[00:06.480 --> 00:07.900] Ok, welcome everybody. [00:12.920 --> 00:18.820] My name is Rob Ronchleib and I'm going to be talking a little bit about some projects that we're working on. [00:21.080 --> 00:25.040] With a few other people, I've started a company in Amsterdam, it's called NAH6. [00:26.900 --> 00:29.980] And NAH6 develops crypto applications. [00:29.980 --> 00:31.520] We do a number of projects. [00:32.340 --> 00:37.000] There's nothing on our website for download now, there's nothing people can use, nothing people can buy from us. [00:37.080 --> 00:45.340] I'm just describing a few projects we've done and I'm actually introducing, showing you the first demonstration of one prototype that we've built. [00:46.220 --> 00:47.960] Which wasn't introduced before. [00:50.060 --> 00:50.540] Whoops. [00:57.160 --> 00:58.660] NAH6 is based in Amsterdam. [00:58.660 --> 01:09.240] And we're basically set up to create some of the crypto software that everybody seems to be needing, that everybody's talking about, yet we can't find anybody that's making it and doing it in the right way. [01:09.360 --> 01:12.860] There's lots of people doing it wrong, doing it without publishing the source. [01:14.980 --> 01:22.820] Our plan is to build partly for-profit commercial software just to offset our costs and maybe make a little money. [01:23.900 --> 01:30.000] And partly GNU and BSD licensed software in the cases where we don't see any immediate profit models. [01:30.340 --> 01:37.220] Or where we're basically making minor modifications to software which already has a GNU license, for instance. [01:41.000 --> 01:44.400] Everything we create will have the source code available for public review. [01:45.540 --> 01:49.020] We're not building any crypto stuff where we say trust us or it's really good. [01:51.320 --> 01:53.180] These are some of the projects we're working on. [01:53.320 --> 01:54.900] One is a secure telephony project. [01:55.040 --> 01:58.580] I've already talked a little bit about that earlier today. [02:00.500 --> 02:06.660] PGP and GPG mail without the means of a localhost, without headache and without plug-ins by a localhost proxy. [02:07.680 --> 02:10.120] A secure mailing list plug-in and secure notebook. [02:11.780 --> 02:14.060] Allow me to go into each one a little bit. [02:14.960 --> 02:17.920] The secure phone, I've already talked about quite a bit today. [02:18.040 --> 02:23.440] This is a type of phone you can now buy in Europe and you'll also be able to buy soon here. [02:23.560 --> 02:27.160] It's an organizer with a built-in GSM GPS phone. [02:27.160 --> 02:29.440] You can just press the phone button and then... [02:29.440 --> 02:31.180] I'm not sure anybody can see this, but... [02:31.180 --> 02:38.460] It'll actually bring up a screen that has phone buttons that are big enough to actually press on the screen and you can make the call using this device. [02:38.740 --> 02:42.200] Yet it's also an organizer very much like the IPAC. [02:42.480 --> 02:44.380] It runs the same operating system default. [02:46.180 --> 02:49.140] So it's very much an organizer and a phone built-in one. [02:49.360 --> 02:53.160] And it's actually powerful enough to do the voice crypto stuff. [02:53.160 --> 02:57.100] So you can actually be on the phone with somebody and nobody can listen in. [02:57.320 --> 03:00.080] And it's all running as an application inside your phone. [03:04.600 --> 03:10.020] We talked about all of this only less than two hours ago, so I'll go over it really quickly. [03:10.300 --> 03:18.120] It basically uses all the technology necessary to deal with the slow bit rate and the long delays of the GSM channel. [03:18.120 --> 03:24.440] So it doesn't use IP in between, but it uses some kind of protocol that is meant to deal with that long delay. [03:26.080 --> 03:32.740] And we'll put on a non-commercial use version on the website, which anybody can download once they have these phones. [03:33.060 --> 03:35.400] Or just an IPAC with a phone card or anything. [03:35.400 --> 03:39.480] They can get secure calls without needing any specialized hardware. [03:40.620 --> 03:42.400] This project is the furthest off. [03:43.640 --> 03:49.980] It's much more difficult than you would think in terms of the codec, in terms of any of those things. [03:50.100 --> 03:51.300] I'll come back to that later, maybe. [03:52.900 --> 03:55.300] So there's definitely nothing we can show there. [03:55.440 --> 04:02.440] There's a prototype running, a very, very, very early prototype of the codec stuff running on Windows, but that's not done yet. [04:05.200 --> 04:08.160] Another thing that's worrying us very much is the future of PGP. [04:09.020 --> 04:19.580] I guess all of you know that an AI who has bought PGP Inc., Network Associates, they no longer maintain the PGP code. [04:19.700 --> 04:21.060] They're no longer developing on it. [04:22.040 --> 04:26.200] They even have completed versions, I think PGP 7 for the Macintosh. [04:26.920 --> 04:29.840] They have completed versions which they're not selling. [04:31.120 --> 04:33.160] And they're not building any new plug-ins. [04:33.520 --> 04:43.380] And if the past is anything to go by, Outlook, Eudora, Netscape will all need new plug-ins once new major versions of these programs come out. [04:44.560 --> 04:50.880] The unavailability of those plug-ins will mean that a huge percentage of the PGP user base will stop using PGP. [04:51.500 --> 04:57.860] We saw a dramatic increase in PGP usership when PGP 5 came out with the graphical user interface and the plug-ins. [04:58.620 --> 05:01.100] I think PGP usership went times ten. [05:01.900 --> 05:12.340] And I don't see why we shouldn't expect an equally dramatic drop once people need to hold on to outdated mailers just to be able to use PGP. [05:14.980 --> 05:17.380] So we need to find a way to keep using it. [05:17.520 --> 05:20.300] And this is why we've sort of decided to develop Cryptomatic. [05:21.800 --> 05:24.300] Cryptomatic is a proxy that runs on your own PC. [05:24.800 --> 05:28.960] So basically you tell your own PC that it is its own POP and SMTP server. [05:29.200 --> 05:32.880] And then you tell Cryptomatic where your real POP and SMTP server are. [05:33.180 --> 05:36.780] And it sits in the middle and it decrypts your mail. [05:36.780 --> 05:37.660] It's written in Perl. [05:38.840 --> 05:45.480] And it runs on Windows using the active state Perl runtime environment, which is a thing which runs Perl code on Windows boxes. [05:48.120 --> 05:58.060] And what it would do is it would sit there and it would wait for you to give it commands such as, for instance, you would start a subject with crypt, colon, and then the real subject. [05:58.100 --> 06:04.840] And then it would replace the subject by stuff or a PGP message or something which would not be indicative of what's in there. [06:04.840 --> 06:07.720] It would stick the real subject in the first line of the message. [06:07.960 --> 06:09.800] It would just insert another subject, colon. [06:10.120 --> 06:13.040] It would crypt the message to that key and send it out. [06:13.120 --> 06:17.280] And if it didn't have that key, it would bounce the message back to you without it ever leaving your PC. [06:18.340 --> 06:20.180] And what we tried to do... [06:20.680 --> 06:24.560] It interfaces with all versions of PGP that have a command line interface. [06:24.900 --> 06:28.340] So basically PGP 2, 5, 6, or GPG. [06:28.440 --> 06:31.820] PGP 7, as some of you may know, doesn't have a command line interface. [06:31.820 --> 06:34.160] So we didn't really feel like talking to it. [06:34.300 --> 06:36.000] And the source is unavailable anyway. [06:36.180 --> 06:41.340] So we don't really see why anybody would be using it in this context. [06:43.420 --> 06:45.900] We fix a lot of PGP's current problems. [06:46.220 --> 06:58.280] One of the current problems is that if you're on a Windows machine, say, and your friend uses a Unix box, you're likely to receive messages in the PGP MIME format. [06:58.520 --> 06:59.580] The two attachments. [06:59.800 --> 07:02.320] One saying, version 1, this is a PGP MIME message. [07:02.600 --> 07:04.840] And the other one with the actual message. [07:04.960 --> 07:06.160] And your plugin can't read it. [07:07.120 --> 07:17.020] And the other way around, if you're using a PGP MIME-based system, you get all these messages where the PGP message is in the body of the text message. [07:17.020 --> 07:19.600] And you can't automatically decode it. [07:20.360 --> 07:29.320] So what we've done is we've tried to learn from incoming mail whether that particular correspondent would want MIME or body text back from us. [07:30.420 --> 07:40.500] Also, if we send messages with any of the plugins or even with MUT or any of the known PGP methods with BCC recipients, it's still going to encrypt only one message. [07:40.700 --> 07:45.440] And the PGP header contains the PGP key IDs of all the people that it's encrypted for. [07:46.080 --> 07:54.180] So if you get a message and you want to know if there's any BCCs, you just look at the PGP header and compare the key IDs with the people in the 2 and the CC lines. [07:54.720 --> 07:58.820] And any missing ones, you just ask the key server who they were and you see who the BCCs were. [08:00.660 --> 08:07.620] Then there's the issue of encrypting to both RSA keys and Diffie-Hellman keys, the older and the newer PGP keys. [08:09.780 --> 08:18.080] Which we think is not a good idea to mix that because if somebody has an old PGP key, they're more than likely to also have an old PGP that they're using that for. [08:18.340 --> 08:22.320] Maybe on an HP handheld or on some other older PC. [08:22.760 --> 08:27.080] And they would not want you to mix in Diffie-Hellman keys because then they couldn't read the message. [08:27.080 --> 08:36.540] So we're trying to very much do the right thing and make all these versions of PGP correspond with each other and try to remove the need for the user to think about these issues. [08:38.260 --> 08:40.380] This thing will have a web interface on port 80. [08:40.520 --> 08:42.220] That's the part we're still very much working on. [08:42.620 --> 08:55.380] It would have a web interface on port 80 where you could also set for each of your keys, you could set do the default thing for this correspondent or always crypt for this person or never crypt for this person or assign always for this person. [08:55.540 --> 09:02.040] So we'd very much try to make it very easy for the user to never use the PGP key interface anymore. [09:02.200 --> 09:03.220] Just install that once. [09:04.740 --> 09:08.020] Make it easy for the user to import keys that came in in mail. [09:09.520 --> 09:15.100] And maybe have a mechanism where it would detect that the correspondent on the other side also had this thing installed. [09:15.100 --> 09:23.280] And then it would prompt the user to say, hey, why don't you verify that the other person really wants this and then we'd never send clear text anymore. [09:25.940 --> 09:28.940] We basically have the whole thing working apart from the web interface. [09:29.880 --> 09:35.680] And there should be some prototype, some working code on our site available for test relatively soon. [09:40.380 --> 09:43.220] Then there's the problem of encrypted group communications. [09:44.160 --> 09:44.960] It's a problem. [09:45.360 --> 09:50.440] That light would need to be turned down a little bit because it's really blinding the hell out of me. [09:51.660 --> 09:52.280] Thank you. [09:55.200 --> 09:56.980] Group communications are a problem. [09:57.620 --> 10:00.160] And there's a lot of people that are trying to address the problem. [10:00.340 --> 10:04.000] There's activist organizations setting up encrypted group communications. [10:05.960 --> 10:19.000] Sometimes that is done through HTTPS, sometimes that's done through a PGP system where the list server would decrypt the incoming mail and then send it back out. [10:19.000 --> 10:20.380] And that's wrong. [10:20.620 --> 10:36.560] Because that means that there's organizations, resist.ca, DAO, activist organizations or whatever organizations that would have the clear text messages of the 500 secret list servers that they're operating. [10:37.580 --> 10:39.760] That's not necessary and it's just plain wrong. [10:40.440 --> 10:43.940] At best, these people are painting these huge crosshairs on their chest. [10:44.100 --> 10:47.360] We have all the clear text for all these people that are really, really interesting. [10:48.040 --> 10:52.640] So what we're trying to do is create a system where the server doesn't have clear text. [10:56.900 --> 11:10.040] The maintainer of a mailing list would send all the participants a key pair, basically a PGP private key and a public key, encrypted with the key, with the public key of that user. [11:10.660 --> 11:12.720] Now that may seem very, very wrong. [11:12.940 --> 11:17.440] Sending a private key over mail sounds very wrong, but it isn't. [11:17.440 --> 11:28.160] Because if the private keys for any of the participants are compromised, in which case this key pair would leak out, the contents of this mailing list would leak out anyway. [11:28.920 --> 11:33.640] Because basically the only thing you're hiding is a thing you're broadcasting to all the members of this mailing list anyway. [11:36.400 --> 11:39.620] So there's no extra threat involved in sending the key pair. [11:39.740 --> 11:44.480] And what the key pair allows us to do is anybody on the mailing list can send to the private key. [11:47.840 --> 11:51.880] And anybody on the mailing list can also decrypt or can send to the public key. [11:51.980 --> 11:55.080] And anybody can decrypt what was sent to the public key with the private key. [11:55.820 --> 11:58.900] Meaning the list server just passes encrypted messages along. [11:59.560 --> 12:00.480] So what did we do? [12:00.800 --> 12:08.400] We built a little plug-in for Mailman, which is a fairly popular mailing list software thing written in Python for Unix machines. [12:08.660 --> 12:11.540] And what we've done is we've created a new property page for the list. [12:11.540 --> 12:12.880] This is an encrypted list. [12:13.120 --> 12:15.520] Of course the list wouldn't need to know anything about this. [12:15.640 --> 12:17.480] You could do this on any mailing list. [12:17.740 --> 12:25.980] But what the nice thing about our software is it allows the users of the list to select whether they want PGP MIME or body text. [12:26.680 --> 12:31.320] Which again is nice if you're using much or if you're using enough of the plug-ins that you get it in the right format. [12:34.180 --> 12:39.280] And it allows the list maintainer to give the public key for the list to the list server. [12:39.500 --> 12:44.660] And then if the list server sees anything floating by that wasn't encrypted, that would be wrong. [12:44.660 --> 12:49.140] And it would attach a message saying this user was really, really dumb and sent it unencrypted. [12:49.140 --> 12:53.180] But I encrypted it anyway before I sent it out to 200 more people. [12:53.420 --> 13:04.620] So that if the traffic to one of the 200 people or five people or three people, if the traffic to any other user but the user sending it in was intercepted, it still wouldn't be in the clear. [13:05.340 --> 13:09.200] So again, we're trying to do the right thing without making people think too much about it. [13:11.300 --> 13:12.960] We did the patch for 2.0. [13:13.440 --> 13:18.080] Mailman 2.1 is almost a rewrite from scratch in some parts, as I understand it. [13:18.600 --> 13:25.240] So we're rewriting some of it before we can submit it for inclusion into the Mailman distribution, which is where it belongs. [13:25.420 --> 13:28.360] We don't want to maintain this code forever, nor can we. [13:29.380 --> 13:36.060] We don't have the bandwidth organizationally to deal with years and years and years of user questions. [13:36.060 --> 13:38.960] So we would like this included in the Mailman distribution. [13:38.980 --> 13:42.620] If there's anybody here that knows people on that team, talk to me afterwards. [13:44.940 --> 13:53.540] Anyway, we're working on inclusion in Mailman and on the 2.1 version, but the 2.0 version should be on the website for people to play with. [13:54.440 --> 13:56.360] What we need to do now is write documentation. [13:56.360 --> 14:01.820] If there's anybody that really likes writing documentation also, just hop on out. [14:01.820 --> 14:07.400] All of this, by the way, both the Mailman CryptoList patch and the previous thing, the CryptoMatic, will be freeware. [14:07.760 --> 14:11.340] We have no expectations of making any money from it. [14:15.110 --> 14:18.390] Then there's the secure workstations, and that's the thing we're going to launch today. [14:18.570 --> 14:19.910] We're going to at least demo today. [14:20.450 --> 14:21.430] It's another problem. [14:21.550 --> 14:30.070] Windows is notorious for leaving clear text all over the disk that it boots from, and in its Windows directory, in the temp directory, at the ends of files. [14:31.070 --> 14:37.310] The Windows applications office, but also any other Windows applications, also leave their clear text all over the place. [14:37.570 --> 14:44.650] It's really, really hard to create a Windows system where the hard disk would not contain any legible information. [14:47.550 --> 14:55.030] Several products exist, PGP disk, all sorts of products exist. [14:55.570 --> 15:04.930] Some are just outright crap, they don't work, or they work so badly that you can't use them, or they're so obviously security broken that there's no point in using them. [15:05.350 --> 15:13.050] They require end user intelligence, which may be in short supply in your particular application, depending who you give this to. [15:14.750 --> 15:19.610] And they only encrypt portions of the disk, certain partitions, certain directories, certain files. [15:20.810 --> 15:24.250] Almost never the boot device, the temp space, or the swap. [15:25.850 --> 15:30.110] And they're all black boxes, which means there's no independent means of verifying how good they are. [15:30.210 --> 15:31.850] You can't see what's inside. [15:32.950 --> 15:38.190] And that means they're not useful in a context where large nation states are or collude with your adversaries. [15:40.290 --> 15:44.830] So what we try to do is create something we call Secure Notebook. [15:45.810 --> 15:47.870] Basically, it's a Debian Linux box. [15:48.050 --> 15:53.010] And as you can see there, it's a Linux box that has X-Windows, the international patch. [15:53.250 --> 15:59.690] It has a simple rule-based firewall, USB support for a small dongle that stores our key material. [16:00.550 --> 16:05.590] It doesn't have swap, because we don't want any clear text ending up in the Linux swap partition. [16:06.190 --> 16:07.370] But it has enough RAM. [16:07.990 --> 16:10.030] A couple of modifications we did. [16:10.070 --> 16:11.250] I can talk about those later. [16:11.930 --> 16:14.330] And our NAH6 secure notebook software. [16:16.310 --> 16:17.850] Inside that, we run VMware. [16:18.350 --> 16:22.010] And inside that, we run Microsoft Windows XP, but you could run anything there. [16:23.830 --> 16:37.810] What happens is the outside box, the Linux box, puts partitions or files on its hard drive through what's called the loopback encryption process, meaning it becomes a new device which is encrypted. [16:38.230 --> 16:50.590] And it sets up all the keys for that based on the passphrase you type and the key file, which is usually stored on the USB dongle, and then sets up those disks and gives those disks to VMware. [16:51.230 --> 16:54.290] For those of you who really know VMware well, VMware has two systems. [16:54.410 --> 17:00.050] It either uses a virtual disk, for which it creates a file in the file system, or it uses real disks. [17:00.110 --> 17:05.170] And we give them to VMware as real disks for performance reasons, for which we had to hack. [17:05.270 --> 17:07.930] That's the NAH6 loop.c mod you see up there. [17:07.930 --> 17:14.470] We had to hack the loopback driver to convince VMware that it was really hardware and not some software thing. [17:14.950 --> 17:22.410] But basically, this VMware thing that runs inside this Linux box, because of this trick, has no means of ever writing a byte of clear text. [17:22.570 --> 17:31.430] Its whole concept of the outside world is really faked by this Linux box, including its real hardware disk drives that it thinks it has, which are faked. [17:33.090 --> 17:41.990] VMware writes a really large file in temp, which is called RAM 0, which to us sounded really like it contained all sorts of interesting clear text. [17:42.210 --> 17:46.430] So what we created was this crypt ID slash temp, which is basically a boot trick. [17:46.850 --> 17:54.370] At boot time, we make a one-time key, which we install, do another one of these crypt ID loopback tricks with. [17:54.370 --> 17:58.370] And that disk is then mounted as temp. [17:58.990 --> 18:03.690] So everything written to temp after we boot is basically encrypted, too. [18:03.790 --> 18:06.650] And we can forget that key when we shut down, because we don't need temp anymore. [18:06.710 --> 18:11.770] We just mount a new... we just do a new FS on that every time we start up. [18:13.250 --> 18:31.650] And then after... after X exits, and after this whole machine comes down, we do the NAH6 RAM wipe, which basically tries to get from the operating system megabytes of RAM and zeroes them out until it can't get any more, and then it gets half megabytes and quarter megabytes until it can't get any memory anymore. [18:31.810 --> 18:34.930] It has zeroed it all out, and then it releases all that memory and exits. [18:34.930 --> 18:38.950] So we try to do as good a job as we can at erasing the memory. [18:40.790 --> 18:49.750] So that if anybody does a post-mortal investigation of the computer and tries to figure out what's on the computer, they can't even get it from the RAM. [18:49.930 --> 18:51.910] There's definitely nothing on hard disk, we know that. [18:52.450 --> 18:55.210] The last thing that Unix does is it... [18:56.170 --> 19:01.590] It is a network address translator and firewall between the network and this PC on the inside. [19:01.590 --> 19:05.890] So there's no more Windows networking tricks, there's no more... [19:05.890 --> 19:07.370] So the easy things are gone. [19:07.530 --> 19:10.150] And of course, if you want to be paranoid, you don't hook it up to the network at all. [19:10.370 --> 19:12.990] But we try to make it possible to hook it up to the network. [19:14.250 --> 19:16.510] Now, what we're going to do... [19:16.510 --> 19:20.690] Oh yeah, there's a bunch of residual threats, which is what remains after you do this. [19:21.690 --> 19:24.810] The most important one becomes surreptitious access to hardware. [19:25.070 --> 19:29.190] Anybody that can get to your hardware can log the keys that you type. [19:29.190 --> 19:46.930] Now, even if they can't, which they can, they can mess with the Debian that's installed, but even if you would somehow make it impossible to modify the installed Debian, they could flash the BIOS on your notebook computer and make the BIOS log your keys or install a transmitter in it. [19:47.050 --> 19:50.850] So any surreptitious access to the hardware will get you. [19:50.930 --> 19:54.010] So you must use the computer and put it under your pillow when you sleep. [19:55.870 --> 19:57.670] And then there's attacks via the network. [19:58.230 --> 20:00.990] We try with the firewall to catch those. [20:01.150 --> 20:03.850] But of course, zero-day exploits against your web browser. [20:04.330 --> 20:05.450] We can't catch. [20:05.690 --> 20:08.850] So if you want to be paranoid, don't web browse from the machine. [20:08.990 --> 20:11.510] Minimize your use from this machine. [20:11.810 --> 20:12.990] Don't connect it at all. [20:13.750 --> 20:15.290] Then there's things we could have done wrong. [20:15.430 --> 20:22.110] It could be just plain bugs or slight biases in the random generator we use to generate these keys for the disks. [20:25.030 --> 20:28.850] Residual charge, RAM analysis, or any other extreme hardware hacking. [20:28.990 --> 20:38.250] There could be some keyboard buffer in the chipset that does the keyboard interface on your particular motherboard that we don't know about that has a residual charge on it. [20:39.190 --> 20:42.610] So there could be really, really extreme things done to the hardware. [20:44.330 --> 20:48.070] And then there's RF and other sort of radiation attacks. [20:48.610 --> 21:03.330] If you can interpret what's on the screen remotely, or if you can interpret the keyboard, or even if you can see the light from a real CRT monitor on the back wall, it's now been proven that that light is actually just... [21:03.330 --> 21:14.710] It's emitted because the ray from the cathode ray tube goes on the screen and goes on and off in the sequence of what you're actually displaying. [21:15.030 --> 21:16.350] So that's been done too. [21:16.870 --> 21:19.850] So these are sort of placed outside our threat model. [21:19.970 --> 21:24.630] Our threat model is just your PC gets stolen, you leave it in the train, whatever. [21:24.890 --> 21:29.650] A threat model where an adversary takes the PC and tries to read what's on it. [21:29.710 --> 21:30.650] It's secure against that. [21:30.650 --> 21:35.570] It's not secure against adversaries that go through the trouble of breaking in your house, or whatever. [21:35.730 --> 21:39.130] So just to make people aware of what the limitations of such a system are. [21:40.070 --> 21:40.490] All right. [21:43.410 --> 21:45.070] This is very important. [21:45.410 --> 21:47.910] We're now going to do high-tech demonstrations. [21:50.410 --> 21:53.730] What I'm going to do now is I'm going to end this PowerPoint presentation. [21:59.410 --> 22:04.090] And then I'm going to show you, and for that I think I need to switch it to... [22:07.630 --> 22:15.430] You'll see the left of the screen sort of dropping off a little bit, but that's just the way this video outworks, and the way the projector takes that video out. [22:16.990 --> 22:18.430] I'm going to turn off the computer. [22:20.150 --> 22:25.330] And then you're going to notice that this nice Windows box wasn't a nice Windows box to begin with. [22:50.610 --> 22:57.190] While it's rebooting, can you talk about what you're running it on and the performance running it on? [22:58.370 --> 23:04.490] This is an IBM ThinkPad, a fairly new IBM ThinkPad, but it would run on basically any new kind of computer. [23:05.210 --> 23:11.670] We prefer notebooks because you can actually take them out of harm's way as where desktops would be left in a building that you can't secure. [23:12.170 --> 23:13.850] I was just curious about the performance. [23:15.230 --> 23:20.970] Performance, basically, what I can do now is just power it off and then make it come back on. [23:25.150 --> 23:27.710] Basically, we set off doing this, figuring... [23:27.710 --> 23:29.850] Oh boy, this should look much better. [23:32.190 --> 23:34.670] Yeah, we had it looking much better. [23:37.870 --> 23:38.790] Yeah, there we go. [23:41.620 --> 23:42.800] Okay, now it's off. [23:44.040 --> 23:45.480] And now we turn it back on. [23:47.900 --> 23:50.080] It's always a trick whether you put it in the right mod. [23:51.220 --> 23:52.560] It looks like the right mod. [23:56.460 --> 23:58.120] Anyway, let me go through... [23:58.120 --> 23:58.700] Yeah, that looks right. [23:59.000 --> 24:01.000] Let me go through this boot process. [24:01.000 --> 24:03.560] What you see here is the Debian booting, of course. [24:17.270 --> 24:18.770] And it finds the wavelength. [24:20.190 --> 24:21.550] We've set it up to where... [24:21.550 --> 24:29.650] I'll show you that later, but we've set it up to where you can either use the built-in Ethernet on this notebook, or whatever it recognizes as eth1. [24:30.510 --> 24:32.330] Now, it asks you to type your passphrase. [24:32.470 --> 24:35.510] As you see, it doesn't come up with login or anything Unix-y. [24:35.710 --> 24:40.770] It just comes up with a nice sort of known style window that says enter your passphrase. [24:41.250 --> 24:42.890] So the user enters the passphrase. [24:42.950 --> 24:45.510] In this case, it's the awfully secure blah blah. [24:47.610 --> 24:49.050] And then it says keys are unlocked. [24:49.230 --> 24:55.390] It gets the key file, which would normally be on a USB storage dongle, which broke on us last night. [24:55.390 --> 24:57.530] So we had to sort of hack our way around it. [24:58.350 --> 25:00.870] So the key file, we then decrypt. [25:01.230 --> 25:06.750] In the key file, I could go to secure session, and then it would just basically start the Windows box. [25:06.990 --> 25:08.730] But I first want to show you some other things. [25:09.030 --> 25:20.430] Here in the system settings, we can basically tell which of the peripherals of this fake environment that we're creating are connected to the one Windows box that's inside. [25:21.090 --> 25:23.310] Some of the stuff we haven't finished yet isn't working. [25:26.430 --> 25:29.710] This is basically where we get our connection from. [25:30.490 --> 25:32.430] How it does its... [25:33.270 --> 25:34.590] And this is the firewall. [25:34.730 --> 25:36.610] And we basically made a few scripts. [25:36.810 --> 25:38.610] These are just scripts it runs at startup. [25:39.070 --> 25:45.810] And there's a script you can just edit yourself in a text editor to create your own firewall rules for the machine. [25:46.490 --> 25:48.090] So that's the network settings. [25:48.090 --> 25:54.370] And then we've created a backup system where you can create secure backups. [25:54.510 --> 25:56.570] And it makes new keys for the backups. [25:56.710 --> 25:58.890] And there's a CD writer in these notebooks. [25:59.490 --> 26:04.010] So you can create secure backups on CD of data you'd want to backup. [26:04.110 --> 26:09.850] And there's a special drive, which is 700 megs, that you can copy your data to where it's loopback encrypted. [26:09.870 --> 26:14.390] And then you just take that whole loopback encrypted file and stick it on a CD. [26:14.610 --> 26:15.850] And that's all done automatically. [26:15.850 --> 26:18.390] So the user just has to know to do that. [26:18.570 --> 26:19.810] To write to that disk. [26:20.050 --> 26:25.410] And then go to this menu to backup and restore from those volumes that are created. [26:28.050 --> 26:28.750] Let me see. [26:28.870 --> 26:29.350] Is there anything? [26:30.710 --> 26:31.210] Keyring. [26:31.710 --> 26:33.510] Here's the change to passphrase. [26:34.290 --> 26:35.930] Shut down if the keys are removed. [26:35.930 --> 26:44.630] If they're on a USB dongle, you can create a mechanism which, if you pull out the USB dongle, basically the Windows machine, the virtual Windows machine gets killed. [26:45.150 --> 26:48.370] And the keys get forgotten and everything pretty much immediately. [26:48.970 --> 26:51.090] And here's the advanced feature. [26:51.230 --> 26:55.650] This is the disks which are installed on this virtual machine. [26:55.650 --> 26:58.890] Basically, disk one is HDA6. [26:59.050 --> 27:00.570] It's a partition on the real disk. [27:00.770 --> 27:05.030] And it's presented to this fake machine as the IDE primary master disk. [27:06.770 --> 27:09.930] And you can set the encryption on them and everything. [27:11.010 --> 27:21.670] And here you can't set the size, but if you create a new one and you say it's in a file and not on a partition, then you can actually set the size and it would go out and create that file, fill it with random, and give it to you as a disk. [27:21.770 --> 27:27.530] And these are all the backups that are made with their ID so it recognizes the right disk. [27:27.850 --> 27:30.350] The trick is you can't use the same key for two backups. [27:30.770 --> 27:37.090] Because then an adversary could very easily tell how much you've changed between these two backups and they could possibly clean information from that. [27:37.510 --> 27:41.190] So we make new keys for each backup that is being created. [27:43.930 --> 27:45.110] Okay, that's that. [27:45.710 --> 27:46.870] Let me say secure session. [27:47.490 --> 27:49.450] Which is the user would just press enter twice. [27:49.690 --> 27:51.830] Oh, I would like it to show you that. [27:52.290 --> 27:52.950] Oh, there we go. [27:58.230 --> 28:00.170] Will you have a number of algorithms? [28:01.650 --> 28:16.710] No, there's the whole suite of crypto algorithms as available in the international patch, including XOR, DES, single DES, I think there's even ROT13 in there. [28:16.930 --> 28:24.410] But you can use anything in the international crypto patch, including also Blowfish, 2Fish, anything. [28:26.070 --> 28:28.570] Well, this is, of course, the Windows startup screen. [28:29.230 --> 28:32.930] I have a password here, but that's not necessary, I guess. [28:34.390 --> 28:37.070] And then it starts up as a Windows box. [28:37.210 --> 28:38.490] And this Windows box is actually... [28:38.490 --> 28:40.530] You've seen the PowerPoint presentation coming out of it. [28:43.190 --> 28:44.770] This Windows box is really usable. [28:45.170 --> 28:47.030] We've used it to play audio. [28:47.530 --> 28:49.130] We've used it for video. [28:49.350 --> 28:52.350] And we actually set out doing this, figuring, why is nobody doing it? [28:52.350 --> 28:53.170] It must be impossible. [28:53.230 --> 28:54.370] The performance will suck. [28:55.090 --> 28:58.070] This will be an impossible, unstable machine that you can't use. [28:58.170 --> 29:02.350] And we set out doing it in a couple days just to prove to ourselves that that wasn't the way. [29:02.350 --> 29:07.530] And we ended up with a machine that was actually so good, that did so well for us. [29:07.810 --> 29:10.950] Let me switch that mode where it does do the whole screen again. [29:11.710 --> 29:12.190] There we go. [29:13.190 --> 29:20.850] It worked so well for us that we, within the frame of a couple days, we ended up forgetting that that was this kind of machine. [29:20.850 --> 29:27.530] We ended up using it, giving it to people that needed a machine in the office, doing their mail on Hotmail on it or whatever. [29:27.810 --> 29:32.970] And then we figured, well, if we hardly know that that's underneath, then that's good enough, right? [29:35.770 --> 29:44.450] It loses, because of the tricks we did where we don't use the Linux file system, but we use a partition, and we... [29:44.450 --> 29:47.770] The Israeli military stopped the 7-busters exit into Malik. [29:47.950 --> 29:57.250] As the soldiers conducted a head count and searched each bus for explosives, they singled out the five Palestinians in the group, prompting all 400 Israelis to protest. [29:57.570 --> 30:00.170] As if they were returned to their seats in each bus. [30:00.350 --> 30:09.630] I wouldn't personally use it as my high-tech video editing machine or my quake station, but for anything short of that, it is good enough. [30:09.630 --> 30:13.630] This will do anything you otherwise would need to do. [30:14.890 --> 30:23.110] We lose about... I think on most benchmarks, we lose about 5 or 10% on the processor and a lot more on the disk. [30:25.630 --> 30:27.110] This is... we just... [30:28.090 --> 30:32.690] 1.6, but we've had it installed on 1 GHz machines and it runs fine. [30:33.690 --> 30:44.090] We've sort of come to the point where operating systems can't be made slow enough to keep up with the processor speed increases every half year. [30:46.010 --> 30:50.370] Which is a good thing because we need a little headroom, but what I'm trying to say is we don't need that much. [30:50.470 --> 30:54.310] We need RAM headroom because we're not installing swap on the Linux box. [30:54.990 --> 30:57.250] We have half a gig of RAM in there and we need... [30:58.530 --> 31:02.350] For running XP inside the box, we need at least that half gig. [31:02.350 --> 31:06.210] It would possibly work in 256, definitely not in 128. [31:06.430 --> 31:09.750] Then again, that is becoming the standard you buy for a notebook these days. [31:10.270 --> 31:14.950] So we need a little extra... we need a little extra RAM that's most noticeable. [31:15.750 --> 31:17.670] And we lose on disk performance. [31:17.710 --> 31:20.510] If you do very disk intensive things, you would notice it. [31:21.070 --> 31:23.910] But not... as I said, we've used Office on it just fine. [31:23.910 --> 31:26.530] It's not like Office would come down to a halt. [31:28.270 --> 31:30.010] We've... animations work fine. [31:30.210 --> 31:33.230] Just web pages, flash, it all works. [31:33.810 --> 31:36.210] There's hardly noticeable that you're on this machine. [31:37.450 --> 31:39.250] Can you try to move up to the mic? [31:39.510 --> 31:40.790] Because they're recording this. [31:42.550 --> 31:44.430] Or grab the mic and pass it around. [31:44.550 --> 31:48.070] A lot of organizations use access databases, which are very intensive RAM. [31:48.330 --> 31:50.330] The whole access database is pulled into RAM. [31:50.350 --> 31:50.850] Works fine. [31:51.010 --> 31:51.410] That's fine. [31:51.410 --> 31:51.970] Works fine. [31:52.130 --> 31:53.390] Well, it depends how huge it is. [31:53.490 --> 32:00.190] If you're just skimming the edges of what your hardware can do to begin with, then this might not be your thing. [32:00.310 --> 32:03.290] But as I said, you would want to do this on fairly new hardware. [32:04.910 --> 32:06.090] So, no, you're fine. [32:07.170 --> 32:09.410] On your disk performance, is it... [32:09.410 --> 32:12.270] I use VMware myself, but I haven't run the loopback. [32:12.350 --> 32:16.870] So I'm wondering how much of the loss is just because you're running VMware, and then how much is the overhead on the crypto? [32:18.270 --> 32:20.130] We haven't really tested that. [32:20.130 --> 32:21.990] We haven't done a blank loopback or anything. [32:22.210 --> 32:30.030] My guess is the VMware and basic process of getting it through the loopback takes much more than the actual crypto. [32:30.230 --> 32:31.250] That would be my guess. [32:31.450 --> 32:36.070] I was curious because I've got the same data without using the loopback. [32:36.290 --> 32:39.350] As long as you're not discontent of VMware, it works really quite fine. [32:39.690 --> 32:47.710] Now, the thing is, what we've tried to do here, again, and this is sort of a theme through all the projects we do, what we've tried to do here is create a system which you can give to non-technical people. [32:47.930 --> 32:51.390] Now, you've seen me boot this thing, and this is something anybody can do. [32:51.490 --> 32:52.610] Type a passphrase and go. [32:53.390 --> 32:55.990] And then up pops your Windows box and it is completely secured. [32:55.990 --> 33:02.450] And you can give this machine to somebody that is not knowledgeable about any of these topics and have them use it for five years. [33:03.190 --> 33:06.910] And then the hard disk would still not contain a single byte of clear text. [33:07.470 --> 33:10.970] I have a question about the USB key device. [33:12.190 --> 33:12.350] Yes. [33:13.590 --> 33:18.530] So, does this mean like when the feds come knocking on the door, I can flush it down the toilet with my pot? [33:21.930 --> 33:28.110] They would usually wait for you to flush the toilet in situations like that and then come in while the bowl is still filling. [33:28.410 --> 33:29.950] Or they disconnect the water. [33:32.030 --> 33:35.290] But you could theoretically take a hammer and whatever. [33:37.910 --> 33:40.990] The key device we use does no crypto. [33:42.110 --> 33:43.630] We store the keys on it. [33:43.730 --> 33:47.390] It's literally just a plain off-the-shelf USB storage device. [33:47.990 --> 33:52.410] And we think it's handy to be able to separate the keys from the machine. [33:52.770 --> 34:00.930] It doesn't really offer any tamper-proofing or any of the strong cryptographic things that some of these donkers do. [34:00.930 --> 34:10.030] Then again, there's no real point in believing in those strong cryptographic things in a context where all your clear text is then in the processor and in RAM. [34:10.430 --> 34:15.470] So there's no point in storing these keys in a really tamper-proof environment if you're going to move them to a Windows box. [34:17.390 --> 34:22.110] How tightly coupled are the backups to the actual machine? [34:22.290 --> 34:24.730] Can you bring them from machine to machine? [34:24.890 --> 34:25.290] Or do you only... [34:25.290 --> 34:36.390] Basically, what we do is we have a 700 meg partition on the Linux box, which is given to the Windows box over Samba. [34:37.550 --> 34:41.690] So you just write your files to it and they end up on that partition. [34:41.850 --> 34:44.510] And that partition is actually inside a loopback file. [34:45.170 --> 34:46.590] So let's put it this way. [34:46.630 --> 34:48.170] We have a 700 meg loopback file. [34:49.070 --> 34:52.130] It's where you write your files and it's shared over Samba to the Windows box. [34:52.370 --> 35:02.630] And then once you're done writing all your files there from Windows to this drive letter or whatever, you then exit the Windows and say commit that disk to CD. [35:03.170 --> 35:04.270] And then it's clean again. [35:05.050 --> 35:06.170] And it's on the CD. [35:06.870 --> 35:10.270] But in your control panel, you had a list of the backup keys that you had previously... [35:10.270 --> 35:10.390] Yes. [35:10.390 --> 35:12.050] You didn't have any here, but... [35:12.270 --> 35:15.850] It would, for each CD that you burn, it would have its own key. [35:15.990 --> 35:21.990] The CD would have an ID, which would be in the file name of the actual 700 or 600 meg file that's on there. [35:23.750 --> 35:25.650] So the file name would hold the ID. [35:25.830 --> 35:30.570] And then if you stuck that CD back in and said, I want to restore this, then it would offer it to you again. [35:30.770 --> 35:32.050] It would mount it from the CD. [35:32.210 --> 35:33.190] It wouldn't need to copy anything. [35:33.490 --> 35:38.670] It would mount that loopback file and give it to you as another drive letter mounted over Samba. [35:38.870 --> 35:42.150] So it would be very simple, but it would work for Joe Random user. [35:42.870 --> 35:44.810] It would work in getting the files back. [35:45.510 --> 35:49.270] Yes, it would be completely portable between machines once you had that key dongle with you. [35:49.470 --> 35:50.870] So it is coupled to the dongle? [35:50.870 --> 35:54.310] It is coupled to your key file, wherever you have it reside. [35:54.510 --> 35:54.590] Yes. [35:56.850 --> 35:58.730] I saw some other question back there. [36:00.170 --> 36:01.930] It's obviously disappeared. [36:02.470 --> 36:03.150] Yeah, there's one there. [36:03.750 --> 36:08.730] Have you done any testing with the IPsec communication with Windows? [36:09.990 --> 36:12.570] Done any testing with IPsec communication with Windows? [36:13.970 --> 36:24.370] We're not talking IPsec between the Debian and the Windows, because it's all inside the VMNet interfaces, the interfaces that VMware has for talking. [36:24.990 --> 36:27.410] We don't think there's much point in doing IPsec in that. [36:27.650 --> 36:39.970] What is a logical extension that we've thought about is to give this box to people and provide them with an open BSD box or some other thing which they don't have to think about for the office. [36:39.970 --> 36:47.050] And then have these boxes connect to the office box over the network using some kind of secure tunnel. [36:47.430 --> 36:48.770] That would make a lot of sense, yes. [36:48.770 --> 37:01.410] The other thing we've of course thought about is combining the localhost proxy for PGP, setting that up on the Debian machine, where your keyring would be on the dongle, and the Windows box wouldn't have any concept of PGP. [37:02.010 --> 37:04.490] It wouldn't have a keyring for people to steal. [37:04.610 --> 37:05.310] It wouldn't have anything. [37:05.310 --> 37:13.030] It would just send mail to its pop and SMTP hosts and receive mail from them. [37:13.150 --> 37:16.570] And the Unix would do all the encryption and decryption. [37:18.350 --> 37:23.950] So the user would be further removed from the actual key material, and it would be more transparent. [37:24.170 --> 37:26.130] The user wouldn't ever need to think about this stuff. [37:31.970 --> 37:37.610] No, but I'm sure it would work. [37:38.070 --> 37:42.550] We're not doing anything special that's not possible in any other VMware box. [37:45.800 --> 37:56.290] Have you considered the possibility of one of the key being instead on the smart card, and two of the encryption being on an external device using a hardware type encryption? [37:56.290 --> 37:57.900] Yes, we have considered that. [37:58.650 --> 38:07.020] The thing is, we like things that don't involve hardware, because from our personal experience, hardware projects take years, and software projects take months. [38:08.270 --> 38:12.420] For some weird scientific reason, we don't yet understand. [38:14.290 --> 38:20.380] Also, people can't just take something that involves hardware and install it on their own machines, and do things with it. [38:20.570 --> 38:25.040] So there's a much bigger industrial thing involved in getting it out to people that need it. [38:26.520 --> 38:42.150] Doing the crypto on hardware, even if it's just hardware, you can buy crypto tokens or iButtons or something, and then keying this crypto on the fly with some stream that comes out of the hardware, which is existing technology. [38:43.360 --> 38:47.550] We've thought of that, but for this particular model, we don't see much that it adds. [38:49.000 --> 38:59.270] In the sense that once somebody can freeze your machine and get the key, they can also freeze whatever state it's in that would allow it to get any file using your device. [38:59.730 --> 39:13.090] If they can take the machine from you in the train or wherever while it's hot, while it's open, then by definition it must have access to each file on the hard drive for that Windows to run. [39:13.090 --> 39:21.880] So whether that crypto then resides in a token or hardware or whether it resides in software, at that point, from a practical point of view, it doesn't really matter. [39:22.690 --> 39:27.940] So yes, there's definitely applications for hardware crypto, but this, in our minds, wasn't one of them. [39:29.900 --> 39:33.570] As much as we like some of these cool iButtons and devices and chip cards. [39:40.740 --> 39:43.420] You mentioned that you've made some patches to loop.c. [39:43.620 --> 39:45.140] Can you recall what those issues were? [39:47.160 --> 39:52.660] Mainly, VMware wants a geometry for the drive that it's being presented with. [39:52.840 --> 40:04.800] So if you tell VMware that its drive is dev loop one, then it goes out and does the IO control call for, tell me, GetGeo, I think it's called, for giving me the geometry of this drive. [40:06.160 --> 40:16.060] And we basically implemented that one on the loopback device and said, well, we'll just invent something nice and make it look like a drive you would want to use in LBA mode. [40:16.740 --> 40:20.800] And from there on out, VMware never uses that geometry anymore and is completely happy. [40:20.880 --> 40:27.020] But if you don't give it the geometry, even though it doesn't do anything with it, it just dies and then gives all sorts of boxes. [40:27.240 --> 40:28.420] Like, we've never seen this before. [40:28.700 --> 40:29.080] Panic. [40:29.240 --> 40:29.800] Call VMware. [40:33.190 --> 40:33.670] Yes? [40:36.470 --> 40:41.050] Is this something that you're planning to, like, install on the machines and then sell the machines? [40:41.130 --> 40:43.370] Or are you planning on making, like, an installation? [40:44.170 --> 40:50.990] We plan to, through third parties, probably sell the actual hardware. [40:51.330 --> 41:08.830] The thing is, it's a little too involved to tell people, well, just get yourselves a machine and install Linux on it and do these patches and get X working and get X working so that it can go in full screen mode, which is fairly involved in some video chipsets. [41:09.770 --> 41:19.650] So we try to make it easy for users that would want this sort of instant, we just go get the thing and get it working. [41:20.470 --> 41:22.330] You would want to sell it with hardware. [41:22.330 --> 41:24.590] But we're not, personally, we're a development company. [41:24.710 --> 41:26.010] We don't want to get into this business. [41:26.190 --> 41:30.370] So what we plan to do is work with partners that want to sell the solution. [41:30.910 --> 41:32.870] So working with solution providers. [41:33.550 --> 41:41.850] And, of course, the thing is, as a commercial solution, it would be fairly expensive compared to the other things in the market because the VMware license costs money. [41:44.110 --> 41:48.230] So, as a commercial solution, it would still sit in the top of the market. [41:48.390 --> 41:52.110] But we feel it has a place because it's the only open source solution. [41:52.250 --> 41:54.250] It's the only thing that you can eventually trust. [41:55.010 --> 41:55.130] Right. [41:55.650 --> 42:05.090] So, like, would you have any plans to kind of have as a target audience Linux users so that, like, you could actually get, you know, a Unix prompt, like, once you... [42:05.090 --> 42:07.090] Like, is there a way to get to the Unix prompt? [42:07.670 --> 42:10.350] There's... currently, we've set it up to where there's a maintenance mode. [42:10.470 --> 42:14.270] If you press shift on the Lilo, there's a mode where you can just go to the normal Unix boot. [42:15.570 --> 42:24.530] But basically, we figure, it being free for non-commercial use, the Linux user community can just get our program and install it on their own machine. [42:24.570 --> 42:27.930] And they already have X working, and they already have the international patch. [42:28.510 --> 42:30.090] And if not, they can get it working. [42:31.910 --> 42:37.070] So, I don't... we're still thinking about whether there's a commercial market for dual booting. [42:37.070 --> 42:39.150] Boot systems and people that want to use it that way. [42:40.190 --> 42:45.350] And, of course, if you're a Linux user, you can choose to use whatever inside that box that you want as well. [42:45.410 --> 42:46.970] You don't have to put Windows XP there. [42:47.070 --> 42:51.630] You can put anything there you want and have the added security of that. [42:56.080 --> 42:59.900] There's... it's also possible to ask questions about these other things that I've been into. [43:00.040 --> 43:01.860] The PGP localhost proxy thing. [43:02.380 --> 43:05.020] We don't have to focus completely on the secure notebook. [43:09.810 --> 43:10.910] Yes, there's a... [43:10.910 --> 43:13.230] What's your release date for the secure notebook? [43:13.950 --> 43:15.590] Release date for the secure notebook. [43:15.730 --> 43:16.530] That's a good question. [43:17.770 --> 43:22.810] We're fairly... fairly conservative where it comes to actually releasing it as commercial software. [43:23.310 --> 43:27.690] Because we feel crypto software needs time to ripen. [43:27.690 --> 43:40.990] It needs a lot of people to look at it in a beta test context where we warn people not to use it on vital data, not to take it to Nigeria and keep tabs on the government there. [43:42.450 --> 43:48.410] Until actually some people with a brain have looked at it and have said that we haven't made any stupid mistakes. [43:48.850 --> 43:53.130] We try our best not to make these mistakes, but we definitely need more time to look at it. [43:53.130 --> 43:59.030] So it's going to be on the website for testing a lot sooner than it's going to be a commercial product. [44:00.910 --> 44:02.250] Months... several months sooner. [44:02.490 --> 44:05.330] So don't expect anything commercially within the first half year. [44:05.510 --> 44:07.110] When do you expect to be on the website? [44:07.550 --> 44:09.010] When do we expect to be on the website? [44:09.570 --> 44:10.650] That's a difficult question. [44:10.790 --> 44:15.470] We expect to have... our website is basically blank right now because this is the first time we're actually presenting stuff. [44:17.610 --> 44:19.910] Something should be on the website within two weeks. [44:20.710 --> 44:24.210] The mailman modification can go up pretty much immediately. [44:24.510 --> 44:28.570] The first test versions of Cryptomatic should be up within a month or so. [44:29.630 --> 44:36.550] This thing... it really depends what time we decide to call it version 0.9 or something. [44:38.410 --> 44:40.130] There's still some decisions to be made. [44:40.310 --> 44:41.610] The backup system isn't completely... [44:42.090 --> 44:42.690] Thank you. [44:43.010 --> 44:48.630] The backup system isn't completely stable yet in the sense that we're not... [44:48.630 --> 44:52.710] Not all the design decisions have been made in the way that we like them. [44:53.630 --> 45:03.510] So it really depends what version we throw out to the people, but usable for people to actually go and test in live situations with non-vital data within a month or two. [45:11.370 --> 45:16.550] www.nah6.com I'll put on the slide number one. [45:24.550 --> 45:25.350] There we go. [45:30.540 --> 45:36.720] So there should be... basically now it's a blank page with a company logo, so don't be surprised if you look at it today. [45:36.860 --> 45:39.840] But as of next week, there should be something more legible or intelligible there. [45:39.980 --> 45:42.340] At least the copy of these slides will be up there. [45:43.260 --> 45:46.940] And soon at least these two PGP things should be there. [45:47.520 --> 45:57.160] It's a well-known fact that if you have any suspense that people have physical access to your machine, that you should consider it insecure. [45:57.820 --> 46:02.120] Have you given that any thought and maybe would like to share some ideas? [46:02.700 --> 46:05.440] Were you here for the presentation? [46:06.360 --> 46:15.160] Because I did a slide, basically this one, where we talk about the residual threats, and one of them is surreptitious access to hardware. [46:15.260 --> 46:17.620] We just have to put that outside of the threat model. [46:18.340 --> 46:18.640] You have... [46:18.640 --> 46:19.920] I was asking about... [46:19.920 --> 46:21.300] Have I given any thoughts to it? [46:21.380 --> 46:24.540] And the only thought I've given to it is... [46:24.540 --> 46:28.540] Well, I've given a lot of thought to it, but basically the conclusion is you just can't protect against that. [46:29.540 --> 46:33.660] You can't protect against somebody hanging a monitor behind you and looking at what's on your screen. [46:33.820 --> 46:34.820] You can't protect against... [46:34.820 --> 46:36.360] If you're talking about phone conversations. [46:36.840 --> 46:39.480] You can't protect against the microphone in your room. [46:40.340 --> 46:41.840] You can't protect... [46:41.840 --> 46:42.660] There's... [46:42.660 --> 46:54.900] Once you become a real intelligence target, and once you're the focus of some real money being put behind getting your clear text, there's other measures you should take. [46:55.080 --> 46:56.280] There's other things you should consider. [46:56.620 --> 47:06.040] This is for your machine being stolen, crossing an airport in some bad country where you don't want them to look at the hard disk, or whatever. [47:09.370 --> 47:10.570] Can you walk up to the microphone? [47:11.590 --> 47:12.510] There's one right there. [47:16.290 --> 47:24.050] I was just wondering if you gave any thought to, say, crossing an airport in a country where you might not want to have your data looked at. [47:24.050 --> 47:27.330] If you've given any thought to, you know, secondary keys. [47:27.430 --> 47:30.250] In other words, if someone points a gun at your head and says, type in the passphrase. [47:30.510 --> 47:34.850] There are other encryption products that have sort of fallback positions. [47:35.030 --> 47:38.990] They say, well, I'll encrypt part of it, but it's, you know, mom's chocolate chip cookie. [47:39.010 --> 47:41.390] Yeah, there's this technographic file system. [47:41.570 --> 47:47.130] There's all sorts of systems where you have multiple sets of files in one disk. [47:48.130 --> 47:53.070] We've given that thought and decided that we wanted something out that was usable for people now. [47:55.070 --> 47:56.310] And, no, we haven't... [47:56.310 --> 47:57.110] Is that an eventual model? [47:57.430 --> 48:00.570] I mean, that would be an important form of... [48:01.550 --> 48:01.950] It's... [48:03.310 --> 48:07.010] It's one of the ways in which, yes, this can be enhanced. [48:09.050 --> 48:10.350] But, no, we haven't... [48:10.350 --> 48:18.770] Of course, torture is always one of the things that is really hard to defend against if you really have the screws on your thumbs. [48:20.490 --> 48:24.990] Now, we know you didn't bring in this machine just to play Pong or Ms. Pac-Man. [48:24.990 --> 48:25.150] Yeah. [48:25.490 --> 48:26.350] We are sure. [48:33.520 --> 48:34.540] Any other questions? [48:38.870 --> 48:39.510] Over there? [48:39.670 --> 48:39.750] Yeah. [48:43.430 --> 48:53.890] This is not quite related to crypto, but have you thought about, like, implementing some sort of caching system in the Linux layer to enhance hard drive performance or anything like that? [48:53.890 --> 48:55.950] I mean, it would seem like it's all the way out this way. [48:56.110 --> 48:57.790] There is caching in the Linux layer. [48:57.930 --> 48:59.370] There's the normal drive caching. [48:59.530 --> 48:59.770] Yeah. [48:59.970 --> 49:00.050] Yeah. [49:00.250 --> 49:01.870] But, well... [49:01.870 --> 49:02.590] I guess... [49:02.590 --> 49:10.810] If you're a total expert on the way Linux talks to its drives and how the loopback file system works, then by all means just talk to us. [49:18.030 --> 49:18.470] Okay. [49:19.550 --> 49:20.710] And I guess that's about it. [49:20.990 --> 49:21.870] Thank you very much. [49:22.490 --> 49:22.750] Thank you very much.