The history of cryptography reveals that while cypherpunks successfully won the 'cryptography war' by making encryption tools widely available, the resulting PGP system failed to achieve mass adoption due to its complexity and lack of usability. Modern secure messaging requires protocols that provide forward secrecy (protecting past messages if keys are compromised), deniability (allowing users to plausibly deny sending messages), and seamless user experience. The Signal Protocol (Axolotl) addresses these challenges through ratcheting key material that moves forward and cannot be reversed, enabling end-to-end encryption that works transparently across multiple devices without requiring users to understand cryptography.
Private Communication Evolution: From PGP to Axolotl Protocol
Added:1995 was the year that Netscape introduced Netscape Navigator and at the time it was almost revolutionary right and a lot of people move to capitalize on that opportunity one of the players was Microsoft and they introduced Internet Explorer and so you know the the story of the decade became about the browser Wars you know Netscape versus Microsoft and we all know how that went so at the same time there was a different war that was happening and it was not as out in the open but perhaps more significant and it was a war over this thing the little padlock in the bottom left corner of your web browser and more importantly the ideas behind it cryptography on one side of this war were the cypher punks these were people who wanted to see cryptography used and spread widely throughout the world and on the other side of the war were the eavesdroppers and these are people that wanted to limit the use and distribution of cryptography and so the lines were drawn and on the cypherpunks side you had people like you know Matt Blaise Philip Zimmermann Ian Goldberg david sharm the the heroes of my teenage years and the government thought that these people were dangerous in fact their ideas scared the [ __ ] out of them they were talking about a world you know the shift in a world where they had ultimate control and ultimate access to all information that was transmitted globally to a world where they would have no control and no access to any information that was transmitted in fact they thought these ideas were so dangerous that they considered them to be weapons they classified cryptography as ammunition and if you wrote a little bit of crypto code in the United States and sent that to your friend over the border in Canada that was the same as exporting Stinger missiles and you could be tried and prosecuted as such at the same time the government realized that this whole like cryptography privacy thing might be important to some people and so they had their own solution in the form of the Clipper chip which was a piece of hardware that they wanted to embed into every piece of consumer electronics every telephone every fax machine every device and it would perform cryptography and allow you to establish secure sessions with you know somebody who had another computer or another device the only catch was that the government had like a master key that they could use to decrypt all of the the communication and so that's that's how things were shaping up now the government's problem is that cryptography is not a banana which is to say the information cannot be is not the same as an object right if you have a banana and you share it with your friend there's still only one banana in the world you know if you write a little bit of crypto code and you share it with your friend there's two pieces of crypto code in the world and and that's exactly what happened the cypherpunks mantra at the time was cypherpunks write code and so people got to work some people moved to this island in the Caribbean called Anguilla which had favorable laws considering the export and distribution of cryptography they started writing these cleanroom implementations of cryptography and then shipping it throughout the world other people moved to this place the Principality of Sealand which is an old world war two anti-aircraft gun platform that was built by the British and then abandoned and it's in the middle of the English Channel in international waters so this crazy guy his name is Roy Bates in the 1960s just went out there and like claimed it he like colonized it as his own and since it's in international waters he says that it's his own country he originally did that to broadcast pirate radio like rock and roll back into the UK but so a bunch of people went out there to do like a data Haven cryptography project and then back in the United States people tried other things in 1995 Philipp Zimmermann published this book called PGP source code and internals and the whole deal is that it was a book with the PGP source code in a machine readable font so you could take the book and then easily scan it in and get software out of it and so the idea is that you know if you write if you have like a digital representation of cryptography that's a weapon but if you print it into a book then that's speech and in the United States you know you can't ban books right so you know very limited print run you know they did that and you know mailed it to a few places in the world and those people scanned it back in and stuff like this continued until 2000 when the Clinton administration repealed all of the most of the significant laws limiting the use and export of cryptography and it kind of seemed like the game was over you know that the war was one that we'd really done it but if you go back and you look at the cyberpunk predictions of what would happen once we'd won this war it's somewhat less clear you know first of all the first prediction was that they would win and I think that this that was the most prescient thing this is one of the first times that we saw that information really does want to be free but there are other predictions of what would happen were somewhat less prescient they thought that anonymous digital cash would flourish that intellectual property would disappear that surveillance would become impossible the governments would be unable to continue collecting taxes and that governments would fall flash forward 20 years and if we're honest with ourselves cryptography is the thing that allows us to securely transmit our credit card number to amazon.com so we can buy a copy of Sarah Palin's book on going rogue and as we now know holy [ __ ] they are surveilling everything in fact surveillance is probably at an all-time high and privacy is probably at an all-time low so what happened you know you know there's all this cypherpunk activity we won this war shouldn't are like emails texts phone calls messages shouldn't that all be encrypted nope none of it okay so what were these people doing in Sealand and Anguilla and stuff you know didn't like there's this whole movement like what did we get we got this PGP has anybody here ever tried to use this PGP okay well not very many people well you're not missing much do people at least know what this is PGP yeah okay so one way to explain this is that in many ways the cypherpunks were preparing for a future right and the future that they saw was a future of proximate surveillance it was the future of the Clipper Chip right remember that they were going to embed this piece of surveillance technology into every piece of consumer electronics and the people that were you know writing this crypto code had just coming come from like seeing the matrix in the theater right and so that's the feature that they imagined and instead we got this feature of a bleak surveillance which is subtly different you know to give you an example you know if I asked how many people here would be ok with a law they required them to carry a government mandated tracking device on them at all times probably not many people would opt into that but then if I asked how many people here have a cell phone I imagine almost everyone in the room would raise their hand and so what's the difference you know a cell phone is just a thing that reports your real-time location to a handful of telecommunication companies which are required by law to provide that information to the government you know so what's the difference between a government mandated tracking device and a cell phone well the difference is choice right like you choose to have a cell phone you wouldn't necessarily choose to have a government mandated tracking device but it's a complicated choice because you know what starts off as a choice between whether you have a piece of consumer electronics in your pocket or not slowly becomes a choice between whether you participate in society or not that in some sense today the choice not to have a mobile phone is a choice not to participate in society and that's something that the cypherpunks didn't really see coming so you know back in 97 at the dawn of the Internet's potential the hypothesis for private communication was simple we'll just develop really powerful tools for ourselves and then teach everyone to be like us and PGP is the result of that origin story you know we got software that looks like this you know should the underlying block cipher that you use when you communicate with somebody be serpent idea to fish or AES that's up to the user the GP g-man page is 16,000 words long for comparison the novel Fahrenheit 451 is only 40,000 words long and so this leads to like all kinds of usability to disasters you know people say things like I send you my private key to communicate privately right which is not how it works by the way but so if you know we sort of break this down the way that PGP works you know you got someone Alice and she wants to communicate privately and so she has what's known as a key pair a private key and a public key and she may want to communicate with people like Bob Charlie and Dave and so what she does is she sends them her public key Republic he doesn't need to remain secret she could broadcast it widely anyone can know it it's sort of like if you imagine I send you an open unlocked safe that you don't know the combination to and then you put your message in the safe and you close the door and you spin the knob now even you can't unlock the safe and then you just mail me back the safe now at the same time there's someone else that we need to consider Eve the eavesdropper and so whenever Bob Charlie and Dave want to communicate with Alice they just use Alice's public key to encrypt a message and send it to Alice now Eve is going to be there Eve is always there and you know Eve can observe these messages in transit but since Eve doesn't know Alice's private key she can't decrypt this is just ciphertext right so the thing is that every single time Bob Charlie Dave and anyone else sends Alice a message they use the same key over and over and over again for years at a time and Alan or I'm sorry Eve can just store this ciphertext for years at a time you know collects years of traffic and maybe she can't decrypt it she just stores it and then maybe if one day she's ever interested in Alice she goes to Alice and somehow compromises Alice's private key either she physically seizes the device that it's on and extracts it or she coerces Alice somehow or compels her through legal action or something like that but at the moment that that happens now Eve can go backwards in time and decrypt every single message that has ever been sent to Alice over years right so PGP has some problems right like it lacks this so that phenomenon is what's known as future secrecy so it lacks this thing forward I'm sorry it's known as forward secrecy lock this phenomenon known as forward secrecy it also lacks deniability so if I send you a PGP signed message you know that it came from me cryptographically but there's no way for me to deny it if you show it to anybody else you know what you want is for me to send you a message and you know it came from me but you can't prove to other people that it came from me and then you know complicated setup in usage basically what we're saying is that PGP is like a Museum of bad 1990s cryptography and an interface that was designed in the same era as Lotus Notes you know nobody uses Lotus Notes anymore I don't understand why we would expect people to use PGP yeah this may seem obvious but like people in the security community like myself are so brain damaged that it takes us a while to figure that out so what do we need well what we need is something that has limited damage from key compromised you know to to deal with that Alice scenario we need something with opinionated defaults you know we shouldn't have a man page that's 16,000 words long we need something that has opportunistic transparent encryption and is mobile oriented works in multi device setups and is generally like suited for the modern world basically what we need is to make the lock icon a thing of the past as they say one-click encryption is one-click to many so what we did was we thought about it and we worked for four years on a new cryptographic protocol called axolotl and axolotl is asynchronous which means it works on mobile devices it supports multi device it has both forward and future secrecy and it has this deniability property and the way it works is through what we call a ratcheting forward secrecy protocol and essentially what's happening is that as you're communicating with somebody the key material that you use to communicate is ratcheting forward which means it moves forward and cannot move backwards and the old key material is destroyed as soon as it's used so somebody records a whole bunch of ciphertext for years at a time and then they come and seize your device there are no keys on the device that can be used to go back and decrypt those old messages which is exactly what we want we also worked on the the key distribution flow so instead of like copying and pasting stuff around the way it works is you have a device and it communicates with a server that is you know mediating your messaging and when you want to send a message you first contact the server and you ask for the next cache key for the recipient of the message the server responds with what's known as identity key and the next key that's available and then your phone generates a new ephemeral key and uses that to encrypt a message send it to the server and the server responds that is received the message and then fords it onto the recipient so this all happens behind the scenes in a normal messaging flow and it only adds one trip to the server the first time that you communicate with a specific recipient in cryptography there's always this question of how you deal with key validation so if you see a public key for somebody how do you know that it's really their public key and not you know Mallory's public key or Eve's public key and so we use a model called tofu which is trust on first used so the first time you see a key for somebody you just assume that that's the good key for them this is similar to how SSH does things and if that key ever changes then we notify the user and prompt them and until they they approve it because of that simplification a user doesn't need to know what a key is and a user doesn't need to know to fingerprint is if they don't want to and if we're honest most people don't want to so what do we get for all this well what we get is a messenger that looks like this so we took the protocol and we built a whole messenger around it and this is the android client it's called tech secure and the idea is that it looks just like any other messenger there's nothing special about it you don't have to know what if how cryptography works you don't have to you know do key exchanges and ASCII armor or there's no command-line options it's just a normal messenger and you know given that we had that we were able to demonstrate that this technology really worked in a frictionless way in a way that could be truly invisible and since what we do is open source and we don't have any patents or intellectual property on our protocol or any of the software that we write we were able to take this and give it to what's at which is the most popular messaging up in the world they're larger than SMS and we have started an integration with them where we're integrating our protocol into the into their clients so that if you communicate if you use whatsapp and you communicate with any whatsapp user when the integration is done your communication will all be int and encrypted and not even know it already where we are in the in the integration we believe that this is the largest deployment of India and encryption in history and we think that this is the kind of mass adoption that can actually put a cramp in the style of mass surveillance in general what we found is that if you code you design and if you design usability matters and if your software isn't usable nobody's going to use it but that usable crypto can stop mass surveillance this is the kind of thing that we're going to continue working on an open whisper systems we're not done we want to do more integrations and keep pushing this until all communication is end unencrypted it's an open source project and so we invite everyone to join us and we hope we see their thanks [Applause]
Up Next

Python for Data Analysis: Numpy, Pandas & Visualization
@freecodecamp
3.2M views•2021-02-18

BitTorrent Protocol Explained: Piece Selection & Peer Choking
@StevenGordonAU
481 views•2013-02-22

HTTP Requests Explained: GET, POST, PUT, DELETE
@codecademy
103.1K views•2021-10-07

Enigma Machine Mechanics: WWII Encryption Explained
@JaredOwen
13.2M views•2021-12-11
Related Study Plans & Knowledge Roadmaps
Structured learning paths in Computer Science












































