[00:01.470 --> 00:04.070] What it does is transmit the keys to the feds. [00:04.210 --> 00:05.830] That seems like kind of a bad idea. [00:06.870 --> 00:08.270] That's where I got introduced. [00:08.650 --> 00:10.990] I got hooked up with Whit Diffie at that point. [00:11.150 --> 00:17.490] People said to me, well, if you talk to Whit, if you can build a secure phone he'll like, then you've solved the problem. [00:17.850 --> 00:24.310] Okay, well, meanwhile, three companies later, and several million dollars, where it's kind of like, okay, where are the secure phones? [00:24.470 --> 00:26.590] That's part of our topic for today. [00:27.050 --> 00:28.270] Rob, do you want to introduce yourself? [00:35.070 --> 00:36.430] My name is Rop Gonggrijp. [00:36.590 --> 00:37.490] I'm out of Amsterdam. [00:37.490 --> 00:39.630] We just founded a new company called NAH6. [00:39.870 --> 00:43.890] There's much more on what we do and plan to do at 6 in the same room. [00:44.450 --> 00:48.050] But one of our projects is a secure telephony project. [00:48.610 --> 00:54.130] And this is how we got in touch with Eric's company Starium, which was also doing secure telephones. [00:54.250 --> 00:57.750] But it's probably more prudent if Eric talks about his part of the story first. [00:57.910 --> 00:59.110] But we'll get to what we're doing. [01:01.610 --> 01:04.450] Okay, so let me just kind of get an idea. [01:04.550 --> 01:06.730] Who's actually used a secure phone here of any kind? [01:06.910 --> 01:08.950] Either STU-3, you know, military or otherwise. [01:09.130 --> 01:09.250] Okay. [01:10.250 --> 01:10.770] Let's... [01:10.770 --> 01:13.590] Here's kind of secure telephony 101. [01:13.590 --> 01:19.930] And this model applies independent of whether you're going over the switched phone network or IP. [01:20.590 --> 01:25.170] So we've got the classic Alice and Bob, as we always call them in CryptoWand. [01:25.250 --> 01:26.970] And they've got some kind of a telephone here. [01:27.610 --> 01:29.090] And they want to talk to each other. [01:30.590 --> 01:33.830] And there's this cloud that's, you know... [01:33.830 --> 01:35.150] Maybe I'm trying to talk to Rob. [01:35.210 --> 01:35.710] He's in Amsterdam. [01:35.710 --> 01:36.530] I'm in Monterey. [01:36.790 --> 01:39.510] And we've got some eavesdropper here in the middle. [01:40.130 --> 01:44.950] And the assumption that we make is that in the simple case, the eavesdropper is a passive eavesdropper. [01:45.230 --> 01:48.210] So it has access to all the bits that we transmit back and forth. [01:48.850 --> 01:54.950] Sort of the next level up threat is that the eavesdropper can actually mangle the bit stream between us. [01:55.110 --> 01:59.770] He can insert bytes, drop bytes, smash bytes, anything like that. [02:00.850 --> 02:04.990] So the basic idea here is, well, we're saying, okay, this is the digital world. [02:04.990 --> 02:06.050] I've got my phone. [02:06.190 --> 02:08.270] I've got to somehow digitize it. [02:08.590 --> 02:11.150] And then I want to do some kind of a crypto thing on it. [02:11.230 --> 02:12.050] And then I go into this. [02:12.190 --> 02:13.630] Then I've got some kind of a modem. [02:14.190 --> 02:14.550] Modem. [02:15.750 --> 02:22.030] I've got to digitize into the PSTN and basically out the other side. [02:23.170 --> 02:29.050] Another modem, my other crypto, and then back to the phone. [02:29.730 --> 02:31.530] So that's in the simplest case. [02:31.770 --> 02:33.390] It's probably totally illegible. [02:33.510 --> 02:35.730] But bottom line is I've got to digitize the speech. [02:35.890 --> 02:37.750] I've got to jam it across some bit pipe. [02:37.890 --> 02:40.690] And then I've got to get it back out the other end and decrypt it. [02:41.030 --> 02:42.730] A couple of problems come up right away. [02:42.850 --> 02:51.750] One of which is if I just sort of take telephone quality voice, and I just use it, if I deal with it the way that the phone company deals with it, I've got a 64 kilobit channel. [02:52.270 --> 02:56.890] And most modems won't eat 64 kilobits in any kind of, you know, any kind of way. [02:56.890 --> 03:00.510] Particularly if I'm interested in working in a really kind of harsh environment. [03:01.070 --> 03:04.550] As the military people, they say operating off of ships is really hostile. [03:04.930 --> 03:07.850] But operating across a wireless link of any kind is also hostile. [03:08.390 --> 03:14.290] So we end up with a slightly revised picture, which is kind of where the reality of this problem comes in. [03:15.190 --> 03:17.290] Which looks like... I'm going to just show one end here. [03:17.830 --> 03:23.250] So I've got... I've got A to D converter on one end. [03:23.350 --> 03:26.110] And I've got D to A converter on the other. [03:26.290 --> 03:27.170] So I've got in and out. [03:27.830 --> 03:29.210] I've got compress. [03:29.910 --> 03:31.190] I've got decompress. [03:33.670 --> 03:38.550] And then I've got some kind of crypto going on here. [03:40.510 --> 03:41.830] Then I've got my modem. [03:42.170 --> 03:45.370] Then I've really got... usually there's some kind of mux happening here. [03:45.630 --> 03:49.910] Because I've got some control stuff related to call setup, setting up the key material. [03:50.250 --> 03:51.390] Then I'm out here to my modem. [03:52.310 --> 03:54.230] And the modem could be buried in a radio. [03:54.230 --> 03:58.470] You know, if I'm working over a digital cell phone, basically the modem is in the cell phone. [03:59.730 --> 04:04.730] So part of the game plan here is in the steady state case, you've got... you've got this question about... [04:04.730 --> 04:07.230] How do I set up a key between each side? [04:07.470 --> 04:12.270] So the general strategy everybody's using is... is I don't... a couple things. [04:12.430 --> 04:14.030] I'm trying to build a box that's inexpensive. [04:15.150 --> 04:18.770] More than likely what I want to do is I don't want to have to make the box tamper resistant. [04:19.030 --> 04:23.230] I don't want it to be a thing where if I drop it or lose it or it's stolen, I go... [04:23.230 --> 04:24.710] Oh boy, I'm in big trouble. [04:25.570 --> 04:31.410] So we want to build a system that basically generates a new key every time we make a new phone call. [04:31.790 --> 04:34.990] So to do that, we use the Diffie-Hellman exponential key exchange. [04:35.370 --> 04:37.070] If we've got time, I can run through that. [04:37.470 --> 04:38.550] Do people know what this is? [04:39.170 --> 04:41.790] Okay, so the shorthand version is... [04:41.790 --> 04:44.070] We're back at the Alice and Bob picture. [04:44.210 --> 04:48.850] It turns out that if Alice and Bob send messages back and forth in each other, it takes like two round trips. [04:48.850 --> 04:57.110] Eve can watch everything going on and yet miraculously, Alice and Bob come up with a key that's shared between them that Eve doesn't have. [04:57.650 --> 05:02.810] It turns out that it's fairly straightforward math with modular exponentiation and it works. [05:03.830 --> 05:06.890] So the bottom line here is I've got some A to D converter. [05:07.050 --> 05:07.670] I've got to compress. [05:08.050 --> 05:15.650] And typically we compress down to something like either 14,400 bits per second or 96 or 4800. [05:16.250 --> 05:19.190] There's a whole bunch of trade-offs here on the voice compression. [05:19.310 --> 05:21.950] They call them codecs, which is sometimes confused with the A to D converter. [05:22.150 --> 05:23.470] The same word used in both environments. [05:23.670 --> 05:31.210] But in the codecs, you basically get to trade off how many MIPS it takes for what kind of bandwidth, for what kind of sound quality. [05:31.210 --> 05:33.890] So it's kind of one of those pick any two kind of a problem. [05:34.210 --> 05:37.070] And then some of them are encumbered with a bunch of patents and things. [05:38.230 --> 05:41.250] The crypto, pretty much you've got two kinds of crypto going on here. [05:41.410 --> 05:44.810] One of which is the traffic crypto, which is let's assume I've somehow agreed on a key. [05:45.090 --> 05:47.650] Then I'm going to use some kind of crypto to encrypt the stuff. [05:47.870 --> 05:52.250] Generally what we end up running today, we do AES with 256-bit keys. [05:53.690 --> 05:55.990] The devices that I built were all triple DES. [05:56.910 --> 06:01.690] And I built the stuff that the FreeSwan guys are currently using, which was built with the first company. [06:01.810 --> 06:03.790] These look like black boxes but kind of like modems. [06:04.290 --> 06:06.910] And then I've got some of the Starium units here. [06:06.910 --> 06:07.770] I'll pass one around. [06:08.050 --> 06:11.690] We may be able to pull a demo off here, but don't hold a breath. [06:12.530 --> 06:15.610] Please, somebody, whoever ends up with this, please return it to me at the end. [06:17.290 --> 06:22.850] This Starium thing I'm sending around, just so you know what you're looking at, is a device that goes between the handset and the phone base. [06:23.450 --> 06:31.570] Instead of between the phone and the wall, it was designed that way so that it could work with ISDN phones or phones hooked to PBX as well as proprietary interface. [06:32.170 --> 06:33.690] It has a way to auto-configure. [06:34.150 --> 06:38.070] It does the Diffie-Hellman with the 2K-bit modulus and then does triple DES. [06:38.490 --> 06:42.470] It uses either the full-rate GSM coder or Kelp as a fallback at 4800. [06:44.050 --> 06:47.750] Okay, that's kind of a hand-wavy explanation of crypto. [06:47.750 --> 06:49.130] A short bit of history. [06:49.290 --> 06:52.370] The first secure phone, and feel free to ask questions at any point. [06:52.910 --> 06:54.970] And I know we're starting late, so we're kind of pushed here. [06:56.310 --> 06:56.630] Yeah? [06:56.990 --> 06:57.830] I had a question about the key exchange. [06:57.830 --> 06:58.850] Can you step up the mic, please? [06:58.990 --> 07:00.430] Sorry, that was the other speaker I was supposed to tell you. [07:03.030 --> 07:07.070] Regarding key exchange, you said it's independent or you do it on your own? [07:07.350 --> 07:12.550] We do the Diffie-Hellman, so the two parties on the end participate. [07:12.550 --> 07:13.690] Do you have an option? [07:13.730 --> 07:15.910] I mean, Diffie-Hellman would be vulnerable to a man in the middle? [07:16.170 --> 07:16.670] That's correct. [07:16.850 --> 07:17.410] Let me... [07:17.410 --> 07:19.770] I'd be delighted to talk to you about how we defend against it. [07:19.890 --> 07:20.310] I want to... [07:20.310 --> 07:20.710] Okay. [07:21.090 --> 07:22.310] We're a little pressed for time. [07:22.770 --> 07:25.170] I've run the whole math and show you the defense against it and the whole thing. [07:25.330 --> 07:25.430] Okay? [07:25.830 --> 07:27.350] But I want to try to get some other stuff covered. [07:27.670 --> 07:27.750] Okay? [07:29.530 --> 07:29.850] Okay. [07:30.930 --> 07:31.370] Let's see. [07:31.450 --> 07:31.690] Where'd it go? [07:31.810 --> 07:37.610] So the first secure phone that I know of was actually towards the end of World War II, and I guess it would have been Churchill and Roosevelt. [07:37.610 --> 07:43.890] They had this huge thing that was one of those, you know, here's the room, it goes from here to there, a big rack of gear. [07:44.270 --> 07:48.790] And it was a one-time pad system based on like phonograph records that they had specially built. [07:48.950 --> 07:50.930] Like phonograph records, they only made two of them. [07:50.990 --> 07:52.310] I think they actually made three of them. [07:52.950 --> 07:57.690] And they shipped, you know, one to England and one to Washington, and then there was a spare. [07:58.050 --> 08:05.170] And what they had to do is they'd key these two records up, they had some way to synchronize them, and then they could go on and have, I think, about a 30-minute conversation. [08:07.010 --> 08:10.030] What drove secure telephony from the very beginning was military use. [08:10.150 --> 08:15.990] People really wanted the same thing that us folks now want, is you want to be able to have an absolutely private conversation, you know, at the distance. [08:16.970 --> 08:22.010] I think of this personally, and what my motivation for this whole thing was, is I would like the... [08:22.450 --> 08:34.530] If I wanted to have a private conversation with someone, and you're with me, we would kind of like, let's go take a look around, and we're going to go take a look, walk in the woods, kind of hard here in Manhattan, but we go look around, we go take a walk in the woods, [08:34.630 --> 08:36.750] we say whatever we want to say, and we come back. [08:37.490 --> 08:46.370] I wanted that kind of, basically, intimacy, that kind of freedom to say what I wanted to say, and not have to be physically located next to people. [08:46.530 --> 08:49.850] So this is sort of my personal goal on this whole thing about, you know, why. [08:50.370 --> 08:57.150] And, you know, I've been accused of being a professional paranoid and all that, but it's just like, you know, I think, why shouldn't I be able to have a private conversation? [08:57.350 --> 08:59.290] You know, it's just like a very simple thing. [09:01.010 --> 09:01.890] All right. [09:03.250 --> 09:09.950] The next really secure phones in the history basically came up with the Stu 2s, which I actually haven't seen them. [09:10.010 --> 09:16.870] I think they're still deployed in NATO and Europe right now, and then primarily what's currently used are what are called Stu 3, secure telephone unit, third edition. [09:17.130 --> 09:18.490] I don't know if it was really a Stu 1. [09:18.590 --> 09:20.150] I don't know, I've never heard of one deployed. [09:20.670 --> 09:24.390] Stu 3 looks like kind of a full-feature desk phone. [09:24.730 --> 09:33.410] The Motorola ones are really kind of big and clunky and heavy, and they're cast aluminum, and you open them up, and they've got three separate layers of boards in them. [09:33.490 --> 09:34.870] They were designed quite a while ago. [09:34.970 --> 09:36.570] So they actually have seven separate processors. [09:36.970 --> 09:37.890] They're really hardcore. [09:38.750 --> 09:39.950] I mean, they've got separate power supplies. [09:40.130 --> 09:46.150] They've got, like on the hook switch for the cutoff, there's actually four separate micro switches in there. [09:46.230 --> 09:49.970] So there's all this redundancy to make sure that when it's on the hook, it's really on the hook. [09:50.110 --> 09:53.210] I mean, these things are really, these were designed by people who knew what they were doing. [09:54.770 --> 10:00.610] Us commercial guys wanted to build something that we could actually ideally, you know, the holy grail is the $100 secure phone. [10:00.890 --> 10:07.250] This is like, you know, $300, it's like, okay, you can get some people at a thousand bucks, or $2,500, which is what most of the stuff you'll find. [10:07.330 --> 10:11.430] And it's like, yeah, there's a few people, but we noticed that they're hard to find. [10:11.430 --> 10:15.630] And we, you know, we spent a lot, many years trying to track down these customers. [10:17.490 --> 10:25.710] Then there were some commercial phones that entered the market, one of which was a silent unit, which again was, that must have been built in the late 80s. [10:26.010 --> 10:31.110] It had like three TI DSPs in it, and it sounded actually pretty good, a big, big clunky thing. [10:31.410 --> 10:44.050] And then the thing that really revolutionized it all for the commercial marketplace was AT&T, and it was really the same guys who were involved in designing the Stu-3 under the NSA, built a thing that was called the TSD-3600. [10:44.450 --> 10:51.430] The first ones they built, it went in the handset cord, it did single DES encryption, and this came out in about 92. [10:52.290 --> 10:53.470] And it was really pretty amazing. [10:54.290 --> 10:55.950] I've got a few of them at home. [10:56.630 --> 10:59.170] And they worked, they sounded pretty good. [10:59.350 --> 11:02.410] They used, you know, about a 4800 bit per second vocoder. [11:02.610 --> 11:04.390] They would work in a pretty harsh environment. [11:04.570 --> 11:19.490] They did kind of a kludgy James Bond bag phone, which had like an old car, a car, it had like a gel cell in it, and an audio box, amps, car transceiver in it, cabled up to this thing. [11:19.650 --> 11:23.690] And it had part of the inconvenience of it only to work on a certain set of telephones. [11:23.730 --> 11:25.310] They had little modules they had to plug into them. [11:26.630 --> 11:33.750] That was the product that actually basically invoked, that provoked the whole thing with the clipper chip. [11:34.430 --> 11:44.530] So what happened is AT&T, you know, they're big, it's the same guys that are doing the Stu-3s, they go talk to their buddies at the NSA and say, hey, we're looking to do this, we want to secure commercial communications in the U.S. [11:44.610 --> 11:47.110] And their buddies go, ooh, that's a good idea. [11:47.330 --> 11:50.310] Ooh, hmm, let's see, we've got an idea for you. [11:51.110 --> 12:03.690] And so what actually happened at that point is that they redesigned the box, same form factor and everything except there was now this clipper chip in it that it had this feature that it transmitted the keys to the feds. [12:03.710 --> 12:07.050] Plus it used a classified algorithm so no outside people could vet it. [12:07.970 --> 12:12.610] Years have gone by and it turned out it was skip-jack and, yeah, it's been, now people know how it works. [12:12.910 --> 12:21.190] There's one piece of the key exchange algorithm that's still classified, but pretty much people have a pretty good idea of how it works, just first principles and how it could work. [12:23.150 --> 12:26.650] But that's where they really shot themselves in the foot because no commercial people wanted it. [12:26.870 --> 12:37.670] They, in fact, offered how they did for, they had a few customers that had the single DES version and they wanted them all back and then they were going to, quote, upgrade you, unquote. [12:38.070 --> 12:40.890] And there was going to be no warranty support on the single DES ones. [12:41.030 --> 12:43.550] So those are really quite nice little collectors I have right now. [12:43.970 --> 12:48.090] The people that I know that had purchased a number of them certainly weren't sending them back for the upgrade. [12:48.590 --> 12:50.770] They just bought some of the other ones just to have. [12:52.570 --> 12:56.230] Then I got interested in about 92, 93 with this clipper chip. [12:56.470 --> 13:01.890] And I spent about two years figuring out from like ground zero how to build a secure phone. [13:02.010 --> 13:05.830] And this is, you've got to remember, this is before there was a voice over IP or anybody who really knew what was going on. [13:05.890 --> 13:13.650] Spent a bunch of time at the Berkeley Engineering Library reading through a bunch of stuff and talking to people, talking to Whit Diffie and some folks about, gee, where do we go from here? [13:13.650 --> 13:14.230] What does it take? [13:14.470 --> 13:15.470] Tell me about this crypto. [13:15.570 --> 13:16.250] Where should I read? [13:18.170 --> 13:21.470] So we built some boxes, sold a few of them. [13:21.630 --> 13:24.710] Again, it was kind of like, okay, how do they use, who wants to use them? [13:25.470 --> 13:31.530] Then responding to the next company, which is Starium, which is the device that you were sending around, which is again targeted at the commercial marketplace. [13:32.030 --> 13:40.910] A couple of lessons we've learned with this, and kind of my words of wisdom, is what I've found so far is that people really won't pay much for crypto. [13:41.370 --> 13:44.970] There are a few people who will say, yeah, I'll pay $5,000 for it. [13:45.070 --> 13:53.970] But if you're actually trying to put a business plan together that's going to take the risk of building hardware, which is always an expensive proposition, that you need a business plan that really is going to make you serious money. [13:54.490 --> 13:57.150] And at this point, I haven't found it with secure phones. [13:57.390 --> 14:04.570] My personal holy grail is really to get all the crypto into a cell phone, into the device that I already carry. [14:04.790 --> 14:06.690] I mean, like in my office, I don't have wired lines. [14:06.810 --> 14:08.830] It's like, you know, I've got DSL and a cell phone. [14:08.890 --> 14:09.830] Why would I need a wired line? [14:09.830 --> 14:12.070] So in one fact, I'm kind of like the cobbler with the children. [14:12.130 --> 14:14.330] I've got the box of secure phones and nothing to plug them into. [14:16.650 --> 14:18.010] So we learned some lessons about that. [14:18.110 --> 14:20.710] So one of which is if they're at all inconvenient, people won't use them. [14:20.830 --> 14:29.370] This is the same story I got from talking to military users of the Stu-3s, and they're even more inconvenient to use than all the commercial stuff because they have different key management and all this. [14:30.050 --> 14:32.050] But if the thing's at all inconvenient, people won't use it. [14:32.110 --> 14:39.430] So it's the reality of, you know, you have a hard to use piece of software, people don't use it, or if it kills your files, or if it's anything inconvenient, it won't get used. [14:39.630 --> 14:43.030] So this is sort of my words of wisdom to my colleague here. [14:45.170 --> 14:47.810] The other thing is I don't think that people want it cheap or free. [14:47.950 --> 14:54.830] So there's an opportunity in here somewhere for, like, an open-source version running either on some inexpensive hardware or some commodity hardware. [14:54.970 --> 14:57.390] But again, I think you've got to get it down to a small size. [14:58.750 --> 14:59.190] Questions? [15:00.250 --> 15:00.570] Yeah. [15:01.090 --> 15:01.910] Stand on the mic, please. [15:03.950 --> 15:13.790] Yeah, well, as I remember, does anybody remember the attempt to basically use general-purpose computers for secure voice communication, namely PGP Phone? [15:13.950 --> 15:14.110] Yeah. [15:14.290 --> 15:18.750] And it had the clever thing for defeating man in mental attacks. [15:19.510 --> 15:21.570] Do you know anything or want to speak on that issue? [15:22.090 --> 15:22.530] Sure. [15:22.690 --> 15:23.310] So I'll talk a little bit. [15:23.370 --> 15:24.390] Do you want to talk about PGP Phone? [15:25.510 --> 15:37.410] PGP Phone was an attempt by Phil Zimmerman, who also created the email version or the text version PGP, to create a secure telephone using IP telephony. [15:37.830 --> 15:50.610] And what they did is basically the same thing that's happening here, A to D conversion, compression, and then instead of sending it over a modem and a telephone line, it was sent over the Internet to the other side. [15:51.550 --> 15:54.530] And there's a number of reasons why that never went anywhere. [15:55.330 --> 16:01.430] What they also did is they had a clever system where it would list either words or hex digits on either side. [16:02.350 --> 16:20.430] And this would be your means of knowing for sure that the NSA wouldn't be in the middle with two of these devices, because that's the man in the middle attack that everybody's been talking about is what happens if the NSA is in the middle with two of these devices that autonomously set up some kind of magic key. [16:20.670 --> 16:27.890] Then they could negotiate a key with each side and just hook the analog parts together and have the phone audio. [16:27.890 --> 16:34.690] And the property of this Diffie-Hellman magic thing that we're talking about is what happens. [16:36.530 --> 16:48.810] You can make sure that it is impossible for the person in the middle, the man in the middle, Eve, the NSA, whoever, it's impossible to negotiate the same key with both parties. [16:48.810 --> 16:52.930] So they would actually be forced to negotiate a different key with each party. [16:53.210 --> 17:07.070] And by hashing the key or by hashing some part that leads to the key and displaying a number of digits, you can make sure that if these two people can verify over the phone using their voice, can verify that these digits are the same on both their displays, [17:07.330 --> 17:08.750] that there is no man in the middle. [17:09.350 --> 17:21.410] And, of course, there's still the possibility of them sitting live in each conversation ready with the voice impersonators, going, they're going to say it now, and break the voice and say different things on these two lines. [17:21.630 --> 17:30.590] But it would make it incredibly hard and it would make it impossible to do that, or near impossible to do that in anything but real time. [17:30.850 --> 17:33.530] So this is this man in the middle protection we're talking about. [17:33.710 --> 17:50.550] Anyway, PGP incorporated, did PGP phone as sort of a side project, which was conveniently sidetracked when NAI, which by coincidence is a major defense contractor, bought PGP Inc. [17:52.210 --> 17:54.170] I guess that's one way of saying it. [17:54.370 --> 17:58.410] Another reason it never went anywhere is the same, because there's other things which do the same thing. [17:58.530 --> 18:01.430] There's speak freely, which is really nice. [18:01.430 --> 18:05.970] It doesn't have the Diffie-Hellman setup, so you need a secret to put into it. [18:06.010 --> 18:08.550] You need a password, but you can send that on PGP or something. [18:09.150 --> 18:12.310] But there's a number of other tools out there. [18:12.550 --> 18:18.530] There's a standard for IP telephony, the H323, and there's ways of securing that. [18:18.650 --> 18:20.950] You could even run that over a link that has IPsec. [18:22.130 --> 18:32.390] The main problem why IP telephony as a whole never went anywhere is that people don't necessarily sit at their computer or are ready to launch applications at the time the phone rings. [18:33.770 --> 18:39.750] So people want to talk to you and they can't reach you because your computer is not on, you're not with your computer, you don't carry your computer. [18:39.990 --> 18:49.950] This will all go away when we have instantaneous fast IP connections in our pockets with the next generation of cellular phones, at which point all these things converge back again. [18:49.950 --> 18:51.290] But this is another reason. [18:51.450 --> 18:53.650] It's not just an AI buying PGP Inc. [18:53.710 --> 18:56.910] It's also IP telephony as a whole never going anywhere. [18:57.330 --> 19:00.570] Another thing with the problem with PGP Phone Hat is it really... [19:00.570 --> 19:04.050] It sounded pretty good when you're running on a local area network, but it didn't work well at Dialog. [19:04.390 --> 19:06.210] It also had some user interface problems. [19:06.330 --> 19:07.490] They were using conventional modem. [19:07.850 --> 19:14.890] So it required that you had to know that the call was coming in, and oh, now I have to push this button on the receive as opposed to answering hello. [19:15.850 --> 19:20.410] So there was a bunch of, again, this is the thing about if the thing's hard to use or inconvenient, people won't use it. [19:20.870 --> 19:26.490] Part of why we built hardware that was specific to this thing is you want to be able to use this on your regular phone line. [19:26.650 --> 19:35.590] You want the call to come in and you'd be in the clear and say hello, and then, you know, maybe I'm talking to my mother, she doesn't have the secure phone, or maybe now I'm talking to somebody who does. [19:35.970 --> 19:46.830] The way that the AT&T units and our units work was you just one party or the other pressed the big green go secure button, and it would, the other end noticed automatically and just cut over in a secure mode. [19:47.330 --> 19:49.090] So again, this is back to this thing about usability. [19:50.210 --> 19:50.870] Another question? [19:51.390 --> 19:51.790] Yeah. [19:52.150 --> 20:02.110] I wonder if you'd mind giving the capsule summary about digital cell phones and what kind of crypto is in use and what kind of eavesdropping it might defend against. [20:02.550 --> 20:03.970] Some of my favorite rants. [20:04.070 --> 20:04.650] Thank you very much. [20:04.650 --> 20:12.270] So in the US, we've got GSM cell phones, we have the IS-136 cell phones, which are the TDMA ones. [20:12.350 --> 20:14.770] Those are the ones that AT&T Wireless currently has deployed. [20:15.290 --> 20:18.510] And then there's the CDMA ones, IS-95. [20:19.830 --> 20:30.670] The IS-136 ones, for the longest time, they have, you read the specification, there's an opportunity for crypto to be in there for voice privacy. [20:30.670 --> 20:34.710] But it turns out they've done a reasonably good job of protecting their billing information. [20:35.050 --> 20:44.110] So part of the big push for the cell phone operators, and rightfully so, was they had a huge fraud problem with the AMPS phones, because all the billing information was sent in the clear. [20:44.290 --> 20:46.150] This is what the cloning problems and all this. [20:46.710 --> 20:48.270] So they pretty much fixed that. [20:48.390 --> 20:51.910] As far as I can tell, I don't hear them, I don't hear the operators complaining. [20:52.590 --> 20:56.910] But really, it was a token gesture on what they were going to do to provide voice privacy. [20:57.110 --> 21:00.530] And again, this would also just have been between the mobile and the base station. [21:00.530 --> 21:05.550] So then, of course, it's in the clear across the public switch telephone network, and then basically back in. [21:05.710 --> 21:13.490] But it turns out that the crypto that they spec'd for this thing was a fixed mask that was XR'd across each vocoder frame and never changed. [21:13.790 --> 21:16.490] So you've got like this 160-bit long vocoder frame. [21:16.590 --> 21:19.170] You have a fixed mask that, you know, who cares how they generate it? [21:19.270 --> 21:20.030] It makes no difference. [21:21.290 --> 21:25.190] Another thing to know is that the phones run with what's called discontinuous transmission nodes. [21:25.190 --> 21:32.050] So that when you stop talking, there's like three vocoder frames that are statistically silenced and then the thing stops transmitting. [21:32.230 --> 21:33.790] So all I've got to do is I've got to watch. [21:33.930 --> 21:35.190] I'm just watching, watching, watching. [21:35.330 --> 21:36.390] I say, oh, you stopped transmitting. [21:36.450 --> 21:39.370] That means that statistically the last three frames were silenced. [21:39.610 --> 21:40.510] Which gets me close. [21:40.590 --> 21:43.350] And I can just compute backwards because I know the structure of the vocoder frame. [21:43.730 --> 21:50.710] And that gets me right back to close enough to what the values are, because it's a fixed XOR mask, because I can solve... [21:50.710 --> 21:54.030] I know what the frame looks like, more or less. [21:54.170 --> 21:55.730] I mean, I don't know some of the low bits, but big deal. [21:55.850 --> 21:58.510] The vocoders are designed to work in the presence of errors. [21:59.230 --> 22:04.330] Also, there was kind of a mis-feature, which was that the foreign error correction was on the wrong side of the crypto. [22:05.350 --> 22:08.710] And this is like, okay, gee, it seems backwards, doesn't it? [22:09.030 --> 22:10.530] This goes back to sort of the history. [22:10.630 --> 22:14.130] I've talked to people who were at these meetings where the standards were set. [22:14.670 --> 22:20.630] There was a classic, you know, NSA making recommendations to the cell phone companies at the time. [22:20.650 --> 22:32.210] This was before the crypto exports had eased up, saying, wow, you know, if you don't want to have a problem with that, if you want to be able to sell that thing anyplace, I suggest you make these changes here. [22:32.510 --> 22:33.950] So that's the IS-136. [22:34.090 --> 22:38.310] And also, up until... I've been looking for eight years. [22:38.690 --> 22:47.590] And somebody finally told me they'd actually seen a base station that accepted the request of the handset to go to the enhanced privacy mode, which wouldn't have made any difference anyway. [22:47.750 --> 22:51.670] But we looked all over the U.S. for this. [22:51.790 --> 22:56.870] And finally, somebody reported, yes, they found one in one location, a base station that accepts the handset's request. [22:57.010 --> 23:00.070] The handset, you could configure your little phone, say, enhanced voice privacy. [23:01.050 --> 23:04.790] You place the call and you get this warning beep, you know, voice privacy not available. [23:04.930 --> 23:07.970] So you eventually turn it off because it beeps on every call you place and every call you receive. [23:07.970 --> 23:10.950] I played this trick with my wife's phone because she's subscribed to that. [23:11.130 --> 23:12.950] I got different carriers so we can kind of try them all out. [23:13.390 --> 23:14.590] She's like, turn this thing off. [23:14.710 --> 23:15.550] It beeps on every call. [23:16.210 --> 23:18.490] So anyway, now I've heard that it's turned on someplace else. [23:19.270 --> 23:23.050] The IS-136 stuff, this is the spread spectrum. [23:23.570 --> 23:25.390] Now, the big... [23:25.390 --> 23:26.130] IS-95. [23:26.130 --> 23:26.490] IS-95, sorry. [23:29.030 --> 23:31.330] You know, it's got a 42-bit key. [23:31.770 --> 23:35.310] You know, it's like, oh, a huge number of combinations and all this. [23:35.310 --> 23:43.350] Well, it turns out that the forward channel, which is from the base station to the mobile, it turns out there's only 64 spreading codes used. [23:43.550 --> 23:44.090] They're known. [23:44.810 --> 23:50.110] So that if you build the right piece of equipment, you basically, you can receive all of the raw bits. [23:50.310 --> 23:55.510] So there's no problem in finding the bits from the base station to the mobile. [23:56.170 --> 24:02.150] So now the trick is, oh, gee, you look at this, you read the specification, you go, God, this looks like it's got some problems. [24:02.190 --> 24:04.810] There's like a whole lot of redundancy in this thing. [24:05.350 --> 24:10.750] And you also look at the, quote, crypto function, unquote, and it turns out it's a linear function. [24:11.310 --> 24:16.550] So you're going to go, oh, my, we've got redundancy in this signal, and we've got a linear function. [24:16.690 --> 24:24.090] Well, it turns out that you, with a little bit of algebra, turns out you can set up 42 equations and 42 unknowns. [24:24.090 --> 24:26.230] And this is, you know, in Z sub two. [24:26.450 --> 24:28.250] So the unknowns are zero or one, you know. [24:28.590 --> 24:31.770] And so you get 42 equations, 42 unknowns, you can solve this in no time. [24:32.350 --> 24:37.330] If the guy isn't talking when you happen to look, it turns out you can get it in one vocoder frame. [24:37.970 --> 24:42.650] And if he's talking, it takes maximum one second to gather enough data. [24:42.950 --> 24:49.410] And what the difference is, is that they, there's a field of 24 bits in the frame. [24:49.670 --> 24:57.350] And of that field of 24, there are 16 bits that are subject to getting really randomly smashed that communicates some power control information. [24:57.790 --> 25:00.630] So you only have eight bits out of 24 that you can really count on. [25:00.730 --> 25:03.390] So that's why it takes a whole second to gather the data you need. [25:03.650 --> 25:15.390] Now, the other piece in the, you know, cellular telephony conspiracy theory thing is that there's a patent issued to AT&T researcher, Jim Reeds, that was the fix for this problem. [25:15.470 --> 25:21.630] And this patent was, like, written and submitted prior to the IS-95 standard even being accepted. [25:22.070 --> 25:24.290] So it was, like, this problem wasn't, the problem was known. [25:24.930 --> 25:25.790] Nobody's talking about it. [25:25.890 --> 25:28.670] Of course, you're not going to see Qualcomm going to go, yeah, there's a problem, no kidding. [25:28.870 --> 25:30.990] You know, smart people have been breaking this thing from the get-go. [25:31.910 --> 25:33.170] So that's the word on those two. [25:33.270 --> 25:36.570] Now, the GSM one, as far as we know, is actually holding up pretty well. [25:37.410 --> 25:38.830] There have been some attacks. [25:39.770 --> 25:42.870] I don't know, I personally don't know of anybody that's done the off-the-air attack. [25:43.190 --> 25:48.210] There's the one that takes, like, the 170 gigabytes worth of disk space, which is clearly doable right now. [25:48.210 --> 25:51.050] I think it takes a minute's worth of data. [25:51.050 --> 25:53.670] It takes a minute's worth of data or something. [25:53.830 --> 25:54.430] It's more data. [25:54.650 --> 25:56.850] I personally don't know anybody who's run the attacks. [25:56.970 --> 25:58.130] I can't say, but it's doable. [25:58.570 --> 26:06.910] The other thing is that the SIMs, the vast majority of the SIMs, I think it's like 80% of them, have the low 10 bits in the key that the generator is zero. [26:07.590 --> 26:09.350] So this is like, oh, we're helping again. [26:10.530 --> 26:24.890] So that's... and the other thing on the GSM, I know that this is the way they do it in the UK, is that although they, you know, the air interface is encrypted, the backhaul from the cell site back to basically the next level up in the chain is a line-of-sight microwave link, [26:24.970 --> 26:25.690] it's unencrypted. [26:26.010 --> 26:30.830] And apparently GCHQ co-locates with those guys, which just solves that problem. [26:30.990 --> 26:31.790] You don't have to talk to anybody. [26:32.470 --> 26:32.730] Okay? [26:35.190 --> 26:36.990] I apologize if I missed this. [26:36.990 --> 26:37.970] I came in somewhat late. [26:38.090 --> 26:47.230] I've seen advertisements for secure GSM phones being available in Europe, which would obviously be available once our infrastructure comes up. [26:47.390 --> 26:55.690] But I was wondering if there are certain regulatory or just sheer cost hindrances that are preventing that from being made available here in the States. [26:55.930 --> 26:56.730] I think of the Tiger. [26:57.050 --> 26:58.190] Yeah, the Sektra. [26:58.290 --> 26:58.630] Yeah. [26:58.950 --> 26:59.950] Sektra Tiger, I think. [27:00.090 --> 27:09.230] And it's now, I think, approved for NATO use up through Secure, but not top secret, which is something to take note of. [27:11.410 --> 27:14.110] What I know about those is it appears to actually... [27:14.610 --> 27:17.790] The phones are relatively expensive, like in the thousands of dollars. [27:18.090 --> 27:30.690] They also require a call to a key management facility, so they don't stand alone, which is kind of a funny environment, because if you were really talking about a wartime, I don't really want to have more than... [27:30.690 --> 27:32.410] I don't want to have extra parts that have to fail. [27:32.870 --> 27:38.430] Like if you look at how STU-3 works, it talks to a key management facility, but not very often. [27:38.790 --> 27:47.010] It gets a key revocation list, and it initially gets its key material, but then it doesn't have to talk to the KMF again for like a long, long, long time, months. [27:47.310 --> 27:50.390] So in case the KMF is boom, you know, we can still keep talking. [27:51.550 --> 27:53.710] STU-2 had to talk to the KMF every time. [27:53.930 --> 27:55.190] So I don't know. [27:55.510 --> 27:57.330] Part of the reason is that... [27:57.330 --> 28:00.690] I mean, I've looked at doing secure GSM cell phone. [28:00.690 --> 28:04.630] The way that it looks to me like you've got to do it, is you've got to have a partnership with a phone manufacturer. [28:04.890 --> 28:06.650] You certainly don't want to go build your own phone. [28:06.790 --> 28:07.930] That's going to be extremely expensive. [28:08.510 --> 28:09.790] Again, it's what are people willing to pay. [28:09.950 --> 28:14.830] I mean, everybody pretty much, at least in the U.S., has got a subsidized phone, so nobody really knows what a phone costs. [28:14.930 --> 28:16.870] Oh, mine goes $49, or mine was free! [28:17.130 --> 28:17.850] You know, it's like... [28:17.850 --> 28:20.410] You know, who knows what the real cost is. [28:20.510 --> 28:28.610] I think the real cost, as far as I can tell, is on the order of about $150 bucks, is what the guys who build the phones sell them to the next level up. [28:29.510 --> 28:32.750] So let's say that you could sell a $450 secure cell phone. [28:32.850 --> 28:33.270] It's possible. [28:33.770 --> 28:37.270] Then there's some issues with regard to how good it sounds, because you have to use the data channel. [28:37.990 --> 28:39.910] Because you want to push bits across this thing. [28:40.630 --> 28:43.430] And our experience says that how... [28:43.430 --> 28:46.610] what kind of latency the data channel has really varies depending on the operators. [28:47.170 --> 28:48.370] Nobody's optimized it. [28:48.370 --> 28:50.170] They just, you know, they think you're sending emails. [28:50.350 --> 28:52.890] They don't care what the latency is. [28:54.070 --> 28:54.350] So... [28:54.350 --> 28:56.290] But really no fundamental reason it couldn't. [28:56.390 --> 28:56.730] Yeah, Ryan. [28:57.010 --> 29:07.050] The Tiger also has the interesting feature that if you don't have access to the communications management server, it will default to a fixed key, which is the same on all the phones, according to Mr. Lucky Green. [29:07.350 --> 29:08.350] Oh, that's convenient, yeah. [29:10.610 --> 29:11.550] There's another phone. [29:11.650 --> 29:15.370] There's one being sold by Rhode & Schwarz, which is the... [29:15.370 --> 29:19.150] who is Nachrichtendienst shopped for interesting telecoms equipment. [29:20.470 --> 29:23.370] And that phone was originally built by Siemens. [29:23.470 --> 29:26.290] It is a Siemens phone with a special module in it that does the crypto. [29:26.650 --> 29:27.990] And it's also a GSM. [29:28.070 --> 29:29.010] Yeah, it's a G35. [29:29.270 --> 29:30.430] Yeah, it's like... [29:30.430 --> 29:34.490] It's a fairly standard Siemens model with an extra hardware module in it. [29:34.850 --> 29:35.030] Yeah. [29:35.370 --> 29:38.210] And I think when I look that one up, they don't tell you what the... [29:38.210 --> 29:40.590] You get no info really on what the crypto has. [29:40.690 --> 29:43.470] It says, you know, how many bits, but it doesn't say if it's like XOR or what. [29:43.650 --> 29:44.390] It's really good. [29:45.850 --> 29:46.410] Trust us. [29:46.590 --> 29:47.030] We're your friends. [29:47.150 --> 29:47.590] It's really good. [29:47.810 --> 29:50.170] I've also heard of an Israeli phone. [29:50.350 --> 29:52.830] I haven't seen it yet, but I heard from some people snooping around. [29:52.950 --> 29:53.570] I haven't seen it in the US. [29:53.610 --> 29:57.630] I haven't seen the advertising for it, but I heard that there's an Israeli secure phone now. [29:57.970 --> 29:58.770] But again, I haven't seen... [29:58.770 --> 29:59.750] I don't know any information about it. [29:59.910 --> 30:00.750] It's supposed to be inexpensive. [30:01.610 --> 30:07.830] When mentioning Rhode and Schwartz, you should mention that they also support the Bundesnader deeds with the IMSI catcher. [30:08.530 --> 30:15.750] So to be perfect on the man of the middle attack, enabling so-called crypto mode, which is far more convenient even. [30:15.990 --> 30:16.670] Very good. [30:16.850 --> 30:17.250] Thank you. [30:17.470 --> 30:19.850] It's like the Converse people, your friends, right? [30:19.850 --> 30:21.150] They rebuild their... [30:21.150 --> 30:25.950] For those of you who don't know who put Converse, there was this big scandal that went away in the US. [30:26.170 --> 30:39.430] But again, rants on phone stuff, is that there was Amdocs, which is a company that it turns out they provide all the billing services for all of the phone companies in the US. [30:39.990 --> 30:41.210] They just priced it really low. [30:41.350 --> 30:45.950] It turns out it's an Israeli-owned operation, and who knows why they're able to bid so low. [30:46.110 --> 30:49.190] But if you think what they get is all the traffic. [30:49.190 --> 30:51.050] They get complete traffic analysis data. [30:51.270 --> 30:52.930] And they're selling it to the U.S. [30:53.110 --> 30:58.150] Here, we'll underbid you, and we get all the traffic analysis data. [30:58.430 --> 31:12.650] And then there's Converse, who, what they build are the lawful intercept equipment that has been mandated by CALEA, the Communications Assistant to Law Enforcement Act, which is the right name for it. [31:12.690 --> 31:17.910] The working title for that was the Privacy Improvement and Digital Telephony Act, or whatever it was. [31:17.910 --> 31:21.950] I think the Communications Assistant to Law Enforcement Act. [31:22.090 --> 31:27.390] But the working title before that was Digital Telephony and Privacy Improvement. [31:27.550 --> 31:29.830] It was a total double-speed claim. [31:31.050 --> 31:32.350] Okay, another question? [31:33.630 --> 31:35.510] Getting back to your holy grail again. [31:36.550 --> 31:38.630] The guy was talking about the Internet in your pocket. [31:38.630 --> 31:50.590] Do you see some sort of, maybe with Java in the phone, possibly an open-source application in the phone that could just be distributed easily doing crypto either over the data channel or possibly over the voice channel? [31:50.790 --> 31:51.190] Absolutely. [31:51.370 --> 31:52.250] Rob, do you want to talk about that? [31:52.250 --> 31:52.370] Yeah. [31:53.110 --> 31:55.710] He's whipping out the leading-edge PDA. [31:55.910 --> 31:56.470] I'm whipping out the device. [31:56.830 --> 32:01.970] This is now for sale in Europe, and they will be for sale here, or phones of this type. [32:03.310 --> 32:07.470] It's rebranded as O2, which is one of the larger carriers, formerly Orange, out of England. [32:08.510 --> 32:11.790] It's called the XDA, and it's basically a pocket PC device. [32:11.790 --> 32:12.850] I'm sure you can't see it. [32:12.850 --> 32:16.950] It's an IPAC with a phone built in, and it has GSM GPRS telephone. [32:17.270 --> 32:18.470] So it does packet switched. [32:19.010 --> 32:20.370] It's always on Internet. [32:20.870 --> 32:25.250] Although the latency on this packet switch network is way too insane to do any kind of voice over. [32:26.730 --> 32:33.350] It also will do GSM data calls, which are 9600 and have a still insane but fixed latency. [32:33.670 --> 32:35.270] So at least you can talk to each other. [32:35.670 --> 32:48.710] And we're in the process of developing an application for this, which will basically run the secure telephone, because the organizer part, the IPAC part, is powerful enough where it could do the codec, the crypto, the key management, and the user interface. [32:48.950 --> 32:51.370] And it would only need the GSM part to make a data call. [32:51.590 --> 33:01.230] The thing about doing it over the voice channel is that the voice channel on the other end gets converted back into analog and back into digital, or at least you can't count on it staying digital. [33:01.770 --> 33:10.410] And since this compression is lossy, and since the crypto can't deal with lossiness, you would end up with no audio. [33:10.410 --> 33:13.990] So it has to be the data channel, which has good and bad parts. [33:14.170 --> 33:17.570] But we're working on an application that will run inside these phones. [33:18.370 --> 33:35.870] And where we're going is we're all going to have, whether it's this network or the next generation CDMA networks or even the next generation of mobile telephone networks altogether, we're all going to have phones which are very capable of running this whole application in software. [33:35.870 --> 33:51.270] We just have to make sure that by that time that we have them, there's no chip built in there, which doesn't allow running any applications which haven't been first screened, so that they can't violate any digital rights management schemes. [33:51.770 --> 33:51.950] Right, yeah. [33:51.950 --> 33:54.690] You might be shipping music or something. [33:54.950 --> 33:55.510] Yes, yes. [33:55.690 --> 34:00.050] That would be even worse than anything, than any other conversations you could be having. [34:01.010 --> 34:04.030] Anyway, so be on the lookout for these phones. [34:04.630 --> 34:08.930] I'll be talking a little bit more about it at six when we discuss all our other projects as well. [34:09.110 --> 34:12.410] But this is what we're working on, and this is where it's going, this type of phone. [34:14.770 --> 34:15.590] We have it. [34:15.590 --> 34:15.710] We have it. [34:15.990 --> 34:16.190] It's here. [34:16.410 --> 34:16.930] It's here. [34:17.030 --> 34:20.910] Don't find it in Kansas, but I mean, pretty much, that's what I use. [34:21.590 --> 34:22.410] It's called... [34:22.410 --> 34:24.050] It's the 1900 band. [34:24.250 --> 34:25.190] There's three GSM bands. [34:25.290 --> 34:27.470] There's 900, 1800, and 1900. [34:27.970 --> 34:30.270] And in Europe, there's 900 and 1800. [34:30.750 --> 34:33.410] Verizon's a CDMA carrier. [34:33.770 --> 34:34.990] So where do you live? [34:36.730 --> 34:37.330] I don't know. [34:37.530 --> 34:38.130] Who is Pennsylvania? [34:38.330 --> 34:39.170] Who knows the name of the... [34:39.170 --> 34:39.830] VoiceDream. [34:40.130 --> 34:40.910] VoiceDream, okay. [34:41.730 --> 34:43.810] It's singular where I live, but it's VoiceDream. [34:44.130 --> 34:45.050] It's singular where I live, but it's VoiceDream. [34:45.830 --> 34:46.670] Yeah, yeah. [34:46.990 --> 34:50.650] It all depends on where you are, but singular in my neighborhood is GSM. [34:50.890 --> 34:51.950] VoiceDream is GSM. [34:52.550 --> 34:54.250] Verizon is selling that handset now. [34:55.750 --> 34:58.590] Okay, but Verizon is a CDMA operator. [34:58.790 --> 34:58.950] CDMA. [34:59.330 --> 34:59.630] Right. [35:00.190 --> 35:01.070] But that would still work. [35:01.170 --> 35:03.570] I don't know how they interoperate from the GSM to the... [35:03.570 --> 35:09.850] Part of this whole thing is that, in answer to the question that was back here in Rob's answer, is really, these are convergent. [35:10.490 --> 35:16.090] Because really, for us folks that like to make secure calls, what we need are some horsepower in the phone, and we need a bit pipe. [35:16.610 --> 35:21.210] You give us a bit pipe and some horsepower in the phone, and access to the speaker and the mic, and we've got it done. [35:22.170 --> 35:24.550] So the crypto is like a well-understood problem. [35:24.830 --> 35:25.490] This is... [35:25.490 --> 35:27.990] And the phones now are having enough MIPS to run it. [35:29.230 --> 35:29.690] So... [35:29.690 --> 35:29.970] Okay. [35:30.730 --> 35:36.750] In addition to the information that's being transmitted, oftentimes just as important is who's talking to who. [35:37.010 --> 35:38.650] Is there anything being done about that? [35:38.950 --> 35:40.870] The question is who's talking to whom. [35:41.070 --> 35:45.450] The endpoints, the traffic, the call setup information, which also in the U.S. [35:45.490 --> 35:49.170] is available for like, you know, you don't even... they don't need any... [35:49.170 --> 35:53.510] Almost no... probably after the Patriot Act, they probably just have to just call and ask for it. [35:53.690 --> 35:54.250] And it's... [35:54.250 --> 35:55.710] There's a very low standard. [35:56.070 --> 35:57.450] They're called pen registers as well. [35:57.550 --> 35:58.110] It's called the law. [35:59.690 --> 36:00.830] The... I don't know of any... [36:00.830 --> 36:04.190] If you're going to use a regular switched telephone network, they're going to have it. [36:05.890 --> 36:07.430] Well, the Internet stuff, there's all kinds of... [36:07.430 --> 36:08.510] There's all kinds of ways, but it's... [36:08.510 --> 36:11.410] It comes down to the same mix master kind of problem that people have with email. [36:11.730 --> 36:13.350] And it's a surprisingly hard problem. [36:14.170 --> 36:14.890] And it's... [36:14.890 --> 36:15.450] There's... [36:15.450 --> 36:17.470] There's zero knowledge attempted to... [36:17.470 --> 36:19.530] To solve the problem in... [36:19.530 --> 36:21.510] In the context of streaming data. [36:21.890 --> 36:23.070] And in the context of... [36:23.070 --> 36:24.990] Context of streaming data, it's... [36:24.990 --> 36:26.910] At present, pretty much impossible to solve. [36:27.470 --> 36:32.690] Even with the amount of bandwidth available on the Internet, it's still fairly trivial for... [36:32.690 --> 36:35.650] For a determined attacker to find out what stream is going where. [36:37.850 --> 36:37.990] Okay. [36:38.050 --> 36:38.190] Go ahead. [36:38.450 --> 36:39.190] Can you elaborate? [36:39.930 --> 36:42.430] Can you elaborate on the answer you gave in a few minutes? [36:42.430 --> 36:44.050] Are you actually talking into the mic? [36:45.010 --> 36:45.950] I'm right in there. [36:45.950 --> 36:47.070] Are you right into the mic? [36:47.070 --> 36:48.110] It's not coming out. [36:48.490 --> 36:49.410] Can you hear me? [36:49.630 --> 36:50.010] I can hear. [36:50.050 --> 36:50.730] I'll repeat the question. [36:50.870 --> 36:51.250] Go ahead. [36:51.330 --> 36:52.250] Can I elaborate on what? [36:52.630 --> 36:55.950] On the thing about the billing information being shipped out of the country? [36:56.230 --> 36:57.250] The billing information. [36:57.410 --> 36:58.070] This was run... [36:58.070 --> 37:02.490] An investigative reporter for Fox ran an article. [37:02.690 --> 37:03.230] It ran on... [37:03.230 --> 37:04.470] It was on Fox's website. [37:04.650 --> 37:05.490] I don't know when this was. [37:05.610 --> 37:10.090] It was a piece of the 9-11 post that some of the Israelis were detained. [37:10.090 --> 37:10.630] But... [37:11.370 --> 37:13.690] And then this guy asked all these embarrassing questions. [37:14.010 --> 37:16.050] And one of the things was... [37:16.050 --> 37:17.570] I mean, in one sense, it's just straight business. [37:17.710 --> 37:21.690] But on the other, it's like perfect, legitimate espionage operation. [37:26.090 --> 37:26.830] They're subsidized. [37:26.930 --> 37:27.170] Absolutely. [37:27.370 --> 37:29.250] I mean, it's a brilliant piece of work. [37:29.410 --> 37:30.410] You go, like, yay! [37:30.410 --> 37:31.170] Go team! [37:31.370 --> 37:32.110] I mean, it's like brilliant. [37:32.570 --> 37:39.450] So the deal is, they just offer a service to the RBOCs called, we will handle your billing issue. [37:39.530 --> 37:42.630] You just send us the tapes, whatever they send, you know. [37:42.630 --> 37:46.890] Send us the tapes with all the, this phone number, call this phone number, and talk this long. [37:47.570 --> 37:47.910] Right? [37:47.970 --> 37:48.830] Which is really the endpoints. [37:48.970 --> 37:49.590] Call came up. [37:49.750 --> 37:50.730] You know, here's the two endpoints. [37:50.790 --> 37:51.390] Call went down. [37:51.830 --> 37:53.710] And they generate your bill for you. [37:54.790 --> 37:55.190] Okay? [37:55.350 --> 37:57.430] Now, again, this is like... [37:57.430 --> 38:02.270] Either this is just another company, and then it's not fair to say the Mossad's behind it. [38:02.530 --> 38:02.890] Right. [38:02.990 --> 38:07.390] Or the Mossad's behind it, and then it's really smart to say, nothing's going on here. [38:07.670 --> 38:08.410] Nothing's going on here. [38:08.810 --> 38:09.410] Who knows? [38:09.410 --> 38:12.870] I'm just saying, it's just pay no attention to the man behind the mirror. [38:13.030 --> 38:14.810] You know, they just happen to have the lowest thing. [38:14.990 --> 38:20.490] And if it's an accident, and of course, they, you know, they, of course, promised we would never do that. [38:20.650 --> 38:24.850] Just like, just like the telegraph companies in the U.S. promised they would never do that, and they just snuck it out the back door. [38:29.170 --> 38:33.910] You know, it's like, they came over in their envelopes and their couriers, and they hardly... [38:33.910 --> 38:35.250] By the way, the back door... [38:35.250 --> 38:39.010] Amdocs, A-M-D-O-C-S, is the name of the company that handles the billing information. [38:39.010 --> 38:41.270] And Converse is now renamed. [38:41.410 --> 38:43.170] It's now called Variant. [38:43.950 --> 38:44.250] Variant? [38:44.590 --> 38:45.130] Variant? [38:45.170 --> 38:47.970] Converse has been renamed because of this Fox report. [38:48.210 --> 38:48.410] Yeah. [38:48.630 --> 38:50.270] And it's now called Variant. [38:50.570 --> 38:51.170] Variant. [38:51.330 --> 38:53.510] Information at Quintessence.org. [38:53.510 --> 38:54.070] Okay. [38:54.490 --> 38:56.050] And they are big. [38:56.110 --> 38:57.570] They're big all across Europe. [38:57.870 --> 39:01.910] I remember one of the first times I'd heard of them was they were built... [39:01.910 --> 39:07.970] If you look at the 3G, the third generation phone specification, that actually has this whole section on lawful intercept. [39:08.510 --> 39:11.170] And Converse is, you know, we've got the turnkey solution for you. [39:11.510 --> 39:12.630] I mean, who knows? [39:12.690 --> 39:13.590] I'm not saying they did it. [39:13.670 --> 39:14.750] I'm not saying they're up to no good. [39:14.750 --> 39:15.270] It's just... [39:15.270 --> 39:16.730] I think it's a perfect coincidence. [39:18.330 --> 39:18.770] Maybe. [39:18.970 --> 39:19.050] Yeah. [39:19.330 --> 39:19.770] Maybe. [39:19.790 --> 39:21.070] Maybe they're really good at it. [39:21.150 --> 39:22.550] You know, they just have a more efficient system. [39:23.070 --> 39:24.070] Maybe they're data mining. [39:24.290 --> 39:24.530] I don't know. [39:24.950 --> 39:29.130] May I announce a meeting on the GNU telephony project that's upcoming? [39:29.790 --> 39:30.230] Okay. [39:30.230 --> 39:30.870] Go for it. [39:31.050 --> 39:31.210] All right. [39:31.310 --> 39:37.190] On Wednesday, July 31st, the New Jersey Lug is going to have David Sugar, who's the man behind the project. [39:38.250 --> 39:39.210] Gnu Bayon. [39:39.990 --> 39:41.530] It'll be out in New Jersey. [39:42.190 --> 39:44.990] If you look either at their site, NJ Lug. [39:45.210 --> 39:45.430] Okay. [39:45.490 --> 39:46.930] What is the GNU telephony project? [39:47.850 --> 39:48.330] Oh. [39:48.390 --> 39:49.270] Give us... [39:49.270 --> 39:50.390] I mean, I don't know what it means. [39:50.730 --> 39:50.990] Okay. [39:51.050 --> 39:52.290] Just tell me so we can... [39:52.290 --> 39:54.870] Part of Project GNU, the free operating system. [39:55.170 --> 39:55.310] Yeah. [39:55.830 --> 40:04.130] We have a telephony project that David Sugar created to provide all the software for doing all sorts of things on telephones. [40:05.770 --> 40:08.510] It's pretty advanced if you look up the stuff. [40:08.830 --> 40:08.970] All right. [40:09.150 --> 40:11.710] I have links to it on the LXNY site. [40:11.890 --> 40:12.150] Okay. [40:12.630 --> 40:13.170] All right. [40:13.310 --> 40:13.990] See this gentleman. [40:14.350 --> 40:14.710] All right. [40:15.030 --> 40:17.530] Our site is LXNY.org. [40:17.730 --> 40:18.090] Okay. [40:18.170 --> 40:18.450] Very good. [40:20.150 --> 40:20.590] Okay. [40:20.590 --> 40:22.710] We've got just about five minutes and then we've got to wrap here. [40:25.010 --> 40:25.930] Just step the mic. [40:26.610 --> 40:30.970] Historically, I just mentioned about the original Churchill Roosevelt stew phone. [40:31.190 --> 40:31.310] Yeah. [40:31.310 --> 40:32.910] I've only read of one phone. [40:33.070 --> 40:37.070] That started in 1937 from AT&T and the German post office cracked it. [40:37.670 --> 40:42.690] And they got a telephone conversation between Churchill and Roosevelt discussing things in Italy that were useful in 43. [40:43.130 --> 40:45.530] Was there a second phone that was secure after that? [40:45.670 --> 40:45.850] Yeah. [40:45.950 --> 40:46.310] I don't know. [40:46.790 --> 40:47.390] I don't... [40:47.390 --> 40:48.890] It's all in cons, the code breakers. [40:49.370 --> 40:49.510] Okay. [40:49.610 --> 40:51.190] The history of the original... [40:51.190 --> 40:51.390] Right. [40:51.530 --> 40:51.630] Yeah. [40:52.750 --> 40:53.710] Excellent historical. [40:54.030 --> 40:59.590] The code breaker, those of you who want your like crypto history up through about early 70s, is kind of excellent. [41:01.790 --> 41:02.750] I don't think... [41:02.750 --> 41:03.410] I don't think... [41:03.410 --> 41:03.770] Did you... [41:03.770 --> 41:04.510] It's all patched up? [41:04.830 --> 41:04.970] Okay. [41:05.070 --> 41:05.130] Great. [41:05.270 --> 41:05.370] Okay. [41:05.410 --> 41:08.150] We're going to run this phone demo here and then we'll... [41:08.630 --> 41:08.990] Okay. [41:09.110 --> 41:10.650] This phone calls that phone. [41:10.650 --> 41:11.110] focavered. [41:11.190 --> 41:11.710] It's totaled. [41:13.190 --> 41:13.510] Yeah. [41:13.670 --> 41:13.950] I think it was. [41:14.170 --> 41:14.510] Thank you. [41:14.710 --> 41:15.270] I've heard of it. [41:20.430 --> 41:20.960] Oh, that's a good, oh... [41:20.960 --> 41:22.180] I will run, run, run, run. [41:23.240 --> 41:24.120] Hello, hello, hello. [41:24.120 --> 41:28.520] Guys, unbalanced power, you're not going to get much through here. [41:28.660 --> 41:29.540] We can try to make it. [41:29.580 --> 41:30.120] I can hear you. [41:30.480 --> 41:30.950] Can we hear you? [41:30.950 --> 41:31.200] Can we... [41:31.200 --> 41:31.500] Can we hear you? [41:31.560 --> 41:31.700] Can we hear your mic? [41:31.870 --> 41:32.410] We got to hear you. [41:37.260 --> 41:37.580] Hello. [41:37.900 --> 41:38.080] Hello. [41:38.520 --> 41:38.600] Hello. [41:38.620 --> 41:38.660] Hello. [41:38.940 --> 41:39.260] Hello. [41:45.400 --> 41:45.720] Hello. [41:51.080 --> 41:52.020] I'm Mellis, how are we? [42:02.780 --> 42:09.880] We're going to go, we're going to go, we're going to go. [42:11.520 --> 42:13.000] Okay, we're going to go. [42:18.100 --> 42:19.400] Anyway, we have... [42:19.400 --> 42:20.060] Is [42:25.510 --> 42:26.630] that Y simulator here? [42:26.630 --> 42:27.930] No, that's okay. [42:30.190 --> 42:30.910] That's fine. [42:31.230 --> 42:38.090] I was just trying to think, if there's more phones at some other time, if people want to really get their hands on this thing, I'm pleased to send out some other phones. [42:39.670 --> 42:41.250] These are not available for sale. [42:41.390 --> 42:42.970] These were bathing units that were built. [42:44.630 --> 42:47.130] It's very good position right now, and they can't build anymore. [42:47.910 --> 42:51.850] So, that's the short... [42:52.370 --> 42:53.930] All right, I think we need to wrap up. [42:53.930 --> 42:55.330] Rob and I will be around. [42:55.610 --> 42:58.270] I guess we'll probably meet back there in the hallway or something if you have more questions. [42:58.470 --> 42:59.550] And thank you very much. [42:59.870 --> 43:06.930] And I'll be pleased to... Listen, if people have questions about this stuff in general, again, I have a vision for secure telephony being widely deployed. [43:07.310 --> 43:12.270] I happen to be working on software radio right now, having kind of burnt myself for about seven years on this. [43:12.370 --> 43:14.010] I was kind of like, I need to do something else. [43:14.150 --> 43:21.710] But if there's people who are interested in secure telephony, I know of one other group of people who want to do an open source, you know, system. [43:21.710 --> 43:24.550] So, you know, talk to me, I'll get you guys hooked up. [43:24.910 --> 43:26.010] All right, thank you very much. [43:26.110 --> 43:30.150] And there's more presentation of the stuff that we're presently working on here in this room at six. [43:30.150 --> 43:30.630] Thank you very much.