Getting the transcript
Reading the captions from YouTube. A video nobody has opened here before takes 10 to 30 seconds; this page fills in on its own.
Getting the transcript
Reading the captions from YouTube. A video nobody has opened here before takes 10 to 30 seconds; this page fills in on its own.

New America · @NewamericaOrgideas
Words
6,277
Runtime
35:15
Speaking pace
178wpm
Reading time
26min
178 words per minute, just under the 181 median of 349 measured videos. That distribution comes from the 349-video hook study.
Opening (first 30 seconds)
good afternoon I'm Alan Davidson the director of the open technology Institute here at new America and uh delighted to have you all here with us uh this afternoon on our launch of our new uh cyber security initiative and I'm delighted to be here with our guest technologist keyter uh Bruce schneer is somebody who uh really needs uh very little introduction for uh at least for some of the communities who are uh part of this conversation and um he's the author of about uh I think
89 words, the words spoken in the first 30 seconds at 178 words per minute.
Free, no signup. See how the first 30 seconds hold attention, with rewrites.
Sentence shape
| Measure | This transcript |
|---|---|
| Sentences | 1 |
| Average words per sentence | 6277.0 |
| Longest sentence | 6,277 words |
| Questions asked | 0 |
| Sentences containing a number | 1 |
Most used terms
Filler phrases
217 in total: uh 75 · you know 44 · like 25 · um 21 · I mean 19 · sort of 13 · actually 11 · kind of 7 · basically 2.
A literal whole-word count of the same phrase list the Prepublish browser extension uses, so a phrase inside another word is not counted and a phrase used in its ordinary sense still is. It is a count and not a judgement.
Run the check on the words above: where attention is likely to drop, with a rewrite for each weak line. The free check shows the scores and the one issue costing the most.
What this transcript is
Every word below is the caption track YouTube publishes for this video, pulled from the video itself and reproduced unchanged. It is not Prepublish's writing, not a summary, and not a re-transcription: it is the video's own published captions. English captions, generated automatically by YouTube, in the video’s original language. Source: the video on YouTube. A channel that would rather this page did not exist can ask for its removal through the contact page, and it is removed.
No Script X-ray for this video: YouTube shows a Most replayed graph only once a video has enough views.
good afternoon I'm Alan Davidson the director of the open technology Institute here at new America and uh delighted to have you all here with us uh this afternoon on our launch of our new uh cyber security initiative and I'm delighted to be here with our guest technologist keyter uh Bruce schneer is somebody who uh really needs uh very little introduction for uh at least for some of the communities who are uh part of this conversation and um he's the author of about uh I think actually 12 books now uh about uh Plus m is including the forthcoming data in Goliath the hidden battles to capture your data and control your world uh coming out next week next week um and uh he's a uh a renowned computer security researcher I first met Bruce in the uh late 90s when I was a cub attorney uh in the uh crypto Wars of the late 90s I guess we have to call crypto Wars now uh um and uh and even then he was it was very clear that Bruce had a very unusual Talent which was explaining really difficult technical Concepts to a Washington audience uh and since then hello Washington audience he has distinguished himself in this way so we'll get to test him a little uh today as well um well to start off Bruce I was going to say um there's this terrific quote by uh Robert cringley um and it uh about sort of technological development and he says if the automobile had followed the same development cycle as the computer a Rolls-Royce today would cost $100 get a million miles per gallon and explode once a year killing everybody inside uh it feels like we're in that exploding uh car part of the story now or at least some people would say that uh you know with u you know this steady drum beat now of um of of attacks on major retailers who have Target Home Depot attacks on uh the devices that we all carry around with us the celebrity hack attacks where people's most personal photos and information leaked to the world uh the Sony attack uh more and more it feels like the that uh our ability to build great technology has outpaced our ability to keep ourselves safe when using that technology as somebody who's been working in this space for a while uh do you feel like this is something something has changed have we reached a sea change is there a meltdown happening is the car exploding I mean I don't think anything has changed but that quote might be a decade and a half old so that that it shows you how long we've been paying attention to this if anything's changed it's it's the way the presses have been reporting this and the number of of of us who are using it if if the something the magnitude of of the I don't know Home Depot hack happened decade and a half ago it wouldn't be a whole lot of credit card numbers because it wouldn't be the same network and I think in in all aspects of society our our our ability to do something out strips our ability to deal with the consequences we tend to like to rush forward with things and fix the problems later and that that's what we do pretty much all through the history of our species and that works better when you're dealing with systems of smaller scale and the problem here is now our systems are getting so big so inclusive so complicated that this car exploding once a year killing everybody is equaling all the cars exploding once a year killing everybody which is much worse so I don't see a change I I really think this is a natural progression of what's been happening if in the extent people do see a change think it's because it's being reported differently now and the the way the popular culture is looking at it way the Press are looking at it has changed so you know for a lot of people they're going to say well that's not a super tolerable uh you know world to live in you know that's well then you you sort of pick your stuff right okay well so I guess one question a natural question becomes why is this so hard why can't we why can't we protect people online why is it so difficult I mean the the internet's the most complex machine mankind has ever built I that that's the basic answer complexity is the worst enemy of security securing complex systems is hard it just is and as scientists we actually don't know how to build secure computer systems let alone a computer system attached an internet run by a user which makes it infinitely worse these are actually hard problems and in our rush to connect everything to the net we've kind of ignored those hard problems right and that was great when the most important thing you did on the net was discuss Star Trek it got a lot worse when you started doing Banking and then critical infrastructure so this actually isn't an easy problem I mean even the something that Adam Rogers sitting in this very chair said in the answer to my question that that then you know surely we can come up with some legal framework to make this work right what I said to him is that it's not the legal framework that's hard it's the technical framework these are extremely hard technical problems I don't know how to build a secure system so I can't make your system secure the best I can do is make them okay and then try to build enough buffer around it so things fail gracefully so you have some sort of resilience and then we muddle along now yeah you're right as technology gets more powerful intrusive this gets increasingly intolerable your alternative is something like the FDA where it takes millions of dollars and multiple years to approve a new drug now we could do the same thing for a new version of Windows but we as Society have decided we don't want to stifle Innovation that much we don't want a world where only a a very big very powerful very well-funded company can design software because of the regulatory regime so we're making these decisions so you're you're you're you're kind of positing this world where okay we've chosen to have openness we've CH chosen to have a an innovation friendly approach to this problem what are some of the things we could do to mitigate them the harms because right I think a lot of people do look at this and say well uh it's not it's this is like you I said it's not a great to live in if you can't trust your cell phone if you can't trust uh if your company can't trust its infrastructure um are there things we can do to make it better and there are there are certainly success stories I mean credit card Ford is a great success story if you've been following it in the early years of Internet fraud customers were on the hook for for the money the the credit companies would refuse to believe that and hacks and you'd have lots of individual liability we've now move to a world if you have a credit card that you don't really worry about internet fraud if it happens it's caught automatically you're given a new card we don't make the fraud go away it's still extraordinarily expensive and you know we're in a sense paying for it through through fees but the whole security happens in the background and we have some resilience so we don't make the fraud go away but we make the aftermath of it tolerable and you can imagine the same sort of things being done in other regimes now this is harder than others some I'm sorry some areas is harder than others right Sony was an example of an extraordinarily Massive Attack uh you you could easily argue they could not have defended against it and I think that's true but they could have responded a lot better than they did there other times where maybe we need more protective defense so it's going to be it's going to be a Patrick depending on what what's your advice to the average consumer out there agitate for political change this is a hard one I'm always I'm always asked a lot how can I protect myself on the internet and the problem problem we have is that we are not technically Savvy enough to do a lot of that so we rely on others so most of us store our email on Google right Gmail we use we use Gmail or somebody else now I can't call up Google and say I would like you to add these four security measures to improve my email security they would say no thank you click right so we don't have the ability to secure a lot of our stuff right if you had your credit card number at Target and it was stolen there was nothing you did that was wrong target did something wrong so in this world we were increasingly entrusting our data to third parties my cell phone company knows I'm in this room why because my cell phone is on it's on mute but it and it needs needs that to deliver phone calls that's incredibly invasive it's it's Mass surveillance but that's how the cell phone system works and we are increasingly giving this surveillance information to companies for good reasons people like Admiral Rogers are perfectly happy to get themselves a copy which he does and Under lots of different authorities and and and different programs you solving that is not easy and it's there are Technical Solutions but there tend to be around the edges right any any solution I give you that involves leaving your cell phone off and at home you're actually not going to do because that's a dumb solution it's like not having a Facebook account right you can not have one but you're kind of a freak so I I think Adam Rogers was right even though I just I'm sure we disagree on all the details that we need legal framework that if we're going to protect our data protect our privacy we need some some rules because we're not going to protect it by not sharing our data that's just not a viable option so even if you had the so yes and certainly that's the where the open technology institute's been coming from too but even if you had that framework even if you know we we all voted with our feet and our votes and we and we got a framework that that we felt adequately protect you know put the right kinds of rules in place for the NSA dealt with encryption we could talk about those issues you would still be in this world where okay so there's better rules for government access but what do we do we still have the bad guys out there uh or different a different set of bad guys folks who are not obeying the rule of law well and this is where I think the feedback can work in our favor that if indeed we had organizations like the NSA refocused on keeping us secure and keeping our data private I think we would get a lot of of mileage from their knowledge and research and so you would say there actually is a role for the N there definitely is I mean and and they wear two hats attack and defense I mean we normally hear about the attack hat but there is a there is a defense hat too and actually just talked about a little bit when he talked about some of the things he might do to protect against critical infrastructure the and so it's a good way to say it we're all living in one world I mean what what what what the traditional NSA jobs were attack their stuff and defend our stuff that worked really great during the Cold War where you can attack a Russian communication system or a Russian radio and defend a US military radio that kind of failed with the Advent of the internet because there's no such thing anymore as our stuff and their stuff we're all using the same stuff we all use Microsoft Windows and tcip tcpip and Cisco routers and in order to defend our stuff you necessarily have to defend their stuff and in order to attack their stuff you necessarily have to leave our stuff vulnerable that you have to choose between security and surveillance now largely we seem to have chosen surveillance and again and again we see secret NSA hacking tools being used against us so example might be in in the first few months of the Snowden documents one of the stories I wrote based on them was about uh an NSA program called Quantum this was actually the thing when the Guardians was negotiating with the with the US government that the NSA most desperately didn't want us to talk about this is a secret program of packet injection which is an attack technique and the NSA uses it to great effect but it's not an NSA Secret the Chinese government uses it there are companies that sell the capability to Third World governments around the world there are hacking tools that do it right we are all vulnerable to this attack so all the NSA can use it to attack legitimate us enemies by leaving that hole open we are all vulnerable what I would like is if we collectively decided that our security is more important than that surveillance technique and now we can use the expertise inside the NSA inside Academia the the force of law to make some of these changes work to try to secure all of us against this technique and others I can go on and on for list of techniques that were once NSA secrets and and are are now commonly used the story from last week that the NSA has great hacking techniques that drop malware into your hard drives not where you think it is in sort of the boot sector very complicated but basically they have and this is pretty impressive they have a technique to attack computers that even if you reinstall the operating system your computer will remain attacked right that's kind of neat I mean as a taxpayer go team right but right but but after this was released I started doing some some research and there are a few papers in the academic literature on the same technique so what is this secret NSA technique is actually a preview of the criminals are going to do three years from now and that's a way to think of all of these techniques all right so we got three years let's work on a solution and the NSA has two choices here they can keep using this technique as long as they can in hoping that we never figure out how to defend against it or they can help us defend against it because it's coming at us really fast now Admiral Rogers would say you know that there's there and did say that there is Great Value that's come out of these programs out of these techniques I think you said there's value we look at the Great Value we'll go back and look at the transp okay there's value though but this and this is the question there's value from lots of things that we as society decide not to do for all sorts of reasons but we have to decide we either get the value and pay the cost the cost is our vulnerability or we don't get the value and we get the benefit of being secure these are your choices you don't get secure ours and listen to theirs that's what you're not allowed to get that's what that's what having an interoperable internet across the planet denies you if we say only the US gets use the internet then sure ours is different and you can now make these trade-offs one world one technology one decision so in the meantime we still have this world we live in now where there are these attacks High high-profile tax where we do have a somewhat vulnerable uh set of tools that we use out there how you know you you said a little while ago part of the response has to be you know to recognize that and be resilient against it how does the average consumer do that I mean what how do we talk to the average consumer average consumer doesn't right this is what I said the average consumer is putting their their pictures on on Facebook is putting their email on on Gmail and the average consumer really can't make the decision and is blindly trusting the service providers and uh that's the way it has to be and that's okay I'm not saying this is bad you know my mother has a much better Computing experience now that most of her stuff is in the cloud my father still can't use a computer but that's another story that that we we want to push that technical expertise onto somebody else because we are not doing it ourselves and that's where we we're we're blindly trusting and all of these companies of course want you to be secure against everyone except them right Google spends a lot of money now making sure your data is secure on Google's platform from everyone except Google whose job it is to spy on you and make money off that you understand that and all companies are basically like this and this is going to be a problem um I want to make sure we have time to turn to the audience uh one other question sort of a kind of broader questions about how we have this kind of conversation in Washington and what you're talking about is a fairly subtle conversation about trade-offs about the kinds of different things uh that we might accept expect from our technologist from our national security establishment you know how do we get more people involved in this debate how do you have this debate how do we find more Bruce schne how do we clone Bruce how do we find more people who can be translators between the technical world and the uh and the policy world I thought that was your job I thought that was your job damn it okay so so right so this is the problem and I think it's the problem for for a lot of technological issues on the hill that that that subtle discussions of policy are are not uh are hard to have ad Rogers said we need a legal framework I mean I had you know at least 20 minutes of rebuttal to that which which will that conversation really can't happen because it's very simple we need a legal framework where the devils in the details and I've been trying for what a couple of decades how long have we been doing this to to try to have these conversations on the hill we have more or less success I think some of it's generational you know as the generation born to the internet will understand these issues a lot more than the generation who got stuff you know got forced the interet forced on them at age 40 you know and so there's a generation gap here and and I think the nice thing about generation gaps is that the younger generation always wins right because the older generation dies you get that you can't win a generation gap and I think that's good I think the younger generation has an intuitive feel for how the internet works what its values are what its risks are in a way that the current people in power don't so I think some of this will just shake itself out doesn't help us you know fighting the second crypto War right now but I I tend to be I tend to be short-term pessimistic and long-term optimistic questions from the audience let's see we've got Mike's over here and how about uh one how about one up here start up front so back here oh sure we'll go back there since you're there and then we'll come up here well a great presentation um I'm out at the Naval Academy cyber Center where we focus on making every mid shipment about a thousand per year at least conversent on these subjects and I would like to push back on something you said about the issue being technology um if technology diffuses like it always does everyone eventually gets automobiles everyone gets aircraft everyone gets nuclear uh least many countries get nuclear power um that if the crypto diffuses if the machines diffuse then won't power come down to the human factor which Workforce is the most Savvy about cyber security which country's populace is most Savvy and then third and perhaps most dramatic is which population Workforce can function in a degraded internet so I like your comments on that that it really is a human factor in the end analysis so I think that that's perceptive there's a lot of human factor here that you know we've been saying for a couple of decades that that people are the most insecure part of any security system and I think that that's still true you know the Sony was attacked through through a fishing attack so it was an email sent to a person and that that's how the uh attackers got in you know there definitely is a Terrain in cyberspace when you think about that actual cyber War you know if we were to engage in cyber war against North Korea but they have like 12 computers and you know it's really they have a very inherent defense because they're not reliant on cyberspace at all whereas we are very Reliant and so that's that's a very human factor you know the different savviness of populations in a lot of these attacks your security doesn't depend on your average it depends on your weakest so you know for example the fishing attack against Sony it wouldn't matter if how good the average person was recognizing that as an attack and not clicking on the attachment because it only takes one to infect the network so when you have a system where you're reliant on the security of of the weakest then training the a getting the average better doesn't help right if something like uh oh I don't know retail fraud against credit cards will you have a more average then yes you're going to see a a a more Savvy population being more resilient against that sort of attack so I agree that human factors matter a whole lot here here but it has to be tempered with technology I tend to think that solutions that require educating the users they doomed to fail because you know I've met actual users and I'm not too optimistic here you know I'd rather have solutions that work regardless of the user and if you look at where we've gotten security right we have gotten safety right mean something like an automobile we tend to not rely we we rely as little as possible possible on the user you know we try to build safety systems that work even if the user is is somehow not acting in his best interest and I'd like to see more of that in cyberspace and in that way a lot of the cloud works that way yeah question up here hi um I wanted to go into the legal framework just a little bit um I was reading a a Global Network initiative report on Mutual legal assistance treaties that just came out at the end of January and one of the points that was sort of made over and over again is because of this um what's ours as theirs and theirs as ours sort of effect of the internet uh that there are opportunities for um using these mlas as ways of sort of getting other governments to do things the way that you want them to do and I wonder is that naive you know to think that you could hold a country to an international human rights standards you know by saying if you do that will we will honor this MLA or or or not I I think that actually is a Savvy way of looking at things and you could see that in other areas you could see that in things like child labor or bribery or money laundering there are lots of examples of sort of international treaties where countries are really named and shamed for not adhering to an international norm and we've made great strides in reducing whatever the bad thing is through that so I think there is value there how to do it I mean I mean hopefully there people in Washington know way more about this than than than I do but I do think that is a way to deal with some of these Internationals especially when it comes to cyber crime that we are we now living in a world where some countries are safe havens for cyber crime and and that's difficult and bad and and not good especially because you don't have the same geography uh that that will give you a defense you know the fact that I don't know subsaharan Africa is is very far away from the United States is not a defense in cyberspace where it's a great defense in the real world other questions anything uh how about one right here in the middle anything from the Twitter Twitter sphere go we'll go to the Twitter sphere next but how about right here in the middle someone sent me the Twitter sphere posted a picture of Admiral Rogers face when I asked him my question which was completely awesome this is why we love the internet hi Bruce thank you um I'm going to ask you a question as a security engineer um Helen nissau makes this philosophical differ differentiation between technical or information security practice which is where the objective is to um mitigate vulnerabilities that might harm people so if a car hit is hit or hit somebody you look to see how you can improve the car and the roads and maybe traffic rules and cyber security she says it's driven by National Security interests in which an attack on the networks are presented Ed as urgent imminent and existential threat to a signif significant collection namely to the national population um this is Then followed by justifying bending Democratic rules and stepping out of political procedures so the question is what do we do with attacks do we see how we can improve the system so that they don't happen again or do we turn them into a national security problem in which case we justify putting um a a bug on all the cars in the world and profiling all the the drivers hoping that that will maybe mitigate the crashes so I think this is I think so my question to you is is there any security engineering that is left that will be outside of the National Security project that you have outlined so can we do security without necessarily seeing it as an attack on Nations and can we think about whether Americans should decide on all of the global internet infrastructure and how it should be governed thank you so I think most security happens outside that that that National defense framework you know I think of all the security research all the security products they they tend to work under a crime metaphor and a hacking metaphor not a national security metaphor so every one of you works at a company that's bought a whole bunch of stuff has network security in your network the things you have at home these are consumer items these are business items a and they're defending against hacking they're defending against uh cyber criminals they're defending against against you know Anonymous that's the Paradigm the National Security Paradigm is relatively new it's it's it's not a decade old I mean it doesn't even happen right after 911 and it is you know taking over and I think that's bad but primarily most of the good stuff doesn't come out of the National Security establishment it's not stuff that rathon is building or or the NSA is funding it's it's you know it's it's companies that exhibit at the RSA conference that are just trying to sell security us companies foreign companies I mean I think the important uh point you made and the really hard one is it's sort of the first half of your your question when it's whose job it is who what framework are we operating in and let's take the Sony case Sony case is a really interesting example because here it is November 24th and Sony gets massively hacked and it could be either a couple of guys or the Govern of North Korea now pause for a moment and postulate a world where you don't know whether it's a couple of guys or the government North Korea that's really freaky and the legal framework of Defense depends on which one it is so whose job is it to defend Sony well if it's the government of North Korea we can have a conversation should it be the military should it be somebody El I mean who should do it if it's a couple of guys we can have this conversation as well it's took the administration 3 weeks to point a finger at North Korea nobody believed them at the point but it took them three weeks and it was extraordinary for them to do that and it was and it was a big deal to do that okay whose job is to defend Sony before we know whose job is it to defend Sony but the real question is you're being attacked you have to defend you've got oh I don't know 10 milliseconds to figure it out what legal and social norms operate before you know who's attacking you right in the real world you would tell your attacker by the Weaponry if we walked outside and we saw a tank we would know the military was involved because only militaries can afford tanks that is an easy right that that's an easy nemonic and that fails in cyberspace because everyone's using the same stuff so we have to decide what rules operate this is actually not easy this is a very hard question know do we assume and Admiral log would like this to assume that it is a military threat until proven otherwise or do we assume it is a criminal threat until proven otherwise or we do have some this this new interstitial mode where we don't know and some rules in the middle work we have absolutely no idea how to do this sort of policy and if you read uh uh David sanger's great piece on the Sony attack in the New York Times I think it was late January he spent a lot of time talking about how hard it was for the administration not just to figure out who did it but to figure out how to respond whether to announce it it was extraordinary it this this is really hard and the administration had two issues one I mean there are different ways to attribute attacks right attributing is hard knowing who did it is hard and we know that the NSA had some secret evidence you know they probably had Taps into the government they that that was able to uh blame it on Sony but they couldn't reveal that evidence because that would compromise sources and methods and ongoing intellig operations against North Korea which we probably all agree is a good thing for us to have so one can the US government convince itself who did it can two can it go to the attacker and say we know you did it can it go to everyone else and say we know they did it those are three different things increasingly hard so here we are at number three being expected to approve retaliatory action as a country when we cannot be shown evidence that it's right and we're at a low period of trust here we're going off uh the Iraqi weapons of mass destruction thing when and we're we're not really trusting secret evidence this is going to happen again and again these are extremely hard policy question questions and I don't have answers here I'm not like going to tell you what to do we have to figure this out well I time it's okay you want to do one really quick one and then yes or no question one really quick question yes or no question but go ahead from from the from the from the from the internet from the internet well most of the internet is really enjoying quoting Bruce and posting pictures and some of them have referred to uh Star Wars as the new American Cy new America cyber and the future of you know things but the main question that keeps coming up is what you think of the news last week about the firmware hacks and what do you think that means for broader internet architecture yes yes we can we can take another minute for that so so right so very quickly uh and I wrote a piece on this it's it's on my blog from last week uh this is uh this is subtle I mean on the one hand we're seeing very sophisticated targeted attacks against legitimate targets and again go team this is the NSA I I want to pay for right that's going to uh penetrate the networks of of people we don't like and even jop on the traffic uh on the other hand uh the NSA tends to have very broad uh conception of of who to attack including things like the Belgian phone company and stealing uh every single SIM card encryption key that a a Dutch company made and uh I don't know the uh Merkel and the uh the oil company in in Brazil random systemin around the world so that maybe the problem is that this definition of who we should attack is too broad on the third hand again these are techniques that are going to make their way into uh academic papers into criminal toolkits not because of of the uh intercept article but because research continues and and we might be a little behind the NSA we're not nearly as well funded but we're not dumb and when where we you know we we trade along so again we have to decide now that uh you know do we want the NSA to keep using these techniques for attack or or the better ones that have been invented since right you know you know since then or do we want uh the research turn to defense and this these are policies we have to make I I I'm in favor of Defense I think that the number of good guys outnumber the bad guys in society by enormous amount and that in society all Technologies can be used for good or bad good uses are better and that the the price of freedom is the possibility of crime and we accept that because the goodness is so good and do you do you worry even as we asked you think that there's this role for defense that the the trust deficit has become too great I mean when you see major governments involved in these kinds of things like undermining encryption standards or stealing SIM cards uh SIM card data do do you will anybody trust the defense approach if we're living in a low trust era of of our society presumably that's going to be fixed that'll get better you know with time yes that is a huge problem and I do worry about that okay that's what I asked Rogers how do we trust you and and he talked about legal framework and he already has legal framework I'm not sure how that helps well what's your advice for him how does he get trusted I I think uh I think more transparency I think we have to accept that we're living in a more transparent world and that's the way it goes I mean either you do it yourself or Snowden does it to you on that note uh please join me in thanking Bruce [Applause] [Music] schne
The words are the caption track's own and nothing is reworded or re-transcribed. Paragraph breaks are placed between sentences so the text reads as prose.
Free tools for your own script: paste a draft and see where it stands before you record it.
Paste your draft and see where viewers are likely to drop off, with a rewrite for each weak line.
Paste the first 30 seconds of your own draft for a hook score and rewrites.
Check your draft against YouTube's advertiser-friendly guidelines before you record it.
Read this channel's public videos and transcripts, and download a writing brief for it.