[00:10.860 --> 00:11.860] So, we can start. [00:12.800 --> 00:13.360] Well, hi. [00:13.800 --> 00:15.740] Welcome to the Crypto for the Masses panel. [00:16.160 --> 00:17.200] My name is Anatole Shaw. [00:18.740 --> 00:24.760] With me, I have Lucas Goms, Matt Blaze, and Greg Newby. [00:27.160 --> 00:30.940] And contrary to my position up here, I am not going to try to be the moderator. [00:31.180 --> 00:35.100] I want this to be a fairly equal conversation amongst us and amongst you, the audience, as well. [00:35.100 --> 00:42.520] I welcome you to interrupt us if you would like to be part of the discussion at any point. [00:44.340 --> 00:45.360] Crypto for the masses. [00:45.580 --> 00:49.360] Crypto wasn't really a thing for the masses more than about ten years ago. [00:49.520 --> 01:07.560] It's been used by militaries for thousands of years, but until around the time of PGP, people didn't really think about using cryptography to protect their communications or to bridge other kinds of social schemes that we sort of take for granted in reality into information space. [01:07.840 --> 01:13.160] Those social schemes being things like the concept of personal identity, which is that I look you in the face. [01:13.180 --> 01:13.980] I know who you are. [01:14.320 --> 01:18.780] And I associate some degree of trust with you or other attributes. [01:19.280 --> 01:24.380] Concepts like being able to tell a secret or tell you something privately. [01:25.280 --> 01:27.060] Concepts like anonymity. [01:27.060 --> 01:27.900] Connected to details. [01:28.780 --> 01:34.860] Those are all things that have bloomed in information space over the past ten years because of PGP and other technologies. [01:35.040 --> 01:41.460] But they're also things that haven't become... haven't come into the wide use that some people expected them to. [01:41.620 --> 01:54.940] There was a great movement of cypherpunks for a very long time, which has sort of come to an end, partially because of not a total failure to make cryptography widespread among ordinary people. [01:55.160 --> 02:05.860] But I would hasten to say that maybe fewer than one percent of internet users are actively using cryptography to protect their privacy. [02:06.560 --> 02:11.340] Can I get a show of hands of people who've used a program like PGP at least once in the past? [02:13.140 --> 02:13.980] That's a lot of people. [02:14.260 --> 02:17.520] All of the people in New York are here who've used PGP. [02:18.580 --> 02:23.300] And can I get a show of hands of how many people are still using it today on any kind of regular basis? [02:23.780 --> 02:24.040] Sorry? [02:24.440 --> 02:25.240] Do you have any audio on it? [02:25.260 --> 02:28.880] No, we're looking at I think about three quarters the first time, maybe a quarter the second time. [02:29.000 --> 02:30.100] Now there's an even ground somewhere like a nasty humming. [02:32.260 --> 02:35.420] And so let me just throw out the question, why is that? [02:35.420 --> 02:39.920] And there are obviously ease of use issues. [02:40.380 --> 02:44.260] And there's the issue that any security that's not transparent doesn't get used. [02:44.700 --> 02:48.060] But what do any of you folks have to say about that? [02:48.160 --> 02:50.120] Maybe before I chime in, it's Microsoft Solve. [02:50.160 --> 02:51.120] Microsoft Solve, absolutely. [02:51.600 --> 02:56.080] We will all use encryption when it just interoperates and it's easy. [02:56.080 --> 03:05.540] I mean, okay, a lot of us are, but I mean, even for the people that are tech savvy, setting up PGP with whatever your mail client is of choice is a pain in the butt. [03:05.680 --> 03:11.400] And then someone sends you something with a cipher that you don't have, so you're using GPG and stuff like this. [03:11.500 --> 03:13.980] So for the technologically elite, it's a pain in the butt. [03:14.860 --> 03:23.300] And if this were part of Outlook or part of, I mean, we know it's part of Adora, this would really make a big difference. [03:23.300 --> 03:33.280] But, you know, it is part of all of the, you know, all of the commercially equipped browsers include, you know, strong crypto in them now and have for a while. [03:33.580 --> 03:39.500] And, you know, that was largely to solve a, you know, a non-problem. [03:40.700 --> 03:47.560] So, you know, this was largely to solve this non-existent problem of people stealing credit card numbers over the wire. [03:47.560 --> 03:59.660] And, you know, somehow there was this media hype about what a horrible crisis there was about people stealing credit card numbers by tapping into internet connections. [03:59.680 --> 04:03.300] Which, as far as I know, you know, to a first approximation has never happened. [04:04.140 --> 04:09.300] But people perceived that this was a serious threat. [04:09.520 --> 04:12.140] This was something to really worry about. [04:12.440 --> 04:27.260] And, you know, consumers demanded that if they were going to engage in any kind of electronic commerce over the net, in any kind of buying over the web, they wanted encryption. [04:27.260 --> 04:29.720] And, sure enough, we got encryption into that application. [04:30.020 --> 04:32.440] It was kind of a silly motivation for it. [04:32.720 --> 04:39.860] But, you know, it did show that transparent crypto, you know, is certainly feasible to do if there's demand for it. [04:40.980 --> 04:43.180] And you were responsible for implementing that some of your stuff? [04:43.420 --> 04:43.620] No. [04:44.440 --> 04:45.860] Well, you did do CSS, right? [04:46.020 --> 04:51.960] Well, yeah, but that's transparent crypto for file storage, not for web transcription. [04:51.960 --> 05:01.860] But, you know, one of the important questions to ask is, you know, what's the threat and what are you trying to protect? [05:03.580 --> 05:20.280] And, you know, it's very easy to just equate crypto with some kind of magic pixie dust that protects you from, you know, bad things happening without really thinking through what exactly is the information you're trying to protect, what's the threat look like, [05:20.280 --> 05:21.860] and how is encryption going to help you? [05:21.860 --> 05:28.820] So, you know, it's kind of easy to flippantly say, if cryptography is the answer, you probably asked the wrong question. [05:29.040 --> 05:31.340] Or at least you didn't ask a large enough question. [05:32.720 --> 05:34.180] Actually, I want to differ. [05:34.360 --> 05:37.060] I really don't believe it's Microsoft's fault or the user's fault. [05:37.180 --> 05:38.120] I think it's the hacker's fault. [05:40.020 --> 05:43.180] I think the cypherpunks dropped the ball on this very badly. [05:46.540 --> 05:57.620] Specifically, PGP has this completely insane mechanism where every communication involves both parties going out and exchanging keys in this, you know, secure transaction. [05:57.920 --> 06:02.600] We all know that it's a manual process to do true security. [06:02.940 --> 06:04.460] You don't personally have to be there. [06:05.480 --> 06:07.120] With PGP, certainly. [06:08.140 --> 06:12.940] And this is a completely insane approach to security. [06:13.160 --> 06:16.720] It's far too much security for what we actually need to get a level of privacy. [06:17.540 --> 06:21.600] And you can see why this doesn't have a chance in hell of working. [06:22.480 --> 06:24.020] If you think about Reed's Law. [06:24.860 --> 06:26.900] Reed's Law is the value on the internet. [06:27.180 --> 06:36.300] The groups, the number of groups that we can have is the best definition of how much value we can generate from our communications medium. [06:37.060 --> 06:43.180] And Reed's Law is also the best description of the number of key exchanges that are going to need to happen given PGP. [06:44.780 --> 06:53.560] So, we can see that insane value from Reed's Law also takes an insane amount of work from PGP key exchanges. [06:53.560 --> 07:03.860] And so, I personally feel that cyberpunk's over-defined the threat to be super spies and under-defined the threat to be... [07:03.860 --> 07:07.900] And the true threat is that your bytes are passing in the clear most of the time. [07:08.060 --> 07:15.380] And what we need is, I don't know, 25% better security as opposed to 99% better security. [07:17.260 --> 07:27.800] On the same note of PGP and light technologies being an overkill, I have an angle on this as well, which is that cryptography can be overkill in terms of... [07:27.800 --> 07:29.220] Well, let me give an example. [07:29.420 --> 07:39.160] I want to send a message to somebody and prove that that message is from me and my personal identity, as represented by my private key. [07:41.080 --> 07:44.200] In reality, when I want to tell you something secretly, I whisper it in your ear. [07:44.300 --> 07:49.900] When I want to prove my identity, you look at me in the face and you, you know, try to determine whether I'm wearing a rubber mask or not. [07:52.120 --> 08:00.100] On the internet, when I sign a document with my public key, and it's a fairly strong public key, and I give it to you, it's sort of the equivalent of handing you an affidavit. [08:01.580 --> 08:10.360] And I may not want to say something to you in such a way that you can then go around and, in some sense, prove to the whole world that I said such and such a thing on such and such a date. [08:10.360 --> 08:26.460] And so, the particular cryptographic schemes that have been chosen for implementing things like personal identity on the internet, don't match those schemes the way they work in reality very well at all. [08:29.420 --> 08:37.940] And this carries over to some other things as well, including that, you know, people talk about these hierarchies of trust, and that trust is trust in your key. [08:38.120 --> 08:41.920] It's not any kind of human trust as we know it, yet people often confuse it. [08:47.300 --> 08:55.300] One thing that I would like to say is that the whole carrying over of anonymity onto the internet and into information space has been fairly successful. [08:55.480 --> 08:58.200] And while it is underutilized, it's the kind of thing that's been very transparent. [08:59.360 --> 09:00.380] It works very well. [09:01.440 --> 09:07.380] And while some may argue that it's not a right, it has worked very well. [09:07.500 --> 09:09.360] Would anybody like to talk about anonymity? [09:09.880 --> 09:12.540] Yeah, that's the thing I'm most excited about right now. [09:12.620 --> 09:22.620] I think most of the problems of crypto for secrecy and crypto for authentication, outside of the trust model problems, are largely solved. [09:22.700 --> 09:24.720] You know, it's a matter of deploying implications. [09:27.020 --> 09:31.860] The interesting open problems, I think, are, first of all, the trust model problems. [09:32.060 --> 09:40.740] And second of all, how do you hide information that encryption itself doesn't readily protect? [09:40.740 --> 09:45.760] Things like routing and networks, things like, you know, who the source and endpoint of communications are. [09:46.080 --> 09:55.160] There are things that you can use cryptography to help you a little bit with that for, but you also need other mechanisms like mixed networks and onion routing and things like that. [09:55.760 --> 10:03.760] And, you know, we know a little bit about how to construct networks like that, but we don't know how they scale, we don't know what the practical effects of them are. [10:04.100 --> 10:16.060] There's just an enormous amount of work to be done there by people who are interested in pushing the bounds of things. [10:16.060 --> 10:20.380] And the interesting thing is all of these anonymity-protecting networks require infrastructure. [10:20.640 --> 10:27.820] So, you know, they need people to provide, you know, relays on networks and services like that. [10:27.920 --> 10:41.540] So this is really something that the hacker community is ripe to be very much involved with and potentially have a huge impact on the way our electronic society is formed. [10:41.540 --> 10:43.920] So that's the thing I'm most excited about these days. [10:46.420 --> 10:50.280] I think we're clearly losing the anonymity struggle at this point. [10:50.400 --> 10:54.520] I think that hackers have done wonderful, wonderful things. [10:54.600 --> 11:03.180] And at the same time, the main successes of hackers have been in the last mile as opposed to the first mile. [11:03.180 --> 11:10.460] So, for example, most of the privacy you give up is in your IP address associated with logging into websites from a browser. [11:11.400 --> 11:15.520] You know, trivial things like that and giving up the name of your browser manufacturer. [11:17.960 --> 11:23.740] And cipherpunks and hackers have been extremely successful with things like mix nets, which are, you know, wonderful things. [11:23.740 --> 11:46.740] But unfortunately, because the problem of anonymity is mainly a co-evolutionary race between individuals who are seeking privacy and people who want to compromise your privacy, hackers' successes have been targeted at adaptations from the opposite side that haven't occurred yet. [11:46.740 --> 11:55.840] So, for example, nobody's really tracing our IP traffic at the level of what you're talking about, which is a sensible thing, but it's not really what's happening. [11:56.060 --> 12:02.020] People are doing extremely well by tracing your IP address, browser combination. [12:02.420 --> 12:03.820] I know this. [12:03.980 --> 12:14.700] I worked for a company that optimized banner ads according to what we knew about the visitor based on what we could observe. [12:14.700 --> 12:20.480] So their browser, their operating system, their geographic location of their IP address, and so on. [12:20.600 --> 12:24.880] And I can tell you that we knew a hell of a lot about people, and we could increase... [12:24.880 --> 12:26.340] We could predict what people were going to do. [12:26.420 --> 12:30.140] So we know a lot about you based on these trivial trespasses onto your privacy. [12:30.420 --> 12:44.020] And so the...so it's a co-evolutionary race, the bulk of what I want to say, and we need to make sure that our defenses are the defenses for the actual threats as opposed to the most entertaining threats. [12:44.680 --> 12:45.380] Well, yeah. [12:45.580 --> 12:53.700] But with that said, the time to invent the technology to address the threat is not while you're under attack. [12:53.700 --> 13:19.640] So the fact that there isn't widespread, you know, tracing of IP addresses or, you know, huge dossiers of Internet behavior being made right now, you know, either by governments or by the private sector at the moment, doesn't mean that the fact that our infrastructure is very weak against that sort of threat isn't potentially a big problem. [13:20.220 --> 13:28.200] So I think, you know, I think it is very important, particularly for this community and people concerned about privacy generally, to think about these things. [13:29.280 --> 13:31.520] And we're definitely laying on the groundwork. [13:31.740 --> 13:35.340] Like the techniques, the science involved behind it is the right science. [13:36.400 --> 13:37.520] Here's the thing I'm worried about. [13:37.660 --> 13:48.600] If we want to take an example of crypto that didn't quite make it as PGP and crypto that's doing quite well as pure web, right, the difference is ubiquity. [13:48.600 --> 13:57.700] The problem with anonymity on the Internet is if you're acting anonymously, you're one of a very small number of people acting anonymously and therefore guilty, right? [13:57.920 --> 14:05.620] So in order for anonymity to work beyond the technical level, which I agree, we have a lot of, you know, unfortunately a lot of them are overkill. [14:05.760 --> 14:06.720] Like PGP is overkill. [14:06.800 --> 14:08.280] PGP isn't really pretty good anymore. [14:08.420 --> 14:10.520] It's really extremely, extremely good. [14:10.520 --> 14:13.020] You know, very thoroughly scrutinized. [14:13.240 --> 14:13.320] Yeah. [14:13.760 --> 14:14.880] It's really from a crypto point of view. [14:15.060 --> 14:23.320] But for the web stuff, if it's not ubiquitous, you know, we're going to have trouble saying that it's actually working regardless of how good the tech is. [14:23.320 --> 14:29.080] My colleague, Laurie Cranor, came up with this great slogan, privacy loves company. [14:29.660 --> 14:34.420] And, you know, in these mixed networks, you really don't want to be alone. [14:34.900 --> 14:37.500] You want as many other people in there with you as possible. [14:38.320 --> 14:40.780] By the way, just a real quick story. [14:41.280 --> 14:47.140] Back in 1994, which I guess is eight years ago now, I was at the first COPE conference. [14:47.140 --> 14:48.240] We did a crypto panel. [14:49.040 --> 14:51.640] This is a complete aside here. [14:51.800 --> 14:52.860] We did a crypto panel. [14:53.400 --> 15:02.140] And when it got to be my turn to speak for reasons that I've never quite been able to figure out, it was late at night and presumably kind of overindulged. [15:02.860 --> 15:13.240] It was in the audience a reporter from Wired magazine, which I think is still being published, who started just mercilessly heckling. [15:13.460 --> 15:15.200] He started screaming, where is the crime? [15:15.200 --> 15:17.880] Every time I tried to speak. [15:18.660 --> 15:19.680] Where is the crime? [15:19.900 --> 15:21.140] And just screaming. [15:21.400 --> 15:23.780] Even with the microphone, he was much louder than I was. [15:24.200 --> 15:26.560] Is this person in the room by any chance? [15:27.320 --> 15:28.100] I'm just wondering. [15:28.360 --> 15:32.240] Because I've been thinking, and I never got a chance to say anything. [15:32.900 --> 15:36.300] So this is... I've been waiting eight years to be on this panel. [15:38.680 --> 15:47.400] And I've been thinking for the last eight years that there must be some witty retort that if I had come up with, would have shut him right up. [15:47.460 --> 15:48.860] And I still haven't thought of it. [15:49.020 --> 15:52.580] So the fact that this guy is not in the room at the moment is a big relief. [15:52.580 --> 15:53.710] in your pants. [15:55.380 --> 15:58.980] I think that's where the crime is. [15:59.260 --> 15:59.500] Excuse me. [15:59.620 --> 15:59.720] Bye. [16:02.400 --> 16:07.600] Well, sort of Segwaying from cryptography as a threat, it needs to be addressed. [16:08.760 --> 16:12.900] Law enforcement has certainly viewed cryptography as a threat for some time. [16:13.400 --> 16:16.860] The whole clipper fiasco opened our eyes to that quite a number of years ago. [16:18.740 --> 16:23.380] And it continues today in many different ways. [16:23.520 --> 16:25.960] One of which is, and I wanted to pick up also about... [16:26.740 --> 16:29.440] Greg mentioned that PGP is not pretty good. [16:29.540 --> 16:30.760] It's too good at this point. [16:31.100 --> 16:38.940] But PGP, I think a year or two ago, really did have a terrible vulnerability discovered in a feature called, I think, Additional Encryption Keys. [16:40.560 --> 16:50.300] And it's been argued a little bit and, you know, inconclusively as to whether that was an intentional sort of taint or whether it really just wasn't oversight. [16:50.880 --> 17:09.040] But if you examine the structure of corporations that produce cryptography that's in wide use today, whether it's Network Associates or whether it's Crypto AG, which is a well-known fiasco, or Scilink, or Network Associates, or whoever, it's a very sort of in-family of companies. [17:09.780 --> 17:20.020] And they all have a lineage that traces back to the NSA and the other kinds of agencies that are big purchasers of cryptography. [17:20.840 --> 17:25.860] And so one thing I wanted to talk about is the tainting of cryptography. [17:28.220 --> 17:30.120] And maybe we can talk about that a little bit. [17:31.080 --> 17:42.860] Well, you know, everyone has to read Crypto, Stephen Levy's book, which really, if anything else, is that Phil Zimmerman was not an insider and was not even competent, probably, to do what he did do. [17:42.920 --> 17:44.500] And it just sort of worked out okay. [17:44.660 --> 17:48.400] I think he got the attention of a lot of very competent people. [17:48.940 --> 17:54.160] Not that he's incompetent or anything, but I mean, the first approaches to PGP really had very serious problems. [17:57.900 --> 18:00.440] So there's at least that piece of good news. [18:00.580 --> 18:03.760] But of course what happened with that was RSA, you know, happened. [18:04.200 --> 18:16.000] And so we have, of the available crypto, we have the GPG, which is open source, we can examine it. [18:16.700 --> 18:18.060] So that's good, right? [18:18.200 --> 18:22.780] Even if not that many people are really going to be qualified to, you know, to find problems. [18:24.680 --> 18:26.040] And we don't have much else. [18:26.460 --> 18:27.260] So I think you're right. [18:27.360 --> 18:33.140] We don't have that much else that we can really, at least if we wanted to, examine and increase our confidence in. [18:33.140 --> 18:38.380] And what I wanted to mention that's kind of related, maybe you can think of examples that are beyond that. [18:38.480 --> 18:43.100] But what I wanted to mention also is, actually this is in Schneier's book. [18:43.180 --> 18:45.220] Everyone should read Schneier's, Bruce Schneier. [18:45.540 --> 18:46.340] Not applied cryptography. [18:46.920 --> 18:48.600] You should read that too, if you can. [18:48.860 --> 18:50.660] But read Secrets and Lies. [18:51.440 --> 18:56.200] In the end of Secrets and Lies, he mentions how the secure web is a fiasco. [18:56.720 --> 18:57.760] It's a fiasco. [18:57.920 --> 19:01.700] It's not what you have is you have sites redirecting you to other sites. [19:02.200 --> 19:05.340] You have secure sites framed within insecure sites. [19:05.540 --> 19:06.720] You know, in other words, you... [19:06.720 --> 19:10.700] And those are just two examples of exactly what should be impossible. [19:11.140 --> 19:14.020] You know, exactly what really the secure web should prevent. [19:14.360 --> 19:15.100] So, I don't know. [19:15.240 --> 19:16.380] I mean, I think there's... [19:17.180 --> 19:22.560] It's a problem that there are limited people and organizations that are able to get stuff out there. [19:22.740 --> 19:28.560] But even if there's good stuff, the good stuff has to be more widely deployed. [19:28.800 --> 19:29.820] So we're really uphill. [19:29.820 --> 19:32.060] We're really facing about no battle, I think. [19:32.220 --> 19:40.460] Yeah, I think a lot of this concentrating crypto into the hands of the vendors is an artifact of crypto being specialized, right? [19:40.680 --> 19:46.320] Now, as crypto becomes a mass market thing, you can see it in more different kinds of products. [19:47.640 --> 19:58.560] Microsoft notwithstanding, you know, you're still depending on the security of things like your operating system and, you know, any other software that has access to the bits you want to protect. [19:58.820 --> 20:06.060] But, you know, it's kind of easy to focus on things like, is there a flaw in PGP? [20:06.240 --> 20:09.680] You know, has this piece of software been subverted? [20:09.680 --> 20:16.340] When the real problem is that, you know, crypto is so specialized that there are only a few products out there. [20:16.920 --> 20:31.940] You know, that's the... the real problem we've got to solve is not just figuring out whether or not a particular piece of software has weaknesses, but also, you know, get this widely deployed, get lots of different implementations out there. [20:31.940 --> 20:33.240] I think widely reviewed as well. [20:33.380 --> 20:44.640] I think it's incumbent on the hacker community to do more of the kind of review of source code and when it's a black box, more of the kind of, you know, black box review just, you know, hammering it with data it doesn't expect. [20:45.960 --> 20:51.060] And, you know, giving us a level of assurance or non-assurance in these products that we can actually trust. [20:51.500 --> 20:56.680] Let me make a plug for curriculum, too, because in most colleges you can't take a course in crypto. [20:57.040 --> 21:03.100] Or if you can, it's a one semester course, entirely mathematics, usually like a fourth level, you know, math course. [21:03.560 --> 21:10.000] So, you know, the people that get into crypto programming are there often by accident, not by design. [21:10.200 --> 21:11.660] It would be nice to have some of that designed. [21:14.660 --> 21:16.560] Yeah, crypto is a lot of fun. [21:16.740 --> 21:18.420] The math of crypto is fun. [21:19.260 --> 21:23.980] You know, so, you know, that attracts a lot of people into it. [21:24.280 --> 21:29.540] It has these nice properties that the, you know, there are things that are obviously impossible that it turns out you can do. [21:29.840 --> 21:34.660] And there are things that are obviously very easy that turn out to be really hard. [21:35.460 --> 21:38.420] So, you know, the math aspects of crypto are fun. [21:38.420 --> 21:42.900] The software aspects of crypto are also a lot of fun. [21:43.040 --> 21:43.560] They're interesting. [21:43.880 --> 21:48.820] You know, you can build applications that do, you know, surprising things. [21:49.140 --> 21:54.160] It lets you separate out, you know, message security from media security. [21:54.280 --> 21:58.440] And since media is intrinsically insecure, you know, that's nice. [21:58.440 --> 22:08.020] The problem that we've got is that the people who know how to build secure applications are, for the most part, writing the crypto code, which then runs on Windows. [22:08.520 --> 22:08.960] Right? [22:09.140 --> 22:14.620] And, you know, the software, the crypto parts of the software might be completely bulletproof. [22:15.060 --> 22:21.020] But if you're, you know, if you're running it on an out-of-the-box Windows machine, you know, what's the point? [22:23.640 --> 22:29.840] I think that... So we've got... Crypto is not the same as security, but it's easy to focus our attention unevenly. [22:32.640 --> 22:42.960] Crypto is... I think that crypto is a more interesting subject than just the, you know, mixing up of bytes, the obscuring of bytes, so that they're hard to read. [22:43.160 --> 22:43.320] Thanks. [22:44.920 --> 22:51.900] And I think that knowledge is sort of progressing slowly because it's a genuinely hard set of problems. [22:52.140 --> 23:04.640] So that there's a few guys who know how to analyze the security of an algorithm to find, for example, interesting flaws or unknown flaws before. [23:05.740 --> 23:11.820] They're sort of so immersed in the process that it's harder to see the bigger crypto problems. [23:11.820 --> 23:24.400] So I think, for example, that the biggest successes of crypto have been in the general area of information theory. [23:25.800 --> 23:45.460] So, for example, it's less interesting to me in terms of my privacy to know that I can encrypt my bytes as to know that I can obscure the graph leading to my name in a context that I want to keep private. [23:47.080 --> 23:53.020] And that's a big success in terms of cryptography, and it's a more doable algorithm. [23:54.380 --> 24:02.120] So, for example, I certainly can't force anybody who has a link pointing to me that I want, that I don't like, to encrypt their bytes or to get rid of them. [24:02.120 --> 24:08.840] I can't... it's very hard to maintain a MIM for long enough that it's useful. [24:09.580 --> 24:15.160] And at the same time, for short enough that there isn't enough information attached to it that it can lead back to you. [24:16.100 --> 24:18.620] So that's a genuinely hard problem in crypto. [24:18.840 --> 24:22.280] But we now know that you can, for example, obscure a graph. [24:22.280 --> 24:28.240] So, an example is I'm giving a talk later on today on... [24:28.240 --> 24:32.620] I'm going to try to push the far left of digital politics as far as I can take it. [24:33.440 --> 24:37.660] And I don't want that attached to my resume for obvious reasons. [24:38.800 --> 24:46.080] I'm not personally ashamed of it, but when I go into a job interview, I don't want people to be thinking about, you know, my sexual history, my political history, and other stuff like that. [24:46.080 --> 24:47.940] So I want to keep a little bit of privacy. [24:48.160 --> 24:50.480] And so I took a simple step of using a pseudonym. [24:51.620 --> 25:00.760] And the purpose of that pseudonym is to say that graphing back to me, following those links back to me in something like Google, is unlikely to hurt me. [25:02.520 --> 25:20.120] So, to sum this up, I guess my answer to Anatole's general point is that it's a little too hard to do this stuff for a few defections on the part of, you know, network associates to really be key. [25:20.880 --> 25:24.040] It's progressing slowly, and it's really hard. [25:24.480 --> 25:28.120] And capability security just got hit, you know, in the past couple of years. [25:28.120 --> 25:32.800] And it's obviously a huge tool, and it's going to take us a long way, and it's brand spanking new. [25:35.020 --> 25:35.540] So... [25:35.540 --> 25:48.320] Well, on the flip side of government being afraid of encryption, I'd like to present one idea that I have about why encryption is good for government and good for law enforcement. [25:48.980 --> 25:52.340] The traditional thinking, obviously, has been that if you... [25:52.860 --> 25:59.480] Well, let me take a step back even further from that, and just talk for a second about the way law enforcement sort of views the internet. [26:00.340 --> 26:10.840] Which is that, unlike the real world, you don't have to physically travel to see what's going on on the computer network. [26:11.140 --> 26:15.340] You don't have to go through a lot of the same kinds of things. [26:16.320 --> 26:19.320] It's more like just an information pool that you can tap into. [26:19.500 --> 26:22.420] And this has obviously been very tempting for law enforcement. [26:23.380 --> 26:35.060] As people pour more and more of their personal information into the internet or other networks, as people rely more on these networks for their communications, it becomes a more and more tempting medium to just intercept all of it. [26:35.140 --> 26:38.900] And this is what things like ECHELON, obviously, are for, and most of you probably know about that. [26:40.460 --> 26:54.160] And this is really an unnatural thing for such a dragnet approach to be used on such a broad variety of communications. [26:54.580 --> 27:06.520] And what I'd like to say is that the more people who encrypt their communications, the more it is going to help law enforcement to do their job properly. [27:06.680 --> 27:21.200] And by properly, I mean that cryptography or encryption of personal communications prevents law enforcement from just sort of gratuitously snooping on communications, from too easily abusing their powers. [27:21.680 --> 27:26.600] And it really doesn't take away as much power from law enforcement as they'd like us to believe. [27:26.700 --> 27:29.920] They'd like us to believe that if something's encrypted, that's kind of the end-all. [27:29.920 --> 27:37.020] And really, the fact is that you can still walk into somebody's house and implant a keyboard sniffer. [27:37.200 --> 27:38.900] You can still point the camera at somebody's monitor. [27:39.060 --> 27:40.080] And this happens all the time. [27:41.100 --> 27:46.660] All encryption is really doing is forcing law enforcement to go that one additional step to snooping on you. [27:46.800 --> 27:54.060] And it keeps them from having just this churning pot of information where everything is available to them. [27:55.300 --> 27:59.340] And so I would like everybody out there to think about this. [27:59.340 --> 28:19.480] and law enforcement to think about it too, that encryption is a hurdle that really makes the information space a lot more like the real world in terms of police power, in terms of people's privacy, in terms of people to conduct themselves in a private manner, [28:19.480 --> 28:23.500] and keep the kinds of everyday secrets secret that you and I do all the time. [28:24.240 --> 28:30.560] I'd like to point out that I think what you've now stated may well be the mainstream view. [28:30.560 --> 28:38.720] You know, eight years ago, if we'd had this panel, if we'd had the chance to have this panel, that would have been, you know, a radical view. [28:38.840 --> 28:43.300] But I think that view has finally made it into the mainstream. [28:43.920 --> 28:50.660] You know, first is the obvious thing, which is that cryptography's primary purpose is to prevent crime. [28:51.400 --> 28:56.720] It's to keep unauthorized access to information from happening in the first place. [28:56.880 --> 29:00.540] And that's a law enforcement goal and a national security goal too. [29:01.660 --> 29:11.600] For a while, the parts of the government and law enforcement that saw encryption as a threat probably had a disproportionate voice. [29:12.420 --> 29:17.660] And also, you know, tended to want the status quo to continue because that's the thing you had to deal with. [29:17.880 --> 29:20.300] But I think it's turned around. [29:20.580 --> 29:26.500] They've also come to realize, I think, that to a large extent, encryption has helped them even in solving crimes. [29:26.680 --> 29:34.800] It encourages... use of encryption encourages more sensitive data to be put on networks. [29:34.980 --> 29:42.360] Once it's put on networks, once it's communicated, it's available, you know, through subpoenas, through witnesses, through informants, and so on. [29:42.680 --> 29:47.040] You know, just ask Mr. Scarfo, who just pleaded guilty. [29:48.000 --> 29:55.400] Among the evidence they collected from him was his PGP key, which they did by putting a keyboard sniffer in. [29:56.280 --> 29:57.640] You know, that was a targeted attack. [29:57.800 --> 29:58.400] They got a warrant. [29:58.520 --> 29:59.360] They went into his house. [29:59.500 --> 30:00.700] They installed a keyboard sniffer. [30:00.880 --> 30:01.880] They learned his key. [30:02.080 --> 30:05.300] They got his gambling records. [30:05.440 --> 30:11.500] If it weren't for the availability of encryption, those gambling records would probably not have been on his computer in the first place. [30:15.570 --> 30:25.650] On that same note, there are all sorts of attempts to make the PC platform a more attractive platform on which to place personal information. [30:26.470 --> 30:34.690] And one of those is the DRM thing that we're starting to hear about, which is the creation of a trusted path inside your PC. [30:35.450 --> 30:45.690] An attempt to prevent Trojan horses, even keyboard snifferers, things like that, from being able to circumvent the kinds of security measures which either you install or more likely which Microsoft installs. [30:46.410 --> 30:48.950] And this has its pros and cons, obviously. [30:50.010 --> 30:51.250] Would anybody like to pick up that one? [30:53.070 --> 30:54.290] I think it's great. [30:55.050 --> 30:56.270] Do you have a race management? [30:56.610 --> 30:58.390] I think palladium is great. [30:58.550 --> 30:59.870] It's so deeply retarded. [31:01.610 --> 31:04.150] I hope they go whole hog into this. [31:04.870 --> 31:06.450] It's totally, completely stupid. [31:07.810 --> 31:12.550] I think the more general topic is photography that takes freedoms away from people. [31:14.330 --> 31:19.190] Anything that assumes people don't have freedom is not going to work. [31:19.190 --> 31:27.110] I mean, what we know about capability security is that rights leak in a well-known path. [31:28.170 --> 31:32.210] And what palladium does wrong is it assumes that rights aren't going to... [31:32.210 --> 31:35.410] Even though the path into your computer is from you, right? [31:35.590 --> 31:39.610] It sort of says, well, the path into your computer is from Microsoft, right? [31:39.790 --> 31:40.730] It's so wrong. [31:40.890 --> 31:41.410] It's so deeply wrong. [31:41.510 --> 31:44.990] There's a huge difference between the e-language and palladium. [31:46.470 --> 31:46.950] Excellent. [31:46.950 --> 31:48.090] I say go for it. [31:48.250 --> 31:48.990] Let's do it. [31:50.390 --> 31:53.870] Unfortunately, my doctor tells me I'm not supposed to talk about digital rights management. [31:54.250 --> 31:55.790] My blood pressure goes up too much. [31:55.990 --> 32:00.650] But the real problem that... [32:00.650 --> 32:06.590] The thing that makes my blood pressure go up the most is the subversion of the word... [32:07.170 --> 32:08.570] of the idea of trusted. [32:09.290 --> 32:11.650] You know, they talk about trusted computing platforms. [32:11.650 --> 32:19.570] But what they're really saying is trusted by people who don't own the computer to prevent the owner of the computer from doing what they want with it. [32:20.170 --> 32:27.690] You know, which is not what I intuitively think of when I think of something I own being trustworthy. [32:29.650 --> 32:47.170] And, you know, this attempt to build machines that are hostile to the interest of their owner seems to be misguided from all sorts of point of views, not least of which security. [32:47.170 --> 32:52.830] I want to understand what's running on my computer for security reasons, if nothing else. [32:55.190 --> 33:01.590] The threat on the Cypherpunks list lately has been about the demise of the general purpose computer. [33:01.590 --> 33:03.950] And that's something that probably has... [33:03.950 --> 33:03.970] Right. [33:03.970 --> 33:04.790] You know, we have a cell phone. [33:04.950 --> 33:05.410] We have PDA. [33:05.590 --> 33:06.650] So there's something in that. [33:06.890 --> 33:06.990] Right. [33:07.010 --> 33:07.910] In a positive sense. [33:08.330 --> 33:17.010] But I think, really, the only effective way that the full DRM could happen, to me, anyway, when I think about this, is to not have a general purpose computer. [33:17.130 --> 33:18.970] To not have a general purpose operating system. [33:19.130 --> 33:24.430] Because if you have a general purpose computer, whatever's in place, we're going to bypass, you know, if we want. [33:26.050 --> 33:26.450] Yeah. [33:26.610 --> 33:28.170] But maybe we can save ourselves some time. [33:28.310 --> 33:29.330] A quick show of hands. [33:29.510 --> 33:32.510] How many people here think digital rights management is a good idea? [33:33.550 --> 33:33.950] Okay. [33:34.090 --> 33:34.490] Okay. [33:34.550 --> 33:35.070] We don't really... [33:35.070 --> 33:36.590] So there's no convincing we need to do. [33:36.890 --> 33:36.930] Okay. [33:37.830 --> 33:39.470] The choir is... [33:39.470 --> 33:39.930] Yeah. [33:40.890 --> 33:42.110] I think we should try to do it. [33:42.410 --> 33:43.930] I think, you know, just let it happen, man. [33:44.070 --> 33:46.750] Anybody wants to pass a digital rights management bill? [33:47.230 --> 33:47.890] Donate money. [33:49.610 --> 33:50.010] Really. [33:50.370 --> 33:54.410] I mean, the science is so broken behind Palladium that... [33:54.410 --> 33:56.270] Nothing better than can happen. [33:56.490 --> 33:58.310] Just because it'll be so easy to bypass. [33:58.330 --> 33:59.590] It'll be so easy to bypass. [33:59.910 --> 34:00.210] I mean... [34:00.210 --> 34:01.290] In addition to ridiculing it. [34:01.650 --> 34:07.150] I mean, try to prevent me from installing a keyboard sniffer on my own machine? [34:07.270 --> 34:07.950] I don't think so. [34:09.450 --> 34:10.950] You know, just for credit. [34:11.370 --> 34:15.310] Well, you know, there's another term that's been subverted, which is tampering. [34:15.650 --> 34:15.710] Right? [34:16.090 --> 34:17.870] People talk about tamper-resistant hardware. [34:18.210 --> 34:22.330] And the tamperer here is the person who bought it. [34:22.330 --> 34:25.310] But, you know, this idea that I can buy something and tamper with it... [34:25.310 --> 34:26.030] Not have your rates... [34:26.030 --> 34:26.370] Yeah. [34:26.510 --> 34:28.130] It seems very strange to me. [34:28.330 --> 34:28.390] Right? [34:29.330 --> 34:31.770] It's like a tamper-evident bottle of pills. [34:32.050 --> 34:32.170] Right. [34:32.470 --> 34:33.850] You know, that's still tamper-evident. [34:34.070 --> 34:35.090] Someone's raising their hand. [34:36.130 --> 34:45.810] I think if the problem with Palladium isn't that we could bypass it, but it's the people who couldn't bypass it that represent the majority of your users. [34:45.890 --> 34:45.970] Right. [34:46.270 --> 34:47.730] That really is the problem. [34:48.670 --> 34:49.850] Supporting the right medic. [34:50.970 --> 34:52.470] Well, yeah, but people... [34:52.470 --> 34:53.410] Yeah, we have to repeat the question. [34:53.590 --> 34:53.890] Oh, yeah. [34:54.150 --> 35:05.990] Well, the question, or the comment is that, you know, maybe people in this room will figure out a way to bypass Palladium, but if 90-some percent of regular users don't, then they win. [35:06.170 --> 35:09.850] You know, they've got their goal of restricting use. [35:10.030 --> 35:13.110] But, I mean, you know, look at DeCSS, right? [35:13.130 --> 35:14.150] How many people wrote that? [35:14.370 --> 35:15.810] And how many people could run it? [35:15.810 --> 35:30.930] So, if you have software that anybody can run, and you have the DRM, which is preventing common things from happening, like playing your own DVD on your own computer, or whatever the next example is, then, of course, many, many people will run it. [35:32.030 --> 35:33.990] So, yeah, and not everyone, right? [35:34.230 --> 35:39.390] People, a lot of people that will never download some strange program and run it, but people that want to will be able to. [35:40.690 --> 35:52.490] I should just point out that on a factual level, that part of the, you know, practical claims of the Palladium effort are to specifically counteract that. [35:52.970 --> 36:03.570] They say that one person will break an encryption scheme or break a DRM scheme, but they won't be able to propagate it from machine to machine. [36:03.750 --> 36:06.890] But I want to say, I want to respond directly. [36:07.650 --> 36:09.610] You're on the far side here. [36:09.870 --> 36:10.850] I can't see you. [36:10.970 --> 36:13.670] So, responding directly is, I'll bounce it. [36:15.010 --> 36:24.950] I want to say that you're absolutely right, and that adoption of privacy technologies is, you know, is a practical problem to be solved. [36:25.210 --> 36:32.190] We've seen in some few areas that people have been willing to adopt privacy technology. [36:33.650 --> 36:37.610] One of the few areas I know of is that a lot of people really are paranoid about cookies. [36:39.450 --> 36:44.390] And so there has been, and, you know, regular users do turn off cookies. [36:44.650 --> 36:52.090] So I can think of at least one example in nature of regular users, you know, taking a little bit of trouble to protect themselves. [36:52.090 --> 36:56.350] So it's not necessarily absolutely 100% true that it's hopeless. [37:00.960 --> 37:04.140] By the way, there's a tendency for us to get a little... [37:04.140 --> 37:14.100] I'll be talking about this a little in the panel tomorrow on laws and rights, but I'm a little less optimistic that, you know, just let them go ahead and do their worst. [37:14.100 --> 37:15.480] You know, it's such a stupid idea. [37:16.020 --> 37:17.580] As techies, it's tempting to say that. [37:17.760 --> 37:24.520] But, you know, laws and market forces are still powerful, even when they're wrong. [37:26.220 --> 37:32.480] You know, for a while, you couldn't export cryptography. [37:32.580 --> 37:34.100] There was no law against writing cryptography. [37:34.640 --> 37:36.400] There was no law against giving it to your friends. [37:36.400 --> 37:39.740] But if you put it on the net, they claimed that was the same as exporting it from the US. [37:39.740 --> 37:40.900] But it was widely exported. [37:40.900 --> 37:48.920] It was widely exported, but it was completely effective at keeping Microsoft from including encryption in their default operating system. [37:48.960 --> 37:49.620] Or Sun or... [37:49.620 --> 37:53.160] Or Sun or any of the other vendors. [37:53.440 --> 38:03.620] You know, for the most part, most of the world, particularly most of the commercial world, is law abiding for, you know, for these purposes. [38:03.620 --> 38:12.840] So, you know, even if the law is stupid and easily subverted, Microsoft is not likely to choose that as the red flag they wave. [38:13.400 --> 38:18.620] So, you know, I still think it's important to fight on those levels. [38:19.880 --> 38:20.280] Yep. [38:20.880 --> 38:23.580] You know, I'm for fighting on all available levels. [38:25.380 --> 38:25.780] Unless... [38:25.780 --> 38:26.760] I mean, I'm... [38:27.320 --> 38:36.020] Yeah, I guess I would have to take more seriously the jiu-jitsu move of, you know, letting these guys do such an insanely crazy thing. [38:36.220 --> 38:37.540] But I'd take it seriously. [38:37.540 --> 38:39.620] I think it's, you know, potentially a great opportunity. [38:41.080 --> 38:45.420] Yeah, I mean, one thing that I think about is with DeCSS, right? [38:45.920 --> 38:48.620] We would like to think that we won DeCSS because... [38:49.240 --> 38:56.660] Not the court case, but I mean, that we won the ability to play our DVDs on the computers that we have because we can go and download different things. [38:57.020 --> 39:00.200] In practice, code doesn't work anymore. [39:00.420 --> 39:02.020] DVD encryption scheme changes. [39:02.020 --> 39:02.640] We lost. [39:02.900 --> 39:06.340] We can't play what our DVD we want on whatever computer we have. [39:06.940 --> 39:07.540] You know, they won. [39:07.980 --> 39:09.360] That particular battle. [39:09.700 --> 39:10.880] That's sort of the way I feel. [39:11.040 --> 39:11.800] You can see it. [39:12.000 --> 39:13.400] It's not totally black and white. [39:13.720 --> 39:15.140] Basically, I see that we lost. [39:15.420 --> 39:21.580] And I'm a little worried that we can win some of the battles and say, yeah, here's palladium. [39:21.600 --> 39:29.060] Here's something else that someone cracked in 12 hours and the exploit was widely available and we could all download it. [39:29.300 --> 39:35.520] And yet a year in the future, we won't be able to do what it was that they didn't want us to be able to do. [39:38.060 --> 39:43.360] So, we were asked to insist that people use the microphone for questions. [39:43.640 --> 39:44.780] Do you want to take questions? [39:45.820 --> 39:46.540] Yeah, sure. [39:46.700 --> 39:48.040] We have about 15 minutes left. [39:48.500 --> 39:53.620] So, if you could rush to the microphone, just climb over each other and push people to the floor. [39:58.560 --> 40:03.680] Unfortunately, I think the people in this room are not really the indicative people who are on the internet. [40:03.680 --> 40:05.220] My mother... [40:05.220 --> 40:06.360] I'm glad of that. [40:06.720 --> 40:07.320] Doesn't... [40:07.320 --> 40:08.660] Well, as am I. [40:09.020 --> 40:13.520] My mother doesn't understand why she needs her privacy. [40:13.700 --> 40:17.240] She doesn't understand why she should need to encrypt any of her data. [40:17.520 --> 40:20.260] She doesn't understand why she should have antivirus software. [40:20.260 --> 40:24.620] She doesn't understand why she should have a personal firewall on her cable motor. [40:26.080 --> 40:36.140] Until people understand this, you're not going to get the software manufacturers to put out even a half decent piece of software, let alone the garbage that's out there now. [40:36.340 --> 40:39.600] I mean, how do you propose that we handle something like that? [40:39.760 --> 40:42.900] You know, cyberpunks are great, but my mother doesn't read the news groups either. [40:43.720 --> 40:45.280] And she's who's on the internet. [40:45.540 --> 40:45.600] Yeah. [40:45.940 --> 40:46.240] Well, look. [40:46.480 --> 40:48.160] It's a question of demand, right? [40:49.000 --> 40:49.400] The... [40:49.400 --> 40:54.660] You know, there was demand for preventing credit card numbers being sniffed over the wire. [40:55.080 --> 40:58.320] Even though it was a non-problem, there was still widespread demand for it. [40:58.320 --> 41:04.420] And so we got browser security, you know, for that particular problem. [41:05.280 --> 41:15.600] Right now, computer users prefer, you know, web pages that show dancing frogs to, you know, web pages that don't install a virus on your computer. [41:16.020 --> 41:24.860] And until there is that widespread consumer demand, even if you don't understand the details of how to do it, you know, we're not going to be... [41:24.860 --> 41:27.880] We're still going to have manufacturers shipping and secure products. [41:28.100 --> 41:29.060] And it's a real problem. [41:33.170 --> 41:34.450] Hi, I'm Eric Blossom. [41:34.650 --> 41:36.190] I'm working on the GNU Radio Project. [41:36.330 --> 41:37.850] And I just want to jump... [41:37.850 --> 41:38.870] With the hosier, secure phone. [41:39.190 --> 41:40.570] And also secure phones, right. [41:40.810 --> 41:40.830] Yeah. [41:41.630 --> 41:42.310] Yay, yay, yay. [41:42.350 --> 41:42.810] Go team. [41:42.910 --> 41:47.710] But I wanted to just specifically address, I think it's a bad move to just say, let them go at it. [41:48.090 --> 41:56.670] We've run into it already in doing free software HDTV receiver that they are really trying to... [41:56.670 --> 42:00.990] I mean, they've got their objective, and I say they as pretty much content providers, movie companies right now. [42:01.190 --> 42:08.390] But RIAA, MPAA, really want to prohibit people from building equipment that does what the customer wants it to do. [42:08.770 --> 42:18.310] And they have gone so far as to, like, draft legislation that would ban, for example, receivers of HDTV. [42:18.310 --> 42:27.070] The basic modulator model, which is a pretty small piece of a thing, they would like to ban those that didn't implement some kind of a robustness criteria. [42:28.030 --> 42:39.170] Their model of how they want to secure this is they want to set a bit in the air interface, in the clear, and they want to convince all the consumer electronics manufacturers to honor this bit. [42:39.170 --> 42:41.190] Which, of course, some of them aren't so hot about. [42:41.310 --> 42:43.190] But then we're going to pass some laws to prohibit it all. [42:43.710 --> 42:51.990] So the end result of this would be that folks like us are no longer able to build software and freely distribute it. [42:52.770 --> 43:01.490] I mean, we went to them and we said, okay, let's say, is there any way we could write an open source or free piece of software that complied with what you want? [43:01.490 --> 43:02.230] I mean, we're game. [43:02.490 --> 43:05.970] You know, I'll say IFDEF USA, you know, the bid is set down. [43:06.110 --> 43:09.570] But, of course, as soon as I distribute it, and then am I now liable as the distributor? [43:09.690 --> 43:11.190] I think it's a dangerous path to go down. [43:11.550 --> 43:13.590] We've got to talk on Sunday to address... [43:14.450 --> 43:17.650] Let me be clear about my position on that. [43:19.470 --> 43:27.090] It is possible for governments and cartels to collude, and when they collude, to, you know, to triangulate. [43:27.090 --> 43:34.690] So the industry or the cartel introduces a product that stinks, and the government mandates that no other product can be introduced. [43:35.130 --> 43:40.050] And between them, they set up a situation where value has been knocked out of the marketplace. [43:40.630 --> 43:40.850] Right? [43:40.950 --> 43:45.270] So they just say, the value of having good information technology is no longer an option. [43:46.030 --> 43:51.530] So that's the threat that people are making to us. [43:51.530 --> 43:57.210] Now, I think that's a pretty grave situation, but I don't think it's that likely. [43:57.450 --> 44:08.810] I think it's more likely that any time somebody, these forces allocate huge chunks of value to our side, to the good guys, that we come out stronger. [44:09.090 --> 44:11.850] And I would say that file sharing is a wonderful example of that. [44:11.850 --> 44:15.070] That everybody uses file sharing. [44:15.370 --> 44:15.590] Everybody. [44:15.750 --> 44:21.530] Talk about Napster in a bar and, you know, it's like, you know, you're walking around waving a hundred dollar bill. [44:21.810 --> 44:27.210] And that's because all the value has been handed to us as a tool for our side, for the good guys. [44:27.590 --> 44:30.630] And palladium is nothing but a value suck. [44:30.910 --> 44:35.750] It is 100% about removing value from consumers and handing it to us to play with. [44:35.750 --> 44:38.990] So I think it's potentially a wonderful strategic tool. [44:39.190 --> 44:41.070] And I have to be convinced otherwise. [44:41.550 --> 44:42.790] Get your software written. [44:43.150 --> 44:44.910] That's the most important thing. [44:45.230 --> 44:45.890] Yeah, Eric's right. [44:45.890 --> 44:52.670] I mean, the open standards are not being applied to a lot of these. [44:52.850 --> 44:55.010] It's whatever cartels, whatever you want to call them. [44:55.190 --> 45:02.630] And this does create a problem if one of our fundamental devices refuses to do whatever it is that our software wants to tell it to do. [45:02.630 --> 45:04.830] And I think we're going to be seeing more devices like that. [45:06.170 --> 45:07.050] Good afternoon, gentlemen. [45:07.750 --> 45:14.890] Do you see, with the harsher regulatory environment, a lot of the crypto technology and talent moving offshore? [45:16.030 --> 45:19.190] And do you see that as a trend in the future? [45:19.550 --> 45:21.510] And just give me an opinion and thoughts on that, please. [45:21.810 --> 45:22.110] Thank you. [45:22.710 --> 45:23.830] It certainly was for a while. [45:24.150 --> 45:31.070] You know, when we had harsh export laws in the U.S., you know, what that encouraged was the development of a non-U.S. [45:31.190 --> 45:32.010] crypto industry. [45:33.770 --> 45:45.070] You know, fortunately for most products, and there are some exceptions, big routers being one of the most notable, most mass-market products can have crypto in them freely even if they're from the U.S. [45:45.070 --> 45:51.910] and we've fixed that problem, by and large. [45:52.370 --> 45:54.230] There is a risk, though. [45:54.570 --> 45:56.370] You know, whatever the U.S. [45:56.550 --> 46:01.590] regulatory structure is has impact all over the world, right? [46:01.650 --> 46:01.970] The U.S. [46:02.010 --> 46:02.890] is a big market. [46:03.290 --> 46:03.890] The U.S. [46:03.890 --> 46:05.190] is a big source of expertise. [46:06.330 --> 46:06.830] You know, U.S. [46:07.430 --> 46:13.250] policy tends to be exported to other countries, you know, implicitly or explicitly. [46:13.250 --> 46:18.810] So, you know, having it move offshore may not even be sufficient. [46:24.810 --> 46:25.210] Hi. [46:25.210 --> 46:29.510] I think, really, that there's a problem of demand for crypto. [46:29.810 --> 46:31.550] There is certainly demand at the very high end. [46:31.650 --> 46:35.110] Nicky Scarfo, if he weren't in prison right now, probably would have paid a lot more money for his crypto. [46:35.270 --> 46:37.070] He probably would have paid somebody quite reasonable money. [46:37.830 --> 46:39.190] His crypto was fine. [46:39.750 --> 46:42.810] The problem is that his operating system sucked. [46:43.010 --> 46:43.810] His implementation of the... [46:43.810 --> 46:44.570] He used Windows. [46:45.670 --> 46:49.270] Nicky Scarfo is in jail for being a user of Windows. [46:52.110 --> 46:52.670] Yeah. [46:53.050 --> 46:54.910] The total implementation of the system. [46:55.170 --> 47:00.790] There's a... I believe there's a market for the high end where you have a completely secure system and a high credit model. [47:00.790 --> 47:06.270] But the reason we're interested so much in average users' privacy is to have a larger pollution set. [47:06.590 --> 47:08.590] It doesn't really do any good to have the users... [47:08.590 --> 47:13.010] A small number of users of, say, Mixmaster, if it's only the people that really care about security that are using it. [47:13.170 --> 47:16.710] However, if all mail, like all Hotmail accounts were equally secure, then we'd be protected. [47:18.750 --> 47:19.110] The... [47:19.590 --> 47:20.350] Is there any... [47:20.350 --> 47:21.230] How do you get cover traffic? [47:21.350 --> 47:25.010] How do you convince people to provide cover traffic for the real users of crypto? [47:25.190 --> 47:26.350] I don't understand how to do this. [47:26.990 --> 47:28.410] It's an excellent problem. [47:28.510 --> 47:33.690] You have to convince people that there is an application that your mother needs for anonymity. [47:35.030 --> 47:35.990] And right... [47:35.990 --> 47:37.390] There hasn't been... [47:37.390 --> 47:40.830] This was a great phrase I heard on a panel at some of the conference. [47:40.970 --> 47:42.730] I wish I remember it came up with this phrase. [47:42.990 --> 47:46.170] There hasn't been a privacy Valdez, right? [47:46.330 --> 47:50.670] You know, this spill of personal data yet that's been perceived in the public. [47:50.910 --> 47:54.430] Once there is, that might be, you know, certainly inevitable. [47:55.270 --> 48:03.230] Once it happens, that might be the event that causes people to wake up and say, I'm worried about all this data about me. [48:03.290 --> 48:05.910] I'm worried about my habits being monitored. [48:06.250 --> 48:09.690] But I agree, right now, it hasn't happened yet. [48:09.690 --> 48:13.410] And it needs to before you'll get the cover traffic theft. [48:13.570 --> 48:15.130] So it has to get worse before it'll get better. [48:15.670 --> 48:15.910] It has to. [48:16.170 --> 48:16.210] Yeah. [48:18.290 --> 48:19.690] Identity theft is a good example. [48:19.690 --> 48:25.090] Maybe a really well-known case of that would raise the level of information cookies. [48:25.290 --> 48:28.270] I mean, people care about cookies, but we know cookies are not a big deal. [48:30.590 --> 48:34.430] But people do care about privacy, but only in fairly vague ways. [48:34.750 --> 48:37.970] And the caring has gone up because identity theft is a good example. [48:38.110 --> 48:40.070] Some other, you know, news coverage happens. [48:40.070 --> 48:43.030] But of all deads, I mean, that's exactly right. [48:43.250 --> 48:44.310] If we could just have that. [48:44.610 --> 48:48.410] Unfortunately, the problem that I worry about is it might backfire. [48:48.590 --> 48:58.710] You know, if we suddenly, let's say, I don't know, some political figure or actor or something is somehow a victim or there's like someone that we cheer for and say, yes, you know, got him. [48:58.850 --> 49:04.050] Good thing that some reporter was able to scam information they didn't have. [49:04.050 --> 49:06.030] So that could actually go the opposite direction. [49:10.810 --> 49:11.070] Okay. [49:12.890 --> 49:15.610] I don't know the gentleman's name, but we have the same hairdresser. [49:18.170 --> 49:18.690] Kelly. [49:21.970 --> 49:35.590] My question is, I would like to share your optimism about the possibility of government and big industry colluding and taking value out of the marketplace, but that's not so realistic. [49:37.050 --> 49:43.490] I think that's like saying, well, there's a possibility of the sun coming up in the morning, but that's not so realistic. [49:43.690 --> 49:44.350] This is today. [49:44.410 --> 49:45.410] This is the world we live in. [49:45.670 --> 49:51.330] We're going to, a couple of years from now, buy technology, more and more technology, that's not able to do what we want. [49:51.650 --> 49:54.050] We're going to buy motherboards that won't let us copy stuff. [49:54.350 --> 49:55.630] We're going to buy cameras. [49:55.630 --> 49:59.410] We're going to be surrounded by a secure ring of technology, which we're not allowed to understand. [49:59.410 --> 50:00.450] And it's already happening. [50:00.770 --> 50:02.070] The laws are in place. [50:02.650 --> 50:05.150] The technology is in place. [50:05.290 --> 50:07.630] I think what we're going to see is this actually happening. [50:07.790 --> 50:13.890] What we live in, this world we live in, has been already characterized by these people as the analog whole. [50:14.330 --> 50:15.350] This is where we live. [50:15.510 --> 50:17.230] I think it's a mistake to be too gloomy. [50:17.850 --> 50:19.770] We have a lot more going for us than we realize. [50:19.950 --> 50:24.110] For example, Passport and .NET did not work. [50:24.190 --> 50:25.410] They never found an audience. [50:26.110 --> 50:28.450] And we probably gained a little bit of strength off that. [50:29.870 --> 50:36.770] So, you know, it's just not constructive to say we are going to lose because these tighties are going to crush us. [50:36.770 --> 50:37.570] I'm not saying we're going to lose. [50:37.710 --> 50:45.570] I'm just saying, taking collusion between big industry and government as a remote possibility is daydreaming. [50:46.630 --> 50:50.770] One thing that we're losing is essentially the ability to tinker. [50:51.030 --> 50:54.810] And that is what got us where we are now. [50:54.810 --> 51:00.050] The whole computer and internet revolution is an outgrowth of people. [51:00.110 --> 51:01.470] I think, on that note, we are out of time. [51:01.610 --> 51:03.470] But I'd like to encourage everyone to keep tinkering. [51:03.710 --> 51:06.510] And I'd like to thank the panel and all of you for coming. [51:06.510 --> 51:06.770] Thank you very much. [51:06.790 --> 51:07.550] Thank you.