SPAC & TSP - Samuel Smith

KERICONF26 Day 2 · 42:25

0:00 Samuel Smith | SPAC & TSP | KERI Conference 2026

0:03 And so we need to so accountability is

0:06 about imposing those things. So

0:09 since any since you can be correlated

0:12 anytime you share data with a second

0:13 party eventually with repeated

0:15 interactions they're going to know who

0:17 you are and then they can share that

0:18 with anybody they want unless you impose

0:21 on them some sort of liability that says

0:24 I'm afraid

0:27 or I'm worried about the cost. I'm

0:30 worried about something that you've

0:31 imposed on me some externality that says

0:34 I'm not going to share this data. I'm

0:36 going to respect your data rights. So

0:38 any interaction system that does not

0:40 enable first parties to hold second

0:42 parties accountable is fundamentally

0:43 incompatible with privacy. It's it's not

0:46 going to be privacy preserving. It's

0:48 going to incentivize them to share your

0:50 data and violate your privacy rights.

1:02 So how we do it?

1:05 If we understand that the only thing we

1:08 can do

1:10 is to create confidential contexts

1:14 which are protected from third party

1:16 surveillance and within those contexts

1:20 impose liability on the parties to the

1:24 confidentiality that changes their

1:26 behavior. That means that we have to

1:30 either use a combination of economic -,

1:32 legal, civil, contractual means or

1:38 regulatory means and potentially

1:40 criminal means. You know, I think one of

1:42 the Utah guys talked about whether or

1:45 not sharing your data was a form of

1:47 treason. He says, "Oh, that's a

1:49 really great predictor,

1:51 you guys are all treasonous, we can we

1:53 can shoot you, because the

1:56 the law for treason is

1:59 death." So anyway, it was a joke, but

2:02 I thought it was fun to talk about

2:05 that. So, we want to create

2:07 control-safe relationships where the

2:09 interactions are protected from

2:10 surveillance by third parties and second

2:12 parties are held accountable for any

2:14 information shared with or by them. It's

2:16 not just shared with them. It's not just

2:18 one way disclosure.

2:20 We also want to hold them accountable

2:22 for what they what they do, right?

2:25 Because safety is about what is incoming

2:28 as much as it is what is outgoing. If I go

2:30 someplace and I want to be in a safe

2:31 environment, I don't want people calling

2:34 me names, being vulgar, sharing stuff

2:38 with me that I don't want to see

2:40 treating other people

2:43 badly in my presence. That's all part of

2:46 the environment. So you need to hold

2:48 everybody accountable for their

2:49 behavior. That seems very nanny state,

2:52 but actually it's what a refuge and a

2:54 sanctuary is. It's the ability for you

2:56 to decide what interactions you have

3:00 versus what interactions the

3:03 internet forces on you. So we use this

3:05 model.

3:07 Basically two parties are sharing

3:10 information.

3:12 It's always from the view of the first

3:14 party. You're the first party. What else

3:16 did you care about? Third party

3:18 observers may obtain information in this

3:21 model indirectly metadata because they

3:26 observe metadata because this is going

3:28 over the open internet. The open

3:30 internet has to be routable. That means

3:32 routing metadata is public. That means

3:36 there is no privacy on the internet

3:38 because if routing metadata is public

3:41 then everybody can correlate who the

3:44 parties are at either end. It just takes

3:46 time. There is fundamentally

3:48 no ability for you to have that

3:52 interaction without it eventually being

3:54 correlated. So what you have to

3:57 understand is that metadata is the

3:58 problem. It's not the data that's in

4:02 here. It's the metadata about here and

4:05 the Supreme Court has defined it that

4:06 way. You have protections for content

4:09 data and no protections for non-content

4:12 metadata. So I can encrypt the content.

4:16 I can't encrypt the metadata and

4:17 therefore the metadata will always be

4:19 leaky. It'll always provide correlatable

4:22 information. So what I have to do is I

4:24 have to build an artificial construct

4:29 via tunnels so that I tunnel stuff

4:32 across the internet so that the tunnel

4:34 itself

4:35 is content data relative to the internet

4:40 so that its metadata is content at

4:42 another layer. And if I do enough layers

4:45 of tunnels, then I will have a layer

4:48 where the metadata is sufficiently well

4:51 protected that it can't be surveiled

4:53 from the outside. So we can make a

4:55 highly surveillance-resistant

4:58 communication channel, right? So if

5:03 the sharing is leaky,

5:06 there's enough metadata, right? Or

5:09 they're using intermediaries, then

5:11 they can surveil that. if there's any

5:14 kind of collusion, right? So, the way

5:19 we're defining privacy is when third

5:21 parties have no knowledge of who is

5:23 sharing information, then we have

5:25 privacy with regard to third parties.

5:28 And confidentiality is when third

5:30 parties have no knowledge of what is

5:32 what was shared. So if the second party

5:36 shares with the third party, they broke

5:38 confidentiality.

5:40 If the second party

5:42 shares with the third party who they are

5:45 or who's in the party, then they broke

5:47 privacy. And so that follows the Supreme

5:49 Court definition of privacy and

5:52 confidentiality in terms of how we

5:54 reason about it. And it's

5:56 important because if we lump these all

5:59 together under one term, then we get

6:01 confused when we start talking about it.

6:03 So I try to be really clear and not

6:05 get confused about it. So this is the

6:07 the TSP and I leveled SPAC

6:10 because the name of the protocol when I

6:12 wrote the white paper was secure privacy

6:16 authenticity and confidentiality and the

6:18 header to the

6:20 introduction of the protocol says the

6:23 goal here is to get the best privacy we can,

6:26 given we make no compromises

6:29 on authenticity and

6:31 confidentiality.

6:33 So we start with the strongest possible

6:34 authenticity, confidentiality and then

6:37 work backwards to figure out what's the

6:38 best we can do. And the reason for that

6:41 is, that in my experience, as soon as you

6:44 compromise on authenticity and

6:45 confidentiality, you end up with more

6:47 leakage pass more opportunities and the

6:51 net result is you have less privacy

6:53 overall. Whereas if you start with

6:55 privacy, you make hard trades that you

6:58 can never recover from in on the

7:00 confidentiality and

7:04 authenticity part. And that means fraud,

7:07 that means identity theft. And if

7:10 you're worried about somebody knowing

7:11 who you are because your metadata got

7:16 leaked and tracking you, then you

7:19 have to make a judgment decision

7:20 saying, "Well, what's what's more

7:22 important? they know who you are or they

7:24 steal all your money," right? For most

7:27 people, stealing all your money is a

7:29 much bigger harm. Now, there are corner

7:31 cases where knowing who you are can be

7:34 really bad, especially if you're a

7:36 criminal and you're worried about

7:37 going to jail, right?

7:40 When you're a dissident and you're

7:42 worried about being repressed.

7:44 So, the core of the protocol is a triple

7:46 tunnel.

7:49 So, we have a tunnel between A3 and B3.

7:52 Oh, here I can do it over here. Can you

7:54 guys see the cursor showing?

8:00 No cursor. It was there a minute ago. Oh, I guess

8:03 it disappeared. All right. Anyway,

8:06 so it's a triple tunnel. So I

8:10 have three pairs of identifiers. A3 B3

8:13 A2 B2 A1 B1. So endpoint A has three

8:20 identifiers. Endpoint B has three

8:21 identifiers.

8:23 Those identifiers are not mutually

8:25 correlatable. They're independent

8:27 identifiers. What would make them

8:29 correlatable is if they were exposed in

8:32 such a way that the context

8:36 correlated them, but they're

8:37 high-entropy identifier. So they

8:40 don't intrinsically convey any

8:43 information that says they're related.

8:44 So the fact that it's B1, B2, and B3

8:47 doesn't mean anything. They're just ran,

8:48 you know, pseudo-random numbers, right?

8:51 The other important

8:54 distinction is to understand that

8:58 clandestine surveillance and counter

9:01 surveillance for clandestine stuff is

9:04 purely ephemeral

9:06 because clandestine says,

9:09 I'm not detectable. I'm going to

9:11 minimize my detectability as much as

9:14 possible so they can't tell what's

9:15 happening. Covert says I have an overt

9:20 detectable

9:22 identity

9:24 that confuses the surveiller into not

9:27 looking underneath the cover of what I'm

9:31 doing so they don't detect the thing

9:33 that I'm doing. And for persistent

9:38 counter surveillance, I want to I want

9:40 to be covert.

9:43 If Im clandestine, usually

9:46 that means it's a very short op [portunity]. It's

9:49 only going to happen for a short period

9:50 of time cuz eventually I'll start to

9:52 leak stuff. And once they start to leak

9:54 stuff, there's nothing stopping them

9:55 from come getting me. Whereas if I

9:57 covert, they're confused. They go "Wait,

9:59 well, no, he's he's not a problem,"

10:02 right? "We don't see that."

10:05 And the covert stuff allows me to hide

10:07 things in ways that I can't hide it if

10:08 I'm clandestine. So the idea is that

10:11 we're basically creating two cover

10:13 identities to hide this guy. And so they

10:16 have to pierce two covers. They have to

10:19 burn two covers to get what

10:21 we're doing. And the reason

10:22 it's two covers is because of the

10:24 intermediaries. So what happens is,

10:27 I create ..., I'll go to the next one,

10:31 I'm going to introduce the concept of

10:33 relationships. So remember I have three

10:35 three pairs of identifiers. So I have

10:37 relationships between two identifiers

10:39 and the relationship can be bidirectional

10:42 or unidirectional. And this is important

10:44 because

10:46 A can talk to B using a different

10:50 triple tunnel than B talking to A. And

10:54 that removes a form of correlation of

10:57 metadata. So we don't necessarily want

11:00 it to be bidirectional. We want to

11:02 be completely independent and be

11:04 unidirectional or not. What that does, is

11:07 that we can then define a relationship

11:10 graph of all of our identifiers

11:14 and everybody else's identifiers

11:16 and every pair of identifiers forms a

11:19 relationship. And in that relationship

11:21 we have routing data and we have

11:23 identifiers on both ends of each of

11:25 those relationships. And what we're

11:26 trying to do is make it so the metadata

11:29 in those relationships is hidden so that

11:33 it's not surveillable.

11:35 And when I say not surveillable, not

11:39 easily surveillable. Everything is

11:41 surveillable, but you want

11:43 to make it hard enough. And if you think

11:47 about this, this is a self-identity

11:49 graph. This is all of my identifiers and

11:53 my data and attributes. And a

11:55 relationship graph is just the

11:57 intersection of multiple identity

11:58 graphs.

12:00 Right? So when I go when I was here,

12:03 I got controller A and notice it he's

12:06 got multiple identifiers A 1 through 4.

12:09 Right? So his identity graph is that

12:12 subset of this graph, right? But when he

12:15 then forms relationships with B, then

12:17 then those two graphs intersect.

12:20 So, if you haven't figured out ..,

12:23 I love graphs. My brain just

12:27 works in graphs.

12:29 Everything I think about is just like "Oh

12:31 I can graph that!", right. And then I can

12:33 reason about it. So relationships

12:37 properties. I know this is a little small,

12:39 there's a lot of them [properties]. A cryptonym

12:42 is a cryptographically-derived pseudonym

12:44 with at least 120 bits of entropy, so we

12:48 don't have any ability for anybody

12:50 to discover

12:52 anything about it because it has enough

12:53 entropy and AID is a cryptonym that is

12:57 also securely attributable to one of our

12:58 key pairs right you guys know all this

13:00 stuff but some people that see SPAC,

13:02 especially when we present the TSP,

13:04 which is like sort of the TrustoverIP's

13:07 generic version of it. They don't

13:08 understand these things. So

13:11 relationship is just a pair of two AIDs.

13:14 So two AIDs because they're cryptonyms with high

13:17 entropy are uncorrelated.

13:21 There's no .., from an information

13:24 theoretical sense, there's no knowledge

13:26 that one AID provides about the other.

13:28 People say things like, "Oh, they're

13:31 super they're super cookies or they're

13:33 super correlators." From an information

13:35 point of view, they're not. The only

13:39 thing that correlates them is the

13:40 context of their use. They themselves

13:43 have zero correlatability. They're

13:45 totally random. That's what high entropy

13:47 means. So, if I don't use them in the

13:50 same context, they can't be used to

13:52 correlate me. The only way they can be

13:54 used to correlate is if I use them in a

13:56 context and the context leads to

13:58 information that allows the correlation.

14:00 It is the context that is the

14:02 supercorrelator not the identifiers.

14:05 So a context is a set of events. So we

14:08 got to define that two contexts are

14:10 disjoint with respect to an AID when the

14:12 AID appears in one or more events in one

14:14 set but does not appear in the event in

14:16 the other set. If they're disjoint,

14:18 they're not correlatable.

14:21 Right? So the goal is build

14:24 disjoint context. We want to

14:26 partition our context.

14:29 A relationship is not a communication

14:31 channel but the event sent over

14:33 communication channel may be a context

14:35 for the AIDs in relationship. So as

14:39 soon as I start sending information I

14:40 create a context and that context may

14:43 correlate me. Interaction graphs are all

14:46 about correlating using context to

14:49 correlate things.

14:51 A partition is a set of contexts with

14:54 mutually disjoint relationships. I'm

14:56 being kind of mathematical here. Any set

14:59 of relationships using one relationships

15:01 identifiers may form a partition. So

15:04 that's how we get

15:07 disjointness. We only use an identifier

15:12 in one context.

15:14 And if that context could potentially

15:18 form a partition, therefore I'm not

15:20 correlatable outside of the context.

15:24 Partition relative to other contexts.

15:27 Any two member contexts of

15:30 a partition may be correlatable due to

15:32 other information associated with those

15:34 contexts, but the partition

15:35 relationships by themselves provide no

15:37 correlatable information. Partition

15:39 relationships are by themselves not

15:41 mutually correlatable. The relationship

15:43 isn't the problem. It's the context.

15:46 Think context when you're worried about

15:48 correlation. Don't think identifiers. We

15:51 sort of have inverted that when we talk

15:53 about linkability because we say

15:55 cryptographic unlinkability is about

15:58 identifiers. No, it's about how you use

16:01 the identifiers in what context. That's

16:04 where the correlation comes. It's a

16:06 subtle nuance. It's subtle. I get it.

16:08 But it's vitally important if we're

16:10 designing protocols to understand that

16:12 subtlety. So an AID common to any set

16:16 subset of events within a context

16:18 provides a perfectly correlatable

16:19 feature across those common events in

16:21 that context. Now why do we want

16:23 perfect correlation within a context?

16:27 We want perfect correlation within a

16:29 context so that we have accountability.

16:34 That's how we get accountability. You

16:36 can't do something and not have me know

16:38 that you did it. So I have

16:40 non-repudiation. I have absolute ability

16:43 to point the finger at you and say you

16:45 did that. If you leak

16:48 information, I know you leaked it. So

16:51 as soon as we weaken this and

16:55 use identifiers that are not perfectly

16:57 correlatable, we lose accountability.

17:00 And so the whole goal of what we're

17:02 trying to do is to create safe contexts

17:04 we just threw away. We threw away before

17:07 we even built anything. We started with

17:09 something that's broken and we can't

17:11 build it from there.

17:13 We have to start with this and then we

17:15 have to isolate the context.

17:18 So within a context secure

17:21 attributability together with perfect

17:23 correlatability across that context

17:25 ensures reputational trust. I just said

17:27 that in a different way. Accountability,

17:30 right? If I put a gun to your head, I

17:32 know what you're going to do. Right?

17:34 That's reputational trust. Yes.

17:37 Do you see any situation when you would

17:40 want to not have accountability?

17:43 Oh, yeah. There's lots of situations

17:44 like that.

17:46 I'm not precluding those.

17:49 But when I'm talking about internet

17:51 safety and I want to have

17:54 valuable relationships with value to me,

17:58 then they're not valuable unless there's

18:00 accountability. Yes.

18:01 So the Signal people really

18:04 emphasize deniability.

18:06 Yeah, that's a really good question. So,

18:09 I can look up two papers for you. The

18:12 BYU security research group did two

18:16 several papers they published and they

18:18 asked the question, is deniability

18:20 actually what they say it is? And they

18:23 and the answer was no. People want

18:25 accountability, not deniability.

18:27 I' I've heard that as well. I've also

18:28 heard studies that no jury has ever used

18:32 this alleged cryptographic property to

18:34 do.

18:34 That's right. That's the other thing

18:35 they found out is just that they

18:37 claim it, but they won't the

18:39 judges and the juries won't enforce it

18:41 because they don't see it as

18:43 something that they can

18:45 adjudicate [rule on, red.]

18:46 and I believe it actually breaks

18:47 down the device case, but that's a

18:49 separate Yeah.

18:50 It doesn't work in any sense.

18:52 Yeah. But the conclusion was

18:53 It's a false concept. It's

18:56 fundamentally designed as a way to

18:58 advertise the fact that you don't have

19:00 the good properties you want but you

19:03 have other properties that if you're

19:04 criminal sound like they're good and

19:06 actually they are for criminals, right?

19:08 But it doesn't

19:10 protect you, the noncriminal, it's

19:12 actually harmful to you,

19:13 the noncriminal, because you're the one

19:15 who's going to be exploited by the

19:17 criminal who has deniability, and you're

19:20 expecting that you have some recourse or

19:22 protection, and the law says, "No, no,

19:24 we're not going to give you protection

19:26 because they don't believe they should

19:27 protect criminals." And deniability

19:29 says, "Oh, you're a criminal then, so

19:32 we're going to go after you anyway." So,

19:34 I'm summarizing, but you should read

19:36 the papers. They're pretty good. Just

19:37 look up BYU and deniability. There's two

19:39 papers. Yes.

19:40 In use cases where you might need

19:42 deniability like voting, you wouldn't

19:44 use this. You'd use a different

19:45 protocol.

19:46 Yeah. Because one of the thing one of

19:47 the core tenants of voting is that you

19:50 don't want to allow

19:54 repression of voters by exposing their

19:58 votes. You want to have a blind vote.

20:02 And so if you can tell what a voter did

20:04 and what they said and hold them

20:06 accountable, then that has all

20:08 kinds of bad effects.

20:09 So you would use your

20:11 KERI

20:12 for the ticket and then you exchange

20:15 the ticket.

20:16 Yeah. You want you use KERI for the

20:18 voter ID, not for the voting.

20:20 Yeah.

20:22 Partitions balance. This is the

20:25 reason why we talk about partitions.

20:27 They balance these two things. strong

20:29 authenticity and strong confidentiality

20:32 within a context. So that's one side. We

20:35 get accountability when we have

20:37 authenticity and confidentiality.

20:39 Confidentiality isn't really about ..,

20:41 we actually get

20:42 accountability with strong

20:43 confidentiality when it's a symmetric

20:47 with sufficiently strong privacy

20:50 between contexts. That's how we do it.

20:53 We say okay I want context with high

20:57 accountability. I want to sacrifice that

20:58 because that's where most of the value

21:00 is. But I want to have a partition. So

21:04 what can I do to make the partitions as

21:07 strong as possible? I can't make them

21:09 impervious [Impenetrable, red], but I make them strong

21:11 enough

21:13 that the tradeoff between

21:16 account value from accountability and

21:18 the loss of value from surveillability

21:21 or trackability or something else is on

21:23 the side of what I do. And we can do

21:27 really good stuff here. And often I get

21:29 in conversations where I criticize the

21:32 privacy community and people get

21:35 defensive and they think that I'm just

21:37 throwing the baby out with the bath

21:38 water. No, I'm going to great lengths to

21:41 do everything I can to make those

21:42 partitions as strong as possible, right?

21:45 I'm doing everything I can, but I'm

21:47 never going to sacrifice these two just

21:51 to make it easy on me to make those

21:53 partitions strong. I'll have to do more

21:55 work to make the partition strong. Yes.

21:57 You mean you mean privacy or

21:59 confidentiality in the last statement?

22:01 No. Privacy.

22:04 Confidentiality is easy. Privacy is

22:06 what's hard. Privacy is knowing who's

22:08 who's the party.

22:10 Explain what it means to have privacy

22:12 between contexts.

22:13 The parties in each context you

22:16 can correlate. So if I go to a bank and

22:20 I'm interacting in my bank context and

22:23 then I go to Walmart and I interact my

22:25 Walmart context, Walmart and the bank

22:27 can say, "Oh, you're the same person

22:30 that they broke the partition.

22:32 There wasn't a partition there." And so

22:34 tracking and surveillance is about

22:36 aggregating context because that's how

22:38 you gain value, right?

22:40 I need to know how you use,

22:44 what your behavior is. If

22:46 I want to advertise to you, I want to

22:48 profile your behavior. That means

22:50 tracking you across contexts.

22:52 So, you're saying "if you think about

22:54 all of those interactions as building a

22:56 a connection graph,"

22:59 [Sam corrects:] interaction connection graph

23:00 "the ability to define those connections,

23:04 I want to be in control of the

23:05 connection graph."

23:07 Yes.

23:08 that I want to make it so that there

23:10 is no correlated build

23:12 metadata whenever I interact, right? So

23:15 that they can't build the interaction

23:17 graph. I'm basically looking at what

23:20 NSA funded in the post 911 world. They

23:26 spent

23:28 lots of money developing software

23:33 that allowed

23:35 surveillers to build interaction graphs.

23:38 So they would know that if you're

23:41 talking to this person, they're talking

23:43 to that person that somewhere in that

23:45 network they're talking to somebody that

23:47 that is a bad person. And so when

23:49 you do a FISA warrant, one of the things

23:52 you do is you say, "How many hops is it?

23:54 a one hop fight a warrant, a two hop or

23:56 a three hop?," right? Well, one hop is

23:58 your immediate connections in that

24:00 interaction gap. Two hops is two hops

24:02 out. Well, seven hops is the whole

24:05 world, right? So, a three hop FISA

24:08 warrant is a pretty broad warrant,

24:11 right? And people go, "Oh, well, you

24:13 know, right?" So it doesn't take

24:16 much, but it takes a lot of work to

24:18 to fight that. So, let's see how

24:21 we do that. All right. So here another

24:24 acronym PARK portable authentatable

24:27 reputable contextual cryptonimity

24:30 that doesn't roll off the tongue very well.

24:33 All right. So first we have to

24:37 start with how we make the strongest

24:40 possible authenticity and

24:42 confidentiality. We're not going to

24:44 sacrifice that. And this is called ESSR

24:47 encrypt sender sign receiver.

24:50 What it looks like is: I create a

24:54 message. I have cipher data. Inside the

24:56 cipher data, I have the source identifier.

24:58 So that's encrypt sender. Here's

25:01 the data. I then have a destination

25:04 identifier that's within the block

25:06 that's signed. That's the sign

25:09 receiver part. And then in order to

25:11 verify the signature, I need to send the

25:13 source identifier. So the source

25:14 identifier shows up twice because I need

25:16 it to verify the signature.

25:21 What that does,

25:24 is it satisfies all of these and I'm

25:26 just going through these, you can

25:27 go read these papers, but basically

25:30 there's been this tension and this goes

25:33 all the way back to my rate days of

25:36 what should I do? Encrypt then sign,

25:40 sign then encrypt, sign and encrypt,

25:43 right? Well, these are the properties I

25:46 want: I want third party unforgeability

25:49 plain text, third party unforgeability

25:50 cipher text, receiver unforgeability

25:52 plain text, receiver unforgeability cipher

25:54 text. The only one that gives me all

25:57 four is ESSR.

26:00 And signed and encrypt only gives me

26:02 one of these. So it's really bad.

26:06 So what I want to do is

26:08 ESSR. And this is so weird because this

26:10 is like a paper from 2001

26:14 that nobody paid attention to, but it

26:17 tells you exactly [how]. And now,

26:20 18 years later, everybody's

26:24 worried about key compromised

26:25 impersonation attacks. And the IETF 9180

26:30 Hybrid public key encryption standard

26:32 basically says, "Oh yeah, you can't do

26:35 it with encryption. You can't do it with

26:38 chems you can't defy helman you

26:42 can't solve this because it's

26:44 it's vulnerable to key compromise

26:46 impersonation attack." But ESSR isn't and

26:49 so they say you got to sign. So if you're

26:52 not signing, you're vulnerable. So

26:55 every protocol on the planet that

26:57 doesn't sign is vulnerable to one of

26:59 these

27:02 so let's go back I already did this

27:06 yeah that's just a copy of that slide

27:07 okay so let's look at the .., this is a

27:10 little complicated. I'm going to skip

27:12 through this. I don't think you want all

27:14 this.

27:16 Yes.

27:16 How many P and Q's do I have to mind in

27:18 order to get privacy?

27:21 How many P's and Q's?

27:22 Minding my P's and Q's. How many of them

27:24 do I need to?

27:26 I don't know what you mean by is that a

27:27 joke?

27:28 It's a bit of a joke.

27:29 Okay.

27:30 How many? But you have you have one P

27:33 and one Q. Is that all I need? Because

27:36 that's not very many. I can surveil that

27:39 right

27:39 one. No, no, the triple tunnel. I'll

27:42 have to explain how the triple tunnel

27:43 works. So I

27:44 – So Sam,

27:46 I think I need to Oh, there I Yeah, here

27:48 we go. Seeing a single tunnel. Yes.

27:50 – So one of the things you said a bit ago

27:52 that I think everybody misses in this is,

27:57 is your connections to me, at least

28:01 visually, are loosely analogous to

28:03 unidirectional onion routing.

28:05 Yes.

28:07 But the other part of that is: there's

28:11 more than one AID.

28:13 Yes.

28:14 And that's a nuance I don't think I've

28:16 ever heard you say before, but it's an

28:19 important one because the correlation

28:21 that people complain about, including

28:24 myself, is reusing AIDs. And your

28:29 other diagram showed that you don't do

28:31 that.

28:32 No. Yeah,

28:33 that's important.

28:34 That's why I said it's covert. I have

28:36 two AIDs that are cover identities,

28:40 – right.

28:41 So, what is a

28:43 covert op? A covert op says I have a

28:46 cover identity. So, let's say I'm

28:50 going to go to some foreign

28:52 country and I'm going to dress up and

28:56 act like a shopkeeper.

28:58 Actually, a good one for World War II is

29:00 I'm going to get a job at the train

29:02 station as the ticket taker at the

29:05 train station. So, I'm going to spend

29:06 years building that cover identity. And

29:10 during the time that I'm building the

29:11 cover identity, I'm clean.

29:14 I'm spotless, I don't do

29:17 anything bad. Right? Now I have this

29:19 cover identity and everybody trusts me.

29:21 I have this reputation that says I'm the

29:23 ticket taker at the train station. But

29:26 guess what I can do now? I can surveil

29:28 people that use the trains and if I have

29:31 a dead drop someplace, I can share that

29:35 surveillance information and nobody

29:38 goes, "Wait a minute. Who's that guy

29:41 standing at the train station just

29:44 watching everybody?" And they're going,

29:46 "What's he doing there? Why is he there?

29:48 He's surveilling." That's right.

29:51 But if I'm a ticket taker, I'm there

29:54 every day. It's my job to be there. So,

29:57 yeah, give me your ticket. Oh, okay. Who

29:59 are you? Oh, yeah. Who are you? Okay.

30:01 Yeah, I know who is everybody getting

30:03 in and off the train, right? So,

30:06 nobody suspects me as surveilling

30:08 because I'm supposed to surveil as part

30:11 of my cover identity. So, this is great.

30:13 So, what we want is a cover identity

30:15 that says we're doing something that is

30:17 innoculous, that doesn't reveal any

30:20 information, but we're going to use it

30:22 to cover something else we're doing that

30:24 the surveillor can't see through. Right?

30:26 So, the first cover identity is that I

30:30 have an endpoint and I have an

30:32 intermediary and I have a pair of AIDs

30:35 that allow me to communicate to the

30:37 intermediary.

30:38 It's perfectly surveillable.

30:42 It's from the privacy point of view.

30:44 These two are used to route information

30:47 between them. Right? I can encrypt

30:50 the content. So I have confidentiality

30:52 but I have no privacy. That's okay. This

30:55 intermediary has a cover identity P and

30:59 Q that allows these two to talk

31:01 together. Right? And then I've got a Q

31:04 to B1. So here's the path. So my

31:07 packet's going to follow this path. Now

31:09 what's not shown on this graph, which

31:12 makes it really complicated but is vital,

31:15 is that an intermediary .., what does an

31:17 intermediary do? It routes. So if it's

31:20 if it's an intermediary of any value

31:24 there are 100 or a thousand or 10,000

31:28 Q's that P talks to.

31:32 So when Q when P sends out a packet,

31:36 it's got to hurt privacy of a

31:38 thousand because any packet it sends out

31:41 addressed to any of those Q's is

31:43 uncorrelated with a packet I send to P.

31:47 Somebody can observe this pack and they

31:48 go, "Yeah, well it went here and then a

31:50 thousand packets came out here. Which

31:52 one is it?" I don't know. Right? That's

31:55 that's essentially how onion routing

31:57 works.

31:58 The problem is that intermediary P has

32:02 to know which Q A wants to send to. So

32:07 he's now a problem.

32:10 And intermediary Q needs to know how to

32:12 send to B, right? So he's a problem.

32:16 So I can't just tunnel once because

32:19 the intermediaries can disclose the

32:21 tunnel. So what do I do? I add a second

32:24 tunnel. I've got A2. Now A2 is

32:27 encrypted.

32:29 So intermediary P doesn't see A2

32:33 because it's content data relative to

32:35 the pink. So now inter[mediary] P doesn't know

32:39 where the packet's actually going. It

32:41 just knows that I need to forward it the

32:43 next hop. And that's all it knows,

32:47 right? And Q, right, he is

32:51 the one that has to unwrap this one to

32:54 know to get it to B2. So he's still a

32:57 problem. So now I do the triple tunnel

33:02 and A3 and B3 are not known by any of

33:05 the intermediaries. They can't see it.

33:08 So the reason I need three

33:10 tunnels and only three is because I

33:13 want the intermediaries to not surveil

33:15 it either and they're second parties,

33:19 right? So I have third parties that

33:22 that can surveil this. I have second

33:25 parties that can surveil this, but

33:27 nobody can surveil this. So, I don't

33:30 need onion routing. I don't need 20

33:34 onion routers. I need two intermediaries

33:36 with high fan out and high fan in.

33:38 That's it. So, it's inherently easier to

33:40 build. Any internet service provider can

33:44 build this. And they and they're not

33:46 a target for law enforcement because

33:48 they're doing onion routing. They're

33:49 just doing what they're supposed to do

33:52 efficiently route lots of packets. Yeah.

33:55 – It seems like the subtlety is that we're

33:57 talking about routing at an application

33:59 layer versus routing at an IP layer.

34:02 Well, no, it's both,

34:05 right? Because I have to route at the IP

34:07 layer.

34:08 – But the IP layer routing is inconsequential.

34:12 Well, no,

34:14 it's not because this one here, the IP

34:17 layer routing correlates to this and so

34:20 it defeats me. But at this

34:23 layer, then yes, IP's gone at that

34:25 layer. No more IP. So, I've done two

34:28 things. I've gotten rid of IP because

34:30 it's in this layer and now I'm in a an

34:33 application layer and now I'm in an

34:35 application layer inside the application

34:37 layer. And that and so it took three. I

34:39 took me a while to figure it out. I had

34:41 to li, you know, that's why I have these

34:43 diagrams with all these, you know, 50,

34:46 100 symbols on it because I'm keeping

34:48 track of every piece of metadata and I'm

34:50 going, who knows what metadata? What can

34:53 they surveil? And after I got to three

34:55 tunnels, I said, "Oh, wow. I don't need

34:57 any more. I didn't know. I thought I

34:58 might need four or five."

34:59 – If the routes were isomeorphic, then it

35:01 all collapses. Right.

35:03 What do you mean by that?

35:04 – If the route for .., if the pink

35:06 route is the same route ..

35:08 Oh, yeah. That's why I said you have to

35:09 have a fan out. You have to have high

35:11 fan out.

35:12 It's not just fan out. It's that

35:14 there's randomization of the fan

35:16 out.

35:17 No, you just have to have white noise of

35:19 the fan out. So there's two ways to

35:21 do that: One is you can try to randomize

35:24 or two is you make sure that the

35:28 probability is uniform. So you have a

35:31 uniform distribution. And the way we do

35:32 that .., because we can't manage the

35:34 randomness, what we do is we make sure

35:37 that there's no correlatable metadata in

35:39 the packet itself. That means the

35:42 intermediary, if they're a good

35:43 intermediary,

35:45 will send data on all of their fan out

35:48 to maintain a uniform traffic level so

35:52 that you can look at and see a burst of

35:54 traffic from here and then see it

35:56 populated.

35:57 That's practical.

35:58 Yes, it's absolutely totally practical.

36:01 Every TCP connection does that anyway.

36:04 It does that anyway.

36:07 So, we're not adding

36:10 any net traffic.

36:12 Huh?

36:13 – Can be bursting.

36:14 Yeah, it can. But, then you do

36:17 scaling. You do elastic scaling to

36:20 handle the burst. So what we're saying

36:21 is that you design for a certain

36:24 level and then you can either decide

36:26 here to look at your own statistics and

36:29 decide to delay or not send based on

36:32 your statistics,

36:34 right? And every packet is the same

36:35 length. So yes, if you're trying to

36:37 build optimized routers, you don't like

36:40 this. But if you're trying to build for

36:42 privacy, you want uniform. You

36:45 want white noise and so what is

36:48 more efficient? Two intermediaries with

36:51 high fan out and uniform distribution or

36:53 20 nested tour routers

36:59 three minute warning.

37:00 Okay,

37:01 – Just real quick. So on that diagram, P

37:05 is aware of A and Q.

37:08 Oh, sorry.

37:10 And Q is aware of P and Q. Well, in

37:13 order to route the packet from endpoint

37:16 A to endpoint B, you have to

37:20 send the route with the

37:22 packet,

37:24 right? No, I get that.

37:26 My question is what if P and Q

37:30 collude?

37:33 If P and Q collude, the only

37:38 thing that they can do is DDoS this

37:41 route. That's all you can do. They can't

37:43 expose it. They can just break it. So

37:46 that's you're always vulnerable to that.

37:48 So if you're worried about that, then

37:50 you send the same packet by a different

37:52 route. You do

37:54 multi-perspective routing so that you

37:56 have multiple intermediaries. So if two

37:58 of them collude, it still gets through.

38:01 And that's why having it not be

38:03 channel-based but be totally asynchronous

38:05 and unary instead of by you know

38:08 birectional unidirectional allows you to

38:11 do that. And since all the messages have

38:15 cryptographically secure unique sets you

38:18 can you can figure it out at the other

38:20 end that they're .., you can do

38:21 duplicate detection triply with

38:25 with duplicate detection replay attack

38:29 KRAM. Where's the KRAM guys?

38:32 There you go. Sorry. I was looking for

38:34 the first I was looking for the first

38:35 shirt like this. Yes. So,

38:40 you do things like that to protect it.

38:42 But those are good, those are all

38:44 good questions. So, we added to the

38:47 protocol. So, we just need that

38:50 that would be all that's required. But

38:52 we added another protocol because we

38:54 found that it would be useful and that's

38:56 a relation formation subprotocol. What

38:59 that allows us to do is that once we

39:01 establish a route and I won't go through

39:04 all this. Okay, I'll go back. Once we

39:07 establish A3 and B3,

39:10 we have a secure private channel.

39:14 We can use that channel to create other

39:16 secure private channels. And all we're

39:18 doing is saying, I've got an A4 and I've

39:21 got a B4.

39:24 And we'll form a relationship with

39:26 those two. So now within this context I

39:30 can create other secure contexts

39:34 and when I create those I can exchange

39:36 routing data that says move A4 and B4 to

39:41 a different set of intermediaries.

39:44 So now I can use one of these. I can

39:46 stand this one up and then I can do

39:51 Do this on steroids because I say

39:54 okay the first five packets we're going

39:56 to use this one we're just going to

39:57 we're going to create A4 and B4 and part

40:00 of the information we exchange is a new

40:02 set of new pair of intermediaries that

40:04 we're going to use and every time we

40:06 send a message every day we just create

40:09 a new one. So every day we have so we're

40:11 having one-time use contacts and onetime

40:14 use contacts are highly

40:16 uncorrelatable

40:18 because you're minimizing the

40:19 amount of correlatable data because

40:20 you're creating a new pair of

40:24 non-correlatable identifiers within a

40:25 secure context that is

40:28 a partition. So you can create

40:29 partitions on the fly as many as you

40:32 want

40:34 which satisfies all the usable

40:36 properties that people have for privacy

40:39 without sacrifice security or

40:42 confidentiality or authenticity.

40:45 We're done. All right.