WEBVTT

00:00.940 --> 00:21.980
And hello again, everybody. A few minutes ago, you just heard my voice, and you've probably had far, far too much of that today, but we are actually going to give you another hour and a half of, hopefully not so much my voice, but our returning co-host to the show, Verbal, to continue a topic that we started episode 162, actually, I believe. Is that right?

00:22.660 --> 00:23.520
Yes, that's correct.

00:23.520 --> 00:45.700
And this is episode 164, the second episode of today's doubleheader. For those of you listening to us live on the stream, we hope you're enjoying three hours of all hacking goodness, and for those of you on the podcast, well, I guess it doesn't really matter if these were back-to-back when they aired live on September 12, 2006 or not, so I guess, yeah, you really don't care, do you?

00:45.700 --> 01:07.320
So, since this is the second email of our doubleheader for this week, I kind of, actually, I think this is kind of cool, doing two episodes back-to-back, I think this is kind of a, I don't know, it feels like very much like a baseball, football, sports, you know, we're doing back-to-back episodes, we're pulling an all-nighter, I don't know, it sounds, it just feels kind of weird, we've never done this before, so it's actually kind of cool.

01:09.160 --> 01:10.340
And since we're doing this...

01:10.340 --> 01:11.700
Sports analogies you lost me, sorry.

01:11.980 --> 01:12.420
What's that?

01:13.360 --> 01:14.880
Sports analogies you lost me.

01:15.700 --> 01:30.060
Yeah, you know, surprisingly, well, not surprisingly, they're lost on a lot of, a lot of hackers and geeks are not into sports, but, yeah, we won't, we won't insert any NASCAR jokes here, that was Duel's job to give me the NASCAR jokes.

01:31.300 --> 01:32.820
The continual left turn.

01:33.500 --> 01:42.280
Anyway, since we are on the second episode of the doubleheader, that means there's really no housekeeping this week, except verbal, unless you had something you wanted to bring up about the mentor program, how is that going?

01:43.040 --> 01:45.500
Yeah, I want to talk about that a little bit.

01:45.700 --> 01:48.080
Right now it's actually going really well.

01:48.200 --> 01:56.880
I'm getting a steady stream of people asking to participate in the program, but right now we actually have a little imbalance of mentors and mentees.

01:56.880 --> 02:17.820
We need about three or four more mentors, because I have some people waiting to be paired, so if you're listening to the show and you would like to donate your time to mentor someone, you know, whether it is just, you know, Linux or whether, you know, it's some programming or networking knowledge, whatever you feel you can offer.

02:17.820 --> 02:26.300
Send me an email at mentorship.com and, you know, tell me, and, you know, it doesn't take too much time.

02:26.400 --> 02:34.520
It's just like one or two hours a week, and you just basically have to help your mentee and, like, you know, guide them and answer questions for them.

02:34.520 --> 02:38.500
And so, you know, if anyone has time, it would be greatly appreciated.

02:38.500 --> 02:46.380
And you don't have to be, and correct me if I'm wrong here, you don't have to be, like, this master know-it-all of every topic in the world.

02:46.380 --> 02:55.440
If you're a Java programmer, for example, for a living and that's what you're really good at, then you can certainly mentor somebody because people are wanting to learn that particular skill.

02:55.440 --> 02:57.380
So you would absolutely be a great mentor.

02:58.460 --> 02:58.820
Right.

02:58.940 --> 03:06.360
I mean, the whole point of this program is to facilitate, like, the exchange of, you know, ideas and, like, helping each other learn.

03:06.440 --> 03:11.500
So if you're good at one thing but you don't know anything about anything else, you know, that's fine.

03:11.620 --> 03:17.120
Just, you know, teach someone what you know, and then in turn, someone else will teach you what they know.

03:18.120 --> 03:18.900
Right, right.

03:18.900 --> 03:30.620
And, you know, like you, I think you mentioned this a couple episodes ago, too, and I completely am with you on this is I'm looking forward to having someone else mentor me on topics that I'm not as familiar with.

03:30.740 --> 03:36.060
So it's a great way to share some of the things you are familiar with and learn some of the things that you are not.

03:36.220 --> 03:46.820
So it's definitely a cool program, and I don't know if we're going to have anything up by the time, maybe by the end of this upcoming week, we will have some pages up.

03:46.820 --> 04:02.160
I don't want to put us on a deadline or put you on the spot here, but we are working on getting some, getting the site to be a little bit more interactive with the mentoring program so that people are able to kind of get some ideas, share information with each other, and kind of watch the progress of some of the teams as they go along.

04:02.360 --> 04:05.900
So I think we're going to be working on that for this, the rest of this week.

04:06.020 --> 04:12.340
So I'm sure we'll make an announcement on the show as well as in the forums about that when it happens.

04:12.340 --> 04:27.560
Yeah, so what I wanted to do is to put up, like, a wiki or some other type of, you know, dynamic webpage where teams that are participating in this program will put up, like, their syllabus and, like, their progress.

04:27.560 --> 04:54.460
So, you know, you can reference other people's information, and hopefully after a while we'll get a good collection of, like, coursework, you know, not coursework, but, like, a good collection of information for, like, oh, if, you know, if you want to learn, like, you know, some particular thing and you either don't have time or your schedule is, you know, really weird, then you can just go on that site and follow what someone else has already done, you know?

04:54.460 --> 05:03.260
Right, and there's no point in answering the same questions multiple times, so maybe it'll turn into kind of a frequently asked questions repository of specific things.

05:03.260 --> 05:04.860
Right, right, yeah, definitely, definitely.

05:05.160 --> 05:07.060
But anyway, we'll see how that unfolds.

05:07.100 --> 05:11.860
This is all something we're kind of trying to figure out the best way to do, so keep your eyes open for that.

05:12.660 --> 05:15.760
And other than that, again, I don't have any housekeeping.

05:16.480 --> 05:18.220
Did you have anything else, or was that it?

05:18.940 --> 05:20.100
Yeah, I think that's it.

05:20.280 --> 05:23.120
All right, so we do have some e-mail, though.

05:23.120 --> 05:32.940
I split the e-mail up amongst the shows as I felt it was appropriate, and there's some e-mail this week that I thought would be good for us, so let's check that out.

05:49.320 --> 05:51.900
Radio at BenRib.com

05:51.900 --> 05:58.440
Okay, and our first e-mail this week comes from Bob.

05:59.640 --> 06:06.800
Bob says, I use Gmail, but I'm also curious to know how secure Gmail is, and is there a better solution?

06:07.140 --> 06:10.320
I like the ability of being able to check my e-mails from anywhere.

06:10.320 --> 06:18.560
Well, I'll interrupt momentarily and say that pretty much any web mail client will give you the ability to access e-mails from anywhere.

06:18.560 --> 06:30.040
And personally, I use Yahoo Mail, which has, by default now, SSL connections, so that's one alternative that I'm familiar with.

06:30.040 --> 06:39.160
But to continue, he says, do I need software on my computer to encrypt e-mails, i.e. Thunderbird or Outlook, or can I do everything from the net?

06:39.160 --> 06:47.120
If I must encrypt from a program on the computer, what's the best choice, meaning which encryption software and e-mail software are best?

06:47.120 --> 06:54.380
Side note, I've only listened to episodes 1 and 2, and the latest, number 162, which is the one that Verbal and I did.

06:55.060 --> 06:58.980
And I'd like to say that I have given some thought about the definition of a hacker.

06:59.140 --> 07:05.400
I know you're not allowing more discussion about the term hacker, or perhaps you've talked about it in other shows, which we have.

07:05.820 --> 07:07.240
And I'll find those in due time.

07:07.240 --> 07:08.920
All in all, here's my two cents worth.

07:09.520 --> 07:12.460
A hacker is anyone who analyzes systems for vulnerabilities.

07:13.080 --> 07:16.800
What they do with these vulnerabilities defines them as either black or white.

07:16.940 --> 07:18.960
I'm sure he means black hat or white hat.

07:19.540 --> 07:23.700
And if you're too stoned to figure out what to do with the vulnerability, you're a gray hat hacker.

07:25.900 --> 07:27.740
All right, well, thank you, Bob, for the e-mail.

07:29.120 --> 07:35.100
Tell you what, Verbal, since this is kind of a follow-up on last week where you were asking me and posing to the audience,

07:35.100 --> 07:39.180
you know, are you using secure e-mail and encryption and stuff like that.

07:39.260 --> 07:40.980
Why don't you field this one a little bit?

07:41.440 --> 07:45.760
Specifically, well, let's start with maybe the, his first question is,

07:45.820 --> 07:50.780
do we need software on his computer to encrypt e-mail, such as Thunderbird or Outlook,

07:50.940 --> 07:52.500
or can I do everything from the net?

07:52.560 --> 07:53.800
Why don't we start with that?

07:54.820 --> 07:55.160
Okay.

07:56.080 --> 08:02.060
So, actually, I mean, first of all, he was saying, he was wondering how secure Gmail is, et cetera.

08:02.060 --> 08:05.440
You said that Yahoo has SSL.

08:05.760 --> 08:11.100
Do you know if that's SSL for the entire duration of the connection or just for the login?

08:12.160 --> 08:14.440
I believe, yikes.

08:14.540 --> 08:15.580
Actually, that's a good question.

08:15.740 --> 08:17.720
And while you keep answering, I'm going to look that up.

08:18.540 --> 08:18.820
Okay.

08:19.160 --> 08:24.780
So the thing with Gmail is I think if, you know, if I'm wrong, please e-mail in and correct me.

08:24.780 --> 08:32.160
But I think that when you log in, your password is encrypted and it's not transmitted over clear text.

08:32.480 --> 08:36.820
But after you log in, I think everything else is done in clear text.

08:37.200 --> 08:42.340
So if you, like, send an e-mail from Gmail without encrypting it or whatever,

08:43.020 --> 08:48.320
then, you know, someone sniffing the wire will be able to see all the clear text things.

08:48.320 --> 08:48.460
Okay.

08:49.060 --> 08:55.200
Now, normally, let's say you're doing, like, Thunderbird or Outlook or whatever,

08:56.060 --> 09:02.840
and you want to encrypt your e-mails, you can get some software like PGP or, I mean, sorry,

09:02.980 --> 09:06.580
GNU PG or, like, PGP or something like that.

09:06.740 --> 09:10.320
And then it will kind of be integrated into the app and it will do it for you.

09:10.320 --> 09:16.840
You don't have to, you know, do it the getaway where you run the command line tool and you, you know,

09:16.880 --> 09:22.620
put in the text and you get out, like, you know, an armored output where, you know,

09:22.660 --> 09:23.820
then you copy and paste it.

09:24.280 --> 09:29.300
Now, with Gmail, there are plug-ins that you can use to encrypt your e-mail.

09:29.600 --> 09:32.400
If you just go to Google and search for, like, Gmail encryption,

09:32.880 --> 09:37.560
you'll come up with multiple hits for encryption modules for Gmail.

09:37.560 --> 09:44.480
Now, but the thing is, you mentioned that you wanted to not have to install programs, you know,

09:44.580 --> 09:49.320
or do whatever and, like, you know, say you just wanted to check your e-mail at, like,

09:49.360 --> 09:54.820
a local cafe or wherever there's public Internet access and have that encrypted.

09:55.440 --> 10:00.540
That I don't think is possible because Gmail itself doesn't provide encryption.

10:00.940 --> 10:05.720
So even if you did get one of those web-based encryption add-ons for Gmail,

10:05.720 --> 10:11.600
you would have to download, say, a plug-in at the very least for, like, your Firefox,

10:12.080 --> 10:13.700
and that'll do the encryption for you.

10:13.800 --> 10:19.580
Now, when you get the plug-in, you might see a button, you know,

10:19.660 --> 10:26.260
and, like, some UI integrated in your Gmail, but that is not, you know,

10:26.300 --> 10:29.840
that's not going to be there if your browser doesn't have the plug-in.

10:29.840 --> 10:35.700
So if you want to just go to some random place and check your e-mail over the web,

10:36.040 --> 10:39.980
then I don't think you're going to be able to do that without installing any software.

10:40.740 --> 10:46.840
Now, definitely installing a plug-in for Firefox is much easier than, you know,

10:47.160 --> 10:50.580
say, you know, doing Thunderbird or whatever because, you know,

10:50.580 --> 10:54.860
you just install the plug-in once and, you know, you don't have to worry about it.

10:54.860 --> 11:01.260
Now, the other thing you can do if you truly want to, you know, be mobile in that sense

11:01.260 --> 11:05.620
is you can store stuff on, like, a USB key.

11:05.840 --> 11:10.460
Now, I know some public terminals don't let you plug in your USB stuff,

11:10.640 --> 11:15.560
but most of them, you know, if it's, like, a place where you're supposed to be using the computer,

11:16.020 --> 11:18.640
they'll let you plug in your USB drive because, you know,

11:18.700 --> 11:22.180
maybe, like, they'll have a printer service available or whatever.

11:22.180 --> 11:29.100
Now, if you do that, then you can install a program on your USB drive that'll do encryption for you.

11:29.440 --> 11:36.180
Or maybe, you know, you can just install, I mean, they'll put a plug-in on the USB drive

11:36.180 --> 11:37.520
and install it wherever you go.

11:38.400 --> 11:42.880
But, you know, as for what you really want to do, like what you're asking,

11:43.080 --> 11:44.320
I don't think that's possible.

11:44.880 --> 11:49.720
Now, there are other alternatives for sending, you know, that do encryption.

11:49.720 --> 11:54.360
I think one of them is called CryptMail.

11:54.640 --> 11:55.840
I was going to suggest that.

11:56.060 --> 12:01.260
But there are definitely web-only solutions for sending encrypted mail.

12:01.620 --> 12:06.740
But the problem with those is, for some reason, even though it's all public keys

12:06.740 --> 12:11.980
and, like, you know, it's a regular PHP standard, you have to, like, for some reason,

12:11.980 --> 12:17.500
they only let you import and export keys to import in the same system.

12:17.940 --> 12:25.160
Like, the two that I've tried does this, and I think it's because they want you to get other people

12:25.160 --> 12:26.900
to use their email system.

12:27.540 --> 12:30.940
But there should be no reason why, you know, you have to do that.

12:30.940 --> 12:33.760
I didn't realize that that was the way it worked.

12:33.840 --> 12:40.140
I thought that they offered just the encrypted using your public key and everything.

12:40.260 --> 12:43.100
I didn't realize that you could only do that with other users.

12:43.200 --> 12:45.440
I thought it would accept any, but I really don't know.

12:45.740 --> 12:48.740
I did, however, look up, and Yahoo is exactly what we suspected,

12:48.900 --> 12:52.460
and that is that it only encrypts, it only sends the password through SSL,

12:52.480 --> 12:54.020
and then it goes back to an open connection.

12:54.020 --> 12:57.700
So your actual email contents would be sent in clear text.

12:58.640 --> 13:01.180
Yeah, so, yeah, most of them do that.

13:01.400 --> 13:01.700
Right.

13:02.780 --> 13:07.680
But Yahoo used to be that Yahoo even sent the password in clear text,

13:07.920 --> 13:10.740
and they had a secure option, but you had to go out of your way

13:10.740 --> 13:15.920
to go to the HTTPS URL to get to it, and now they do it by default.

13:16.020 --> 13:17.960
So they've at least taken a step in the right direction.

13:18.180 --> 13:20.980
But the problem is that when you're encrypting all this,

13:20.980 --> 13:24.260
it adds a little extra overhead to every packet, basically.

13:24.400 --> 13:26.620
It's going to be encrypted, which makes all the data a little bit larger.

13:27.360 --> 13:30.820
And it's not a big deal when it's just one account or a handful of accounts,

13:30.960 --> 13:36.520
but when you're a giant megalo corporation like Google, Gmail, or Yahoo Mail,

13:36.800 --> 13:41.160
or MSN Hotmail, or whatever, it adds up pretty fast when you've got millions of users,

13:41.160 --> 13:43.240
so it becomes a problem to encrypt everything.

13:43.660 --> 13:50.400
However, that's one of the drawbacks of using these public free webmail things.

13:50.400 --> 13:53.720
Now, you can always set one up yourself, verbal, as you're well aware.

13:53.800 --> 13:56.280
You can always set up a webmail client of your own.

13:56.400 --> 13:59.180
You can use, gosh, there's Squirrel Mail.

13:59.380 --> 14:00.840
There's Horde, which I like.

14:01.080 --> 14:05.720
There's just too many to name that you can set up and run if you have your own server,

14:06.120 --> 14:07.700
and then you do have full control,

14:07.800 --> 14:11.440
and you can certainly encrypt all traffic going to your mail server.

14:11.880 --> 14:15.820
And that stands also if you're using, he mentioned in his email,

14:16.260 --> 14:19.800
needing special software like Thunderbird or Outlook.

14:19.800 --> 14:21.140
Well, those are just clients.

14:21.780 --> 14:30.520
With any client, most of them support secured methods of transportation or transport of your data.

14:30.840 --> 14:34.660
It's just properly configuring your server and setting it up to use it.

14:35.420 --> 14:37.520
So there are certainly options available,

14:38.000 --> 14:42.240
but you really have to have control of the server that you're interacting with,

14:42.280 --> 14:44.960
and when you're using one of these Gmail or something like that,

14:45.000 --> 14:46.940
then obviously you don't have that kind of control.

14:46.940 --> 14:50.920
So the only other thing is what I think you kind of alluded to earlier is,

14:51.460 --> 14:53.360
and I was going to suggest the same thing,

14:53.460 --> 14:56.040
is a USB key and have your PGP key on it,

14:56.480 --> 15:00.420
and encode or encrypt your individual email messages anywhere you go.

15:00.420 --> 15:06.980
Yeah, there should be, I mean, I've not looked into this,

15:07.100 --> 15:10.520
but it wouldn't surprise me if there was like a PGP online.

15:11.200 --> 15:13.300
Like, you can just put in your key,

15:13.960 --> 15:17.880
and then you can, you know, encrypt it on some web page,

15:18.440 --> 15:20.680
and if it doesn't exist, someone should just write it,

15:20.740 --> 15:22.760
because it'll be very useful, you know?

15:22.760 --> 15:24.660
Yeah, I'm not sure.

15:24.860 --> 15:27.760
Something doesn't feel like it's that simple about that, though.

15:27.780 --> 15:29.740
I can't quite put my finger on it now on the spot,

15:29.920 --> 15:32.080
but it sure would be handy.

15:33.040 --> 15:36.560
Well, I mean, it's like you have PGP running on the box,

15:36.700 --> 15:41.180
so, you know, it's just like a web interface where you have the text,

15:41.500 --> 15:42.980
and you just pipe it to PGP,

15:43.060 --> 15:46.180
and it spits back out the encrypted message to you.

15:47.160 --> 15:47.760
I mean...

15:47.760 --> 15:52.340
But you'd have to have your private key and your public key to be able to...

15:52.340 --> 15:54.020
No, you would only need to do that

15:54.020 --> 15:58.520
if you want the website to decrypt your message for you,

15:58.920 --> 16:00.400
not if you encrypt it.

16:00.600 --> 16:03.640
So if you just need to encrypt an email to someone,

16:04.140 --> 16:06.000
then you can just have their public key.

16:07.040 --> 16:09.120
Now, if you wanted to sign it,

16:09.860 --> 16:12.620
then, you know, you would have to give them your key.

16:13.020 --> 16:14.180
Right, that's okay.

16:14.180 --> 16:17.800
But, yeah, you know, if you just want to encrypt someone,

16:18.080 --> 16:21.360
you just need their public key, and then you're all set.

16:21.880 --> 16:27.280
Yeah, for that, it seems like there probably already is a website.

16:27.520 --> 16:30.180
If anybody knows of any, of course, email us, radio at binrev.com.

16:30.220 --> 16:32.320
I would love to bring that up on the next episode,

16:32.440 --> 16:35.200
because that would be very handy for our listeners and for myself as well.

16:36.040 --> 16:36.600
Right, right.

16:36.840 --> 16:40.060
So, now, at the end of the email,

16:40.140 --> 16:41.680
you talked about the definition of a hacker,

16:41.680 --> 16:43.840
and I don't want to spend too awful much time,

16:43.900 --> 16:46.300
because we have done that on multiple episodes before,

16:46.460 --> 16:49.820
but I think everybody's heard my rant of how I have a very,

16:50.640 --> 16:52.780
not my rant, maybe so much my explanation,

16:52.940 --> 16:54.700
that I have a very liberal definition,

16:54.960 --> 16:56.920
liberal definition of the word hacker,

16:57.480 --> 17:00.280
as, you know, anybody who really thinks outside of the lines,

17:00.380 --> 17:02.600
who doesn't take no for an answer,

17:02.700 --> 17:05.420
who does not accept limitations of any kind in anything.

17:05.420 --> 17:08.880
So, to me, it's not even, you know,

17:08.960 --> 17:11.060
people say hacker, you assume computer hacker,

17:11.180 --> 17:13.820
but to me, hacker means anybody who thinks outside of the box

17:13.820 --> 17:15.060
in any particular thing.

17:15.320 --> 17:19.080
It just so happens that usually they do end up being computer people.

17:19.580 --> 17:21.080
But did you have anything additional?

17:21.240 --> 17:22.480
Did you have any thoughts on that, or?

17:23.480 --> 17:27.480
Right, well, so Bob said in his email that, you know,

17:27.480 --> 17:30.400
he was saying, like, someone who analyzes systems or vulnerabilities,

17:30.400 --> 17:32.880
and, you know, depending on what they do with it,

17:32.960 --> 17:34.600
they're either a black hat or a white hat.

17:36.040 --> 17:39.040
You know, like, so my definition of a hacker,

17:39.360 --> 17:42.280
if I did have one, because the other show, on 162,

17:42.580 --> 17:44.780
I mentioned that I really don't like that word,

17:44.900 --> 17:47.040
but if I had to, you know, give a definition,

17:47.200 --> 17:49.060
it would definitely not be as liberal as yours.

17:49.540 --> 17:50.800
But the thing is, you know,

17:50.800 --> 17:54.680
I think Bob's definition is a little too, you know,

17:54.740 --> 17:56.900
narrow for my liking, anyway.

17:57.720 --> 17:59.020
You know, because it's like,

17:59.020 --> 18:01.300
in his definition,

18:01.500 --> 18:04.440
it's just people who deal with, you know,

18:04.480 --> 18:06.860
system security, whether at the host level

18:06.860 --> 18:08.560
or at the network level.

18:09.000 --> 18:11.100
And, you know, security, as, you know,

18:11.280 --> 18:13.520
I assume he's mentioning, right,

18:13.560 --> 18:14.460
since he said vulnerabilities,

18:14.620 --> 18:16.420
I'm assuming he's mentioning, like,

18:16.520 --> 18:19.460
finding exploits, and then either patching them

18:19.460 --> 18:22.580
or, you know, finding holes and exploiting them,

18:22.840 --> 18:24.620
you know, it's like, which side of the fence are you on?

18:24.720 --> 18:27.480
But I think there's more than that, you know?

18:27.480 --> 18:30.820
Like, because I would, I normally would include

18:30.820 --> 18:32.980
other fields, like coding,

18:33.220 --> 18:36.220
like writing good and elegant and clever code

18:36.220 --> 18:37.600
and, you know, being hacking.

18:38.320 --> 18:40.740
Or, like, you know, even with, like, phone freaking,

18:40.980 --> 18:42.120
which I know nothing about.

18:42.660 --> 18:45.300
But, you know, from noting some of you guys

18:45.300 --> 18:46.860
who are really into that, you know,

18:46.900 --> 18:49.880
there's definitely an element of hacking in there,

18:49.980 --> 18:51.000
you know, that mentality.

18:51.000 --> 18:53.420
So, I mean, to me, it's more kind of like

18:53.420 --> 18:54.660
a personality trait,

18:54.980 --> 18:57.100
but I would limit it into, like,

18:57.140 --> 18:59.140
the field of technology.

18:59.360 --> 19:00.840
Like, I wouldn't, you know,

19:01.120 --> 19:03.580
call some, like, writer of novels

19:03.580 --> 19:06.560
who, like, does clever things with the pros a hacker.

19:06.560 --> 19:08.720
No, and I agree with that.

19:08.900 --> 19:10.080
Let me, just to clarify,

19:10.260 --> 19:12.980
I'm not saying that a writer of clever pros

19:12.980 --> 19:13.920
or whatever, to use your example,

19:14.040 --> 19:14.900
makes them a hacker.

19:15.140 --> 19:19.460
But I'm saying it has the fundamental hacking mindset,

19:19.660 --> 19:21.700
the potential of that person.

19:21.700 --> 19:23.060
They think like a hacker.

19:23.260 --> 19:24.240
That doesn't, and that's not to say

19:24.240 --> 19:25.220
that they are a hacker.

19:25.580 --> 19:28.320
Again, really, the word hacker only comes in

19:28.320 --> 19:29.960
when technology becomes involved.

19:30.080 --> 19:31.780
Whether, again, it's freaking, computers,

19:31.960 --> 19:33.380
programming, coding, scanning,

19:33.800 --> 19:34.820
system level, whatever,

19:34.820 --> 19:37.640
that's when the term hacker comes to describe them.

19:37.800 --> 19:39.900
But people can have the same hacking mindset.

19:40.120 --> 19:41.060
That's what I mean to say.

19:41.120 --> 19:43.480
I would never call someone who's,

19:44.020 --> 19:45.800
comes up with a new style of writing

19:45.800 --> 19:48.080
really a hacker per se,

19:48.280 --> 19:49.900
or somebody who comes up with a new,

19:49.900 --> 19:51.020
well, let me ask you this, though,

19:51.100 --> 19:52.740
just for argument's sake.

19:52.800 --> 19:53.820
I didn't want to go into detail,

19:53.920 --> 19:55.760
but what about somebody like, say,

19:56.480 --> 20:00.540
a scientist who comes up with a new application of,

20:02.240 --> 20:03.900
I don't know,

20:03.900 --> 20:06.080
something that ends up being the building blocks

20:06.080 --> 20:07.240
to quantum computing.

20:07.400 --> 20:09.740
So they weren't directly involved in hacking,

20:09.860 --> 20:11.520
but they came up and invented a science

20:11.520 --> 20:13.920
that ended up turning to technology.

20:14.920 --> 20:16.300
Well, I mean, see, that's the thing.

20:16.480 --> 20:17.980
Like, there's these gray areas.

20:18.160 --> 20:20.100
That's why I don't really like to talk about it

20:20.100 --> 20:21.280
and, like, define it.

20:21.540 --> 20:22.760
Because you can't really,

20:22.820 --> 20:24.220
I don't think you can put, like,

20:24.680 --> 20:27.520
exchange boundaries around what is and isn't a hacker.

20:28.140 --> 20:29.480
You know, like, in your case,

20:29.480 --> 20:31.560
you can definitely make arguments either way.

20:31.940 --> 20:32.220
Right.

20:32.220 --> 20:33.080
So it's like,

20:33.140 --> 20:35.060
I don't have an opinion on that, you know?

20:35.060 --> 20:35.780
Right, and actually,

20:35.880 --> 20:37.140
I think that's a good point that you said,

20:37.240 --> 20:38.440
is, you know,

20:38.520 --> 20:39.600
defining it,

20:40.380 --> 20:41.300
see, the thing is,

20:41.340 --> 20:42.620
the media and writers

20:42.620 --> 20:43.720
and everybody out there,

20:43.760 --> 20:45.060
they like to have definitions.

20:45.600 --> 20:47.360
That's another thing I hate about the business

20:47.360 --> 20:48.980
of the, quote, unquote,

20:49.200 --> 20:51.180
security industry and security professionals.

20:51.620 --> 20:53.020
They want to make up all these terms

20:53.020 --> 20:53.680
and labels

20:53.680 --> 20:57.020
and make up all these specific things

20:57.020 --> 20:58.260
that they can call something

20:58.260 --> 20:59.980
just to have a term or a buzzword.

21:00.260 --> 21:01.240
I hate buzzwords.

21:01.920 --> 21:04.100
They've got to make up some textbook definition

21:04.100 --> 21:05.480
so that they can memorize it

21:05.480 --> 21:06.660
and, therefore, take an exam

21:06.660 --> 21:08.020
and become certified in it.

21:08.100 --> 21:09.920
So they have this need to define everything.

21:10.460 --> 21:12.180
I'm defining it only because

21:12.180 --> 21:13.400
people do question it

21:13.400 --> 21:15.340
and it helps explain it,

21:15.640 --> 21:17.160
but I agree with you 100%

21:17.160 --> 21:20.500
that there's no absolute definition

21:20.500 --> 21:21.540
of the word hacker.

21:23.360 --> 21:26.100
So I think that's all we have to say on that.

21:26.160 --> 21:26.860
Let's move on.

21:27.260 --> 21:29.160
Again, we've beaten that horse dead

21:29.160 --> 21:31.900
on this show over the three-plus years.

21:31.980 --> 21:33.340
Wow, that sounds weird to say that.

21:33.820 --> 21:35.640
Three-plus years we've been doing the show.

21:36.560 --> 21:38.220
We have one more email this week.

21:39.240 --> 21:41.180
This one comes from Prince Vegeta

21:41.180 --> 21:42.580
who says,

21:42.660 --> 21:43.280
Dear hackers,

21:43.420 --> 21:45.620
about having a backup phone system.

21:45.620 --> 21:47.980
I rely on my copper line

21:47.980 --> 21:49.440
and my free VoIP connection.

21:49.740 --> 21:51.460
If you subscribe to Internet and Cable TV,

21:51.620 --> 21:52.600
you get free VoIP connection

21:52.600 --> 21:54.600
with 600 minutes for calling locally,

21:55.080 --> 21:55.880
RDS networks,

21:56.220 --> 21:58.560
and 60 minutes for calling normal phones,

21:58.780 --> 22:00.060
R-O-M Telecom,

22:00.140 --> 22:01.220
the national phone company.

22:02.020 --> 22:03.560
Recently, a mobile phone company

22:03.560 --> 22:05.680
named Zapp, Z-A-P-P,

22:06.120 --> 22:07.720
introduced a new kind of phone service

22:07.720 --> 22:09.420
called Zapp FixTel.

22:09.840 --> 22:10.640
In translation,

22:10.880 --> 22:12.320
fixed means an old-fashioned phone

22:12.320 --> 22:14.220
that you can't carry around with you,

22:14.220 --> 22:15.420
but with a twist.

22:15.620 --> 22:17.000
They provide you with a phone

22:17.000 --> 22:19.500
that looks just like a normal copper-lined phone,

22:19.620 --> 22:20.740
but without an antenna,

22:20.860 --> 22:22.460
much like an old mobile phone.

22:22.860 --> 22:23.760
Here's the catch.

22:24.200 --> 22:25.040
It is mobile.

22:25.280 --> 22:26.660
It has no cable.

22:27.040 --> 22:28.280
You could take it with you to work,

22:28.440 --> 22:28.780
excuse me,

22:28.800 --> 22:29.640
you could take it to work,

22:29.840 --> 22:30.860
and you could carry it around,

22:30.920 --> 22:32.020
but that's not very practical

22:32.020 --> 22:34.220
because it's too freaking big.

22:34.620 --> 22:35.660
But in case of emergency,

22:35.860 --> 22:37.360
this new type of hybrid phone

22:37.360 --> 22:38.180
could prove useful

22:38.180 --> 22:39.380
because it's a new service

22:39.380 --> 22:40.700
and wouldn't get dosed

22:40.700 --> 22:42.860
when all the subscribers decide

22:42.860 --> 22:44.880
to use it at the same time.

22:46.080 --> 22:47.680
So he is obviously,

22:47.880 --> 22:48.880
or at least I'm thinking,

22:49.040 --> 22:49.700
he's probably listening

22:49.700 --> 22:50.780
to one of our recent episodes,

22:50.900 --> 22:51.560
the one that was called

22:51.560 --> 22:52.860
Technological Independence,

22:53.560 --> 22:54.660
because on that show,

22:54.820 --> 22:57.480
we talked about having backups

22:57.480 --> 22:59.780
to all of the things

22:59.780 --> 23:01.900
that we've come far too reliant on.

23:02.000 --> 23:02.120
You know,

23:02.180 --> 23:04.060
if your cable modem goes out,

23:04.160 --> 23:05.240
are you going to be scrambling

23:05.240 --> 23:06.340
or shit out of luck

23:06.340 --> 23:07.720
because you can't check your email

23:07.720 --> 23:09.860
or because you can't make a phone call

23:09.860 --> 23:11.280
because your VoIP is out as well

23:11.280 --> 23:12.260
if your power goes out

23:12.260 --> 23:13.100
and things like that.

23:13.280 --> 23:15.560
So that's very, very cool.

23:15.660 --> 23:17.960
I think that's a really interesting setup,

23:18.320 --> 23:19.680
and I actually did a little

23:19.680 --> 23:20.760
looking into this,

23:20.920 --> 23:23.140
and obviously in the email itself,

23:23.200 --> 23:24.460
you could tell that this was,

23:24.900 --> 23:26.120
when he mentioned the word translation,

23:26.120 --> 23:27.360
this is obviously not something

23:27.360 --> 23:28.440
from the United States.

23:29.380 --> 23:31.000
So I did a little looking,

23:31.000 --> 23:33.260
and this is actually in Romania.

23:34.320 --> 23:35.680
So where we have a large number

23:35.680 --> 23:36.760
of Romanian listeners,

23:37.080 --> 23:37.380
by the way,

23:37.440 --> 23:39.180
so shouts to Romania.

23:39.280 --> 23:39.960
You okay over there?

23:40.660 --> 23:41.620
Yeah, I'm fine.

23:41.820 --> 23:42.080
All right,

23:42.120 --> 23:43.100
just making sure you're not dying

23:43.100 --> 23:43.680
on me on the phone.

23:43.740 --> 23:44.980
Now, that would make great radio,

23:45.520 --> 23:46.960
but I don't want you to die on the phone.

23:47.020 --> 23:47.900
That would not be cool.

23:48.800 --> 23:50.260
We'd have the highest ratings ever,

23:50.380 --> 23:51.040
but come on now,

23:51.080 --> 23:51.580
stick with me.

23:53.880 --> 23:55.080
It's kind of cool that,

23:56.080 --> 23:57.440
it's actually kind of weird

23:57.440 --> 24:00.660
because usually what people are doing

24:00.660 --> 24:01.820
is having their VoIP line

24:01.820 --> 24:02.920
as their main line,

24:03.220 --> 24:04.100
and then their copper

24:04.100 --> 24:04.780
as their backup.

24:04.920 --> 24:05.680
But in this case,

24:06.100 --> 24:06.800
you're ordering,

24:07.260 --> 24:08.820
or having the original copper line,

24:08.880 --> 24:10.120
and they're giving you the bonus

24:10.120 --> 24:12.460
of the VoIP internet connection,

24:12.560 --> 24:13.160
which is kind of cool

24:13.160 --> 24:13.960
with the number of minutes.

24:14.340 --> 24:15.840
And I'm certain that people

24:15.840 --> 24:17.180
are going to be using those minutes

24:17.180 --> 24:18.300
for their free long distance

24:18.300 --> 24:19.180
and stuff first,

24:19.240 --> 24:20.720
and their mobile minutes,

24:20.780 --> 24:21.100
or whatever,

24:21.200 --> 24:22.120
however you want to call it.

24:23.260 --> 24:24.240
And the copper,

24:24.600 --> 24:25.380
I would imagine,

24:25.520 --> 24:26.300
wouldn't come into play

24:26.300 --> 24:27.480
until you've run out of those.

24:27.480 --> 24:29.500
So I think that's kind of

24:29.500 --> 24:30.020
a cool setup.

24:30.120 --> 24:30.820
What do you think the chances

24:30.820 --> 24:31.620
of that ever happening

24:31.620 --> 24:32.620
in the United States are?

24:34.460 --> 24:34.860
Well,

24:35.080 --> 24:37.100
I don't think

24:37.100 --> 24:38.640
people care that much

24:38.640 --> 24:39.740
in the United States,

24:39.840 --> 24:40.540
to be honest.

24:40.800 --> 24:41.720
Because most people

24:41.720 --> 24:43.000
have a cell phone anyway,

24:43.660 --> 24:45.340
and people don't like

24:45.340 --> 24:46.460
to think about that stuff

24:46.460 --> 24:47.280
in the United States.

24:47.540 --> 24:48.040
They're just like,

24:48.100 --> 24:48.880
ah, well,

24:48.960 --> 24:49.640
you have a phone.

24:49.800 --> 24:50.120
I mean,

24:50.200 --> 24:50.780
I have a phone,

24:50.880 --> 24:51.220
it's fine.

24:51.440 --> 24:52.540
Like, most people I know

24:52.540 --> 24:53.900
don't even have a landline.

24:54.020 --> 24:55.080
They all just have cell phones.

24:55.080 --> 24:58.280
Yeah, I know some people

24:58.280 --> 24:58.740
like that too.

24:58.760 --> 24:59.680
Like, it's a different

24:59.680 --> 25:00.520
cloud over here.

25:01.180 --> 25:02.240
Yeah, you guys out

25:02.240 --> 25:02.780
on the West Coast

25:02.780 --> 25:03.480
are a little bit different.

25:04.420 --> 25:06.120
No, I know a lot of people

25:06.120 --> 25:06.820
that are in the same boat.

25:06.900 --> 25:07.880
They only have a cell phone.

25:07.940 --> 25:08.660
And quite honestly,

25:09.440 --> 25:10.800
I was so happy

25:10.800 --> 25:12.080
when I lived down

25:12.080 --> 25:12.880
in Fort Lauderdale

25:12.880 --> 25:13.320
down there,

25:13.360 --> 25:13.880
in that area.

25:15.320 --> 25:16.640
I think I spoke on the show

25:16.640 --> 25:17.300
many times

25:17.300 --> 25:18.500
that how much I hated

25:18.500 --> 25:19.080
Bell South,

25:19.260 --> 25:20.420
which is our local telco,

25:20.600 --> 25:21.300
our baby Bell.

25:21.940 --> 25:24.880
And they required me

25:24.880 --> 25:25.980
to have phone service,

25:26.160 --> 25:27.000
basic phone service,

25:27.100 --> 25:27.760
to be able to get

25:27.760 --> 25:28.940
high-speed internet DSL

25:28.940 --> 25:29.340
through them.

25:29.360 --> 25:30.140
And my cable company

25:30.140 --> 25:30.980
didn't offer it yet.

25:31.720 --> 25:32.640
So when the cable company

25:32.640 --> 25:33.580
finally came along

25:33.580 --> 25:34.180
to offer it,

25:34.360 --> 25:34.560
yeah,

25:34.660 --> 25:36.300
I dropped my phone service

25:36.300 --> 25:36.740
completely

25:36.740 --> 25:37.760
and was on cell only

25:37.760 --> 25:38.940
for the longest time there.

25:39.820 --> 25:40.320
So yeah,

25:40.380 --> 25:40.980
it's absolutely,

25:41.440 --> 25:41.920
but if you're going to

25:41.920 --> 25:42.980
make long-distance calls

25:42.980 --> 25:44.220
and you don't want to spend

25:44.220 --> 25:45.520
the kind of money

25:45.520 --> 25:46.060
you have to pay

25:46.060 --> 25:47.320
for a cell phone these days,

25:47.780 --> 25:48.020
I mean,

25:48.840 --> 25:49.740
you're right.

25:49.740 --> 25:51.460
Skype for long-distance calls.

25:52.100 --> 25:52.480
Well, yeah,

25:52.560 --> 25:52.940
you're assuming

25:52.940 --> 25:53.960
computer people too.

25:53.960 --> 25:54.680
But like you said,

25:54.700 --> 25:55.740
it goes back to people

25:55.740 --> 25:56.760
in the United States.

25:56.880 --> 25:57.160
Americans,

25:57.300 --> 25:58.600
they don't care a whole lot,

25:59.060 --> 26:00.000
which is sad in a way.

26:00.100 --> 26:01.060
Apathy is my biggest

26:01.060 --> 26:01.920
pet peeve of all.

26:02.100 --> 26:03.880
But do you think

26:03.880 --> 26:04.940
they would suddenly care

26:04.940 --> 26:07.040
if their cable company

26:07.040 --> 26:07.980
or phone company

26:07.980 --> 26:08.620
came out

26:08.620 --> 26:09.960
and instead of these

26:09.960 --> 26:12.340
bullshit fake-bundled services

26:12.340 --> 26:13.160
where they save you

26:13.160 --> 26:13.800
two dollars

26:13.800 --> 26:15.080
if you bundle shit together,

26:15.640 --> 26:16.800
you think if a company

26:16.800 --> 26:17.380
came up

26:17.380 --> 26:18.180
similar to what

26:18.180 --> 26:18.800
this sounds like

26:18.800 --> 26:19.120
that says,

26:19.200 --> 26:19.380
listen,

26:19.480 --> 26:20.380
we'll give you your cable

26:20.380 --> 26:21.660
and we'll give you

26:21.660 --> 26:22.460
a copper line

26:22.460 --> 26:23.140
that's reliable

26:23.140 --> 26:24.060
that you can count on

26:24.060 --> 26:24.740
and we'll give you

26:24.740 --> 26:25.580
VoIP minutes

26:25.580 --> 26:26.660
that you can use

26:26.660 --> 26:27.680
for your long-distance calls

26:27.680 --> 26:28.480
cheap and easy.

26:29.720 --> 26:30.240
That's certainly,

26:30.400 --> 26:30.980
the capability

26:30.980 --> 26:31.900
is certainly there.

26:32.340 --> 26:32.940
There's absolutely

26:32.940 --> 26:33.800
no reason why

26:33.800 --> 26:34.460
a company

26:34.460 --> 26:35.600
can't do that.

26:35.660 --> 26:35.840
I mean,

26:35.900 --> 26:36.920
let's take a cable company.

26:37.020 --> 26:38.260
They can obviously offer

26:38.260 --> 26:39.960
the high-bandwidth

26:39.960 --> 26:41.600
cable modems.

26:41.840 --> 26:43.100
They can obviously offer

26:43.100 --> 26:43.400
VoIP,

26:43.440 --> 26:44.260
and many of them do,

26:44.940 --> 26:45.620
but they're looking

26:45.620 --> 26:46.140
at profit.

26:46.320 --> 26:46.900
They're not looking

26:46.900 --> 26:47.640
at the best interest

26:47.640 --> 26:48.280
of their customers.

26:48.280 --> 26:48.940
That's the difference

26:48.940 --> 26:49.920
between the United States

26:49.920 --> 26:51.600
and a lot of other countries.

26:51.980 --> 26:52.920
We are looking

26:52.920 --> 26:53.560
at the bottom line

26:53.560 --> 26:54.980
profit for the company,

26:55.260 --> 26:57.000
and there's not necessarily

26:57.000 --> 26:58.240
anything wrong with that.

26:58.320 --> 26:59.000
There's nothing wrong

26:59.000 --> 27:00.320
with making money exactly,

27:00.900 --> 27:02.420
but you cross a certain line

27:02.420 --> 27:03.020
where you're raping

27:03.020 --> 27:03.600
your customers.

27:03.720 --> 27:04.560
You're not looking out

27:04.560 --> 27:05.260
for the best interest

27:05.260 --> 27:05.840
of your customers.

27:06.100 --> 27:06.840
If a company were

27:06.840 --> 27:08.020
to pop up right now

27:08.020 --> 27:09.680
and offer these things

27:09.680 --> 27:10.700
at half the price,

27:10.980 --> 27:11.420
I'll give you

27:11.420 --> 27:12.480
cell phone coverage,

27:13.000 --> 27:13.540
I'll give you

27:13.540 --> 27:14.620
copper landline,

27:14.720 --> 27:15.160
I'll give you

27:15.160 --> 27:16.500
free unlimited long distance

27:16.500 --> 27:17.080
via VoIP

27:17.080 --> 27:18.500
and high-speed bandwidth

27:18.500 --> 27:19.740
and cable television

27:19.740 --> 27:21.800
all for $75.

27:22.840 --> 27:23.780
You don't think

27:23.780 --> 27:24.920
Americans would suddenly

27:24.920 --> 27:25.860
get interested in that?

27:26.040 --> 27:26.820
I think they'd jump

27:26.820 --> 27:27.660
all over that.

27:28.620 --> 27:29.340
Well, now,

27:30.060 --> 27:31.200
the thing is,

27:31.260 --> 27:31.440
okay,

27:31.600 --> 27:32.740
so the number one thing

27:32.740 --> 27:33.780
I think is,

27:34.300 --> 27:35.980
does it cost less?

27:37.420 --> 27:38.260
So the thing is,

27:38.620 --> 27:39.320
the cost,

27:39.920 --> 27:40.540
and then,

27:40.880 --> 27:41.200
like,

27:41.600 --> 27:42.260
the functionality

27:42.260 --> 27:43.560
or the features

27:43.560 --> 27:44.660
is a distant second.

27:44.860 --> 27:46.020
So let's say someone

27:46.020 --> 27:47.280
has some setup,

27:47.420 --> 27:48.460
like they get cable

27:48.460 --> 27:50.100
for cable internet

27:50.100 --> 27:51.140
and TV,

27:51.460 --> 27:51.980
and then they have

27:51.980 --> 27:52.540
a phone line,

27:52.600 --> 27:52.820
you know,

27:52.820 --> 27:53.640
for whatever reason.

27:54.160 --> 27:55.700
And if someone does that,

27:56.180 --> 27:56.420
you know,

27:56.460 --> 27:57.160
the question is

27:57.160 --> 27:57.920
whether or not

27:57.920 --> 27:58.700
it will be cheaper.

28:00.000 --> 28:00.480
Right?

28:00.860 --> 28:01.280
Right.

28:01.280 --> 28:03.080
So in your scenario,

28:03.660 --> 28:04.320
are you saying

28:04.320 --> 28:04.880
that it will be

28:04.880 --> 28:05.760
cheaper or not?

28:06.760 --> 28:07.660
I'm not sure

28:07.660 --> 28:08.520
I understand the question.

28:08.660 --> 28:09.100
I'm saying that

28:09.100 --> 28:10.420
right now,

28:10.840 --> 28:11.760
my cable company

28:11.760 --> 28:12.700
for the setup

28:12.700 --> 28:13.540
that I just described

28:13.540 --> 28:14.280
to you would cost

28:14.280 --> 28:15.660
easily $150

28:15.660 --> 28:16.260
to $200.

28:16.860 --> 28:17.600
And I'm saying

28:17.600 --> 28:18.520
that right now,

28:19.080 --> 28:19.720
they could do that

28:19.720 --> 28:20.420
for half the price.

28:20.420 --> 28:21.240
it would be cheaper,

28:21.320 --> 28:21.560
right?

28:21.720 --> 28:22.200
I'm saying it.

28:22.200 --> 28:22.860
If someone came in

28:22.860 --> 28:23.720
and, you know,

28:23.760 --> 28:25.200
replaced existing services.

28:25.560 --> 28:25.900
Yes.

28:26.760 --> 28:27.060
Right.

28:27.380 --> 28:28.000
So, I mean,

28:28.080 --> 28:29.180
if it's cheaper,

28:29.620 --> 28:30.720
I think most people,

28:30.820 --> 28:31.720
that's enough for them.

28:32.120 --> 28:32.260
Right.

28:32.260 --> 28:32.500
And, you know,

28:32.540 --> 28:33.300
if you tell them

28:33.300 --> 28:33.980
that they can do

28:33.980 --> 28:34.740
the same thing

28:34.740 --> 28:35.600
that they did before

28:35.600 --> 28:36.800
but for cheaper,

28:37.300 --> 28:38.080
then most people

28:38.080 --> 28:38.800
would just do it

28:38.800 --> 28:40.020
for that fact alone.

28:40.160 --> 28:40.460
Right.

28:40.980 --> 28:41.860
Exactly my point.

28:41.860 --> 28:41.960
And in addition,

28:42.220 --> 28:42.480
you know,

28:42.540 --> 28:43.380
if you're trying to put out

28:43.380 --> 28:44.960
additional functionality

28:44.960 --> 28:45.640
and features,

28:46.020 --> 28:46.320
like,

28:46.380 --> 28:47.280
they might get excited

28:47.280 --> 28:47.900
about that,

28:48.020 --> 28:48.500
but, you know,

28:48.560 --> 28:49.000
most people

28:49.000 --> 28:49.740
are not going to care.

28:49.740 --> 28:50.620
So, if it's cheaper,

28:50.960 --> 28:51.900
people are going to switch.

28:52.080 --> 28:52.620
No, yeah,

28:52.700 --> 28:53.540
exactly my point

28:53.540 --> 28:54.300
was the bottom line

28:54.300 --> 28:54.860
is price.

28:55.340 --> 28:55.740
Ironically,

28:56.480 --> 28:57.420
and maybe that is

28:57.420 --> 28:58.240
an American thing,

28:58.600 --> 28:59.220
and maybe that is

28:59.220 --> 28:59.840
an American thing,

28:59.900 --> 29:00.460
that ironically,

29:00.900 --> 29:01.760
the companies are looking

29:01.760 --> 29:02.600
at trying to make

29:02.600 --> 29:03.720
the most possible money

29:03.720 --> 29:04.280
they can

29:04.280 --> 29:05.740
and raping the customers

29:05.740 --> 29:07.120
for every little dime

29:07.120 --> 29:08.620
and the customers,

29:08.920 --> 29:09.620
on the other hand,

29:09.660 --> 29:10.520
are looking to save

29:10.520 --> 29:11.320
every little dime.

29:11.440 --> 29:11.780
So, yes,

29:11.800 --> 29:12.520
the price matters

29:12.520 --> 29:14.000
to the customers as well.

29:14.440 --> 29:15.520
There is no in-between.

29:15.700 --> 29:16.480
There's no compromise.

29:16.760 --> 29:17.660
There's no happy medium

29:17.660 --> 29:18.740
where the company says,

29:19.120 --> 29:19.640
well, we're going to try

29:19.640 --> 29:20.060
to give you

29:20.060 --> 29:20.960
all these services

29:20.960 --> 29:21.640
at a little bit

29:21.640 --> 29:22.320
less price,

29:22.480 --> 29:24.380
and American consumers

29:24.380 --> 29:24.920
would say,

29:25.020 --> 29:25.320
oh, well,

29:25.380 --> 29:26.640
I'll take that.

29:26.760 --> 29:26.880
You know,

29:26.920 --> 29:27.440
it's worth it

29:27.440 --> 29:28.480
if the company's trying,

29:28.620 --> 29:30.040
if they're a good company,

29:30.160 --> 29:31.660
if they're conscious

29:31.660 --> 29:32.480
of their customers,

29:32.660 --> 29:32.920
et cetera.

29:32.980 --> 29:33.760
There's no balance.

29:33.860 --> 29:34.900
There's no acceptable

29:34.900 --> 29:35.720
middle ground.

29:35.800 --> 29:36.700
So, it's two extremes

29:36.700 --> 29:37.200
competing,

29:37.660 --> 29:38.440
and Americans are going

29:38.440 --> 29:39.360
to go for the absolute

29:39.360 --> 29:40.400
cheapest price,

29:40.960 --> 29:41.240
period.

29:41.520 --> 29:42.240
That's why VoIP

29:42.240 --> 29:43.440
has been slow to adopt,

29:43.520 --> 29:44.620
is because Americans

29:44.620 --> 29:45.700
are skeptical of it.

29:45.700 --> 29:46.520
And then,

29:46.680 --> 29:47.820
as word has gotten around

29:47.820 --> 29:48.820
that VoIP is,

29:49.360 --> 29:50.220
and I use this word

29:50.220 --> 29:50.720
hesitantly,

29:50.860 --> 29:51.320
reliable.

29:52.120 --> 29:53.680
It's kind of reliable

29:53.680 --> 29:55.120
compared to regular phone lines

29:55.120 --> 29:56.260
or cell phones,

29:56.320 --> 29:56.860
the same way.

29:56.960 --> 29:57.580
All of a sudden,

29:57.660 --> 29:58.760
when people start adopting them,

29:59.300 --> 30:00.080
that bell curve

30:00.080 --> 30:01.320
took a giant leap

30:01.320 --> 30:02.900
in number of people

30:02.900 --> 30:03.640
adopting them.

30:03.880 --> 30:04.140
So,

30:04.700 --> 30:06.160
once people realize

30:06.160 --> 30:07.040
and start trusting this

30:07.040 --> 30:08.380
and realize they can save money,

30:08.720 --> 30:09.360
then it can happen.

30:09.360 --> 30:09.540
Now,

30:09.620 --> 30:10.680
the problem with the scenario

30:10.680 --> 30:11.420
I gave,

30:11.520 --> 30:12.140
and I know I'm spending

30:12.140 --> 30:13.560
too far time on this,

30:13.600 --> 30:14.420
but this is one of my

30:14.420 --> 30:15.780
sore spots,

30:15.860 --> 30:16.480
so I'm going to rant

30:16.480 --> 30:17.460
a little bit about this,

30:18.060 --> 30:20.500
is the simple fact

30:20.500 --> 30:21.780
that the scenario

30:21.780 --> 30:22.400
I mentioned

30:22.400 --> 30:23.240
of a new company

30:23.240 --> 30:23.860
coming in

30:23.860 --> 30:24.420
and forming

30:24.420 --> 30:26.440
and giving that same stuff

30:26.440 --> 30:27.020
for $75,

30:27.340 --> 30:28.960
$100 with all of this.

30:29.060 --> 30:29.480
Could you imagine

30:29.480 --> 30:30.240
all your utilities,

30:30.440 --> 30:30.920
your phone,

30:31.220 --> 30:31.720
not all of them,

30:31.780 --> 30:31.900
of course,

30:31.940 --> 30:32.380
your phone,

30:32.680 --> 30:33.560
your cable television,

30:33.700 --> 30:35.900
your cable internet,

30:36.240 --> 30:36.980
high-speed internet,

30:37.220 --> 30:38.460
and a copper phone line,

30:38.460 --> 30:39.460
and your cell phone,

30:39.740 --> 30:40.280
all of that

30:40.280 --> 30:40.760
for $100,

30:41.180 --> 30:41.820
which to me

30:41.820 --> 30:43.420
would be freaking fantastic.

30:44.060 --> 30:45.060
That'll never happen

30:45.060 --> 30:45.960
because,

30:46.620 --> 30:47.120
oh man,

30:47.160 --> 30:47.940
I don't want to turn this

30:47.940 --> 30:49.100
into a big government rant,

30:49.180 --> 30:49.780
but it is.

30:50.340 --> 30:51.460
The government won't allow

30:51.460 --> 30:52.400
that company to come in

30:52.400 --> 30:52.900
and exist

30:52.900 --> 30:54.180
because they over-regulate

30:54.180 --> 30:54.440
everything.

30:54.680 --> 30:55.600
The United States

30:55.600 --> 30:57.080
is a place

30:57.080 --> 30:57.880
where people

30:57.880 --> 30:59.240
rather have quantity

30:59.240 --> 31:00.480
over quality,

31:00.580 --> 31:00.800
right?

31:01.140 --> 31:01.460
You know,

31:01.520 --> 31:02.280
we would rather

31:02.280 --> 31:04.340
have six cheeseburgers

31:04.340 --> 31:04.800
for $3

31:04.800 --> 31:06.600
than have like

31:06.600 --> 31:08.020
an actual real meal.

31:08.020 --> 31:08.380
Like,

31:08.420 --> 31:08.960
you know what I'm saying?

31:09.400 --> 31:09.760
Like,

31:09.800 --> 31:10.680
with that mentality,

31:11.420 --> 31:11.760
you know,

31:12.040 --> 31:13.760
if something is crappy

31:13.760 --> 31:14.840
or whatever,

31:15.040 --> 31:15.960
just as long as they

31:15.960 --> 31:17.460
market it decently

31:17.460 --> 31:18.640
and they can convince you,

31:18.720 --> 31:19.520
it will probably be

31:19.520 --> 31:20.300
about the same,

31:20.660 --> 31:21.720
and it costs less,

31:21.980 --> 31:22.620
then people are going

31:22.620 --> 31:23.180
to use it.

31:23.900 --> 31:24.120
Like,

31:24.160 --> 31:24.340
okay,

31:24.520 --> 31:25.880
let me tell you

31:25.880 --> 31:26.620
a quick story.

31:27.040 --> 31:28.160
I was talking to my mom

31:28.160 --> 31:28.860
the other day,

31:28.900 --> 31:29.860
and,

31:29.940 --> 31:30.300
you know,

31:30.380 --> 31:32.340
since I do computers

31:32.340 --> 31:33.200
for a living,

31:33.200 --> 31:35.280
she asked me,

31:35.780 --> 31:36.100
like,

31:36.660 --> 31:36.980
okay,

31:37.100 --> 31:37.740
she said,

31:38.700 --> 31:39.660
there's some,

31:40.000 --> 31:41.020
the cable company

31:41.020 --> 31:42.220
is like telling us

31:42.220 --> 31:43.040
about this new

31:43.040 --> 31:44.400
phone service

31:44.400 --> 31:45.540
that they're rolling out,

31:46.120 --> 31:46.540
and,

31:46.680 --> 31:47.300
you know,

31:47.480 --> 31:49.000
it's cheaper

31:49.000 --> 31:49.740
by $2,

31:50.580 --> 31:52.240
and one of the features

31:52.240 --> 31:53.920
is if the power

31:53.920 --> 31:54.540
goes out,

31:54.840 --> 31:56.180
your phone will still work,

31:56.500 --> 31:57.080
and she's trying

31:57.080 --> 31:57.660
to explain

31:57.660 --> 31:58.460
all these things to me,

31:58.520 --> 31:59.400
basically like reading

31:59.400 --> 32:00.220
the brochure,

32:00.520 --> 32:01.580
and I had no idea

32:01.580 --> 32:02.760
what she was talking about,

32:02.960 --> 32:03.980
and then after,

32:04.300 --> 32:05.160
after like,

32:05.260 --> 32:06.660
like 15 minutes,

32:06.700 --> 32:07.420
I realized

32:07.420 --> 32:07.960
she was talking

32:07.960 --> 32:08.580
about VoIP,

32:09.380 --> 32:09.820
right?

32:10.120 --> 32:10.320
Right.

32:10.420 --> 32:10.700
And,

32:10.820 --> 32:12.000
you know,

32:12.420 --> 32:13.140
and I was like,

32:13.240 --> 32:13.460
well,

32:13.580 --> 32:14.040
I don't know,

32:14.100 --> 32:15.080
you already have a phone,

32:15.300 --> 32:16.220
and it works,

32:16.340 --> 32:16.500
whatever,

32:17.100 --> 32:17.420
but,

32:17.560 --> 32:17.860
you know,

32:17.920 --> 32:18.940
so she switched

32:18.940 --> 32:21.100
because it was $2 less,

32:21.740 --> 32:23.780
and when the power

32:23.780 --> 32:24.480
goes out,

32:24.860 --> 32:26.220
you can still use

32:26.220 --> 32:27.940
your VoIP service,

32:27.940 --> 32:29.660
but the thing is,

32:29.960 --> 32:30.140
like,

32:30.220 --> 32:30.580
so I took,

32:30.660 --> 32:30.820
you know,

32:30.860 --> 32:31.680
so after that,

32:31.800 --> 32:32.460
I hung up,

32:32.500 --> 32:32.960
and I was like,

32:33.060 --> 32:33.340
okay,

32:33.480 --> 32:33.640
well,

32:33.640 --> 32:34.540
I don't really care,

32:34.820 --> 32:35.620
she can switch over

32:35.620 --> 32:36.040
a VoIP,

32:36.180 --> 32:36.340
you know,

32:36.380 --> 32:36.940
it'll be cool,

32:37.040 --> 32:37.820
because maybe I can like

32:37.820 --> 32:38.840
set up an asterisk

32:38.840 --> 32:39.580
on a better place

32:39.580 --> 32:40.660
and mess around with it,

32:41.300 --> 32:41.580
but,

32:41.920 --> 32:42.920
then I realized,

32:43.400 --> 32:43.760
like,

32:44.060 --> 32:45.760
if you have a regular phone,

32:45.860 --> 32:47.120
and your power goes out,

32:47.320 --> 32:48.620
your phone still works,

32:48.640 --> 32:49.840
because the phone company

32:49.840 --> 32:50.740
gives you power,

32:52.520 --> 32:53.760
so it's like,

32:54.040 --> 32:55.060
these features,

32:55.360 --> 32:55.540
like,

32:55.620 --> 32:57.180
you don't even need to

32:57.180 --> 32:59.460
have them be new

32:59.460 --> 33:00.240
and real,

33:00.700 --> 33:01.200
it's like,

33:01.260 --> 33:02.100
just say things

33:02.100 --> 33:02.860
that sound good,

33:02.900 --> 33:04.120
and people will buy it,

33:04.500 --> 33:04.760
like,

33:04.800 --> 33:05.520
people don't think

33:05.520 --> 33:06.380
about these things,

33:06.760 --> 33:07.720
so just have as many

33:07.720 --> 33:08.440
bullet points,

33:08.900 --> 33:10.280
and make it cheaper,

33:10.500 --> 33:11.660
and people will adopt it.

33:11.800 --> 33:12.040
Well,

33:12.080 --> 33:13.040
that's all about marketing,

33:13.140 --> 33:13.360
yeah.

33:14.400 --> 33:14.640
Well,

33:14.640 --> 33:15.000
I'll tell you what,

33:15.040 --> 33:15.700
I'm going to take off

33:15.700 --> 33:16.800
my tinfoil hat now,

33:17.240 --> 33:18.300
and let's get into

33:18.300 --> 33:19.460
the actual main content

33:19.460 --> 33:19.980
of the show,

33:20.080 --> 33:20.500
shall we?

33:21.560 --> 33:22.060
Let's do it.

33:22.060 --> 33:22.840
Because we actually,

33:22.940 --> 33:23.800
we actually kind of

33:23.800 --> 33:25.640
left off episode 162,

33:25.720 --> 33:26.760
we kind of ran out of time,

33:27.180 --> 33:28.340
I do think it wasn't

33:28.340 --> 33:29.600
such a bad stopping point,

33:29.700 --> 33:29.880
though,

33:29.940 --> 33:31.140
but I do think we need

33:31.140 --> 33:31.820
to do a little bit

33:31.820 --> 33:32.360
of a recap

33:32.360 --> 33:34.180
of how we ended

33:34.180 --> 33:34.800
that episode.

33:34.940 --> 33:35.360
In that episode,

33:35.500 --> 33:36.080
we were going to go

33:36.080 --> 33:36.620
into a little bit

33:36.620 --> 33:37.640
more detail about,

33:38.240 --> 33:40.020
I guess we'll call it

33:40.020 --> 33:41.180
secured communications,

33:41.380 --> 33:42.280
for lack of a better term,

33:42.960 --> 33:43.800
but basically,

33:44.020 --> 33:44.720
we found a good

33:44.720 --> 33:45.500
stopping point

33:45.500 --> 33:48.280
after defining

33:48.280 --> 33:49.200
tunneling,

33:49.200 --> 33:50.300
and what tunneling is,

33:50.340 --> 33:51.460
the concept of tunneling,

33:51.920 --> 33:52.200
so,

33:52.500 --> 33:53.100
and by the way,

33:53.140 --> 33:53.600
I don't know if you're

33:53.600 --> 33:53.980
in a good,

33:54.080 --> 33:54.800
getting good reception

33:54.800 --> 33:55.520
on the phone there,

33:55.520 --> 33:55.840
or whatever,

33:55.960 --> 33:56.520
but if you're,

33:56.740 --> 33:57.800
you're kind of garbling

33:57.800 --> 33:58.400
up a little bit,

33:58.440 --> 33:58.920
but I'm going to let

33:58.920 --> 33:59.700
you talk about,

34:01.340 --> 34:02.520
can you give us like a,

34:02.960 --> 34:03.660
obviously we don't

34:03.660 --> 34:04.160
want to rehash

34:04.160 --> 34:04.920
the whole last,

34:05.080 --> 34:05.640
that episode,

34:05.840 --> 34:06.800
but maybe give us

34:06.800 --> 34:07.680
a quick recap

34:07.680 --> 34:09.340
of tunneling concepts,

34:09.480 --> 34:10.200
I think it's important

34:10.200 --> 34:12.480
that we re-address

34:12.480 --> 34:13.180
the stack,

34:13.480 --> 34:14.400
and how tunneling works,

34:14.460 --> 34:15.120
because it is going

34:15.120 --> 34:15.800
to become relevant

34:15.800 --> 34:17.240
in the rest of this

34:17.240 --> 34:17.980
episode of the show,

34:18.100 --> 34:18.820
so can you give them

34:18.820 --> 34:19.840
a quick recap on that?

34:20.600 --> 34:20.840
Yeah,

34:20.920 --> 34:21.260
definitely.

34:21.720 --> 34:22.100
Okay,

34:22.100 --> 34:23.100
so let's do this.

34:23.780 --> 34:24.020
Now,

34:24.660 --> 34:25.520
for tunneling,

34:25.880 --> 34:26.460
you basically,

34:27.540 --> 34:28.260
okay,

34:28.620 --> 34:29.100
so I don't want

34:29.100 --> 34:29.840
to use the same word,

34:29.940 --> 34:30.740
but basically you're

34:30.740 --> 34:33.420
transporting packets

34:33.420 --> 34:34.560
that you actually

34:34.560 --> 34:35.380
want to send,

34:35.860 --> 34:37.140
but you're disguising

34:37.140 --> 34:38.600
them as another type

34:38.600 --> 34:39.060
of packet.

34:39.780 --> 34:41.320
So with the example

34:41.320 --> 34:43.380
that I used last time

34:43.380 --> 34:44.060
for DNS,

34:44.540 --> 34:44.780
you know,

34:45.120 --> 34:46.060
tunneling IP

34:46.060 --> 34:46.640
over DNS,

34:46.640 --> 34:49.480
you have this network

34:49.480 --> 34:50.000
stack,

34:50.240 --> 34:51.380
and all it is

34:51.380 --> 34:52.620
is the order

34:52.620 --> 34:53.780
that your headers

34:53.780 --> 34:55.480
go on in a packet,

34:56.240 --> 34:57.660
and it's a stack

34:57.660 --> 34:58.980
because it's,

34:58.980 --> 34:59.260
you know,

34:59.340 --> 35:00.180
first in and last out.

35:01.060 --> 35:01.320
Now,

35:01.380 --> 35:02.420
what that means is

35:02.420 --> 35:03.200
you have these

35:03.200 --> 35:04.340
abstraction layers,

35:04.460 --> 35:04.660
right?

35:04.720 --> 35:05.580
So we talked about

35:05.580 --> 35:06.660
the physical layer,

35:06.780 --> 35:07.360
the link layer,

35:07.920 --> 35:08.800
and then the,

35:08.840 --> 35:09.160
you know,

35:09.220 --> 35:10.240
the IP layer,

35:10.520 --> 35:11.560
and then layer four,

35:11.680 --> 35:12.360
which is transport.

35:13.360 --> 35:13.720
Now,

35:14.040 --> 35:16.340
when you send

35:16.340 --> 35:17.240
a DNS packet,

35:17.240 --> 35:19.120
you have a normal

35:19.120 --> 35:19.800
DNS packet

35:19.800 --> 35:20.760
would have those

35:20.760 --> 35:21.440
four layers,

35:22.080 --> 35:23.520
and then it would

35:23.520 --> 35:24.240
have the actual

35:24.240 --> 35:25.140
DNS content.

35:26.180 --> 35:26.520
Now,

35:27.420 --> 35:28.540
the DNS content

35:28.540 --> 35:29.260
is a payload.

35:30.140 --> 35:30.340
Now,

35:30.440 --> 35:31.460
in certain situations,

35:31.540 --> 35:31.960
like we're talking

35:31.960 --> 35:32.760
about the application

35:32.760 --> 35:33.720
of that,

35:34.000 --> 35:34.160
you know,

35:34.180 --> 35:35.180
airports and such,

35:35.280 --> 35:36.420
they let you

35:36.420 --> 35:38.680
transport DNS packets

35:38.680 --> 35:39.180
openly.

35:39.740 --> 35:41.140
So that means,

35:41.520 --> 35:41.860
you know,

35:41.960 --> 35:43.360
they don't really care

35:43.360 --> 35:46.580
about the source

35:46.580 --> 35:47.880
and destination address,

35:48.140 --> 35:48.840
but it's more

35:48.840 --> 35:49.620
about the port,

35:49.980 --> 35:50.820
because the port

35:50.820 --> 35:52.740
is to the firewall

35:52.740 --> 35:54.600
is what defines,

35:55.320 --> 35:55.580
you know,

35:55.620 --> 35:56.920
this is a DNS packet,

35:57.640 --> 35:57.900
you know,

35:57.920 --> 35:59.080
because most firewalls

35:59.080 --> 36:00.480
won't look in the

36:00.480 --> 36:02.180
actual packet units

36:02.180 --> 36:03.160
and all to make sure

36:03.160 --> 36:03.800
that, you know,

36:03.840 --> 36:06.400
it fits the DNS payload.

36:07.040 --> 36:08.300
So what they do then,

36:08.520 --> 36:08.740
I mean,

36:08.740 --> 36:09.580
what you do then,

36:09.800 --> 36:10.540
is you replace

36:10.540 --> 36:11.060
the payload

36:11.060 --> 36:13.120
with another type

36:13.120 --> 36:13.580
of packet,

36:13.820 --> 36:14.720
one that you actually

36:14.720 --> 36:15.400
want to send.

36:16.080 --> 36:16.440
So,

36:16.660 --> 36:18.140
in your regular DNS packet,

36:18.260 --> 36:19.100
you have those

36:19.100 --> 36:20.180
four headers,

36:20.480 --> 36:20.640
you know,

36:20.680 --> 36:21.440
the regular headers

36:21.440 --> 36:21.980
that you have,

36:22.180 --> 36:22.860
then you have

36:22.860 --> 36:23.940
your other packet,

36:24.340 --> 36:25.480
but that packet

36:25.480 --> 36:26.580
also has

36:26.580 --> 36:27.520
its own headers,

36:27.720 --> 36:27.900
you know,

36:28.140 --> 36:29.320
that packet will have

36:29.320 --> 36:30.540
its own IP layer

36:30.540 --> 36:32.160
and its own,

36:32.220 --> 36:33.420
you know,

36:33.480 --> 36:34.340
transport layer

36:34.340 --> 36:35.220
and whatever else

36:35.220 --> 36:36.140
you have after that.

36:36.140 --> 36:36.580
Now,

36:36.660 --> 36:37.380
notice that

36:37.380 --> 36:38.100
when you do

36:38.100 --> 36:38.860
the tunneling

36:38.860 --> 36:39.960
and you tack on

36:39.960 --> 36:41.300
your own packet

36:41.300 --> 36:43.800
behind the original

36:43.800 --> 36:44.540
DNS packet,

36:44.820 --> 36:45.600
you don't need

36:45.600 --> 36:46.560
to put the physical

36:46.560 --> 36:48.400
layer and link layer

36:48.400 --> 36:49.700
and that's because

36:49.700 --> 36:52.060
when the proxy

36:52.060 --> 36:53.300
on the other side

36:53.300 --> 36:54.380
gets that packet,

36:55.160 --> 36:55.860
it's already

36:55.860 --> 36:56.740
in the kernel

36:56.740 --> 36:57.680
at that state.

36:58.520 --> 36:58.880
So,

36:59.140 --> 36:59.840
you don't need

36:59.840 --> 37:01.400
the two lowest

37:01.400 --> 37:02.180
physical layers,

37:02.480 --> 37:03.300
you just need

37:03.300 --> 37:04.500
the one that has

37:04.500 --> 37:05.140
like the important

37:05.140 --> 37:05.760
information

37:05.760 --> 37:07.740
like the IP address

37:07.740 --> 37:08.420
and then the port,

37:08.560 --> 37:08.840
et cetera,

37:08.940 --> 37:09.280
et cetera.

37:09.920 --> 37:10.360
Now,

37:10.420 --> 37:11.120
so what we're saying

37:11.120 --> 37:12.280
is after you

37:12.280 --> 37:13.300
tack that on,

37:13.840 --> 37:14.580
after you tack

37:14.580 --> 37:15.180
your own packet

37:15.180 --> 37:15.820
onto the end

37:15.820 --> 37:16.860
of the DNS packet

37:16.860 --> 37:17.860
and use that

37:17.860 --> 37:18.620
as a payload,

37:19.220 --> 37:20.120
you send it

37:20.120 --> 37:21.100
from your machine.

37:21.340 --> 37:21.500
Now,

37:21.560 --> 37:22.280
when you hit

37:22.280 --> 37:23.200
the firewall

37:23.200 --> 37:24.420
or whatever

37:24.420 --> 37:25.580
security measures

37:25.580 --> 37:26.820
have at the airport,

37:27.240 --> 37:28.040
it's going to look

37:28.040 --> 37:28.560
and say,

37:28.680 --> 37:28.800
oh,

37:28.860 --> 37:30.060
this is an IP packet

37:30.060 --> 37:31.440
from someone,

37:31.660 --> 37:31.980
you know,

37:32.040 --> 37:32.620
with an IP

37:32.620 --> 37:33.760
inside the network

37:33.760 --> 37:34.980
and it's going

37:34.980 --> 37:35.620
to go out

37:35.620 --> 37:36.020
on,

37:36.020 --> 37:36.460
you know,

37:37.140 --> 37:39.240
court 53,

37:39.480 --> 37:39.820
I think,

37:39.880 --> 37:40.260
is DNS.

37:40.560 --> 37:41.620
I don't remember.

37:41.820 --> 37:42.280
I think it's not.

37:42.780 --> 37:43.320
It's going to go

37:43.320 --> 37:43.940
up to the port.

37:44.580 --> 37:44.860
Now,

37:45.280 --> 37:46.080
I need

37:46.080 --> 37:47.940
to be able

37:47.940 --> 37:48.320
to access

37:48.320 --> 37:49.000
these DNS

37:49.000 --> 37:49.500
to this.

37:49.640 --> 37:49.860
Okay,

37:50.020 --> 37:50.680
hold on,

37:50.800 --> 37:51.220
verbal,

37:51.400 --> 37:51.720
verbal,

37:51.780 --> 37:52.060
verbal,

37:52.140 --> 37:52.340
verbal.

37:52.400 --> 37:53.020
Hold on just a second,

37:53.080 --> 37:53.580
you're breaking up

37:53.580 --> 37:54.180
really bad,

37:54.840 --> 37:55.620
so I don't want to,

37:55.700 --> 37:56.240
and it's kind of

37:56.240 --> 37:57.160
an important part there,

37:57.280 --> 37:58.940
so let's back up

37:58.940 --> 37:59.600
just a little bit.

37:59.600 --> 38:00.980
what you're doing here

38:00.980 --> 38:03.160
is wrapping up

38:03.160 --> 38:03.880
that packet.

38:04.460 --> 38:05.460
Let's go back to there,

38:05.700 --> 38:06.380
and are you getting

38:06.380 --> 38:07.000
a good signal there?

38:07.060 --> 38:07.540
You're on the cell,

38:07.600 --> 38:07.760
right?

38:08.520 --> 38:08.880
Yeah.

38:09.140 --> 38:09.380
Okay,

38:09.580 --> 38:10.720
let's back up

38:10.720 --> 38:12.480
like five,

38:12.680 --> 38:12.800
ten,

38:13.280 --> 38:13.420
yeah,

38:13.500 --> 38:13.880
let's back up

38:13.880 --> 38:14.500
about ten or fifteen

38:14.500 --> 38:15.140
seconds because you

38:15.140 --> 38:15.760
went completely

38:15.760 --> 38:16.440
garbled on us.

38:16.520 --> 38:18.140
Maybe the feds

38:18.140 --> 38:18.660
didn't like our

38:18.660 --> 38:19.460
comments about

38:19.460 --> 38:20.540
the,

38:20.840 --> 38:21.140
yeah.

38:21.560 --> 38:21.940
All right,

38:22.040 --> 38:22.720
so back up

38:22.720 --> 38:23.400
just a few seconds

38:23.400 --> 38:24.360
and say that again.

38:25.420 --> 38:26.020
Where do you

38:26.020 --> 38:26.720
want me to start?

38:27.000 --> 38:27.280
All right,

38:27.380 --> 38:27.580
just,

38:27.940 --> 38:29.240
let's go back

38:29.240 --> 38:30.280
to you were

38:30.280 --> 38:30.860
saying that you

38:30.860 --> 38:31.640
do not need

38:31.640 --> 38:32.700
the physical

38:32.700 --> 38:33.680
layer information

38:33.680 --> 38:34.860
because the

38:34.860 --> 38:35.440
proxy server

38:35.440 --> 38:35.740
is going to

38:35.740 --> 38:36.400
handle that.

38:37.220 --> 38:37.440
Okay,

38:38.400 --> 38:39.760
now keep in mind

38:39.760 --> 38:41.120
when you have

38:41.120 --> 38:42.040
put on your

38:42.040 --> 38:42.600
own packet,

38:43.100 --> 38:44.220
you only need

38:44.220 --> 38:45.180
a pair of three

38:45.180 --> 38:45.560
and up.

38:45.660 --> 38:46.240
You don't need

38:46.240 --> 38:47.220
to put in

38:47.220 --> 38:47.940
the physical

38:47.940 --> 38:49.020
layer and

38:49.020 --> 38:49.760
the link layer

38:49.760 --> 38:50.820
because once

38:50.820 --> 38:52.700
that encapsulated

38:52.700 --> 38:53.900
packet gets

38:53.900 --> 38:54.540
to the proxy

38:54.540 --> 38:55.320
server on the

38:55.320 --> 38:56.060
other side,

38:56.680 --> 38:56.920
you know,

38:57.380 --> 38:58.160
that packet

38:58.160 --> 38:58.820
goes

38:58.820 --> 38:59.760
from the

38:59.760 --> 39:00.560
wire up

39:00.560 --> 39:01.040
to the

39:01.040 --> 39:01.780
OS kernel

39:01.780 --> 39:02.300
already.

39:03.040 --> 39:04.100
So once

39:04.100 --> 39:04.560
it gets

39:04.560 --> 39:04.880
to your

39:04.880 --> 39:05.220
proxy

39:05.220 --> 39:05.860
server,

39:06.380 --> 39:06.580
you know,

39:06.740 --> 39:07.160
you don't

39:07.160 --> 39:07.720
need to

39:07.720 --> 39:08.740
have the

39:08.740 --> 39:09.220
hardware

39:09.220 --> 39:09.740
addresses

39:09.740 --> 39:10.140
and all

39:10.140 --> 39:10.600
that stuff

39:10.600 --> 39:11.280
because it's

39:11.280 --> 39:12.160
supposedly

39:12.160 --> 39:12.920
already processed

39:12.920 --> 39:13.560
by the kernel.

39:13.940 --> 39:14.620
So you only

39:14.620 --> 39:15.280
need important

39:15.280 --> 39:16.160
things like

39:16.160 --> 39:16.980
the IP

39:16.980 --> 39:17.440
addresses

39:17.440 --> 39:17.980
and then

39:17.980 --> 39:18.320
the port

39:18.320 --> 39:18.780
numbers.

39:19.820 --> 39:20.720
So when

39:20.720 --> 39:21.120
someone,

39:21.420 --> 39:21.580
you know,

39:21.660 --> 39:22.320
when you're

39:22.320 --> 39:23.040
a client

39:23.040 --> 39:23.720
at the airport,

39:23.880 --> 39:24.340
for example,

39:24.400 --> 39:25.020
and you send

39:25.020 --> 39:25.560
that packet

39:25.560 --> 39:25.980
out,

39:26.620 --> 39:27.080
what you,

39:27.340 --> 39:27.540
you know,

39:28.000 --> 39:28.660
the firewall

39:28.660 --> 39:29.440
at the other

39:29.440 --> 39:30.440
end is going

39:30.440 --> 39:30.960
to look and

39:30.960 --> 39:31.120
say,

39:31.240 --> 39:31.400
okay,

39:31.460 --> 39:31.940
this is the

39:31.940 --> 39:32.520
IP packet

39:32.520 --> 39:34.360
and then it's

39:34.360 --> 39:34.740
going to look

39:34.740 --> 39:35.260
at the port

39:35.260 --> 39:35.640
and be like,

39:35.700 --> 39:35.820
okay,

39:35.880 --> 39:36.340
this is the

39:36.340 --> 39:37.060
DNS port,

39:37.300 --> 39:37.840
so I'm going

39:37.840 --> 39:38.480
to allow it

39:38.480 --> 39:39.860
because it

39:39.860 --> 39:40.520
has to allow

39:40.520 --> 39:41.620
other legitimate

39:41.620 --> 39:43.300
users to have

39:43.300 --> 39:44.120
access to DNS

39:44.120 --> 39:44.840
so they can,

39:44.900 --> 39:45.060
you know,

39:45.120 --> 39:46.360
bring up their

39:46.360 --> 39:47.800
freaking login

39:47.800 --> 39:48.600
page or whatever.

39:48.760 --> 39:48.920
Right.

39:48.920 --> 39:49.340
You can't

39:49.340 --> 39:50.380
realistically block

39:50.380 --> 39:51.280
the DNS port.

39:52.440 --> 39:52.540
Right.

39:52.720 --> 39:52.860
So,

39:52.980 --> 39:53.140
I mean,

39:53.220 --> 39:54.720
most firewalls

39:54.720 --> 39:55.020
at,

39:55.040 --> 39:55.300
you know,

39:55.400 --> 39:56.480
at mediocre

39:56.480 --> 39:57.520
security places

39:57.520 --> 39:58.100
will block

39:58.100 --> 39:59.200
based on ports

39:59.200 --> 40:00.220
and source IPs

40:00.220 --> 40:01.240
and destination IPs.

40:01.400 --> 40:01.640
Like,

40:01.680 --> 40:02.140
it's not going

40:02.140 --> 40:02.440
to go through

40:02.440 --> 40:03.000
every packet

40:03.000 --> 40:03.560
and look at

40:03.560 --> 40:04.120
the payload

40:04.120 --> 40:05.060
and validate

40:05.060 --> 40:05.520
that,

40:05.620 --> 40:05.880
you know,

40:05.940 --> 40:06.680
it's a legitimate

40:06.680 --> 40:07.620
DNS packet.

40:08.800 --> 40:09.160
Right?

40:09.380 --> 40:09.680
Right.

40:09.720 --> 40:10.140
Unless they

40:10.140 --> 40:10.760
have some kind

40:10.760 --> 40:11.500
of packet shaping

40:11.500 --> 40:11.740
and,

40:11.840 --> 40:11.900
yeah,

40:11.960 --> 40:12.480
most places

40:12.480 --> 40:13.040
aren't doing

40:13.040 --> 40:13.460
any of that

40:13.460 --> 40:13.720
stuff.

40:14.460 --> 40:14.760
Right.

40:14.840 --> 40:15.060
Because,

40:15.260 --> 40:15.820
I mean,

40:15.880 --> 40:16.060
you know,

40:16.100 --> 40:16.540
it takes

40:16.540 --> 40:18.380
significantly more

40:18.380 --> 40:19.520
hardware and

40:19.520 --> 40:20.280
more resources

40:20.280 --> 40:21.440
to look at

40:21.440 --> 40:22.100
the application

40:22.100 --> 40:22.640
layer of

40:22.640 --> 40:23.400
every single

40:23.400 --> 40:23.840
packet.

40:24.060 --> 40:24.340
Like,

40:24.500 --> 40:24.760
because you

40:24.760 --> 40:25.220
have to run

40:25.220 --> 40:26.140
processing on

40:26.140 --> 40:27.060
it and you're

40:27.060 --> 40:27.520
probably not

40:27.520 --> 40:27.780
going to have

40:27.780 --> 40:28.240
that code

40:28.240 --> 40:28.840
in the kernel

40:28.840 --> 40:29.300
then you have

40:29.300 --> 40:29.680
to kick it

40:29.680 --> 40:30.220
up the user

40:30.220 --> 40:30.660
space.

40:30.920 --> 40:31.160
Like,

40:31.200 --> 40:31.500
they're not

40:31.500 --> 40:31.900
going to do

40:31.900 --> 40:32.240
that.

40:32.680 --> 40:32.880
You know,

40:32.960 --> 40:33.100
like,

40:33.140 --> 40:33.660
maybe some

40:33.660 --> 40:34.660
super fancy

40:34.660 --> 40:35.120
place will

40:35.120 --> 40:35.540
have it in

40:35.540 --> 40:35.900
hardware,

40:36.360 --> 40:36.860
like some

40:36.860 --> 40:37.600
Cisco box

40:37.600 --> 40:38.060
or whatever,

40:38.540 --> 40:38.760
but,

40:38.860 --> 40:39.040
like,

40:39.120 --> 40:40.340
most establishments

40:40.340 --> 40:40.780
are not going

40:40.780 --> 40:41.240
to have that.

40:41.320 --> 40:41.440
So,

40:41.520 --> 40:42.120
if you can

40:42.120 --> 40:43.500
tunnel with

40:43.500 --> 40:44.260
the appropriate

40:44.260 --> 40:44.720
port,

40:44.860 --> 40:45.300
then you should

40:45.300 --> 40:45.880
be all set.

40:46.320 --> 40:46.600
Right.

40:46.760 --> 40:47.040
And,

40:47.480 --> 40:48.000
that's,

40:48.000 --> 40:48.240
you know,

40:48.280 --> 40:48.780
that's pretty

40:48.780 --> 40:50.580
much the all,

40:50.800 --> 40:51.160
you know,

40:51.780 --> 40:52.640
the whole story

40:52.640 --> 40:54.120
about tunneling

40:54.120 --> 40:55.280
is you encapsulate

40:55.280 --> 40:55.960
an existing

40:55.960 --> 40:56.980
packet with

40:56.980 --> 40:57.280
another.

40:57.400 --> 40:57.520
Now,

40:57.560 --> 40:57.980
the important

40:57.980 --> 40:58.360
thing to

40:58.360 --> 40:58.960
remember is

40:58.960 --> 40:59.840
you have this

40:59.840 --> 41:00.460
now funky

41:00.460 --> 41:01.380
network stack

41:01.380 --> 41:02.280
that no one

41:02.280 --> 41:02.960
understands

41:02.960 --> 41:04.120
except for

41:04.120 --> 41:04.440
you,

41:04.600 --> 41:04.880
right?

41:05.120 --> 41:05.360
Well,

41:05.440 --> 41:06.200
you and your

41:06.200 --> 41:06.880
proxy server.

41:07.140 --> 41:07.380
And what you

41:07.380 --> 41:07.780
need to do is

41:07.780 --> 41:08.200
choose,

41:08.620 --> 41:09.320
have a proxy

41:09.320 --> 41:10.140
server on the

41:10.140 --> 41:10.680
other end

41:10.680 --> 41:11.900
that understands

41:11.900 --> 41:13.420
this so it

41:13.420 --> 41:14.380
can proxy for

41:14.380 --> 41:14.740
you and

41:14.740 --> 41:15.760
decapsulate your

41:15.760 --> 41:17.680
packet and send

41:17.680 --> 41:18.660
out your actual

41:18.660 --> 41:19.560
packet and get

41:19.560 --> 41:20.420
whatever information

41:20.420 --> 41:20.880
you need.

41:21.580 --> 41:21.900
Right,

41:22.180 --> 41:22.480
right.

41:22.860 --> 41:23.620
And as long

41:23.620 --> 41:23.800
as,

41:23.860 --> 41:24.180
it's kind of

41:24.180 --> 41:24.400
like,

41:25.040 --> 41:26.180
this is probably

41:26.180 --> 41:26.600
a terrible

41:26.600 --> 41:26.940
metaphor,

41:27.100 --> 41:27.380
but it's kind

41:27.380 --> 41:27.680
of like when

41:27.680 --> 41:28.180
you're a kid

41:28.180 --> 41:28.460
and you had

41:28.460 --> 41:28.900
that secret

41:28.900 --> 41:29.500
code with

41:29.500 --> 41:29.960
your friend

41:29.960 --> 41:30.400
that only

41:30.400 --> 41:30.940
he knew

41:30.940 --> 41:31.700
what you

41:31.700 --> 41:32.200
were saying

41:32.200 --> 41:32.520
and what

41:32.520 --> 41:32.860
to do

41:32.860 --> 41:33.120
with it

41:33.120 --> 41:33.300
or how

41:33.300 --> 41:33.740
to interpret

41:33.740 --> 41:33.940
it.

41:34.360 --> 41:34.820
It's you

41:34.820 --> 41:35.080
and your

41:35.080 --> 41:35.820
proxy server

41:35.820 --> 41:36.080
that are

41:36.080 --> 41:36.360
the only

41:36.360 --> 41:36.740
ones that

41:36.740 --> 41:36.920
are going

41:36.920 --> 41:37.100
to,

41:38.060 --> 41:38.500
again,

41:38.560 --> 41:39.000
if they have

41:39.000 --> 41:39.480
the packet

41:39.480 --> 41:40.180
shaping or

41:40.180 --> 41:40.360
the,

41:40.500 --> 41:40.780
like you

41:40.780 --> 41:40.980
said,

41:41.040 --> 41:41.440
maybe some

41:41.440 --> 41:41.840
high-end

41:41.840 --> 41:42.140
Cisco

41:42.140 --> 41:42.620
device,

41:42.720 --> 41:43.020
but those

41:43.020 --> 41:43.560
are expensive

41:43.560 --> 41:44.500
and people

41:44.500 --> 41:44.920
don't have

41:44.920 --> 41:45.000
them.

41:45.060 --> 41:45.320
They could

41:45.320 --> 41:45.600
really,

41:45.980 --> 41:46.360
it is

41:46.360 --> 41:47.160
plain text

41:47.160 --> 41:48.020
and maybe

41:48.020 --> 41:48.440
this is a

41:48.440 --> 41:48.880
good segue

41:48.880 --> 41:49.280
to talk

41:49.280 --> 41:49.660
about some

41:49.660 --> 41:50.220
other things

41:50.220 --> 41:50.740
that are

41:50.740 --> 41:51.180
related to

41:51.180 --> 41:51.440
this,

41:51.880 --> 41:54.480
is encrypting

41:54.480 --> 41:55.580
or encrypted

41:55.580 --> 41:56.300
communications,

41:56.520 --> 41:57.540
which some

41:57.540 --> 41:58.180
forms of

41:58.180 --> 41:58.760
them work

41:58.760 --> 41:59.360
similarly.

41:59.600 --> 42:00.240
They are

42:00.240 --> 42:00.780
forms of

42:00.780 --> 42:01.160
tunneling.

42:01.200 --> 42:01.480
Is that

42:01.480 --> 42:02.160
an accurate

42:02.160 --> 42:02.540
statement?

42:03.720 --> 42:04.140
Yeah.

42:04.400 --> 42:05.380
Specifically VPN

42:05.380 --> 42:05.920
is what I'm

42:05.920 --> 42:06.220
getting at.

42:06.240 --> 42:06.580
When you

42:06.580 --> 42:07.860
have VPNs,

42:07.860 --> 42:08.060
right?

42:08.200 --> 42:08.500
Right.

42:09.300 --> 42:09.620
You're,

42:10.120 --> 42:10.620
I mean,

42:10.680 --> 42:10.840
okay,

42:10.920 --> 42:11.680
so the idea

42:11.680 --> 42:12.660
of a VPN,

42:13.160 --> 42:13.780
which is a

42:13.780 --> 42:14.420
virtual private

42:14.420 --> 42:14.860
network,

42:14.980 --> 42:16.580
is you have

42:16.580 --> 42:17.820
boxes at

42:17.820 --> 42:18.800
geographically,

42:18.960 --> 42:19.620
you know,

42:19.740 --> 42:21.480
separate locations.

42:22.200 --> 42:22.520
I mean,

42:22.560 --> 42:23.040
it doesn't even

42:23.040 --> 42:23.500
have to be

42:23.500 --> 42:24.080
geographically,

42:24.160 --> 42:24.680
but it's like

42:24.680 --> 42:25.300
you're on

42:25.300 --> 42:26.220
different networks

42:26.220 --> 42:27.660
and you want

42:27.660 --> 42:29.280
them to appear

42:29.280 --> 42:29.860
like they're on

42:29.860 --> 42:30.580
the same network.

42:30.720 --> 42:30.840
So,

42:30.940 --> 42:31.140
I mean,

42:31.220 --> 42:31.720
I'm sure

42:31.720 --> 42:32.340
everyone is

42:32.340 --> 42:33.240
familiar with

42:33.240 --> 42:34.200
like use cases

42:34.200 --> 42:34.760
of VPN.

42:35.160 --> 42:35.680
Like if I'm

42:35.680 --> 42:36.160
working from

42:36.160 --> 42:36.740
home today,

42:37.160 --> 42:37.940
then I want

42:37.940 --> 42:38.500
a VPN

42:38.500 --> 42:39.180
into my

42:39.180 --> 42:39.540
work,

42:39.960 --> 42:40.820
then from

42:40.820 --> 42:41.560
their end

42:41.560 --> 42:42.300
or from

42:42.300 --> 42:43.000
someone else

42:43.000 --> 42:43.400
that's in

42:43.400 --> 42:43.880
the corporate

42:43.880 --> 42:44.360
network,

42:44.640 --> 42:45.300
my machine

42:45.300 --> 42:46.140
looks like

42:46.140 --> 42:47.360
it's supposed

42:47.360 --> 42:48.000
to be there

42:48.000 --> 42:48.400
and it's

42:48.400 --> 42:48.880
plugged in

42:48.880 --> 42:49.220
at some

42:49.220 --> 42:49.660
place.

42:50.320 --> 42:50.460
Right.

42:51.000 --> 42:51.600
Now,

42:51.820 --> 42:53.040
to do that,

42:53.700 --> 42:54.020
right,

42:54.220 --> 42:54.940
you can

42:54.940 --> 42:55.440
implement

42:55.440 --> 42:56.200
a form

42:56.200 --> 42:56.920
of tunneling.

42:57.560 --> 42:57.860
Now,

42:58.120 --> 42:58.600
there's,

42:58.680 --> 42:58.960
you know,

42:59.060 --> 43:00.320
many existing

43:00.320 --> 43:00.920
technologies

43:00.920 --> 43:01.420
for this

43:01.420 --> 43:02.540
and tunneling

43:02.540 --> 43:02.940
is only

43:02.940 --> 43:03.660
one of them,

43:04.100 --> 43:05.200
but mostly

43:05.200 --> 43:05.920
what happens

43:05.920 --> 43:07.080
is there's

43:07.080 --> 43:07.480
a level

43:07.480 --> 43:08.020
of encryption

43:08.020 --> 43:08.520
involved,

43:08.900 --> 43:09.100
right?

43:09.260 --> 43:09.860
You make

43:09.860 --> 43:10.300
some sort

43:10.300 --> 43:10.840
of connection

43:10.840 --> 43:12.580
from yourself

43:12.580 --> 43:13.820
and make

43:13.820 --> 43:15.020
it to some

43:15.020 --> 43:16.300
entry point

43:16.300 --> 43:17.220
in the network

43:17.220 --> 43:17.660
you want

43:17.660 --> 43:18.260
to be a part

43:18.260 --> 43:18.480
of,

43:18.700 --> 43:19.200
right?

43:19.540 --> 43:19.980
Now,

43:20.740 --> 43:21.360
ideally,

43:21.640 --> 43:22.440
to be secure,

43:22.740 --> 43:23.940
that connection

43:23.940 --> 43:25.420
is secure

43:25.420 --> 43:26.160
because the whole

43:26.160 --> 43:26.620
point is you

43:26.620 --> 43:27.880
don't trust

43:27.880 --> 43:28.880
whatever is,

43:28.980 --> 43:29.280
you know,

43:29.320 --> 43:30.380
in between you

43:30.380 --> 43:31.920
and the place

43:31.920 --> 43:32.440
you're trying

43:32.440 --> 43:33.540
to VPN

43:33.540 --> 43:34.000
into.

43:34.640 --> 43:34.900
So,

43:35.040 --> 43:35.440
usually,

43:35.660 --> 43:36.120
the case

43:36.120 --> 43:36.680
is the

43:36.680 --> 43:37.040
internet,

43:37.340 --> 43:37.600
right?

43:38.480 --> 43:38.800
Now,

43:39.800 --> 43:40.320
the first

43:40.320 --> 43:40.920
thing you do,

43:41.680 --> 43:42.280
every single

43:42.280 --> 43:43.340
VPN has

43:43.340 --> 43:43.980
some sort

43:43.980 --> 43:44.760
of authentication

43:44.760 --> 43:46.000
mechanism

43:46.000 --> 43:47.220
at the entry

43:47.220 --> 43:48.020
point to make

43:48.020 --> 43:48.440
sure,

43:48.540 --> 43:48.800
you know,

43:48.880 --> 43:49.400
you have,

43:49.480 --> 43:49.860
you're supposed

43:49.860 --> 43:50.520
to be there.

43:51.140 --> 43:51.620
So,

43:52.100 --> 43:52.440
usually,

43:52.540 --> 43:53.300
there's a firewall

43:53.300 --> 43:54.240
that sits,

43:54.880 --> 43:55.220
you know,

43:55.320 --> 43:56.720
on the corporate

43:56.720 --> 43:57.240
network

43:57.240 --> 43:58.160
at the edge

43:58.160 --> 43:59.520
and if

43:59.520 --> 43:59.860
you want

43:59.860 --> 44:00.400
a VPN

44:00.400 --> 44:00.900
in,

44:01.700 --> 44:02.340
then you

44:02.340 --> 44:02.760
have to

44:02.760 --> 44:03.200
authenticate

44:03.200 --> 44:03.560
with the

44:03.560 --> 44:04.240
firewalls.

44:04.320 --> 44:04.460
So,

44:04.900 --> 44:05.720
that stuff

44:05.720 --> 44:06.500
is implemented

44:06.500 --> 44:07.120
by like

44:07.120 --> 44:07.780
Radius,

44:08.000 --> 44:08.540
like AAA

44:08.540 --> 44:08.960
Radius,

44:09.020 --> 44:09.240
I'm sure

44:09.240 --> 44:09.580
you've heard

44:09.580 --> 44:09.980
of that,

44:10.260 --> 44:10.660
and like

44:10.660 --> 44:11.140
PAM,

44:11.700 --> 44:13.080
the authentication

44:13.080 --> 44:14.180
module stuff,

44:14.580 --> 44:14.780
you know,

44:14.840 --> 44:15.380
they use that

44:15.380 --> 44:16.000
for everything.

44:17.060 --> 44:17.260
Now,

44:17.860 --> 44:18.440
so that takes

44:18.440 --> 44:19.420
care of the

44:19.420 --> 44:19.840
authentication.

44:21.040 --> 44:21.380
Now,

44:21.560 --> 44:22.020
if you've

44:22.020 --> 44:22.460
ever used

44:22.460 --> 44:22.980
a VPN

44:22.980 --> 44:23.980
client before,

44:24.720 --> 44:24.980
you know,

44:25.160 --> 44:26.320
when you start

44:26.320 --> 44:26.720
it and you

44:26.720 --> 44:27.320
authenticate,

44:27.320 --> 44:28.760
then you

44:28.760 --> 44:29.700
kind of,

44:30.180 --> 44:31.040
some magic

44:31.040 --> 44:32.480
happens and

44:32.480 --> 44:33.440
your box

44:33.440 --> 44:34.480
now has

44:34.480 --> 44:36.300
access to,

44:36.400 --> 44:36.920
you know,

44:36.980 --> 44:38.380
other addresses

44:38.380 --> 44:39.460
inside the

44:39.460 --> 44:40.220
corporate network.

44:40.680 --> 44:41.160
Right.

44:41.160 --> 44:41.460
And I'm going

44:41.460 --> 44:42.080
to talk a little

44:42.080 --> 44:43.100
bit about,

44:43.280 --> 44:43.680
you know,

44:43.740 --> 44:44.320
how that's

44:44.320 --> 44:44.980
actually done.

44:45.520 --> 44:45.880
Well,

44:46.000 --> 44:46.220
yeah,

44:46.280 --> 44:46.680
we've got to

44:46.680 --> 44:47.440
address IP

44:47.440 --> 44:48.000
authentication

44:48.000 --> 44:48.680
and IP

44:48.680 --> 44:49.280
resolution.

44:51.320 --> 44:51.880
As far as,

44:51.920 --> 44:52.160
Okay,

44:52.460 --> 44:52.920
all right.

44:53.080 --> 44:53.340
Definitely,

44:53.940 --> 44:54.080
well,

44:54.180 --> 44:54.840
let's just,

44:55.660 --> 44:56.360
I'm sorry,

44:56.360 --> 44:57.860
we want to,

44:57.960 --> 44:58.440
I think we

44:58.440 --> 44:58.880
should clarify

44:58.880 --> 44:59.340
here that

44:59.340 --> 45:00.160
there's a

45:00.160 --> 45:00.580
before and

45:00.580 --> 45:00.800
after.

45:00.940 --> 45:01.680
You said it,

45:01.760 --> 45:02.080
but let me

45:02.080 --> 45:02.920
just simplify

45:02.920 --> 45:03.500
here that,

45:03.700 --> 45:04.240
or make a

45:04.240 --> 45:04.660
clear point

45:04.660 --> 45:04.900
anyway,

45:05.060 --> 45:06.200
that before

45:06.200 --> 45:06.700
you connect

45:06.700 --> 45:06.920
to your

45:06.920 --> 45:07.280
VPN,

45:07.420 --> 45:07.620
you're going

45:07.620 --> 45:07.860
to get

45:07.860 --> 45:08.480
whatever IP

45:08.480 --> 45:09.640
address has

45:09.640 --> 45:10.160
been assigned

45:10.160 --> 45:10.780
to you by

45:10.780 --> 45:11.280
either your

45:11.280 --> 45:11.680
dial-up

45:11.680 --> 45:12.140
provider,

45:12.320 --> 45:13.200
your cable

45:13.200 --> 45:13.580
modem,

45:13.660 --> 45:13.860
whatever.

45:14.020 --> 45:14.460
You've got an

45:14.460 --> 45:15.440
IP address in

45:15.440 --> 45:16.120
their subnet.

45:16.700 --> 45:17.060
And when you

45:17.060 --> 45:17.640
establish this

45:17.640 --> 45:18.720
VPN communication,

45:18.940 --> 45:19.620
as Verbal said

45:19.620 --> 45:20.000
earlier,

45:20.380 --> 45:21.200
you're establishing

45:21.200 --> 45:22.420
a handshake and

45:22.420 --> 45:23.840
you're being

45:23.840 --> 45:25.040
reassigned an IP

45:25.040 --> 45:25.640
address because

45:25.640 --> 45:26.140
you are now

45:26.140 --> 45:27.020
looking on,

45:27.140 --> 45:27.720
at least within

45:27.720 --> 45:28.240
that VPN,

45:28.520 --> 45:28.980
you are a

45:28.980 --> 45:30.560
part of that

45:30.560 --> 45:31.200
network where

45:31.200 --> 45:32.120
the VPN resides,

45:32.220 --> 45:32.680
which is why

45:32.680 --> 45:33.500
the term virtual

45:33.500 --> 45:34.240
private network,

45:34.300 --> 45:35.160
and you're becoming

45:35.160 --> 45:35.720
part of that

45:35.720 --> 45:36.080
network.

45:36.440 --> 45:36.740
And if you'll

45:36.740 --> 45:37.140
check,

45:37.380 --> 45:38.180
your IP address

45:38.180 --> 45:38.880
is now resolving

45:38.880 --> 45:39.440
to something

45:39.440 --> 45:40.780
internal to the

45:40.780 --> 45:41.060
network.

45:41.280 --> 45:42.060
And it's very,

45:42.180 --> 45:43.280
very common in

45:43.280 --> 45:44.040
corporate environments,

45:44.140 --> 45:44.680
which is probably

45:44.680 --> 45:45.920
the way we're

45:45.920 --> 45:46.460
going to emphasize

45:46.460 --> 45:47.160
or talk about

45:47.160 --> 45:47.900
this because

45:47.900 --> 45:49.900
internally,

45:50.580 --> 45:51.180
let's say you

45:51.180 --> 45:51.880
have an internal,

45:52.160 --> 45:52.740
I don't know,

45:52.740 --> 45:53.360
an internal

45:53.360 --> 45:56.720
documentation folder

45:56.720 --> 45:57.400
where you store

45:57.400 --> 45:57.960
all your official

45:57.960 --> 45:58.660
documentation.

45:59.460 --> 46:00.000
And the way that

46:00.000 --> 46:00.580
you keep people

46:00.580 --> 46:00.980
out of that,

46:01.140 --> 46:02.020
one of the

46:02.020 --> 46:02.620
security methods

46:02.620 --> 46:03.220
you have in

46:03.220 --> 46:04.540
there is IP

46:04.540 --> 46:05.340
resolution,

46:05.460 --> 46:06.260
IP authentication.

46:06.720 --> 46:07.440
For only people

46:07.440 --> 46:08.380
that come from

46:08.380 --> 46:09.840
my local internet

46:09.840 --> 46:10.140
where,

46:10.240 --> 46:10.600
I don't know,

46:10.680 --> 46:16.140
147.147.147.x,

46:16.740 --> 46:17.740
anybody within that

46:17.740 --> 46:18.860
has access to it,

46:18.880 --> 46:19.420
or whatever your

46:19.420 --> 46:19.880
address range,

46:19.920 --> 46:20.240
of course I'm

46:20.240 --> 46:21.060
making stuff up now,

46:21.060 --> 46:22.320
but whatever your

46:22.320 --> 46:23.280
address range is,

46:23.380 --> 46:23.840
well when you're

46:23.840 --> 46:24.720
VPNed in,

46:25.000 --> 46:25.780
as far as the

46:25.780 --> 46:26.560
network is concerned,

46:26.640 --> 46:27.320
you are now

46:27.320 --> 46:28.100
within that range

46:28.100 --> 46:29.020
and you can access

46:29.020 --> 46:29.840
all those internal

46:29.840 --> 46:31.480
things even though

46:31.480 --> 46:32.240
you are at home

46:32.240 --> 46:33.720
VPNed into that

46:33.720 --> 46:34.080
system.

46:34.180 --> 46:35.120
So understand IP

46:35.120 --> 46:37.580
authentication and

46:37.580 --> 46:39.760
how that falls into

46:39.760 --> 46:40.320
play of the whole

46:40.320 --> 46:40.860
thing because you're

46:40.860 --> 46:42.940
not really the same

46:42.940 --> 46:43.840
computer anymore.

46:43.980 --> 46:45.320
I don't know how to

46:45.320 --> 46:46.100
put that into words.

46:46.200 --> 46:46.640
Am I doing,

46:47.700 --> 46:48.420
is it making sense?

46:48.920 --> 46:49.660
Yeah, okay,

46:49.660 --> 46:50.560
so maybe I'll be

46:50.560 --> 46:52.240
more clear if I talk

46:52.240 --> 46:53.680
about how that

46:53.680 --> 46:54.580
actually happens and

46:54.580 --> 46:55.620
like how the actual

46:55.620 --> 46:56.600
packet is sent.

46:56.760 --> 46:57.040
Okay.

46:57.660 --> 47:01.480
Okay, so now normally

47:01.480 --> 47:02.600
when you send a packet

47:02.600 --> 47:04.540
from your computer and

47:04.540 --> 47:05.880
you don't have a

47:05.880 --> 47:06.520
tunnel, not,

47:06.700 --> 47:06.920
sorry,

47:07.040 --> 47:07.360
excuse me,

47:07.660 --> 47:08.740
not a VPN,

47:09.000 --> 47:09.400
you know,

47:09.440 --> 47:09.880
configured,

47:10.340 --> 47:11.760
you have your own

47:11.760 --> 47:13.840
IP and you have

47:13.840 --> 47:14.900
your own transport

47:14.900 --> 47:15.340
layer,

47:15.560 --> 47:15.820
you know,

47:15.820 --> 47:16.420
if there is a

47:16.420 --> 47:17.160
transport layer for

47:17.160 --> 47:17.820
the protocol you're

47:17.820 --> 47:18.120
using.

47:18.820 --> 47:19.040
Now,

47:19.600 --> 47:20.580
so don't worry

47:20.580 --> 47:21.200
about the physical

47:21.200 --> 47:21.760
link layer.

47:22.160 --> 47:22.600
That just

47:22.600 --> 47:23.680
sets a packet

47:23.680 --> 47:24.860
out to your gateway.

47:25.320 --> 47:25.820
Like that,

47:25.900 --> 47:26.460
that is just

47:26.460 --> 47:27.160
forgetting it

47:27.160 --> 47:27.980
over the wire.

47:28.740 --> 47:29.840
So all that

47:29.840 --> 47:30.620
interesting routing

47:30.620 --> 47:31.780
stuff happens

47:31.780 --> 47:32.560
with the IP,

47:32.720 --> 47:33.900
starting at the IP

47:33.900 --> 47:34.160
layer.

47:34.900 --> 47:35.220
Now,

47:35.600 --> 47:37.140
when you are,

47:37.220 --> 47:37.560
you know,

47:37.840 --> 47:38.960
when you're

47:38.960 --> 47:39.680
routing a packet,

47:40.120 --> 47:40.660
you need the

47:40.660 --> 47:41.460
source and destination

47:41.460 --> 47:42.660
address so you

47:42.660 --> 47:43.380
know where it's

47:43.380 --> 47:43.640
going,

47:43.640 --> 47:43.920
right?

47:44.360 --> 47:44.740
Now,

47:45.420 --> 47:46.180
when you do

47:46.180 --> 47:47.920
that for your

47:47.920 --> 47:48.520
computer,

47:48.800 --> 47:49.480
it has a certain

47:49.480 --> 47:50.200
IP address,

47:50.280 --> 47:50.520
right?

47:50.900 --> 47:51.100
Right.

47:51.120 --> 47:51.420
Now,

47:51.900 --> 47:52.800
when you're doing

47:52.800 --> 47:53.900
that for a VPN,

47:55.000 --> 47:55.700
not only,

47:55.800 --> 47:56.660
so you have to

47:56.660 --> 47:57.880
get your,

47:57.880 --> 47:59.540
your packet

47:59.540 --> 48:02.120
from your

48:02.120 --> 48:03.360
computer to the

48:03.360 --> 48:04.700
gateway over to

48:04.700 --> 48:04.880
there,

48:04.960 --> 48:05.580
all the way to

48:05.580 --> 48:06.360
the other side,

48:06.520 --> 48:06.800
right?

48:07.060 --> 48:09.040
But the virtual

48:09.040 --> 48:09.980
part comes in

48:09.980 --> 48:11.400
because once it

48:11.400 --> 48:12.200
gets to the

48:12.200 --> 48:13.800
other side to

48:13.800 --> 48:15.040
the VPN way,

48:15.420 --> 48:16.680
the VPN looks

48:16.680 --> 48:17.900
at that packet

48:17.900 --> 48:18.860
and like

48:18.860 --> 48:19.400
tunneling,

48:19.520 --> 48:20.700
it takes away

48:20.700 --> 48:22.280
all the other

48:22.280 --> 48:24.140
stuff as the

48:24.140 --> 48:25.320
IP and

48:25.320 --> 48:26.500
later and

48:26.500 --> 48:27.420
transport layer

48:27.420 --> 48:28.720
of your original

48:28.720 --> 48:29.220
packet.

48:29.580 --> 48:30.360
And what you have

48:30.360 --> 48:31.080
in there is a

48:31.080 --> 48:32.240
whole new packet

48:32.240 --> 48:34.100
and that second

48:34.100 --> 48:35.440
IP and transport

48:35.440 --> 48:36.000
layer,

48:36.680 --> 48:37.400
header,

48:38.200 --> 48:38.500
is,

48:38.840 --> 48:39.760
contains your

48:39.760 --> 48:41.660
IP for

48:41.660 --> 48:42.900
you know,

48:43.000 --> 48:44.100
your virtual

48:44.100 --> 48:45.160
IP address.

48:45.320 --> 48:45.740
Right.

48:45.820 --> 48:46.520
And your,

48:46.680 --> 48:46.860
you know,

48:46.920 --> 48:47.720
whatever other

48:47.720 --> 48:48.580
application you're

48:48.580 --> 48:48.860
using.

48:49.100 --> 48:49.580
Excellent.

48:49.700 --> 48:50.060
Excellent

48:50.060 --> 48:50.680
explanation.

48:52.560 --> 48:52.940
So,

48:53.620 --> 48:53.940
right.

48:54.500 --> 48:54.940
Now,

48:55.480 --> 48:55.920
the thing,

48:56.040 --> 48:56.220
now,

48:56.460 --> 48:57.060
on the other

48:57.060 --> 48:57.400
side,

48:57.480 --> 48:57.780
like what

48:57.780 --> 48:59.180
actually happens

48:59.180 --> 49:01.440
is you have a

49:01.440 --> 49:02.500
virtual interface,

49:02.900 --> 49:03.340
so I mean,

49:03.400 --> 49:04.100
depending on the

49:04.100 --> 49:05.420
OS and the

49:05.420 --> 49:06.360
VPN client you're

49:06.360 --> 49:06.660
using,

49:07.080 --> 49:07.760
if you do like

49:07.760 --> 49:08.940
IF config or

49:08.940 --> 49:10.040
IP config in

49:10.040 --> 49:10.360
Windows,

49:10.720 --> 49:11.100
you'll see

49:11.100 --> 49:11.680
different things.

49:12.420 --> 49:13.600
But you still

49:13.600 --> 49:14.560
have an IP

49:14.560 --> 49:16.060
address on

49:16.060 --> 49:16.640
your local

49:16.640 --> 49:17.160
network,

49:17.540 --> 49:18.420
but you'll

49:18.420 --> 49:19.300
have a virtual

49:19.300 --> 49:20.940
address that

49:20.940 --> 49:22.100
has an IP,

49:22.320 --> 49:22.740
whether they

49:22.740 --> 49:23.740
displayed or not,

49:23.800 --> 49:24.160
they have a

49:24.160 --> 49:25.000
virtual IP

49:25.000 --> 49:27.760
that is for

49:27.760 --> 49:28.400
the VPN.

49:28.960 --> 49:29.200
Now,

49:29.620 --> 49:30.680
most clients

49:30.680 --> 49:31.760
will do full

49:31.760 --> 49:32.680
tunneling and

49:32.680 --> 49:33.760
not split tunneling,

49:33.820 --> 49:34.160
and I'll get

49:34.160 --> 49:34.920
to that in a

49:34.920 --> 49:35.120
second.

49:35.120 --> 49:36.100
But most

49:36.100 --> 49:36.840
VPN clients

49:36.840 --> 49:37.400
will tunnel

49:37.400 --> 49:38.040
all your

49:38.040 --> 49:39.640
traffic over

49:39.640 --> 49:40.480
the VPN.

49:40.680 --> 49:41.160
So what they

49:41.160 --> 49:42.540
do is your

49:42.540 --> 49:43.700
computer has a

49:43.700 --> 49:44.980
default interface

49:44.980 --> 49:45.860
that it sends

49:45.860 --> 49:46.420
stuff to,

49:46.920 --> 49:47.680
and it'll send

49:47.680 --> 49:48.080
it to the

49:48.080 --> 49:49.140
virtual interface,

49:49.800 --> 49:50.700
and that

49:50.700 --> 49:51.780
virtual interface

49:51.780 --> 49:52.760
will have

49:52.760 --> 49:53.920
code that

49:53.920 --> 49:54.340
is going to

49:54.340 --> 49:55.080
put in

49:55.080 --> 49:57.020
headers for

49:57.020 --> 49:57.600
other,

49:57.920 --> 49:58.140
you know,

49:58.200 --> 49:58.500
for your

49:58.500 --> 49:59.680
virtual identity

49:59.680 --> 50:00.580
in the corporate

50:00.580 --> 50:01.200
network or

50:01.200 --> 50:01.780
whatever you're

50:01.780 --> 50:02.680
VPNing into.

50:03.520 --> 50:04.500
Then that

50:04.500 --> 50:05.100
virtual interface

50:05.100 --> 50:06.080
will link up

50:06.080 --> 50:06.640
to the

50:06.640 --> 50:06.940
physical

50:06.940 --> 50:07.520
interface.

50:08.320 --> 50:09.220
So once,

50:09.520 --> 50:09.820
you know,

50:09.860 --> 50:10.280
the virtual

50:10.280 --> 50:10.900
interface is

50:10.900 --> 50:11.440
done with

50:11.440 --> 50:12.320
putting in,

50:12.420 --> 50:12.640
you know,

50:12.660 --> 50:13.140
the virtual

50:13.140 --> 50:14.080
info on it,

50:14.420 --> 50:15.020
that's a

50:15.020 --> 50:15.640
valid packet,

50:15.860 --> 50:16.300
but not for

50:16.300 --> 50:16.620
your local

50:16.620 --> 50:16.980
network.

50:17.320 --> 50:17.780
When you

50:17.780 --> 50:18.540
send it out

50:18.540 --> 50:19.240
through the

50:19.240 --> 50:19.600
physical,

50:19.820 --> 50:20.120
like the

50:20.120 --> 50:21.000
real interface,

50:21.780 --> 50:22.500
then that

50:22.500 --> 50:23.060
interface,

50:23.540 --> 50:23.780
you know,

50:23.840 --> 50:24.240
code in the

50:24.240 --> 50:24.720
kernel will

50:24.720 --> 50:25.800
tack on IP

50:25.800 --> 50:26.340
headers and

50:26.340 --> 50:26.920
other headers

50:26.920 --> 50:27.780
for that

50:27.780 --> 50:28.220
interface.

50:28.880 --> 50:29.900
So when it

50:29.900 --> 50:30.400
goes out,

50:30.480 --> 50:30.920
you'll have

50:30.920 --> 50:31.520
the, you

50:31.520 --> 50:31.620
know,

50:31.660 --> 50:32.260
encapsulated

50:32.260 --> 50:32.660
packet.

50:32.660 --> 50:34.500
Right,

50:34.620 --> 50:35.140
and this

50:35.140 --> 50:35.800
is basically

50:35.800 --> 50:36.460
the VPN

50:36.460 --> 50:37.440
server that

50:37.440 --> 50:37.820
you're talking

50:37.820 --> 50:38.380
here is very

50:38.380 --> 50:39.080
much a parallel

50:39.080 --> 50:39.800
to the

50:39.800 --> 50:40.940
proxy server we

50:40.940 --> 50:41.580
described in

50:41.580 --> 50:42.160
tunneling on

50:42.160 --> 50:42.680
that previous

50:42.680 --> 50:43.380
episode and

50:43.380 --> 50:44.120
earlier in this

50:44.120 --> 50:44.460
episode.

50:44.860 --> 50:45.600
They're both

50:45.600 --> 50:46.100
doing the

50:46.100 --> 50:47.120
similar things,

50:47.200 --> 50:47.940
it's just that

50:47.940 --> 50:49.200
you're not

50:49.200 --> 50:50.140
necessarily tunneling

50:50.140 --> 50:50.760
on the DNS

50:50.760 --> 50:51.840
layer this time

50:51.840 --> 50:52.400
or the DNS

50:52.400 --> 50:53.180
packet types.

50:54.240 --> 50:54.940
This is just

50:54.940 --> 50:57.100
virtualizing the

50:57.100 --> 50:57.740
whole process,

50:57.820 --> 50:58.180
I guess.

50:58.180 --> 50:59.780
Right.

50:59.920 --> 51:00.440
It's an

51:00.440 --> 51:01.060
encrypted proxy.

51:01.060 --> 51:01.460
When you do

51:01.460 --> 51:02.920
that, you

51:02.920 --> 51:03.700
will obviously

51:03.700 --> 51:04.260
use more

51:04.260 --> 51:05.020
bandwidth because

51:05.020 --> 51:05.540
you have extra

51:05.540 --> 51:06.000
hackers.

51:07.140 --> 51:07.420
But, you

51:07.420 --> 51:07.820
know, so,

51:07.980 --> 51:08.200
you know,

51:08.240 --> 51:08.740
sometimes your

51:08.740 --> 51:09.340
VPN is just

51:09.340 --> 51:09.820
up and it's

51:09.820 --> 51:10.520
slower, but,

51:10.620 --> 51:10.720
you know,

51:10.740 --> 51:11.400
that's why it's

51:11.400 --> 51:11.700
happening.

51:12.960 --> 51:14.380
Now, before

51:14.380 --> 51:14.900
when I was

51:14.900 --> 51:15.660
saying, like,

51:15.780 --> 51:17.060
if you use

51:17.060 --> 51:18.120
some program,

51:18.340 --> 51:18.740
like VPN

51:18.740 --> 51:19.580
clients, they'll

51:19.580 --> 51:21.020
tunnel all your

51:21.020 --> 51:21.660
connections.

51:22.580 --> 51:22.760
Now,

51:22.980 --> 51:23.740
Stank, have

51:23.740 --> 51:24.780
you used any

51:24.780 --> 51:25.760
VPN clients,

51:25.900 --> 51:26.840
like, you

51:26.840 --> 51:27.220
know, in

51:27.220 --> 51:27.760
work or

51:27.760 --> 51:28.020
whatever?

51:28.360 --> 51:28.800
Absolutely.

51:29.040 --> 51:29.380
I use them

51:29.380 --> 51:30.020
on a daily

51:30.020 --> 51:30.480
basis,

51:30.600 --> 51:31.020
regularly.

51:31.880 --> 51:32.880
What VPN

51:32.880 --> 51:33.500
client do

51:33.500 --> 51:33.820
you use?

51:35.060 --> 51:35.500
Multiple

51:35.500 --> 51:36.960
ones, and

51:36.960 --> 51:38.140
I can't drop

51:38.140 --> 51:38.480
too many

51:38.480 --> 51:38.900
docs or

51:38.900 --> 51:39.380
anything, but

51:39.380 --> 51:39.840
in my line

51:39.840 --> 51:40.360
of work, I

51:40.360 --> 51:40.940
have to,

51:41.800 --> 51:42.560
security is a

51:42.560 --> 51:43.740
big aspect of

51:43.740 --> 51:44.200
it, so

51:44.200 --> 51:45.220
whatever different

51:45.220 --> 51:46.080
clients use at

51:46.080 --> 51:46.440
their different

51:46.440 --> 51:47.320
sites is what

51:47.320 --> 51:48.400
I use, so I

51:48.400 --> 51:48.780
have to be

51:48.780 --> 51:49.520
flexible to use

51:49.520 --> 51:49.620
them.

51:49.800 --> 51:50.360
But let's

51:50.360 --> 51:50.980
go with

51:50.980 --> 51:52.420
Cisco if you

51:52.420 --> 51:53.060
want a specific

51:53.060 --> 51:53.720
example or

51:53.720 --> 51:54.020
something.

51:54.760 --> 51:55.100
Right.

51:55.100 --> 51:55.720
So, now,

51:56.140 --> 51:57.020
when you use,

51:57.240 --> 51:57.760
I mean, for

51:57.760 --> 51:58.320
any of your

51:58.320 --> 51:59.320
VPN clients,

51:59.920 --> 52:00.700
does it

52:00.700 --> 52:01.920
tunnel all

52:01.920 --> 52:02.280
of your

52:02.280 --> 52:03.560
traffic over

52:03.560 --> 52:04.120
the VPN?

52:04.860 --> 52:05.460
Well, and

52:05.460 --> 52:06.180
actually, I

52:06.180 --> 52:06.860
think that's a

52:06.860 --> 52:08.140
good question for

52:08.140 --> 52:08.780
everybody.

52:09.620 --> 52:10.360
Every one of

52:10.360 --> 52:10.940
them is different,

52:11.040 --> 52:11.480
so I can't

52:11.480 --> 52:11.980
really give you a

52:11.980 --> 52:12.440
straight answer.

52:12.540 --> 52:13.160
Some do, some

52:13.160 --> 52:13.540
don't.

52:14.000 --> 52:14.280
Right.

52:14.280 --> 52:15.800
But I think this

52:15.800 --> 52:17.280
is very excellent

52:17.280 --> 52:19.800
and I think we

52:19.800 --> 52:20.240
should emphasize

52:20.240 --> 52:22.200
this that, well,

52:22.300 --> 52:23.280
let me actually

52:23.280 --> 52:23.980
ask the question

52:23.980 --> 52:24.720
back to you.

52:25.100 --> 52:25.980
Does it matter?

52:26.100 --> 52:26.580
What is the

52:26.580 --> 52:27.620
difference between

52:27.620 --> 52:28.960
split or full

52:28.960 --> 52:29.660
tunneling?

52:30.340 --> 52:32.120
Okay, so the

52:32.120 --> 52:33.320
explanation I had

52:33.320 --> 52:36.560
before was for a

52:36.560 --> 52:37.580
full tunneling.

52:38.020 --> 52:38.840
So that means that

52:38.840 --> 52:40.200
no matter what you

52:40.200 --> 52:40.800
do, you know,

52:40.800 --> 52:41.800
let's say I'm

52:41.800 --> 52:42.920
tunneled into,

52:42.920 --> 52:43.720
you know,

52:44.240 --> 52:45.380
AOL.com because

52:45.380 --> 52:46.040
I work there for

52:46.040 --> 52:46.400
some reason,

52:46.940 --> 52:47.700
which I don't

52:47.700 --> 52:48.100
by the way.

52:48.180 --> 52:48.720
God help you.

52:49.500 --> 52:50.460
But let's, you

52:50.460 --> 52:51.360
know, I tunnel in

52:51.360 --> 52:52.860
there, then after I

52:52.860 --> 52:54.500
do that, all of my

52:54.500 --> 52:55.880
traffic, you know,

52:55.940 --> 52:56.720
will go through the

52:56.720 --> 52:57.480
corporate network.

52:57.740 --> 52:58.740
Now, I might be

52:58.740 --> 53:00.400
working at home and

53:00.400 --> 53:01.340
I want to, you

53:01.340 --> 53:01.920
know, check my

53:01.920 --> 53:03.300
email, but I'm

53:03.300 --> 53:04.620
also surfing child

53:04.620 --> 53:05.620
porn or whatever,

53:06.360 --> 53:07.500
you know, but all

53:07.500 --> 53:08.360
of that stuff will

53:08.360 --> 53:08.900
go through the

53:08.900 --> 53:09.580
corporate network.

53:09.580 --> 53:10.180
And if your

53:10.180 --> 53:10.800
corporate network

53:10.800 --> 53:11.940
has any type of

53:11.940 --> 53:13.160
monitors, then

53:13.160 --> 53:14.020
they'll see that.

53:14.220 --> 53:14.700
So, you know, make

53:14.700 --> 53:16.200
sure you're aware of

53:16.200 --> 53:17.220
what kind of tunneling

53:17.220 --> 53:17.880
is going on.

53:18.100 --> 53:18.620
When you're surfing

53:18.620 --> 53:19.440
for child porn.

53:19.560 --> 53:20.360
Let's just back it

53:20.360 --> 53:21.280
up to regular porn,

53:21.360 --> 53:21.700
can we?

53:22.420 --> 53:23.040
Oh, okay.

53:23.480 --> 53:24.680
I'm just saying for

53:24.680 --> 53:25.920
this sake of argument

53:25.920 --> 53:26.840
because I don't work

53:26.840 --> 53:27.300
at AOL.

53:27.480 --> 53:28.080
It was funny.

53:28.240 --> 53:28.600
I got you.

53:28.620 --> 53:28.800
But I'm saying

53:28.800 --> 53:29.460
this is all

53:29.460 --> 53:30.000
fetitious.

53:30.680 --> 53:31.640
Well, AOL and

53:31.640 --> 53:32.500
child porn go hand

53:32.500 --> 53:32.900
in hand.

53:33.000 --> 53:33.700
I think we all know

53:33.700 --> 53:34.540
that, but anyway.

53:37.420 --> 53:38.960
Okay, so the other

53:38.960 --> 53:40.140
thing is split

53:40.140 --> 53:40.720
tunneling.

53:41.040 --> 53:42.420
Now, for tunneling,

53:42.560 --> 53:43.940
what happens is,

53:44.300 --> 53:46.520
you know, if I'm at

53:46.520 --> 53:47.660
my house and I turn

53:47.660 --> 53:49.160
it on, all the

53:49.160 --> 53:51.120
traffic that goes to

53:51.120 --> 53:53.440
AOL subnets or,

53:53.440 --> 53:55.240
you know, AOL.com

53:55.240 --> 53:56.740
domain will be

53:56.740 --> 53:58.240
tunneled over through

53:58.240 --> 53:59.460
the connection, but

53:59.460 --> 54:00.700
everything else will

54:00.700 --> 54:02.200
go over my regular

54:02.200 --> 54:04.840
local network

54:04.840 --> 54:05.680
connection, whatever

54:05.680 --> 54:06.400
that may be.

54:06.920 --> 54:07.160
Right.

54:07.200 --> 54:08.760
Now, when you do

54:08.760 --> 54:10.180
that, like, that

54:10.180 --> 54:11.580
might sound better

54:11.580 --> 54:13.020
from, you know,

54:13.160 --> 54:14.520
whatever point of

54:14.520 --> 54:15.120
view that I was

54:15.120 --> 54:16.060
coming from with the

54:16.060 --> 54:17.300
porn and stuff and

54:17.300 --> 54:18.040
the check and work

54:18.040 --> 54:18.320
email.

54:18.780 --> 54:20.020
But keep in mind,

54:20.100 --> 54:20.960
when you do that,

54:21.200 --> 54:22.820
you're kind of gapping

54:22.820 --> 54:23.580
a bridge.

54:23.840 --> 54:24.860
Like, you're creating,

54:25.140 --> 54:26.380
your computer becomes a

54:26.380 --> 54:27.980
bridge from the

54:27.980 --> 54:30.100
outside internet and

54:30.100 --> 54:31.680
the inside secure

54:31.680 --> 54:33.060
corporate network.

54:33.060 --> 54:34.560
Well, that doesn't

54:34.560 --> 54:35.480
sound very secure.

54:35.760 --> 54:36.420
That sounds like a

54:36.420 --> 54:36.600
problem.

54:36.620 --> 54:38.260
So that's why a lot

54:38.260 --> 54:39.620
of places don't do

54:39.620 --> 54:39.940
that.

54:40.180 --> 54:40.740
Like, I mean, a lot

54:40.740 --> 54:41.880
of solutions don't

54:41.880 --> 54:43.040
allow you to do that

54:43.040 --> 54:44.620
because, you know,

54:44.680 --> 54:45.760
they're already in

54:45.760 --> 54:46.800
enough trouble as it

54:46.800 --> 54:48.660
is with people, you

54:48.660 --> 54:49.460
know, taking their

54:49.460 --> 54:50.880
laptops from work and

54:50.880 --> 54:52.520
going home and, like,

54:52.580 --> 54:53.940
browsing MySpace

54:53.940 --> 54:55.060
forever and getting

54:55.060 --> 54:56.200
malware and viruses

54:56.200 --> 54:57.280
installed and coming

54:57.280 --> 54:58.440
back to work and,

54:58.520 --> 54:59.240
like, nothing happened

54:59.240 --> 55:00.160
and then plugging into

55:00.160 --> 55:01.020
the corporate network.

55:01.960 --> 55:02.340
Right.

55:03.060 --> 55:04.920
Now, I'm sorry,

55:04.980 --> 55:05.180
go ahead.

55:05.920 --> 55:07.140
Yeah, but split, I

55:07.140 --> 55:08.220
mean, split tunneling

55:08.220 --> 55:10.120
does have its, you

55:10.120 --> 55:11.400
know, benefits, right?

55:11.600 --> 55:13.840
Now, if you can, you

55:13.840 --> 55:16.140
know, guarantee your

55:16.140 --> 55:17.640
boxes secure or somehow

55:17.640 --> 55:20.940
have separation of,

55:20.940 --> 55:22.500
you know, permissions,

55:22.660 --> 55:23.860
like, if for some

55:23.860 --> 55:25.480
reason your email client

55:25.480 --> 55:27.220
is jailed and, like,

55:27.240 --> 55:28.080
that's the only thing

55:28.080 --> 55:29.980
running that's using the

55:29.980 --> 55:31.060
split tunneling, then,

55:31.120 --> 55:31.980
like, yeah, whatever,

55:31.980 --> 55:32.500
thing, you know?

55:33.120 --> 55:33.880
Well, I mean,

55:33.960 --> 55:34.840
there are pros and

55:34.840 --> 55:35.800
cons to each, and you

55:35.800 --> 55:36.700
just need to understand

55:36.700 --> 55:37.580
them and decide what

55:37.580 --> 55:38.620
solution works for you.

55:38.840 --> 55:39.840
Yeah, and that comes

55:39.840 --> 55:40.640
back, and it's why I

55:40.640 --> 55:41.100
wanted to mention

55:41.100 --> 55:42.520
earlier about the IP

55:42.520 --> 55:44.160
authentication, because

55:44.160 --> 55:46.340
it has to know what

55:46.340 --> 55:47.300
you're trying to reach

55:47.300 --> 55:48.640
and what IP block it's

55:48.640 --> 55:49.920
in and what your

55:49.920 --> 55:51.980
virtual IP block is,

55:52.020 --> 55:52.860
and that's how it can

55:52.860 --> 55:53.700
know whether it's

55:53.700 --> 55:54.320
going to take you

55:54.320 --> 55:55.440
through the VPN tunnel

55:55.440 --> 55:56.980
or take you to the

55:56.980 --> 55:58.320
outside internet through

55:58.320 --> 55:59.440
your normal paths.

55:59.440 --> 56:01.700
Right, exactly.

56:02.240 --> 56:02.440
Now...

56:02.440 --> 56:03.460
Well, I mean, actually...

56:03.460 --> 56:04.100
Oh, sorry, go ahead.

56:04.260 --> 56:05.360
I was just going to

56:05.360 --> 56:05.760
throw out a couple

56:05.760 --> 56:06.600
questions, if I can.

56:06.700 --> 56:07.800
I don't want to stop

56:07.800 --> 56:09.060
you if you're...

56:09.060 --> 56:09.980
Like, for example...

56:09.980 --> 56:10.880
No, no, go for it.

56:10.900 --> 56:11.560
Yeah, all right, just

56:11.560 --> 56:13.300
to clarify, if I'm on a

56:13.300 --> 56:15.320
full tunneled VPN,

56:16.040 --> 56:17.060
every single thing that

56:17.060 --> 56:18.540
I browse, every...

56:18.540 --> 56:19.740
Not even browse, every

56:19.740 --> 56:20.680
single packet I send,

56:20.720 --> 56:22.400
if I check my personal

56:22.400 --> 56:23.860
POP3 mail account

56:23.860 --> 56:26.060
through something, I go

56:26.060 --> 56:27.240
browse some websites,

56:27.240 --> 56:29.440
I chat with somebody

56:29.440 --> 56:31.080
online, all of those

56:31.080 --> 56:32.160
packets in a full

56:32.160 --> 56:33.240
tunneling situation are

56:33.240 --> 56:34.120
all going to go through

56:34.120 --> 56:36.320
that VPN server,

56:36.760 --> 56:37.000
correct?

56:37.300 --> 56:38.720
Yes, that is correct.

56:39.200 --> 56:40.100
Now, they are

56:40.100 --> 56:41.200
encrypted, which is

56:41.200 --> 56:44.200
great, but are they...

56:44.200 --> 56:45.020
Well, actually, how

56:45.020 --> 56:45.280
about this?

56:45.340 --> 56:46.140
Let's play the

56:46.140 --> 56:47.120
conspiracy theory here.

56:47.420 --> 56:48.560
Can the administrator,

56:48.700 --> 56:49.320
the server of that

56:49.320 --> 56:50.540
VPN machine, can they

56:50.540 --> 56:51.640
see and track all of

56:51.640 --> 56:52.160
my traffic?

56:52.960 --> 56:54.580
Yes, unless you

56:54.580 --> 56:55.360
encrypt it.

56:55.360 --> 56:57.120
But, like, let's say

56:57.120 --> 56:57.920
you send an encrypted

56:57.920 --> 57:00.080
email via Gmail, then

57:00.080 --> 57:01.060
they won't be able to

57:01.060 --> 57:01.900
see that, because that's

57:01.900 --> 57:02.920
application layer

57:02.920 --> 57:03.540
encryption.

57:03.740 --> 57:04.160
Right, right, because

57:04.160 --> 57:05.820
if I PGP encrypt it,

57:05.860 --> 57:06.360
for example.

57:07.160 --> 57:08.580
Right, they'll see that

57:08.580 --> 57:10.420
you connected to Gmail,

57:10.780 --> 57:12.020
and you executed some

57:12.020 --> 57:13.520
command, and that you

57:13.520 --> 57:14.140
probably, you know,

57:14.140 --> 57:15.700
sent an email, but the

57:15.700 --> 57:16.820
contents of the email

57:16.820 --> 57:19.040
are encrypted, and you,

57:19.240 --> 57:20.340
you know, they won't be

57:20.340 --> 57:21.620
able to get that unless

57:21.620 --> 57:22.180
they have the key.

57:22.180 --> 57:23.080
All right, well, let's

57:23.080 --> 57:24.540
go a step further here

57:24.540 --> 57:25.460
and play what if.

57:26.040 --> 57:27.780
What if I had a second

57:27.780 --> 57:28.740
VPN server?

57:29.360 --> 57:30.440
Can I chain them

57:30.440 --> 57:32.540
together, and VPN into

57:32.540 --> 57:36.600
box A, then box A has a

57:36.600 --> 57:37.940
VPN connection set up to

57:37.940 --> 57:38.920
box B.

57:39.020 --> 57:39.940
Let's say that's up and

57:39.940 --> 57:40.660
running constantly.

57:41.060 --> 57:42.620
I connect to box A, which

57:42.620 --> 57:44.140
then connects to box B, and

57:44.140 --> 57:46.120
then box B is going to go

57:46.120 --> 57:47.440
out and do whatever traffic

57:47.440 --> 57:48.780
I want, receive it, send it

57:48.780 --> 57:49.940
back to box A, and then

57:49.940 --> 57:50.680
back to myself.

57:50.680 --> 57:52.780
A, is that possible, and

57:52.780 --> 57:53.940
B, are there any benefits

57:53.940 --> 57:55.100
or reasons to do that?

57:56.100 --> 57:59.160
Now, what, okay, so what

57:59.160 --> 58:02.480
is box B, like what

58:02.480 --> 58:03.420
networks are they in?

58:03.540 --> 58:04.740
Now, are you saying, like,

58:04.800 --> 58:06.860
your work is box B?

58:07.200 --> 58:08.480
Let, yeah, let's say box

58:08.480 --> 58:10.460
B is, um, all right, I'm

58:10.460 --> 58:11.220
going to make up a totally

58:11.220 --> 58:12.360
hypothetical situation.

58:12.460 --> 58:14.580
Let's say box B is, um,

58:15.020 --> 58:16.340
is, let's use AOL, for

58:16.340 --> 58:19.120
example, and AOL, that's

58:19.120 --> 58:20.140
their VPN box.

58:20.900 --> 58:23.120
Uh, box A is, let's say

58:23.120 --> 58:25.260
I'm a, um, security

58:25.260 --> 58:27.180
consulting firm, and I

58:27.180 --> 58:29.600
have a box that needs to

58:29.600 --> 58:31.080
access all of the AOL

58:31.080 --> 58:32.060
stuff so I can do my

58:32.060 --> 58:32.600
security work.

58:32.660 --> 58:33.660
That would be box A.

58:34.460 --> 58:36.680
And me, my, sitting at

58:36.680 --> 58:37.880
home with my laptop, I

58:37.880 --> 58:39.820
want to VPN to box A so

58:39.820 --> 58:40.480
that I can then

58:40.480 --> 58:41.800
subsequently get into box

58:41.800 --> 58:42.640
B. Let's say they don't

58:42.640 --> 58:43.700
want me or don't allow me

58:43.700 --> 58:44.880
to directly get into box

58:44.880 --> 58:46.360
B. Yep.

58:46.560 --> 58:47.600
Is that possible?

58:48.300 --> 58:50.520
And if so, is there any

58:50.520 --> 58:52.360
advantage or reason for

58:52.360 --> 58:52.880
doing that?

58:54.080 --> 58:55.300
Yeah, I mean, that is

58:55.300 --> 58:56.960
possible, and people do do

58:56.960 --> 58:59.280
that. Um, so what you're

58:59.280 --> 59:00.600
saying, right, is that you

59:00.600 --> 59:03.420
VPN into box A, right?

59:03.620 --> 59:03.860
Right.

59:03.860 --> 59:04.480
That's your consulting

59:04.480 --> 59:04.920
company.

59:05.060 --> 59:05.340
Right.

59:05.860 --> 59:07.880
And you, you know, like

59:07.880 --> 59:09.700
that, that kind of

59:09.700 --> 59:11.880
permission, like, contract,

59:11.880 --> 59:12.900
I guess you can say,

59:12.980 --> 59:14.800
between yourself and the

59:14.800 --> 59:16.740
company you work for is

59:16.740 --> 59:17.500
one thing.

59:18.280 --> 59:20.460
Now, box A, which is at

59:20.460 --> 59:21.420
your consulting company,

59:21.580 --> 59:23.660
box B, which is AOL.com,

59:23.700 --> 59:25.180
for example, they will

59:25.180 --> 59:27.840
have another thing set up.

59:27.960 --> 59:28.720
You know, they'll have

59:28.720 --> 59:30.300
another kind of, you know,

59:30.320 --> 59:30.960
if they're doing some

59:30.960 --> 59:32.220
project, they'll have their

59:32.220 --> 59:34.080
own permissions set up and

59:34.080 --> 59:36.440
everything, and that VPN,

59:37.020 --> 59:39.680
right, is a different set of,

59:39.860 --> 59:40.860
you know, I'm not getting

59:40.860 --> 59:41.740
the right word here, but

59:41.740 --> 59:43.320
that VPN is something

59:43.320 --> 59:45.160
completely different than,

59:45.280 --> 59:46.360
you know, the permissions

59:46.360 --> 59:48.100
that you have with, from

59:48.100 --> 59:49.680
you and your own company.

59:49.920 --> 59:50.140
Right.

59:50.200 --> 59:50.380
Right?

59:50.820 --> 59:51.920
So then what ends up

59:51.920 --> 59:53.820
happening is you tunnel

59:53.820 --> 59:58.020
your packet to box A, and

59:58.020 --> 01:00:00.740
then they rip off the

01:00:00.740 --> 01:00:02.580
headers, you know, that

01:00:02.580 --> 01:00:04.360
are, that went over the

01:00:04.360 --> 01:00:05.920
internet, and then that

01:00:05.920 --> 01:00:07.220
packet's floating around in

01:00:07.220 --> 01:00:08.960
the corporate network, and

01:00:08.960 --> 01:00:11.560
if it's destined to go to

01:00:11.560 --> 01:00:13.980
AOL.com and box B, that

01:00:13.980 --> 01:00:17.080
will be re-encapsulated, so

01:00:17.080 --> 01:00:18.480
it will be sent from the

01:00:18.480 --> 01:00:20.500
VPN link from your

01:00:20.500 --> 01:00:22.180
consulting company onto

01:00:22.180 --> 01:00:22.540
AOL.

01:00:22.800 --> 01:00:23.920
All right, that's, that's

01:00:23.920 --> 01:00:24.880
the word I wanted to hear.

01:00:25.180 --> 01:00:26.520
Does it get, and I'm on,

01:00:26.600 --> 01:00:27.400
this is an honest question,

01:00:27.440 --> 01:00:28.100
I really don't know the

01:00:28.100 --> 01:00:28.780
answer to this, does it

01:00:28.780 --> 01:00:30.640
get re-encapsulated, or

01:00:30.640 --> 01:00:33.380
does it get cumulatively

01:00:33.380 --> 01:00:34.840
encapsulated?

01:00:34.840 --> 01:00:36.280
Does it add that second

01:00:36.280 --> 01:00:37.420
layer of encryption to an

01:00:37.420 --> 01:00:38.780
already encrypted packet?

01:00:40.060 --> 01:00:41.140
No, so from the

01:00:41.140 --> 01:00:42.560
description that you gave

01:00:42.560 --> 01:00:44.560
me, it doesn't accumulate

01:00:44.560 --> 01:00:44.920
it.

01:00:45.300 --> 01:00:47.560
It decrypts it first, so

01:00:47.560 --> 01:00:48.600
you have your packet

01:00:48.600 --> 01:00:49.440
floating around.

01:00:49.500 --> 01:00:50.020
I see.

01:00:50.200 --> 01:00:51.060
In your corporate

01:00:51.060 --> 01:00:53.460
network, and then if, you

01:00:53.460 --> 01:00:54.740
know, at some point it

01:00:54.740 --> 01:00:55.920
needs to be encapsulated

01:00:55.920 --> 01:00:58.680
again, then it will go

01:00:58.680 --> 01:01:01.040
over again to, you know,

01:01:01.100 --> 01:01:02.460
because like, what you

01:01:02.460 --> 01:01:04.500
probably have is you'll

01:01:04.500 --> 01:01:06.080
have two gateways, one

01:01:06.080 --> 01:01:08.080
for authentication with

01:01:08.080 --> 01:01:10.140
your, you know, working

01:01:10.140 --> 01:01:11.880
from home people, and

01:01:11.880 --> 01:01:13.400
another gateway for

01:01:13.400 --> 01:01:14.360
AOL.com.

01:01:14.560 --> 01:01:16.400
Now, you can set it up

01:01:16.400 --> 01:01:17.740
so it does that.

01:01:18.140 --> 01:01:19.580
Now, if you do that,

01:01:19.700 --> 01:01:20.480
the routing will be a

01:01:20.480 --> 01:01:21.440
little more complicated,

01:01:21.640 --> 01:01:23.520
and I'm not sure if there

01:01:23.520 --> 01:01:25.300
is a legitimate use case

01:01:25.300 --> 01:01:26.960
for it, but you can do

01:01:26.960 --> 01:01:27.300
that.

01:01:27.640 --> 01:01:28.500
Well, I'm wondering if

01:01:28.500 --> 01:01:30.820
they're encrypted

01:01:30.820 --> 01:01:32.920
cumulatively, and I'm sure

01:01:32.920 --> 01:01:33.680
there's probably some

01:01:33.680 --> 01:01:34.720
business buzzword that I'm

01:01:34.720 --> 01:01:35.400
supposed to know that I

01:01:35.400 --> 01:01:38.100
don't, but if it re-encrypts.

01:01:38.220 --> 01:01:39.100
You're basically daisy

01:01:39.100 --> 01:01:41.780
chaining the proxies.

01:01:42.020 --> 01:01:42.900
And I'm thinking that by

01:01:42.900 --> 01:01:45.200
doing that, like the

01:01:45.200 --> 01:01:46.480
first packet that goes to

01:01:46.480 --> 01:01:49.060
my box, if it then gets

01:01:49.060 --> 01:01:50.420
encrypted again before it

01:01:50.420 --> 01:01:51.420
goes to the AOL box,

01:01:51.500 --> 01:01:52.640
maybe they would not see

01:01:52.640 --> 01:01:54.400
the original content.

01:01:54.540 --> 01:01:55.460
They would only see the

01:01:55.460 --> 01:01:56.820
secondary content because

01:01:56.820 --> 01:01:57.740
the first one is still

01:01:57.740 --> 01:01:58.860
encrypted, but you know

01:01:58.860 --> 01:01:59.020
what?

01:01:59.020 --> 01:01:59.940
I'm probably going a little

01:01:59.940 --> 01:02:01.060
bit into weird scenarios

01:02:01.060 --> 01:02:02.160
that would never happen in a

01:02:02.160 --> 01:02:03.120
real-world environment, so

01:02:03.120 --> 01:02:04.400
let's back up a little

01:02:04.400 --> 01:02:04.540
bit.

01:02:04.580 --> 01:02:05.340
There's one other thing I

01:02:05.340 --> 01:02:06.160
wanted to talk about with

01:02:06.160 --> 01:02:08.280
tunneling, if I may, that I

01:02:08.280 --> 01:02:09.880
think our listeners might be

01:02:09.880 --> 01:02:11.780
interested in, and it's

01:02:11.780 --> 01:02:12.820
something that more people

01:02:12.820 --> 01:02:15.100
might want to use, and it

01:02:15.100 --> 01:02:15.920
kind of goes back to our

01:02:15.920 --> 01:02:17.280
first example of the DNS

01:02:17.280 --> 01:02:20.200
tunneling, and that is SSH

01:02:20.200 --> 01:02:20.640
tunneling.

01:02:20.920 --> 01:02:21.780
Would this be an appropriate

01:02:21.780 --> 01:02:23.380
time to bring that up or

01:02:23.380 --> 01:02:24.060
talk about that?

01:02:24.800 --> 01:02:25.480
Okay, yeah.

01:02:25.620 --> 01:02:28.060
I mean, so SSH tunneling is

01:02:28.060 --> 01:02:31.380
an application level tunneling.

01:02:31.380 --> 01:02:34.060
Now, with, you know, even with

01:02:34.060 --> 01:02:37.580
VPN, you can VPN in layer

01:02:37.580 --> 01:02:40.600
two, and you can also VPN in

01:02:40.600 --> 01:02:42.020
from layer three.

01:02:42.660 --> 01:02:45.100
Now, for using buzzwords,

01:02:45.300 --> 01:02:48.680
right, VPNing in layer two is

01:02:48.680 --> 01:02:51.360
what they use IPSec for that.

01:02:51.600 --> 01:02:52.420
I'm sure you've heard of

01:02:52.420 --> 01:02:52.920
IPSec.

01:02:53.040 --> 01:02:53.540
Of course.

01:02:53.760 --> 01:02:55.480
I think the noise, I'm sorry.

01:02:56.340 --> 01:02:59.900
Layer hang in layer, yeah, okay,

01:02:59.900 --> 01:03:00.680
I'm fine.

01:03:01.080 --> 01:03:05.360
So, for IPSec, your IP address is

01:03:05.360 --> 01:03:06.580
actually encrypted.

01:03:07.940 --> 01:03:10.560
The actual, so this is the

01:03:10.560 --> 01:03:13.060
tunneling mode that we, you know,

01:03:13.100 --> 01:03:14.700
have been assuming the whole time.

01:03:15.100 --> 01:03:17.100
So, you know how you're going to

01:03:17.100 --> 01:03:19.280
end up having two IP headers,

01:03:19.400 --> 01:03:19.600
right?

01:03:19.860 --> 01:03:20.180
Right.

01:03:20.180 --> 01:03:24.240
So, the first one, when it goes

01:03:24.240 --> 01:03:26.300
from your box to the VPN gateway,

01:03:26.520 --> 01:03:27.680
that is unencrypted.

01:03:28.420 --> 01:03:28.580
It has to be.

01:03:28.580 --> 01:03:29.760
Because, I mean, that goes over

01:03:29.760 --> 01:03:31.660
the untrusted, you know,

01:03:31.740 --> 01:03:33.140
untrusted internet or whatever.

01:03:33.580 --> 01:03:33.880
Right.

01:03:33.880 --> 01:03:36.900
But your second layer, your second

01:03:36.900 --> 01:03:38.840
IP layer, that will be

01:03:38.840 --> 01:03:41.260
encrypted, and only the VPN gateway

01:03:41.260 --> 01:03:42.940
on the other side will be able to

01:03:42.940 --> 01:03:43.560
decrypt that.

01:03:43.560 --> 01:03:45.400
So, you know, people who are

01:03:45.400 --> 01:03:48.300
sniffing, you know, people who are

01:03:48.300 --> 01:03:50.520
sniffing are not going to be able

01:03:50.520 --> 01:03:53.140
to see any addresses from your

01:03:53.140 --> 01:03:54.940
corporate network, and, you know,

01:03:55.080 --> 01:03:56.920
potentially, like, services you have,

01:03:57.020 --> 01:03:59.720
et cetera, and open ports leaked out

01:03:59.720 --> 01:04:01.400
into the public internet.

01:04:01.740 --> 01:04:02.020
Right.

01:04:02.100 --> 01:04:03.660
It's not just the payload that's

01:04:03.660 --> 01:04:03.980
encrypted.

01:04:04.160 --> 01:04:06.220
It's the entire packet, IP address

01:04:06.220 --> 01:04:06.940
included.

01:04:07.280 --> 01:04:07.500
Right.

01:04:08.360 --> 01:04:09.780
Right, because, you know, because

01:04:09.780 --> 01:04:13.120
it's like, you have, you know,

01:04:13.180 --> 01:04:15.680
you're connecting to the VPN, and

01:04:15.680 --> 01:04:17.740
we mentioned the mechanism, you

01:04:17.740 --> 01:04:19.880
know, to actually get the packet

01:04:19.880 --> 01:04:22.040
over there, but we didn't really

01:04:22.040 --> 01:04:24.280
talk about, you know, the security

01:04:24.280 --> 01:04:26.540
part, and, you know, that part is

01:04:26.540 --> 01:04:27.920
pretty plain, because you just

01:04:27.920 --> 01:04:30.060
encrypt it, you know, with AEFs or

01:04:30.060 --> 01:04:33.040
whatever new fandangled encryption

01:04:33.040 --> 01:04:34.000
algorithm you have.

01:04:34.640 --> 01:04:34.820
Right.

01:04:34.840 --> 01:04:35.040
Okay?

01:04:35.380 --> 01:04:35.560
Yep.

01:04:35.560 --> 01:04:38.180
Now, the other thing is you can

01:04:38.180 --> 01:04:40.620
encrypt in a higher level, which is

01:04:40.620 --> 01:04:42.220
you can use SSL.

01:04:43.260 --> 01:04:45.840
Now, when you do that, only the

01:04:45.840 --> 01:04:48.400
actual data is encrypted.

01:04:49.520 --> 01:04:53.180
So, if I were sniffing your traffic

01:04:53.180 --> 01:04:55.560
and you were using an SSL encryption,

01:04:56.900 --> 01:04:59.800
then I would be able to see IP

01:04:59.800 --> 01:05:02.500
addresses that are in the corporate

01:05:02.500 --> 01:05:04.360
network and, like, what ports you're

01:05:04.360 --> 01:05:05.300
sending to and stuff.

01:05:05.560 --> 01:05:07.580
Right.

01:05:08.040 --> 01:05:10.060
So, that's more appropriate for

01:05:10.060 --> 01:05:13.340
web access type, when you just want

01:05:13.340 --> 01:05:15.300
the contents encrypted.

01:05:16.260 --> 01:05:16.580
Right.

01:05:17.440 --> 01:05:18.720
So, right.

01:05:18.860 --> 01:05:20.320
So, you know, that would be cool if

01:05:20.320 --> 01:05:21.820
you're, like, connecting to a web

01:05:21.820 --> 01:05:22.580
proxy or whatever.

01:05:23.040 --> 01:05:23.260
Right.

01:05:23.300 --> 01:05:25.040
Or, actually, what we were, started

01:05:25.040 --> 01:05:26.340
off the episode when I was talking

01:05:26.340 --> 01:05:27.240
about Yahoo Mail.

01:05:27.720 --> 01:05:28.020
Right.

01:05:28.020 --> 01:05:29.680
It goes through SSL to encrypt just

01:05:29.680 --> 01:05:32.040
the password when I log in to be

01:05:32.040 --> 01:05:33.440
protected so my password is not

01:05:33.440 --> 01:05:33.880
sniffed.

01:05:34.020 --> 01:05:35.600
But people can certainly still see

01:05:35.600 --> 01:05:37.760
from the rest of the packet

01:05:37.760 --> 01:05:39.340
information that I was going to

01:05:39.340 --> 01:05:41.640
mail.yahoo.com or whatever the

01:05:41.640 --> 01:05:42.520
server you're going to is.

01:05:42.580 --> 01:05:44.500
That's still in plain text that could

01:05:44.500 --> 01:05:45.580
be sniffed out of the air, but you

01:05:45.580 --> 01:05:46.940
could never get the actual password.

01:05:47.660 --> 01:05:48.020
Right.

01:05:48.420 --> 01:05:48.820
Exactly.

01:05:48.820 --> 01:05:50.580
So, it's a choice of how much

01:05:50.580 --> 01:05:52.020
security do you need.

01:05:52.900 --> 01:05:53.240
Right.

01:05:53.860 --> 01:05:56.500
So, now, the other thing, so you're

01:05:56.500 --> 01:05:58.240
asking about SSH tunneling, right?

01:05:58.280 --> 01:05:58.480
Right.

01:05:59.120 --> 01:06:02.060
And, I mean, people love that because

01:06:02.060 --> 01:06:03.000
it's easy.

01:06:03.340 --> 01:06:05.380
You know, everyone has SSH installed.

01:06:06.240 --> 01:06:08.980
And, you know, there's a, the person,

01:06:09.260 --> 01:06:10.620
you know, the group who develops it

01:06:10.620 --> 01:06:12.040
really made it very versatile.

01:06:12.760 --> 01:06:14.680
And, you know, it can do a lot of

01:06:14.680 --> 01:06:15.040
things.

01:06:15.040 --> 01:06:17.180
But keep in mind that when you do

01:06:17.180 --> 01:06:20.340
SSH tunneling, that is an application

01:06:20.340 --> 01:06:21.560
layer tunneling.

01:06:22.020 --> 01:06:24.760
So, that's not even at layer 3 or

01:06:24.760 --> 01:06:25.420
layer 4.

01:06:26.280 --> 01:06:28.740
Like, you're tunneling in, you know,

01:06:28.780 --> 01:06:30.660
the actual application layer.

01:06:30.800 --> 01:06:33.320
So, what happens is you set up a

01:06:33.320 --> 01:06:35.080
tunnel on, you know, the SSH.

01:06:35.140 --> 01:06:36.300
So, you know how, when I was talking

01:06:36.300 --> 01:06:38.240
about, you have, like, a virtual

01:06:38.240 --> 01:06:41.460
interface on your computer that you

01:06:41.460 --> 01:06:42.980
send all your packets to that you

01:06:42.980 --> 01:06:44.100
want to go over the VPN?

01:06:44.100 --> 01:06:46.660
And that virtual interface will, like,

01:06:47.000 --> 01:06:51.260
put on the headers for you for, like,

01:06:51.300 --> 01:06:52.400
your virtual identity.

01:06:52.640 --> 01:06:53.660
And then it'll encrypt it.

01:06:53.780 --> 01:06:56.900
And then that mesh will be put into,

01:06:57.160 --> 01:07:01.460
you know, the actual header of, like,

01:07:01.480 --> 01:07:03.700
your local network.

01:07:04.000 --> 01:07:04.360
Right.

01:07:04.740 --> 01:07:04.960
Right.

01:07:04.960 --> 01:07:07.840
So, that, okay, so now, for SSH

01:07:07.840 --> 01:07:11.560
tunneling, pretend that virtual interface

01:07:11.560 --> 01:07:15.000
that does the encrypting, the adding of

01:07:15.000 --> 01:07:18.020
the headers, imagine that is the entry

01:07:18.020 --> 01:07:20.000
point for your SSH application.

01:07:20.700 --> 01:07:24.580
So, when you do SSH tunneling, that is the

01:07:24.580 --> 01:07:26.800
functionality that SSH is providing for you.

01:07:26.800 --> 01:07:29.860
So, if, you know, I set, like, a forwarder

01:07:29.860 --> 01:07:33.280
for my SSH, like, let's say I set a local

01:07:33.280 --> 01:07:37.680
forward, and I, you know, SSH into some

01:07:37.680 --> 01:07:41.220
gateway, and if I set a local forward in the

01:07:41.220 --> 01:07:44.200
command options, then, you know, for, like,

01:07:44.240 --> 01:07:48.360
okay, local port, like, you know, 31337 is

01:07:48.360 --> 01:07:51.300
going to tunnel to, like, some other place.

01:07:51.300 --> 01:07:55.060
And what happens is when I send packets to

01:07:55.060 --> 01:07:58.540
that local port, it's going to instead go

01:07:58.540 --> 01:08:01.820
through SSH, and SSH is going to encrypt

01:08:01.820 --> 01:08:04.560
this for me, and now your, quote, quote,

01:08:04.620 --> 01:08:07.460
VPN gateway is going to be the SSH server

01:08:07.460 --> 01:08:08.600
on the other side.

01:08:09.580 --> 01:08:12.600
And whatever you're sending is going to go

01:08:12.600 --> 01:08:14.960
into the other side, and it's going to be

01:08:14.960 --> 01:08:19.540
shot out in the direction that you specified

01:08:19.540 --> 01:08:20.460
in your command line.

01:08:20.460 --> 01:08:23.280
So, if you said, tunnel all my connections

01:08:23.280 --> 01:08:26.260
and my packets from, you know, my, this

01:08:26.260 --> 01:08:29.560
local port on my machine to, like, port, you

01:08:29.560 --> 01:08:33.320
know, 80 on some remote machine, right,

01:08:33.560 --> 01:08:36.420
that the SSH server can access, then the

01:08:36.420 --> 01:08:39.420
SSH server on the other side is going to

01:08:39.420 --> 01:08:42.380
tack on the appropriate headers, so your

01:08:42.380 --> 01:08:44.620
packets will get routed to the correct

01:08:44.620 --> 01:08:45.400
place remotely.

01:08:45.960 --> 01:08:48.040
So, that's exactly what, you know, a VPN

01:08:48.040 --> 01:08:51.420
does in a, you know, logical, from a logical

01:08:51.420 --> 01:08:54.120
perspective, but it's at different layers, and it

01:08:54.120 --> 01:08:55.600
uses different encryption schemes.

01:08:56.400 --> 01:08:56.740
Right.

01:08:56.840 --> 01:08:59.800
Now, are there other schemes or other

01:08:59.800 --> 01:09:02.520
protocols besides IPsec and SSL?

01:09:03.700 --> 01:09:04.280
Right, yeah.

01:09:04.340 --> 01:09:05.980
So, I mean, there's a whole slew of them,

01:09:05.980 --> 01:09:09.520
because the thing is, you know, all you have to do is

01:09:09.520 --> 01:09:17.140
logically create a connection to the VPN gateway, and you need a mechanism to do the tunneling

01:09:17.140 --> 01:09:22.140
and, like, the encapsulation for you, and you need a mechanism to encrypt the packet that's

01:09:22.140 --> 01:09:22.760
your payload.

01:09:23.520 --> 01:09:29.660
Now, there are many, you know, ways to do this, and some of them are, like, PPTP, which is a point-to-point

01:09:29.660 --> 01:09:38.620
connection, and L2TP, which is a layer-2 tunneling protocol, and L3TP version 3, which is layer-3 tunneling,

01:09:39.020 --> 01:09:41.060
and MPLS, to name a few.

01:09:41.180 --> 01:09:46.540
But all of these is to, you know, establish, it's a tunneling protocol to establish connectivity

01:09:46.540 --> 01:09:49.240
between you and the VPN gateway, right?

01:09:49.480 --> 01:09:55.800
Because you need to have some sort of protocol that tells you, you know, how to, like, what kind of header

01:09:55.800 --> 01:10:03.220
to have to identify this packet that you're sending with, you know, what you used to encrypt it on the other end,

01:10:03.320 --> 01:10:08.660
and, like, what header order in the packet you expect to see and all that stuff.

01:10:10.080 --> 01:10:13.860
Now, you don't really have to worry about that if you're not going to be, like,

01:10:13.860 --> 01:10:16.360
develop rolling your own VPN implementation.

01:10:16.860 --> 01:10:22.700
If you're just going to use something, then you don't need to know, you know, how, like, you know,

01:10:22.720 --> 01:10:24.520
or which protocol it's using.

01:10:24.840 --> 01:10:29.780
But if you want to, like, you know, hack it or reverse engineer it, then you definitely need to know

01:10:29.780 --> 01:10:31.360
how that protocol operates.

01:10:31.860 --> 01:10:37.780
And, you know, if you are, you know, for example, right, if you're using IPsec or some L2 tunneling thing,

01:10:37.780 --> 01:10:45.040
then you're going to need to know that the IP address for the virtual network is not going to be exposed to you

01:10:45.040 --> 01:10:46.320
and all that stuff, right?

01:10:46.620 --> 01:10:46.840
Right.

01:10:48.140 --> 01:10:49.240
And that's all, yeah.

01:10:49.240 --> 01:10:55.640
So, I mean, one last thing that I want to throw out there is if you're using a VPN of any sort, you know,

01:10:55.640 --> 01:11:03.720
make sure your, you know, your security on your box is really good that you're SSH-ing into or, I mean,

01:11:03.840 --> 01:11:10.060
VPNing into because, I mean, your box is, like, on multiple networks at different times, right?

01:11:10.220 --> 01:11:10.460
Right.

01:11:10.540 --> 01:11:12.240
And, like, your box is pretty much a slut.

01:11:12.420 --> 01:11:17.720
So you have to protect it or else, you know, if you just go to, like, Starbucks or whatever

01:11:17.720 --> 01:11:22.420
and use the network there, you know, the security and the risk involved is much greater.

01:11:22.800 --> 01:11:27.760
And if you bring that stuff back into wherever your VPNing is, then, you know,

01:11:27.800 --> 01:11:30.280
you're screwing over everyone on that network.

01:11:30.740 --> 01:11:32.720
So you'll give your box a venereal disease?

01:11:32.800 --> 01:11:33.460
Is that what you're saying?

01:11:34.160 --> 01:11:34.480
Yeah.

01:11:34.560 --> 01:11:39.280
I mean, seriously, it's just like sex in a very boring way.

01:11:42.140 --> 01:11:42.540
Wow.

01:11:42.660 --> 01:11:45.780
That was a great way to end this segment there.

01:11:46.660 --> 01:11:47.420
Actually, you know what?

01:11:47.420 --> 01:11:52.120
I'm kind of looking over the notes here, and I actually – I want to go back to split tunneling.

01:11:52.320 --> 01:11:53.080
We've got a few minutes.

01:11:53.220 --> 01:11:54.820
I'll go back to split tunneling for a second.

01:11:55.780 --> 01:11:55.980
Okay.

01:11:56.420 --> 01:12:01.920
I think also – I think maybe another good example or a good application that might be worth mentioning.

01:12:02.820 --> 01:12:07.480
Again, split tunneling is when you're only traffic going to a certain IP range

01:12:07.480 --> 01:12:12.020
or a certain domain resolution, whatever you want to call it, is encrypted,

01:12:12.020 --> 01:12:16.360
but everything else to the rest of the global interweb that doesn't need to go to that domain

01:12:16.360 --> 01:12:18.980
is sent through whatever your standard is.

01:12:19.260 --> 01:12:19.780
Yeah.

01:12:19.780 --> 01:12:30.640
Now, isn't it, in fact, true that you may find yourself with the need to connect to a different IP-resolved address

01:12:30.640 --> 01:12:35.000
from the same computer at the same time securely?

01:12:35.000 --> 01:12:38.600
You mean, like, have two VPN connections?

01:12:38.720 --> 01:12:40.000
That's what I'm getting at, yes.

01:12:40.000 --> 01:12:48.300
So you can do that, and that does happen, but, like, most, if not all, of the VPN software out there

01:12:48.300 --> 01:12:54.600
doesn't allow you to do that out of the box because it's complicated,

01:12:54.900 --> 01:12:59.500
and your OS has to support, you know, that kind of tunneling.

01:12:59.640 --> 01:13:05.260
Okay, actually, so a good example is to tell you what I'm doing or what I want to set up at my house

01:13:05.260 --> 01:13:08.440
so you can get, you know, a better idea of what's involved.

01:13:09.320 --> 01:13:15.240
Now, I have, okay, so there are a couple ways to log into my work.

01:13:15.780 --> 01:13:22.440
One of them is I can SSH into some gateway they have, and then I can, you know, pipe everything through that.

01:13:22.440 --> 01:13:31.840
Now, that's a good, you know, that's a decent way to do it, but it's annoying because every single, you know,

01:13:31.880 --> 01:13:34.520
service I want to use, I have to tunnel it.

01:13:35.220 --> 01:13:39.980
So it's like if I want to use some web page, I have to create a local tunnel on SSH,

01:13:40.280 --> 01:13:46.400
and I have to, like, actually, you know, say in the command line, you know,

01:13:46.400 --> 01:13:48.680
whatever I send to a local port, do that.

01:13:48.920 --> 01:13:50.080
I have to set up the port.

01:13:50.080 --> 01:13:53.640
All right, so you're saying that, I think I might have interrupted you there.

01:13:53.680 --> 01:13:56.960
I think you were saying that it's kind of a pain because you have to tunnel,

01:13:57.300 --> 01:14:03.440
when you do the SSH tunneling, you have to specify every individual port that you want to tunnel,

01:14:03.520 --> 01:14:04.800
which is kind of a hassle, right?

01:14:05.600 --> 01:14:06.340
Right, right.

01:14:06.660 --> 01:14:11.300
So the other thing I can do is I can use the VPN client.

01:14:11.680 --> 01:14:17.780
Now, if I use the VPN client and, you know, it's a full tunnel client, so it's not split.

01:14:17.780 --> 01:14:24.060
So all of my traffic goes over, you know, the corporate network, and, you know,

01:14:24.120 --> 01:14:27.580
that's not good for reasons I previously mentioned.

01:14:28.180 --> 01:14:33.140
You know, so it's like if I want to, you know, play some music off my share from my computer,

01:14:33.220 --> 01:14:34.000
I can't do that.

01:14:34.800 --> 01:14:38.160
Now, what I want to do is to start split telling.

01:14:38.300 --> 01:14:40.640
Now, there's a lot of ways to do this, but this is what I'm going to do.

01:14:40.640 --> 01:14:46.440
Now, we can get a router, like a Dink, Elittle, Cisco, like 800 series router,

01:14:46.880 --> 01:14:50.820
and we can get that to set up as a full tunnel.

01:14:51.340 --> 01:14:58.740
So I plug that into the wall, and that router will create a VPN connection with my work.

01:14:59.460 --> 01:15:05.740
And then if I plug in my box into, you know, one of those hub connections,

01:15:06.160 --> 01:15:09.280
then I get a IP at work.

01:15:09.280 --> 01:15:11.080
So that's fine.

01:15:11.420 --> 01:15:17.980
But what I need to do to implement split tunneling is I have to tell my computer

01:15:17.980 --> 01:15:23.040
and all the computers on my network that if I am looking for, you know,

01:15:23.400 --> 01:15:28.960
a DNS like www.al.com, then to tunnel it to my work,

01:15:29.320 --> 01:15:30.560
because that's where I work, supposedly.

01:15:30.960 --> 01:15:31.220
Right.

01:15:31.220 --> 01:15:34.620
And if it's not, then just go out the regular Internet.

01:15:35.080 --> 01:15:41.260
But the problem is when you're doing that, you know, you can't say, like,

01:15:41.320 --> 01:15:43.920
make sure you do it for all the names.

01:15:43.920 --> 01:15:54.040
Like, you can't do aol.com because you have to, like, you have to pick a DNS to go to, first of all.

01:15:54.320 --> 01:16:00.500
Like, if you have a private AOL DNS and they have, like, interweb names,

01:16:00.760 --> 01:16:05.880
then you need to go through that one, like the AOL DNS.

01:16:05.880 --> 01:16:14.940
But if it's not, then you don't want to send all your DNS queries automatically to the private one, the AOL DNS.

01:16:15.560 --> 01:16:18.200
So you have to do it at the IP level.

01:16:18.340 --> 01:16:24.500
So what you're going to do is have to find out what subnets AOL has for their work, you know,

01:16:24.540 --> 01:16:27.280
people in your area or I guess in their whole corporate network.

01:16:27.280 --> 01:16:35.340
You know, once you find that out, you need to tell your computer if, you know, if either I,

01:16:35.520 --> 01:16:42.380
if I go to any of these IPs, then I need to go to this, or if not, go to the regular Internet.

01:16:42.800 --> 01:16:46.920
But the thing is, if you type in a web page, like I was saying before, you know,

01:16:46.960 --> 01:16:52.960
you do, like, some interweb thing for AOL, then you're not going to know where it is.

01:16:52.960 --> 01:17:00.800
So you should also run your own DNS server that's going to, you know, do the splitting for you.

01:17:00.900 --> 01:17:06.680
So that DNS server will have both public Internet domain names

01:17:06.680 --> 01:17:14.240
and also be able to resolve, you know, specific interweb AOL domain names for you.

01:17:14.600 --> 01:17:22.280
Now, so what I'm going to do is plug in my router that has a VPN connection into another router.

01:17:22.960 --> 01:17:23.600
Okay?

01:17:23.880 --> 01:17:27.480
So that router is, like, my normal access to the Internet.

01:17:27.900 --> 01:17:33.960
So when I plug that in, I can then have the router say, like, okay, for all your DNS queries,

01:17:34.260 --> 01:17:35.040
go to this guy.

01:17:35.120 --> 01:17:38.260
So I have to run my own DNS router, DNS server.

01:17:38.580 --> 01:17:42.000
Then once you get the IP address, sorry, give me one second.

01:17:42.120 --> 01:17:49.520
Once you get the IP address, then your router will decide which interface to go out of,

01:17:49.520 --> 01:17:51.100
the VPN one or the regular one.

01:17:51.100 --> 01:17:51.540
Right.

01:17:53.300 --> 01:17:55.620
And actually, I think that's even a little bit more detail.

01:17:55.740 --> 01:18:02.340
What I was thinking more along the lines of, let's go back to, remember my scenario of daisy chaining

01:18:02.340 --> 01:18:03.840
with machine A and machine B?

01:18:04.580 --> 01:18:04.960
Right.

01:18:04.960 --> 01:18:15.160
Let's say I'm that same consultant, and I work for a security company, machine A, and I also am being hired out to do pen testing

01:18:15.160 --> 01:18:18.400
or some kind of security work for AOL, box B.

01:18:19.160 --> 01:18:19.600
Yeah.

01:18:19.600 --> 01:18:26.500
It is entirely possible for me to VPN to box A, because maybe I need to get on there and download tools from my job

01:18:26.500 --> 01:18:29.640
or fill out some forms or whatever and need that secure access there.

01:18:30.240 --> 01:18:35.600
But I'm also working on the AOL network, doing some scanning or doing some whatever,

01:18:35.840 --> 01:18:39.000
and I need to be, have all that traffic also secured.

01:18:39.460 --> 01:18:43.980
I can have two different software clients running on my box.

01:18:43.980 --> 01:18:48.160
Now, I think you said earlier that most software clients will not support that easily.

01:18:49.440 --> 01:18:50.300
Yeah, that's right.

01:18:50.440 --> 01:18:58.900
But if you have two different software clients, for example, maybe I use a Cisco client to set up the VPN tunnel over to box A,

01:18:59.140 --> 01:19:04.660
but then I use the Microsoft VPN client to tunnel into box B.

01:19:04.660 --> 01:19:08.160
Is that a common scenario?

01:19:09.080 --> 01:19:09.840
No, you can't.

01:19:09.880 --> 01:19:18.080
Unfortunately, you can't do that, because if each VPN client is configured for full tunneling,

01:19:18.140 --> 01:19:22.800
then what they're going to do is, you know, I mean, they might do it in slightly different ways,

01:19:22.860 --> 01:19:26.260
but what they're going to do is configure their own virtual interface

01:19:26.260 --> 01:19:34.000
and then set that in your computer as the default gateway for your local box and make all traffic go to it.

01:19:34.000 --> 01:19:37.220
So if, let's say, you...

01:19:37.220 --> 01:19:38.900
So one's going to take charge of the other.

01:19:38.980 --> 01:19:40.120
One's going to override the other.

01:19:40.120 --> 01:19:40.940
Right, yeah.

01:19:41.020 --> 01:19:43.000
So one is going to just kick the other one down.

01:19:43.660 --> 01:19:48.200
Now, you could write some software yourself, or I don't know if there exists any,

01:19:48.500 --> 01:19:52.300
but you create the tunnels, but then in your box,

01:19:52.300 --> 01:20:01.220
you have to be able to decide which way to route your packets, depending on what IPs they are.

01:20:01.220 --> 01:20:07.260
So your box will have to be a router, and you have to turn on IP routing and make some rules and stuff.

01:20:07.260 --> 01:20:14.440
Yeah, and it seems like a shame that more software clients don't support that or allow that.

01:20:14.540 --> 01:20:18.260
I understand why, for reasons you've explained, but it's certainly not...

01:20:18.820 --> 01:20:20.700
Like you said, you could write your own thing to do it,

01:20:20.760 --> 01:20:23.680
but you would think they would write some support for that into some of these clients,

01:20:23.740 --> 01:20:28.100
because I honestly don't see that as an unreasonable or unrealistic scenario.

01:20:28.440 --> 01:20:31.940
The first one where it was daisy-channing, yeah, that's a little bit probably weird,

01:20:31.940 --> 01:20:36.560
but this one, I can see many valid reasons and applications for doing that,

01:20:36.600 --> 01:20:38.580
so I'm surprised more of them don't support that.

01:20:39.660 --> 01:20:46.000
Well, I think the number one reason why they don't do that is because when that happens,

01:20:46.200 --> 01:20:53.700
you're creating a rogue, like, connection point between two networks that you shouldn't be doing.

01:20:53.800 --> 01:20:55.720
Well, that's a very good point. Yeah, you're right.

01:20:55.720 --> 01:20:58.000
Right. So if one gets owned...

01:20:58.000 --> 01:20:58.200
Yeah.

01:20:58.380 --> 01:21:02.380
Yeah, so if I get owned through box B, suddenly box A is now vulnerable.

01:21:03.460 --> 01:21:03.860
Yeah.

01:21:04.100 --> 01:21:04.640
Yeah, that's an excellent point.

01:21:04.640 --> 01:21:06.800
So I think for that reason, that's why they don't do that.

01:21:06.920 --> 01:21:07.920
That's an excellent point.

01:21:08.800 --> 01:21:10.460
But you know what I'm going to try?

01:21:10.600 --> 01:21:12.380
Actually, I was thinking about this the other day,

01:21:12.660 --> 01:21:14.740
and I haven't tried it yet, but I'm going to see if this works.

01:21:14.740 --> 01:21:22.760
So I have a MacBook, and I run Windows XP on Parallels because I love Microsoft Office.

01:21:23.500 --> 01:21:30.800
And what I'm going to try is run the VPN client from inside the VM,

01:21:32.560 --> 01:21:39.380
and then maybe I think if I do that, the VM will be, you know,

01:21:39.380 --> 01:21:49.260
just, like, connected by a VPN into wherever and the host class can use the network natively.

01:21:50.020 --> 01:21:51.240
Yeah, that would be interesting.

01:21:51.560 --> 01:21:53.640
Make sure we bring that up on a later show.

01:21:53.680 --> 01:21:56.200
I'd like to know how that works out, how that comes out.

01:21:56.200 --> 01:22:00.040
I'm going to try that as soon as I install a VPN client on the SOS.

01:22:00.560 --> 01:22:01.040
Virtualization.

01:22:01.040 --> 01:22:04.400
That's what happens for these things, like VMware or Parallels.

01:22:04.820 --> 01:22:12.380
They have their own, like, virtual interfaces set up for, like, your network

01:22:12.380 --> 01:22:16.500
because what they have to do is you can do the bridge network thing,

01:22:16.500 --> 01:22:20.940
which is another application of tunneling where they have your packets

01:22:20.940 --> 01:22:28.340
and your guest OS that you're sending tunneled to the regular Internet via your host OS.

01:22:30.080 --> 01:22:30.600
Right?

01:22:30.600 --> 01:22:34.820
So if they have that virtual interface set up already,

01:22:35.200 --> 01:22:38.440
then the mechanism is there for both of them to play nicely.

01:22:39.240 --> 01:22:45.920
So if I send VPN traffic through that virtual VMware interface or whatever,

01:22:46.620 --> 01:22:51.400
then with the way they set it up, it shouldn't affect the host OS network connectivity at all.

01:22:51.600 --> 01:22:55.180
Right, because it's, well, they're individual independent stacks.

01:22:55.300 --> 01:22:57.580
They're two different unrelated things.

01:22:57.680 --> 01:22:58.120
But you know what?

01:22:58.140 --> 01:22:59.520
We're going to have to wrap up, I think.

01:22:59.520 --> 01:23:05.020
We've got a few minutes to wrap up, but is there anything else that you can think of

01:23:05.020 --> 01:23:08.240
that we should mention here before we wrap up?

01:23:08.240 --> 01:23:09.820
No, I mean, I think that was the last thing.

01:23:09.880 --> 01:23:11.920
I'm going to try that, and I'll get back to you.

01:23:12.040 --> 01:23:13.220
Yeah, I think that's interesting.

01:23:13.220 --> 01:23:29.900
Virtualization in general is something that a lot of people are starting to, I mean, originally, and I guess still the most popular application is for people who need to do a lot of testing or need to run a lot of several boxes on one machine or something like that.

01:23:29.900 --> 01:23:33.400
It's very much, I guess, I guess a business need for it, I guess.

01:23:33.400 --> 01:23:35.960
There's not many people using it on an individual level.

01:23:36.780 --> 01:23:44.020
It's very useful for software application programming, stuff like that, when you want to do multi-environment testing and stuff.

01:23:44.020 --> 01:23:55.520
But I think a lot of hackers are starting to realize the potential with this because each one of those, the way virtualization works is its own independent box, for lack of a better word, a virtual box.

01:23:55.520 --> 01:24:08.580
And it allows you to do so much testing on your own system, which is – we could go into a whole thing about virtualization.

01:24:08.680 --> 01:24:16.960
Maybe we should on an upcoming show, but I guess I'll just leave it at virtualization is very cool and something that I think people should really look into a lot.

01:24:16.960 --> 01:24:24.020
And I am going to put that on our to-do list to talk about an episode about that and some of the applications of it.

01:24:24.020 --> 01:24:29.720
I know Knott Theory swears by it now, and he uses it for almost everything, so maybe we'll get him on an episode to talk about it.

01:24:31.100 --> 01:24:33.760
But, yeah, for now, I think we're going to wrap it up.

01:24:33.860 --> 01:24:42.780
I think that was – I think this episode is going to be like a drinking game where every time we say the word packet, everybody in the IRC has to take a drink or something.

01:24:43.840 --> 01:24:44.360
For cuddling.

01:24:44.360 --> 01:24:51.840
Oh, yeah, every time we say packet, everybody has to take a shot or something because we – this was a very, very detail.

01:24:51.980 --> 01:24:58.640
I hope we did a good job of balancing explaining it in such a way that it made sense and not just a bunch of techno babble.

01:24:58.720 --> 01:25:00.140
I think we did a pretty good job.

01:25:00.220 --> 01:25:04.820
I think I – at least as a listener listening to you, I think I was able to follow most of that.

01:25:04.920 --> 01:25:07.520
So hopefully it comes across that well in the show.

01:25:08.400 --> 01:25:11.680
Let's do some shouts this week, and I'll go ahead and start.

01:25:11.680 --> 01:25:15.420
I'll go ahead and give a shout-out to Romania because we got that email earlier.

01:25:15.780 --> 01:25:18.440
The entire country of Romania gets my shout-outs this week.

01:25:18.960 --> 01:25:25.380
And to my good friend MC Frontalot, he just sent me some lyrics to a new upcoming song of his he's going to be releasing.

01:25:25.740 --> 01:25:32.460
I don't know how soon, but that is surprisingly – I wish it was released because it would have been a great closing music this week.

01:25:32.500 --> 01:25:33.880
It's very appropriate for this topic.

01:25:33.880 --> 01:25:38.160
So shouts out to the front one, the frontingest one.

01:25:38.820 --> 01:25:40.140
And what do you got for us this week?

01:25:41.100 --> 01:25:44.160
I just want to give a shout-out to my new buddy, Venom.

01:25:44.820 --> 01:25:54.200
And also, if you have any questions or comments on anything you heard tonight, you can email me directly at verbal at binrev.com.

01:25:54.200 --> 01:26:00.440
Or you can email us at radio at binrev.com, which is the main address for feedback for the show.

01:26:00.800 --> 01:26:04.380
Our site of the week is – well, actually, let's see.

01:26:04.420 --> 01:26:07.820
We had a site of the week in the first episode, so maybe I should not do it.

01:26:07.820 --> 01:26:09.320
Now, I'm going to give you two sites this week.

01:26:09.380 --> 01:26:13.580
The second site of the week is powerlabs.org.

01:26:13.580 --> 01:26:17.460
That's P-O-W-E-R-L-A-B-S.org.

01:26:17.580 --> 01:26:25.540
It's some cool hardware hacking type projects and focusing specifically on how to power them and things like that.

01:26:25.580 --> 01:26:31.840
So if you're into hardware hacking, not totally computer-related stuff, but just some hardware hacking in general,

01:26:31.980 --> 01:26:37.220
building your own devices, building your own things, that's a pretty cool site to check out.

01:26:37.680 --> 01:26:42.160
The closing music that we are going to use this week is from MC Chris.

01:26:42.160 --> 01:26:44.800
I don't think I've ever used this one before.

01:26:44.940 --> 01:26:47.180
It's called FTW for the win.

01:26:47.680 --> 01:26:49.280
MC Chris, we're going to close it out.

01:26:49.420 --> 01:26:52.720
And verbal, thank you for being on the show again this week.

01:26:52.780 --> 01:26:53.280
No problem.

01:26:53.640 --> 01:26:56.340
And we will tell everybody that we will see him next week.

01:26:56.560 --> 01:26:57.940
Same hack time.

01:26:58.760 --> 01:27:00.040
Same hack channel.

01:27:00.660 --> 01:27:01.140
Biatch.

01:27:03.160 --> 01:27:10.020
Tonight at the Alamo Dome, he gets happy-go-jacky on the big white guy like a donkey eating a waffle.

01:27:10.020 --> 01:27:12.960
Sweet Sassy Molassi.

01:27:13.040 --> 01:27:17.520
Get out the checkbook and pay Bram off with a rubdown as the Spurs beat the Heat.

01:27:17.700 --> 01:27:18.680
86-79.

01:27:19.160 --> 01:27:19.440
Stewart.

01:27:19.500 --> 01:27:20.200
And see the name.

01:27:20.320 --> 01:27:21.080
My kick is a cray.

01:27:21.260 --> 01:27:22.100
Display wide range.

01:27:22.160 --> 01:27:23.000
Shit for them heads.

01:27:23.100 --> 01:27:23.940
You tell it like planes.

01:27:24.020 --> 01:27:24.840
I'm Hanna to Lame.

01:27:24.940 --> 01:27:25.740
Chemical craze.

01:27:25.800 --> 01:27:26.620
I'm from Hunter Fades.

01:27:26.700 --> 01:27:27.620
Around the four days.

01:27:27.780 --> 01:27:28.480
Rockers, they play.

01:27:28.720 --> 01:27:30.300
Eat free those names whenever I'm played.

01:27:30.380 --> 01:27:32.180
My soul's on fire, so call me in the cage.

01:27:32.360 --> 01:27:33.820
Dressing all back, so please call me Christine.

01:27:34.160 --> 01:27:35.860
On it again, put others in shame.

01:27:36.080 --> 01:27:36.820
Here I am.

01:27:36.820 --> 01:27:38.640
I'm tired of like claiming a waffle of lanes.

01:27:38.820 --> 01:27:39.520
I'm Mr. Ducky.

01:27:39.740 --> 01:27:41.420
Lucky enough cause you cause wanna fuck me.

01:27:41.580 --> 01:27:42.400
I'm out of jock.

01:27:42.540 --> 01:27:43.300
You know, like sports.

01:27:43.460 --> 01:27:44.240
I want to cry.

01:27:44.400 --> 01:27:45.160
Just got divorced.

01:27:45.300 --> 01:27:46.960
Like a drink beer and chill with my friends.

01:27:47.020 --> 01:27:48.820
They turn and see me cause it's for the win.

01:27:48.920 --> 01:27:49.280
Win!

01:27:49.420 --> 01:27:49.760
Win!

01:27:49.900 --> 01:27:50.240
Win!

01:27:50.340 --> 01:27:52.140
And you cringe.

01:27:53.000 --> 01:27:55.920
And you cringe for the win.

01:27:56.680 --> 01:27:59.600
And you cringe for the win.

01:28:00.380 --> 01:28:01.940
And you cringe for the win.

01:28:01.940 --> 01:28:03.640
Dope and tease and disbelief.

01:28:03.640 --> 01:28:05.440
MC, Rom, John, flip the beat.

01:28:05.560 --> 01:28:07.260
Flip the bell, we fail the seat.

01:28:07.460 --> 01:28:09.100
Kick us out, we fail the street.

01:28:09.300 --> 01:28:10.920
Mike, magician, check the scene.

01:28:10.980 --> 01:28:12.560
Don't take my dick, my masterpiece.

01:28:12.960 --> 01:28:14.560
No, I feel the fast relief.

01:28:14.880 --> 01:28:16.500
MC's there for magic heat.

01:28:16.660 --> 01:28:18.240
Hit the beat for water, make the beat.

01:28:18.460 --> 01:28:19.960
Why they inhale out of histamine.

01:28:20.140 --> 01:28:21.900
Now, please fuck a slip of the crystal key.

01:28:21.980 --> 01:28:23.720
Then try to be me, it's all kind of a treat.

01:28:23.920 --> 01:28:25.660
Feel a fatigue, you're getting started.

01:28:25.800 --> 01:28:27.580
Shit, the addiction, we're gonna get caught in.

01:28:27.580 --> 01:28:29.280
Living this life till I'm nearly departing.

01:28:29.280 --> 01:28:31.320
Now, when I win up, somebody fought it.

01:28:31.320 --> 01:28:34.440
And you cringe.

01:28:35.140 --> 01:28:37.240
And you cringe for the win.

01:28:38.780 --> 01:28:41.420
And you cringe for the win.

01:28:42.480 --> 01:28:44.380
And you cringe for the win.

01:28:46.520 --> 01:28:48.800
John Stockton says, hey, look at me.

01:28:48.840 --> 01:28:49.900
I'm a little teapot.

01:28:49.960 --> 01:28:51.140
I'll go right up your dress.

01:28:52.320 --> 01:28:55.780
But then Alden Pollenese says, I'm not going to pay a lot for this muffler.

01:28:55.780 --> 01:28:58.780
But then Karl Malone says, sweet sassy molassie.

01:28:58.960 --> 01:29:00.220
You are going to pay a lot.

01:29:00.220 --> 01:29:02.800
And the cost is going to be prohibitive.

01:29:03.020 --> 01:29:05.200
Jazz win, $99.93.

01:29:05.620 --> 01:29:07.080
Sweet sassy molassie.

01:29:07.220 --> 01:29:07.500
Yeah.

01:29:08.640 --> 01:29:10.540
If you like it, don't steal it.

