Old political labels don't apply in the fight against Section 215. Arendelle Books' Philip Bevis, who says he's a member of the NRA, believes that when the full ramifications of the provision become clear to not only booksellers and publishers, but a wide variety of powerful organizations, the NRA, the American Medical Association, or the credit card industry, it will be a slam dunk for Congress to repeal the provision. In the meanwhile, many in the book industry have signed on to independent Congressman Bernie Sanders' Freedom to Read Protection Act and Republican Senator Larry Craig's Security and Freedom Enhancement Act. Philip Bevis. I'm in the government. Okay, for the exciting conclusion to this story, tune into the rebroadcast at 11.30. It's four minutes after seven o'clock now. I think that's well enough time to get started with Off the Hook. Off the Hook. And a very good evening to everybody. The program is Off the Hook. Sorry for the late start. We have a lot of ground to cover. Jeff, welcome. Thank you. And Mike Redhack and Leo over there. How are you doing? We have special things to talk about tonight. First, any news from you guys? Nothing at all? No, no. Nothing at all. You've got an entire week and you've got no news. Well, I've got lots of news. Dell has canceled Indian tech support. After an onslaught of complaints, computer maker Dell Inc. has stopped using a technical support center in India to handle calls from its corporate customers. Some U.S. customers have complained that the Indian technical support representatives are difficult to communicate with because of thick accents and scripted responses. You know, whenever I talk to American Express, it's always in India, almost always. Sometimes it's in Canada. I find them to be more helpful than when they're in Ohio or something. So it's, you know, kind of weird. But it's mostly unfair to the people over there who get paid such tiny wages compared to what you would get paid here in this country. And that's the real reason, of course, they're doing it. But apparently, Dell had a lot of complaints, and that was the result of that. It's true about them being really scripted responses. I remember maybe two years ago, I was on the phone with Dell technical support, and I was speaking to someone who was in India, and their only response they could give me for anything was, Format your hard drive, over and over again. And as soon as I got in line with somebody else, it was fine. This is a problem not limited to people in India, though. I've chatted with U.S.-based tech support people who know even less. Just last night, I was talking to Time Warner Cable people, and boy, you might as well be talking to voice automation, really. They just keep telling you the same thing, and the same problems keep happening. But I'm not going to get into that. I'll be talking for a half hour. We have some listener email from people that are interested in the whole cellular phone portability. And Bernie joins us from Philadelphia. Bernie, are you there? Yes, I'm sitting right by Independence Hall here in Philadelphia, shivering. Are you allowed to do that anymore? There's a Wackenhut private security guard watching me. They sort of hired Wackenhut guards instead of the Federal Park Police to guard our national shrine here. Wasn't Wackenhut kind of implicated in all kinds of beating deaths and things like that? Yes, they run a lot of private corporate-owned prisons. Prisons for hire. He's eyeing me steely, with steely eyes. These are real prisons that they run, not just workplaces that some people refer to as prisons. These are actual prisons, but they're owned by a corporation who charges the government to run them. Wow. And they're in charge of Independence Hall right now, Wackenhut? They're in charge of the immediate security perimeter around Independence Hall. And they're armed? They are armed. In fact, I asked one of them about that. He was proud to cite his Federal certification for carrying a firearm. You can tell they're Wackenhut because they have tan slacks. Tan slacks? Tan. Tan as in beige slacks. And the Federal Park Police have dark green slacks. The difference is that simple. They can't just change their pants. I guess not. Well, at least not when it's cold. This isn't a joke, Bernie. Wackenhut is really the name of a... Oh, yeah. That's big time. They've been around for years. They're like a multi-billion dollar company, Wackenhut. And international, too, right? Yep. I was waiting for a punchline. No, no punchline there. No bad jokes this week. But just be careful, Bernie. No sudden moves, all right? Okay. We were talking a little bit about cellular portability. Have you heard any fallout since it began last week? I've heard that some people, not firsthand, but just postings on the Internet, people have warned that the one thing you should not do is try to change your carrier online. Because if you do that, what will happen is your first phone will be shut off before your second phone is reactivated. So they recommend dealing with live people and urging those live people to make sure that you don't experience any downtime, or at least no significant downtime. Because you could be left without a phone for a couple days. It works. Except by calling 911. This listener writes in to ask if we'll still be able to find out which carrier somebody has by their phone number. Obviously, that's not going to work anymore, is it? No, that's going to be tough. You can tell from Philadelphia, the 432-215-432 exchange you know is print PCS. Well, not anymore. It could be anything anymore. And that brings up another interesting issue as far as this whole do not call telemarketing list. If you transported your home number to a PCS or cellular number, the exchange could still be in the list of exchanges that telemarketers call and they wouldn't know it's a cellular phone. So you could start getting... I predict sometime in the next year you're going to start getting people, telemarketers calling at cell phones. And that's going to make a lot of people, because they're paying to receive those calls in many cases. Well, I predict sometime in the next hour someone's going to call us and say that that's happened to them already. I'll bet you're right. All right. I get a lot of spam. I get a lot of spam e-mail to my Sprint PCS phone. And if you look at them, they're clearly directory harvest attacks type spam where they just go through the alphabet at sprintpcs.com and just mail. Have you gotten any of those? No, I have not. Well, I get a ton of them. And I've never sent my Sprint PCS e-mail address to anybody. And you can see that they just go through a variety of alphabetic combinations and just arrive at these different addresses. And Sprint seems to have no interest in blocking these. They have a provision for blocking like anything at yahoo.com where a lot of these seem to come from. But the filters don't work on their website. Well, the reason it doesn't work for me, I suspect, is because my e-mail address apparently was disabled. You see, I don't know if you recall the story of a couple of years ago, but I tried to get a manual at sprintpcs.com, and someone had taken that. So I tried to get some other names, and they were all taken. So I just got very, very angry, and I just put an obscenity in front of the word Sprint. I remember when you... And made that my e-mail address. And that was accepted, and I had that for a good long time. But then for some reason, somebody at Sprint must have caught it, and they just made the password not work anymore. And I'd feel like a fool calling them and saying, yeah, that's my e-mail address, you know, and sort of insult them on the phone and expect them to reactivate it. I think you should call them on the air and ask them about that. Yeah, but then I'd be in trouble on all different levels as well for saying that. You'd have to beep yourself out so they could hear you, but the audience couldn't. Yeah. Now, this other person writes in wanting to know concerning the portability issue. They were told that they could not transfer their phone number over because they had a prepaid account. Do you know anything about that? I have heard that this does not apply to prepaid phones. It doesn't have the same... It's not really looked at as a regular account in your name, even though it kind of is. A prepaid account, the listeners aren't aware of that. You pay as you go. You give them like maybe $50 or $100 a month or whatever you want to pay ahead of time, and then it's deducted, kind of like a debit card. But apparently the FCC didn't require carriers to include prepaid phone numbers. I don't understand the logic behind that. It's a phone number just like any other number. You would think so, but I've heard several people say that they have run into that same problem. Aren't there some prepaids that are anonymous? Yes. Yeah, and I think that's why it falls into the same category. Well, there are prepaid accounts that you can have in your own name, and then there's ones you can just make up a name or be anonymous. I still don't see how that affects the phone number, though, if you're anonymous. It shouldn't, but, you know, it's just one less thing the carriers have to do to... It's one less way, or I should say it's one way the carriers are avoiding having to lose accounts. Well, I think it also might point to a software problem in that they can't figure out how to do this. Like what if somebody changes their number and then changes their class of service? You know, it might crash the whole system or make somebody get cell service for free. Who knows? God forbid. Yeah, God forbid. We also have this from an Australian listener. Here's a new service introduced to the Vodafone mobile phone network in Australia. It seems a bit strange to me. Their advertisement is dial 1-2-3 and ask us anything you need to know. We'll do everything to help, from street directions to movie guides, even your wildest trivia questions. 1-2-3 is a premium rate service. At 1-2-3, we love a challenge. Ask us any weird or wonderful question you've got. How many hearts does an octopus have? Where did Led Zeppelin get their name? I wonder if I get money for that if I work for them. What sound does a giraffe make? Ask us. No matter how trivial, we'll do everything we can to find the answer. Maybe type something into Google. They probably do that. I'd love to run a service like that where you just have people calling you, asking you the silliest questions, and you do your best to find out. Who knows how much they get paid for that? How much per minute? How much per minute? That's a good trivia question right there. I'll bet you can call them and ask them that. Google actually runs an online service where you can pay to have a list of researchers search your question and answer it for you. Check that out. I haven't ever used it, but it seems intriguing. This other person writes in with a complaint. Dear 2600 and Off the Hook, I consider myself to be a hacker. Not a computer hacker, but a hacker all the same, being a locksmith by trade. I have always been interested in how things worked and technology in general. I was recently given a new CD as a gift by my teenage children, Let It Be Naked by the Beatles. I just got that, actually. On first look, I noticed the copy protection logo on the cover in place of the CD digital audio mark, and then read the disclaimer on the back along with the Windows, Apple, and DVD video logos and a warning that it may cause problems with certain equipment. This is obviously not an audio CD, but is in fact a CD-ROM. Wanting to test its format, I did what any person would do and attempted to play it in every CD player I owned. It played successfully in my home audio system, but not my older CD player, nor one of the five DVD players in the household, or my card player, which also plays MP3s. It just read file checks, so I thought I could do what I do with all my CDs I own, and most of my collection of vinyl, by the way, and make a backup to play so I can preserve my original and rip a copy for my archive. I popped the CD into my PC, and it was definitely a CD-ROM wanting to install a software player of its own. I then hit the copy button in Nero, and it copied in a few minutes without any problem whatsoever. I was shocked, but I still could not play the songs on my PC. I installed the Windows Media plug-in that came with the CD, and it then opened up as an audio CD in the only program that could read it, Windows Media Player. I then copied all files to my hard drive with digital media rights turned off as 160 kbps WMA files, which I then burnt back to disk as an audio CD. I then removed the WMA files and ripped the audio CD back to my preferred format of MP3. We're not going to be going over these steps again for those of you who want to do this. What an absolute waste of time. My children informed me it was purchased from the local Sanity CD store from the audio CD section, not the DVD section, so I took the quote-unquote CD back to the store and demanded a refund. After a lot of explanation to the untrained staff that this is not an audio CD, which is what my children thought and expected, I was at first refused a refund, but after an hour or so, the store manager eventually received a refund of the $30 they paid for this crap. I don't think I paid $30 for it, and I haven't even opened it yet, so if I get this kind of a hassle, believe me, there's going to be some problems for somebody. I then, of course, removed the files from my PC, destroyed the audio CD, and went back to a much superior sound of my vinyl collection. Signed, Breto. Well, thanks very much for that little saga there, but boy, when I bought this thing online, it said nothing anywhere about it not being a regular audio CD. In fact, I looked at the receipt, and it says audio CD on the receipt, so if this causes me any problems whatsoever, it's going to be a big major case. Take it back. There's a copyrighted and trademarked term called compact disc. Right. And that means that it's a red book format, meaning it will play, you know, it says real audio CD. Hello? Hello? Uh-oh. Yes. Hang on. Hang on. We seem to have lost one of our guests. Hang on. We're going to have to turn this down and figure out how to put these people on hold. All right. This really kind of stinks because I've got to call overseas now. Now, Bernie, are you still there? Bernie? I'm here, but you can kick me off if you have to. No, I don't have to kick you off. In fact, I can probably put you in a better place now that this other line seems to have opened up. Can you put me in some place warmer than I am right now? I don't know if I can do that, but all right. We're going to have to try to make a phone call live on the air because we had somebody on hold. We had a special guest on hold. Now we have Bernie on hold. All right. We're going to get a dial tone. Okay. But you know what? I lost a piece of paper where I had the person's phone number. We can just listen to the dial tone. Yeah, we can listen to the dial tone. It's always a nice soothing sound. All right. We're dialing a whole bunch of numbers here because we're dialing overseas. Of course, I had to do this several times before because our phone system got confused. There's always the chance that we're going to get connected to a total stranger. Waiting for the special tone now. A total stranger who may not want to speak English or be woken up at this time of night. Yes, we're calling over to Germany, in fact. It's 1 a.m. there, isn't it? Yes, it's after 1 a.m. We can use this as a way to introduce our guest. That's a ring over there, by the way. Let's hope it picks up. Hello, is this Frank? Yes. Frank, hi, it's Emanuel. You're live on the radio. Okay. We lost our connection. We're going to attempt to hook you in with Bernie S., so please hold on for a moment. Bernie, are you there? Okay. Okay. That sounds like Bernie freezing his ass off in Philadelphia. Yes. Okay. Frank joins us, actually, from CCC over in Berlin, and we want to talk to you tonight about an invention you guys have come up with, a bunch of you, actually, some collaborators from Holland as well as Germany, a device known as the CryptoPhone. It basically allows you to have encrypted conversations between cell phones. It's caused quite a stir in the community, in all kinds of different communities, the hacker community being one, but also the law enforcement community as well, because they, I guess, would like to be able to listen in on everybody's phone calls. Frank, why don't you tell us why is there a need for something like the CryptoPhone? Are cellular phones really that insecure? Yes. If you look, especially in the U.S., where there have been a lot of political scandals connected to intercepted mobile phone calls, there should be some sort of consciousness about how sensitive mobile phone calls can be. In Europe, the normal mobile phone standard is GSM, and GSM has some sort of encryption on the air, that means between the cell phone and the cell phone tower, but not after the signal is received by the cell phone tower and piped into a mobile phone network. That means it's only protected on the air, and this encryption is very weak and has been broken time and again. So we felt that it's time now to set up a system that allows it to have full end-to-end encryption, to communicate secure and not being intercepted by economic criminals or whoever else wants to listen in. Well, let's just focus for a minute on the GSM encryption being cracked. You say that's happened a few times. There have been a number of papers in the cryptographic community about the weaknesses in GSM encryption. There are several modes of GSM encryption. The most prominent are A5-1 and A5-2. A5 is the name of the base algorithm, and the A5-1 is one variant and the A5-2 is another variant. They have been both broken and can be broken with moderate equipment. What's even more important is that GSM is not protected against man-in-the-middle attacks. That means someone can play to your mobile phone and say, OK, I'm on the cell phone tower and everything is fine. By the way, I leave out this nasty encryption thingy, and you won't notice as a user because your call is being piped through to the network, but in between, encryption has been disabled on the signaling level. These devices are called IMSI catchers. They are available on the market. They are even now passive. That means not man-in-the-middle, but really off-the-air snooper systems that can be used to intercept GSM calls if you know the secret key of the network. These devices are being sold for around $80,000 from companies in India, for instance, and they are easily available. You cannot say that cell phones are secure anymore, not even the GSM ones. Bernie, what was the device that you almost bought at a hamvention in Ohio that was some kind of a GSM monitoring device for Europe? It was a European GSM... Bernie? Oh, no, he's been silenced. I'm here. OK, say that again. We didn't hear you. Can you hear me now? We hear you fine. I observed and almost purchased, somebody else, a spooky guy beat me to it, a mobile surveillance platform for the European GSM frequencies, and it consisted of several Watkins-Johnson receivers in a suitcase with wheels on it, a SCSI tape drive, an iPhone, and a computer interface, and you have to use it with an external laptop. I was about to buy it, and some spooky-looking guy behind me plunked down the money and walked off with it. But that was not an MC catcher, I believe. I'm not sure what it was, but I think it was just for logging the GSM data for later decryption, although I couldn't understand why there was an earphone on it. Watkins-Johnson, their biggest market is to government surveillance entities like the National Security Agency, CIA, organizations like that. But the MC catcher is a different piece of gear and much larger in size. But they're probably in use in the United States as well, so I wouldn't trust my GSM calls to be secure anywhere in the world. In addition to that, of course, as Frank already knows, the connection leading up to the wireless part is, of course, prone to be intercepted at any point, right? Sure, and the connection between the towers as well is not encrypted at all. It's just simply digital, which, you know, the encoding schemes are readily known and available. Is that right, Frank, that the connection between the cell sites is open? Yeah, they're plain and open. The signaling is quite simple if you're used to ISDN signaling, and it's not a huge difficulty to intercept a signal. These are quite standard 2 megabit or multiples of 2 megabit trunks, at least in Europe, and intercepting them is possible with this gear that's available for, let's guess, if you get some surplus gear, about $20,000. So that's not really difficult and you can get in an awful lot of calls if you're picking the right cell phone tower. And the cell phone towers are linked by microwave links because most operators do not have the cheap cable network that incumbent operators have, so they're hooking up networks of microwave towers that are basically spreading over all of the cities here. So certainly an employee of a GSM company would be able to, with the right equipment, obviously, would be able to intercept calls fairly easily, and I imagine law enforcement has a relationship with these companies where they can do the same thing. Yeah, law enforcement has, of course, normal interfaces that are standard that are required for any operator to put in there. But even if we leave the law enforcement out for a moment, all phone companies have intercept equipment that they need to combat fraud. That means they listen in at any point they want and on any user they want for the purpose of monitoring fraud. And, of course, this cannot be controlled. Who is intercepting what and what calls are solved by corrupt employees there. Now, this is only GSM we're talking about now. I imagine the other cell phone services, Sprint PCS, Nextel, those companies, they don't even encrypt their signals, do they? I don't know the situation there so much in detail. The only thing that I know is that the GSM networks are using basically standard European equipment. So maybe Bernie can put a bit more on the analog control systems. Sprint PCS uses CDMA technology. And it's digital like all these other TDMA, which is what AT&T uses, although AT&T also uses GSM. But I do know for a fact that Sprint PCS's signals are encrypted, but it's probably weak encryption, and apparently it's not a readily available or published or open specification. So it probably would not be difficult for someone who knows people at Sprint PCS to do this. In fact, there's a whole network of monitoring that Sprint has built called SINS, S-I-N-S. I forget what it stands for. But basically it allows law enforcement officials to monitor any Sprint PCS number over the Internet with the right software on their local workstation. So this is easily done, and all they need to do is get a warrant or have a friend at the carrier, and this can be done, and your calls can be monitored. I don't know much about it in terms of the cell phone encryption, but for Verizon I do know that on their phones at least they have settings for voice privacy, which I assume is some sort of weak encryption algorithm. So I mean it's there in the phone. The user sets it? Well, you can set it to enhanced or standard. I assume enhanced would mean encrypted, standard would mean unencrypted, but that's probably just some sort of key that's for the whole network. Enhanced could just mean suspicious. Maybe we should watch this guy. Who knows? Okay, so we've established that these phones are completely insecure and that there is a need for people who want to have secure conversations for something like the crypto phone. I imagine that's the thinking that inspired you guys to do this, right? Yes, basically we thought that now the technology has arrived that we can produce this kind of security. Since processes in mobile phones and PDAs have become fast enough over the last years, it is now possible to do the whole process of voice encoding and encryption and decryption and playing back the voice and protocol handling and so on on something like a normal PDA. So these PDAs contain now 200 MHz ARM processors, which is much faster than what they had several years back in our personal computers. And so there is now enough processor capability available and will be available in a rising number of devices. If you look at the latest generation smartphones like the Nokia 3650, they are quite fast enough to do the job now. And by that we were able to come up with a system that is completely open source. So we can publish the inner workings of the system and make it trustworthy encryption, not just some black box encryption that is being done by some guys you don't know. Now, you actually introduced this a couple of weeks ago. I know you've been working on it for quite some time, but the actual product came out a couple of weeks ago? Yeah, we worked on it for two years now and we announced it about two weeks ago. And tonight, if I get to work again after the interview, we will probably put up the source code and the free Windows version, and products have been shipping since yesterday. Okay, so you're releasing free Windows software and source code today? Yes, that's the plan. It could be that it will sneak onto tomorrow because we need to do some reformatting and documentation to make it a bit more nice and readable. But the plan is to do it today or tonight. Now, what kind of response have you gotten since this was introduced? We've gotten much more response than we expected. So we have been internationally and basically every major tech press. And from the emails that we are getting, I can see that we have been in the press in countries that I have never heard of. And the people are mainly saying, okay, I want this product, I want to know it, I want to read the source. And so the word is spreading really fast. It looks like people have really waited for it. And my impression is that we get more response from countries that have laws that allow for easy interception by basically anybody than from the countries that have more strict interception laws. What kind of response have you gotten from the US? I got a lot of interest from the US. The problem is that we currently have not ready for shipment and product that is capable to work in the 1900 GSM networks that the US choose to have instead of the GSM 900 and 1800 that the rest of the world uses. Yeah, we just like to be different. Yeah, I know that. So we will have a 1900 phone probably available in January. Don't name me on it, but that's the plan. Based on the hardware, it's also capable of using 1900 GSM in the US. And there has been a lot of response from the US, from Canada. And people are asking, how can you buy it and where can you buy it? And will the Windows version be ready? And so there's a lot of interest because obviously people know that there are a number of different other encryption products on the market, but that they cannot look at it and cannot verify the encryption. Two questions. First of all, the encryption itself, it happens on the digital audio signal before it goes out onto the cell phone network? Yes. And secondly, is it public key cryptography? Do the phones send a key to each other before they start the conversation? Is that how the... Yeah, the key exchange is being done by a 4096 bit Diffie-Hellman key exchange. And to prevent man-in-the-middle attacks on that, you get a four-digit, sorry, a six-digit hash of the session key, and you read out the first three characters to a partner, and your partner reads the second three characters so you know that you're on the same session key and have no man-in-the-middle in your Diffie-Hellman. Now, of course, the person you're talking to has to have one of these as well. Yes. I'm really surprised about it. About 20% of the questions that I get is, do both partners need the crypto phone? So this is a little bit surprising because we have not thought about it, that people could come up with the idea that you could make something secure with having a secure phone only on one end. Until somebody told me, okay, that in a lot of spy movies that's exactly how it's being shown, that you need to have a secure phone that disables any listening device on the line, which is, of course, pure bullshit. Right. Well, you know, of course, we won't be calling payphones with something like this because that would be completely wide open. Yeah, I've got a couple of questions. Frank, is it possible to turn the encryption off when you're using the phone as well if you wanted to? Yes. Let me maybe put some more technical background to this. What we're using is a device that's in the U.S. being sold under the name SX56 or in other parts of the world it's being known as XDA, which is being made by a Taiwanese company called HTC. It's basically a PDA that has a 206 megahertz ARM processor and a GSM engine in there, and we are running it on top of that PDA or software. That PDA, of course, contains also an unencrypted phone application, an application for sending unencrypted SMS and so on. So that's basically the normal PDA. Since the PDA runs on Pocket PC 2002, Windows CE, an early incarnation, we restricted a lot of features on the thing. That means we kicked out all the Internet Explorer and GPRS and WAP and all the network protocols that are possibly harmful and just left in the minimum necessary stuff that is necessary to communicate, meaning our encrypted phone application, the unencrypted phone application and SMS things. I noticed from your web page that the standby battery life was 150 hours. You had 30 hours of encrypted time. Three hours. Excuse me, three hours. And then another three hours of unencrypted time. So I thought, well, I didn't quite understand all that, but now I do. Thank you. That website, by the way, is www.cryptophone.de. And Frank, I noticed on that site you answer the question, and you answer it with corporate executives, lawyers, accountants, bankers, mergers and acquisitions specialists, consultants, journalists, law enforcement officers, government officials, doctors, private investigators, and other people who simply prefer to communicate in private. Now, it's that latest group, the last group that I'm most interested in, the average person out there that just wants to maintain privacy. Are you getting a lot of interest from people like that? Yes, of course we get. The problem that we currently have is that the product is quite expensive for, let's say, non-business interests. So it's selling for about 1,800 euros, and with your massively declining dollar value, it's quite expensive in dollars. And so people are asking, okay, could you get it cheaper? Could you get it cheaper? And how could we achieve a lower price? The first thing we released, we'll release today, hopefully the Windows version for the crypto phone. That means you can install it on any laptop that runs Windows and has a modem on an SDN card, and use the same protocols and cryptography to communicate between two laptops. It's a very simple application. It has not many features, but it should work very well and provide quite reasonable voice quality. On top of that, you can also phone with this application to mobile crypto phone users. It means if you have a friend who has a mobile crypto phone, you can just call him with the Windows application, and he can call you from his mobile phone on your Windows laptop. Of course, we are working on a much cheaper version. We cannot announce any definitive plans now, but we want to get it really down to make it affordable for basically everybody who can afford a $500 phone. You have software that works over the plain old telephone systems. How feasible would it be to make some sort of device that could be put over the handset of a regular telephone and do the same sort of encryption? The point is that we checked on what could we do for normal telephone stuff, like the Starium that did for putting it between the handset and the telephone. But that market isn't that interesting for us because most people, at least in Europe here, are beginning to put down their landlines instead of just using mobile phones exclusively because mobile phone usage is getting cheaper and has much more interesting properties than landlines have. So there's also a lot of other encryption products for landlines available. So that was not our main focus. We wanted explicitly to do something for mobile phones. But with the Windows software, it is very easy to build yourself a cheap landline box by just purchasing a cheap billboard, put the Windows software on it, and there you go. You have a cheap landline phone that does doing encryption. Frank, I have a question. The Windows software, of course, you said, would allow a crypto phone caller to call me even though I don't own a crypto phone and I could talk to them with a headset on my laptop or PC and make calls. That will work over a regular plain old analog line? Yes, it works over a plain old analog or SDN. You do not need a high bandwidth connection? No, you don't need a high bandwidth connection. It's all dial-up. The codec that we use in the current mode needs only 9.6 kilobit because that's what we have as a data channel over the GSM. I have noticed that there are public telephones here in the United States and probably in Europe. I did some alpha testing for Starium Corporation a few years ago. The AT&T Public Phone 2000, which I'm sure Emanuel has seen in airports and hotels and so forth, it's a public telephone that has an RJ11 jack where you can actually connect a laptop modem or something like that. So conceivably, if you wanted to talk to someone who has a crypto phone securely, you could walk up to any of these AT&T Public Phone 1000 or Public Phone 2000 and plug in your laptop with your crypto phone software and connect right to the payphone line and communicate that way with anonymity. Well, now, Frank, it's obviously an interesting option to use, yes. You must be getting all kinds of negative feedback, though, from people who say that, well, this kind of thing will be a great tool to have in the hands of terrorists. How do you respond to that? Okay, the point is, we got, of course, some of these feedbacks, but mainly from the right-wing press, as expected. In my opinion, the point is very simple. Currently, the world is much more endangered by people who are listening in to your phone calls, and this also includes terrorists. If you look at the price tag, if you're a major good finance terrorist organization, it's very cheap to buy an ATK dollar device from India and then listen in, for instance, to Homeland Security operators using their cell phones without encryption. On the other hand, if you look at the damages that are being done by economic espionage, a lot of that is being done by intercepting cell phone calls. Then you see that the damage that is being done by having no encryption is much greater than the damage that can be done with encryption. On the other hand, there have been a lot of encryption products on the market. If you look at the known communication patterns of terrorists, that's basically nothing that they would use because that would light up on the screens of the NSA with red blitz. Well, now, do you expect this to result in some kind of backlash from various governments, possibly our own, that having such a device is tantamount to being suspicious just by owning a phone that can do encryption like this? Okay, there are a number of other encryption products on the market. So they are not open source, but they are on the market and some of them offer quite strong encryption, at least nominally. And so if they would go to outlaw or make it suspicious or whatever to own our device, they would seriously have to explain what is with all the other devices. So because it is not legal, I can sell the device in Europe. The government here in Germany is very, very friendly to encryption software. You know that the German government sponsored the further development of GPG to make it possible to make it a much better product. And we are receiving, on the contrary, we are receiving a lot of positive feedback here from our local government. There has been some outcry, at least in the Netherlands, where the government feared that massive interception of cell phone calls that they are using for all kinds of stuff in the law enforcement field might get hampered. But essentially, also in the Netherlands, a lot of encrypted phones have been for sale and the police haven't tried out on them. So the interesting question then comes up, so what is with all the other phones? Frank? Yes. I have one other question. You mentioned other devices on the market. I have noticed that Rode and Schwarz, I believe it is a German test equipment company, they have a secure GSM phone, or they call it a secure GSM phone. Qualcomm here in the United States has a secure CDMA phone, so they call it secure. And Motorola also has a secure cellular phone. I am not sure which technology it uses. What will be the difference between those companies' technology and the crypto phone that we are talking about tonight? If you look at most phones that are on the market, they are using only 1024-bit RSA for the session key. And the problem with that is that 1024-bit RSA is not enough anymore. If you look at the latest papers published by BHM and Co. that showed that this key length can be broken within the near future with moderate effort, I mean moderate force from somebody like NSA. So these kinds of phones are not offering enough security from a cryptographic point of view. On the other hand, these phones are closed box products and some of the manufacturers that make them have known ties to the intelligence community and are known for having their background deals there. And so you can simply not look into it. And the big difference is on one hand our security, our cryptographic security is much higher and on the other hand you can verify it. That's interesting. You guys are not a hardware manufacturer, right? No. The beauty of the concept is that we are not bound to that specific phone. We just choose that one because it was most convenient to get and it was the cheapest platform that was fast enough for what we wanted. We can run our software on anything that has a decent 200MHz ARM processor. That's basically the minimum requirement that we have to have the codec running in sufficient quality. So if you take a market survey, there are now I think 10 or 15 mobile phones and PDAs with GSM on the market that are sufficiently fast enough to run our software and you cannot expect us to go to these other systems very soon. And we expect that encrypted telephony will be something that might be standard in two years on everything that's fast enough to run it in the mobile space. Now I was going to say that someone mentioned that Motorola and Qualcomm have developed these systems for government use and they don't sell them to people like us. They could if they wanted. Motorola could put this technology in every phone they sell but they have a vested interest in not doing so which I think points to why we have to go to sources like you guys to really get the security that we may want. The point is that what we are doing even from a business perspective is completely different than what Motorola does. We have pointedly not tried to achieve all this kind of military tempest security and all this kind of government certification that is needed to be able to be purchased by government officers. Our system is just a software that should qualify to some criteria like it's open source, it's strong crypto and so on and so on and it's just much cheaper to develop. So if you look at the prices that Motorola calls for their phones and all that Roland Schwarz calls for their phones, that's much higher than what we charge and to get an inferior system for that. They are pointedly trying to limit their sales to government and related groups just because these people are willing to pay these high prices. Interesting. So basically your system is open to everybody and I imagine it's making the people that normally have access to this kind of thing a bit nervous. Are you prepared for them to make all kinds of demands of you, to turn over your customer list for instance, things like that? How will you respond? We are based in Germany here and as I told you the German government is quite sympathetic to strong encryption efforts and they have even sponsorship efforts to create a strong and independent German crypto industry. That's something that the German government really wants to have for a lot of reasons, most of them economic. So they know that interfering with the interests of these companies or trying to force them to do something or whatever would simply erase the business place here for anything crypto related. The current German government sees a strong crypto industry as something that they really want to have for all kinds of reasons. One of them is that Germany is one of the biggest export countries in the world. There is a lot to lose if the industry interests are not protected by proper crypto. So of course we have implemented a lot of technical measures that would prevent a leak of customers and stuff like that. But on the other hand, we are here in Germany and that's not something that is like okay we would be based in New York or whatever, the FBI just could show up and say hand over the customer list. Do you think there is going to be a problem having these sent to the United States? Would they be seized by customs or anything like that? That is something that we will be very interested to see. So currently most of our sales have been done in Europe in the European Union and here this is common market and there is no customs requirement inside the EU. And some of our shipments have also been done to countries outside the EU but these are also not a problem. But so far we haven't shipped anything to the US and we will see. Are there any places you won't ship to? Of course. There is a number of countries that we cannot ship to under German export control. Let's say the usual suspects like Libya and Iran and so on and so on. Basically these are all the countries that I have no business interest in shipping to. These are countries that are mandated by EU and German export law that we would need a very special export license to export to them. And we don't see any reason to apply for that. We have not had any interest from there. So then secondly there is a list of countries that we need to ask for an export license. These are countries like China and some other major human rights violators. And there is a third list of countries that we need to ask for an export license if the customer is from the military or intelligence or police community. And of course we need to check every customer against a list of known terrorists and terrorist support organizations that is also an EU mandate. So that's basically the export regulations in a nutshell. The countries that we can ship without export regulations is basically the European Union plus all the countries that are participating in ECALON plus Japan and Switzerland and Norway. So this is basically the list of countries that are exempt from any export regulations. We are speaking with Frank, one of the inventors of the Cryptophone which was announced a couple of weeks ago. You are based in Germany or Holland or both? We are based in Germany and Berlin. So some of the development has been taking place in Netherlands but the main operation is here based in Berlin and Germany. Their website is www.cryptophone.de and if you want to call in and ask some questions, 212-209-2900 is our phone number. Frank, any words that you would like to give to people who are considering getting something like this? We are about to build the 1900s version in January so that we can also have the US market and meanwhile we can try around with the Windows version that we are hopefully releasing tonight. And of course we are releasing the source also for people to look for bugs, to look for problems in the source code. And if you find something really nasty in there, something that impairs the security of the cryptography or the security of the phone application, then you describe us this bug and of course you will receive the Cryptophone as a present. So I can encourage only everybody to look at the source as you publish it and tell us if you find something. And I imagine this is something you will be demonstrating at the upcoming CCC Congress in Berlin, right? Yeah, sure. We will have, I think, a talk about the software structure and the protocol. One more thing, the protocol that we use for the Cryptophone will be published and you are free to implement a compatible product to the protocol, of course, without using our source. But if you choose to implement this protocol yourself, then we will help you with getting it compatible. Okay. Our number 212-209-2900. Bernie, I think we are going to lose you because of the limitations of the BAI phone system. We are not able to keep two calls on at the same time on the line you are on. That's okay. It might work, though. It might work. So let's just say a conditional goodbye to you. And if you do disappear, we will see you next week. Very good show tonight. All right. Let's take our first phone call. And good evening. You are on the air. Bernie is still there and this person is not. Okay. Let's try over here. And good evening. You are on the air. I'd like to talk about all the cryptology and stuff. All right. You've got 10 seconds, Robert. Okay. But before I do, I just want to know if you've got the pictures of the bridges and all the signs. You know, you blew it. You blew it. Because you asked me that question last night on the other radio show. And for some reason, I sound like I'm in a... Okay. There we go. All right. More limitations of the BAI phone system. Good evening. You are on the air. Hey. Hey. How are you doing? Go ahead. What's on your mind? I wanted to ask Frank how confident he is in his system and whether the NSA can break it or not. Yeah. Okay. This is one of the most interesting questions of all. What we see is that currently all the major cryptographers in the public and open world say, the 4096-bit Diffie-Hellman and using the session key that is resulting in both AES and 2FISH, the 256-bit key length, we are on the upper limit of what is being regarded as practical in cryptography today. And that should be immune against the known attacks. So, of course, you cannot always know what the NSA has on special hardware and stuff like that. But we are quite confident that the key lengths are enough for some time to prevent... Limitation being the processing power of the phone? Again? The limitation being the processing power of the phone? The limitation on the Diffie-Hellman is basically the bandwidth that we have. Because in Diffie-Hellman exchange over 9.6 kilobit takes already between 5 and 10 seconds for 4096-bit. And so this is one of the limitations. On the other hand, there are no good tested implementations for the AES and 2FISH for longer than 256-bit key length. So these are at the moment the limitations in there. If we see that there is any chance that something might go wrong with these key lengths and these algorithms, then, of course, we will lengthen the keys, the protocols implemented for that, so that we can put in also a longer key length in there. But for the moment, we feel quite confident that it should be enough. Will it be a simple matter to upgrade the phones that have already been sold if you need to do something like that? Yeah, that's not the problem. We have implemented an update mechanism that's again secured by a 4096-bit public key. And we will distribute the updates either via SD card or via download from an HTTPS site and then find update. So you can install the update yourself. The update only updates in block in the ROM. So not all of the phone is being multiple times verified for integrity. So we can update the phones. For instance, if somebody finds a security flaw in our protocol and our implementation, then we will, of course, notify our customers and send them an update. That's a refreshing change from the usual policy of if you find a security flaw, we prosecute you. We are actively encouraging people to look at the source. And if they find something that is really relevant, we will be happy to supply them with the crypto phone and other things and provide our customers, of course, with a quick update. All right, let's take another question. And good evening, you're on the air. All right, let's go over here. Good evening, you're on the air. All right, one more. Good evening, you're on the air. Okay, I don't know what's wrong with the phone system today. Frank, let me ask you a question. I know that when you were testing this thing, because I was watching you guys test it at one point, one of the problems was the delay in, I guess, processing power to do the actual encryption. Has that been alleviated? The problem with the delay is not resulting mainly from the processing power anymore. We had some problems in the beginning, but that's solved now. The delay that we have today now is mostly from the delay of the data channel and the GSM network. The GSM network is not handling all calls equally, and especially data calls received a lower priority. And you have a higher systemic delay on them. So in usual normal GSM networks inside the same operator, you have about a second of delay between two operators. It might go up to one and a half seconds. And if you have something like an international call with multiple operators involved, like rooming on one operator and being network of another operator, then it can go up to four seconds. But this is the worst case that we have ever seen. Okay, we've been speaking with Frank of Cryptophone. Does this company have an actual name, Cryptophone? The company that is doing the Cryptophone has called GSMK, which is a German abbreviation that basically says it's the company that is doing secure mobile communication. And their web address is www.cryptophone.de. Is there any last-minute information you want to give out? Again? Any last-minute information, contacts or anything like that? Just click on the website. I'm working on putting up the source code on the Windows version. Hopefully tonight. If not, then it will be tomorrow latest. But it's just formatting stuff. It's two in the morning where you are, so probably sometime tomorrow. Frank, I want to thank you very much for being a part of the show tonight. And we'll see you in Berlin. Good luck with this. And we'll, of course, keep people updated. And hopefully we'll get one of these to play with here. Okay. And that's our show for tonight. We'll see you next week. Good night.