[00:01.800 --> 00:04.580] Welcome to BitPart. [00:05.060 --> 00:08.200] Well, like you said, five-in-one platform for activism over signal. [00:11.340 --> 00:12.300] Who am I? [00:12.600 --> 00:15.940] I am, well, Josh King. [00:16.160 --> 00:18.840] I'm a senior software engineer at ThroneList Tech. [00:19.000 --> 00:30.900] ThroneList Tech is a worker cooperative that develops software and does digital security trainings for activist groups and nonprofit organizations. [00:30.920 --> 00:33.360] and community organizations in the Washington, D.C. area. [00:36.820 --> 00:37.920] What is BitPart? [00:38.460 --> 00:40.940] So BitPart is a tool that we developed. [00:41.240 --> 00:44.100] It's a one-to-many messaging tool that plugs into signal. [00:44.340 --> 00:48.580] It's designed with human rights defenders and journalists operating in repressive environments. [00:49.040 --> 00:53.120] It's intended for anyone needing to communicate with a large network safely over signal. [00:53.440 --> 01:05.880] I'm going to talk a little bit about what led us to developing BitPart, some of the research that went into its design and then talk through some of the technical specifics of how BitPart works. [01:07.660 --> 01:10.640] So BitPart didn't come from nowhere. [01:12.560 --> 01:19.880] Way back in 2018, myself and a friend of mine came up with the idea of... [01:20.500 --> 01:24.900] This was pre-signal usernames and things like that. [01:25.060 --> 01:47.960] Came up with the idea of how we might use mass messaging over signal in the event of, say, some sort of protest action or something where one of the members of a protest action, everyone is on a signal group, and one of the devices got lost or compromised or taken by the authorities. [01:48.180 --> 01:49.860] And then the... [01:49.860 --> 01:51.960] The social graph of that group is then exposed. [01:53.260 --> 01:59.520] So we came up with this idea that we called Ionosphere for bouncing signals off of stuff. [02:00.220 --> 02:18.100] And Ionosphere was sort of an ugly hack to take some of the components out of a signal desktop, build a JavaScript library around it in order to facilitate building JavaScript tools that could... that could interact with signal. [02:20.700 --> 02:22.640] And then creating a... [02:26.720 --> 02:27.360] Okay. [02:27.360 --> 02:39.020] Creating a tool that would basically be a bot that would relay messages from one or more organizers to a large group of individual protesters one-to-one. [02:39.300 --> 02:41.060] So that if any... [02:41.060 --> 02:50.020] Any one device got taken, they would only know about the throwaway burner number of the bot, and they wouldn't know about all of the other members of that group. [02:50.440 --> 02:51.880] So that was the general idea. [02:51.880 --> 02:51.980] Any idea. [02:53.820 --> 02:56.580] With Ionosphere, like I said, it was kind of an ugly hack. [02:57.520 --> 02:59.040] And the... [03:03.100 --> 03:06.780] Fast forward about 20... Like to about 2021... [03:08.120 --> 03:10.520] Signal desktop was undergoing a major rewrite. [03:10.880 --> 03:12.720] I was working on this in my spare time. [03:13.260 --> 03:19.040] And it became just kind of unmaintainable to try and keep the pretty complex... [03:19.040 --> 03:30.540] Complex Signal libraries that I had pulled out of Signal desktop in sync with all the things that were going on with the Signal protocol and with the desktop client. [03:31.360 --> 03:46.640] So ultimately, I sort of ended up treating that as an unfortunate dead end and went on to... then, don't ask what I was doing during that one year, hopefully I was taking a nap or something. [03:48.180 --> 04:09.220] And we basically decided that it's time to take a step back, design it properly, and assemble a team, start fundraising to basically create the proper maintainable version of this tool. [04:10.420 --> 04:29.020] So in order to do that, we launched a wide-ranging international user research project in order to determine, like, what do activists, journalists, human rights defenders, what do they need from tools running over Signal? [04:29.180 --> 04:34.020] How do they, like, use messaging as part of their day-to-day activist work? [04:34.180 --> 04:44.580] And so we engaged 28 activists, journalists, tool builders, and support organizations across 11 different countries throughout Africa, Asia, Europe, Latin America, America, and the U.S. [04:44.820 --> 04:45.700] We interviewed them. [04:45.980 --> 04:48.520] We talked with them extensively. [04:49.100 --> 05:04.180] We got... basically compiled a full research report about all of the... all of the insight that they were able to provide into exactly what they needed from their messaging tools in order to facilitate their work. [05:05.840 --> 05:10.740] And that sort of forced us to take a step back to, like, why build a messaging tool? [05:11.280 --> 05:16.660] Well, messaging is an integral part of all of our lives, obviously, now. [05:17.340 --> 05:31.780] But activists, like, use messaging as part of their day-to-day organizing, but that stretches beyond their day-to-day organizing to all of their interactions that they might have during the day. [05:31.900 --> 05:34.540] Most of them aren't using, like, separate devices and separate accounts. [05:34.660 --> 05:50.280] A lot of times they're in many different groups, some of which might be related to their activist activities, and some of which might just be family or friends or work groups or other sorts of communication channels that they might be using messaging for. [05:50.640 --> 05:56.480] So they're in many different groups with people that they know personally, and with people that they don't know at all. [05:56.880 --> 06:01.280] And what we found is that the... which... [06:02.380 --> 06:14.360] is that some of the largest groups are the ones with the least activity, but are some of the most valuable for, like, getting information updates about particular actions and activities. [06:14.780 --> 06:32.860] And by building a messaging tool, we can meet people where they are by building something that runs over top of a tool that they already have, and not ask them to install another app on their phones, which is a pretty high bar for engaging with a lot of people. [06:34.480 --> 06:36.320] You might also ask, why Signal? [06:36.760 --> 06:39.600] Well, Signal is increasingly a critical tool for online organizing. [06:39.760 --> 06:50.020] If you're engaged in any kind of community organizing or other sorts of organizing, you probably either use Signal or you, you know, interact with somebody who uses Signal. [06:50.640 --> 06:53.440] It has a large increasing user base. [06:53.720 --> 07:02.220] It's thought that has somewhere between 70 and 100 million users right now, with nearly 300 million downloads. [07:04.260 --> 07:09.580] The... it has a solid reputation for good reason as a safe place for secure communication. [07:10.540 --> 07:15.560] And because it's a complex protocol, there's a relative lack of messaging tools running over Signal. [07:15.740 --> 07:16.740] There aren't none, of course. [07:16.880 --> 07:24.440] There are a bunch of projects, but there are fewer than the sorts of tools that run over some other messaging protocols. [07:24.800 --> 07:33.000] And so, there's a needs gap that we can fill there by creating tools and making it easier to build tools that operate over Signal. [07:35.520 --> 07:40.120] We found that Signal usage varies globally. [07:40.400 --> 07:46.920] In some places, like Hong Kong, Signal is kind of the default for for, for activists. [07:47.140 --> 08:03.180] And it provides a kind of a collective shielding effect in that it's so common that it isn't taken as unusual that you might have Signal installed on your device. [08:03.500 --> 08:11.040] But in other places, what's app is often like the de facto messaging clients. [08:11.560 --> 08:19.120] And Signal is just used for, for very confidential conversations. [08:19.600 --> 08:29.220] And in, in some locations, Signal is, in some countries, Signal is associated with spying or crime. [08:29.520 --> 08:37.880] And so even just having Signal installed on your device could be reason for suspicion if you are stopped and your device is inspected. [08:38.740 --> 08:55.500] Likewise, Signal can be risky in some places or even just not usable because even with the circumvention support that you can activate in Signal settings, that isn't a 100% proof against blocking. [08:55.860 --> 09:01.120] And there are many places in the world, like in Russia, where it's often Signal doesn't work. [09:01.240 --> 09:06.780] It just doesn't connect even if you have, like, different circumvention settings enabled. [09:07.380 --> 09:12.120] But it's exactly those risks that are often why people increasingly use Signal. [09:12.420 --> 09:28.860] When the, when there are rumors about another chat service being compromised, or when there's a crackdown on protests, there, these are all reasons why people then, like, end up shifting to Signal because it's perceived greater security. [09:29.740 --> 09:52.080] Through working with these, uh, with these different, uh, activists and journalists and human rights defenders and other folks, uh, we developed five main use cases that are, uh, basically the use cases that Bitpart supports out of the box in order to cover a wide range of possible functions that [09:52.080 --> 09:56.120] might be useful for the different communities that we interacted with. [09:56.620 --> 10:01.220] Uh, first of all is kind of the one that I already alluded to is the broadcast use case. [10:01.880 --> 10:11.660] So, in this, one or more operator sends messages, uh, to a list of users, um, via a chat bot by, via Bitpart. [10:12.020 --> 10:13.860] And users just know about the bot. [10:13.980 --> 10:14.980] They can't see each other. [10:15.640 --> 10:28.140] So, this has a wide range of uses for, um, exactly the kind of thing that I was talking about before, for, um, mass protests, uh, for, um, uh, different kinds of activists. [10:28.280 --> 10:37.820] Even, like, we, we've sometimes, uh, talked to, uh, activists who maybe go to a lot of actions but aren't very involved in organizing. [10:38.120 --> 10:44.740] For them, the challenge is really, like, knowing what's important and getting notifications about the things that are most important for them to know. [10:45.000 --> 10:59.180] And something like Bitpart that can, like, give them just that information, like transmitted by the organizers, transmitted by, um, other activists, is, uh, uh, useful for, uh, for them to be able to sort through that noise. [11:00.260 --> 11:02.580] Um, anonymous tip lines. [11:02.980 --> 11:10.700] So, where an anonymous user or users sends a tip to Bitpart and the, and the bot relays the messages to one or more operators. [11:11.280 --> 11:31.580] So, um, this obviously has applications for journalism or really for anything where you might have a situation where you have a, um, uh, any kind of confidential information that you want to have a secure channel for people to be able to provide, uh, that information to a trusted source. [11:33.180 --> 11:37.200] Um, the, uh, help desk. [11:37.400 --> 11:55.400] So, this is a, uh, uh, a tool where, uh, a user is able to message Bitpart and, uh, get some pre-written, uh, instructions, like, helping them on a particular topic, whether that's digital security, whether that's operational security, whether that is, [11:55.560 --> 12:01.980] uh, even just, like, how do, like, where do I find the local grocery stores or something like that? [12:02.160 --> 12:11.260] The, uh, they get some pre-written advice and if that advice isn't able to, uh, answer their question, it gets relayed to an operator who is then able to contact them. [12:13.600 --> 12:15.840] Uh, VPNs. [12:16.120 --> 12:21.100] Um, the, uh, one thing I forgot to say about the help desk. [12:21.220 --> 12:37.960] We actually talked about, with, um, a number of, like, journalism support organizations that trying to do this kind of, like, um, uh, or, like, human rights support organizations that in order to support, uh, this kind of work, they had people, like, uh, [12:38.500 --> 12:42.220] over Signal, they had basically have to do all of that manually. [12:42.520 --> 12:48.580] They had people, like, checking their phones day and night in order to be able to, like, deal with these sort of support requests. [12:48.680 --> 13:00.960] And so, any level of being able to automate that, that the messages that they're getting over these secure channels, like Signal, is, uh, invaluable for being able to, uh, basically lift that workload for them. [13:02.880 --> 13:16.520] The VPN use case is, um, one where the, um, the operator loads a database with prepaid VPN codes and then a user requests one or more codes to distribute to their community. [13:16.780 --> 13:35.300] This is a use case that primarily came out of places that have, um, restricted or censored Internet access and where there are, um, organizers on the ground who are, um, basically, like, right now just using, like, spreadsheets of codes and, like, writing them down on pieces of paper and, [13:35.440 --> 13:44.320] like, trying to keep track of, like, all of the prepaid codes that they send out to different members of their community so that they're able to access the Internet uncensored. [13:44.620 --> 13:59.140] And any level of automation of that capability of being able to distribute those codes, uh, would massively lighten the workload of, uh, of interacting with, like, with, uh, the workload of distributing those to the community. [14:00.440 --> 14:22.160] Um, very similarly, eSIMs, prepaid eSIMs, uh, the reason this warrants a second, like, a separate workflow is because there are some differences as far as, like, working with different carriers in different regions, um, and, uh, so, the, uh, operator loads a database with prepaid eSIMs, [14:22.240 --> 14:33.280] and a user requests one or more eSIMs to distribute in places where the, um, uh, where mobile access might be the only way to access the Internet. [14:33.580 --> 14:35.280] Places like, for instance, Gaza. [14:36.140 --> 14:54.360] And, uh, there are many, like, uh, many of the eSIM providers are, uh, getting increasingly worried about state censorship of the codes that they're distributing to places like Gaza and, like, there are, there are organizations that want to be able to switch over to a more secure channel for [14:54.360 --> 14:56.040] distributing that information, like Signal. [14:57.600 --> 15:08.600] Um, so then we took that and we went and developed a prototype of what some of these workflows would look like, um, working with these, uh, these different communities. [15:09.240 --> 15:13.900] And, um, testing revealed some key findings about what users wanted. [15:14.340 --> 15:16.940] Um, they wanted a human-to-human connection. [15:17.120 --> 15:21.820] They always wanted to be able to reach a human being when they were interacting with an automated system. [15:22.020 --> 15:30.000] They wanted to know that they could always, like, get the operator, basically, to, uh, be able to, uh, get help directly from, uh, from a person. [15:30.600 --> 15:34.140] Uh, they wanted consent as a design principle. [15:34.480 --> 15:43.520] By that, I mean that, uh, users had to actively consent in order to, uh, be a part of this service, uh, to receive these messages. [15:43.720 --> 15:53.040] So that, uh, at no point was anyone, uh, getting, would get tricked into, like, doing this, or, like, get unsolicited messages. [15:53.860 --> 15:56.120] And, uh, no creepy AI. [15:56.560 --> 16:03.660] By that, I mean, like, they wanted to know that, uh, they wanted to know that they were talking to a machine when they were talking to a machine. [16:04.000 --> 16:08.860] They didn't want a machine trying to trick them into thinking, thinking that it was a human that they were talking to. [16:09.220 --> 16:27.620] And so they wanted it to be really clear and really procedural as far as, like, the options for, um, uh, what they could do when they were interacting with the system and not have an AI that was, uh, basically, like, uh, trying to talk to to them as if they were... as if it was a human being. [16:29.400 --> 16:36.000] So that meant that we couldn't just train an LLM and hook it up and like, and then you're good. [16:37.360 --> 16:45.300] But designing the workflows for all of those different use cases is complex. [16:46.000 --> 16:55.060] This is just like a small portion of like the design for some of the workflows and all of the different edge cases for covering all of these five use cases. [16:55.260 --> 16:58.220] for different communities and different languages. [16:59.640 --> 17:01.380] And it gets pretty complicated. [17:01.520 --> 17:10.660] So we needed a sufficiently flexible platform in order to be able to essentially script out these conversations. [17:11.400 --> 17:17.760] So we adopted an open-source tool called the conversational state meta language or CSML. [17:18.020 --> 17:23.600] It was an existing open-source language designed specifically for writing conversation flows. [17:24.980 --> 17:28.580] So we weren't reinventing the wheel unnecessarily. [17:29.120 --> 17:31.000] The interpreter is written in Rust. [17:31.200 --> 17:37.660] So it's fast, memory safe, all that good Rust stuff that everyone always talks about. [17:38.140 --> 17:39.760] You get all of that for free. [17:40.160 --> 17:49.620] And we adopted it and integrated it into Bitpart and extended it with additional keywords in order to support our unique use cases. [17:52.120 --> 17:58.660] In order to connect it to Signal, we use the excellent Signal libraries from the Whisperfish project. [17:59.120 --> 18:03.920] Whisperfish being a Signal client for the Sailfish OS operating system. [18:04.280 --> 18:10.360] But they have some very excellent Rust-based libraries for interacting with Signal. [18:10.940 --> 18:15.840] One of the things about Signal is that they publish all their libraries open-source and everything. [18:16.060 --> 18:19.520] But for most languages, all they publish is the wire protocol. [18:19.600 --> 18:32.160] And so we're going to use the wire call library, which basically does the wire call library, which basically does all the complicated cryptography, but doesn't include any of the actual protocol for talking to Signal, the Service, for being to actually connect to and send a message, [18:32.300 --> 18:33.540] or receive a message from Signal. [18:34.680 --> 18:36.060] It makes sense. [18:36.440 --> 18:49.060] They do have the Java version of that because they are Android clients and stuff is one of the main reasons that they... main ways that they interact with their own services. [18:53.440 --> 19:05.920] So essentially, the Whisperfish project wrote Libsignal Service RS, which is the Rust version of the JavaScript library that I wrote back for Ionosphere. [19:06.680 --> 19:15.760] And on top of that, they wrote a high-level library called Presage that makes it super simple to make signal clients and bots using Rust. [19:18.500 --> 19:20.920] So how does Bitpart actually work? [19:21.260 --> 19:29.180] So a single instance of Bitpart, which you can run just as an executable, it's just a standalone server. [19:29.420 --> 19:41.340] A single instance of Bitpart can run any number of bots where a bot is like any of those workflows that I mentioned, any of those use cases, or your own custom workflow that you write in CSML. [19:44.900 --> 19:53.080] Also it's really easy to hook up CSML scripts to other platforms and things, so you could hook it up to a completely different system. [19:54.300 --> 19:59.020] I wouldn't hook it up to an LLM, but if like someone wanted to hook it up to an LLM, you could do that. [20:00.640 --> 20:03.580] It's one signal account per bot. [20:04.620 --> 20:15.820] We do that mostly so that you can actually connect more than one signal account to... like you can connect one signal account to more than one bot, but then all of the bots will reply to the same message and it gets really confusing. [20:17.780 --> 20:19.540] So one signal account per bot. [20:20.060 --> 20:29.920] You link it the same way that you link any other secondary device, like if you've ever linked Signal Desktop with a QR code from your Android or iOS Signal client. [20:32.340 --> 20:46.160] For that reason, we recommend using a separate Signal account specifically for this purpose, because otherwise if you're using your primary Signal device and you hook it up to a bot, then the bot's going to respond to all of your messages that you receive, which is probably not what you want. [20:52.380 --> 21:11.660] It's... as part of like trying to... which I'll talk a little bit more about later on, partly as a handy thing for preventing this being used for spam, it can only be... it can only send a message if it's received at least one message from that number. [21:11.980 --> 21:18.680] So the... someone has to message it in order to opt into the... the broadcast list in order to subscribe to it. [21:18.860 --> 21:34.340] Someone needs to message it in order to send it a tip or to make a help desk query, and it's only after that that... that it knows about your device and is able to send a message back, which means it can't be used for like mass spamming, a giant list of phone numbers, [21:34.360 --> 21:35.220] or something like that. [21:36.620 --> 21:40.580] It keeps absolute minimal data that we can get away with. [21:40.680 --> 21:42.240] It doesn't store any message contents. [21:42.820 --> 21:56.880] It stores like a little bit of conversational state information and whatever encryption keys the signal protocol needs in order to maintain the... in order to be able to send and receive messages. [21:58.880 --> 22:06.720] And all of the information is stored in an encrypted SQL cipher database that is built into the tool. [22:06.980 --> 22:11.960] So you don't need to... let's say like set up a Postgres database and do all of that. [22:12.100 --> 22:16.880] Everything is encrypted at rest and is fully integrated into the tool. [22:18.720 --> 22:20.960] Just a note about encryption. [22:22.600 --> 22:27.240] In an end-to-end encrypted conversation, bitpart is one end of that conversation. [22:27.400 --> 22:29.480] It can read the messages you send to it. [22:30.020 --> 22:32.000] So just be aware of that. [22:32.320 --> 22:35.880] It's... we don't think that that's contrary to user expectations for the most part. [22:36.040 --> 22:40.280] Like if you send a message to a help desk, you expect the help desk to be able to read the contents of that message. [22:40.780 --> 22:46.940] The only exception might be the broadcast list where it seems more like it's relaying a message. [22:47.040 --> 22:55.800] And we wouldn't want people to think that like the message from the operator all the way to those end users is encrypted all the way. [22:57.400 --> 23:01.760] We haven't written bitpart so that it exposes any message contents ever. [23:02.020 --> 23:07.800] But we just want to be clear that there isn't anything cryptographically preventing that from like happening. [23:08.080 --> 23:10.540] If bitpart receives a message, it can read it. [23:11.420 --> 23:16.620] We just have written it so it doesn't store any contents and doesn't expose those to the operators. [23:19.120 --> 23:25.140] There are a couple of different ways that bitpart can be can be used. [23:25.780 --> 23:36.980] So the one good thing is like, okay, well, given that bitpart can read the messages that it's receiving, maybe you don't trust someone else to run bitpart for you. [23:37.960 --> 23:43.340] So you can run it yourself and have your own security guarantees around storing messages. [23:44.180 --> 23:56.360] So the two ways of running it is that Throneless is going to be providing a hosted platform, which we've made as secure as we possibly can. [23:56.520 --> 24:11.720] It uses a Next.js based web dashboard that is basically allows you to just select one of those five use cases and just fill out a short form and customize it with all of your own like text and information. [24:12.420 --> 24:18.600] So that you can then create as many of those bots as you want and manage them through this web-based dashboard. [24:19.320 --> 24:30.920] Currently, the dashboard is in the hands of our trusted tester group via invite code, but we'll be releasing it more widely early next month. [24:32.760 --> 24:51.200] A big reason that we wanted to provide a hosted platform that will keep operating for as long as we can is because nothing makes someone's eyes glaze over like talking to like a relatively non-technical activist or maybe even a technical one and you're like, [24:51.300 --> 24:52.560] oh, I've got this really great tool. [24:53.180 --> 25:01.740] All you have to do is get a server and install Debian on it and install a bunch of packages and download this image from Docker and it's very simple. [25:02.020 --> 25:12.560] So we wanted to make sure that this was something that was within the reach of people who didn't necessarily have the technical wherewithal to want to run their own server. [25:15.380 --> 25:19.240] But if you do have the technical wherewithal, you can also run it yourself. [25:21.420 --> 25:23.820] That way you have full control over all of your data. [25:25.860 --> 25:31.320] If you want, you can set up the dashboard and the whole stack and have a nice web interface and everything. [25:31.780 --> 25:37.360] But if you don't want to do that, you can just run it and it has a nice command line interface. [25:37.840 --> 25:39.220] Well, it has a command line interface. [25:39.460 --> 25:41.200] You can decide whether it's nice or not. [25:43.600 --> 25:47.400] And you are able to use that to run as many bots as you have. [25:47.500 --> 25:52.700] And the nice thing about that is that after you set it up, then all the communication is taking place over signal. [25:52.880 --> 25:57.500] So you could have it running on old laptop in a closet or something. [25:57.500 --> 26:01.440] It doesn't need to be publicly exposed to the Internet as long as it has a connection. [26:02.520 --> 26:07.620] And it's available as either a static binary or as a Docker image. [26:09.480 --> 26:12.240] And I did just want to talk a little bit more about mitigation. [26:12.940 --> 26:22.020] So mitigating spam or other malicious messages and things. [26:23.700 --> 26:36.480] Obviously, the fact that it has all signal security guarantees and then we are also committed to carrying those guarantees forward by not reading, not exposing the contents of the messages. [26:37.160 --> 26:47.520] That makes it pretty difficult to say monitor and enforce any sort of usage of the tool. [26:49.200 --> 27:03.460] But the fact that it can only message an account that messages at first means that at least it can't be used for a widespread spam attack or other sorts of things. [27:03.720 --> 27:06.980] It's also subject to all of the signals' own protections on their network. [27:07.160 --> 27:09.460] Like all of the messages are regular signal messages. [27:09.660 --> 27:14.920] So they're all subject to signals' own rate limits and spam filter and all of that other stuff that signal brings to the table. [27:16.660 --> 27:29.020] And we're also investigating for the hosted platform that we're operating whether or not there's any kind of network monitoring that we could use that would tease out patterns that we could identify abusive behavior. [27:29.780 --> 27:35.940] I'm not saying that we'll be able to do that, but that's something that we're actively researching to see if we could detect patterns of abusive behavior. [27:36.120 --> 27:45.460] But otherwise, it's probably going to be based on reports via support requests of abusive behavior or something like that. [27:45.900 --> 27:53.800] But I just wanted to touch on that because the last thing that we want is to enable any sort of abusive uses of the signal network. [27:57.740 --> 28:04.980] But we think that we have some relatively strong mitigations to preventing some widespread abuse. [28:07.020 --> 28:13.920] So given all of that, Bitpart is available open-source under the AGPLv3. [28:15.700 --> 28:20.720] The code is available as of today at github.com. [28:21.620 --> 28:23.120] Oh, is it going to do it? [28:23.280 --> 28:23.740] Yes. [28:24.020 --> 28:24.140] Okay. [28:27.040 --> 28:28.880] Having some video adapter problems. [28:29.720 --> 28:33.500] The code is available as of today at github.com. [28:33.660 --> 28:36.960] That's where that QR code leads. [28:38.280 --> 28:42.820] The hosted platform and dashboard will be available early next month. [28:42.980 --> 28:46.600] We're rolling it out at the Internet Freedom Global Gathering in Portugal. [28:51.280 --> 28:59.660] And it's there to try out, set up, and let's collaborate and build stuff together. [29:00.340 --> 29:01.120] Thank you. [29:13.490 --> 29:13.890] Hi. [29:13.890 --> 29:14.290] Hi. [29:14.590 --> 29:14.810] Hi. [29:16.670 --> 29:20.750] I really like that at the beginning of the project... First of all, building stuff on top of Signal is great. [29:21.010 --> 29:27.290] And you're the first project that I've seen that does it in a coherent way, having tried to research use cases for activists, etc. [29:27.830 --> 29:28.910] But I have some concerns. [29:29.410 --> 29:29.790] Of course. [29:30.090 --> 29:30.230] Great. [29:31.890 --> 29:34.150] You've surveyed people in a large number of different countries. [29:35.430 --> 29:36.650] You've named a few regions. [29:37.050 --> 29:43.550] So I can infer from that that a number of those countries have completely dissimilar threat models from one another that activists face. [29:44.250 --> 29:52.170] In some of those, just to state it very simply, in the CIA model of security, we've used the word security a lot, right, in mitigations. [29:52.350 --> 29:55.190] But some of those countries, the main concern is confidentiality. [29:55.550 --> 29:57.230] And in other countries, the main concern is availability. [29:58.850 --> 30:00.250] So what is your threat model? [30:01.090 --> 30:08.050] How have you made a project and made claims about its security security in the face of such widely differing threat models? [30:11.310 --> 30:15.870] The... So talking about the threat model, I think that there's like a couple of different answers to that. [30:16.110 --> 30:28.230] Like one is the threat model that we have for our like hosted platform, for how we're trying to protect users of that platform from, say, external threats, like you mentioned the CIA, like threat actors. [30:28.230 --> 30:29.790] The CIA is not a threat actor. [30:29.910 --> 30:32.530] CIA is a confidentiality, integrity, availability breakdown. [30:33.750 --> 30:34.270] Oh, sorry. [30:34.270 --> 30:34.270] Sorry. [30:34.350 --> 30:34.350] Sorry. [30:35.150 --> 30:36.230] No, that makes sense. [30:37.670 --> 30:47.570] The... So the... But I mean, that could include state actors and other sort of actors like that. [30:48.310 --> 31:03.170] So part of our... And then separately, the threat model for like people who are using this on a self-hosted basis in order to provide for like, to be able to use it for their communities. [31:04.190 --> 31:08.410] For the... And you're right that I use security a lot. [31:08.590 --> 31:14.690] And I was using that, like maybe conflating that a little bit where I could have been using privacy, like in some cases. [31:15.150 --> 31:22.110] And the... I do have to apologize that I actually can't see my notes at all. [31:22.390 --> 31:24.150] Like, so I just winged that. [31:27.970 --> 31:38.190] The... The threat model for the... For the hosted platform, I'll say like, as part of that, we are... [31:42.770 --> 31:48.970] Well, I'm trying to figure out like, we're not planning on making like the configurations of the hosted platform public necessarily. [31:49.390 --> 32:01.870] But like, we're hosting it in a... Well, I'll say like, we're hosting it in a favorable jurisdiction, like... That is not responsive to subpoenas from Western countries? [32:02.490 --> 32:06.830] Even though you have a centralized list of all the activist signal identities that you're communicating with? [32:07.650 --> 32:11.590] Well, we don't have a list of all of the activist signal identities that we're communicating with. [32:11.590 --> 32:11.970] Interesting. [32:12.370 --> 32:12.750] How so? [32:13.050 --> 32:13.590] Architecturally? [32:14.150 --> 32:27.890] Architecturally, we... So once the message from signal comes in, the... The message is only identified via a internal UUID, like within the... [32:27.890 --> 32:29.970] The sealed sender. [32:30.130 --> 32:43.050] And so we actually don't have like the... We never received the... The phone number or the signal user ID for any... Anybody who is like, say like the recipient of one of those broadcast lists. [32:43.130 --> 32:44.950] But how do you then respond to them? [32:45.050 --> 32:46.950] Aren't those UUIDs repeatable? [32:47.050 --> 33:03.430] So if you reverse engineer signal desktop and you extract the UUID associated with a particular conversational partner from two different signal desktop instances that independently contacted the same party or were contacted by the same party, the UUID is under signal's new IAM since February 20th of last year. [33:04.770 --> 33:09.010] Actually a fully identifying... Actually fully identifies the user, doesn't it? [33:09.250 --> 33:11.130] So you have that UUID, don't you? [33:13.090 --> 33:14.270] Um... Am I mistaken? [33:14.550 --> 33:15.250] I might be mistaken. [33:15.330 --> 33:16.850] I could be... I think it's session. [33:17.170 --> 33:17.670] Yeah. [33:25.300 --> 33:29.040] But is that normal user behavior for a non-technical user? [33:29.120 --> 33:30.940] Because you claim you're defending non-technical users. [33:31.420 --> 33:34.640] If you're holding all the UUIDs centrally, isn't that subpoenable? [33:35.140 --> 33:36.920] And essentially identifying to all those activists? [33:37.420 --> 33:39.780] And isn't that also true in the self-hosted version? [33:42.980 --> 33:44.100] That's a really good question. [33:44.500 --> 33:45.510] I don't think that the... [33:47.660 --> 33:51.060] Um... I mean, the UUIDs cycle up like per session. [33:51.420 --> 33:52.670] So I'm not sure that that's like... [33:53.890 --> 34:03.630] uh... the... um... that that corresponds to like... directly having a like... uh... global unique identifier for each of those users. [34:03.730 --> 34:03.890] Okay. [34:04.490 --> 34:05.770] But, um... [34:05.770 --> 34:07.450] How do you then send out announcements? [34:09.490 --> 34:11.010] Well, the... [34:11.610 --> 34:17.510] So it has the keys for like... over the... uh... that it's able to use over the... uh... service library. [34:17.950 --> 34:22.010] Like, in order to be able to... in order to be able to send out the messages to... [34:22.010 --> 34:24.070] the users the same as any other signal client. [34:24.590 --> 34:24.930] Right. [34:24.930 --> 34:32.290] So, but now you have it stored centrally on a host that presumably is, in most cases, not in someone's house, right? [34:32.370 --> 34:36.430] If you're in... it's cool that you're... that you brought up the example of being in someone's closet. [34:36.430 --> 34:37.790] But it's subject to subpoena. [34:37.890 --> 34:39.750] So sorry, I was getting down a rabbit hole with the UUID generation. [34:39.830 --> 34:40.010] Yeah. [34:40.310 --> 34:47.610] But the... um... but yes, it does have the keys for... um... for the... like... in order to be able to like... [34:47.610 --> 34:49.130] communicate with those messages. [34:49.390 --> 34:54.530] What it doesn't have is those keys like... linked to the identifying information... [34:54.530 --> 34:56.890] like... uh... of that person. [34:57.270 --> 34:57.650] Right. [34:57.710 --> 34:58.390] But Signal does. [34:58.650 --> 35:06.230] So under the present IAM, if you were to be subpoenaed and Signal would be subpoenaed, then lists of hundreds or thousands of activists would all be unmasked. [35:06.230 --> 35:09.130] by any Western government that subpoenaed your records and subpoenaed Signal. [35:10.250 --> 35:15.010] Are you familiar how confident you are? [35:15.730 --> 35:17.070] Uh... maybe we can talk afterwards. [35:17.130 --> 35:22.990] Yeah, I think that... I think that there is a re-architecture to put it on... um... specific chips that would achieve this. [35:24.130 --> 35:24.530] Okay. [35:24.610 --> 35:25.550] But that hasn't currently... [35:25.550 --> 35:26.610] We can talk about this after. [35:26.750 --> 35:28.550] I think maybe I'm not totally getting it, but... [35:29.850 --> 35:33.210] Um... okay, and... sorry, there was one additional brief question. [35:34.030 --> 35:34.950] Uh... go ahead, actually. [35:35.290 --> 35:35.410] Okay. [35:36.130 --> 35:39.210] I... I have a question from the live stream, uh... which is... [35:39.210 --> 35:42.610] Did you say this can be extended to work on other transport? [35:43.270 --> 35:44.150] Other transports? [35:44.170 --> 35:46.110] What's that is heavily used for these groups in the UK? [35:46.510 --> 35:48.570] And organizers would love to use this tool over... [35:49.050 --> 35:49.650] What's that? [35:50.170 --> 35:50.610] Right. [35:51.210 --> 35:52.710] So the, um... [35:52.710 --> 35:55.930] It is something that we would like to bring to WhatsApp and other platforms. [35:56.330 --> 36:00.410] The code is written in a modular way so that we, uh... [36:00.410 --> 36:04.470] Hope that we can extend it to, um... to use other transports. [36:04.550 --> 36:06.670] There isn't any, like, um... [36:06.670 --> 36:09.130] I mean, it's essentially a scriptable chatbot engine. [36:09.330 --> 36:13.270] There isn't anything that's, like, really a limitation as far as bringing it to other platforms. [36:14.290 --> 36:17.370] And WhatsApp is, like, the one that we, um... [36:17.370 --> 36:19.210] We would most like to, uh... bring it to. [36:22.130 --> 36:29.110] So I wonder what your experience has been so far of running large-scale signal bots, because it's not really meant for that. [36:29.350 --> 36:31.990] And so you mentioned they have rate limiting, right? [36:32.430 --> 36:33.010] Mm-hmm. [36:33.670 --> 36:34.150] And... [36:34.670 --> 36:35.910] So that's the first part. [36:36.050 --> 36:38.190] And then also the fact that it's... [36:38.190 --> 36:40.590] Of course it's open-source, which is great. [36:40.590 --> 36:44.350] But they also don't really have any kind of commitment to, like, third-party compatibility. [36:44.350 --> 36:46.110] They change it as often as they feel like. [36:46.110 --> 36:50.450] And, you know, so you're sort of just at the mercy of whenever they change something. [36:51.350 --> 36:51.790] Yeah. [36:52.490 --> 36:52.890] Uh... [36:52.890 --> 36:54.290] The, um... [36:54.290 --> 36:56.730] I mean, um... [36:56.730 --> 36:57.790] Answer the second part first. [36:57.990 --> 36:58.990] Like, yeah, absolutely. [36:59.310 --> 37:00.990] I mean, that's something that we're, um... [37:03.330 --> 37:05.210] Like, that we are at the mercy of. [37:05.370 --> 37:09.610] And that we're just, like, in cooperation with, like, uh... [37:09.610 --> 37:13.590] We hope to work with the Whisperfish developers to, like, help with maintaining that compatibility. [37:14.150 --> 37:15.990] But, and we have reached out to Signal. [37:16.410 --> 37:17.370] Like, um... [37:17.370 --> 37:19.010] We haven't received a response yet, but... [37:19.010 --> 37:21.510] Yeah, I mean, my understanding is they're kind of not really interested in that. [37:21.650 --> 37:24.230] They're not actively stopping anybody from doing that. [37:24.530 --> 37:25.370] But, uh... [37:25.370 --> 37:27.370] In some cases, no answer is a good answer. [37:27.490 --> 37:28.150] I guess. [37:28.430 --> 37:28.770] Maybe. [37:29.070 --> 37:31.150] But, I mean, do you foresee that, like, being a problem? [37:31.230 --> 37:32.450] How fast does it change, you know? [37:33.030 --> 37:33.410] Uh... [37:33.410 --> 37:34.690] I mean, the... [37:34.690 --> 37:37.210] Most of the underlying protocol doesn't change that fast. [37:37.510 --> 37:40.230] Like, it doesn't break compatibility, like, that quickly. [37:40.510 --> 37:41.710] But, um... [37:41.710 --> 37:44.950] Yeah, we do anticipate that being, like, an ongoing challenge with, uh... [37:44.950 --> 37:47.130] Maintaining the project, uh... [37:47.130 --> 37:47.650] Over time. [37:47.970 --> 37:49.390] And, uh... [37:49.390 --> 37:50.770] We've just tried to... [37:50.770 --> 37:54.210] I think we're familiar with that challenge through some of the past work. [37:54.390 --> 37:57.070] And so we've tried to architect things this time. [37:57.070 --> 38:00.170] So we're, like, able to, like, uh... [38:00.170 --> 38:02.070] Lean on as many other developer communities. [38:02.510 --> 38:04.890] And, like, be able to, like, uh... [38:04.890 --> 38:06.330] Like, structure it in a really clean way. [38:06.470 --> 38:07.770] And just try and stack the deck in our favor. [38:07.990 --> 38:11.030] As far as being able to keep up with, like, um... [38:11.030 --> 38:12.590] Maintaining compatibility, uh... [38:12.590 --> 38:12.990] Over time. [38:14.310 --> 38:15.190] And, um... [38:15.190 --> 38:15.370] Yeah. [38:15.510 --> 38:19.270] Our experience with, um... [38:19.270 --> 38:20.750] Managing large-scale signal bots. [38:21.410 --> 38:23.330] The, um... [38:23.330 --> 38:26.010] We have tested this with fairly large, uh... [38:26.010 --> 38:26.470] Groups. [38:27.410 --> 38:27.930] Um... [38:27.930 --> 38:28.450] The... [38:28.450 --> 38:30.450] And the, um... [38:30.450 --> 38:33.870] We've designed the hosted platform, at least, to be horizontally scalable. [38:34.670 --> 38:35.190] Um... [38:35.190 --> 38:37.730] But the rate limiting is always a challenge. [38:38.230 --> 38:38.630] Um... [38:38.630 --> 38:39.590] I think that it... [38:39.590 --> 38:41.430] We have to deal with it in a couple of different ways. [38:41.950 --> 38:44.030] One that, um... [38:44.030 --> 38:45.530] The, uh... [38:45.530 --> 38:49.650] Not right now, but one thing that we are adding into it is its own rate limiting. [38:49.950 --> 38:53.070] So that we are able to, like, keep underneath, like, signals limits. [38:53.710 --> 38:54.110] Uh... [38:54.110 --> 38:55.570] And, uh... [38:55.570 --> 38:57.310] Cache any messages before they go out. [38:57.490 --> 38:59.390] So that we aren't hitting, like, signals limits. [38:59.610 --> 39:01.390] Because then you would get a CAPTCHA. [39:01.570 --> 39:05.050] Of course, the bot isn't going to be able to fill out the CAPTCHA for you or anything like that. [39:05.590 --> 39:06.750] But the, um... [39:22.650 --> 39:23.050] Um... [39:23.050 --> 39:26.990] And then you would have a group with thousands of users in it or something. [39:27.690 --> 39:28.090] Uh... [39:28.090 --> 39:29.490] Order of magnitude, how long is that? [39:30.430 --> 39:30.830] Sorry? [39:31.330 --> 39:31.690] Uh... [39:31.690 --> 39:32.830] Roughly, how long is that? [39:33.470 --> 39:34.290] If you have... [39:34.290 --> 39:37.030] If you have, I don't know, yeah, a couple thousand users or something. [39:38.050 --> 39:38.450] Uh... [39:38.450 --> 39:39.030] Well, let's see. [39:39.270 --> 39:40.550] So the... [39:40.550 --> 39:41.510] I wish I had the rate limit. [39:41.810 --> 39:45.390] You can find all the rate limits, actually, like, in the signal server source code. [39:45.390 --> 39:47.870] So you can, um... [39:49.490 --> 39:49.970] Uh... [39:49.970 --> 39:51.130] I want to say it's... [39:52.350 --> 39:54.510] 300 messages every five seconds. [39:54.750 --> 39:55.490] Don't quote me on that. [39:55.830 --> 39:57.030] It's, like, uh... [39:57.030 --> 39:59.850] But it's in the, um... [39:59.850 --> 40:04.250] But it is in the signal server source code, all of those rate limits, on a per account and per IP basis. [40:05.790 --> 40:06.270] Um... [40:06.270 --> 40:10.610] And so we are, like, seeking to stay just underneath that. [40:11.030 --> 40:12.450] But, um... [40:12.450 --> 40:12.690] Yeah. [40:12.910 --> 40:15.270] It'll take good user communication and good documentation. [40:15.270 --> 40:19.010] In order to be able to, like, establish expectations about what it can do. [40:21.590 --> 40:23.050] Another question from Livestream. [40:23.270 --> 40:27.310] How easy would it be for me to add a sixth use case that I have in mind? [40:27.490 --> 40:28.330] Is it all in Rust? [40:28.870 --> 40:29.890] And how to contribute? [40:30.650 --> 40:31.090] Uh... [40:31.090 --> 40:31.990] It's not all in Rust. [40:32.190 --> 40:34.950] It's actually, like, all of the use cases are written in that, um... [40:35.950 --> 40:36.030] Uh... [40:36.030 --> 40:37.050] CSML scripting language. [40:37.390 --> 40:39.350] So that we, um... [40:39.350 --> 40:39.570] Yeah. [40:39.750 --> 40:41.510] We didn't want to, like... [40:41.510 --> 40:44.650] We wanted to be able to benefit from the speed and memory safety of Rust. [40:45.410 --> 40:52.910] But we didn't want people to have to, like, write Rust code in order to, like, add to and extend their own use cases or anything like that. [40:53.030 --> 40:53.630] I like Rust. [40:53.830 --> 40:54.990] It's not the easiest thing to write. [40:55.350 --> 40:56.530] But the, um... [40:57.470 --> 41:01.030] And not really, like, that suitable for, like, um... [41:01.030 --> 41:05.710] Writing out and editing something that you want, like, want to modify, uh, extremely frequently. [41:06.790 --> 41:07.190] Um... [41:07.190 --> 41:08.630] So, uh... [41:08.630 --> 41:08.790] Yeah. [41:08.850 --> 41:16.030] In order to write your own sixth use case, you would have to write a much, a much simpler C-S-M-L script rather than, um... [41:16.030 --> 41:17.670] Writing a, um... [41:17.670 --> 41:18.590] Like, anything in Rust. [41:23.050 --> 41:24.490] So, first, this is super cool. [41:26.070 --> 41:26.430] Um... [41:26.430 --> 41:28.550] As I was sitting, I think I've answered my own question. [41:28.690 --> 41:29.150] But I just want to make sure. [41:29.290 --> 41:29.890] So the one... [41:29.890 --> 41:32.670] As many bots as you want, but one account per, right? [41:33.390 --> 41:34.250] That means you for... [41:34.250 --> 41:37.030] Like, let's say that, like, in the example of Washington, D.C. [41:37.030 --> 41:53.070] Right now, if you had one organization having separate mobilizations in Southeast, Petworth, and U.S. treet, and they each needed their own announcement channel, you'd have to have three separate signal accounts on three separate, like, tied to three separate phone numbers, basically. [41:54.230 --> 41:54.650] Yeah. [41:54.810 --> 41:55.690] Currently, that's the case. [41:55.730 --> 41:59.070] And that's just because otherwise we don't have a way of distinguishing, like, which... [41:59.070 --> 42:01.690] If we're running multiple bots on a, like... [42:01.690 --> 42:12.250] If we're running multiple bots on a given instance, then otherwise we don't have a way of distinguishing which incoming messages are meant for which bot, like, other than, like, distinguishing them by the Signal account that's associated with it. [42:12.310 --> 42:13.650] Makes perfect sense, but... [42:13.650 --> 42:14.150] I just want to make sure. [42:14.270 --> 42:17.070] But yeah, it is unfortunate that we couldn't just be like, yeah, just use one. [42:17.210 --> 42:19.530] And it's like, you know, and they can all use the same one. [42:19.750 --> 42:20.210] Thank you. [42:20.530 --> 42:21.030] Yeah, no problem. [42:22.430 --> 42:23.670] Another question from Livestream. [42:23.870 --> 42:29.290] Why won't Signal the organization play ball, as you recently mentioned in some of the responses? [42:30.890 --> 42:33.550] Well, I mean, I think Signal has a... [42:33.550 --> 42:34.570] I don't know that they... [42:36.510 --> 42:38.970] I mean, won't play ball as, like... [42:38.970 --> 42:51.950] I think that they've been very, like, kind and not smacking down all of the projects that, like, I've attempted to build on top of Signal. [42:52.290 --> 42:54.030] But I think that they have... [42:55.310 --> 43:06.150] The way I usually feel about Signal is, like, I can always see the reasoning behind all of their, like, security decisions and things, even if it isn't exactly what I would do in the same situation. [43:06.150 --> 43:08.630] I always respect their reasoning for how they do it. [43:08.970 --> 43:10.550] And I think that the... [43:11.590 --> 43:14.910] They're just very focused on their own, like, particular... [43:15.610 --> 43:17.130] Their own particular threat model. [43:17.290 --> 43:20.910] Their own particular, like, way of, like, how they operate and engineer their service. [43:20.910 --> 43:38.270] And I think that's fine that they don't want to, like, collaborate with a bunch of other open-source projects on, like, things built on top of their platform when they are laser focused on providing the best, most secure messaging software that they possibly can. [43:39.630 --> 43:42.010] But it does make things more difficult sometimes. [43:49.620 --> 43:50.260] All right. [43:50.580 --> 43:51.200] Thank you very much.