Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Remember the rubber hose

Remember the rubber hose

A talk in distributed ledgers, privacy and an often disregarded threat mode.

Ricardo J. Méndez

July 20, 2018
Tweet

More Decks by Ricardo J. Méndez

Other Decks in Technology

Transcript

  1. July 20, 2018 / [email protected]
    @ArgesRic

    https://mastodon.social/@ricardojmendez/
    Remember the
    rubber hose
    Ricardo J. Méndez

    View Slide

  2. @argesric @samsungnext
    About me
    Technical Director for Europe at Samsung NEXT
    in Berlin.
    We partner with innovators and invest in
    forward-looking deep-tech companies.
    This talk, however, is about privacy.
    Feel free to grab me later if you want to talk
    more.

    View Slide

  3. Speaking of
    which…

    View Slide

  4. @argesric @samsungnext
    Kudos to the
    organizers.
    We need more
    conferences taking
    people’s desire for
    privacy into account.

    View Slide

  5. Let’s talk about
    privacy

    View Slide

  6. @argesric @samsungnext
    Have you asked
    people about
    decentralization?

    View Slide

  7. @argesric @samsungnext
    Most have no idea.

    View Slide

  8. @argesric @samsungnext
    People do know a few things, though
    The "crypto"comes
    from all the data out
    there being
    encrypted...
    Blockchains are
    private because they
    are decentralized...
    And this makes them
    anonymous and
    untraceable.

    View Slide

  9. @argesric @samsungnext
    This is partly our fault.

    View Slide

  10. @argesric @samsungnext
    There’s a lot of new
    concepts for people.

    View Slide

  11. @argesric @samsungnext
    Privacy “as a way to prevent signalling concerns from
    encompassing all of our activity.”
    Vitalik Buterin, reddit thread

    View Slide

  12. @argesric @samsungnext
    Everything we do in
    public generates signals.

    View Slide

  13. @argesric @samsungnext
    First world problem?

    View Slide

  14. @argesric @samsungnext
    “We are putting X on the blockchain”

    View Slide

  15. @argesric @samsungnext
    Effectively, logging.

    View Slide

  16. Let’s talk about
    keys

    View Slide

  17. @argesric @samsungnext
    Raise your hand…
    Who believes in being
    in control of their
    private keys?
    Who expects public
    key cryptography will
    keep our data safe at
    least until quantum
    computers?
    Who has ever had a
    gun to their heads?

    View Slide

  18. @argesric @samsungnext
    Yeah. That signaling.

    View Slide

  19. @argesric @samsungnext
    “We are making the world a better place”

    View Slide

  20. @argesric @samsungnext
    What’s the worst thing
    that can happen?

    View Slide

  21. @argesric @samsungnext
    Censorship resistance?
    Pseudonymity?

    View Slide

  22. @argesric @samsungnext
    Those who can benefit
    the most are vulnerable.

    View Slide

  23. View Slide

  24. Rubber hose
    cryptanalysis

    View Slide

  25. @argesric @samsungnext
    Easy, cheap, and effective.

    View Slide

  26. View Slide

  27. View Slide

  28. @argesric @samsungnext
    We need to make it
    easier for people to be
    private.

    View Slide

  29. @argesric @samsungnext
    Yes, we are better off.
    But we have it pretty
    good already.

    View Slide

  30. @argesric @samsungnext
    Hey, I’ll take it.

    View Slide

  31. How can we help?

    View Slide

  32. @argesric @samsungnext
    Yes, users can change
    your defaults.

    View Slide

  33. @argesric @samsungnext
    If your defaults aren’t
    private, they will stay
    non-private.
    Source

    View Slide

  34. @argesric @samsungnext
    Can we help with the
    metadata?

    View Slide

  35. @argesric @samsungnext
    Plausible deniability?

    View Slide

  36. @argesric @samsungnext
    But mostly, speak plainly.
    Help them build a mental
    model.

    View Slide

  37. Because we’re
    really close

    View Slide

  38. View Slide

  39. @argesric @samsungnext
    We’re in the cusp of
    something here.

    View Slide

  40. @argesric @samsungnext
    … and then 95% of them
    won’t change the defaults.

    View Slide

  41. View Slide

  42. View Slide

  43. @argesric @samsungnext
    Thank you.
    Contact: [email protected]

    View Slide