[00:01.120 --> 00:02.460] What was that for? [00:03.820 --> 00:08.320] Pretty good turnout for 8 o'clock on Friday night, I guess. [00:08.940 --> 00:10.160] My name is Bryan Maloney. [00:12.580 --> 00:25.940] I'm going to be giving a talk tonight on rights, cyber rights, and specifically the restriction of free expression on the Internet in places like China and the Middle East. [00:26.720 --> 00:29.320] With me on kind of a last minute thing is Alan Brown. [00:29.780 --> 00:31.040] Alan's a cyber rights activist. [00:31.200 --> 00:36.880] He's going to be starting a group in Russia, a cyber rights activist group in Russia, which is fascinating stuff. [00:37.320 --> 00:47.700] He's going to be chiming in here and there with some more information and he's going to talk a little bit at the end about the efforts of peer-to-peer networking to circumvent some of these talks. [00:48.800 --> 00:51.520] Okay, so I apologize. [00:51.740 --> 00:56.720] My original manuscript and slides got screwed up and I kind of have to read from the script here. [00:57.920 --> 00:59.080] Can everybody hear me? [01:00.120 --> 01:00.620] Great. [01:01.800 --> 01:04.820] Okay, so the purpose of my talk is twofold. [01:04.900 --> 01:12.520] I kind of want to give you some facts on Internet censorship, surveillance, and suppression by world governments, and mildly abetted by corporations. [01:13.820 --> 01:15.940] The problem of Internet regulation is not new. [01:16.100 --> 01:23.180] As early as 96, Human Rights Watch was already warning of government efforts to filter block content on the Internet. [01:24.080 --> 01:36.480] The other goal of this talk is to help identify ways, as I said, to circumvent particular access denial tactics induced by governments around the world, and to suggest methods to better allow information to flow in places where it's . [01:38.560 --> 01:45.040] I don't know if many of you guys were at H2K, but I gave a talk there about feasibility of a purely online nation. [01:45.140 --> 01:52.660] The idea that ignoring raw materials and food, all the nation's critical resources can be contained, monitored, and sustained online. [01:52.860 --> 01:55.140] Securing borders is as simple as securing a network. [01:55.880 --> 01:59.500] The trick is, how do you secure the servers that secure this nation? [02:00.260 --> 02:03.480] Indeed, there's a salient point in one that is underscored here in the stock. [02:05.620 --> 02:13.140] Online communication, communication between people and groups in various parts of the world, not necessarily right next door is nothing new. [02:13.380 --> 02:23.400] While ARPANET was still a secret known only to the military, people were calling out bulletin boards, chatting, playing games, seeking out mainframes, public assets, public access ports to try and crack. [02:24.360 --> 02:26.600] Usenet's been alive and well since well before I was born. [02:26.920 --> 02:32.160] Publishing all sorts of bizarre, fascinating, disturbing, annoying, and enlightening material, I'm still going strong. [02:33.380 --> 02:44.240] And beyond the occasional legal trouble for a couple of rabble-rousers and a few bad movies that played on publicized fears, not a whole lot happened with Usenet or the BBS system. [02:44.540 --> 02:47.840] At least, not much except what can draw us here. [02:49.020 --> 02:58.300] But then the web tour snuck up on us and the pretty graphics and flash and extensive options for all sorts of crazy schemes captured the public's imagination. [02:58.680 --> 03:01.700] People began rabid coding and began rabid buying. [03:02.320 --> 03:04.040] Venture capital cash started flowing. [03:04.280 --> 03:10.380] IPO underwriters started pushing e-spatulas.com on the stock market and the rest is, well, you know what happened. [03:11.280 --> 03:16.960] Despite the recent burst of the net bubble, the journal is gleefully reporting on one .com failure after another. [03:17.280 --> 03:20.680] The web perseveres and the web continues to inform for those who seek it out. [03:22.400 --> 03:25.060] Ultimately, the net's appeal has always been its decentralization. [03:25.200 --> 03:25.860] That's the whole point. [03:26.520 --> 03:33.020] It's the most successful example of peer-to-peer networking that's based on a relatively simple, robust communication protocol. [03:33.540 --> 03:38.980] The network was designed to survive the most deadly and destructive assaults imaginable and continue functioning. [03:39.760 --> 03:43.680] It's this resistance to destruction that also makes it a real headache for governments to regulate. [03:44.240 --> 03:48.200] Take away a government's power to dismantle, destroy, neutralize in one fell swoop. [03:48.340 --> 03:52.820] And their abilities to curb behavior they deem undesirable or significantly reduced. [03:54.180 --> 04:00.340] It was this resistance to attack and regulation that gave the global network, the world wide web, the information superhighway, its massive appeal. [04:00.340 --> 04:01.100] There were no rules. [04:01.240 --> 04:10.460] And because interactions on the web occurred across state and sometimes national boundaries, it was tremendously difficult to apply historical legal precedent to a system that really has no precedent. [04:11.060 --> 04:14.080] All manner of human interaction sprung up as quickly as the code could be written. [04:14.360 --> 04:18.960] Chat rooms, game sites, peep shows, department stores, grocers, accountants, casinos. [04:19.760 --> 04:20.840] Legislators were overwhelmed. [04:21.000 --> 04:30.340] Not only was the system without precedent, understanding its basic structure barred knowledge and skills largely alien to men and women trained in law, public administration, and business. [04:33.880 --> 04:38.620] Seemingly all of a sudden, the people with the real power were the people like us, the people of good code. [04:39.400 --> 04:41.580] The nerds and the geeks finally had their day. [04:43.280 --> 04:48.420] Then came the visionaries, men like Guy Kawasaki, Mark Andreessen, and hundreds of imitators, John Kett. [04:49.120 --> 04:52.560] Proclaiming the new way of the world of business, culture, and yes, of government. [04:52.840 --> 04:56.780] The free flow of information would finally break the iron curtains of totalitarianism. [04:57.380 --> 04:59.300] Democracy would no longer be denied. [05:00.420 --> 05:05.520] The heyday of this great prognosticating was sometime around 96 to maybe 99. [05:06.020 --> 05:07.160] It's been a few years. [05:07.220 --> 05:07.920] Has much changed? [05:08.500 --> 05:09.440] Not a whole lot. [05:10.240 --> 05:16.180] China is still a repressive regime that jails people for actions so bold as remembering the victims of the Tiananmen Square massacre. [05:16.880 --> 05:21.240] Teenagers in the Middle East sneak off to discos because dance music is forbidden in some countries. [05:21.960 --> 05:27.560] Poverty is rampant and people are so hopeless they believe and cling to religious leaders preaching murder. [05:28.860 --> 05:30.480] Hasn't the free information sunk in? [05:30.600 --> 05:31.360] Hasn't it got there? [05:31.620 --> 05:32.500] Haven't they seen it? [05:32.500 --> 05:37.560] Aren't they organizing in chat rooms sending encrypted, encoded messages to each other fomenting revolution? [05:37.780 --> 05:38.200] What happened? [05:39.780 --> 05:41.400] Government learned how to use a computer. [05:43.120 --> 05:51.100] I'd like to talk to you about... I'd like to present some facts and figures about the incarnation of the internet and a couple of basic censorship hotspots. [05:51.880 --> 05:56.620] China, the Middle East, and we're going to talk a little bit about Western Europe and the United States. [05:56.620 --> 06:12.060] It's by no means meant to be comparable to restrictions in places like China, but rather it's meant... presence is meant as a sort of reference, so we'll definitely discuss some regulations, past, present, and future, potential and actual in these areas of the freest internet access. [06:13.580 --> 06:14.640] Let's start with China. [06:16.320 --> 06:22.900] Current estimates have the People's Republic of China as the nation with the second largest online population to the United States. [06:23.460 --> 06:29.540] Approximately 57 million people in China have net access at home, and growth is seen at 50% every six months. [06:29.760 --> 06:38.940] Some estimates say that China's... that a quarter of China's one billion plus citizens could have home net access by 2006, about 250, 275 million people. [06:40.240 --> 06:54.100] The Chinese government officially places a ban on information on the internet that qualifies as, quote, rumors, libels, subversion, sabotage of national security, promotions of cults, and feudal superstition, pornography, violence, and gambling. [06:55.400 --> 07:01.660] There aren't really any more definitions beyond that, leaving tremendous latitude for government agencies to interpret this as they please. [07:01.660 --> 07:08.460] The People's Republic of China employs almost every tactic imaginable to stifle from software to hardware to guns. [07:09.740 --> 07:13.740] Recently, they established the Internet Propaganda Administrative Bureau. [07:14.080 --> 07:17.120] It was tasked with policing the internet and punishing offenders. [07:17.480 --> 07:32.180] In concert with this, the state security ministry started circulating voluntary self-discipline agreements to internet cafe owners that they were expected to sign, in China, saying, in part, that they would report all users who search on terms and ideas that were forbidden in China. [07:32.760 --> 07:36.920] Another part of this voluntary agreement called for the installation of filter software. [07:37.580 --> 07:52.040] A particular piece of software called Guo Lu Wang, or Internet Cafe Management Specialist, not only blocks access to some 500,000 sites, but it also records the user's actions and sends a log to local police officers to investigate. [07:53.500 --> 08:01.080] In concert with this and other similar software efforts, like software called FilterKing, this didn't seem to work well enough. [08:01.580 --> 08:10.080] And a few years ago, the People's Republic of China contracted with Cisco to provide them with specialized routers to help facilitate the blacklisting of internet sites. [08:10.800 --> 08:19.360] Cisco officials won't comment on the full capability of these routers, but among other things, they block access to sites like CNN.com and the BBC, as if they didn't exist. [08:19.360 --> 08:23.440] Users get a 404 error, police get a log of their activity. [08:24.180 --> 08:34.320] These routers, which would retail for about $50,000 according to Cisco, China spokesman David Zhu, were sold, with the assistance of IBM financing, for about $20,000 apiece. [08:35.320 --> 08:37.380] And word is these routers are everywhere. [08:39.040 --> 08:44.860] And then China does not strictly rely on hardware and software filtering to keep people from doing subversive stuff. [08:44.860 --> 08:51.500] In 2001, approximately 17,000 internet cafes in China were shut down for violating licensing conditions. [08:52.040 --> 09:02.860] And in 2000, a man named Huang Qi was arrested, not long after giving an interview to the BBC, for allowing posted articles on his website that commemorated the Tiananmen Square Massacre. [09:03.740 --> 09:08.540] He was found guilty last August and is still waiting a sentence of up to 10 years in prison for subversion. [09:10.180 --> 09:11.080] For years, U.S. [09:11.180 --> 09:20.680] companies doing business with China have been in a unique position to take the PRC to task on the human rights violations and open up the net to the free flow of information. [09:21.260 --> 09:26.080] But as Cisco and IBM have shown, corporate ethics are just the same today as they were a few years ago. [09:28.160 --> 09:30.260] So let's move on to the Middle East. [09:30.760 --> 09:35.560] This is a region heavily dominated by socially conservative forms of Islam. [09:35.860 --> 09:41.900] And governments here have a vested interest in insulating their citizenry from information they would find contradictory to Muslim culture. [09:44.880 --> 09:51.120] Being dictatorships, they also seek to protect their regimes from their subjects discovering dissenting viewpoints. [09:52.140 --> 09:58.900] Accessibility and implementation varies from nation to nation, but nearly all Middle Eastern nations heavily filter and block Internet data from reaching their citizens. [10:00.500 --> 10:06.300] Saudi Arabia, which has the largest online population of the area, nearly 125,000 people, among my figures. [10:08.800 --> 10:15.380] They first got connected in 1994, though usage was restricted to state academic, medical, and research institutions. [10:15.960 --> 10:21.760] King Fout officially approved access for the public in 97, but it didn't reach the population at large until 1999. [10:22.180 --> 10:29.060] The reason being they were trying to figure out a way to prevent people from seeing some of this nasty stuff out there on the internet. [10:31.400 --> 10:34.600] What they came up with was a sort of national gateway system. [10:34.740 --> 10:41.120] Though there are still private ISPs, all internet connections lead to a proxy server at King Abdulaziz's City for Science and Technology. [10:42.300 --> 10:49.800] Here, a 500-gigabyte storage system caches pages that have been officially approved by Saudi sensors for public consumption. [10:50.720 --> 10:56.480] Requests for pages not in the cache system go to a second system where software provided by WebSense, a U.S. [10:56.600 --> 11:01.460] company, applies filter rules of up to 30 categories of unsuitability. [11:02.460 --> 11:06.440] Assuming the page request passes this filter, the page is returned to the user. [11:06.680 --> 11:08.540] Otherwise, file not found. [11:10.300 --> 11:22.360] The United Arab Emirates runs a similar gateway system, and Tunisia has specifically, has gone a further step in, specifically legislated that internet usage falls under their existing press laws that limit freedom of speech. [11:22.820 --> 11:27.600] Anything you can publish using a hand press, you can publish on the net, anything you can't. [11:27.880 --> 11:28.460] It's the same thing. [11:29.100 --> 11:39.700] Syria doesn't even allow public citizens access to the internet, nor does Iraq, though they say they don't have net access at all due to communications infrastructure damage due to the Gulf War. [11:41.040 --> 11:50.700] And although countries like Jordan and even Bahrain and Morocco don't officially censor, block, or filter the internet, taxes and surcharges make it very expensive to the average user. [11:54.370 --> 12:06.730] So, obviously, compared to places like China and Saudi Arabia, the U.S. and Western Europe are bastions of freedom of information compared to these places. [12:06.730 --> 12:13.730] You can find all sorts of stuff, even through corporate firewalls and hotel firewalls. [12:14.970 --> 12:18.150] That's not to say freedom of information and privacy are beyond threat. [12:20.090 --> 12:32.110] For example, the French authorities in 1991 admitted that the DGSE, the French CIA equivalent, performed, quote, certain telephone wiretaps that are not directly linked to the objective of preventing penal crimes. [12:32.430 --> 12:37.210] In other words, they're phishing expeditions to gather information on citizens under no suspicion of wrongdoing. [12:37.790 --> 12:46.150] It's not beyond reason to suggest that in the ten years since, such wiretaps extend to email, chatroom, and other data transmitted across the web. [12:46.970 --> 12:58.350] The German FIS, which is also an intelligence agency, also works with the DGSE, sharing information should a wiretap subject decide to cross the border. [13:00.290 --> 13:01.450] But that's Western Europe. [13:01.550 --> 13:02.090] What about here? [13:02.710 --> 13:04.330] Well, we all know about carnivore. [13:05.410 --> 13:11.230] Two or three years ago, the Department of Justice raised controversy with this hardware software device used as a wiretap on email. [13:12.630 --> 13:13.630] Despite the U.S. [13:13.930 --> 13:22.310] Supreme Court agreeing that the system, which can only be used on a court-ordered wiretap, what violated no section of the U.S. [13:22.390 --> 13:26.990] Constitution, privacy advocates still agree that it's a threat to gathering information of non-suspects. [13:28.590 --> 13:29.810] Nevertheless, the U.S. [13:29.850 --> 13:38.050] has enjoyed a fairly free web, thanks in part to the near-complete lack of regulation in the sphere of packet-switch networks. [13:40.110 --> 13:43.690] It's interesting to notice, and what a lot of people don't notice, this almost never came to pass. [13:44.710 --> 13:54.610] In the early 1990s, as Cisco began to assert its dominance in supplying the routers that make the Internet work, Lucent began competing for their same business using their telco switches. [13:56.050 --> 14:06.930] Cisco eventually won this market battle, but it was a near-miss, because due to the way the law is written, using Lucent switches on large backbones would have placed the networks using them under existing telco law. [14:07.950 --> 14:20.030] Thus, the regulation that governs AT&T and WorldCom and Sprint would have extended to everybody's Internet usage. [14:21.590 --> 14:24.590] So, the free web dodged a bullet, thanks in part to Cisco. [14:27.430 --> 14:29.490] So, I guess I'm moving kind of fast here. [14:32.570 --> 14:37.310] So, with all this kind of bad news, I guess the question is, is there hope? [14:37.890 --> 14:44.590] You know, can we get, can people in these countries get information that they have a right to, that they're entitled to? [14:46.830 --> 14:53.830] Yes, but it's not, obviously not going to come through, come with the blessing of the governments. [14:54.410 --> 14:59.510] So, people have to find new ways of circumventing, circumventing restrictions. [15:01.110 --> 15:04.650] An option that seems to be on the rise in the Middle East is the use of satellite dishes. [15:05.610 --> 15:11.810] Dishes that are about the size of your average direct TV satellite dish, while expensive, are starting to gain popularity and use throughout the area. [15:11.810 --> 15:18.970] Because these are satellite dishes, they, it's impossible for the government to monitor the communications. [15:20.350 --> 15:27.930] For circumventing the national gateway systems, like in Saudi Arabia and the United Arab Emirates, another expensive but more readily available option is foreign dial-ups. [15:28.130 --> 15:34.770] There's no restriction on people hooking up their modems and calling up France or Crete or Cyprus to get out to the net. [15:35.610 --> 15:38.670] Though in some places rates can run as high as 80 cents a minute. [15:39.550 --> 15:43.990] Private users are finding this to be an effective way to get to sites that are blacklisted by the government. [15:45.850 --> 15:53.770] So, far simpler, but more likely to be restricted as well, and it can be anyway, are things like anonymous remailers like anonymizer.com. [15:53.990 --> 15:58.930] Though, anonymizer is said to be blocked by the PRC according to anonymizer's precedent. [16:01.090 --> 16:13.950] Also, the use of encryption and the expanding use of steganography or encrypting data and other data formats are probably the best bet to be pushed for users in an area where surveillance is rampant if they want to get information that is restricted to them. [16:15.530 --> 16:25.210] One of the key aspects often overlooked in determining which nations have free internet access and others is the amount of control the national governments have over the telecommunications infrastructure. [16:25.690 --> 16:35.050] In the U.S., despite reasonably heavy regulation and re-regulation, the FCC plays more of a referee role than that of a regulator, especially in regards to the content on provider systems. [16:35.770 --> 16:44.810] Contrast this to places like China, Saudi Arabia, or the United Arab Emirates, where telecommunications systems are under direct control of the national government and are a function of the government. [16:45.530 --> 16:53.670] It was a simple matter for Saudi Arabia to establish a gateway system at King Abdulaziz city for science and technology when they own and run the telecom infrastructure. [16:54.610 --> 16:56.830] Of course, there are notable exceptions to this rule. [16:57.770 --> 17:03.010] Egypt, which has allowed a modicum of privatization in the telco system, still maintains a national gateway. [17:03.010 --> 17:14.050] And France, despite essentially creating Minitel, a sort of high-speed use net, built in randomizer functions that protect a user's privacy and they still do not officially monitor that system. [17:16.090 --> 17:19.390] Freedom of information and freedom of choice exist in sort of a feedback loop. [17:19.910 --> 17:22.590] The freedom of the net would never have occurred without the freedom of the U.S. [17:22.670 --> 17:27.350] and Western cultural values of free expression, open debate, and judicial oversight of government. [17:28.410 --> 17:32.470] These places like China and Saudi Arabia have no freedom of choice. [17:32.470 --> 17:37.930] The trick is to figure out how to expand freedom of choice using the rapidly shrinking freedoms of information. [17:39.930 --> 17:48.690] So I guess ultimately the question is, so can we, the people, the governed, find a way to keep our communications private and secure from government intervention on our own? [17:49.730 --> 17:50.170] Unlikely. [17:50.290 --> 17:55.370] Unless people stand up for privacy, encryption, and data security, governments of the world will likely be calling the shots. [17:57.530 --> 17:59.590] So that's a little bit, that's pretty much all I had. [17:59.710 --> 18:03.570] I wanted to open up the floor to Alan, who's been, who's been a little silent. [18:03.770 --> 18:06.310] I'm afraid I've been stealing a little too much of the thunder here. [18:06.570 --> 18:09.170] Alan's going to talk a little bit about peer-to-peer networks. [18:10.150 --> 18:13.970] Yeah, I can make a couple of comments about what you said. [18:15.890 --> 18:18.830] You're a little more optimistic than I am, I'm afraid. [18:20.790 --> 18:29.750] I would like to, I would like to hope that by virtue of people standing up for their rights, that that will make a difference. [18:31.530 --> 18:34.650] There hasn't been evidence of that recently, I'm afraid. [18:35.450 --> 18:38.150] GILC, for example, I'm in the GILC circle. [18:39.650 --> 18:47.210] We've had some effect through organizations which actually will take, for example, the government to court, groups like the ACLU. [18:47.610 --> 18:51.850] But for the most part, GILC has had almost no impact at all in Europe. [18:53.690 --> 19:03.190] They've made statements and they've gotten a different opinion out to the public, and that is crucial that people see that there is at least controversy about these issues. [19:06.450 --> 19:19.290] But I think that there have to be methods of communicating which it will be up to, for example, people at this conference probably to try to develop. [19:19.790 --> 19:22.510] I want to say a couple of things about Peer-to-Peer. [19:23.490 --> 19:27.010] I developed a system in Peer-to-Peer which has actually never been built. [19:28.110 --> 19:32.430] But it got published a little while ago, and I still think there are some good ideas in it. [19:32.550 --> 19:42.270] But I want to tell you, by contrast, what most people are doing with Peer-to-Peer and what, in my experience in human rights, absolutely will not work. [19:43.370 --> 19:51.850] There's currently the view, and I talked to some people at, for example, Freenet about that, who believe that their project is an anti-censorship device. [19:52.590 --> 19:59.190] And I can see why they say that, because they're dealing with at least anonymity in one sense. [19:59.910 --> 20:13.450] But the problem, and please take this seriously, because this is going to get people killed on the other end of these firewalls, the issue is not whether the message gets through anonymously. [20:13.450 --> 20:23.870] The message is whether the poor bastard sitting at his computer somewhere in China knows how to protect his computer well enough so that he's not hacked. [20:25.110 --> 20:31.770] China arrested some guy and put him in jail as a result of hacking a foreign website in order to get data on him. [20:32.310 --> 20:35.610] There's no reason that's not going to happen with Peer-to-Peer. [20:36.150 --> 20:40.050] The Chinese government has not waited for things like warrants. [20:40.050 --> 20:43.510] Suspicion is sufficient to arrest you in China. [20:44.410 --> 21:02.210] And one thing that I think we're going to see a lot of is that while we're over here on the so-called free side of the firewall, coming up with these very clever... and for example, CDC has an extremely clever peer-to-peer program that they're planning to launch pretty soon, [21:02.270 --> 21:05.410] as I understand, maybe they'll mention it at this conference. [21:06.210 --> 21:18.650] It involves a very small client which, when this client is on the other end of the firewall, will permit in their estimation a method of anonymous communication. [21:19.350 --> 21:23.390] One problem, of course, is how the hell are you going to get this client into China? [21:23.890 --> 21:38.250] The other problem is, once it's into China, I hope it's nothing like Freenet, which ends up putting an icon on the desktop, the Chinese government is not going to be that stupid that they can't find out who's running a peer-to-peer program. [21:38.890 --> 21:44.330] They're not going to wait and try to see if there's some anonymous message they can crack. [21:44.490 --> 21:47.250] They're going to come into your house and see what's on your hard drive. [21:47.250 --> 21:50.290] This is not a computer issue. [21:50.730 --> 22:01.570] This is an issue of how well you can protect your own ass, knowing that they're not going to use civilized due process to find out if you're guilty or not. [22:02.190 --> 22:14.430] What I recommend, and you can take the project that I came up with called Red Rover seriously or develop one of your own, is that I think we need to start working on something that could be called clientless peer-to-peer. [22:14.630 --> 22:20.070] We need a way of using computer technology where it's efficient and where it truly is anonymous. [22:21.110 --> 22:28.190] And we need to recognize that what counts as anonymity for us does not count as anonymity in other places. [22:28.410 --> 22:31.930] There are absolutely at least two senses of anonymity going on. [22:31.930 --> 22:35.570] People who do programming know one sense. [22:35.930 --> 22:40.050] People who do mathematics know a sense which is derivative on that. [22:40.290 --> 22:42.110] You know, it's not quite the same. [22:44.250 --> 22:55.470] But if you're in China and your life depends on whether or not anyone's going to find out about it, that's not the sense of anonymity that we use when we're worried about whether or not our boss is reading our email. [22:55.730 --> 22:57.070] This is a completely different game. [22:58.810 --> 23:15.250] So, for at least one point, what I'd like to recommend is that if you want to find a solution to getting information through firewalls, you have to assume that the same security problems are going to plague peer-to-peer, that have plagued the web and plagued the email. [23:16.270 --> 23:24.130] My own position is that if you're going to try to get information through, you should try to use the least technical tricks that you know. [23:25.430 --> 23:28.170] I've been saying for a long time that if there was a way... [23:28.170 --> 23:31.330] You know, you can read the peer-to-peer proposal I made. [23:31.450 --> 23:33.810] It was in the Andy Orm book a couple of years ago. [23:34.190 --> 23:42.630] But the thing is that to the extent that you look like you're not doing anything sneaky, you're going to be better off. [23:42.810 --> 23:52.490] When in a country where the very notion of cryptography is something that is enough to get you into jail, you don't want to play around with things like steganography, at least in my opinion. [23:52.490 --> 23:57.690] You know, we're going to debate this until we finally get some real-life testing on them and see if people get killed or not. [23:58.570 --> 24:02.910] There was triangle boy, but triangle boy, to my knowledge, never really got used. [24:03.930 --> 24:05.310] I mean, that's a whole other thing. [24:05.590 --> 24:07.830] You go ahead, you create a peer-to-peer program. [24:08.050 --> 24:09.950] You've got to get people to want to use it. [24:11.670 --> 24:13.690] This is completely an open issue right now. [24:13.790 --> 24:17.550] And the fact is that there is no peer-to-peer program that's been tested under these conditions yet. [24:17.550 --> 24:21.950] I absolutely would not recommend anybody resting their freedom on this issue. [24:23.710 --> 24:31.890] If... if I can... if I can say a word about ECHELON also... I... question? [24:38.160 --> 24:38.820] Well... [24:38.820 --> 24:41.780] The question is why are you worried about steganography? [24:43.540 --> 24:44.660] I... steganography... [24:45.600 --> 24:49.640] First of all, at least to my knowledge, you can always spot steganography. [24:49.920 --> 24:58.420] I mean, unless you're... unless you are very keen about what kind of background picture you're using. [25:03.730 --> 25:05.530] Could you come up to the mic there? [25:06.470 --> 25:10.810] It would just... we can't really hear you and it also gets you on tape. [25:11.210 --> 25:13.110] Sorry to... you know... calling you out. [25:14.330 --> 25:15.690] Things like Outcast? [25:15.990 --> 25:16.750] Or is there... [25:17.850 --> 25:19.310] Or MP3 Steg? [25:19.930 --> 25:20.770] No, that... [25:21.290 --> 25:22.890] You're still not using the mic. [25:23.190 --> 25:23.670] Maybe you should... [25:25.470 --> 25:26.030] Okay. [25:26.510 --> 25:30.910] Things like MP3 Steg or Outcast or even the Linux file system. [25:30.910 --> 25:31.550] Mm-hmm. [25:32.010 --> 25:32.410] Implemented. [25:32.670 --> 25:33.350] Things like that. [25:34.470 --> 25:35.390] Wouldn't be secure? [25:36.010 --> 25:36.230] Well... [25:36.230 --> 25:37.810] Wouldn't be hidden enough? [25:37.930 --> 25:42.130] Look, I mean, what we noticed is something very similar to, I think, what Arthur C. [25:42.230 --> 25:45.190] Clarke noticed, which is that it looks... it looks wonderful to us. [25:45.270 --> 25:46.390] It looks magical to us. [25:46.510 --> 25:49.790] But the thing is, these things are going through servers and being traced. [25:50.070 --> 25:56.210] And we don't know that in a couple of years there isn't going to be a crack to these things, which is going to enable all these people to get rounded up again. [25:56.510 --> 26:00.410] Yeah, as far as I know, there are already some... some software that... [26:00.410 --> 26:04.190] can spot some basic steganography protocols. [26:04.510 --> 26:11.530] So, you know, there's nothing to say that this stuff can't be simplified and, you know, put in as a process on a router. [26:11.830 --> 26:13.310] Oh, I mean, the simpler ones can. [26:13.570 --> 26:22.550] But, I mean, developing it to the point where you have algorithms and steganography like RSA or Algamal, where you feel confident that it's not the problem that they're going to get cracked. [26:24.650 --> 26:27.230] Well, I wouldn't bet my family on that. [26:27.450 --> 26:34.770] I mean, the issue is, it's not just a matter of whether or not this is an uncrackable encryption. [26:34.770 --> 26:38.110] It's whether or not it can be detected as encryption as well. [26:38.610 --> 26:45.770] It's also a matter of whether or not the actual behaviors that permit you to do the encryption can themselves be detected. [26:46.230 --> 26:48.190] I mean, Zimmerman was keen on this. [26:48.290 --> 26:53.110] Zimmerman said, look, you know, my PGP is going to work great, but just know you've still got to hide your keys somewhere. [26:53.510 --> 26:54.190] You know what I mean? [26:54.310 --> 26:54.470] Right. [26:55.290 --> 26:56.770] Look, I hope it happens. [26:57.150 --> 27:01.190] I mean, I'm not pessimistic to the point of saying we need to stop trying on this. [27:01.190 --> 27:08.050] But the thing is, there isn't, to my knowledge yet, a form of cryptography or a form of... [27:08.050 --> 27:13.550] I mean, I don't consider steganography cryptography per se, but I mean, it's just a real cool thing. [27:13.890 --> 27:23.110] But there's nothing yet that is in some sense so private that other people in the same community don't know what's going on with it. [27:24.610 --> 27:29.570] There's a notion of privacy here that I feel needs to be incorporated better into this community. [27:29.830 --> 27:36.270] And that is that anonymity cannot mean that you're, in some sense, an island. [27:36.710 --> 27:47.310] I mean, people who end up putting, for example, passwords into their programs hoping nobody can crack it don't realize that the same other people know how to find these passwords out. [27:48.830 --> 28:05.630] And so, I mean, I guess what I would say about this is that if you really trust that the same people who are creating this software are not met in a peer-like method with the same levels of intelligence trying to crack the very problem that you think you've solved, [28:05.870 --> 28:07.850] I think that's a very dangerous assumption. [28:08.770 --> 28:14.850] There is no crypto that is not reversible in a sense in which it is massively used. [28:14.850 --> 28:33.150] Now, nobody's going to take the trouble to do it, but I would really recommend that if you're going to make a program that's going to require you to have a fingerprint on your hard drive of this program or of this process, that you need to look at not just whether or not you have a good algorithm. [28:33.610 --> 28:41.350] You have to really cover your tracks, I mean, cover your lifestyle, so that you don't end up becoming, in some sense, suspicious. [28:42.190 --> 28:42.590] Right. [28:43.050 --> 28:46.870] I mean, ultimately, that's like the issue, especially with a place like China. [28:48.110 --> 28:55.070] It's not so much that they can't read the message, so they're going to give you the benefit of the doubt. [28:55.390 --> 29:05.350] If they see that you're sending a whole lot of encrypted stuff or you're getting a whole lot of images that look kind of weird, they're going to start to get suspicious and they're going to focus a bit more energy. [29:14.260 --> 29:14.740] Hi. [29:14.880 --> 29:22.540] You spoke about Cisco making those routers and IBM financing to create that gateway for China. [29:22.680 --> 29:31.100] Is there any other companies that you know of that have assisted in the censorship of these countries? [29:31.100 --> 29:37.080] Not to my knowledge, the Cisco one was pretty... that one was kind of famous. [29:37.260 --> 29:42.880] The BBC somehow got winded that and they did a pretty good story on it. [29:43.400 --> 29:50.700] I wish I remembered where it was, but part of this... the way it was implemented was... [29:50.700 --> 30:10.620] I don't know, they wouldn't... obviously they wouldn't say what the full capabilities of it, but an American working in a Chinese news agency office checking his Hotmail account would see words like Taiwan and Falun Gong and insurrection and cult highlighted in his text. [30:10.840 --> 30:14.240] Almost like, we know what's being said. [30:15.140 --> 30:20.600] So I mean, yeah, the Cisco one was the only one I've been made aware of. [30:24.500 --> 30:28.040] I guess in the world, everybody's money is as good as everybody else's. [30:28.440 --> 30:42.440] And, you know, if a company is approached by, you know, a China or Saudi Arabia saying, hey, make us these routers that do this cool stuff, you know, I wouldn't be surprised to hear about other instances of it. [30:43.160 --> 30:44.360] Do you know? [30:47.560 --> 30:48.800] I'm sorry, could you... [30:48.800 --> 30:49.580] NetScreen. [30:49.920 --> 30:50.480] NetScreen? [30:50.640 --> 30:50.860] Yeah. [30:53.080 --> 30:54.260] NetScreen in California? [30:54.580 --> 30:54.720] Yeah. [30:54.820 --> 30:57.500] Could you come up to the mic and tell us a little bit more? [30:58.760 --> 30:59.060] Yeah. [30:59.560 --> 31:16.980] I just heard there's a company in California called NetScreen that makes filtering devices sold mostly to China, and not tell us sold a lot of data or routers to China. [31:17.580 --> 31:18.400] Oh, that's great. [31:19.300 --> 31:21.660] There was one a couple of years ago. [31:21.720 --> 31:24.460] I don't remember the name of the company, but they came out of Elmira, New York. [31:24.820 --> 31:29.600] And they claimed that they could actually spot pornography in photographs. [31:29.600 --> 31:34.220] The idea was that you run a photo through this program and it will tell you whether it's pornographic or not. [31:34.940 --> 31:39.260] And they claimed that they had really good accuracy in this thing, and they sold it to China for a whole lot of money. [31:40.380 --> 31:53.560] And a group called Peace Fire, which is run by a really clever guy who a lot of you probably are already fans of, did a little test on this thing and ran through a picture of Baltimore, and it turned out that the skyline of Baltimore turned out to be pornographic under this program. [31:53.900 --> 32:00.580] So, I mean, we were all really worried about that and really pissed off about the fact that American companies were trying to, you know, feed technology to China. [32:00.660 --> 32:04.520] But as long as they feed shit like this to China, I mean, that's actually doing us a favor. [32:06.740 --> 32:10.420] Now, a little bit more information about the China. [32:11.040 --> 32:13.260] You were bringing up the Saudi Arabia. [32:13.480 --> 32:15.140] It was a single point of access to the Internet. [32:15.380 --> 32:23.260] I'm really surprised you did not bring up the well-known Great Firewall of China, Beijing State University, sorry, Chinese State University in Beijing. [32:25.160 --> 32:30.680] Cluster of AIDS, Sun Enterprise 10,000, Robots for Sun, Australia financed by Sun. [32:31.200 --> 32:35.560] They're the ones doing, they're the ones that are acting as a main gateway into China. [32:35.900 --> 32:42.560] They're the ones that do a lot of caching, and Cisco is only internally just off, just dealing with this alone. [32:42.560 --> 32:45.440] So that information is fairly well-known. [32:45.800 --> 32:53.920] And if you end up trying to get a contract with Chinese, you can probably request a tour of the facility. [32:54.440 --> 32:55.080] Yes. [32:55.600 --> 33:03.640] The company I was involved with was trying to sell Chinese government stuff, and they've been showing this to select people. [33:03.640 --> 33:12.140] In the interest of full disclosure, in case you didn't see my bio in the program, I work for Sun in the high-end server engineering department. [33:12.440 --> 33:19.140] So, yeah, we're well aware, at least I am well aware of our sales within the People's Republic of China. [33:19.500 --> 33:24.700] And personally, yeah, it's something I don't really approve of. [33:26.380 --> 33:43.980] Actually, one thing that I think you mentioned while introducing your co-panelist was about the attempt to form an EFF-like organization in Russia. [33:44.200 --> 33:45.660] Could you cover that a little bit? [33:45.960 --> 33:51.960] Maybe talk a little bit about SOAR, and I kind of lost track of it, but you probably know a bit. [33:51.960 --> 34:01.020] Well, yeah, just as far as the Russia thing goes right now, you've got 11 time zones, and you don't have anybody who's watching this stuff at all. [34:01.140 --> 34:02.860] I mean, we've got a real luxury in the U.S. [34:02.880 --> 34:08.700] of having the ACLU and GILG, you know, GILG, which is at least centered here, and EPIC. [34:08.860 --> 34:12.000] But there's nobody doing that kind of work in Russia. [34:13.060 --> 34:19.360] I talked to a number of human rights groups in Russia, and they all agree that there's a need for a cyber rights organization. [34:19.900 --> 34:25.960] The way things are heading up right now, I'm going to be starting this thing under the auspices of Glassnose Media. [34:26.720 --> 34:28.420] This is the Glassnose Foundation. [34:29.560 --> 34:36.260] They're frankly about the only people there who are willing to actually give me an office, which is how I... [34:36.260 --> 34:44.400] I don't know who you're thinking of. [34:44.600 --> 34:46.060] I don't believe they're under sores. [34:46.340 --> 34:46.480] No. [34:47.500 --> 34:48.260] I hope not. [34:49.400 --> 34:49.800] Okay. [34:51.720 --> 34:53.940] But they're not funding us anyway, for what it's worth. [34:54.000 --> 34:55.080] They offered to give us space. [34:55.160 --> 34:56.860] It's a matter of us still raising the money. [34:56.980 --> 35:03.500] So if you know anybody who's interested in getting this thing started, please try to contact me, because we're looking for funding on that right now. [35:03.640 --> 35:05.420] It's the first step for everything. [35:08.260 --> 35:09.080] I have a quick question. [35:09.180 --> 35:12.640] You mentioned that the goal is to move towards a client-less system. [35:12.820 --> 35:12.900] Sorry. [35:13.640 --> 35:17.300] You mentioned the goal is to move towards a client-less system. [35:17.500 --> 35:22.180] So someone in China can access information without having to have a program sitting on his desktop computer. [35:22.400 --> 35:24.980] Can you give us some ideas of what ideas you've had? [35:25.080 --> 35:26.300] I can't think of how that might work. [35:26.300 --> 35:27.420] No, sure, sure, sure. [35:28.000 --> 35:41.180] And one thing that unfortunately I cannot claim for this is that it is as highly secure in the programming sense as some of the peer-to-peer systems that we're all familiar with. [35:42.420 --> 35:55.220] The idea that I have for this is that you use unencrypted text in a sort of childlike message panel. [35:55.220 --> 36:22.460] So, for example, if you were to take an IP address and let's say the first number was 192 and come up with a sentence that had a one-letter, a nine-letter, and a two-letter word in it, you come up with garbage like that which the user would recognize as being an IP address. [36:22.740 --> 36:27.520] That will not get stopped by either a word checker or a grammar checker going in or out. [36:27.660 --> 36:28.680] It's not encrypted. [36:28.820 --> 36:32.540] It can be a little message that has variable sizes. [36:33.120 --> 36:46.120] My own idea was that what we would need to do in order to make this effective would be to have this kind of information very plainly and openly dispensable through regular email. [36:47.400 --> 36:56.040] If it turns out that it ends up being intercepted, the idea is that this basically looks like spam and looks like garbage and that we don't know what it is. [36:56.700 --> 36:59.540] There's at least no fingerprint on the computer. [37:00.680 --> 37:09.060] My idea also, because one of the things that is extremely dangerous also about peer-to-peer systems, is in fact the very thing that makes them attractive to us, namely the fact that it is decentralized. [37:09.620 --> 37:23.380] If what you're doing is you're getting information across your firewall that may be in fact subversive, I mean it may really be subversive according to their definitions, one of the things that is a real danger there is that when you have a decentralized system, [37:23.500 --> 37:35.320] you don't... it's at least a matter of trust which is far more complicated, whether the information that you're getting is in fact accurate or not, whether it's really coming from who you think it's coming from. [37:35.320 --> 37:52.380] So my recommendation was that in fact the group that would be supplying all of these emails with what would be actively running IP addresses, at least temporarily until they get blocked, would in fact be centralized. [37:52.380 --> 38:00.600] It would farm out this information to what would be a distributed system, a sort of SETI at home system. [38:01.180 --> 38:08.720] These things, by virtue of the fact that they run on IP addresses, means that they would actually change when the person ends up logging on. [38:08.980 --> 38:12.720] So once these things get blocked, they will still have a little bit of life in them. [38:12.920 --> 38:15.700] China can block these things within about 15 minutes, is my understanding. [38:15.900 --> 38:17.160] It generally takes them about a week. [38:17.980 --> 38:29.180] So the general picture is that you have centralized information, it gets shooting out to a sort of peer-to-peer system, but all of the clients are in the free area of the world. [38:30.240 --> 38:39.360] They receive the information, and then there's a different source which sends email giving the IP address of who received it in the free world. [38:40.100 --> 38:45.800] This then gets sent to email based on a scheduling system, which is very easy, I think, to reckon with. [38:46.720 --> 38:53.460] The people within China then would read their email, see what would be one or two active email addresses at the time. [38:53.620 --> 38:54.900] They would only get one or two of them. [38:55.100 --> 39:00.600] Go to one through a regular web sit-up, presumably anonymized if possible. [39:00.780 --> 39:02.980] Of course, better if they use a proxy server. [39:03.440 --> 39:20.700] But the idea would be that they're going to a website, which by virtue of the fact that it has a unique IP address which won't be running soon, would not be traceable back to the same information because as soon as the session ends, presumably they're not going to be coming back to the same session. [39:22.100 --> 39:28.640] Whenever you log on to most of the systems that run in the United States, you get a different IP address each time, at least in that last octet. [39:29.260 --> 39:31.480] So the Chinese can go ahead and block it. [39:32.840 --> 39:39.820] Assuming that they block the fourth octet and leave at least some other choices, that client can still run for a while. [39:40.560 --> 39:45.880] So I mean, the thing is, I'm not saying, frankly, I'm not saying this thing will work. [39:46.040 --> 39:53.500] But I'm saying that this is the kind of idea that doesn't involve cryptography in any sort of dangerous sense. [39:54.460 --> 40:01.120] It involves no change in entropy levels because you're using regular coding, you're using regular vocabulary. [40:02.580 --> 40:07.480] And it doesn't involve the danger of either transporting these things through the mail. [40:08.240 --> 40:11.940] Because, I mean, look, you can go ahead and you can have a little client, even a small client. [40:12.480 --> 40:14.220] The Chinese are going to know what size it is. [40:14.320 --> 40:16.080] They're going to be looking for a packet that size. [40:17.360 --> 40:20.220] So this is only an example of what I think could be built. [40:20.860 --> 40:22.980] And it's really, it's anyone's guess whether it would work or not. [40:23.080 --> 40:28.500] It just seems to me that I would feel more comfortable at least with that one than I would with Fremant, for example. [40:30.140 --> 40:58.540] Wouldn't you believe that the recent, well, relatively recent slew of email-borne viruses, originated, I guess, with I Love You and Code Red, would be a very interesting way of potentially spreading, acting as a spreading vector for a fairly randomised technographical application that will actually end up going out and being installed on the hard drives of, [40:58.540 --> 41:07.400] say, all the systems that have an IP address and an APNIC allocated IP blocks for, say, China, Saudi Arabia, you name it. [41:08.000 --> 41:14.820] Because, basically, you don't even need to activate the software past the reproduction stage. [41:14.820 --> 41:17.420] It just has to be installed on a hard drive of a user. [41:17.660 --> 41:23.260] However, at this point, once the surveillance sources in the foreign... [41:23.260 --> 41:35.380] Well, those who watch notice that everyone has a copy of the particular application, at that point, you can start claiming plausible deniability. [41:35.600 --> 41:36.840] In other words, you didn't know. [41:37.300 --> 41:44.600] Because, right now, a lot of countries have guilty until proven innocent doctrine. [41:44.600 --> 41:50.600] And that seems like the only way a doctrine like this can be overturned. [41:52.020 --> 41:53.180] Let me think about it. [41:53.420 --> 41:53.780] Let me think about it. [41:53.780 --> 41:54.400] It's interesting. [41:54.560 --> 41:54.840] Thank you. [41:55.420 --> 42:04.300] Obviously, with that angle, what you now have to worry about is antivirus software, you know, propagating it in a virus. [42:04.300 --> 42:17.600] And suppose... suppose the Internet propaganda administrative bureau in China decides that everybody has to... everybody who has a computer has to run this antivirus program to eliminate the other... [42:17.600 --> 42:20.820] Well, I still get a good chunk of I love you viruses. [42:21.240 --> 42:27.640] And besides, I mean, the Chinese officially declared spam illegal, but you still get tons of spam from China. [42:28.540 --> 42:28.920] Yeah. [42:37.190 --> 42:37.830] Yeah. [42:37.910 --> 42:38.050] Sure. [42:38.730 --> 42:41.550] Just gonna say, I find the... [42:41.550 --> 42:44.970] I guess the proposal that you had for... [42:44.970 --> 42:46.430] for a... [42:47.690 --> 42:52.250] a means of, say, of sending secure or private... [42:52.250 --> 42:58.050] private communications, without using encryption, and without using... [42:58.890 --> 43:08.550] in theory, without using means that will uniquely identify it, and flag and flag the users as being engaged in subversive activity. [43:09.010 --> 43:15.810] It sounds good at first, but I am a little concerned that... [43:15.810 --> 43:20.030] especially if the system is as simple... [43:20.030 --> 43:28.750] as simplistic as something as you described, and as you describe it, needs to be simple in order for it to work at least... [43:30.450 --> 43:40.630] if, say, for example, there's a Chinese intelligence person sitting at the conference here, which wouldn't be unreasonable. [43:41.470 --> 43:42.210] It's... [43:42.210 --> 43:52.290] I think once the government knows what to look for, they can still find messages like that. [43:52.290 --> 43:52.730] if they... [43:52.730 --> 43:56.770] if they know that certain types of spam, with... [43:56.770 --> 43:58.330] with unusual... [43:58.330 --> 44:01.090] sorts of patterns of them, could... [44:02.370 --> 44:02.890] contain... [44:02.890 --> 44:05.330] could be used as covert channels. [44:05.910 --> 44:07.610] It's still... [44:07.610 --> 44:07.790] I... [44:09.130 --> 44:11.290] I see it as still... [44:11.290 --> 44:12.810] as still being potentially dangerous. [44:13.050 --> 44:16.590] Look, I absolutely do not want to claim that this thing is... [44:17.270 --> 44:20.630] I mean, we all know, including me, that it's absolutely not foolproof. [44:20.630 --> 44:23.830] I also don't want to say that it has the kind of... [44:23.830 --> 44:28.230] of anonymity that some of the onion routing proposals have, for example. [44:28.790 --> 44:29.250] I'm... [44:29.250 --> 44:31.370] I'm presenting it only that it's a... [44:31.370 --> 44:34.230] it's a project in progress in some sense. [44:34.570 --> 44:38.190] I think that it's the direction that should at least be explored. [44:38.330 --> 44:41.370] I don't see that this type of thing is being explored. [44:41.370 --> 44:43.450] Everyone is, I think, very caught up in... [44:43.450 --> 44:45.670] in seeing what kind of cool... [44:45.670 --> 44:46.090] uh... [44:46.090 --> 44:47.030] code they can write. [44:47.250 --> 44:50.030] And I think that the real issue here is not... [44:50.030 --> 44:52.330] to write the coolest code right now. [44:52.410 --> 44:53.950] The real issue is to look at... [44:53.950 --> 44:54.110] and... [44:54.110 --> 44:57.630] and this is something that I don't see people at Freenet or at CDC doing. [44:58.270 --> 45:02.570] To look at what the needs are in all of these individual countries, and how these things are... [45:02.570 --> 45:03.310] are... [45:03.310 --> 45:05.390] are protected, these firewalls. [45:05.390 --> 45:07.390] One thing I might also add... [45:07.390 --> 45:08.550] it is not only... [45:09.030 --> 45:10.590] the one place that has... [45:12.190 --> 45:13.790] this censorship in China. [45:14.030 --> 45:15.270] It's not just at the university. [45:15.650 --> 45:17.690] There are, in fact, four places... [45:17.690 --> 45:18.770] that are doing this. [45:19.030 --> 45:22.130] There is one that looks only at university censorship. [45:22.470 --> 45:23.830] I mean, they've got one all to that. [45:23.970 --> 45:26.490] But there are three other locations in China you have to deal with. [45:26.650 --> 45:29.290] And these things are not connected. [45:29.850 --> 45:30.590] So it's not... [45:30.590 --> 45:32.910] it's not like you could sort of, like, knock them all out together. [45:33.170 --> 45:34.750] They're all operating individually. [45:45.130 --> 45:47.310] I would like to add a little bit... [45:47.570 --> 45:48.270] piece of information. [45:48.710 --> 45:49.430] Since... [45:49.430 --> 45:53.190] as you may have seen in the news recently, China... [45:53.850 --> 45:57.050] enforced every internet cafe has to install the... [45:57.050 --> 45:57.950] like Fiddle King. [45:58.590 --> 45:59.630] And what they do is... they have a long list of... [46:01.270 --> 46:03.910] 500,000 blacklists. [46:04.650 --> 46:05.150] And... one thing... [46:06.110 --> 46:08.350] I heard some reporters... [46:08.350 --> 46:11.070] there are filters at the application level. [46:11.750 --> 46:12.090] So... [46:13.250 --> 46:15.030] when you use a... [46:16.350 --> 46:17.550] a browser... [46:17.550 --> 46:18.010] to view... [46:18.010 --> 46:18.790] on every site... [46:18.790 --> 46:19.570] when you have... [46:19.570 --> 46:20.470] some keyword in it... [46:20.470 --> 46:21.830] it's going to trigger the alarm. [46:22.770 --> 46:23.370] So... [46:23.370 --> 46:24.210] so... [46:24.210 --> 46:24.950] on one side... [46:24.950 --> 46:25.310] it's a... [46:25.310 --> 46:25.750] it's a... [46:25.750 --> 46:27.630] one more technical problem for... [46:27.630 --> 46:28.550] any... [46:28.550 --> 46:29.390] programmer... [46:29.390 --> 46:31.430] trying to develop some architecture or code. [46:31.430 --> 46:31.970] people... [46:31.970 --> 46:32.690] but... [46:32.690 --> 46:32.970] a... [46:32.970 --> 46:34.930] more general picture is... [46:35.810 --> 46:36.770] I like... [46:36.770 --> 46:37.890] I can't remember the name... [46:37.890 --> 46:38.510] someone say... [46:38.510 --> 46:39.490] it's a... [46:39.490 --> 46:40.050] technical race. [46:40.690 --> 46:41.170] So... [46:41.170 --> 46:42.850] they are developing pretty fast. [46:43.750 --> 46:44.230] So... [46:44.230 --> 46:45.770] what's your view about this? [46:45.970 --> 46:48.270] They're starting a new operating system... [46:48.270 --> 46:49.030] which in my opinion... [46:49.030 --> 46:51.050] is going to be much more of a challenge right now... [46:51.050 --> 46:51.550] because... [46:51.550 --> 46:53.710] if what we're doing is writing right now... [46:53.710 --> 46:54.310] for example... [46:54.310 --> 46:55.230] DOS programs... [46:55.230 --> 46:57.490] which are going to be the basis of a peer-to-peer client... [46:57.490 --> 46:58.530] for example... [46:58.530 --> 46:59.930] I'm not sure what China is... [46:59.930 --> 47:00.230] I mean... [47:00.230 --> 47:02.270] it's very tough to get information about this... [47:02.270 --> 47:03.010] but they're... [47:03.010 --> 47:04.010] they're planning to... [47:04.010 --> 47:06.070] rewrite their entire government... [47:06.070 --> 47:08.470] operating system essentially... [47:08.470 --> 47:10.350] I'm not sure what the status of this is... [47:10.350 --> 47:11.250] from what I've heard... [47:11.250 --> 47:14.530] the rumors are that this thing is going to be more like a Unix system... [47:15.570 --> 47:15.970] but... [47:15.970 --> 47:16.890] Red factory? [47:17.070 --> 47:18.510] It's going to be called something like... [47:18.510 --> 47:19.870] Big Mama... [47:19.870 --> 47:20.390] and... [47:20.390 --> 47:22.250] and this is going to be a... [47:22.250 --> 47:23.190] non-DOS... [47:23.190 --> 47:24.090] non-Unix... [47:24.090 --> 47:25.050] non-Windows... [47:25.050 --> 47:25.830] non-everything... [47:25.830 --> 47:27.310] it's going to be their own baby... [47:27.310 --> 47:29.550] and they're going to be able to write programs for it... [47:29.550 --> 47:30.170] and... [47:30.170 --> 47:32.250] it's unclear what effect this is going to have on... [47:32.250 --> 47:32.850] for example... [47:32.850 --> 47:35.150] peer-to-peer projects that are Western-based... [47:37.110 --> 47:38.250] to my mind... [47:38.250 --> 47:38.450] that's... [47:38.450 --> 47:40.310] that's a more interesting problem right now... [47:41.010 --> 47:41.350] I mean... [47:41.350 --> 47:42.090] that's the thing that I... [47:42.090 --> 47:42.950] I am really... [47:42.950 --> 47:43.850] holding my breath on... [47:43.850 --> 47:44.670] because that could... [47:44.670 --> 47:45.790] that could really... [47:45.790 --> 47:47.690] isolate China in a big way... [47:47.690 --> 47:48.570] which is... [47:48.570 --> 47:48.870] I think... [47:48.870 --> 47:49.370] the goal... [47:51.190 --> 47:52.190] unfortunately... [48:00.130 --> 48:01.970] that.. my name is Jeff Smith... [48:01.970 --> 48:04.090] I'm one of the principals in the American National News Service... [48:04.590 --> 48:06.370] I guess our largest client... [48:06.370 --> 48:07.090] is down in Washington... [48:07.570 --> 48:08.650] the American Free Press... [48:08.650 --> 48:09.410] and recently... [48:09.410 --> 48:10.630] they sent me over to... [48:10.630 --> 48:11.050] James Banford... [48:11.650 --> 48:12.190] who was speaking... [48:13.430 --> 48:14.390] midtown Manhattan... [48:14.390 --> 48:15.110] he's the... [48:15.650 --> 48:16.150] author... [48:16.150 --> 48:16.490] of course... [48:16.490 --> 48:17.370] of the Puzzle Palace... [48:17.370 --> 48:18.370] and he sort of... [48:18.370 --> 48:20.390] works on the National Security Agency... [48:21.290 --> 48:21.750] and... [48:21.750 --> 48:22.430] I went over there... [48:22.430 --> 48:23.620] and I asked him an interesting question... [48:24.030 --> 48:24.310] I said... [48:24.310 --> 48:24.850] first of all... [48:24.850 --> 48:25.930] how much surveillance... [48:25.930 --> 48:27.250] is actually being done... [48:27.250 --> 48:28.830] on Americans... [48:28.830 --> 48:29.430] and of course... [48:29.430 --> 48:30.150] he agreed with me... [48:30.150 --> 48:30.870] and everyone else... [48:30.870 --> 48:31.130] that... [48:31.130 --> 48:32.850] the government loves the internet... [48:32.850 --> 48:33.870] of course... [48:33.870 --> 48:35.370] great tracking system... [48:35.370 --> 48:36.370] greatest tracking system... [48:36.370 --> 48:36.890] in the world... [48:36.890 --> 48:38.050] of course... [48:38.050 --> 48:39.190] but then I asked him... [48:39.190 --> 48:39.570] look... [48:39.570 --> 48:40.090] you know... [48:40.090 --> 48:41.410] isn't it true... [48:41.410 --> 48:42.370] that the basic way... [48:42.370 --> 48:57.710] They have gotten around the recent limitation laws is they simply take the raw data and ship it over to Britain and ship it over to some of our other so-called allies and have it analyzed and have it compressed and then brought back here and voila, it's legal to do. [48:58.550 --> 49:09.970] Number one, how secure is it for America's most inner secrets to be shipped abroad to be analyzed and then compressed and brought back in? [49:09.970 --> 49:14.890] What kind of a policy is that in terms of honesty, national security? [49:15.570 --> 49:20.270] Think of the problems we've had in the Middle East with escape of military information. [49:21.310 --> 49:24.770] As you know, this is very worrisome. [49:24.950 --> 49:30.370] The other thing is that what is also worrisome is, of course, you mentioned the satellites and dishes. [49:31.390 --> 49:33.390] Remember, satellites can be jammed. [49:33.610 --> 49:37.350] You notice what happened to the Iranian programming. [49:38.170 --> 49:46.050] They just shot up a jamming signal until the satellite owners had to pull the station, had to pull the program. [49:46.450 --> 49:50.190] Secondly, there is now a decline of the short wave. [49:50.490 --> 49:56.790] Now, I know this is a computer convention and I know that this is a competing old technology. [49:56.790 --> 49:57.870] I'm very sorry. [49:57.870 --> 49:59.950] But there is a place for the short wave. [50:00.210 --> 50:05.950] If you do away with the short wave to the rate that is now happening, where it's all going on the internet. [50:06.070 --> 50:07.390] Okay, it doesn't chop in and out. [50:07.510 --> 50:07.870] So what? [50:08.030 --> 50:08.810] It gets through. [50:09.070 --> 50:13.230] If you do away with the short wave, you've just put a stranglehold on everybody. [50:13.230 --> 50:15.490] This is a very, very dangerous trend. [50:16.190 --> 50:20.270] Anybody, low technology does have its place in freedom. [50:20.590 --> 50:28.530] You want that kid to put together a simple circuit, low power transmitter, and get on the air, where a couple hundred thousand people listen to it. [50:28.690 --> 50:34.490] If you get away from that, or simply say, oh, that's old fashioned, this is dangerous. [50:34.630 --> 50:35.790] But I need a direct comment. [50:36.670 --> 50:40.810] What's your opinion on what's going on in the State of Israel? [50:41.290 --> 50:51.890] What is going on, number one, with the policy of the NSA exporting raw data overseas to be compressed and analyzed and brought back into this country? [50:52.110 --> 50:53.190] Any comment on that? [50:53.290 --> 50:56.270] Mr. Banford would have no comment on that whatsoever. [50:56.550 --> 50:58.450] What do you guys have to say about that? [50:58.450 --> 51:00.270] So this is the U.S. [51:00.530 --> 51:04.170] sending data to other countries? [51:09.270 --> 51:10.210] I don't know. [51:10.350 --> 51:16.510] Personally, it's going to sound a bit like a dog, but that's kind of the U.S. [51:17.190 --> 51:18.090] government's prerogative. [51:18.230 --> 51:21.350] I mean, there's not a whole lot we as individuals can do about that. [51:21.750 --> 51:25.650] I mean, the government did build, you know, the basis of this network. [51:25.650 --> 51:39.270] And how they do it, you know, behind closed locked doors with MP guards is something we can, you know, moan about all we want, but that's not necessarily going to bring much change about it. [51:40.570 --> 51:49.030] The only way... that sort of thing... it's... I don't know if I have a position on that personally. [51:50.550 --> 51:51.870] That's something I'd have to think about. [51:51.870 --> 51:57.250] But initially, my gut reaction initially is it's probably not a good idea. [51:57.750 --> 51:58.610] Alan, do you want a comment? [51:59.590 --> 52:07.370] I'm afraid I have nothing really to add to that except that I'll absolutely affirm your belief in shortwave. [52:07.550 --> 52:13.090] I've got a drake at home, and I think that low technology is very underestimated. [52:14.750 --> 52:21.650] If I can take 20 seconds to say something that I think we can all try to do at home to try to f*ck up ECHELON. [52:23.250 --> 52:39.110] If you build into your web pages and you build into the signature in your email some little sentence that says something like, the NSA will be happy to know that this email contains no information about Islam, Jihad, formaldehyde, or other bombings. [52:40.470 --> 52:42.950] These things are bound to trip up. [52:43.030 --> 53:01.150] And what we are hoping could happen if enough people did this is that it would simply create such a number of ticks over at the ECHELON office that hopefully this would have the same effect that they did in Denmark during World War II when all the Danes joined the Jews and were in yellow stars. [53:01.970 --> 53:07.010] When you can no longer discriminate the good from the bad data, you end up going to other methods. [53:07.250 --> 53:11.550] And so I don't see us ever stopping ECHELON, but I do see us fucking it up. [53:11.910 --> 53:16.550] Yeah, there is like, I think there's an anniversary ECHELON f*ck up data. [53:16.690 --> 53:18.130] I think it's October 17th. [53:18.130 --> 53:19.610] Needs to be more than one day a year. [53:20.150 --> 53:21.810] Every day should be a f*ck up ECHELON. [53:21.810 --> 53:28.210] Well, I think last year or the year before it was, yeah, send it out to your friends on October 17th. [53:28.410 --> 53:33.850] Put as much of these red flag words in any email you can to anybody and let them know. [53:34.630 --> 53:36.110] This is going to have to be our last question. [53:36.370 --> 53:41.410] Now, just a comment, I guess, on the subject of the satellites and shortwave, etc. [53:41.610 --> 53:50.490] Shortwave is indeed a really great, really easy to implement and really easy for the end user to use technology. [53:50.490 --> 53:56.390] And I mean, I grew up listening to the BBC, which was mercilessly jammed. [53:56.390 --> 53:59.470] And, oh yes, it was, big time. [54:00.030 --> 54:13.430] And basically the question I have is about, I don't know if you were on any of the more politically, politics and technology-oriented mailing lists such as ISN and Politech. [54:13.630 --> 54:36.230] But basically there was information coming across about Falun Gong, Falun Dafa supporters using a three-meter dish to not jam, but literally overpower the signal that was broadcast, that was the uplink signal to one of the Chinese TV rebroadcasting satellites, [54:36.610 --> 54:48.210] where for multiple days there have been the Falun Gong subversive messages for 15 minutes at a time broadcast on all six national, six of many national channels. [54:48.710 --> 55:01.370] Do you suppose techniques like this are actually effective, or is that something that should be avoided in order not to suppress a little freedom, and that is still there? [55:05.640 --> 55:13.580] That's something that strikes me more as civil disobedience, and it's kind of fun and funny to see and hear about. [55:14.760 --> 55:24.080] But I don't know if it advances the free exchange of information, which is ultimately what we're trying to get here in China. [55:24.960 --> 55:27.020] But it's definitely entertaining. [55:27.800 --> 55:37.880] Well, what I'm saying, from what I understand, there have been attempts to literally provide information what, say, Falun Gong is all about to the masses on national TV. [55:38.520 --> 55:54.600] And technically, a case can be made that this was information designed to get at least people thinking, but at the same time, you know, if the resulting crackdown is going to be, well, we're going to turn off the news all the way, and from now on, it's only going to be sitcoms. [55:54.640 --> 55:55.380] Is it a good thing? [55:58.220 --> 55:59.600] I understand the question. [55:59.600 --> 56:00.100] I'm sorry. [56:01.100 --> 56:14.640] No, I think that if you don't try to fight these things, and if what you say instead is that, I'm not going to basically put up my fists because I might get beat up even harder. [56:16.880 --> 56:21.320] You know, it's a personality issue, but I'd rather get beat up a few times. [56:21.620 --> 56:30.900] I mean, this is an important issue, and at some point, you just have to hope that you're going to give the other side a good fight for its money. [56:31.920 --> 56:38.520] Obviously, Falun Gong doesn't have a chance, I mean, if it's going to be a matter of sheer power from the government. [56:39.780 --> 56:48.280] But I would recommend, I think, going back to maybe your first question, I would recommend that we don't get tied down on what is the best method. [56:48.740 --> 56:51.640] I don't think there is such a thing as a best method, frankly. [56:51.940 --> 57:03.460] I think that what we need is to keep the entropy high on these issues and use everything and anything that works, from shortwave to spam to passing notes to each other. [57:03.740 --> 57:07.400] And the ultimate goal we have to remember is to get the information through. [57:07.680 --> 57:12.860] It may be that one day technology will not enable us to do that, and we have to do it some other way. [57:13.780 --> 57:17.900] But the important thing is that the information gets through, and we'll take our knocks. [57:19.680 --> 57:20.200] All right. [57:20.460 --> 57:23.140] Thanks for sticking around for this long, and I appreciate it. [57:28.300 --> 57:31.800] I don't know about Alan, but I'll be sticking around if anybody wants to talk or ask more questions or anything. [57:31.980 --> 57:32.380] Thanks a lot.