Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security Podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Happy birthday to you! Alex, happy birthday! Thanks, Robb.
As we kick off episode 63 for the week of April 16th, 2018, we do celebrate your birth in the year— what was it, 1952? Uh, about that time. Yeah, you're a little bit off, give or take. Give or take a couple. Yeah.
All right. Uh, anyway, happy birthday. We're glad to get to celebrate with you. I obviously— we're wearing party hats and, um, and, you know, putting away all— and we've been drinking a lot. Absolutely.
Cheers. Cheers. Um, moving on to, uh, maybe talking about some podcasty type stuff. Why don't we start off by thanking our Patreon? Yeah, so, uh, we have a Patreon page.
You can go out there and help support us. Uh, thanks to all those folks that have done that already. That money is going towards our ongoing expenses for producing the podcast, so we really appreciate that. And kind of some other housekeeping stuff, we have a Slack channel. Uh, we actually just this last week started a new channel that's about kids or youth programming and trying to come, come up with solutions for how do we solve the talent gap by starting earlier, you know, getting kids in high school or maybe even younger involved with security and show them kind of the way to get there.
Yeah, I'm really excited that people were, were interested in getting that started, and, uh, should be a lot of fun. And as, as a reminder, we do have a mailing list for the show each week. If you, if you sign up on the website, um, we'll get the show notes into your inbox and a little link to download the show if you want it. Um, it's a nice way to get the articles delivered to you. And of course, please sign up on iTunes or Google Play or your favorite podcasting service.
And when you do, please go out and rate us because we would love to have that, that rating out there. Awesome. Let's go ahead and jump into the stories. Number 1, uh, we are firmly in the top 3 for best cities to live in in the United States. Yes, congratulations Colorado.
Uh, Colorado Springs was number 2 and Denver was number 3. And, uh, Colorado Springs was number 2 with a, with a rocket. They were number— they had been 10 last year. They really climbed up the charts this year. Um, I guess really popular among, uh, people.
Yeah, people like Colorado Springs. It's beautiful down there. So it's US News and World Report and they had this this survey based on a few criteria. The value of living there, which includes stuff like home ownership versus renting, cost of living, quality of life, job market health, people moving into the state, are they leaving, are they moving in? Anyway, Colorado Springs number 2, Denver number 3, and our dreaded foe, our arch nemesis, Austin, took the number 1 spot.
Yeah. Damn Austin. Yeah, it's pretty consistent that they're right there with us neck and neck and again have beaten us. I do have to say we are better at most things, but they do have pretty good barbecue down there. They have pretty good barbecue, yeah, and it's much hotter, so they got that going for them too.
That too. Next, Colorado Legislative Tech Caucus has been looking into blockchain technologies. I wanted to say Bitcoin. Yeah, we've talked about this a couple other times on the show. There's a couple of bills that are out there around asking or requiring the government to look at how blockchain can solve some problems.
This is crazy. This is crazy. It's not crazy that you could use blockchain to solve problems. It's crazy that you would make a law that says you must use blockchain to solve some problems. Yeah, I'm pretty sure that the verbiage in there has been softened a little bit to say that you know, they should encourage the use of blockchain, which is even still a little bit crazy considering how early on blockchain is.
I like the sentiment that they want to improve the security of our information, but maybe that's not the best way to do it. There's also a second bill that is out there that is working to define what cryptocurrency is and regulating cryptocurrency in Colorado. So I just say, I give my little diatribe on blockchain. Blockchain is the first implementation of the distributed ledger technology that's had some mass adoption. You know, distributed ledger is a great idea.
You get, you know, consent and consent management with a non-centralized model. Makes a lot of sense. Blockchain has a lot of flaws. Obviously, a couple, you know, 2 of the big ones: energy consumption. You know, it's taking more energy to fuel our blockchain infrastructure than it does for many countries, including Denmark.
I think that was the famous one. And it also is just notoriously slow. The number of transactions you can do per second is a real bottleneck problem. I think something's going to come along behind blockchain, but I think that asking someone to actually use blockchain specifically is kind of asking for trouble. With that, let's move on.
I would agree. Uh, next, Colorado is among the states engaged in the Cyberstorm exercise to talk about Election Day threats. So I can only assume that means computers are raining from the sky. Yes, exactly. Yeah, also thunder and lightning.
Well, uh, so obviously it's great that we're starting to do some tabletop and, and more than just tabletop exercises around what election security looks like. Um, it might have been nice to have done this a few years ago, but you know, we'll take what we can get here. Well, and I, I think that this is an ongoing competition, things that have happened in the past. Uh, also we talked about the story previously that, uh, I think Colorado had a B+ in election security. So, we're not doing too bad, but they are competing with 1,000 other entities to look at this competition and get their security better around elections.
Well, go Colorado. We're all pulling for you here. Moving along, there is a survey that was released this week by LogRhythm. It's their benchmark survey talking about kind of industry perceptions and data. The link is in the show notes to get the survey.
There's a couple of interesting things I wanted to pull out. Number one, I'll say it's just neat to get this kind of perspective on what industry leaders think. Couple interesting things to pull out here. Number one, less than half of organizations were able to detect a major incident within an hour. I don't think that's surprising, but it's kind of a nice baseline to understand that somewhere just less than 50% thought they could find it in less than an hour.
And the second interesting thing was that organization, excuse me, on average, companies employ 12 security analysts. Security professionals. However, more than half of the respondents said that they employ 10 or fewer. So there's obviously some that have much larger numbers that are pulling up the average to get up to 12. Yeah, I would say it's surprising to me that we're even that high in terms of an average.
Yeah, and obviously we didn't really go into the methodology on this, but obviously we're not talking about all companies, right? There must be a cutoff to say we're only talking about companies over a certain size, because if you start talking about the flower shop and the gas station, You know, it just would skew the numbers too much. Yeah, exactly. Next story, we have GTRI, which is a local reseller here and service provider. They have changed their name to Zavaro.
Zavaro. So at first we said, why would they do this? Seems sort of silly. But we understand they were purchased by a company last year, and the name of that is Zavaro Holdings. Hey.
Yeah. Strangely, they have then changed their name to Zavaro. And Zavaro Holdings, I believe, is owned by a masked man from Mexico. Named Zavaro. Uh, if that's not true, I mean, to show some kind of evidence of that.
All right, well, that— congratulations, Zavaro and, and, uh, GTRI folks. Uh, Aaron Simmons, our friend, the CISO over there, um, happy for you that you have new business cards. That's going to be good. Uh, moving along, we have a press release from Secure64. They are the secure DNS appliance that is headquartered in Greenwood Village or Fort Collins, depending on what what you believe.
And they this week announced that they have come up with a new service called TunnelGuard, which detects and blocks DNS tunnels. First thing that we thought is— what do you think first? This sounds like a great feature. Yeah, it sounds like a great feature. I thought the same thing, something you might embed into a firewall.
But as you dive a little bit deeper into the press release, it looks like they're really targeting, you know, big telecoms and big providers where you know, having this as a feature in a, you know, in a UTM just doesn't make any sense, right? They're, they're really offering a new service at massive enterprise scale. Um, so anyway, sounds like a good thing. I don't know much about it, but yeah, good news. Good for Secure64.
Uh, next, Automox had a blog talking about real-time patch management. So you talked to the founder of Automox last week, right? Uh, Jay Prassel last week was on our feature interview. And so this is talking about, uh, how they do patch management differently, less time-consuming, more automation. So if you didn't get enough details about what, what their, you know, vision for patch management looked like last year in the show, last week in the show, this is your chance to read an article and learn some more about Automox.
Exactly. Your local patch management company. Next story, we have a blog by Optiv about who is the data protection officer. So if you guys don't know what a DPO is, hopefully that means that you don't have to be GDPR compliant. If you don't know what it is and you do need to be GDPR compliant, you should go talk to your DPO about what a DPO is.
Or your legal counsel or somebody, because you're gonna be in big trouble. So this is just a nice— it's a little white paper you can download from Optiv that kind of explains the position, kind of gives some nuanced descriptions about what they're supposed to do and who it should be. Anyway, interesting. Responsibilities, all that kind of stuff. So it looks interesting.
I recommend you guys take a look at it. And then our final news story for this week, Direct Defense had a blog talking about what is in your security wallet. Yeah. I don't know if I would've used the term wallet, but they're really talking about security tools that you might have with you on a, you know, a go bag or a, I think they say a jump drive or something like that. A really great blog post about some great resources.
Yeah, so it started off talking about those kind of tools like you mentioned that might be in a go bag, but they actually go into some stuff that isn't really something you have, right? They start off by talking about tools like having Sysinternals, having Wireshark. Those are some technologies, Kali. But then they get into some resources you might wanna use. NIST as a resource, the Center for Internet Security, OWASP, where you go do some research online.
Good resources there. And then kind of a whole different perspective where they're just giving some tips on how to get into the industry. How to build a home training lab. How to download virtualization software and use that to do your training. There's a lot of really good tips in here.
Yeah, a list of great books to read and other things like that. Yeah, so I think as I read this, I'd say number one, you know, anyone who's new to the industry, this would be a really good resource for you to start to get your arms around what all is out there. And anyone who's been in the industry for a little while, it'd be good to kind of, you know, check your own resources up against this and see if there's something you're not using that you could be. Yeah, exactly. So that takes us to the end of the news.
So now it is time for our Slack Message of the Week. Slack Message of the Week. Thanks to Andre Gaeta for sponsoring the Slack Message of the Week contest. I feel like we need to get some music that plays when we talk about Slack messages. Maybe there will be music by the time we release this episode.
Cha-ching or something, you know?
Slack message of the week.
You know, maybe they just heard it and you don't even know they heard it. Ooh, that's deep. So looking at the Slack messages of the week, this week we want to say congratulations to Jade. Jade pointed out on the general channel that ISC²'s CPE entry process has become really difficult. Yeah, so I would— I'd like to say that it used to really suck.
It was bad. Yeah, and apparently now it sucks even more. So yeah, it sucks more and you get errors now when you have to do your CPE. Right. They apparently just moved to a new system and not only is it hard, but they're experiencing some problems getting the system to work.
So rather than specifically calling out a comment she made, I just want to talk— she started this great conversation Where we found out that there, for some types of CPEs at least, there's a requirement that you have to write a 250-word description of the event. Yeah, that seems like a lot of overhead. Yeah, that's gonna be challenging. It makes me not want to renew. Yeah, it sure does.
All right, anyway, congratulations to Jade. You will get one of the items from the Colorado Equal Security Store, and thanks to Andre for supporting our competition. Thanks, Andre. Let's go ahead and move on to events. As a reminder, we do have a calendar on the website.
We're going out. I was just talking to Alex before. We've really filled out the calendar here over the next several months. Really, SecureSet just put a bunch of stuff on the calendar. So take a look at what's going on out there through really through the end of June is really well filled out.
So the first event is ISSA Colorado Springs. They're having their April meetings on April 17th and 18th. On the 19th, SecureSet has one of their career conversations with Kevin Ford. From CyberGRX. Also on the 19th, ISACA is having their annual meeting.
So this is their annual general membership meeting. Go in there and get some delicious treats. I assume they'll have a cake or a cupcake, or maybe not, I don't know, but they've always done a pretty good job before. On the 24th, we are celebrating 1 year of Women in Security in Denver. So congratulations to that group.
You don't have to be a woman to come, you just have to appreciate that women are awesome. Also on the 24th, CSA is having their April meeting. On the 25th, the GDPR meetup is meeting and they're talking about Article 32 and the Elastic Stack. You don't know what Article 32 is? Well, either pick up GDPR and read it or just go to this meeting.
It comes after Article 31. Next, DENSEC is having their monthly meetup also on the 25th, and that's— they moved that downtown a couple months ago. They also had to move this off by one week because They had previously had it scheduled over RSA conference, and nobody wants to have an event scheduled over RSA conference. The 27th, SecureSet has one of their capture the flag events. If you have not done a capture the flag, that's not a problem.
Show up an hour early at 5 PM, and they'll teach you how to do it, and you can contribute to the real one at 6 o'clock. Sweet. And then finally, on the 28th of April, ISSA Colorado Springs is having one of their mini seminars. That's awesome. Hey, listen, there's a couple of big events coming up in town in May, right?
What's going on? You know, I hadn't heard. What events are you talking about, Robb? Well, let's look this up. It's the Rocky Mountain Information Security Conference.
That sounds interesting. Yeah, yeah, that does look interesting. Now, I hear a couple of interesting things happening with Colorado's biggest conference where we expect to just blow the numbers off of everything we've done in the past. A couple interesting things happening. Number one, there is going to be a security focused escape room this year.
Yeah, so there's a company called Living Security and they are coming to do their escape room as part of the conference. So this is security awareness training and they're demonstrating this for everyone. So when you register for the conference, you can also register to do one of the sessions with them. They can only do, I think, 10 or 12 participants per hour. So make sure you register for that.
If you've done an escape room before, it is a lot of fun. This is security-focused. It should be a good time. What about any other pre-conference trainings? Did we do anything we want to talk about there specifically?
You want to call any of those out? So there is a great auditing track we have, Auditing Cybersecurity. So this is the, the same course that is being offered at the ISACA International Conference where you have to pay $1,000 or something like that to take it. But you can come and have this essentially for 25% of the cost. Great trainer, great content auditing cybersecurity.
There's a couple other ones, obviously the Atomic Red Team, which we talked about with Casey Smith on the show a few weeks ago. We've also got a cryptocurrencies talk that's actually being put on by SecureSet. And I believe there's one— there's also a cloud security training by Mohammed Um, Malky and Muhammad is of course one of the board members for OWASP here in town, um, and it should be— oh, sorry, uh, CSA, Cloud Security Alliance. And that should be an interesting talk as well. Yep, should be great.
Did I miss one? Oh, I did. I missed one that we, we both care about, right? Yeah, for any security leaders in town, there is a CISO event. Uh, yeah, you do have to be running a security program, but there's an afternoon event that you can be a part of where you'll get to learn some interesting stuff.
Yeah, should be a great time. And with that, I'll say there's also the closing keynote on Thursday. Much like we did last year, we have a local big-time professional comic who's going to be closing out the conference. Phil Palisole is going to be doing it. I've got to hear his videos.
He's super— he's hilarious, and it should be a really good time. And if you're going to the conference, feel free to bring a friend, bring a loved one. We do kind of open it up during the closing keynote for non-attendees. Yeah, and so Rocky Mountain Information Security Conference is May 8th through the 10th. Of course, following the Rocky Mountain Information Security Conference is Denver BSides on the 11th and 12th.
Yeah, that's a fun— that's a super fun event. There's always beer. It's always much more laid back. Fun events. You know, last year they did the slideshow.
I don't know what you call that slideshow charades or whatever it's called. Yes. PowerPoint karaoke. Yeah. PowerPoint karaoke.
Yep. So that's always fun stuff. And of course, there's also lots of hacking and owning of things going on. It's a good time and a good way to get to meet people. And it's free.
It's, it's free, although they would love it if you would donate and help contribute to them. Yes, exactly. Let's go ahead and jump over to jobs. As a reminder, we do, you know, we cover about 10 jobs every week. They're in the show notes.
We don't put them on the website permanently because we don't want to have to go check and see when the jobs have closed. So you can look at each week's show notes and see what we found this week and check next week and see the new stuff, right? First on the list, there's a job for Ping Identity. Yeah, so we are still hiring a a senior security analyst, looking for somebody who's got, you know, some experience and some chops, really looking for someone technical who understands the underpinnings of the technology rather than saying, hey, I want you to be good at Linux and AWS. I want you to really understand how these things work.
And, you know, we're not looking for someone who just knows how to run a tool. Exactly. Uh, next, uh, Pulte Financial Services. Um, I am hiring 2 interns this summer, so if you are a college student or someone without a job or someone who's just graduated, want to come work with us for the summer, we'd love to have you. We also have a position from Innovage, which is hiring a vice president of security from what I understand from Alex.
This is a retirement community or a series of them, a group of them. Exactly. TIAA is hiring a director of fraud detection. This sounded really cool because it is cybersecurity fraud and other kinds of fraud as well. Very cool.
Brown and Caldwell is hiring a senior manager of information security. Greenhouse Data is hiring a manager of information security. Is Greenhouse Data a marijuana company? Do we know? I, I don't think so.
I think they're a, uh, a hosting provider. Hosting. Okay, good enough. Um, Lockheed Martin is hiring a cyber architect senior staff. A cyber architect.
Yeah, so you get to architect the cybers. Senior staff. You're on the senior staff and you architect the cybers. And these, by the way, these are both, um, what do you call those dashes? Um, oh my goodness, hyphen, hyphenated.
These are all hyphenated. It's all between each of these words. It's cyber architect senior staff. Yes. Yeah, it is getting late.
We're having a good night here, right? Uh, public service credit union is hiring a senior security administrator. Western Union is hiring an information security engineer for their security operations center. S&P Global is hiring a project manager for information security. And Akamai, one of the, you know, core protectors of the web, is hiring a technical project manager focused on security.
Exactly. Well, that takes us to the end of our news this week, Alex. I think what you— this week you talked to Zooko Wilcox, right? I did. Zooko is a really interesting character.
He is the founder of Zcash. Zcash is a cryptocurrency. So, you know, we were bashing on the blockchain earlier, but, you know, one of the interesting things about Zcash is it has some encryption and privacy built into it as opposed to some of the other cryptocurrencies that do not. So very interesting. You can have some more anonymity and privacy.
Yeah. And so he, he was one of the founders of that. Did, did you guys talk at all about that podcast that he did on, on, uh, you know, on Radiolab? Yeah, he— we found out about him from Radiolab, uh, podcast. Yeah.
So, uh, there's a great Radiolab podcast. You should go out and listen to it. We touched on it briefly, but I think in the interview we basically said go listen to the Radiolab podcast. It's much better than we can tell it here. So great story.
I'll put it— I'll put a link in the show notes to the Radiolab podcast. So folks who find him interesting can go learn more. It was a really interesting story. Yeah, and he's a really interesting character. I had a good time interviewing him.
Cool. Well, I think that takes us to the end of the week. RSA conference is next week. I'm going to be out there. I think you're going to be not there this year, right?
I will not be there this week. I get to go instead of San Francisco, I get to go to Detroit for a Mortgage Bankers Association conference. One of those is better than the other, and you know, it'll be up to you to figure out which. Detroit! All right, with that, we'll call it a week, and we'll talk to you next week.
Thanks, Robb. Hello, this is Sean Murray. I am a director on the International Board of Directors for ISSA, and I am a principal scientist at Northrop Grumman Corporation working in Colorado Springs. This is Colorado Equals Security, for Colorado security professionals by Colorado security professionals. This is Alex Wood with Colorado Equals Security, and I am here today with Zooko Wilcox.
Zooko, thanks for taking a couple minutes to speak with us. Mm-hmm. Thank you for having me. Yeah. So you are the founder— I don't know if that's your official title— founder of Zcash.
Right. Zcash, a cryptocurrency. Mm-hmm. So I wonder if we could start just by you giving a little background on yourself, you know, what you've sort of done in your past and how it is that you came to starting a cryptocurrency? I've mostly done programming, like software engineering, some infosec work like security auditing of the source code of other people's apps, implementing cryptography, a couple of science papers about cryptography and distributed networking.
And then a few years ago, almost maybe, geez, I've lost track, but maybe 7, 8 years ago at this point, I decided to make my own company and be the CEO so I could do everything my way. Everybody's dream, right? Get to be your own boss. Yeah, it turns out that the boss is a pretty tough taskmaster, but I really loved it. And that first company that I made is named Least Authority.
And it still exists, but then later we spun off a separate project that became Zcash. But that first project, Least Authority, is still in operation, and it does the commercial support for a decentralized, cryptographically protected object store, like a cloud file system, like Amazon S3, but with cryptography. So that's pretty cool.
You started there doing that with blockchain for another purpose besides cryptocurrency, it sounds like. It wasn't precisely blockchain. It depends on how broad your definition of blockchain is. Yeah. And there's a legit argument that you ought to have a fairly broad definition, like Git, which uses secure hashes, or at least uses SHA, which is supposed to be a secure hash, to link newer things to the older things from which they come.
That's basically a blockchain too. So I guess that's a good place to start, right? So what's your definition of a blockchain?
Well, the important addition that Satoshi added on top of the use of secure hash functions for immutable references— so Git, well, I mean, Git didn't invent it, but the notion of using secure hash functions for immutable references has been around for a long time and used in Revision control systems, like Monotone was a predecessor to Git. Git's kind of a clone of Monotone, and Monotone was one of the most important examples of using that secure hash function as data references. Also, file systems have used it in the past. And then what Satoshi added was the proof of work as a way to incentivize all the players to come to consensus instead of, instead of advocating for their interpretation of history. Right.
Yeah, that's— I think that's definitely an important part, right? Yeah. The decentralization and the consensus. Yeah, that's a really deep— it's one of those things that theoretical or even applied computer scientists firmly believed was impossible until Satoshi demonstrated it. Yeah, you know, there were even proofs that it was impossible.
And so whenever something like that happens, there is a proof that something's impossible, and then you find an example of it, then you get to reverse engineer what was the mistake in the proof, right? Right. So that's enlightening. So you have this, uh, this company that is doing what we'll call a blockchain technology, then you decide to start Zcash. What was the reasoning behind wanting to start your own cryptocurrency?
Well, it's actually basically my lifelong dream really. And then I got the chance because a bunch of scientists, not me, had devised a cryptographic design for a privacy-preserving decentralized cryptocurrency. And then they invited me to be the sort of organizer and business leader of the project to make it practical and widely deployed. So that was, that was the opportunity I got when those scientists approached me. But I had always dreamed about such things since I was about 19 years old, in fact, when I discovered the science papers of this cryptographer named David Chaum.
He invented the notion of privacy-preserving digital money. He also invented the notion of Privacy-preserving networking like Tor and other things. That concept was invented by him originally, as well as some important concepts in basic cryptography.
As well, he was part of a cohort of cryptographers along with Whit Diffie and Ron Rivest and others who in sort of an act of civil disobedience, made cryptography into a public science instead of a secret military science in the '70s and early '80s. Well, in 1993 or so, I discovered papers he had written about these things, and the internet was pretty new to me back then. Kind of new to most people. And it was really heady days to imagine what the world would be like if the internet spread all around it to most of the people in the world. And at the same time, I immediately imagined then the very next step will be we'll spread some kind of money system, some kind of financial economic system so that people who are newly able to communicate because of the internet will also be able to cooperate in like sharing resources or charity or business deals with each other, right?
We'll have a global economy. And then that never took off. And one of the, one of the attempts to make it take off way back in the day was a company founded by that same scientist, David Chaum, And I went to work for that company for 2 years. I dropped out of college when I was 21 years old and went to work for that company. Um, but it didn't have Satoshi's breakthrough of full decentralization with proof of work.
So everything back then, everything up until Bitcoin, had some kind of centralization that, that meant there was something that could fail, or there was something that people would have to trust before they'd be willing to trust this monetary system. And that was also true of David Chomp's company. I would also imagine that meant that there would have to be some level of control by that central authority Um, and also along with that, you know, you mentioned privacy and Zcash, one of the reasons for doing that. So anytime you have that centralized control, you have the risk of somebody, um, you know, exposing privacy or, um, you know, trying to control things in a way that others don't want to do. Well, some— there's different kinds of control, like exposing, getting access to other people's private information is a very important kind.
Being able to change the money supply, right, that's the major difference between cryptocurrencies like Bitcoin and Zcash and all of the current fiat currencies of the world, is that there's a credible belief that nobody has the ability to change the number of Bitcoins or the number of Zcash.
That's a different kind of control. Then there's access and limiting access. There's this ongoing problem in the current legacy banking system which they call de-risking. De-risking is where you're not doing anything illegal or even suspicious, but the bank needs to cut costs. And a good way to do that is to close all the accounts of people from a certain category.
And that's totally legal. And not only is it legal— like, this would be illegal if it were like housing or a job, but it's totally legal for a bank account. Yeah. And, um, not only is it legal, but the way the current system works, it kind of forces the banks to do it because it's very expensive for them to deal with compliance costs, and they also have compressed profit margins nowadays. So what they're doing is just selecting whole groups of businesses or users and saying, well, all of those guys are out.
For example, they've done this quite a lot to the porn industry in the United States, which is legal in the US according to the law, right? But it's also legal for the bank to just close all of the accounts of anyone who has ever had anything to do with the porn industry. And so that's what they've done. Similarly, they pick remote countries that it's expensive for them to deal with the compliance costs, and they don't make that much money by serving, like Somalia or whatever, and they just cut them off. They're like, well, the Somali people have to figure out how to deliver money to their country some other way because it's too much work for us to deal with it.
So that's another form of control, is being able to limit access, or somebody requires your permission, or they require your help before they can have access to the system. There's lots of different kinds of control in a system like this, and with Zcash, we've engineered it to minimize all the different kinds of control, including the the knowledge of other people's private data. And that's a really important kind of control that people may not have appreciated at first. But like, Bitcoin is really bad in that way. Bitcoin is super great in decentralization and reducing control that someone could exercise in lots of other ways.
But because it doesn't have encryption and all of your transaction data gets divulged, that makes it quite vulnerable to control by someone who just looks at the public ledger and then, like, closes your bank account or threatens you with arrest or threatens you, you mustn't do certain kinds of things and we're watching, we'll know if you do. Right, well, and I mean, I think a couple examples of that are, you know, the first was when, when Bitcoin started to get popular, everyone said, oh well, it's only criminals using it because they can be anonymous while using Bitcoin, right? Um, which of course is not true. Um, you know, you can see everything that's happening, you just may not know exactly who it is that's behind that particular account. I remember when they said that, and it reminded me of what they said when the internet was new, right?
Nobody knows you're a dog on the internet because it's just a dotted quad address. Right, instead of your home address. The same way they thought just because a Bitcoin address is just a random string instead of your home address, that makes it anonymous. But it's way harder than that to make something truly private on the internet. Yeah, I mean, I think the other example I've seen is, you know, with the IRS now.
They're, uh, from what I've been told, are monitoring, you know, all the Bitcoin transactions so that they can make sure that people get charged, uh, you know, taxes when they, uh, they cash stuff in. Yeah, and there's a court battle going on between the IRS and Coinbase, where, as I understood it, the IRS is— so they sent a subpoena or whatever, some kind of demand for records to Coinbase, and they're supposed to explain their justification for why they're demanding these records, right? And the first version of their justification was, well, Uh, the records we're demanding are all of them, like all of the users that you had during these years. And our justification is, if anybody was using Bitcoin during those years, they were probably tax evaders. Seems logical, right?
Well, I don't know statistically, but it doesn't feel right. Yeah, it doesn't. Um, in terms of justice, you know, there's a sort of presumption that you ought to have a better reason than because I used Bitcoin to accuse me of wrongdoing. Anyway, I don't know what's the current status of that court battle. So, um, for those that aren't familiar with Zcash, how is it that Zcash does things differently?
Hmm, well, think about it like this. Satoshi and Hal Finney and the other creators of Bitcoin wanted to preserve privacy. In fact, that was almost like— I think it was probably one of the top 2 goals of the whole Bitcoin project: decentralization and privacy. And, and the 2 are almost inseparable, because if you don't have privacy, then some central power can just dictate what you can and can't And so that was always what they wanted. And they talked on the Bitcoin mailing list about whether they could use some kind of better cryptography to protect the information from being exposed in the blockchain.
But back then, that the cryptography was not well developed enough, so they couldn't. But since then, what we what scientists came up with was more efficient zero-knowledge proofs that they didn't have back in 2008.
And with what a zero-knowledge proof does is it, it's a cryptographic proof. It's like a big, you know, digital signature or like a secure hash output. And it's a proof that I couldn't have come up with this digital signature unless I knew some input to a program which results in the following output. Does that make sense? Yeah.
So then you check the cryptographic validity of it and then you say, okay, I'm convinced whoever came up with this proof, they must have known some input to this function such that the function's output was was this string. And this is for a deterministic function, right? Like a deterministic program that will take some input, do some computation, return some output, and it always returns the same output for the same input. Okay, so with that, now that once scientists had come up with a way to generate zero-knowledge proofs efficiently enough, then scientists, including founders of the Zcash project, figured out how to use this to solve that problem that Satoshi and Finney couldn't solve in Bitcoin. And the way— the reason this matters is what you need to do— the reason the bit— so here's a question: why didn't we just encrypt the transactions in the Bitcoin blockchain in the first place in 2008?
Because we, you know, Satoshi already knew how encryption worked. Yeah. But instead, all the transactions are publicly visible. We just use digital signatures to make sure that they're signed by the spender, and we secure hash functions just like Git and Monotone did to make sure that they're correctly integrated into the history. Yeah.
But why didn't we also use encryption to make sure they're private? The answer is, if we had, then the miners wouldn't have been able to detect and reject bogus transactions, like double spending, where you already spent the money once and now you're trying to spend it a second and third time to other people. You would just know that something happened, you wouldn't know what it was. And then we need the miners to be able to detect and reject double spending so that the ledger is a ledger consisting of only valid transactions, so that if you receive a payment and you look in the ledger and you see your payment is in there, you know that you're the only one who got the money, right? So that's why Bitcoin had to have this pervasive lack of privacy, is so that the miners could reject double spends basically, or other invalid transactions.
Okay, well, zero-knowledge proofs are a different way to prevent double spends. So in Zcash, the miners test the zero-knowledge proof that comes with each transaction, and each proof shows that somebody knew a secret key that was the secret, uh, the secret key for a, for a coin, and that they used this coin to, like, use it up. They've spent it, and this is the first time anyone's ever done this for this coin. Okay, so it can't have been double-spent, right? And then they gave the money to this other public key for the next use.
Now there's a zero-knowledge proof that the miner can check to make sure this transaction satisfies all those conditions, but the actual details of which coin and which address and how much it was worth, that's all cryptographically protected. So that's Zcash. It's a big It's a big breakthrough, really. That is pretty cool. Yeah, I think, um, so the first time that I ran across you was through a Radiolab podcast talking about, um, what they called the ceremony.
I'm not sure if you guys actually called it the ceremony or not. Yeah, that was our terminology. Okay, um, so, so this was essentially, uh, what you guys had to do in order to to start Zcash, you had to start with, uh, I guess I'll call it a seed, right? Yeah, a seed, right. Um, I kind of think of it as a public key.
So I mean, it's kind of, to speak a little bit loosely, yeah, it's like, it's pretty much like a public key, but you're not using it for encryption, you're using it for generating and testing these zero-knowledge proofs. Got it. And so this is like a key generation ceremony where we want to make sure nobody is secretly stealing the private key, the corresponding private key, right? So that's where we named the corresponding private key— we named that the toxic waste because we had come up with this idea that This is another breakthrough. I mean, I hate to sound like I'm tooting my own horn, but we've done several things which are basically the most advanced cryptography that has, as far as I know, ever been deployed to the public at large.
But one of these things we did, which is the most advanced thing ever, was the ceremony, where we came up with a technique. So there are other ceremonies. In fact, we didn't invent the term ceremony, actually. People use the term ceremony already for other cryptographic processes, like for DNSSEC. You know, there's a root key that signs all the other keys that signs all the DNS records.
Yep, and they have a whole ceremony where they have to have— They have a ceremony. They call these people from around the world that fly to the same room, there's video cameras, they each have a smart card, There's an HSM, you know, a hardware security module that contains a private key. That is a ceremony. And I have to say, our ceremony blew that one out of the water. Our ceremony is so much better than that ceremony because, because in the DNSSEC ceremony, it's pretty good, but it basically involves bringing all the secrets and all the people together at one moment and one point, right?
And there you generate the new secret. This new secret is contained inside the hardware security module. That's, that's what— that's why you believe that no one has stolen that secret, is that you have video and you didn't see anyone like taking a screwdriver to the hardware security module or whatever. But our ceremony is way better than that because there was no moment at which the secret existed. So we renamed it to be the toxic waste, and we said there's going to be 6 precursor chemicals, each of which is harmless.
And the only way the toxic waste would ever come into existence, even for 1 millisecond, would be if all 6 of them came together at the same time. So now we're going to do this process to— that's sort of like the DNS ceremony, but there's like 6 separate ones.
And each one is going to use its precursor and then destroy its precursor before it ever has a chance to come into contact with the other 5 precursors. Yeah, and you're doing this all distributed, right? So in the DNSSEC ceremony, they're all in one place. For, for your ceremony, anyone can be anywhere, right, as long as they can perform the operations that need to be performed. That's right.
And we, we tried hard to use OPSEC procedures, right? So that if there were— so I figured no one— there were no attackers who even knew about the Zcash project's existence, right? I mean, the Zcash project was a publicly known thing, but I figured the only people who'd ever heard about it were cryptocurrency geeks, you know, who are fellow hackers, open source enthusiasts, Bitcoiners. So I just figured no thieves or saboteurs or enemy governments or anybody would even know about or care about this whole thing. But nonetheless, just to be extra safe, we'll have a level of OPSEC around it where there were 6 participants and 3 of them were unknown even to the other participants.
They were known only to me and they went by pseudonyms during the process, and each of the 6 participants had a different process to avoid being backdoored and to have monitoring and detection so that if anyone were to try any attack, each of the 6 different stations would have different levels of detection and defense, right?
Like I say, we really went overboard on this level of security. So, so then we performed the process, which was more than 24 hours of terror plus boredom, right? For my— I was one of the 6. I was one of the 6 human operators of the stations. Our station was called Denver Station.
We got together with a film crew who was gonna make unbroken video to prove that nobody took a screwdriver to it at any point when we looked away.
And a journalist that we invited to come serve as an independent observer to testify that she didn't notice us doing anything squirrely.
So we got the whole crew together, the film crew, the journalist, and me, and we got in a van and we turned off all of our cell phones in case somebody was like listening or tracking us with GPS or whatever. And we got this big paper map and we walked into the nearest coffee shop and we were like, uh, hey man, could you look up the nearest computer store? And he was like, what is this, a scavenger hunt? Yeah, something like that. Something like that.
He was like, okay, I'll Google computer store. And he gave us the address, and then we were like looking up the address. You remember how with paper maps there's like an index where you can look up the roads and the grid? Anyway, so we— Isn't it funny how soon we forget that stuff? I know.
It's like, oh, I remember why this took so long. Anyway, so we eventually figured out how to drive to the computer store with all of our cell phones turned off. We went in there with cameras like hidden under our coats so that the computer store wouldn't be freaked out by the cameras. And we, we walked around and we said to the salesman, okay, we want one of these. And he says, okay, well, there's 2 boxes here, you can have this one.
And we said, no, no, no, we want the other one, not the one you were going to give us. And he was like, okay, man, you can have the other one.
So this, this is our paranoia. Now we've defeated the supply chain attack, right? Nobody, even if they planted a spy acting as the salesman in that store that day, would have been able to give us a backdoored computer. That's our hope. And at the same moment, around the world in 5 other places, 5 other people are doing the same thing.
They're going into random stores and demanding a specific computer and walking out with it. So once we bought the computer, I was married to that thing, and I carried it around in my arms and didn't let it out of my sight. Or my like physical contact for like 24 hours, or well, it ended up being 48 because that was like day 1, buying the computer and then driving around and finding a hotel that had good internet. At this, we basically failed. We couldn't find a hotel that had good internet.
We went from hotel to hotel. It's a tough task. And we finally like, oh fuck, we'll just use this one. Um, so we were stuck in a hotel with bad internet and, um, And the next day, and I slept with the computer like under my arm, and the next day we set up, the next day was like Saturday, I think, Saturday morning, we set up continuous video cameras, and we had actually, this was fun, but I'm never gonna do this again because it was way too stressful. We had weeks earlier secretly gone to a, um, security hardware store in Denver, you know, like that sells alarm systems, right, and stuff.
And we had found the only multi-camera video camera system that doesn't have Wi-Fi. It doesn't plug into the internet, right? Um, you know, closed circuit. It was old. It was like, you know, used, many years old.
So we bought that thing. For like $800 because I didn't— you know, we're being— we're overdoing it on the paranoia here. I don't want to have to wonder if someone hacked the video cameras in addition to everything else that we've got going. So we have the— we have this non-internet-enabled continuous video cameras, and we, we tape them to the walls or set them on tripods or whatever in the hotel room that we're in so that they're pointing at each other. So we have a continuous recording showing that no ninjas slunk in and tampered with one camera and then tampered with the other camera because they're recording each other.
And then I slept under that thing that night under continuous video surveillance. Um, and then we set up what's called the compute node The compute node is the thing that I bought from the store and then didn't let out of my sight. So then we open it up and we don't turn it on. Instead, we unscrew the case and we take out the radios, like the Bluetooth and Wi-Fi chips come out, and the hard drive comes out. So now it can't boot except from DVD media, and because we have this pre-built append-only DVD.
And this is another layer of security or monitoring here, is if any attacker was surreptitiously backdooring the whole process and they had inserted a backdoor into the software that we were going to run during the ceremony, well, that software got burned onto this append-only DVD. That's the only way you can boot the computer is from that append-only DVD, and so then we have evidence ex post facto that we can study the laser image on the DVD in order to determine if we think there's a backdoor in there.
Where was I? So then we've got this air-gapped machine, the compute node, that's never been plugged into the internet in its entire life. It was bought at random off the shelf, so we don't think the CIA or whoever inserted a backdoor into it. North Korean government. Or, you know.
Yeah, right. So yeah, again, back then I really did not believe that any attacker would even try to attack this process. Yeah, much less I figured any attacker would be completely stymied by like the— any one of the layers of defense, like the 6-part thing where there's 6 different stations. Okay, they're already gonna give up right there. They have no idea what's going on, or the fact that the computer's air-gapped.
Okay, that already means they cannot just pop the computer using their remote exploit, right? So that already just basically ends the whole arsenal of any random attacker. So that was what we were thinking. But why not? We get overboard with the append-only DVDs, and then we started doing the actual key generation process where each of the 6 computers in turn generates random numbers, produces a shard of the resulting public key, and then deletes their random numbers out of memory.
And that's the part that took more than 24 hours by itself. That was exhausting, because this is the critical moment once we've— I didn't explain this part yet, but it was a multi-round protocol. Okay, so you have to generate your random number, which is the precursor. It's the sensitive information that you must ensure that no attacker gets access to it, and you must ensure that it was generated truly randomly so that no attacker could have guessed it or forced it to go to a certain answer, right? That's the sensitive bit, the precursor.
You got to generate that in your air-gapped machine, then you've got to generate a some public key material. Then you've got to transport that public key material across the air gap to the other 5 stations in turn, and then it comes back to you and you have to do another round, another computation using your same precursor. So during that period, that 27-watt-hour period, that's when we had to have maximum vigilance on the machine because it had the secret in it. And if anybody were able to compromise the machine during that 27-hour period, they could get the secret out, right? So that's the part that I'm never going to do again.
Um, I did sleep, but only because I had these continuous cameras on me and on the computer while I slept. And I, I think we, we sort of talked about it, but I think we buried the lead a little bit in that the reason that you had to do this is because that that secret that you're generating, if someone has it, then they can essentially counterfeit Zcash. Exactly, yeah. This is the terrible thing. This is the scary scenario, is if anyone got all 6 of the precursors, they can mix them together to form the toxic waste secret.
And what you can do with that— it's really important that you cannot violate anyone's privacy with I've always got to hammer that home because people easily get confused. And it's kind of ironic because the whole point of our design is to make the privacy completely mathematically guaranteed. That's where the zero-knowledge proofs allow— how do I put this? Remember how zero-knowledge proofs prove the correctness, right? Right.
Once you have this proof of the correctness, Now you can use the strongest mathematical technique to guarantee the privacy. And the zero in zero-knowledge proof means that it leaks nothing about your privacy.
It leaks zero knowledge about the private inputs to the verifier. So the whole point of this system is that it's the strongest way science currently knows to guarantee privacy in this kind of mathematical structure. And the unfortunate trade-off is that therefore you risk counterfeiting. Okay? So it really annoys me when people sloppily or mistakenly think that the toxic waste is a threat to people's privacy.
It's the opposite. The mathematics guarantees the privacy, and in order to achieve that, we had to suffer the risk of the toxic waste violating the counterfeiting. Yeah. But anyway, that's why we went to all that effort, is to make— is to not only— not only to make sure that nobody got the toxic waste, but also to provide evidence that we could then offer to other people. So why they should have confidence in that, right?
Because other people need to decide if they think it's safe enough that they can hold Zcash, whether they think there's a risk that the toxic waste has been secretly stolen and that then Zcash could be counterfeited. If that happened, then the price of Zcash would go down, right? Once the counterfeiters started using his counterfeit coins. So therefore we wanted to— that's why we went to all the effort of documenting it with the videographers and the journalists. Each of the other participants also documented their own with various narrative storytelling, photographs, independent witnesses, like a testimony, like, I did the following things, in order to let people have evidence of what had occurred.
So should I go into the bizarre part? Well, so I'd say if people want the, you know, the part that you're alluding to there, I'd say go listen to that Radiolab podcast. Yeah, there's a great story by Radiolab about then what went wrong. And that one was an especially great episode. So Yeah, uh, go check that one out.
I don't remember the episode number, but it is called The Ceremony. That's right. It's very easy to find and a great story. Um, it was funny, I actually, uh, switching gears slightly, I heard this week about a Telegram vulnerability. Telegram, the messaging application.
And one of the things that they were using, using the vulnerability to was to install miners on people's computers. And one of the miners that they were installing was a Zcash miner. Really? I did not hear this story yet. And so, and while it's an interesting story, the question that I wanted to talk to you about is, what do you— how— what's your feeling about how Zcash is used?
Right. So you've done a great job of implementing privacy. So you, you eliminate some of the shortcomings of Bitcoin, but then now you have the ability to be more private in how you use it. So, you know, you may attract more criminal elements or, you know, other things like that that are, that are using Zcash. Is that something that you're concerned with?
You know? Yeah.
I'm really concerned about it because there's a mistaken narrative that people could fall into, especially journalists and regulators and people who aren't like deep tech people.
They already did this with Bitcoin and then they somehow got past it. I don't want them to do the same thing with Zcash. Is associating it with crime. Because for a long time, Bitcoin was just— right, it just meant crime. Yeah, to, to, to, like, to, to we techies and like early adopters, we were like, no, no, no, it's not about crime, it's about global financial independence and fairness and openness and all these other values.
But to a lot of people who didn't have that perspective and that background, for several years the only thing they knew about it was it was like criminal money, right? And then eventually it grew out of that to where those people found out there were other purposes and other consequences of the technology and other users than criminals. Now, so far Zcash has actually been a lot luckier than that in this sense because criminals have not adopted Zcash very much. Like your story about But someone installing a Zcash miner on other people's computers illicitly, that's new to me, and it's one of the rare examples of criminals using Zcash for anything so far. There are a couple, but not very many.
I mean, obviously criminals use the fiat money system more than anything. But 99.8% of all criminal activity is done with normal old bank accounts and dollar bills and everything like that. But out of the 0.2 or whatever percent that's done with new technology, almost all that's still Bitcoin. I actually read a report on this recently where some investigators, they kind of surveyed the dark markets, but they did 2 methods, which I appreciated. First, they like read all the chatter, all the web forums where the dark market users were advocating for what kinds of cryptocurrencies they thought should be used.
Yeah. But then second, they actually went and studied the listings of who was actually offering to buy and sell stuff in what currencies and compared that to the chatter.
And Zcash doesn't appear in the results. Rather to my surprise, I think the— well, rather, not to my surprise, the current most common used cryptocurrency for dark markets is still Bitcoin, but it's rapidly falling. I don't know if those users realize how dangerous it is for them to use Bitcoin. Because of its pervasive lack of privacy, or if they're just abandoning it because the transaction fees skyrocketed for a while. Yeah.
But they're switching to Ethereum, Litecoin, Monero, and Dash. So do you think that there's a reason why they haven't moved to Zcash yet? Is it just— that's a good question— knowledge? Is it coincidence?
I don't know. Part of it might be like branding, you know? Like, we have always worked hard to point to the law-abiding use cases for Zcash. Like, a lot of nonprofits accept donations in Zcash, and they're like, you know, legit nonprofits. They're not like counterculture underground things.
They're like just— donors like their privacy, and nonprofits like to accept donations when they can, and so a lot of them accept Zcash.
And we made this partnership with JPMorgan, which is the most valued bank in the world according to the stock markets, and probably one of the most hated institutions in the world according to Bitcoiners.
And we emphasized all along that privacy is necessary not only for civil liberties and free political decisions and political discussion, um, and human— like, human dignity and making moral choices. Because when you are alone with yourself, that's when you can really choose what you believe is right and choose to live with it. But we've always argued not only is privacy important for these well-understood social and human rights reasons, but it's also necessary for commerce. So that's why we made that deal with JP Morgan is so we can point to them as an example of a completely boring, non-revolutionary, profit-oriented enterprise that just needs encryption so that they can do their business successfully and make money. So, so what does that partnership look like?
What are they— they're not using Zcash, the actual cryptocurrency. That partnership is just that they're using the technology to add that encryption-based privacy to their enterprise blockchain. Got it. But that, that satisfies that satisfies the example of demonstrating that privacy is necessary for business. Anyway, you were asking why don't criminals use Zcash more?
Yeah. And I don't know, maybe better marketing and better buzz for the others that I mentioned, but also because we've always branded Zcash as like the family-friendly, business-oriented mainstream kind of privacy.
So maybe that seems reasonable. Maybe that caused them to be less— to hear about it less often or whatever. Yeah, I don't know. Um, yeah, so I have also heard recently about, um, attempts by, by governments to, to more to try and regulate cryptocurrencies, either, you know, you know, outlawing them altogether in a country, or, you know, some less stringent measures. Oh yeah.
What's your thought about the sort of the government regulation aspect? Oh, um, it's really interesting how the different governments of the world are diverging in their approach, doing very different things. Like, um, Like, China is one of the most important markets for cryptocurrencies. It was the one of the, the biggest sources both of money, of people putting money into the different cryptocurrencies and tokens, and also of technological innovation in the whole scene for years. And then the government of China is now trying to ban cryptocurrencies entirely from the country.
So that's a pretty extreme, and it'll be interesting, it's a pretty extreme position, and it'll be interesting to see what happens. Like, first of all, if they're successful in stamping it out, or how successful they are, or what kind of sort of, if it evolves within their borders in response to that. Pressure, but also if they observe the other governments that are instead trying to integrate it and promote it, and if they start thinking, oh wait, maybe our competitors are profiting and benefiting by doing the opposite of what we did, then they might— that'll be interesting to see if they reconsider. But the US is actually right now one of the best, rather to my surprise actually.
No offense to any US government regulators that are listening, but I really did not expect them to be as open-minded and balanced in their approach as they are, in fact. But they spent years and years learning about the technology, including me and the other members of the Zcash team flying around to United States regulators in Washington, D.C. and New York, and just teaching, like giving lectures about the technology. Because, you know, knowledge is the number one antidote to fear, right? As soon as you think it makes sense and you can understand how it works, you immediately become a lot less anxious about a thing.
Yeah, so the United States, there's— it's not perfect, but it seems to be heading in the right direction in terms of regulation. Yeah, like the current leading regu— like, there's one thing that's bad about the United States system is that there are a big patchwork of regulators who have authority over different parts, and sometimes there's multiple regulators who have authority over the same part. Like, if you want to do a money transmission business in the United States, you literally have 50 or 53 different regulators, and you have to get a prior approval from all of them before you can start your business. Literally, that's like the way it works. That's like, ugh.
And also, with a new weird thing, you know, Bitcoin and Zcash are like, It's like the blind men and the elephant where no one can quite agree on what it is in the first place. So some regulators say, oh, this is a commodity, and others say this is a currency, and others say this is money. The bond nation. Yeah.
But so that's the problem with the United States is it's such a complicated system of who's responsible for what. However, in fact, all of the regulators who are responsible for regulating cryptocurrencies in the United States have done a pretty reasonable job. The worst is the IRS, which made a totally reasonable-sounding decision, but it completely screws everything up, which is that they said, we're going to tax cryptocurrencies like property, which means If you write a computer program for someone in like a piecework job or a contracting job, and they send you like $5,000 worth of Bitcoin in payment for that, and then you go online and you buy like a cool t-shirt and you send them like $15 worth of Bitcoin for the t-shirt, now since we're treating it like property, This is as if you like bought a chunk of land for $5,000 and then you sold a little slice of it for $15 to someone else. You have to calculate the difference in the current market value of the thing at the day you bought it versus the day you sold it and like subtract the difference and then pay us taxes on the difference. Which I can see how that would kind of make sense from some perspectives, but it is completely the opposite of making it usable as currency, right?
It makes you happy if you're a tax preparer, but that's about it. So that's like an example of a reasonably well-intentioned but completely terrible rule in the United States system. But most of the other rules are even much better than that. Yeah. So on your point about the, uh, the blind man and the elephant, you know, on blockchain more generally, I'm starting to see, you know, everybody and their mother starting to pop up with, oh, hey, we're a company that's going to do blockchain for X, you know, for, for medical, for, for cybersecurity, for this, for that.
You know, my day job is in the mortgage industry, and there's all kinds of talk about how blockchain is going to solve every possible problem. In the mortgage industry. What's your thoughts on that in general and how likely it is that blockchain will take off and help in some of these areas or maybe even hurt in some of these areas? That's a really good question. You know, my main— so I agree with you, there's a lot of that and with your implicit skepticism that it hasn't really been proven out yet.
So I'm becoming a little bit discouraged because it's been, I guess, almost 3 years since that hype started. Yeah. And so that's basically long enough that you ought to be delivering something. Like by now, people, you ought to have some customers who are like saving a ton of money every month. And then your other customers ought to be saying, whoa, look at them saving all that money.
I'm going to do some of that and I'm going to save that money. And then this should be really like taking off, and it's not. So the question is, why not? Is this just all a bad idea that never made sense in the first place? Is there some like level of completion of the product that we need before we can get to that stage of more and more value?
It could be that privacy is the answer. Yeah, I've heard that from the financial industry. I haven't really talked to the, like, healthcare and mortgage and other industries. I don't know what their current story is about whether that's a blocker or what their solution is to it. That's why JP Morgan partnered with us, is that the financial industry— and we're talking like more than a year ago when we started that project— the financial industry at that time was sort of having a dawning realization that the blockchain projects they had embarked upon were all facing a showstopper of the privacy— the private information about the data leaking to unauthorized parties who are users of the blockchain.
So, that was why we did that with JPMorgan, was say, oh, well, we'll solve that blocker and then see if now they this leads to real business traction. I haven't seen it yet, so.
We're continuing to work with JP Morgan to improve their enterprise blockchain, which is called Quorum. It now has this encryption feature, it has smart contracts, it's open source, so anyone can use it for anything.
So we're doing another round of grinding. You know, in the entrepreneurship world, there's the pivot and then there's the grind, right? And these are 2 things that you— 2 different alternatives you might take when your current attempt doesn't really seem to be working.
So I guess, you know, for us, for the Zcash company, we've been working on the Zcash Open Currency, and that's totally working super well, so we're just more and more resources and ambition is pouring into improving Zcash. But with our enterprise arm and our partnership with JPMorgan, what we're currently doing is grinding. We're going to keep making that product better and better, you know, just more efficient and have more flexibility and such, and then see if it does meet someone's business use case in it takes off. Nice. That sounds pretty cool.
So I feel like we're— we've still barely scratched the surface, but we're already coming up on an hour. Hmm. So I think I'll probably start wrapping this up. But if somebody wants to know more about Zcash, get involved in Zcash, maybe even just cryptocurrency in general, Any resources that you would point folks to? The Zcash website, which has got a great domain name, it's z.cash.
Nice. I didn't realize that there was a .cache subdomain. Yep. Me neither. Top-level domain, I mean.
Yeah, me neither until I found somebody offered me z.cash. That's awesome.
There is also the Zcash Foundation. Okay, its domain name is z.cash.foundation. You didn't know there was a .foundation either, did you? That one at least I think makes more sense, right? Yeah, but, but yeah, um, the Zcash Foundation is the first ever public charity devoted to improving the public good with cryptocurrencies.
Oh, that's awesome. So that's a good resource for like science basically at this point. They're, they're a bunch of scientists and educators, and so they're definitely a good place to look too. Awesome. Well, thanks, Zooko.
I appreciate the conversation. This has been a lot of fun. Yeah, thank you. We'll have to do it again and, and keep exploring down the rabbit hole. Yeah, for sure.
And, uh, this has been Alex Wood with Colorado Equal Security, and we will talk to you all next time. Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.