Jul 28, 2017 · 15m · a16z

Raluca Ada Popa

Raluca Ada Popa · 13m spoken
0:00 / 0:00
▶ Watch on YouTube →

gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions

At the Andreessen Horowitz Academic Roundtable, UC Berkeley professor Raluca Ada Popa presents BlindBox, a breakthrough system that enables deep packet inspection over encrypted HTTPS traffic without sacrificing user privacy. She also highlights the broader technological shift toward computing on encrypted data across enterprise systems like CryptDB and major cloud services.

How this conversation actually went

Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. How this is scored →

The host as informed peer 0.0 Guest teaching 6.0 Guest disagreement 0.0 The host pushing back 0.0
05100:0010:000:42–4:10 · The host as informed peer 0/10 Background on Deep Packet Inspection The guest presents an academic talk explaining Deep Packet Inspection and how current SSL middlebox workarounds rely on insecure man-in-the-middle attacks. The host only offers a brief check-in ('Ok?'), resulting in zero host expertise or pushback.4:10–6:37 · The host as informed peer 0/10 Introducing the BlindBox Solution Popa introduces BlindBox's threat model and security goals, balancing user privacy with middlebox payload inspection. The host remains entirely passive during the monologue.6:37–9:51 · The host as informed peer 0/10 BlindBox System Design Overview Popa educates the audience on searchable encryption, contrasting fast deterministic schemes with secure randomized schemes. She explains how BlindBox achieves both via AES hardware instructions and salt schedules.9:51–12:38 · The host as informed peer 0/10 Fast Detection Protocol and Handshake The guest details how secure two-party computation allows encrypted rule matching during the SSL handshake without exposing keys or rules. Performance metrics comparing BlindBox to Snort are presented.12:38–15:29 · The host as informed peer 0/10 Broader Vision: Computing on Encrypted Data Popa expands the talk to the wider paradigm of computing on encrypted data, highlighting CryptDB, Myler, and commercial adoption by companies like SAP and Microsoft.15:29–15:38 · The host as informed peer 0/10 Conclusion and Q&A Transition Popa concludes her presentation by emphasizing that privacy and functionality can co-exist in modern software systems before opening for Q&A.0:42–4:10 · Guest teaching 6/10 Background on Deep Packet Inspection The guest presents an academic talk explaining Deep Packet Inspection and how current SSL middlebox workarounds rely on insecure man-in-the-middle attacks. The host only offers a brief check-in ('Ok?'), resulting in zero host expertise or pushback.4:10–6:37 · Guest teaching 6/10 Introducing the BlindBox Solution Popa introduces BlindBox's threat model and security goals, balancing user privacy with middlebox payload inspection. The host remains entirely passive during the monologue.6:37–9:51 · Guest teaching 7/10 BlindBox System Design Overview Popa educates the audience on searchable encryption, contrasting fast deterministic schemes with secure randomized schemes. She explains how BlindBox achieves both via AES hardware instructions and salt schedules.9:51–12:38 · Guest teaching 7/10 Fast Detection Protocol and Handshake The guest details how secure two-party computation allows encrypted rule matching during the SSL handshake without exposing keys or rules. Performance metrics comparing BlindBox to Snort are presented.12:38–15:29 · Guest teaching 6/10 Broader Vision: Computing on Encrypted Data Popa expands the talk to the wider paradigm of computing on encrypted data, highlighting CryptDB, Myler, and commercial adoption by companies like SAP and Microsoft.15:29–15:38 · Guest teaching 4/10 Conclusion and Q&A Transition Popa concludes her presentation by emphasizing that privacy and functionality can co-exist in modern software systems before opening for Q&A.0:42–4:10 · Guest disagreement 0/10 Background on Deep Packet Inspection The guest presents an academic talk explaining Deep Packet Inspection and how current SSL middlebox workarounds rely on insecure man-in-the-middle attacks. The host only offers a brief check-in ('Ok?'), resulting in zero host expertise or pushback.4:10–6:37 · Guest disagreement 0/10 Introducing the BlindBox Solution Popa introduces BlindBox's threat model and security goals, balancing user privacy with middlebox payload inspection. The host remains entirely passive during the monologue.6:37–9:51 · Guest disagreement 0/10 BlindBox System Design Overview Popa educates the audience on searchable encryption, contrasting fast deterministic schemes with secure randomized schemes. She explains how BlindBox achieves both via AES hardware instructions and salt schedules.9:51–12:38 · Guest disagreement 0/10 Fast Detection Protocol and Handshake The guest details how secure two-party computation allows encrypted rule matching during the SSL handshake without exposing keys or rules. Performance metrics comparing BlindBox to Snort are presented.12:38–15:29 · Guest disagreement 0/10 Broader Vision: Computing on Encrypted Data Popa expands the talk to the wider paradigm of computing on encrypted data, highlighting CryptDB, Myler, and commercial adoption by companies like SAP and Microsoft.15:29–15:38 · Guest disagreement 0/10 Conclusion and Q&A Transition Popa concludes her presentation by emphasizing that privacy and functionality can co-exist in modern software systems before opening for Q&A.0:42–4:10 · The host pushing back 0/10 Background on Deep Packet Inspection The guest presents an academic talk explaining Deep Packet Inspection and how current SSL middlebox workarounds rely on insecure man-in-the-middle attacks. The host only offers a brief check-in ('Ok?'), resulting in zero host expertise or pushback.4:10–6:37 · The host pushing back 0/10 Introducing the BlindBox Solution Popa introduces BlindBox's threat model and security goals, balancing user privacy with middlebox payload inspection. The host remains entirely passive during the monologue.6:37–9:51 · The host pushing back 0/10 BlindBox System Design Overview Popa educates the audience on searchable encryption, contrasting fast deterministic schemes with secure randomized schemes. She explains how BlindBox achieves both via AES hardware instructions and salt schedules.9:51–12:38 · The host pushing back 0/10 Fast Detection Protocol and Handshake The guest details how secure two-party computation allows encrypted rule matching during the SSL handshake without exposing keys or rules. Performance metrics comparing BlindBox to Snort are presented.12:38–15:29 · The host pushing back 0/10 Broader Vision: Computing on Encrypted Data Popa expands the talk to the wider paradigm of computing on encrypted data, highlighting CryptDB, Myler, and commercial adoption by companies like SAP and Microsoft.15:29–15:38 · The host pushing back 0/10 Conclusion and Q&A Transition Popa concludes her presentation by emphasizing that privacy and functionality can co-exist in modern software systems before opening for Q&A.

speaking balance: gold is the host, purple is the guest (3 minute bins)

0:00 · the host 0% · guest 100%0:00 · the host 0% · guest 100%3:00 · the host 0% · guest 100%3:00 · the host 0% · guest 100%6:00 · the host 0% · guest 100%6:00 · the host 0% · guest 100%9:00 · the host 0% · guest 100%9:00 · the host 0% · guest 100%12:00 · the host 0% · guest 100%12:00 · the host 0% · guest 100%15:00 · the host 0% · guest 100%15:00 · the host 0% · guest 100%
Sharpest disagreement ▶ 3:10 Critique of standard SSL middleboxes

The guest forcefully critiques current industry practices as an embarrassing and insecure man-in-the-middle attack that destroys SSL security guarantees.

Hardest push from the host ▶ 3:41 Moderator audio/flow check

The host/moderator merely interjects a brief 'Ok?' to signal following along, representing the only host participation.

Biggest teaching moment ▶ 7:00 Demystifying searchable cryptography trade-offs

Popa educates the listener on the core technical dilemma between fast deterministic encryption and secure randomized encryption.

The host holds their own ▶ 10:00 Detailing secure 2-party computation protocol

Popa demonstrates deep cryptographic authority when explaining how secure two-party computation resolves the rule-privacy dilemma.

the scores for every segment, with the reasoning behind each
ChapterTopicThe host as informed peerGuest teachingGuest disagreementThe host pushing backWhy
Background on Deep Packet Inspection 0600 The guest presents an academic talk explaining Deep Packet Inspection and how current SSL middlebox workarounds rely on insecure man-in-the-middle attacks. The host only offers a brief check-in ('Ok?'), resulting in zero host expertise or pushback.
Introducing the BlindBox Solution 0600 Popa introduces BlindBox's threat model and security goals, balancing user privacy with middlebox payload inspection. The host remains entirely passive during the monologue.
BlindBox System Design Overview 0700 Popa educates the audience on searchable encryption, contrasting fast deterministic schemes with secure randomized schemes. She explains how BlindBox achieves both via AES hardware instructions and salt schedules.
Fast Detection Protocol and Handshake 0700 The guest details how secure two-party computation allows encrypted rule matching during the SSL handshake without exposing keys or rules. Performance metrics comparing BlindBox to Snort are presented.
Broader Vision: Computing on Encrypted Data 0600 Popa expands the talk to the wider paradigm of computing on encrypted data, highlighting CryptDB, Myler, and commercial adoption by companies like SAP and Microsoft.
Conclusion and Q&A Transition 0400 Popa concludes her presentation by emphasizing that privacy and functionality can co-exist in modern software systems before opening for Q&A.

Statements from this episode (17)

Assertion Supported
Popa: BlindBox inspects encrypted traffic while maintaining user privacy
“So I'm going to tell you about some very recent work on Blindbox, which enables us to inspect traffic that remains encrypted and protect the privacy of the users.”
Raluca Ada Popa Jul 28, 2017 ▶ 0:14
Prediction Not checkable as stated
Popa: Computing on encrypted data will significantly impact industry
“And then I'm going to scope out from this and tell you about a bigger vision that Blindbox is part of, namely Computing on encrypted data, which I think can have a lot of impact to industry and to what people use today.”
Raluca Ada Popa Jul 28, 2017 ▶ 0:25
Opinion
Current HTTPS middlebox workarounds rely on man-in-the-middle attacks
“And actually, the solution is very embarrassing and insecure solution. People basically mount a man in the middle attack on SSL.”
Raluca Ada Popa Jul 28, 2017 ▶ 3:04
Assertion Supported
Popa: BlindBox is first system enabling DPI on encrypted traffic
“Our system blind box is the first to show that this could be possible, and is the first system that enables DPI middle boxes to inspect traffic without seeing the traffic.”
Raluca Ada Popa Jul 28, 2017 ▶ 4:22
Assertion Supported
Popa: Microsecond Network Speeds Severely Limit Usable Cryptography
“Network rates are on the order of microseconds, so not a lot of cryptography remains that could be used in this setting.”
Raluca Ada Popa Jul 28, 2017 ▶ 6:04
Assertion Supported
Raluca Ada Popa: BlindBox HTTPS operates without altering core SSL primitives
“What we build in Blindbox is an enhanced version of HTTPS called Blindbox HTTPS. And with Blindbox HTTPS when a user sends a message the user gets the message gets encrypted through SSL as before, so we don't change SSL.”
Raluca Ada Popa Jul 28, 2017 ▶ 6:38
Assertion Supported
Popa: BlindBox encryption matches security of randomized and speed of deterministic schemes
“So as part of Blindbox, our first contribution was to construct such a scheme. A scheme that is as secure as randomized schemes, and as fast as deterministic schemes.”
Raluca Ada Popa Jul 28, 2017 ▶ 8:34
Assertion Partly supported
Popa: BlindBox encryption operates at network rates using hardware AES
“And third is that actually it's fast. It can run at network rates, because it only uses AES, and we have AES instructions in hardware.”
Raluca Ada Popa Jul 28, 2017 ▶ 9:39
Assertion Supported
BlindBox uses secure two-party computation during SSL handshake for encrypted rule generation
“So for this, we use really cool primitive from the crypto community, namely secure two-party computation, which enables the middle box and the user during the SSL handshake to produce this encryption scheme to get this encryption encrypted value together witho…”
Raluca Ada Popa Jul 28, 2017 ▶ 10:18
Assertion Partly supported
Popa: BlindBox middleboxes learn only matching malicious string locations
“The middle box learns only if a malicious string matches at some location, but it doesn't learn anything else about the other locations.”
Raluca Ada Popa Jul 28, 2017 ▶ 10:47
Assertion Partly supported
Popa: BlindBox equality matching supports watermarks, filtering, and IDS rules
“Only the equality part that I told you about can support already watermarks, checking if exfiltrated documents contain watermarks, and parental filtering, and a bunch of the IDS rules.”
Raluca Ada Popa Jul 28, 2017 ▶ 11:14
Assertion Supported
Popa: BlindBox detection speed is competitive with Snort
“So the detection of the middle box is competitive to Snort.”
Raluca Ada Popa Jul 28, 2017 ▶ 11:48
Assertion Supported
Popa: BlindBox increases page load time by 15% to 100%
“In terms of the transmission time, we increase it so page load time would become 15% to a hundred percent slower.”
Raluca Ada Popa Jul 28, 2017 ▶ 11:51
Assertion Partly supported
CryptDB achieved 27% overhead compared to MySQL on TPCC benchmark
“So for industry standard benchmarks such as TPCC, CryptDB had an overhead of 27% compared to MySQL.”
Raluca Ada Popa Jul 28, 2017 ▶ 13:02
Assertion Not yet assessed · timeframe Jul 2020
Popa: Google Encrypted Query is based on CryptDB
“Google's encrypted query is based on CryptDB.”
Raluca Ada Popa Jul 28, 2017 ▶ 13:20
Assertion Supported
Popa: A Boston hospital uses Myler for medical applications
“And actually a hospital in Boston is currently using Myler in one of their medical applications.”
Raluca Ada Popa Jul 28, 2017 ▶ 14:18
Insight
Popa: Computing on encrypted data eliminates the confidentiality-functionality trade-off
“But the bottom line that I want to mention is that computing on encrypted data can be practical for a set of systems that we use today. And it really gives you, at the same time, confidentiality and functionality. So you don't have to choose only one anymore.”
Raluca Ada Popa Jul 28, 2017 ▶ 14:59
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 1,000 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.