[00:00.580 --> 00:02.600] We'll have all the electronics functioning. [00:03.540 --> 00:05.060] Thanks for your patience, everyone. [00:06.160 --> 00:08.960] This next panel, as you can see, is steganography. [00:09.840 --> 00:12.180] The man standing to my right is Peter Wehner. [00:12.340 --> 00:17.980] He is author of the book Translucent Databases and Disappearing Cryptography. [00:19.560 --> 00:24.700] Both books you can get as a special deal if you come see him after his discussion. [00:24.880 --> 00:29.900] He's got a flyer to give you, but you can also check those out on Amazon.com. [00:30.800 --> 00:33.860] He's been very patient as we figure out how light works. [00:34.240 --> 00:36.260] Without further, Peter Wehner. [00:42.960 --> 00:43.560] Thank you. [00:43.740 --> 00:51.120] And, you know, if you ever really figure out how light works, that'll be a real discovery because I think it's a lot more confusing than the physicists even understand. [00:52.500 --> 01:01.960] And what I want to do is actually confuse you some more today because, you know, the more and more I've investigated steganography and really thought about these things, the more and more confused I've become. [01:03.140 --> 01:11.820] I think a long time ago when I was trying to decide what to major in, I ended up majoring in math and I thought I was, when I was, you know, what my parents were buying was something that was very real. [01:11.980 --> 01:15.500] They were buying concrete theories, concrete theorems and things that were true. [01:15.620 --> 01:17.120] You know, we weren't dealing with deconstruction. [01:17.120 --> 01:20.280] We weren't dealing with, you know, abstract philosophical thoughts. [01:20.440 --> 01:24.160] We weren't dealing with, you know, things that may be relatively true or relatively false. [01:24.160 --> 01:30.100] You know, I thought my parents were buying me something that was, you know, solid and rock, you know, rock solid and sure. [01:30.360 --> 01:41.800] And, you know, the more I've started dealing with numbers and dealing with steganography, I really think it's the science of trying to... of deconstructing numbers, if you will, or trying to break apart everything. [01:41.800 --> 01:44.460] And you begin to really wonder what is zero and what is one. [01:45.500 --> 01:47.580] So I want to start off with... [01:50.860 --> 01:54.160] This is a promotional still from the movie A Beautiful Mind. [01:54.320 --> 01:55.400] I don't know how many of you have seen it. [01:56.660 --> 02:00.520] When I was watching the movie, it really kind of flipped me out. [02:00.960 --> 02:09.300] Because the whole conceit is this guy is a really brilliant mathematician, and then he starts to go gradually insane. [02:09.560 --> 02:18.700] And the way that his colleagues understand that he's lost it is that they go in his office and he's built this huge matrix of documents. [02:18.940 --> 02:29.140] And he's frantically looking in Life Magazine and newspapers and everything else that's out there, looking for hidden messages that Russians may be sending their spies in America. [02:29.600 --> 02:36.560] And, you know, the filmmaker, who I think did a very good job with the film, needed something to somehow capture that this guy is totally nuts. [02:37.000 --> 02:43.100] And, you know, the way they do it is that the guy is hiding hidden messages in pictures and images and things like that. [02:43.100 --> 02:46.220] And I'm reading, I'm watching this, and I'm thinking, you know, am I nuts? [02:48.120 --> 02:51.560] You know, does this, do all these algorithms work? [02:51.720 --> 02:55.820] You know, what have I spent these last five years working on and trying to understand? [02:56.400 --> 02:58.080] And, you know, it threw me for a loop. [02:58.100 --> 03:00.980] And the more I began to deal with it, the more confused I started to get. [03:01.660 --> 03:08.360] But I do think what I'm about to show you and some of the techniques I'm going to run through and some of the ideas I'm going to show you are very solid. [03:08.360 --> 03:10.160] They've got mathematical basis. [03:10.500 --> 03:11.140] You know, they work. [03:11.820 --> 03:16.000] And, you know, the big question we have right now is, how do we politically deal with them? [03:16.260 --> 03:18.840] And how do we make decisions about where they go? [03:19.040 --> 03:20.100] Who gets to use them? [03:20.360 --> 03:23.660] And, you know, what place they have in society? [03:29.080 --> 03:30.380] Okay, so this is the book. [03:37.440 --> 03:40.900] Okay, so, you know, what really is stegnography? [03:42.060 --> 03:52.300] To a large extent, the whole reason I wrote that book, Disappearing Cryptography in the first place, is because I was doing some research on it and I said, you know, I talked to Bruce Schneier and I said, you know, you should put a whole chapter on this. [03:52.340 --> 03:53.140] This is really interesting. [03:53.240 --> 03:53.820] This is fascinating. [03:53.980 --> 03:55.680] He said, well, you know, it's not really cryptography. [03:56.300 --> 04:01.100] And, you know, we got an argument and so then it became my job to go off and write a book about it. [04:03.360 --> 04:06.020] And I think it's a really difficult question, what is stegnography? [04:06.140 --> 04:08.900] And in the most general sense, it's kind of a hidden message that can't be... [04:08.900 --> 04:10.580] You know, there's four different classes here. [04:10.760 --> 04:12.960] You know, a hidden message that can't be found by humans. [04:13.300 --> 04:16.040] You know, it's a hidden message that can't be found by some kind of computer. [04:16.620 --> 04:20.660] You know, or it might be a hidden message that can be found by the computer, but not found by the humans. [04:20.760 --> 04:23.160] And we've got some people who are working on algorithms like that. [04:23.160 --> 04:27.000] Or, you know, you have a hidden message that can be found by some algorithms and not for others. [04:27.280 --> 04:41.040] And I don't know how much you guys know about math and philosophy and books like Godel, Escher, Bach, but you really quickly become, you know, you start running into the boundaries of logical systems and the ability of our minds to deal with, you know, [04:41.140 --> 04:48.340] things that work when you try to define, you know, stuff that can be understood by one algorithm but not understood by another algorithm. [04:51.040 --> 04:57.200] So, I think steganography is just about camouflaging information and making it look like something else. [05:04.000 --> 05:10.320] Now, like I said, you know, whenever we try to define what hidden is, we start running into problems. [05:10.520 --> 05:23.800] Obviously, all of the notions of the Turing machine proofs, the Godel, Escher, Bach results, all of those different logical investigations have shown us that we can't really do a great job of defining what hidden is. [05:24.560 --> 05:28.480] And there's also a parallel problem kind of in the human space, in the meat space. [05:29.100 --> 05:41.560] One friend of mine was telling me, he said, you know, he's trying to work on these watermarks for Hollywood and he wants to make the watermarks that will, you know, put a little secret message in there that says, do not copy, this is a copyrighted material owned by whatever, [05:41.740 --> 05:43.200] and they put these little sounds... [05:43.200 --> 05:52.000] He's working particularly in music and he said the big problem he has is that the band Pink Floyd is so particular, they can hear practically every little change he makes to the files. [05:52.460 --> 05:55.460] And, you know, they come in and they have, like, these very particular needs. [05:55.660 --> 05:58.440] They say, we want to use this recording machine by this company. [05:58.700 --> 06:01.840] And, you know, the companies just don't want to disturb the artists. [06:02.080 --> 06:06.600] And there... it turns out that there's just a wide range of human perception. [06:06.820 --> 06:11.660] Some of us hear things, some of us have dog-like hearing abilities, and then the rest of us are somehow deaf. [06:13.680 --> 06:17.840] And defining these things, at least in a scientific method, is practically impossible. [06:18.300 --> 06:21.640] I know in Hollywood, who's been trying to do it, they come up with this notion of human... [06:21.640 --> 06:24.080] They have these people who have so-called golden ears. [06:24.400 --> 06:31.060] And, you know, they'll listen to the tapes, and if they hear it, they'll veto it, or... and if they don't hear it, they'll say, oh, this might be a good system. [06:32.240 --> 06:34.380] How... how we get beyond that, I don't know anyway. [06:37.240 --> 06:43.880] And the bigger problem also is... we'll get to this toward the end of the talk, is how steganography begins to break down. [06:44.420 --> 06:54.880] Some of the algorithms leave these kind of things, these statistical messages, these statistical profiles, these kind of little ripples or waves in the statistical characteristics of the file. [06:55.140 --> 06:59.400] And some people are able to tune into that, and they're able to use algorithms and detect it. [06:59.460 --> 07:10.480] I think... if you saw earlier this week, there was an article on the cover of USA Today, and people were wondering, you know, how... they were saying, you know, we have this big problem, the Al-Qaeda terrorists are putting messages on eBay. [07:11.580 --> 07:12.680] How do we know this? [07:12.860 --> 07:23.620] Well, there are some people who work for the Department of Defense, and there are some people who are academics, and what they'll do is they write these programs that look at the statistical characteristics of the files. [07:23.760 --> 07:26.240] They look at, you know, how much red, green, and blue there is. [07:26.540 --> 07:36.800] And they went out and they... they apparently look at a lot of the different eBay pictures, and, you know, perhaps have found some evidence that the statistics have gotten a little bit different over time. [07:36.800 --> 07:40.100] And they think that perhaps these may be a steganographic message. [07:41.060 --> 07:45.520] It's certainly a job that's a lot like looking for a needle in the haystack, but there are people out there who are doing it. [07:45.920 --> 07:49.140] So, you know, we don't really understand what steganography is. [07:49.180 --> 07:51.420] We don't really understand what the limits of steganography are. [07:51.620 --> 07:56.880] But, you know, we begin to realize that there are certain things where it works, and sometimes it doesn't work. [07:56.960 --> 07:59.700] And they're like the human ears that break, and they're these statistical problems. [08:06.440 --> 08:09.480] Okay, and now we want to jump over to the political space. [08:10.180 --> 08:13.060] The question is, who really wants to use steganography? [08:13.200 --> 08:19.180] And I think this is part of important... this is important because a lot of people are wondering in Washington, you know, should we pass laws about this? [08:19.280 --> 08:19.880] You know, what do we do? [08:19.980 --> 08:25.360] And I've actually given some briefings to people down there, and they want to know, how can we regulate this, and how can we do something? [08:26.660 --> 08:28.940] Those people are concerned about evildoers using it. [08:28.940 --> 08:32.780] And I mentioned, you know, the front cover of USA Today says that Al-Qaeda... [08:32.780 --> 08:40.520] They quote these anonymous official sources saying Al-Qaeda terrorists are using the steganography. [08:41.340 --> 08:43.620] So we know that perhaps evildoers are doing it. [08:44.600 --> 08:47.280] Now, of course, there are perhaps good doers. [08:47.340 --> 08:48.840] And since we're in the U.S., that means U.S. [08:48.940 --> 08:49.220] forces. [08:50.280 --> 08:56.300] And so, if good guys can use steganography just as well as bad guys, then presumably the U.S. [08:56.400 --> 08:57.260] has spies out there. [08:57.260 --> 09:01.300] And presumably maybe they're tuning into eBay every day and getting their instructions that way. [09:01.780 --> 09:03.620] I don't know, but, you know... [09:09.200 --> 09:10.520] Well, right, I said since... [09:13.740 --> 09:18.260] Right, well, you know, I just said since we're in the U.S., we, you know, we can polarize things this way. [09:19.940 --> 09:23.280] And, you know, aside from that, there are also other people like copyright owners. [09:23.520 --> 09:24.780] I own a few copyrights. [09:24.800 --> 09:28.280] I don't know whether I would go to the extremes that Hollywood wants to go to. [09:28.580 --> 09:30.760] But they're definitely into steganography. [09:30.760 --> 09:33.180] They want to be able to put these little hidden messages everywhere. [09:33.920 --> 09:36.160] They want to be able to track stuff. [09:36.320 --> 09:47.940] And they're hoping that maybe steganography will give them a way to control the Napsterization and find an ideal way to, you know, as they say, maximize the revenue and monetize all of the passion people have for art. [09:49.600 --> 10:02.660] And the last one, I think, is the one that doesn't get enough press and isn't as interesting to people, but I think is very important and is probably what steganography is going to be remembered for in 10, 20 years from now. [10:02.660 --> 10:05.680] And that is software developers are a lot of people who use this. [10:05.800 --> 10:07.520] And they may not even realize they're doing it. [10:07.800 --> 10:12.040] You know, a lot of times when I was programming, I'd realize, you know, hey, I've got to set another bit somewhere. [10:12.220 --> 10:15.900] I've got to, you know, my data structure needs to grow for version 2.0. [10:16.000 --> 10:17.540] And I need to put a little bit someplace. [10:17.720 --> 10:21.560] And, oh, here's a neat little place I can stick it in the data structure and no one's going to notice. [10:21.580 --> 10:23.200] And it's still going to be backwardly compatible. [10:24.080 --> 10:36.880] So I would like to suggest that every programmer who's out there who's kind of tacking on extra data into their data files and finding hidden places to put it that doesn't disturb their previous versions are steganographers. [10:37.260 --> 10:40.740] And I think this is, you know, something that's saving us from bit rot. [10:40.880 --> 10:45.420] It's keeping computers running and it allows us to, you know, make real progress in the software world. [10:45.960 --> 10:48.460] So, you know, I think that's a very legitimate use for it. [10:55.420 --> 10:57.560] Okay, now I'm going to start to get a little more technical. [10:58.720 --> 11:09.640] And, you know, like I said before, that we don't really understand what steganography is, but we have some models and some schemes that work and have, you know, that manage to do what they're supposed to do. [11:10.480 --> 11:13.200] And so here are a few of them that I think are notable. [11:13.720 --> 11:22.180] The first one is, you know, every time you find a random number generator in a program, you can just replace that random number generator with your message that you're trying to send out. [11:23.060 --> 11:33.440] One guy I know is really hot on the idea that every TCP IP packet, you know, or communication starts off with a random number just to prevent collisions and misidentification. [11:33.660 --> 11:35.640] And he says, why should you stick a random number in there? [11:35.720 --> 11:39.880] You should start putting in your own message and that way it'll just go, it'll sail right through the system. [11:40.240 --> 11:50.160] Most of the software that bugs your... that people are using to bug the Internet strips all that information away because they think of it as just random noise that should be thrown away. [11:50.340 --> 11:54.300] You know, if we're going to be tracking the Internet users, we want to know what GIF files they're looking at. [11:54.360 --> 11:55.280] We want to know the HTML. [11:55.900 --> 11:57.380] This will sail right past that. [11:57.480 --> 11:58.560] People won't even understand it. [11:59.020 --> 12:01.480] And, you know, people at the other end will be able to strip it away. [12:01.940 --> 12:05.360] So, I mean, that's just one place where people are using random numbers. [12:05.600 --> 12:11.200] And why should you be wasting that bandwidth on just randomness when you could be sending information to someone else? [12:13.380 --> 12:19.040] In a slight corollary to that, there's the replacing every... replacing noise with your message. [12:19.520 --> 12:24.860] So, what I'm going to show you in a few minutes are kind of the way... some of the images that people use. [12:24.860 --> 12:29.440] And what people do is they often want to replace the least significant bit in a number. [12:29.720 --> 12:40.640] So, you know, if every pixel on an image is recorded as a number between 0 and 255, they may, you know, one byte of data, they may just flip the least significant bit. [12:40.760 --> 12:42.340] And it's only going to change by one unit. [12:42.580 --> 12:46.700] It's going to be a small change and it's going to be a change that's in the noise and you're not going to notice it. [12:46.940 --> 12:52.460] But it's still, you know, it can be one eighth of the entire file that you can just commandeer for yourself. [12:57.160 --> 13:07.020] A bunch of other people who are into watermarking say that you should avoid the noise because the noise is going to be attacked by compression algorithms and stripped away and you can't reliably hold that for your own. [13:07.240 --> 13:10.780] And they say what you should be doing is tweaking the position of the salient features. [13:11.000 --> 13:29.900] And that's kind of academic vision speak for, you know, going out, finding the big visual things in the image or the big crescendos in the music and moving them, say, a microsecond sooner or moving them a pixel to the left or tweaking things that the eye has to see and you know will not be damaged by compression functions. [13:30.380 --> 13:35.080] So, I mean, that's another solution. [13:35.360 --> 13:39.940] You can see that compression is starting to appear on this slide a couple times. [13:40.120 --> 13:53.800] Compression is really one of the big problems and one of the, I think, sources or solutions for, or one of the great inspirations for steganography. [13:53.800 --> 14:03.940] I think it's a parallel art and in this case, you're looking for structure and you want to strip away all the noise and in steganography, you want to look for structure and you want to insert your own image or your own data. [14:05.280 --> 14:12.280] So, compression... One of the, one of the nice solutions I've seen for using steganography is to run a compression algorithm in reverse. [14:12.520 --> 14:19.720] Because what a compression algorithm really does is it finds the structure in a file and saves that structure And it somehow understands the space. [14:19.900 --> 14:22.540] So if it's an image file, it understands how people construct images. [14:22.680 --> 14:26.540] If it's a text file, it understands the statistics of text and how people do that. [14:26.700 --> 14:37.660] If you run that in reverse and you put the data in there, it's going to pop out and you will be able to... maybe you'll be able to capture some of the knowledge that's built into the compression function to run things. [14:37.720 --> 14:39.140] And I'll show you an example of that later. [14:41.380 --> 14:49.800] One of my all-time favorite now, and this is one of the newer chapters that's in the book, and something I was just working on earlier this year, is just to change the order of a list. [14:50.180 --> 14:53.200] So every night, David Letterman gets out there with his top 10 list. [14:53.300 --> 15:00.000] And it turns out that you can put maybe 10, 11 characters of information just by shuffling that list around. [15:00.000 --> 15:06.180] So if you shuffle it any order you want, you can come up with... you can hide messages in the order of the list. [15:06.180 --> 15:14.400] If you have a shopping list... and what I'll show you later is a list of my favorite top 43 disco songs of the 70s. [15:14.560 --> 15:17.500] And it turns out that's got a message embedded in it as well. [15:18.040 --> 15:21.620] So I think that there's... that's a great source for steganography. [15:23.680 --> 15:29.340] And I think the... another one that has a lot of potential is you can synthesize something that's entirely new. [15:29.340 --> 15:40.360] And if you look at, say, the rendered movies like Toy Story or the computer graphics or what you see when you're playing Doom, this is a synthetic world that's created for you on the screen. [15:40.740 --> 15:46.120] There's no reason why every person has to see those characters in exactly the same location. [15:47.700 --> 15:57.060] One, I think, watermarking technique that would be kind of interesting would be for Hollywood to generate completely new and differently rendered movies for every person that's out there. [15:57.160 --> 16:01.980] And then you'd be able to track it and figure out, you know, who's downloading them onto the internet. [16:03.120 --> 16:09.080] I don't think that that's really a feasible mechanism, but I think it's a very easy way for you to understand what... [16:10.420 --> 16:12.920] what you could do if you had a really nice render farm. [16:23.050 --> 16:34.810] Okay, so let's start with the kind of classic thing that people think about as steganography, which everyone thinks of steganography as being about images and what Osama bin Laden is using to communicate with his minions around the world. [16:35.650 --> 16:37.810] It turns out this is a very big photograph. [16:38.470 --> 16:41.130] It's 3.7 megapixels. [16:41.310 --> 16:42.490] It's 24-bit color. [16:42.750 --> 16:46.190] It's very pretty when it's in full screen. [16:46.190 --> 16:49.950] And you can see that this is the Golden Gate Bridge. [16:49.950 --> 17:00.810] Now the section I want you to pay attention to, because I'm going to show you some graphs and a few slides, is just this gradient right across the top of the sky. [17:05.040 --> 17:07.840] And I want you to see if you see anything changing along there. [17:07.940 --> 17:12.360] And I'm going to show you a little bit of math that people are using and how they may detect steganography. [17:12.500 --> 17:16.980] So you just have a flavor of what people are talking about when you read USA Today. [17:17.840 --> 17:19.800] Okay, so let's take this original picture here. [17:19.920 --> 17:23.160] And I'm going to commandeer one-eighth of the file for my own purposes. [17:23.480 --> 17:29.660] It turns out I hid a copy of the book, which you may be able to pick up if you've got a really high-resolution camera out there. [17:31.820 --> 17:34.770] And, you know, we're going to go and we're going to change the picture. [17:34.900 --> 17:39.660] And it's going to have one-eighth is going to be taken over by my, for my own nefarious or not so nefarious purposes. [17:54.560 --> 17:56.580] And, you know, you can, I can't tell the difference. [17:56.600 --> 17:58.800] I don't know, maybe someone out there has golden eyes. [18:00.280 --> 18:03.380] But now let's do it, let's take it to even a greater extreme. [18:11.380 --> 18:13.400] Okay, so now I've taken over half the image. [18:13.640 --> 18:15.960] So, you know, this is 3.7 megapixels. [18:16.120 --> 18:17.320] It's like 11 megabytes. [18:20.060 --> 18:24.940] And I have embedded 44.1 megabits of my own message. [18:24.980 --> 18:28.160] And there's 44.1 megabits left of the original image. [18:28.400 --> 18:34.980] And if you look across the sky in the gradient there, which is the most sensitive part of the image, you may start to see some plateauing. [18:35.240 --> 18:37.020] And you may start to see some banding. [18:37.680 --> 18:38.540] You know, right here. [18:43.320 --> 18:45.140] And that's, that's the only effect. [18:45.340 --> 18:49.680] And that's one of the reasons I use this picture is because it's got such a nice subtle light blue color on the sky. [18:50.160 --> 18:55.060] You can't, I can't see any difference in the, in the rocks or in the surf below. [19:07.870 --> 19:10.050] Okay, so now I'm going to go to show you some graphs. [19:10.190 --> 19:13.830] And this is the, this is the graph of the intensity as you move across the sky. [19:14.710 --> 19:20.550] And the, the first graph that you're kind of, you're, that's kind of peaking on the screen right now shows the original image. [19:20.890 --> 19:24.370] And it's got a, it's got a fairly smooth gradient as things go. [19:35.050 --> 19:36.810] Now, now this is the second picture. [19:36.970 --> 19:40.610] And you notice all of a sudden the, the character of the line has changed. [19:40.770 --> 19:45.770] And instead of being a smooth picture, it's got kind of a hash mark or a saw-like structure to it. [19:45.930 --> 19:52.950] And this is because the least significant bit has, you know, a lot of the pixels along that line have changed by plus or minus one unit. [19:55.930 --> 19:56.330] Okay. [20:01.450 --> 20:04.570] Now you can see here, I've replaced four bits of every pixel. [20:05.350 --> 20:08.270] And that means plus or minus 16 units. [20:08.750 --> 20:10.490] And we start to see plateauing. [20:10.590 --> 20:13.230] And, and part of that's because of the structure of the data I put out there. [20:13.350 --> 20:15.910] And the way I encoded it, I didn't use perfectly random data. [20:16.250 --> 20:19.010] But this is the kind of effect that people are looking for. [20:19.130 --> 20:23.890] And this is the kind of effect that the officials claim that they're seeing in some of the pictures on eBay. [20:23.890 --> 20:27.530] You know, they're looking around and they start to see, you know, this should be a nice smooth line. [20:27.570 --> 20:29.130] And we're really seeing these plateaus. [20:29.290 --> 20:33.750] We're seeing this kind of random behavior that's not the way images normally look. [20:34.330 --> 20:38.770] And I think this is the most, one of the simplest and most graphic way to just kind of show it to you evolving. [20:39.550 --> 20:45.050] And, you know, if you wanted to, you could write some code and maybe you could get a contract from the DOD to look for Al Qaeda messages. [20:46.630 --> 20:49.950] But, you know, this is one of the techniques that people are using. [20:59.420 --> 21:01.210] Now, this is a blown up picture. [21:01.530 --> 21:04.080] And in this case, I did two things. [21:04.250 --> 21:10.960] One, this image is 2048 by, you know, it's basically, it's divisible by eight. [21:11.100 --> 21:12.320] The width is divisible by eight. [21:12.490 --> 21:16.230] And I encoded pure ASCII text into the image. [21:16.460 --> 21:25.710] Now, if you guys know ASCII files and you've thought about ASCII files for a bit, you realize that the top bit, the most significant bit, is always zero if it's text. [21:26.420 --> 21:29.750] And the second bit is the upper or lower case bit. [21:29.880 --> 21:34.120] So if it's uppercase, if it's pure uppercase, then the second bit is always zero, too. [21:34.420 --> 21:40.840] If it's pure ASCII text, then it's going to be, you know, the upper, the seventh bit is going to be one a lot. [21:41.340 --> 21:43.180] Now, you notice there's some banding here. [21:43.230 --> 21:46.580] And that's because the data I put in there is putting in these stripes. [21:46.580 --> 21:51.020] And this is another effect that I think makes it fairly obvious how it's working. [22:02.780 --> 22:04.220] I've got a page for a minute here. [22:08.410 --> 22:14.930] But even in the sand in this picture, you can almost see that line, every eighth line, that pattern. [22:28.480 --> 22:34.160] Okay, so that was hiding information in the least significant bits of image. [22:34.240 --> 22:37.660] Now I'm going to talk just a little bit about steganography and its evil twin compression. [22:40.200 --> 22:43.060] I don't know how much you guys know about JPEG compression. [22:43.060 --> 22:52.300] But these are four of the 64 functions that JPEG compression uses to break apart a block, an 8x8 grid. [22:52.440 --> 22:54.520] And let me show you in the next slide how that kind of works. [23:01.790 --> 23:06.250] Okay, so up on the left here, we have an 8x8 corner of a picture. [23:06.450 --> 23:11.290] And it's, you know, you can, you probably can't see, but it's actually someone's forehead and their eye. [23:11.290 --> 23:21.050] But what the JPEG function does is it breaks that picture up into a linear combination of those 64 functions that you saw before. [23:21.350 --> 23:32.830] So maybe that top line is 14 units of the first base square, minus three units of that vertical stripe square, minus two units of that checkerboard square. [23:32.830 --> 23:35.010] And it goes on and on for, you know. [23:35.770 --> 23:43.690] And it turns out that, you know, compression, if you use a compression system like that, that can destroy what you're doing with the least significant bits. [23:44.350 --> 23:49.110] But, you know, no matter what you do, it turns out there's always a way you can kind of tweak things a little bit. [23:49.590 --> 23:53.870] So, one easy way, if you wanted to hide a message, is to just tweak these coefficients themselves. [23:54.730 --> 23:57.390] So, instead of using 14, you use the number 15. [23:57.610 --> 23:59.710] Instead of using the number three, you use the number two. [24:00.250 --> 24:02.650] Any time you can make a little change, you can hide a message. [24:02.890 --> 24:13.150] If you can, if you have a freedom to make a little change in your file, whatever the structure is, Then you have the freedom to kind of go in there and hide a secret channel or hide a message in there. [24:35.980 --> 24:39.120] It turns out that there's a lot of different ways you can work around compression. [24:39.440 --> 24:47.320] And one of the neat things you can do is you can use error-correcting codes that deal with problems. [24:47.320 --> 24:52.180] If you encode stuff and then the compression breaks things, you can use error-correcting codes to fix that. [25:01.070 --> 25:05.610] One of my favorite uses of compression is to kind of identify the salient features of an image. [25:05.810 --> 25:17.770] So what you may do with your JPEG system or your super-hot lossy compression system is to go in there and compress it and then uncompress the file and then compare it to the original one. [25:17.870 --> 25:21.530] And if there's no change, then you know that's an important salient part of the image. [25:21.530 --> 25:29.870] And the noise you can ignore and you can only put your changes in the significant part of the image and it will sail through the compression function. [25:37.920 --> 25:42.300] Okay, so now in the next slide after this, I'm going to show you running some compression functions in reverse. [25:43.520 --> 25:44.340] I'm going to... [25:47.680 --> 25:56.140] Normally what compression does is it takes your data and whatever structure it may be, it might be English text, it may be, you know, a program that you've written, it may be an image. [25:56.340 --> 26:06.520] And it tries to squeeze out all the extra noise and all of the extra extraneous information there and produce something that's close to a pure stream. [26:07.300 --> 26:11.260] And if you know anything about information theory, it means that it's got, you know, full entropy. [26:11.660 --> 26:14.960] And you want to squeeze that in and that looks very random and it's totally compressed. [26:15.520 --> 26:20.500] And then when you deal with that, if you've got a good compression function that does that, you can try running that in reverse. [26:20.680 --> 26:30.900] You can take your message and what you can do is you can pass it into the compression function, run the compression function in reverse, and you should have something that looks like the underlying data. [26:31.000 --> 26:32.560] And that's what I've done with some English text. [26:38.890 --> 26:40.990] Okay, so this is what I did with English text. [26:41.110 --> 26:45.210] I went and I analyzed it and I figured out what are the statistical properties of the text. [26:45.390 --> 26:47.610] So, you know, how many times does the letter E occur? [26:47.710 --> 26:50.810] And everyone knows that's the most common one in your Scrabble set. [26:50.810 --> 26:52.970] You know, how many times does the letter T occur? [26:53.090 --> 26:54.190] How many times does the letter Z? [26:54.490 --> 27:02.570] And then what I did is I used my data, my secret message, to choose in a way that's biased according to these statistics. [27:02.770 --> 27:06.590] So, if you look at the first line, that's what I call first order text. [27:06.790 --> 27:11.090] And in that case, it's only statistically equivalent. [27:11.370 --> 27:16.610] It has the same first order statistics of the underlying data. [27:17.270 --> 27:21.550] But the second one, I started to do, be a little clever about how you do this. [27:21.690 --> 27:27.770] And instead of just figuring out how many times the letter E occurs or the letter T occurs, I started doing it in pairs. [27:27.950 --> 27:32.370] And I said, well, after the letter T, what's the next letter and how often does that occur? [27:33.210 --> 27:40.630] And, you know, the H occurs after the letter T very often, but the letter, you know, Q doesn't come after T hardly at all. [27:40.630 --> 27:45.810] And so, in that case, I tried to balance, you know, I used that data. [27:45.950 --> 27:47.970] And it starts to look a little bit more like English. [27:48.670 --> 27:51.690] And then the third order, I tried to use triplets of letters. [27:51.830 --> 27:55.530] And the fourth order, I used four letters and built very complicated tables. [27:55.770 --> 27:59.330] But you notice that the bottom looks a lot like standard English. [28:00.090 --> 28:11.970] And using that, I was able to turn out something that looks, you know, like statistical English, that looks like something that might be, that's going to pass through anybody's statistical detector. [28:12.390 --> 28:15.770] Yet, it has a secret message that's hidden away underneath it. [28:16.970 --> 28:19.890] So, you know, if you try to read it, you might get a little bit confused. [28:20.150 --> 28:24.190] But, you know, the real message is underneath. [28:24.450 --> 28:26.430] It's, you know, you have to read between the lines. [28:33.550 --> 28:39.390] Okay, so here's what I think is my favorite new method of dealing with this. [28:39.650 --> 28:43.030] And this does not change the underlying statistics at all. [28:43.170 --> 28:45.590] And so it means that you can put anything you want into it. [28:45.950 --> 28:49.970] And it's going to change the order around, but the statistics underneath are not going to change. [28:50.130 --> 28:53.250] That means it's very hard for someone to detect anything changing. [28:53.570 --> 28:59.410] You know, I've always, I've never really understood what order David Letterman uses for the top ten list he puts up there on the screen. [28:59.830 --> 29:03.950] And I don't necessarily think number one is that much funnier than number seven or number four. [29:04.450 --> 29:06.050] And I don't, you know, maybe they do. [29:06.930 --> 29:10.750] But I think you could reorganize these things very easily and no one will notice. [29:10.870 --> 29:13.930] But if you do that, you can take advantage of this, of the math. [29:15.290 --> 29:20.430] I don't know if you guys remember this, but if you have n items, there are n factorial ways you can arrange them. [29:20.430 --> 29:22.750] And n factorial grows to be large pretty quickly. [29:23.270 --> 29:28.230] So if you have, you know, a lot of items and you change the order, you can encode a pretty long message. [29:30.730 --> 29:41.370] One of the neat things, and I'll just mention this as an aside, if you're into cryptography, if you try to, what you need to make this to work, in order to make this work, you need to kind of alphabetize the list. [29:41.370 --> 29:45.150] And that defines a canonical order, and then you go and you do the math. [29:45.550 --> 29:48.830] But you don't necessarily have to alphabetize the item itself. [29:48.830 --> 29:51.810] You can alphabetize a hash of the item with a password. [29:52.070 --> 30:00.050] And so in essence, you create, you have a secret message that you're encoding with a password, with someone, you know, you've never communicated with before. [30:00.470 --> 30:06.390] And you're able to, if you use that as the alphabetization, then people really can't tell. [30:06.810 --> 30:09.850] They can't break that unless they can break the hash function. [30:09.850 --> 30:13.750] And most of the hash functions seem to be impervious, at least right now. [30:14.410 --> 30:17.270] So I think it's a very secure way of communicating. [30:17.550 --> 30:19.830] And I think it's very, very subtle. [30:19.870 --> 30:22.270] I think it would be very difficult for someone to detect. [30:24.570 --> 30:26.230] So, you know, and here are some numbers. [30:26.330 --> 30:28.530] You can store 65 bytes in 100 objects. [30:28.530 --> 30:31.650] You can store 210 bytes in 256 objects. [30:31.790 --> 30:33.670] You know, you can get a fair amount of bandwidth in there. [30:35.190 --> 30:38.290] And the six items I've even got right here can store nine bits. [30:38.290 --> 30:42.090] And maybe, you know, I think I may be a little bit random as a speaker. [30:42.090 --> 30:44.230] Or maybe I'm talking to someone out there. [30:44.370 --> 30:44.770] Who knows? [30:50.080 --> 30:51.060] This is an example. [30:51.200 --> 30:52.180] These are 43 disco. [30:52.640 --> 30:54.440] There are 43 disco songs. [30:54.800 --> 30:58.960] It turns out the log of 43 factorial is 176. [30:59.600 --> 31:01.900] So what I've done is I've hidden a message in here. [31:01.980 --> 31:04.040] The message up there is there is no secret message here. [31:04.100 --> 31:04.600] Look elsewhere. [31:06.260 --> 31:09.600] And if you go and use, you turn that into a big integer. [31:10.220 --> 31:12.500] And I've got all the source code for this if you want it. [31:12.580 --> 31:16.780] You all can, you can actually play with this on an applet on my website. [31:18.300 --> 31:20.300] You know, that's what the number comes out looking like. [31:20.460 --> 31:22.360] And you guys can check it if you really care. [31:23.300 --> 31:27.360] But once you scramble these things, these 43 disco songs come out looking like this. [31:27.860 --> 31:32.340] And, you know, presumably if you're sending a message to your friend, you might say, you know, I think you're totally wrong. [31:32.340 --> 31:35.560] If I was on a desert island, these are the 43 disco songs I would want. [31:36.340 --> 31:39.500] And I think that this is very, very secure. [31:39.500 --> 31:45.460] I don't think anyone could break this code unless they look at this listing and say, you know, this guy has totally lost it. [31:45.540 --> 31:49.380] I mean, you know, there's no way that Barry White and KC and Sunshine Band are at the top. [31:49.480 --> 31:51.580] Anybody who likes Barry White is not going to like KC. [31:52.080 --> 31:54.740] You know, and that's, I think, the only way that people can detect this. [31:54.740 --> 31:56.480] There's no statistical change in the list. [31:56.680 --> 32:01.260] The statistics of the letters are still the same, no matter how you shuffle it. [32:01.660 --> 32:04.320] Because you leave everything in place, you just change the order. [32:19.520 --> 32:20.760] You know, I mentioned this before. [32:20.960 --> 32:27.980] I think that there are lots of neat ways that you could be sending secret messages to each other when you're playing online games or other things like that. [32:28.320 --> 32:36.200] You know, whenever you're in a synthetic world, there's no reason that every item has to be in exactly the same place for everybody who's looking at that synthetic world. [32:36.420 --> 32:40.300] You can move things over a nudge and send information that way. [32:42.120 --> 32:50.700] You know, there's, I don't know why, you know, if you needed to communicate with someone in your Doom maze that you're in, you might shoot in Morse code. [32:51.100 --> 32:55.140] You know, a blaster can be a dot, a grenade launcher can be a dash. [32:55.820 --> 33:00.060] You know, you can tap dance or you can grab the least significant bit of your position. [33:00.320 --> 33:13.260] You know, I think there's so much bandwidth out there that's being used and there's so much noise in this bandwidth that there's a huge number of opportunities for people to go out there and hide information and use it for whatever purposes they have. [33:16.060 --> 33:24.340] One of the more fascinating watermarking techniques I've heard about is that people want to go in there and they want to change the acoustics of the room ever so slightly every few seconds. [33:24.740 --> 33:27.160] And they want to modulate that to send out their message. [33:28.040 --> 33:31.440] And, you know, it's so subtle that, you know, only people with golden ears would hear it. [33:31.480 --> 33:33.780] But I thought that was kind of a real clever idea. [33:43.230 --> 33:48.550] You know, if you want to get more sophisticated, you can come up with mathematical ideas that are, I think, also very, very strong. [33:50.950 --> 33:59.350] You know, if you've played around and you've studied some computer science, you understand that computer scientists often talk about these things called context-free grammars. [33:59.690 --> 34:04.250] And it's just a very simple way of representing how language works. [34:04.410 --> 34:10.050] You know, when you diagram sentences, in essence, you're building a context-free grammar for how people talk. [34:10.550 --> 34:26.050] And if you take those context-free grammars and you kind of use them to, you know, you use your message to choose, you know, which branch of the, you know, the sentence you're choosing or, you know, whether you're going to, you know, start with the direct object or you're going to start with the indirect object, [34:26.210 --> 34:26.470] et cetera. [34:27.050 --> 34:30.670] You know, you can change the order of sentences and you can modulate that and you can sneak in. [34:30.790 --> 34:31.310] And what do you know? [34:31.370 --> 34:33.270] You've got another channel for a secret message. [34:40.990 --> 34:46.590] You know, here's a context-free grammar if you remember what, you know, what you may have learned in a computer science course. [34:47.770 --> 35:00.130] The items that are in blue are variables, and the items that are in purple are productions that come off the variables, and the items that are in italics, you know, can then be variables that are used again. [35:01.290 --> 35:09.050] And, you know, I built a huge grammar out of this that mimics how a voiceover for a ball game. [35:09.310 --> 35:10.610] And I think it's pretty sophisticated. [35:10.610 --> 35:12.370] It keeps track of how many outs. [35:12.570 --> 35:21.590] If you're reading this and you think this is some guy who's just, you know, sending a secret message, well, there's going to be three outs in every inning, there's going to be four balls, there's going to be three strikes, etc. [35:21.930 --> 35:28.570] It does a good job of keeping track of the underlying, you know, state of the ball game, and it doesn't make any mistakes about that. [35:28.750 --> 35:33.110] The game, you know, the names of the players and everything are kind of goofy, but you could do a better job. [35:39.570 --> 35:45.590] You know, and here's some output that just talks about some ball game in Blavonia, I guess. [35:45.750 --> 35:48.850] But you may want to use the Yankees or the Mets or something like that. [35:50.090 --> 36:02.510] And, you know, if you really wanted to get into it, you could write a screen scraper that pulls off the data from last night's game and say, hey, here, you know, Bob, I wanted to tell you about the game last night, and you could use a context-free grammar system like this. [36:02.650 --> 36:09.590] And it would tell, you know, it would, it would, okay, it would explain exactly what was going on with the game. [36:09.670 --> 36:10.610] It would be correct. [36:10.610 --> 36:13.150] Anybody who saw the game would know that you're not fiddling around with it. [36:13.450 --> 36:18.990] But when they would go and, you know, someone at the other end was trying to pull away the secret message, they would find it. [36:27.920 --> 36:31.100] Okay, so, you know, there are people out there who are trying to do steganalysis. [36:31.100 --> 36:33.040] And the big question is, is this stuff very strong? [36:33.040 --> 36:34.380] And I think the answer is yes. [36:34.940 --> 36:37.480] I think it's as strong as encryption. [36:37.880 --> 36:42.720] And, you know, if you do the math very well, you know, it should be as strong as RSA. [36:42.720 --> 36:45.260] And there are a lot of different arguments about why that may be. [36:47.560 --> 36:57.460] You know, I don't, I think there are plenty of reasons why this is a very, very powerful way to communicate or to pack information in bits and to, you know, work with what you're doing. [37:07.470 --> 37:10.950] Again, you know, at the beginning I mentioned, you know, hey, do we know if these things are really working? [37:11.170 --> 37:12.070] What's the deal? [37:12.270 --> 37:15.230] I think, again, that's a very difficult prospect. [37:15.350 --> 37:22.690] But I think there are a lot of mathematical reasons why it would be very hard to attack a lot of the systems that are the best of the breed that people are using. [37:24.410 --> 37:26.530] You know, whether they can be detected or not, I don't know. [37:26.730 --> 37:31.390] But I think that if you're careful about it, you know, I think that you can build something that's very secure. [37:43.460 --> 37:48.140] I wanted to just say a little bit more about the statistical detection of noise and what we were talking about before. [37:48.360 --> 37:49.980] I think it's kind of a cat and mouse game. [37:50.100 --> 37:58.080] The more I look at it, the more I realize that people who come up with these detectors, and some of them are very good and some of them are very powerful, can still be fooled. [37:58.220 --> 38:03.580] And then you end up in this cat and mouse game where there's people who are trying to hide information and they come up with a scheme and people who are trying to detect it. [38:03.760 --> 38:05.460] And then, you know, it's spy versus spy. [38:06.780 --> 38:18.780] I think anybody who is really trying to send a secret message, the best way to stop anybody who is trying to detect it is to use a very short message in a very big file. [38:18.940 --> 38:24.620] The smaller the message is, the smaller the needle is in the haystack and the harder it is for the statistics to work out. [38:32.590 --> 38:39.810] You know, people always talk about regulating cryptography, regulating steganography, and there are a lot of reasons why people, you know, want to do these things. [38:39.810 --> 38:45.470] I think that would be a mistake, and I think there are a couple of real good reasons why we need steganography. [38:46.930 --> 38:50.870] The software developers just need to be able to have a new channel when they expand. [38:51.290 --> 39:08.230] One woman I talked to at an information hiding workshop who is very, very sharp, she said she was working on this process where she would take JPEG files of radiograms, which are x-rays, that's the new word for x-rays, and they would do a little bit of steganography in there to put the doctor's comments in there, [39:08.290 --> 39:09.990] and then they would ship them on to other software. [39:10.290 --> 39:18.090] And it turned out, because they were using the steganography, they were able to do it in a way that wouldn't disturb the old software, but the messages would still be there for the new software. [39:18.230 --> 39:25.830] So the company didn't... the doctors didn't have to spend a lot of money on a lot of new software, and... but they could still overlay this new layer and this new feature. [39:26.010 --> 39:30.790] And so I thought that was a very good way to fight bit rot and save money and, you know, help people out there. [39:30.830 --> 39:32.230] And I think steganography is doing that. [39:35.430 --> 39:40.570] Obviously, the people in Hollywood think it could be a great deal for them, and they want to fix these things, and they want to use it. [39:40.750 --> 39:48.890] So, you know, that may be... we may end up with a system that does a very good job for creating a porous marketplace for information like we just heard in the keynote. [39:49.690 --> 39:54.210] And this steganography may turn out to be a tool that will allow us to regulate at just the right amount. [39:54.530 --> 39:59.850] So we... you know, people can copy things occasionally, they can put them in their cars, but they can't post them on the Internet. [40:00.090 --> 40:10.030] And that may be something that's a real... that ends up being a decent compromise for people who want to use information and consumers who don't want to get ripped off, and the companies that want to make a decent return. [40:10.250 --> 40:14.790] I don't know, but I think steganography has the power to, you know, has the potential to provide that. [40:14.950 --> 40:18.010] It's the politics that may or may not work. [40:19.170 --> 40:25.290] And I think regulating steganography is impossible because it's trying to, like, regulate double entendres and, you know, et cetera. [40:26.030 --> 40:28.750] You guys can go to my website where you can play with the applets. [40:28.830 --> 40:32.310] You can create your own list of disco songs to send to your friends. [40:32.430 --> 40:33.690] You can play with the mimicry. [40:34.130 --> 40:40.910] There's a great website out there called Spam Mimic where someone took the software and they took all... they created a context-free grammar of spam. [40:41.290 --> 40:48.230] So if you want to create your... if you want to send your message out and it'll look just like fake spam, it'll be, you know, instead of Nigeria, it might be Cameroon. [40:48.430 --> 40:50.750] But, you know, that's one bit that they're hiding in there. [40:50.890 --> 40:51.950] And it's very clever. [40:52.190 --> 40:53.290] The guy did a great job with it. [40:53.490 --> 40:54.590] And so you should check that out, too. [41:01.600 --> 41:03.240] Yeah, and we're back to the books. [41:03.480 --> 41:05.440] So this is the last slide if you have questions. [41:06.380 --> 41:11.460] If you're interested in either of these books, I've got these brochures up here. [41:11.620 --> 41:12.680] There's a magic number. [41:12.880 --> 41:18.400] If you know that code, DM22427, you can go to the Morgan Kaufman website and get 20% off. [41:19.380 --> 41:26.640] If you go to this particular somewhat hidden web page on my site, you can get 30% off translucent databases until Monday. [41:27.340 --> 41:31.200] It's all printed out here if you want to just come pick it up and save yourself the trouble of writing it down. [41:31.380 --> 41:34.120] Or you can save some paper and write it down yourself. [41:34.880 --> 41:38.440] If anyone has questions, I would love to try to answer a few of them before we're done. [41:42.840 --> 41:43.760] There's somebody over here. [41:50.410 --> 41:50.810] Hi. [41:50.970 --> 41:52.210] I'm a reporter from Reuters. [41:52.450 --> 42:04.790] And I've had difficulty talking to some of the people who've talked about the use of steganography by Al-Qaeda or in other criminal uses. [42:04.950 --> 42:09.470] I've had difficulty having people actually produce any evidence that this has actually happened. [42:09.790 --> 42:13.770] There's a lot of reports of it in USA Today, in the New York Times. [42:14.470 --> 42:20.010] There's some discussion and there was a plot to bomb the U.S. [42:20.090 --> 42:20.930] Embassy in Paris. [42:22.450 --> 42:26.850] Have you seen any of this evidence or do you know people who have seen this evidence? [42:28.290 --> 42:30.530] No, I don't know of any evidence. [42:30.670 --> 42:32.770] I have not seen any evidence like this. [42:32.990 --> 42:37.130] And I do know, in fact, of one person who has counter evidence, if you can say this. [42:37.150 --> 42:40.170] A guy at University of Michigan, Niels Provost, who's a very sharp guy. [42:40.550 --> 42:45.210] He went out there and he wrote a program that downloaded a million pictures, I think that's the number, from eBay. [42:45.450 --> 42:46.670] Two million pictures from eBay. [42:47.310 --> 42:49.390] And he put them through his own statistical detector. [42:49.950 --> 42:52.150] And he found nada, nothing, zilch. [42:52.310 --> 42:53.350] Nothing was out of the ordinary. [42:53.650 --> 43:01.270] And, you know, it may be that the two millionth and oneth picture was the one that's out there because, you know, Lord knows eBay churns through a million items a day, practically. [43:01.810 --> 43:09.150] But, you know, I think that's pretty... I mean, it's not conclusive evidence, but I think it's interesting evidence. [43:09.350 --> 43:14.690] Now, it may be his statistical detector was bad or it wasn't tuned to what the method that Al-Qaeda was using. [43:15.350 --> 43:25.370] I have talked to people who have hinted to me, you know, in a not-for-attribution basis and, you know, without really telling me anything that there are better detectors out there that can find more serious things. [43:25.370 --> 43:27.010] But I've never seen that myself. [43:27.590 --> 43:31.510] So, you know, is it possible that people are doing this? [43:31.590 --> 43:31.750] Yeah. [43:32.010 --> 43:36.830] I mean, the software's out there and it's interesting and, you know, but they may just be using Hotmail. [43:41.010 --> 43:47.770] It seems like steganography is a relatively young field academically, but there's been a lot of study of covert channels in security systems. [43:48.070 --> 43:52.890] And one of the main areas where those are a pain to try to limit are timing attacks. [43:53.150 --> 44:02.150] And I'm wondering if timing attacks or timing variations are a useful avenue to explore for steganographic content, delaying a packet by a small amount of time rather than actually changing the content. [44:02.990 --> 44:03.430] Yeah. [44:03.570 --> 44:06.330] I mean, I think that's, you know, I really should lump those in there. [44:06.510 --> 44:06.990] I mean, you're right. [44:07.110 --> 44:11.470] There's been a lot of people who've talked about covert channels and, you know, the NSA's been worrying about them for a long time. [44:12.390 --> 44:22.050] I think people have pretty much understood that there's very little that you can actually do because once you allow people to communicate, they can change the time or they can change, you know, you can modulate practically anything that's out there. [44:22.250 --> 44:28.090] So, I mean, I think covert channels are another good way for people to experiment with, you know, if that's what you're interested in. [44:30.590 --> 44:43.690] Has anyone looked into modifying heuristic algorithms that actually analyze the image for compression, before compression, so they don't necessarily turn out the optimal compression ratio and use that as a predictable way to be able to hide a message in an image? [44:46.130 --> 44:52.370] You know, I can't put my finger on any papers, but I think that people have, you know, I think that's, that would be a neat thing to explore. [44:52.590 --> 44:57.550] If you go out and you kind of check how people are doing compression and they may not do the optimal compression mechanism. [44:57.850 --> 45:01.350] And there are so many parameters in a lot of these compression systems that I think you could do it. [45:01.670 --> 45:07.450] I think the only problem you have is that what someone may do as a detector is they may have their version of PK-Zip. [45:07.530 --> 45:08.930] Let's say you try to do it with PK-Zip. [45:09.310 --> 45:13.150] They may compress the file with PK-Zip and say, hey, wait, this is not optimal. [45:13.350 --> 45:14.990] This, this file is just slightly fatter. [45:15.170 --> 45:16.730] It's got an extra couple of bytes in it. [45:17.170 --> 45:20.550] You know, that, that, that would be a very easy way for someone to detect it. [45:21.050 --> 45:25.350] So, you know, if you're using a non-standard mechanism for compression, it would be a good way to begin. [45:25.350 --> 45:31.090] But if you're using something, if you're trying to, to tweak a standard method, then, you know, it's slightly more, you've got more danger there. [45:35.750 --> 45:36.110] Okay. [45:36.210 --> 45:39.610] Well, I think that's, that, that should be the end of everything right now. [45:40.490 --> 45:41.850] Thank you very much for coming here. [45:41.970 --> 45:45.930] I'd like to thank the people from the 2600 Magazine for hosting me. [45:46.130 --> 45:49.630] And I'd like to talk with any of you guys over the weekend if you're around. [45:49.870 --> 45:50.230] Bye.