
1
00:00:00,300 --> 00:00:04,785
So, welcome to our lecture on Pubic Key 
Encryption where we're going to go back 

2
00:00:04,785 --> 00:00:09,040
to confidentiality. 
And so, so here we go. 

3
00:00:09,040 --> 00:00:12,253
If, if you recall we've been having these 
two topics that have been our theme 

4
00:00:12,253 --> 00:00:15,445
throughout. 
just some[INAUDIBLE] . 

5
00:00:16,980 --> 00:00:19,940
Oh sorry, I'm starting to, talk in route 
13. 

6
00:00:19,940 --> 00:00:23,880
Let's translate this back to non route 
13. 

7
00:00:23,880 --> 00:00:27,430
the terminology, the two kind of themes 
we've been following over the last couple 

8
00:00:27,430 --> 00:00:31,390
of lectures and this lecture, are 
confidentiality and integrity. 

9
00:00:31,390 --> 00:00:34,728
And confidentiality is hiding, right, 
shielding information. 

10
00:00:34,728 --> 00:00:38,424
Not leaking information to people that 
you don't want to show it to. 

11
00:00:38,424 --> 00:00:42,120
And integrity is making sure that you 
know who you're dealing with. 

12
00:00:42,120 --> 00:00:45,540
And then the previous lecture, we really 
talked about kind of real light 

13
00:00:45,540 --> 00:00:49,017
approachable ways of ensuring 
confidentiality with things like Caesar 

14
00:00:49,017 --> 00:00:53,210
cipher. 
And then integrity using a simple message 

15
00:00:53,210 --> 00:00:58,195
digest, that, based on a shared secret. 
So, the problem with all of those things 

16
00:00:58,195 --> 00:01:02,300
that we just saw, is that they require a 
shared secret. 

17
00:01:02,300 --> 00:01:06,510
And the problem in the world of the 
internet is, it's just really difficult. 

18
00:01:06,510 --> 00:01:12,270
For every one of us before we establish 
well, before we can make any purchases or 

19
00:01:12,270 --> 00:01:19,660
whatever at Amazon, that we somehow have 
to drive to Amazon headquarters. 

20
00:01:19,660 --> 00:01:24,448
And, and get a shared secret from Amazon. 
Open up a book and say okay, hi Chuck, I 

21
00:01:24,448 --> 00:01:28,800
see who you are and here's our shared 
secret, and you walk away. 

22
00:01:28,800 --> 00:01:31,980
And as long as you carry that shared 
secret while you go. 

23
00:01:31,980 --> 00:01:36,090
And if the shared secret is lost, it's 
difficult to review, revoke. 

24
00:01:36,090 --> 00:01:41,127
So, as the internet and, and frankly in 
general, as security needed to be able to 

25
00:01:41,127 --> 00:01:45,282
work at arms length. 
Meaning that you couldn't always bring 

26
00:01:45,282 --> 00:01:47,705
everybody together and hand out shared 
secrets. 

27
00:01:47,705 --> 00:01:51,190
And then have them go to the far reaches 
of the world and communicate. 

28
00:01:51,190 --> 00:01:56,650
public key encryption was identified, as 
an extremely elegant solution to this 

29
00:01:56,650 --> 00:02:00,651
problem. 
And so it was proposed by Diffie and 

30
00:02:00,651 --> 00:02:05,320
Hellman in 1976. 
And it relies on two keys. 

31
00:02:05,320 --> 00:02:08,670
It's asymmetric, meaning we're not using 
the same key to encrypt as decrypt, the 

32
00:02:08,670 --> 00:02:12,370
way we were in the previous lectures. 
These are asymmetric. 

33
00:02:12,370 --> 00:02:16,096
There is a public key, which is actually, 
does not need any protection whatsoever, 

34
00:02:16,096 --> 00:02:20,008
and a private key. 
And the idea is they're generated inside 

35
00:02:20,008 --> 00:02:22,073
of a computer. 
You generate the public key and the 

36
00:02:22,073 --> 00:02:24,754
private key. 
You send out the public key, the public 

37
00:02:24,754 --> 00:02:28,150
is used to do the encryption. 
And then private key is used to do the 

38
00:02:28,150 --> 00:02:31,320
decryption. 
And they're related mathematically, in a 

39
00:02:31,320 --> 00:02:35,322
way that's well understood, but difficult 
to compute for a key length that's large 

40
00:02:35,322 --> 00:02:38,706
enough. 
So, there's a public key and a private 

41
00:02:38,706 --> 00:02:41,114
key. 
So, I'd like you to take a look at this 

42
00:02:41,114 --> 00:02:44,990
little video up on YouTube of Diffie, 
Hellman, and Merkle, the, the inventors 

43
00:02:44,990 --> 00:02:50,040
of this. 
and I think it's a great video. 

44
00:02:50,040 --> 00:02:54,380
I would love it if this were my video, 
but I didn't produce this video. 

45
00:02:54,380 --> 00:03:03,430
So so take a quick look. 
So, one of the things about this public 

46
00:03:03,430 --> 00:03:07,005
private key encryption is now that we 
know about it, it's like wow, it's pretty 

47
00:03:07,005 --> 00:03:10,328
obvious. 
And frankly Caesar and the Germans and 

48
00:03:10,328 --> 00:03:14,260
everybody could have used this idea. 
They just hadn't thought of it yet. 

49
00:03:14,260 --> 00:03:17,484
And the other thing that's kind of 
interesting if you look into the story of 

50
00:03:17,484 --> 00:03:21,020
this, is that the first reaction people 
got when they started thinking about this 

51
00:03:21,020 --> 00:03:25,979
is like it can't be this easy. 
Now, it's sort of both easy and hard but, 

52
00:03:25,979 --> 00:03:29,159
but the concept is real elegant and 
really beautiful, and that is that we 

53
00:03:29,159 --> 00:03:33,390
have this public key. 
So, the public key is part of a public 

54
00:03:33,390 --> 00:03:36,750
private pair, and it's used to do the 
encryption. 

55
00:03:36,750 --> 00:03:40,726
The beautiful, beauty is it's computation 
and difficult to recover that private key 

56
00:03:40,726 --> 00:03:43,945
from the public key and the encrypted 
text. 

57
00:03:43,945 --> 00:03:49,156
A key thing is, is it's not impossible. 
And that's kind of one of the interesting 

58
00:03:49,156 --> 00:03:52,439
philosophies of security that, that we 
started at the very beginning in talking 

59
00:03:52,439 --> 00:03:55,920
about security. 
The perfect security is kind of 

60
00:03:55,920 --> 00:04:01,040
impossible to achieve, unless you simply 
don't send anything. 

61
00:04:01,040 --> 00:04:05,396
And so, public private key, asymmetric 
keys is, is well understood as to how you 

62
00:04:05,396 --> 00:04:09,290
would break it. 
Everyone knows how to break it. 

63
00:04:09,290 --> 00:04:12,218
The problem is, is that computers aren't 
fast enough to break it, and when 

64
00:04:12,218 --> 00:04:15,540
computers get faster we'll just make the 
keys bigger. 

65
00:04:15,540 --> 00:04:19,430
So, the mathematics of this makes it 
impractical to break. 

66
00:04:19,430 --> 00:04:24,050
I mean literally impractical to break. 
Now I think we can safely assume that, 

67
00:04:24,050 --> 00:04:27,590
governments probably have enough 
computation to crack these once in a 

68
00:04:27,590 --> 00:04:31,045
great while. 
I mean, they're not cracking every 

69
00:04:31,045 --> 00:04:34,929
transaction between you and target when 
you want to buy something. 

70
00:04:34,929 --> 00:04:38,859
But if they really have to, they can 
record the encrypted transmissions. 

71
00:04:38,859 --> 00:04:42,269
And if they really had to and took a long 
time, I have no idea how long it would 

72
00:04:42,269 --> 00:04:46,375
be, they can break it. 
So, that's actually kind of a neat way to 

73
00:04:46,375 --> 00:04:49,538
think about this. 
By revealing it all, frankly, any 

74
00:04:49,538 --> 00:04:53,686
computer scientist could make a name for 
them their whole life if they proved that 

75
00:04:53,686 --> 00:04:59,112
there was something wrong with this. 
By revealing the algorithm, revealing the 

76
00:04:59,112 --> 00:05:02,596
cracking technique, if someone can come 
up with a better cracking technique, it 

77
00:05:02,596 --> 00:05:07,588
is like, fame and glory forever. 
Which means that, we're pretty sure that 

78
00:05:07,588 --> 00:05:10,864
there's no good way to crack this other 
than the brute force mechanism, that 

79
00:05:10,864 --> 00:05:17,873
requires a large amount of computation. 
So, if you're going to use public private 

80
00:05:17,873 --> 00:05:22,145
key encryption, you have to generate a 
pair. 

81
00:05:22,145 --> 00:05:27,540
And it starts by charging, choosing two 
really large random numbers, with 

82
00:05:27,540 --> 00:05:33,520
hundreds if not thousands of digits that 
are prime. 

83
00:05:33,520 --> 00:05:36,411
See you kind of choose a, choose a random 
number really big. 

84
00:05:36,411 --> 00:05:39,419
And then you kind of look around for a 
nearby prime number and you choose two of 

85
00:05:39,419 --> 00:05:43,330
those. 
And then you multiply them, okay? 

86
00:05:43,330 --> 00:05:47,460
Getting an even larger number. 
And then, through some steps, through 

87
00:05:47,460 --> 00:05:50,760
some calculations, you compute the public 
and the private keys from that large 

88
00:05:50,760 --> 00:05:53,976
number. 
The essence of this, are those two prime 

89
00:05:53,976 --> 00:05:56,426
numbers. 
Prime numbers of course are numbers that 

90
00:05:56,426 --> 00:06:00,360
you only divide by themselves and one 
which means they have no factors. 

91
00:06:00,360 --> 00:06:03,500
Which means they're kind of like looking 
for a needle in a haystack. 

92
00:06:03,500 --> 00:06:07,410
And so the public and private key is 
really based on these two prime numbers. 

93
00:06:07,410 --> 00:06:11,660
If you could figure out what the prime 
numbers were, you'd be okay. 

94
00:06:11,660 --> 00:06:14,300
But the computational difficulty is 
finding the prime numbers that are 

95
00:06:14,300 --> 00:06:19,160
extremely large, and finding the right 
prime numbers that are extremely large. 

96
00:06:19,160 --> 00:06:23,380
So, it's easy to do some calculations in 
one direction, but not in other. 

97
00:06:23,380 --> 00:06:25,250
So, for example, what are the factors of 
55,124,159? 

98
00:06:25,250 --> 00:06:29,799
Quick. 
But if I simply ask you what do you 

99
00:06:29,799 --> 00:06:38,334
multiply 7,919 to get that 55 million 
number. 

100
00:06:38,334 --> 00:06:40,870
That's easy. 
You do a division. 

101
00:06:40,870 --> 00:06:46,596
And it turns out that you can find out 
6961 really easy, right? 

102
00:06:46,596 --> 00:06:51,604
So, if I just say what are these two 
numbers? 

103
00:06:51,604 --> 00:06:54,996
That's hard. 
If I say given this number, what's the 

104
00:06:54,996 --> 00:06:57,700
other number? 
That's trivial. 

105
00:06:57,700 --> 00:07:01,122
So, you can think of this as, the 
decryption is where the receiver of the 

106
00:07:01,122 --> 00:07:04,671
message knows kind of half of the 
calculation. 

107
00:07:04,671 --> 00:07:07,600
Where as the world doesn't know either 
half of it. 

108
00:07:07,600 --> 00:07:10,990
Doesn't know the calculation, so has to 
figure out both halves. 

109
00:07:10,990 --> 00:07:13,790
Whereas the receiver only has to figure 
out one half. 

110
00:07:13,790 --> 00:07:18,212
And so that's how asking the question of 
what are the factors, versus given one, 

111
00:07:18,212 --> 00:07:22,115
what's the other. 
So it, it takes a problem that's easy, 

112
00:07:22,115 --> 00:07:24,966
makes it computationally nearly 
impossible. 

113
00:07:24,966 --> 00:07:27,325
But again, not impossible, just nearly 
impossible. 

114
00:07:27,325 --> 00:07:33,746
Okay, so here's the notion. 
So, you're about to type your visa card 

115
00:07:33,746 --> 00:07:38,520
into a credit card into like Amazon's web 
page. 

116
00:07:38,520 --> 00:07:43,070
And so what happens is, is that Amazon 
will has a public key and a private key. 

117
00:07:43,070 --> 00:07:46,510
That they retain. 
And they will send you the public key 

118
00:07:46,510 --> 00:07:50,035
across a medium, the internet. 
They're going to send this to you 

119
00:07:50,035 --> 00:07:54,264
somehow. 
But the bad guys, Eve, or Charlie or 

120
00:07:54,264 --> 00:07:59,584
whoever they are. 
The bad guys. 

121
00:07:59,584 --> 00:08:04,590
This is Alice and Bob. 
Eve and Charlie are always looking. 

122
00:08:04,590 --> 00:08:07,770
So, Eve and Charlie could intercept it. 
And you assume that they can. 

123
00:08:07,770 --> 00:08:10,780
This is the key. 
Don't, don't try to pretend they can't. 

124
00:08:10,780 --> 00:08:12,560
Even though it's very difficult for them 
to do it. 

125
00:08:12,560 --> 00:08:15,725
But you assume they can. 
So, the public key comes across. 

126
00:08:15,725 --> 00:08:19,885
It is simply sent to you as part of the 
beginning of establishing a sur, secure 

127
00:08:19,885 --> 00:08:26,070
connection. 
And the bad guys see it too, or girls. 

128
00:08:26,070 --> 00:08:28,840
They see it too. 
So, the public key comes to you. 

129
00:08:28,840 --> 00:08:34,080
And then what you do, is you encrypt, 
using that public key. 

130
00:08:34,080 --> 00:08:37,178
And create some encrypted text, cipher 
text. 

131
00:08:37,178 --> 00:08:41,168
Which you then send back across the 
danger, where Eve and Charlie are 

132
00:08:41,168 --> 00:08:44,588
watching. 
And it comes across, they intercept the 

133
00:08:44,588 --> 00:08:47,695
encrypted text. 
They've intercepted the public key. 

134
00:08:47,695 --> 00:08:54,640
And they, they can try as hard as they 
like with supercomputers to derive this. 

135
00:08:54,640 --> 00:08:57,853
And frankly, like I said, if they had 
months and months and months and really 

136
00:08:57,853 --> 00:09:01,975
fast computers, they could. 
Okay, but because Amazon is in sole 

137
00:09:01,975 --> 00:09:06,415
possession of private key and it never 
left Amazon servers. 

138
00:09:06,415 --> 00:09:10,760
It is a very simple matter for Amazon to 
decrypt and get your plain text. 

139
00:09:10,760 --> 00:09:14,510
It happens, very quickly. 
Just like if you kind of know half of the 

140
00:09:14,510 --> 00:09:17,644
prime number calculation. 
Figuring out the other prime number is 

141
00:09:17,644 --> 00:09:21,131
really, really easy. 
Okay, so, so again, these people see all 

142
00:09:21,131 --> 00:09:25,883
of this information, and yet it's 
computationally virtually impossible, for 

143
00:09:25,883 --> 00:09:31,478
all practical purposes, to do it. 
And so it's beautiful, because there was 

144
00:09:31,478 --> 00:09:35,308
no need to protect the public key. 
We never had to get in the same room, and 

145
00:09:35,308 --> 00:09:38,619
away it goes. 
So you just, Amazon just blasts out it's 

146
00:09:38,619 --> 00:09:41,880
public key and we encrypt using Amazon's 
public key. 

147
00:09:41,880 --> 00:09:45,628
We can't decrypt it but we don't need to 
decrypt it. 

148
00:09:45,628 --> 00:09:49,880
All we need to do is send it to Amazon 
and voila, it works. 

149
00:09:49,880 --> 00:09:53,540
So, the beautiful thing is the public 
keys can be distributed, they can be 

150
00:09:53,540 --> 00:10:00,737
intercepted and it does not matter. 
So, with this notion of public private 

151
00:10:00,737 --> 00:10:08,510
key encryption in general, we made a 
change to HTTP. 

152
00:10:08,510 --> 00:10:11,530
A layer, a mini layer is in the data 
model. 

153
00:10:11,530 --> 00:10:15,400
If you remember way back, perhaps you've 
even forgotten about the layered model. 

154
00:10:15,400 --> 00:10:21,320
Remember that layered model? 
Application, transport, Internet. 

155
00:10:21,320 --> 00:10:25,400
Remember this is sort of one computer and 
this is the other computer. 

156
00:10:25,400 --> 00:10:28,648
These are their routers, routers. 
These are the hops. 

157
00:10:28,648 --> 00:10:30,760
There's like 15 of these. 
Remember? 

158
00:10:30,760 --> 00:10:33,735
Remember all this? 
So, it comes back now to haunt us. 

159
00:10:33,735 --> 00:10:36,961
Okay. 
So, if you recall, just sort of to, to 

160
00:10:36,961 --> 00:10:40,825
briefly remember that, the transport 
layer is responsible for the 

161
00:10:40,825 --> 00:10:45,534
retransmission. 
It gives us the appearance of a reliable, 

162
00:10:45,534 --> 00:10:50,490
ordered connection between the, our 
application and the far application. 

163
00:10:51,550 --> 00:10:57,095
HTTP is one of the application protocols. 
and so there is a little mini layer that, 

164
00:10:57,095 --> 00:11:03,069
that is layered in, sort of seamlessly on 
top of the transport layer. 

165
00:11:03,069 --> 00:11:09,030
That basically takes plain text and 
encrypts it and turns it into ciphertext. 

166
00:11:09,030 --> 00:11:12,815
And then ciphertext on the way out turns 
it back into plain text. 

167
00:11:12,815 --> 00:11:15,700
Okay. 
And so what happens is, is these 

168
00:11:15,700 --> 00:11:19,850
applications just send plain text. 
And out comes plain text. 

169
00:11:19,850 --> 00:11:23,480
And there's a little bit of extra glue in 
the middle here, that's sort of a secure 

170
00:11:23,480 --> 00:11:28,524
transport, secure sockets layer. 
This is, this thing here is often called 

171
00:11:28,524 --> 00:11:33,280
a socket, oop, SOCK. 
It'd be good if I could spell socket. 

172
00:11:33,280 --> 00:11:38,330
So, this is a socket, and then the red 
part is a secure socket. 

173
00:11:38,330 --> 00:11:41,330
So, the applications kind of don't 
encrypt the data at all. 

174
00:11:41,330 --> 00:11:45,590
There's a library that encrypts it. 
And the other thing is, is that all the 

175
00:11:45,590 --> 00:11:49,430
rest of the internet, the internet, the 
link layer, the routers nothing, the 

176
00:11:49,430 --> 00:11:53,650
Ethernet, the fiber. 
They don't even know the difference 

177
00:11:53,650 --> 00:11:57,514
between encrypted text or non encrypted 
text, because the encrypted text wanders 

178
00:11:57,514 --> 00:12:01,820
around fully encrypted. 
Addresses are not encrypted. 

179
00:12:01,820 --> 00:12:05,192
And so it stays encrypted all the way 
through the entire network. 

180
00:12:05,192 --> 00:12:09,665
It actually, if you then think about the 
fact that, this is the moment that it 

181
00:12:09,665 --> 00:12:15,054
leaves your computer. 
The only thing, so the plain text comes 

182
00:12:15,054 --> 00:12:18,130
in here, gets encrypted here, encrypted 
comes down. 

183
00:12:18,130 --> 00:12:21,480
The only thing that leaves your computer 
is encrypted text. 

184
00:12:21,480 --> 00:12:24,627
And it makes it all the way across. 
The encrypted text goes into Amazon, so 

185
00:12:24,627 --> 00:12:27,980
this is Amazon. 
This is you. 

186
00:12:29,130 --> 00:12:32,315
The encrypted text finds its way through 
all these things. 

187
00:12:32,315 --> 00:12:36,670
And it come in encrypted. 
And it actually doesn't get encrypted, 

188
00:12:36,670 --> 00:12:39,920
until it's sort of right at the point 
where Amazon's web server that's going to 

189
00:12:39,920 --> 00:12:46,799
actually charge your credit card. 
So, this is actually beautifully elegant. 

190
00:12:46,799 --> 00:12:52,532
In that, the rest of the network is 
blissfully unaware, that any encryption 

191
00:12:52,532 --> 00:12:56,230
is happening. 
It's just moving the data. 

192
00:12:56,230 --> 00:12:58,764
So, this did not require any change. 
Again the beauty of the layer of 

193
00:12:58,764 --> 00:13:01,194
architecture. 
Did not require any change, sort of below 

194
00:13:01,194 --> 00:13:04,003
the transport layer. 
And as a matter of fact, all of the 

195
00:13:04,003 --> 00:13:07,565
sequencing and re-transmission that 
happens in the TCP layer. 

196
00:13:07,565 --> 00:13:12,060
That happens with the encrypted stuff too 
because it's just encrypted. 

197
00:13:12,060 --> 00:13:14,472
It's just text. 
It's gibberish text, it's not the 

198
00:13:14,472 --> 00:13:17,290
original visa card number that you're 
sending. 

199
00:13:17,290 --> 00:13:22,340
You're sending 123 and out comes, you 
know, wxy, the wxy just goes. 

200
00:13:22,340 --> 00:13:26,010
It's re-transmitted. 
All this crap just works, it's like, 

201
00:13:26,010 --> 00:13:28,150
beautiful. 
It's a beautiful thing. 

202
00:13:28,150 --> 00:13:32,502
It's absolutely a beautiful thing. 
Then it's just like this mini layer kind 

203
00:13:32,502 --> 00:13:36,340
of between, it's like the top slice of 
the transport layer. 

204
00:13:36,340 --> 00:13:39,207
That's how I'm drawing it right here. 
It's like this little kind of top extra 

205
00:13:39,207 --> 00:13:42,151
little thing, that says you know what, 
we're going to transport, actually help 

206
00:13:42,151 --> 00:13:45,619
me out and give me some encryption while 
we're at it. 

207
00:13:45,619 --> 00:13:47,720
And there's all kinds of cool stuff that 
goes back and forth. 

208
00:13:47,720 --> 00:13:49,873
The public and private keys get 
exchanged. 

209
00:13:49,873 --> 00:13:52,230
That's all kind of stuff we don't worry 
about. 

210
00:13:52,230 --> 00:13:55,735
We just send data and get data back. 
Pretty cool, huh? 

211
00:13:55,735 --> 00:14:00,949
So, this really solves the problem of the 
fact that we basically should assume, 

212
00:14:00,949 --> 00:14:07,740
that everything between our computer and 
the destination computer. 

213
00:14:07,740 --> 00:14:11,480
This is you. 
This is Amazon, right? 

214
00:14:12,820 --> 00:14:16,903
Everything here, this is all dangerous. 
There's some like, terrifyingly scary 

215
00:14:16,903 --> 00:14:21,390
individual, that's watching everything, 
doing packet sniffing. 

216
00:14:21,390 --> 00:14:25,929
This might be Eve the eavesdropper. 
This looks like a little he, he looks 

217
00:14:25,929 --> 00:14:28,160
pretty tough. 
Right. 

218
00:14:28,160 --> 00:14:30,280
And, and so that even the wireless, 
right? 

219
00:14:30,280 --> 00:14:33,270
This is the wiFi connection. 
The WiFi is dangerous. 

220
00:14:33,270 --> 00:14:36,200
Now, the reality is, is these things 
aren't all that dangerous. 

221
00:14:36,200 --> 00:14:39,140
The WiFi's probably the weakest link of 
these whole thing. 

222
00:14:39,140 --> 00:14:41,610
But we have to assume that it's 
dangerous, right? 

223
00:14:41,610 --> 00:14:45,027
We, we want to assume that the only thing 
that's safe, and unfortunately if you put 

224
00:14:45,027 --> 00:14:49,410
viruses in your computer then they can 
get at the plain text. 

225
00:14:49,410 --> 00:14:54,260
If Amazon loses its data somehow, then 
they get the plain text, right? 

226
00:14:54,260 --> 00:15:00,410
But, but basically, you know, we want to 
distrust all of this, okay? 

227
00:15:00,410 --> 00:15:05,302
So, this concept is called Transport 
Layer Security. 

228
00:15:05,302 --> 00:15:09,540
Also called SSL. 
Also known as HTTPS. 

229
00:15:09,540 --> 00:15:14,230
HTTPS for secure, and it's kind of like 
between the TCP layer and the application 

230
00:15:14,230 --> 00:15:17,878
layer. 
Or the top half of the TCP layer is the 

231
00:15:17,878 --> 00:15:22,770
way I like to think about it. 
It's because it's based on public private 

232
00:15:22,770 --> 00:15:26,211
key encryption it's, difficult but not 
impossible. 

233
00:15:26,211 --> 00:15:30,111
Normal people don't have the kind of 
equipment to break it, even governments, 

234
00:15:30,111 --> 00:15:34,124
if they can break it, I don't know I'm 
not an expert. 

235
00:15:34,124 --> 00:15:38,024
I don't hang out with the government, so 
I don't really know but, assume that if 

236
00:15:38,024 --> 00:15:42,682
they really put their mind to it, in a 
very narrow situation. 

237
00:15:42,682 --> 00:15:47,280
If you become really interesting, they 
will find your credit cards. 

238
00:15:47,280 --> 00:15:51,966
Probably there's easier ways to get your 
credit cards, than by decrypting your 

239
00:15:51,966 --> 00:15:56,610
text. 
So, it's hard to decrypt. 

240
00:15:56,610 --> 00:15:59,834
And as I mentioned, because of the 
layered architecture, the TCP layer, IP 

241
00:15:59,834 --> 00:16:06,066
and Link layers are completely unaware. 
So, you'll, you, you see this in the form 

242
00:16:06,066 --> 00:16:10,301
of URLs that start with HTTPS. 
[SOUND]. 

243
00:16:10,301 --> 00:16:11,907
Right, they start with HTTPS. 
Dub dub dub facebook.com versus HTTP. 

244
00:16:11,907 --> 00:16:19,267
And there was a time a few years back 
where you know, they were, it used to be 

245
00:16:19,267 --> 00:16:28,240
a little more expensive inside of the 
servers to do HTTPS. 

246
00:16:28,240 --> 00:16:31,384
It still is. 
And so some sites would try to do some of 

247
00:16:31,384 --> 00:16:35,060
their activity without using secure 
protocols. 

248
00:16:35,060 --> 00:16:39,131
And others would use use, use non secure 
and secure and then flip you back and 

249
00:16:39,131 --> 00:16:41,860
forth. 
Like if you're typing your password. 

250
00:16:41,860 --> 00:16:45,760
The problem was is that there is actually 
still sensitive data being sent. 

251
00:16:45,760 --> 00:16:49,388
Even across the insecure. 
And there was a, quite a famous, thing 

252
00:16:49,388 --> 00:16:53,090
where people could install a Firefox plug 
in. 

253
00:16:53,090 --> 00:16:58,182
And watch Facebook, non secure Facebook 
things go back and forth across, like, a 

254
00:16:58,182 --> 00:17:01,160
Starbucks. 
And it would just show you all the 

255
00:17:01,160 --> 00:17:04,168
people's Facebook accounts. 
And you could log in as them and post as 

256
00:17:04,168 --> 00:17:06,760
them. 
And so you've seen a situation where 

257
00:17:06,760 --> 00:17:10,940
companies are just starting to use HTTPS 
for everything. 

258
00:17:10,940 --> 00:17:15,280
You, as a user, have to be aware to see 
if you're typing anything sensitive, 

259
00:17:15,280 --> 00:17:19,780
never type it into a URL that doesn't say 
HTTPS. 

260
00:17:19,780 --> 00:17:20,620
'Kay? 
Never do that. 

261
00:17:20,620 --> 00:17:24,750
You're typing in a password, a credit 
card number, any kind of personal 

262
00:17:24,750 --> 00:17:28,751
information. 
Make sure you're doing HTTPS, and make 

263
00:17:28,751 --> 00:17:33,047
sure that, that you know what it is. 
We'll talk about that in a bit, we'll 

264
00:17:33,047 --> 00:17:35,090
talk a little bit more about that in a 
bit. 

265
00:17:35,090 --> 00:17:38,570
So, so if we take a look and we think 
about where the bad guys are it, the bad 

266
00:17:38,570 --> 00:17:44,324
guys are kind of everything. 
And this secure TCP runs, is the one part 

267
00:17:44,324 --> 00:17:49,238
of the layer of our architecture that 
runs from within your laptop to within 

268
00:17:49,238 --> 00:17:53,740
the server. 
And so, then, if we kind of assume the 

269
00:17:53,740 --> 00:17:57,650
worst. 
The, the, the backbone is pretty safe. 

270
00:17:57,650 --> 00:18:02,097
The wiFi is probably the most dangerous. 
Alright, but when we do secure system 

271
00:18:02,097 --> 00:18:08,097
TCP, secure system to system TCP. 
We are doing the encryption, right here 

272
00:18:08,097 --> 00:18:13,585
inside your computer before it leaves. 
And we're only doing the encryption right 

273
00:18:13,585 --> 00:18:17,000
when it comes back in the computers. 
So, the decryption and encryption are 

274
00:18:17,000 --> 00:18:20,558
happening inside of Amazon's computer and 
inside your computer. 

275
00:18:20,558 --> 00:18:24,960
And nothing else. 
So, Secure Sockets is pretty good. 

276
00:18:24,960 --> 00:18:28,494
Now the place where you're still in 
danger, is there might be a virus that's 

277
00:18:28,494 --> 00:18:32,394
watching your keystrokes, right. 
This is why virus checking is so 

278
00:18:32,394 --> 00:18:35,241
important. 
Because at some point, you're typing it 

279
00:18:35,241 --> 00:18:39,085
into your computer and the, and the 
greatest danger you have to losing your 

280
00:18:39,085 --> 00:18:43,970
data is really two things. 
One, that you've got a virus. 

281
00:18:43,970 --> 00:18:51,300
Or B, somebody has redirected you not to 
talk to evil Amazon instead of Amazon. 

282
00:18:51,300 --> 00:18:54,990
And that's what we'll talk about in the 
next lecture. 

283
00:18:54,990 --> 00:18:58,730
How to know, how do these browsers really 
know they're talking to the real Amazon? 

284
00:18:58,730 --> 00:19:03,179
And that is not confidentiality. 
Confidentiality is stopping the bad guy 

285
00:19:03,179 --> 00:19:07,240
from seeing what you're sending. 
As they're eavesdropping. 

286
00:19:07,240 --> 00:19:09,580
Eve is eavesdropping. 
Okay? 

287
00:19:10,840 --> 00:19:15,384
Now, the next thing is the question of is 
this the real Amazon, or is this a fake 

288
00:19:15,384 --> 00:19:18,390
Amazon? 
So, we'll talk about that next. 

