be, right? [42:08.370 --> 42:25.000] What is the real impact of having a permanent record, where you can never make a mistake, where everything that you do, like, every piece of porn that you download when you're 18 years old, you know, becomes something that is permanently in a file someplace that the government can look at anytime that they want to. [42:25.000 --> 42:28.120] And, you know, this isn't conjecture, right? [42:28.350 --> 42:29.720] Like, to some degree, it is. [42:29.930 --> 42:47.640] But when you look at the tools that are available today, and you look at how powerful these tools are to regimes that really aren't nice ones and don't get the best tools, you can infer pretty well that that actually is the reality that we've built. [42:48.140 --> 42:50.040] Should we have done that as a society? [42:50.290 --> 42:52.680] And how are we going to deal with that in the future? [42:53.200 --> 43:12.960] And this is actually something that I I think that as hackers, we really need to get involved in a big way in politics, because we understand this stuff, we actually understand the power of the technology, and we understand ways, more importantly, to use the technology against real threats, [43:13.350 --> 43:20.930] and build technology, technical controls, such that it can't be used against threats that aren't real. [43:21.160 --> 43:22.720] And that's really what I'd like to see. [43:24.040 --> 43:24.600] Thanks. [43:27.660 --> 43:28.260] Hi. [43:28.420 --> 43:29.740] Thanks so much for your time. [43:30.060 --> 43:32.920] I'm a criminal and civil litigator from San Francisco. [43:33.180 --> 43:48.320] You made a really interesting point sometime during your discussion, pointing out a number of circumstances and concluding that violence, and I assume you mean physical violence, is becoming the norm dealing with nonviolent protests. [43:48.320 --> 43:48.880] Sure. [43:49.060 --> 44:01.360] If you look at the Occupy Wall Street protests, you know, as a matter of example, I consider spraying a student in the face at close range with, you know, serious high-pressure pepper spray to be pretty violent. [44:06.400 --> 44:11.120] Technically, it may be a chemical weapon under the Geneva Convention, somebody in the audience points out. [44:12.340 --> 44:23.780] I think that any time you've seen that there's a large-scale protest recently in the United States, it's a normal expectation that the police will be violent. [44:25.640 --> 44:26.080] Okay. [44:26.080 --> 44:29.720] And so you're mentioning the Occupy protests as an example, and I was just... [44:29.720 --> 44:31.640] Well, that's just the most recent set in the U.S., right? [44:31.840 --> 44:36.140] But if you look at this around the world, you know, I don't strictly have the U.S. [44:36.240 --> 44:36.820] focus, right? [44:36.820 --> 44:40.500] Other countries also respond to protests violently. [44:41.000 --> 44:42.860] So my question was... [44:42.860 --> 44:43.340] Sure. [44:43.720 --> 44:47.800] I was just wondering, do any other examples come to mind? [44:48.360 --> 44:54.140] Like most recent, most significant examples of that come to mind that have occurred within this country? [44:54.540 --> 44:56.080] Do any come to mind to you? [44:57.540 --> 44:59.140] Well, that's why I'm asking you. [45:00.120 --> 45:12.760] I think in the last year, we've seen the revolutions in Tunisia, in Egypt, in Libya, and we've seen the Occupy Wall Street movement as the major sets of political change, right? [45:13.020 --> 45:15.600] As major change agents. [45:16.540 --> 45:19.180] I think we've seen a lot of violence in all of those. [45:19.820 --> 45:25.460] In Asia, we've also seen some localized political blow-ups, particularly in China. [45:26.900 --> 45:31.300] You know, I don't want to get into too many details in China, given that I live there. [45:33.260 --> 45:42.000] But I will say that it generally is the norm that if the population is restive, the government doesn't respond peacefully. [45:42.580 --> 45:44.180] I would like to see... [45:44.180 --> 45:51.140] I would like to believe that it's true, but I think we've actually just had a real paradigm shift in the way that police respond to protest. [45:51.900 --> 45:56.160] And it's actually... maybe it's... maybe it hasn't been one. [45:56.400 --> 46:00.160] In the 1950s, during the Civil Rights Movement, there was a lot of violence, too. [46:00.420 --> 46:02.060] So maybe we'll just have to see that. [46:02.460 --> 46:04.420] I'm not seeing protesters being violent. [46:04.560 --> 46:05.840] I'm seeing the police being violent. [46:06.860 --> 46:07.500] Okay, yeah. [46:07.620 --> 46:14.680] So I was more concerned with our country and the response of government in our country to peaceful protests. [46:14.680 --> 46:16.560] And I know you mentioned Occupy Wall Street. [46:16.980 --> 46:24.180] And I'm just curious, in your opinion, if any others in this country kind of jump out to you most recently besides... [46:24.180 --> 46:28.480] I haven't been living here, so what jumps out to me is what gets covered in the media. [46:28.980 --> 46:30.660] Seattle 99 WTO. [46:30.660 --> 46:32.560] Yeah, Seattle 99 WTO. [46:32.720 --> 46:33.400] I lived there then. [46:33.700 --> 46:34.720] That's a good example. [46:44.360 --> 46:51.020] So somebody in the audience pointed out that political conventions are other places where there's often a lot of protest and some violence. [46:52.240 --> 46:59.300] I think the focus of my talk isn't really specific examples of where the police get violent. [46:59.640 --> 47:04.060] I think that we have plenty of examples already that protests can turn violent. [47:04.060 --> 47:08.140] And my concern really is that that is happening. [47:08.440 --> 47:09.080] Okay. [47:09.420 --> 47:09.760] Thank you. [47:09.980 --> 47:10.160] Sure. [47:12.860 --> 47:19.880] It was mentioned that government can turn off the Internet and government can turn off telephone service. [47:20.680 --> 47:30.680] Assuming that the government did turn off the Internet and before they turned off telephone, what is the feasibility of old-fashioned BBSs used to convey information? [47:31.840 --> 47:32.980] Completely feasible. [47:36.120 --> 47:38.660] It's also completely feasible they could be monitored. [47:39.080 --> 47:42.220] Keep in mind that it's not technically challenging to do that. [47:42.420 --> 47:42.760] Yes. [47:42.960 --> 47:49.040] However, the BBS services would not be disconnected until phone service was disconnected. [47:49.340 --> 47:49.740] Yeah, sure. [47:49.960 --> 47:56.960] So one thing that's really important to point out, you know, when we talk about BBSs, I used to run a BBS back in the early 90s. [47:57.920 --> 47:58.980] BBSs aren't anonymous. [48:00.140 --> 48:05.020] You know, there's a phone line that physically goes someplace that's running a BBS, right? [48:05.320 --> 48:16.300] So if you're trying to use a BBS to organize protests and you also want to protect the personal safety of whoever owns that phone line, that's a pretty tough thing to do. [48:16.820 --> 48:20.480] It's also incredibly easy to monitor, you know, dial-up BBSs. [48:20.600 --> 48:24.060] Modems are not complicated to log in and monitor in real time. [48:25.180 --> 48:28.380] I disagree with your assessment of SSL and VPN as weak. [48:28.620 --> 48:31.300] They're at least as strong as the providers are in the equipment vendors. [48:31.300 --> 48:40.140] So I wonder what do you think the best practices are for equipment vendors, service operators, everything else that are operating in various legal regimes to do this? [48:40.260 --> 48:42.200] Should they fully comply with law? [48:42.320 --> 48:43.840] Should they be actively trying to change laws? [48:44.000 --> 48:45.260] What exactly should they do? [48:45.580 --> 48:51.240] There's always a conflict between the term lawful interception and actual real security. [48:51.820 --> 49:01.760] I think that if you look across the landscape of, you know, large multinational corporations, they will always side with lawful intercept. [49:02.020 --> 49:10.740] And the reason for that is that if you don't side with lawful intercept, no matter where you're selling a product, then you're not able to sell a product in that jurisdiction. [49:12.080 --> 49:22.640] So, and when you look at what lawful intercept is, you know, particularly if you look at a country like Russia, they have a very broad definition of lawful intercept, right? [49:22.880 --> 49:30.960] So, this is why I think it's never safe to assume that whatever shiny crypto that you have is actually safe to use. [49:31.100 --> 49:36.900] Maybe it is, but if you assume that and it could get you killed or arrested, that's probably not a smart assumption. [49:36.900 --> 49:37.440] Okay. [49:37.580 --> 49:42.160] So, people should take into account the vendors they're buying from when they buy security-related infrastructure? [49:42.500 --> 49:42.860] Sure. [49:43.040 --> 49:47.080] Well, people should take into account, if they're using open-source, what bugs might be there. [49:48.420 --> 49:53.100] Does your criticism of SSL apply to SSH and GPG also? [49:53.700 --> 49:58.380] Man-in-the-middle attacks can apply to any cryptographic solution that's public key. [49:59.100 --> 49:59.560] Okay. [49:59.720 --> 50:00.020] Thank you. [50:00.640 --> 50:02.980] One-time pad is the only reliable crypto. [50:04.400 --> 50:04.960] I don't know. [50:04.960 --> 50:08.280] Just thought I'd close with, I don't know, a question. [50:09.820 --> 50:13.240] Give you an opportunity to share maybe some views that maybe we can all agree with. [50:13.360 --> 50:15.940] But I already know Palantir is creepy. [50:16.540 --> 50:17.000] Excuse me. [50:17.100 --> 50:20.800] I already know that Palantir is creepy, having been in their office, but... [50:20.800 --> 50:21.700] Well, I think they're creepy. [50:21.960 --> 50:24.020] Like, you know, the people who work there and... [50:24.020 --> 50:29.840] I'm just saying, could you share some story or some vignettes with us to... [50:30.400 --> 50:31.300] Well, okay. [50:31.480 --> 50:36.900] So, when we look at what Palantir does, it's actually, you know, just one step up from what Axiom's doing, right? [50:37.020 --> 50:40.980] And so, the technology itself isn't so creepy. [50:41.060 --> 50:44.000] It's actually what you can do with the technology and who's doing it. [50:44.240 --> 50:59.660] So, generally speaking, the idea of data visualization is gathering data from, you know, a number of disparate data sources on a particular target and trying to figure out what relationships they have to, you know, some investigative end, right? [50:59.920 --> 51:05.120] So, maybe what you want to do if you're Axiom is you want to figure out how to sell people things. [51:06.060 --> 51:13.420] Maybe if you're a customer of Palantir in the intelligence community, you want to find out whether somebody's a spy. [51:14.100 --> 51:24.640] Or maybe if you have access to this incredibly powerful technology and you are an oppressive regime, you know, some tin pot dictatorship someplace. [51:25.360 --> 51:29.040] You want to figure out who your political opponents are and actually kill them. [51:29.140 --> 51:30.380] And this is real stuff, right? [51:30.780 --> 51:39.260] You know, I live in a corner of the world, like, you know, near Southeast Asia where a lot of really bad stuff happens in a lot of really unfriendly regimes. [51:39.540 --> 51:41.140] Like, you know, I'm not far from North Korea. [51:41.260 --> 51:41.780] I've been there. [51:42.160 --> 51:43.560] I'm not far from Myanmar. [51:43.840 --> 51:47.540] Like, these are not places where political opposition is tolerated, right? [51:47.540 --> 51:56.580] So, when we make these tools in the technology community and they fall into the hands of governments like these, real people can get killed. [51:56.900 --> 51:59.300] And this actually really worries me, right? [51:59.600 --> 52:07.300] And what also worries me is, what if our government is, you know, at some point becomes less benevolent than it is now? [52:07.660 --> 52:13.760] What if, at some point, you know, Western governments start to look more like something like North Korea? [52:13.760 --> 52:19.640] We could guess that it would never happen, but also people in the Weimar Republic thought that it could never happen. [52:20.840 --> 52:22.060] Thank you very much for your time. [52:22.320 --> 52:22.780] It's a great talk.