[00:00.480 --> 00:03.260] Start again tomorrow at 10 a.m. [00:03.680 --> 00:15.380] And we do have some really fascinating stuff signed up in the C session room and I should probably even... No, I'm not going to try to grab my pad, although I wanted to mention what those were. [00:15.580 --> 00:20.220] But we have one thing going on now, another thing at 11 o'clock, and a bunch of stuff scheduled for tomorrow. [00:20.480 --> 00:23.240] So be sure to check out that schedule over in the C area room. [00:24.480 --> 00:29.020] Without further ado, next talk is 10 Years of Practical Anonymity. [00:29.260 --> 00:30.300] Here's Len Sassaman. [00:34.530 --> 00:35.210] Thank you. [00:36.510 --> 00:38.430] So I see there's a few of you here. [00:38.590 --> 00:43.970] I was glad to see the late scheduling of the talk didn't discourage all of you. [00:44.630 --> 00:55.950] I'm going to talk here without slides and just go over briefly the history of anonymous services, particularly email services, on the internet. [00:56.030 --> 00:57.190] in the last 10 years. [00:58.130 --> 01:03.530] So if you have any questions at any point, please stick your hand up and I don't mind the interruption. [01:04.750 --> 01:09.410] And I will take this talk whatever direction we feel it needs to go. [01:11.270 --> 01:30.950] The starting point for anonymity on the internet, I believe, has to be the anon.penet.fi remailer, which certainly wasn't what we would consider truly anonymous and isn't the first mention of anonymity in the literature or even in the context of networks, [01:30.950 --> 01:44.430] but is the first time that a wide internet audience had the opportunity to experience something remotely equivalent to anonymous email services on the net. [01:44.430 --> 01:53.370] Penet was probably more accurately described as a pseudonym server rather than a remailer. [01:53.990 --> 02:05.890] Users were able to register themselves with this mail service and create an account that was something of the equivalent of a non.123 at anon.penet.fi. [02:05.890 --> 02:31.070] And through the use of some basic tools to retrieve their mail by setting up forwarding between the Penet server and their actual real address, this had one major flaw from a security standpoint, which is you've got a database of mappings of real addresses to pseudonyms on the server in a database. [02:31.070 --> 02:42.710] And that's easily obtainable through either hacking attacks or what we refer to as legal attacks, where one can try to subpoena records. [02:44.230 --> 02:56.070] That is if one wants to avoid breaking the law and just breaking in and taking them, which I have heard multiple people say that they did during the time that Penet ran. [02:56.070 --> 03:01.490] Penet was in operation in the early 90s, finally checked down, I believe, in 94. [03:02.090 --> 03:08.410] But while Penet was gaining in popularity... [03:08.410 --> 03:13.150] Now, remember, at the time that Penet was operating, we didn't have anything like Yahoo Mail or Hotmail. [03:13.250 --> 03:15.630] Hotmail wasn't started again until, I think, 95. [03:16.050 --> 03:24.670] So the idea of an email address that one could obtain that wasn't linked to their real name was pretty foreign. [03:24.670 --> 03:28.790] There was very little in the way of free email services out there. [03:28.910 --> 03:39.430] You had to either be using an ISP or you had to be going to a school where you had an email account and an internet login as part of your... as being a student. [03:44.190 --> 03:52.930] The Penet server, as I said when I introduced it, is not truly an anonymous mail service. [03:55.130 --> 03:59.130] It's only anonymous insofar as your real name isn't attached to it. [03:59.230 --> 04:06.370] But when we in the computer security field talk about anonymity, we are implying something much stronger than that. [04:06.370 --> 04:14.370] But the concept of anonymity is defined as the state of being indistinguishable within a group... [04:14.370 --> 04:17.790] within a certain set of other like individuals. [04:18.330 --> 04:27.850] So, if you are to be truly anonymous, you are a player in a group of other actors that are... not distinguishable from you and vice versa. [04:34.410 --> 04:43.370] The early strong anonymity proposals were made well before Penet or before any of the... the real research into the issues involved with anonymity. [04:48.590 --> 05:11.630] Shortly after the discovery and publication of the concept of public key cryptography, a fellow by the name of David Chalm came up with a very simple method of using public key cryptography to create a construct which could allow people to have truly anonymous communication. [05:12.370 --> 05:12.750] This... [05:14.390 --> 05:25.210] This protocol, which I'll describe in a moment, was intended to be resistant against more attacks than just keeping your name separate from your postings. [05:28.590 --> 05:50.150] Having an idea of different threat models and knowing that you have varying threats, depending on who you are and who you're hiding yourself from, leads you to understand how this is an important distinction here between using Penet or using a Hotmail throwaway account that isn't linked to your name. [05:50.310 --> 06:10.430] If, for instance, you have a concern that there are potential adversaries that are monitoring the flow of email messages on the internet or watching internet traffic, the idea that you are hiding your name by using Hotmail or by using Penet or Yahoo Mail, [06:10.430 --> 06:25.950] it goes out the window because if your dial-up account can be linked to you and you're going to a website, then an observer on the network will be able to determine that Bob at Hotmail.com belongs to you, even though your name isn't Bob. [06:26.910 --> 06:28.010] We want to beat that. [06:28.010 --> 06:46.470] We also want to avoid a large range of attacks, which I'm going to brush over because Nick Matheson is going to be talking in a little bit more detail about attacks in particular on anonymity systems. [06:46.870 --> 07:18.030] But in addition to the concept of a global passive attacker or omniscient observer that just sits and monitors the network looking at traffic and correlating centers with identities, you can do a number of different, more active attacks, which can allow you to determine who is behaving similarly to a pseudonym and then link them together. [07:18.410 --> 07:20.850] And again, I'm going to let Nick go into the details of that. [07:20.850 --> 07:44.150] But the principal concern with a system like Penet was, again, not even the idea that there would be an observer watching network traffic, but you have this database of real names or real email addresses to the pseudonymous email addresses. [07:44.150 --> 08:07.150] So, somebody could post some controversial material through the Penet remailer and have years later someone else obtain the database and records of one's real email address and correlate that back to a previously so-called anonymous posting and reveal his identity. [08:07.730 --> 08:08.710] This is a problem. [08:09.270 --> 08:12.410] This is a problem not only for the users, but also for the operators. [08:12.810 --> 08:21.170] Because you generally don't want to be sued to have to give up the core feature provided by your service, the anonymity of it. [08:21.410 --> 08:34.350] So, knowing that this potential existed, a group of programmers in the early 90s, referred to as the cypherpunks, started to look at ways of countering this. [08:34.650 --> 08:40.330] And they dug up some of David Chom's works and said, hey, this problem has been thought of before. [08:40.330 --> 08:42.950] We can do this better. [08:44.330 --> 08:51.550] And implemented a rough approximation of what Chom was going for with a number of serious shortcomings. [08:52.270 --> 08:56.350] This is referred to as the Type 1 remailer network or the Cypherpunk remailer network. [08:57.350 --> 09:03.490] The way this worked was it introduced the concept of chained remailers. [09:03.750 --> 09:21.330] Rather than having one remailer, which you had to trust, that was the other problem with Penet, was not only are you opening up yourself to the risk that Pennant could be broken into or the record subpoenaed, but you also have to inherently trust that the operator is honest and doing what he's saying he's doing. [09:22.550 --> 09:28.070] That's generally not something that many people are going to be able to put into their threat model. [09:28.810 --> 09:35.910] So, if you want to avoid having to trust a third party, you can do that in a number of different ways. [09:36.070 --> 09:48.730] The simplest way is to assume that you can't trust any one third party, but that you can use multiple third parties and make the best guess that they're not all going to cooperate. [09:48.730 --> 09:52.630] Even if they're all individually untrustworthy, they're not as a group untrustworthy. [09:52.950 --> 10:17.030] So, if you have a network of multiple different remailers and you chain your message through multiple hops, then you have a rough assurance that you're not going to have to worry about any one of them outing you, or the whole of them all getting together and agreeing to break your anonymity. [10:18.470 --> 10:33.130] Now, there's, again, the problem of, well, okay, if we're forwarding messages through multiple hops, what's to stop any one hop from reading the contents of the message and figuring out who it's coming from and where it's going to? [10:33.130 --> 10:34.590] That is a problem. [10:35.130 --> 10:50.050] But due to the prevalence of the early introduction of accessible public key cryptography to the internet in the early 90s with PGP, this problem was roughly solved. [10:51.930 --> 10:53.370] the procedure is simple. [10:53.530 --> 10:57.570] You take your message and each remailer has a key. [10:58.750 --> 11:13.490] Encrypt your message to the last hop, the final remailer, and then take that encrypted chunk of PGP message and encrypt that to the second-to-last remailer with instructions saying forward this on to the last remailer. [11:13.490 --> 11:32.130] Work backwards through the chain as long as you feel you need it to be and encrypt the second-to-last blob to the second blob to the first remailer and then mail this encrypted message out to the first remailer which receives it and then works forward through the chain, [11:32.430 --> 11:41.110] stripping off the encryption, finding a newly encrypted message which that remailer cannot read, Simply saying, send this on to the second remailer. [11:41.610 --> 11:43.690] It does that, and so forth. [11:45.350 --> 11:49.630] Coming to the last remailer, which strips off the last layer of encryption, and then delivers your message. [11:50.270 --> 11:52.090] Is that clear to everyone? [11:52.210 --> 11:53.650] Is there any question with that? [11:56.690 --> 12:09.330] So, this solves the problem of individual remailers looking at message content and determining who's sending to whom. [12:10.010 --> 12:13.110] They can only tell... Now, the first remailer can tell who's doing the sending. [12:13.270 --> 12:14.950] The last remailer can tell who's doing the receiving. [12:15.770 --> 12:21.110] And all the in-between remailers can't tell anything except that there's mail coming from one remailer going to another. [12:21.770 --> 12:24.950] And no one party knows both the sender and the recipient. [12:27.130 --> 12:40.970] This infrastructure is still in place today because there's a more clever addition to this, which allows people to receive messages anonymously. [12:40.970 --> 13:04.770] You can give out a public key and an address mapping, referred to as reply block, which allows you to receive messages at a NIMS server address, which then forwards your message along with this reply block, which is actually a nest of instructions to other remailers. [13:04.770 --> 13:06.570] I'm going to breeze quickly over this. [13:07.650 --> 13:08.590] But the... [13:09.370 --> 13:17.170] This is important to mention because it has one serious problem and it has a major feature, right? [13:17.270 --> 13:20.370] The people want to be able to receive mail anonymously and not just send it. [13:21.170 --> 13:26.750] Remailer systems are not really nearly as useful if you can only send mail anonymously and cannot receive it anonymously. [13:26.750 --> 13:31.890] That's a major feature deficit if your system only does sending. [13:33.350 --> 13:55.210] However, the way the type one system is designed, the allowance for reply blocks for return messages to the system opens up a major security problem in that you are receiving messages coming back to the network multiple times. [13:55.210 --> 14:05.330] Each time you send a reply back with a reply block, you are basically setting yourself up to be observed as... [14:05.330 --> 14:07.150] It's referred to as a replay attack. [14:07.470 --> 14:19.670] So, somebody observing the network can witness reply blocks going through multiple times and realize that, hey, this message always gets sent to these remailers after it's sent through. [14:20.210 --> 14:28.790] Let's watch this and let's see, is there a pattern to who is receiving mail whenever messages are sent with this reply block. [14:29.630 --> 14:35.870] Do this a few times and you are able to determine who is sending or who is receiving messages at a given NIMM address. [14:36.790 --> 14:46.710] Additionally, because of the allowance for this feature, the type one system has no built-in prevention methods for general replays. [14:46.710 --> 15:03.190] So, if you wanted to intercept a message going through the network and you have the ability to watch pieces of the network and determine that a message has gone through multiple times, you can then re-inject that message and observe it going through again. [15:03.190 --> 15:08.950] I'm not going to go into too much detail here either because I believe Nick talks about the concept of replay attacks. [15:10.550 --> 15:19.670] But this is a major distinction between the type one system and the type two system, which I'll describe in a moment. [15:21.050 --> 15:31.410] And type two, which is the network that a couple of remail order software packages, Mixmaster most notably, and Reliable implement. [15:34.690 --> 15:40.290] The type one system had no real standard way of doing message reordering or delays. [15:43.830 --> 15:46.030] With... I'll get the padding in a minute. [15:46.610 --> 15:49.490] With... Who are you by the way? [15:52.350 --> 15:58.630] People that know about padding are... Sorry, that threw me off there. [16:01.530 --> 16:10.550] When you're dealing with remailers, you have the opportunity here, particularly with layered encryption, to thwart a number of attacks. [16:11.610 --> 16:18.670] If you have mail coming into a remailer, you generally want that mail to go out of the remailer in a different order than it arrived. [16:20.890 --> 16:23.570] Some of the cyberpunk type one implementations do this. [16:23.790 --> 16:24.530] Others don't. [16:25.130 --> 16:33.310] So there's no real assurance that somebody watching the remailer network can't just track messages going in and coming out in the order that they go through. [16:33.550 --> 16:39.270] And, you know, you're just watching it, watch the ball bounce, and then you know who the sender is and who the recipient is. [16:41.850 --> 16:47.630] In... In the anonymity literature, there's multiple different approaches to doing delays. [16:48.210 --> 17:00.730] The method that is in use most widely is what's referred to as a pool mix, where you have messages come in and they land in a bucket, basically. [17:00.730 --> 17:02.450] You've got a couple of hats here. [17:03.170 --> 17:05.810] And messages are coming into the network. [17:05.810 --> 17:12.150] And when they hit a node, the bucket fills up until there's sufficient messages in that bucket that you start sending them out. [17:13.410 --> 17:15.150] They get sent out in random order. [17:15.330 --> 17:19.230] So messages coming in are mixed with all the other messages coming in. [17:19.230 --> 17:25.110] And then the ones that are delivered are consequently leaving in entirely different order than they arrived. [17:26.710 --> 17:29.950] This happens at every node in the network. [17:30.830 --> 17:35.290] And you have... you have reordering at each hop. [17:35.630 --> 17:41.610] So an adversary that's watching the network can't... presumably cannot trace the messages going through. [17:44.370 --> 17:49.820] The... mix master software had a... a sane way of doing reordering. [17:50.490 --> 17:53.490] Whereas cypherpunk systems, the original ones had no reordering at all. [17:53.650 --> 18:00.810] And the subsequent ones did some less secure methods of doing reordering. [18:01.830 --> 18:07.610] That's kind of being generous, but... for some adversaries, they were sufficient. [18:10.070 --> 18:11.710] Another aspect is padding. [18:12.990 --> 18:18.210] With PGP, you have a couple of problems. [18:20.150 --> 18:25.690] One... it's generally... it can be assumed that as messages travel through the network, they're going to get smaller. [18:25.870 --> 18:27.310] Because you're removing a layer of encryption. [18:27.750 --> 18:34.790] And you have... consequently, if you're removing an envelope from a package, you've got a smaller package inside. [18:36.170 --> 18:40.930] The way mix master deals with this, every packet is the same size. [18:41.170 --> 18:46.850] Messages are... either padded out to the fixed size, or they are split into multiple chunks. [18:47.090 --> 18:51.270] And the last one, if it's not of the... normal size, it's padded out. [18:52.610 --> 18:55.450] So... you have each message at a fixed size. [18:55.870 --> 19:02.730] And... as they travel through the network, padding is added in a way that is indistinguishable from the... encrypted blob. [19:03.690 --> 19:07.150] So... all the packets going through the network are identical. [19:07.810 --> 19:08.830] They're all encrypted garbage. [19:09.090 --> 19:10.330] And they're all of the same size. [19:10.970 --> 19:17.770] An adversary can't watch an individual message and... assume that... this message is coming in. [19:17.890 --> 19:22.770] Is that message going out based on the size reduction or... other clever techniques that... [19:23.670 --> 19:25.250] will probably be discussed in the next hour. [19:27.610 --> 19:29.510] There's no real way to get this with PGP. [19:29.730 --> 19:33.210] Which is... why mix master implements its own... encryption scheme. [19:33.970 --> 19:37.710] There's also the concept of tagging attacks, which allow... an attacker to... manipulate the cypher text in such a way that the message will still be... [19:44.170 --> 19:45.290] Decryptable and processable. [19:45.290 --> 19:50.790] But... will have some visible alteration in the resulting plain text... as a message travels through the system. [19:52.710 --> 19:57.290] So that... flipping one bit on a... an encrypted message before it enters... a node... will result in you being able to determine... [20:00.870 --> 20:02.650] which message that was as it leaves. [20:04.530 --> 20:07.550] That is very easy to do with the PGP network. [20:07.990 --> 20:09.510] Still possible with a mix master network. [20:10.750 --> 20:13.510] But... it's... fairly trivial with... the way the PGP message format is designed. [20:16.750 --> 20:21.050] Of course, PGP was designed not as a... a primitive for re-mailer networks... [20:21.050 --> 20:23.170] but as a message encryption... protocol. [20:23.470 --> 20:26.510] So... these are attacks... against PGP... [20:27.590 --> 20:29.550] for a use that it wasn't designed for. [20:29.930 --> 20:31.850] So... it shouldn't be... [20:31.850 --> 20:33.490] I'm not faulting PGP here. [20:33.770 --> 20:37.510] But... this is... just a problem with trying to use... [20:38.490 --> 20:43.110] PGP as a general purpose... PGP which is a general purpose encryption tool... [20:43.110 --> 20:44.310] for a very specific application. [20:47.840 --> 20:48.560] There's... [20:49.560 --> 20:50.900] one major problem... [20:51.960 --> 20:53.540] with... the mixed message network. [20:55.440 --> 20:57.580] For... most threat models... [20:57.580 --> 20:59.220] it is... it is perfectly secure. [20:59.580 --> 21:02.060] There are... incidental improvements... [21:02.480 --> 21:04.380] that are being made on it... [21:04.380 --> 21:07.200] but... the... biggest failure it's had... [21:07.200 --> 21:09.060] is that it has not replaced the type 1 network. [21:09.520 --> 21:12.340] There are still clients... and still re-mailers out there... [21:12.340 --> 21:13.980] which operate the cyberpunk... [21:13.980 --> 21:16.940] network... even though it is... inherently... [21:16.940 --> 21:19.460] very insecure... compared to... [21:19.460 --> 21:21.540] the effort that somebody puts into using it. [21:22.060 --> 21:24.240] And that is... there's no way to do... [21:24.240 --> 21:25.680] return messages in Mixmaster. [21:26.420 --> 21:28.020] Because Mixmaster has the awareness of the replay attacks... [21:32.180 --> 21:33.300] and has built-in... [21:33.300 --> 21:34.620] protection mechanisms... [21:34.620 --> 21:35.240] against replay attacks... [21:35.780 --> 21:36.680] it has no method... [21:36.680 --> 21:37.400] of doing reply blocks. [21:37.960 --> 21:38.520] So... if you want to be able to use... [21:40.400 --> 21:41.380] a NIM server... [21:41.840 --> 21:43.080] based on reply blocks... [21:43.080 --> 21:43.360] like... [21:43.360 --> 21:44.260] the NIM.alias.net... [21:45.060 --> 21:45.620] system... [21:45.620 --> 21:46.620] run at MIT... [21:46.620 --> 21:47.380] you... [21:47.380 --> 21:48.240] are stuck using... [21:48.240 --> 21:49.060] type 1 system. [21:49.780 --> 21:50.820] Because of that... [21:50.820 --> 21:51.420] there are still... [21:51.420 --> 21:51.700] type 1... [21:51.700 --> 21:52.860] and type 1... [21:52.860 --> 21:53.440] clients... [21:53.440 --> 21:53.920] and... [21:53.920 --> 21:54.560] this is... [21:55.540 --> 21:56.100] overall... [21:56.100 --> 21:56.680] a bad thing. [21:57.940 --> 21:59.060] Cypherpunk network... [21:59.060 --> 22:00.260] was based on software... [22:00.720 --> 22:01.100] that... [22:01.100 --> 22:01.840] that... [22:01.840 --> 22:02.740] a couple of hackers... [22:02.740 --> 22:03.300] in the Bay Area... [22:03.300 --> 22:03.720] put together... [22:03.720 --> 22:04.340] in a weekend... [22:04.340 --> 22:05.800] as a proof of concept... [22:05.800 --> 22:07.300] this was back in 92... [22:08.060 --> 22:08.380] and... [22:08.380 --> 22:10.060] it's still being used... [22:11.160 --> 22:12.340] Mixmaster's been around... [22:12.340 --> 22:13.060] since late 94... [22:14.040 --> 22:15.060] it should have... [22:15.720 --> 22:16.660] phased out... [22:16.660 --> 22:18.060] the type 1 system... [22:19.520 --> 22:21.520] because of the... [22:21.520 --> 22:21.920] the... [22:21.920 --> 22:22.960] the... [22:22.960 --> 22:23.740] apparent necessity... [22:23.740 --> 22:24.720] of reply blocks... [22:24.720 --> 22:25.580] for the users... [22:25.580 --> 22:26.780] it hasn't... [22:26.780 --> 22:27.580] it... [22:27.580 --> 22:29.100] is still used by people... [22:29.100 --> 22:30.580] that want to send forward messages... [22:31.540 --> 22:31.920] but... [22:31.920 --> 22:33.040] that is a... [22:33.040 --> 22:33.630] a small minority... [22:35.300 --> 22:36.580] compared to people that... [22:37.100 --> 22:38.360] use the type 1 systems... [22:38.360 --> 22:38.650] reply blocks... [22:39.280 --> 22:39.680] and... [22:39.680 --> 22:40.580] further compared to the people... [22:40.580 --> 22:41.140] that use... [22:41.140 --> 22:42.300] dependent system... [22:42.300 --> 22:43.580] because of its ease of use... [22:44.860 --> 22:45.320] so... [22:46.420 --> 22:47.960] the goal in recent years... [22:47.960 --> 22:49.420] has been to build a system... [22:49.420 --> 22:51.160] which is... [22:52.640 --> 22:53.730] at least as secure... [22:54.120 --> 22:54.780] or more... [22:54.780 --> 22:55.860] than Mixmaster... [22:57.760 --> 22:58.500] that allows the... [22:58.500 --> 22:59.440] utility of... [22:59.440 --> 23:00.620] return messages... [23:00.620 --> 23:01.860] in some fashion... [23:02.300 --> 23:04.580] and achieves a greater ease of use... [23:05.480 --> 23:06.080] Yes... [23:15.820 --> 23:16.520] That's the question was... [23:16.520 --> 23:17.260] What's to prevent encrypting a throwaway email address in your message that you send out through Mixmaster [23:22.000 --> 23:22.820] And then have somebody else manually reply to that. [23:24.860 --> 23:25.500] There isn't anything to prevent that. [23:26.140 --> 23:26.500] However... [23:26.500 --> 23:27.820] it's not automatable... [23:27.820 --> 23:28.940] when a message comes out... [23:28.940 --> 23:29.800] of the Mixmaster network... [23:29.800 --> 23:30.760] it comes out... [23:30.760 --> 23:31.420] as... [23:31.420 --> 23:32.400] the address of the remailer... [23:32.400 --> 23:32.680] saying... [23:32.680 --> 23:34.180] do not reply at... [23:34.180 --> 23:35.020] remailer.org... [23:35.020 --> 23:35.640] or... [23:35.640 --> 23:37.060] what have you... [23:37.830 --> 23:38.240] so... [23:38.520 --> 23:38.900] sure... [23:38.900 --> 23:39.740] you could put in... [23:39.740 --> 23:40.600] your message... [23:40.600 --> 23:41.060] hi... [23:41.060 --> 23:42.340] this is... [23:42.340 --> 23:43.360] deep throat... [23:43.360 --> 23:45.000] you need to contact me... [23:45.000 --> 23:46.040] send me mail at... [23:46.040 --> 23:46.860] this address... [23:46.860 --> 23:47.540] or... [23:48.520 --> 23:49.880] a technique that's used... [23:49.880 --> 23:50.680] fairly regularly... [23:50.680 --> 23:51.040] is... [23:51.520 --> 23:52.620] to give... [23:52.620 --> 23:53.040] the... [23:53.040 --> 23:53.640] correspondent... [23:53.640 --> 23:54.710] a PGP key... [23:54.710 --> 23:55.220] which... [23:55.220 --> 23:56.240] has the address of... [23:56.240 --> 23:57.340] you know... [23:57.340 --> 23:59.220] alt.anonymous.messages... [23:59.220 --> 24:00.120] where... [24:01.100 --> 24:02.660] it's a Usenet group... [24:02.660 --> 24:02.980] and... [24:02.980 --> 24:04.600] you receive encrypted messages... [24:04.600 --> 24:06.020] posted to that Usenet group... [24:06.020 --> 24:07.020] and... [24:07.020 --> 24:07.840] then... [24:07.840 --> 24:08.500] can... [24:09.720 --> 24:10.400] um... [24:10.400 --> 24:11.480] obtain your mail... [24:11.480 --> 24:13.080] in a somewhat anonymous fashion... [24:13.080 --> 24:13.500] however... [24:13.500 --> 24:14.440] there's... [24:14.440 --> 24:15.920] further problems with that... [24:15.920 --> 24:16.400] the... [24:16.400 --> 24:17.440] the first problem of... [24:17.440 --> 24:17.600] just... [24:17.600 --> 24:18.500] I've got a Hotmail account... [24:18.500 --> 24:19.660] that I'm receiving mail at... [24:19.660 --> 24:20.480] again... [24:20.480 --> 24:21.920] you're going there from your... [24:22.350 --> 24:23.540] IP address of your... [24:24.040 --> 24:24.490] home computer... [24:25.000 --> 24:25.500] or... [24:25.500 --> 24:25.840] of the... [24:25.840 --> 24:26.710] the proxy server... [24:26.710 --> 24:27.540] open proxy server... [24:27.540 --> 24:28.020] in Pakistan... [24:28.020 --> 24:28.710] that you found... [24:28.710 --> 24:29.100] or... [24:29.100 --> 24:30.040] what have you... [24:30.040 --> 24:30.900] you're again... [24:30.900 --> 24:32.000] not reaching the security... [24:32.000 --> 24:32.820] that you've achieved... [24:32.820 --> 24:34.240] with the... [24:34.240 --> 24:35.140] type 2... [24:35.140 --> 24:36.260] re-mailer network... [24:36.260 --> 24:36.460] and... [24:36.460 --> 24:37.320] somebody... [24:37.320 --> 24:38.280] watching the network... [24:38.280 --> 24:38.860] can... [24:38.860 --> 24:39.280] observe... [24:39.280 --> 24:40.600] your web traffic... [24:40.600 --> 24:41.360] or... [24:41.360 --> 24:42.960] your email traffic... [24:42.960 --> 24:43.460] and... [24:43.460 --> 24:43.980] determine... [24:43.980 --> 24:44.340] that... [24:44.340 --> 24:50.320] Simply by replying to the throwaway email address, that you are the owner of that email address. [24:51.710 --> 24:55.020] Likewise, the Usenet solution is not the greatest, either. [24:55.820 --> 24:56.940] It's more secure. [24:57.060 --> 25:01.740] However, in order to be truly anonymous, you've got to be behaving like everyone else. [25:02.440 --> 25:04.400] So, people that are down... [25:04.900 --> 25:14.360] In order for this to work, in a perfect world, everyone would download the contents of Alt Anonymous messages every day at the same time. [25:14.960 --> 25:19.040] And they wouldn't cherry pick which messages they wanted. [25:19.120 --> 25:22.360] They wouldn't look for particular messages encrypted to certain keys or certain subjects. [25:22.540 --> 25:23.400] They would just grab everything. [25:23.600 --> 25:32.000] And if all of you grabbed everything, then one person wouldn't stand out as looking for a given message. [25:33.000 --> 25:38.660] In actuality, the way it's going to work is if you're expecting a message, you're going to be checking Alt Anonymous messages. [25:38.660 --> 25:41.600] If you're not expecting a message, you're not going to be checking it. [25:41.740 --> 25:47.400] Or you're going to look at it, get the subject lines, and not ever download anything unless what you want is there. [25:47.600 --> 26:04.180] And you might think you're clever and download a whole bunch of other things at the same time, but an attacker who is watching this behavior can pretty quickly determine when you're downloading and when you're not based on when a certain key is being posted to, et cetera. [26:05.100 --> 26:12.320] So, you've identified the problem there of non-automatability and laziness. [26:13.160 --> 26:15.680] And these are key problems. [26:15.920 --> 26:21.240] Anything that assumes that the system is only anonymous if the user does the right thing is broken. [26:22.040 --> 26:24.460] Systems have to behave properly by default. [26:24.820 --> 26:28.180] There needs to be one standard way of operation. [26:28.880 --> 26:35.040] And in that standard way of operation, everyone behaves the same and everyone does the right thing. [26:35.160 --> 26:37.280] There's no way to turn it off or do it incorrectly. [26:40.420 --> 27:12.820] With Type 2 not having phased out Type 1 after nearly a decade now, the problem has become blatantly obvious that we need to do something about getting rid of this Type 1 network and providing better anonymity solutions, which addressed the problems that Type 2 addresses while preserving a minimum level of functionality that the Type 1 system had, [27:12.980 --> 27:14.400] preferably improving upon that. [27:16.960 --> 27:38.160] Enter the Type 3 network, which is currently one software program called Mixed Minion, which is also written by Nick, implementing a protocol which I'm not going to go into too deeply as well since I'm pressed for time, but it has the... it achieves the main goal, [27:38.210 --> 27:41.120] which is to provide a secure method of doing replies. [27:41.120 --> 27:49.240] So that there's no... there's no longer any... functionality requirement to keep a Type 1 network alive. [27:51.780 --> 28:10.880] However... and in addition, it addresses a number of problems in the Type 2 network that come into play when you have a stricter threat model than just somebody watching messages on the network and observing shrinking packets and so forth, but are nevertheless still rather important. [28:13.780 --> 28:17.160] Nick's attacks talk will cover those in more detail, I believe. [28:18.640 --> 28:19.780] But... you'll try. [28:21.710 --> 28:24.960] Key things remaining are usable clients. [28:25.280 --> 28:33.860] The Type 1 system has been around for almost... for over a decade now, also there's a number of different Windows GUI applications out there for them. [28:34.460 --> 28:41.480] And in order for Type 3 to become fully successful, we'll need to have, again, usable systems. [28:41.620 --> 28:49.400] I'd like to see something far more usable than what we have for Type 1 already, preferably plugins for various mail clients and so forth. [28:49.820 --> 28:53.780] That opens up a whole other layer of logistical problems. [28:53.840 --> 29:05.920] But we are moving toward recognizing, in general, in the privacy and security world, recognizing that usability itself is a security issue. [29:06.320 --> 29:17.320] If users are, A, too daunted by the prospect of using an additional program to preserve their privacy, they're likely not going to use it. [29:17.440 --> 29:19.580] And at that point, the program utterly fails in its mission. [29:19.740 --> 29:22.760] It does not preserve one's privacy at all if it's never used. [29:23.460 --> 29:36.920] And then the second problem of people using programs incorrectly due to bad UI design or the ability to take shortcuts is an existing problem. [29:39.780 --> 29:48.880] I'm going to briefly cover some other... jump back a bit here away from email for a moment and discuss other anonymity systems. [29:50.480 --> 29:55.600] Many of you are familiar with some of the... I'm going to name some programs, and if you can raise your hand if you've heard of them. [29:56.900 --> 29:59.880] Just get an idea of what you're familiar with, and then I'll go into each one in a little more detail. [30:01.600 --> 30:02.640] Have you heard of Freenet? [30:04.480 --> 30:04.800] Okay. [30:05.980 --> 30:06.740] Have you heard of Freedom? [30:07.600 --> 30:08.560] Zero-knowledge Freedom. [30:11.540 --> 30:12.560] The Onion Router? [30:14.560 --> 30:15.540] Fewer hands yet. [30:16.580 --> 30:18.840] What about the Java Anonymous Proxy? [30:19.180 --> 30:20.320] Actually known as Jap? [30:22.280 --> 30:23.160] About the same. [30:26.590 --> 30:30.750] And I think that covers everything that I would expect people to know. [30:32.590 --> 30:40.570] Most of your hands went up for Freenet, which is kind of sad since Freenet makes a lot of claims that are utterly incorrect. [30:42.530 --> 30:52.810] I'm going to skip Freenet for a moment and move on to the Zero-knowledge Freedom System, which is... Okay. [30:53.090 --> 30:53.490] Was. [30:53.670 --> 30:55.670] It's no longer... The network is no longer in operation. [30:55.870 --> 31:02.130] However, the source code is still available for review if a charitable soul wants to start operating one. [31:02.550 --> 31:22.970] Was a packet network-level encryption and anonymity system, which allowed you to do pretty much the same sort of nested encryption and forwarding through mutually untrusted proxy scheme as the email network, only when you're dealing with network protocols files over this, [31:23.110 --> 31:30.350] you have a much higher requirement for low latency than you do with email. [31:30.790 --> 31:44.350] The fact that I'm using an anonymity system for my email and that, therefore, increases the length of time a message can get delivered via email by a day isn't necessarily a problem. [31:45.250 --> 31:55.590] If it takes, you know, an extra half hour, extra 24 hours, I really don't care because my message is still getting through and I'm achieving anonymity as a trade-off for bad performance. [31:56.930 --> 32:07.070] However, I don't think any of us here would be willing to wait a half an hour or a day for our web pages to load or our top three login to happen. [32:07.430 --> 32:20.070] So there are a whole new level of requirements added to dealing with a network-level anonymity system based on the need to do it quickly. [32:22.090 --> 32:34.670] This has the effect of either drastically decreasing the amount of anonymity that you're going to receive or vastly increasing the amount of users you need in order to achieve equivalent anonymity. [32:35.730 --> 32:45.990] Again, the anonymity set is the number of people that are behaving just like you and you are anonymous within that anonymity set. [32:46.670 --> 32:59.690] So with email, it could be every person who's sending within the same rough timeframe that you send with a network-level anonymity system. [32:59.830 --> 33:11.250] It's everyone who is browsing the web at the exact same time you are within, well, again, roughly the same time, which instead of being roughly by a few hours either direction, it's roughly by a few seconds either direction. [33:11.550 --> 33:20.170] So you need to have a constant stream of users on all the time or the ones that are on when few others are on have very little anonymity. [33:21.770 --> 33:28.030] The implicit problems with that should be fairly obvious. [33:29.670 --> 33:49.490] This applies to the onion router system as well, which handles the approach to doing this on a packet level slightly differently, but in effect has the same sort of limitations based on necessity to do things quickly and lack of users. [33:50.710 --> 33:55.670] The zero-knowledge freedom system, I've heard a couple numbers as to how many users they had. [33:55.890 --> 33:59.470] The most frequently spoken number is 30,000. [34:00.110 --> 34:04.110] And that's 30,000 people that paid for their software. [34:04.550 --> 34:09.330] So let's be generous and assume that 10% of their people are on at any given time. [34:10.170 --> 34:14.650] And let's assume that they're always the same 10% that are on at any given time with each other. [34:15.650 --> 34:18.610] So that's 3,000 people you're hiding in. [34:20.970 --> 34:32.870] As Nick will undoubtedly discuss in a few minutes, you can whittle that number down quite quickly by a number of different methods. [34:33.670 --> 34:43.690] And at the end of the day, you probably end up with about this room, about the number of people in this room that you're hiding with. [34:44.450 --> 34:51.270] As a very generous... on a really good day. [34:54.460 --> 34:59.980] So, even though the capacity is 526, we have, what, 40 people in here? [35:02.440 --> 35:08.660] You're not very anonymous then, particularly if external factors can be taken into play. [35:08.920 --> 35:13.400] Suppose you're talking about your experiences with a... [35:16.240 --> 35:23.200] A cult that wants to make sure you don't spill their secret alien abduction recipes. [35:24.640 --> 35:34.160] And half the people in this anonymity set that you're in, in the room, are, you know, happy practicing Catholics. [35:35.400 --> 35:40.720] That's an external factor that eliminates them from your anonymity set that the attacker could potentially use. [35:40.720 --> 35:43.260] It's not based on the technology. [35:46.220 --> 35:56.600] So, often people have suggested, well, if you have an email, you know, why go to all this trouble with the email anonymity systems? [35:56.740 --> 36:01.340] You can just use pop three over freedom. [36:01.980 --> 36:04.680] Now they're saying pop three over Tor, the onion router. [36:05.600 --> 36:09.400] And send all your mail over these lower level anonymizing networks. [36:09.700 --> 36:11.100] And you've solved the problem. [36:11.280 --> 36:13.020] And you don't need to worry about the email anonymity. [36:13.940 --> 36:18.040] The problem here is that you don't achieve the same level of anonymity in a high latency. [36:18.800 --> 36:20.500] Or in a low latency. [36:20.780 --> 36:22.080] In a fast system. [36:22.500 --> 36:25.740] Then you can reasonably expect to achieve a higher latency system. [36:25.860 --> 36:27.740] Which is why we are building these higher latency systems. [36:27.740 --> 36:31.320] Which is why we are, you know, focusing on improving them. [36:31.520 --> 36:36.740] Even though there's simultaneous work on the lower level approaches. [36:37.700 --> 36:57.560] Most people that have a strict threat model to protect their identity when they're corresponding via email are more serious about what they're needing to protect than people that are doing casual web browsing. [36:57.560 --> 37:02.540] Yet don't want their web browsing, yet don't want their web browsing information to be public. [37:03.120 --> 37:13.840] So there's legitimate uses for these low latency systems that don't provide the same level of anonymity as a higher latency system. [37:14.240 --> 37:19.200] But again, it all comes back to what an individual user's threat model is. [37:20.860 --> 37:22.380] Who your attacker is. [37:22.600 --> 37:23.160] Who your attacker is. [37:23.160 --> 37:25.680] What motivation they have. [37:25.840 --> 37:27.040] Why they might be targeting you. [37:27.640 --> 37:29.540] And who your... [37:30.460 --> 37:32.080] What their capabilities are. [37:33.340 --> 37:35.320] So if you have... [37:36.060 --> 37:36.860] If you have... [37:36.860 --> 37:42.080] If your concern is simply hiding your present identity... [37:43.540 --> 37:48.960] Disconnecting your present identity with communications you might be publicly conversing about. [37:49.120 --> 37:51.920] You know, on a mailing list or using that post and so forth. [37:52.260 --> 37:58.220] You don't want a potential employer to link you to discussion about legalizing marijuana. [37:58.940 --> 38:01.740] You might think that using Hotmail would be sufficient. [38:01.920 --> 38:03.040] And in many ways it could be. [38:03.140 --> 38:09.580] However, if you're discussing anything that is now or potentially could become in the future illegal. [38:11.480 --> 38:16.200] The prospect of entrusting your future safety to the presumably inherent anonymity of Hotmail is dubious. [38:23.840 --> 38:29.800] There are logs, there are IP address correlations between accounts. [38:30.620 --> 38:35.920] And your messages could be traced back to you. [38:36.300 --> 38:44.120] However, if your threat model is only incorporating future attackers that are looking at the output of your messages. [38:44.400 --> 38:46.160] A post to a mailing list. [38:46.160 --> 38:47.880] And not monitoring the network. [38:48.040 --> 38:50.700] Not monitoring you actively at the time you're sending. [38:51.040 --> 38:56.840] You have a much less sophisticated attacker than you otherwise might. [38:57.300 --> 39:04.320] So, a system like the type 1 system might be totally sufficient for you. [39:04.720 --> 39:10.320] There's no linking back of your real email address to the fake email address you're using. [39:11.900 --> 39:12.980] as Penet had. [39:14.840 --> 39:17.880] And there's... there is future deniability. [39:18.680 --> 39:20.580] You've sent your mail through the system. [39:20.900 --> 39:21.720] It's been delivered. [39:22.220 --> 39:25.460] And if no one was looking when this happened, you've got what you wanted. [39:25.640 --> 39:27.780] You've got an anonymous posting that's not linkable back to you. [39:29.280 --> 39:30.240] So, yes. [39:37.330 --> 39:38.350] After the fact. [39:40.650 --> 39:44.510] You're hiding... your email address is not being posted at the end of the... the delivery of the message. [39:46.890 --> 39:49.810] However, there are attacks that can happen if... [39:49.810 --> 39:51.230] Again, threat model. [39:51.430 --> 40:00.510] If your potential attacker, your adversary, is someone who is capable of watching the network when you send your messages. [40:00.510 --> 40:02.910] Or is expected to be watching while you're sending messages. [40:04.030 --> 40:09.450] Then there are attacks that come into play that can allow him to determine who is who. [40:10.390 --> 40:26.430] However, if you're merely concerned about someone in the future looking at a mailing list archive and tracing messages back after the fact, type one is really no worse off than anything else out there. [40:29.190 --> 40:32.110] It does strip the email headers. [40:32.110 --> 40:34.170] It does hide your real email address. [40:34.610 --> 40:41.190] But it doesn't give you the same level of assurance that you might want if your attacker is someone like... [40:41.970 --> 40:43.030] Like the NSA. [40:43.350 --> 40:47.730] Who is presumably able to watch message traffic in real time and analyze it. [40:50.290 --> 40:52.010] I'm getting close to time here. [40:52.010 --> 40:53.450] So let's take some questions. [41:04.300 --> 41:10.040] Where even going to a system like this would tip off that you're doing something that you're not supposed to do. [41:10.280 --> 41:18.720] Is there any work that you know of being done for systems that actually allow you to remain anonymous using the anonymity system? [41:18.820 --> 41:21.640] That no one would even know that you are using an anonymity system. [41:21.820 --> 41:26.460] So the question was regarding what happens if you are... [41:26.460 --> 41:27.640] I'm repeating this for the tape. [41:27.640 --> 41:35.960] What happens if you're in a scenario where you not only have to hide your identity, but you need to hide the fact that you're using an anonymity system? [41:36.180 --> 41:37.600] This is referred to as steganography. [41:38.430 --> 41:38.760] You... [41:39.580 --> 41:43.220] The anonymity systems that I've described that we're talking about here don't provide this. [41:43.300 --> 41:46.120] This is a separate security access. [41:50.150 --> 41:59.550] Right now, if you're in a situation where even using any kind of privacy software is going to get you into trouble, there's really nothing you can do about it. [42:00.050 --> 42:09.130] There are a number of projects that attempt to allow covert channel communication, but nothing is practical at this point. [42:09.990 --> 42:17.230] The only thing that you can really hope for is to, again, blend in with a large crowd. [42:17.230 --> 42:25.750] And probably for a Chinese dissident, using Hotmail is likely going to make them stand out less. [42:27.570 --> 42:29.110] Again, who is your attacker? [42:29.290 --> 42:30.110] What is your threat model? [42:30.110 --> 42:57.250] Well, if you're in a jurisdiction of a repressive government who is comfortable with a rough conviction that an anonymous poster belongs to this real life identity and doesn't need 100% proof, you're in a lot worse off position than if you are needing irrefutable proof in a court for a lawsuit. [42:58.290 --> 43:10.190] And if they're willing to round up suspects and put them in jail for an extended period of time because they are quite likely the person they're looking for, but not necessarily. [43:10.830 --> 43:12.790] And they've demonstrated they're going to do that. [43:13.750 --> 43:15.990] It's probably a bad idea to make yourself a suspect. [43:16.470 --> 43:19.050] It's probably a bad idea to use these systems at all. [43:20.670 --> 43:31.170] However, that's a double-edged sword because if people are afraid to use anonymity systems, then no one will, then you have a small anonymity set and you don't blend in with anyone if you decide to use it. [43:32.210 --> 43:46.120] I, of course, encourage people to use the anonymity systems that are out there, but I think we end up talking about the necessity of armed revolution when we're dealing with governments that are that oppressive. [43:48.200 --> 43:51.980] Which is an entirely separate talk and I won't start off on it tonight. [43:52.360 --> 43:52.500] Yes? [43:52.720 --> 43:54.280] Our next question is actually... [43:54.280 --> 43:54.640] Okay. [43:56.700 --> 44:02.270] Earlier, you mentioned the Freenet system and that they've made some claims that perhaps... [44:03.260 --> 44:04.500] Oh, I knew I shouldn't have done that. [44:06.600 --> 44:09.900] I'm just curious if you could go into that a little bit further. [44:11.500 --> 44:24.640] The biggest problem with Freenet isn't even from its anonymity architecture, but the fact that the protocol has changed many times over the past few years. [44:25.860 --> 44:27.620] There's... I don't want to... [44:27.620 --> 44:33.740] This could... I could have an entire talk on problems in Freenet and I don't want that to become what this is. [44:33.740 --> 44:45.740] But, my reason for mentioning it was that the strong anonymity systems that are out there tend to be very cautious about their claims. [44:46.020 --> 44:49.780] Because the more you learn about anonymity, the harder you realize it is to achieve it. [44:49.780 --> 45:05.000] And the more casual, anonymous communication systems that haven't rigorously evaluated their anonymity are more willing to make bold claims about what their systems can do. [45:05.060 --> 45:08.300] Because they haven't realized exactly what their limitations are. [45:08.300 --> 45:21.500] So, when I mention anonymity systems and I mention Freenet and most of your hands go up, it is just an indication of marketing winning out over practicality. [45:25.830 --> 45:32.210] Without naming any names, can you talk about commercially successful anonymity proxies? [45:33.430 --> 45:35.830] Commercially successful anonymity proxies? [45:35.970 --> 45:38.490] Without naming names... [45:38.490 --> 45:41.250] Well, there are a number of... [45:42.790 --> 45:48.290] I'm not sure about successful, but a number of commercial anonymity systems out there. [45:48.430 --> 45:49.170] Which are all... [45:49.170 --> 45:56.770] Which all basically, with the exception of zero knowledge freedom, which is sadly dead due to practicality issues. [45:57.270 --> 46:07.370] The overhead cost of running a low latency network level system when all your users want to download kinky porn all at the same time becomes astronomical. [46:07.370 --> 46:10.910] And if you're charging $30 a year, you can't afford to do it. [46:10.970 --> 46:11.650] So, they shut down. [46:12.130 --> 46:18.830] With the exception of ZKS, all the commercial anonymity providers out there are trusted single-hop proxies. [46:19.290 --> 46:22.130] So, again, we get back to the problems with Pennant. [46:22.310 --> 46:22.970] You have... [46:24.650 --> 46:26.270] A, you have to trust the provider. [46:26.270 --> 46:41.670] You have to believe that not only are they honest in that they're going to be hiding your identity for you, but they also have to not have had their network compromised, haven't been broken into, and had some... [46:42.150 --> 46:45.810] Had your adversary backdoor their system without their knowledge. [46:45.970 --> 46:51.650] So, you can have a truly honest single-hop proxy that's completely worthless to you because it's been owned by the people you're trying to hide from. [46:51.650 --> 46:56.850] And then, of course, there's legal attacks, which I mentioned at the beginning as well. [46:58.330 --> 46:59.450] Which are... [46:59.450 --> 47:14.370] Now, a number of the commercial anonymity providers take steps to be able to avoid in that they aren't able to answer subpoenas because they go through extra measures to hide the identity of their users from themselves. [47:14.990 --> 47:17.410] Again, all this comes down to a matter of trust. [47:17.650 --> 47:23.130] If it is in your threat model that you can trust a third party with your identity, then... [47:25.310 --> 47:31.870] Yeah, you could use them, but you're probably better off using free systems and not paying for them. [47:34.030 --> 47:43.770] At this point, you're probably better off using Tor, the onion router, or something else along those lines, rather than trusting this third party. [47:45.510 --> 47:46.270] Does that... [47:47.190 --> 47:48.950] Did that go where you wanted that to go? [47:51.430 --> 47:53.230] I think you already answered. [47:53.290 --> 48:01.610] I was going to ask you, what is your preferred system if all you're concerned about is, I guess, a mild anonymity while browsing the web? [48:01.610 --> 48:09.910] You're not worried about anyone's significant adversary trying to, you know, recraft your packets, but you just don't want all your information to be flown out there. [48:10.090 --> 48:13.610] You don't want your traffic necessarily to be able to be seen where you're going. [48:13.610 --> 48:18.650] Well, if your threat model was greater and you still wanted to browse the web, I'd say you're out of luck. [48:19.710 --> 48:23.730] So, it's good that you're only mildly concerned and you want to browse the web. [48:25.010 --> 48:32.810] So, you can look at Tor, which in its current state does not have a large number of users. [48:33.210 --> 48:41.950] So, you have to keep in mind that your anonymity set is extremely small, particularly if you have an adversary watching you in real time, rather than somebody who is simply watching on the ends. [48:41.950 --> 48:57.370] If all you're really worried about is hiding your identity from the websites you're going to, you get away with a lot more than if you're worried about hiding yourself from your ISP or from your employer or from the government. [48:57.370 --> 49:06.250] But, your two main approaches are to use the onion router system or to use a commercial anonymity provider. [49:07.010 --> 49:09.490] Have any of you heard of any commercial anonymity providers? [49:09.770 --> 49:09.950] Is there? [49:11.090 --> 49:12.430] There's one hand. [49:15.130 --> 49:15.750] Proxify. [49:16.210 --> 49:18.010] I have not even heard of Proxify. [49:18.250 --> 49:19.170] Do they make money? [49:20.430 --> 49:21.050] Wow. [49:21.810 --> 49:22.830] Congratulations to them. [49:23.090 --> 49:25.490] No one else has heard of any commercial anonymity systems. [49:26.510 --> 49:29.290] That's surprising, sadly. [49:29.670 --> 49:30.530] Other questions? [49:32.090 --> 49:35.290] Have you heard about ProxyChains and what do you think about it? [49:37.910 --> 49:38.570] Describe it. [49:39.070 --> 49:42.450] ProxyChains is a way of doing inline... [49:43.270 --> 49:46.910] You open up one open proxy and you connect to another proxy. [49:47.170 --> 49:53.930] And then through a chain of maybe four or five proxies, you can connect to the site you're trying to go to. [49:54.970 --> 49:56.530] ProxyChains.sourceports.net. [49:56.810 --> 50:01.430] Again, this is depending on who your threat model... [50:01.430 --> 50:08.210] What your threat model is, it's either a cheap way of hiding your IP from a website you're going to or completely useless. [50:09.710 --> 50:16.390] Because if there's no layered encryption, no remixing with other users, somebody watching that just sees where you're going to. [50:16.510 --> 50:17.850] It doesn't matter that you're going through five hops. [50:19.770 --> 50:28.590] On the other hand, if you are trying to hide yourself from a website, sure you could do that. [50:28.710 --> 50:32.050] But I'm not certain why you'd want to do it through five different hops rather than just one. [50:32.250 --> 50:37.350] Because any one of those five can see where you're going to and who you are and then reveal your identity. [50:37.970 --> 50:42.610] In fact, it would probably be better to just pick one that you trust rather than five that you all have to trust. [50:43.330 --> 50:53.710] In a chain system with no encryption, you're not making the bet that at least one of the ones you picked will hide your identity. [50:53.710 --> 50:56.270] You're making the bet that all of them will hide your identity. [50:56.270 --> 51:01.610] This turns out somewhat counterintuitive to realize that using more is worse in that case. [51:01.790 --> 51:08.810] But it turns out that if you're using five of them, you have five times the chance that one of them will reveal your identity. [51:23.760 --> 51:24.200] Right. [51:25.060 --> 51:33.220] The problem is any one of these proxies could look at the traffic you're passing through and figure out what your final destination is. [51:33.960 --> 51:37.760] Whereas with all the other systems, you have layered encryption. [51:38.500 --> 51:43.420] And while one proxy might be bad, and it can look at the... [51:43.420 --> 51:45.980] You know, if it's the first topic, it can see who is sending. [51:46.280 --> 51:49.120] Or if it's the last topic, it can see where those messages are going to. [51:49.440 --> 51:51.340] It doesn't see both at once. [51:51.340 --> 51:57.060] It sees who is sending and this encrypted blob that it knows to pass on to this next top. [51:57.300 --> 52:05.500] It doesn't see what the contents of that blob are, which include the final message and whatever material that... [52:05.500 --> 52:07.880] Routing material in there that determines where it's going. [52:08.040 --> 52:11.440] Either an email address, if it's an email message, or a final website request. [52:12.160 --> 52:17.680] Can you explain the status of Mixed Minion as it is today in terms of development? [52:18.560 --> 52:22.280] I believe I can, and Nick can jump in and correct me since Nick is the developer. [52:23.500 --> 52:28.740] Mixed Minion is in deployed beta right now, correct? [52:29.180 --> 52:29.620] Or... [52:29.620 --> 52:30.140] Alpha. [52:30.880 --> 52:31.320] It's... [52:31.320 --> 52:32.500] What's an alpha? [52:32.620 --> 52:33.100] What's a beta? [52:33.400 --> 52:34.320] It's in a... [52:34.320 --> 52:41.560] It's in a don't trust this for anything really serious at this point because we're still testing it, and the protocol is not 100% solid yet. [52:42.380 --> 52:45.780] But everyone should download it and play with it and report bugs stage. [52:46.080 --> 52:46.460] Yeah. [52:50.080 --> 52:50.680] Um... [52:50.680 --> 52:51.740] What about the API? [52:55.200 --> 52:55.800] Um... [52:55.800 --> 52:56.140] Wait. [52:57.440 --> 52:58.040] No. [52:59.200 --> 52:59.800] Um... [52:59.800 --> 53:01.500] The API is likely to change. [53:02.320 --> 53:02.920] Um... [53:02.920 --> 53:05.760] On the other hand, the command line interface is pretty solid. [53:05.760 --> 53:12.680] All that would need for the API to get stable would be for someone to come up with a nice, clean interface. [53:13.020 --> 53:14.780] It is written in Python right now. [53:14.860 --> 53:20.220] So, if you need it to be written in C, then, um... [53:20.220 --> 53:21.980] You would need to do your own implementation. [53:22.280 --> 53:24.000] There's a full RFC that you could look at. [53:24.440 --> 53:25.040] Not RFC. [53:25.160 --> 53:30.400] There's a spec on an RFC level of detail that you can look at to do compatible implementations. [53:30.400 --> 53:36.600] One of the Mixmaster developers tried, over the course of a couple of weeks, to do a compatible Java library. [53:36.960 --> 53:38.500] And he got it to send messages. [53:38.840 --> 53:40.660] So, it's not a hard protocol to clone. [53:41.400 --> 53:42.380] Nodes, right now? [53:42.520 --> 53:44.400] And speaking of cloning, we're, um... [53:45.100 --> 53:45.460] We're also... [53:46.040 --> 53:49.760] Mixmaster 4.0 is slated to speak the Type 3 protocol. [53:50.200 --> 53:51.620] So, if we interoperate with Mixed Minion. [53:52.020 --> 54:10.780] And the idea is to have a C library, which is based on OpenSSL, which can then be used in other programs, as a linkable library on a cross-platform basis, so that, hopefully, people could be encouraged to write plugins for email clients, and so forth, [54:11.120 --> 54:12.160] that would speak Type 3. [54:13.800 --> 54:16.460] How many Alf Theta nodes do you have right now? [54:18.380 --> 54:19.140] I'll have to... [54:19.140 --> 54:21.460] For Mixed Minion, I'll have to remember the word Alf Theta. [54:22.240 --> 54:22.720] Um... [54:22.720 --> 54:23.200] Let me check. [54:24.900 --> 54:31.620] For the currently active remailer network, the Type 2 network, the Mixed Master network, there's about 50 active nodes. [54:33.300 --> 54:38.640] And about 40 of those, at any given time, are functioning properly. [54:41.180 --> 54:41.700] Yes? [54:41.980 --> 54:42.700] I have a comment. [54:45.610 --> 54:47.370] Are you talking about... [54:50.450 --> 54:53.570] Where you can make high-level calls to Python and C? [54:55.310 --> 54:55.670] Maybe... [54:55.670 --> 54:59.510] Maybe, perhaps, you could use that to accelerate your development for a C library? [54:59.870 --> 55:00.170] Sure. [55:00.270 --> 55:02.410] Anyone who wanted to do that is welcome to. [55:02.510 --> 55:03.290] It's all open source. [55:04.190 --> 55:04.550] SWIG. [55:05.430 --> 55:05.790] SWID. [55:05.970 --> 55:06.230] Thank you. [55:07.410 --> 55:07.910] Oh, man. [55:08.710 --> 55:09.830] Is the network down? [55:10.630 --> 55:11.650] One last question? [55:16.030 --> 55:28.290] Okay, so that was a fairly high-level brief intro to the past 10 years of history of low latency, high latency anonymity systems email. [55:29.090 --> 55:41.930] And then we touched briefly on the lower latency, less secure, but more usable for general purpose applications like web browsing, anonymity systems. [55:42.430 --> 55:53.410] And I guess I will introduce Nick Matheson here, who is going to be talking about attacks on the various anonymity systems. [55:54.150 --> 55:57.330] Yeah, my talk doesn't start for a couple of minutes, but the answer to your question is 39. [55:57.690 --> 55:58.730] And let's give you a hand to Len. [55:58.730 --> 55:58.830] What's going on?