[00:01.210 --> 00:03.630] Welcome once again to HOPE everybody. [00:03.950 --> 00:09.130] I am very excited to introduce this very excellent talk here with a really great team for you. [00:09.670 --> 00:13.950] The talk is entitled, Clawing Back Your Data from Big Tech with Sid. [00:14.350 --> 00:17.250] And we have three experts on clawing back data here. [00:17.430 --> 00:20.710] We have Micah Lee, Redshift Zero, and Yael Grauer. [00:21.590 --> 00:26.070] Micah Lee and Redshift Zero are both members of the Lockdown Systems Collective. [00:26.230 --> 00:31.130] You probably know Micah from his work as a journalist, as a security researcher. [00:31.210 --> 00:31.990] as a coder. [00:32.210 --> 00:36.570] And from his most recent book... what is the title of your book again? [00:36.830 --> 00:38.130] Hacks, Leaks, and Revelations. [00:38.470 --> 00:40.250] Hacks, Leaks, and Revelations? [00:40.550 --> 00:41.610] Okay, very good. [00:41.770 --> 00:51.130] Excellent book about analyzing data from... basically analyzing data from various breaches and things and how to derive meaning from that, if I understand it correctly. [00:51.290 --> 00:51.590] Very good. [00:52.390 --> 00:59.130] Redshift Zero, a member of the Lockdown Systems Collective, has worked on a lot of privacy enhancing technologies, so she's very well suited to speak on this. [00:59.250 --> 01:14.970] And Yael Grauer, who's an investigative tech reporter, and works extensively now with Consumer Reports, writing on issues such as Stockerware, and VPNs, and other types of very interesting privacy, I guess dilutive types of technologies and things. [01:15.330 --> 01:18.490] So, without further ado, I'll hand it off to these three. [01:18.790 --> 01:19.190] Thank you. [01:19.390 --> 01:20.410] Let's give them a hand. [01:22.690 --> 01:23.090] Hello? [01:23.450 --> 01:23.750] Hello? [01:23.750 --> 01:23.750] Oh. [01:24.050 --> 01:24.350] Thank you. [01:24.650 --> 01:25.030] Come on, Tim. [01:26.050 --> 01:26.710] Hey, what's up? [01:26.830 --> 01:32.270] We're Lockdown Systems, and we believe that you should have control of your data instead of seeding it to big tech. [01:33.110 --> 01:34.110] This is who we are. [01:34.290 --> 01:35.830] So, I'm Jen Hellsby. [01:35.970 --> 01:37.430] I go Redshift Zero on the Internet. [01:37.630 --> 01:39.830] I'm a researcher and engineer working on privacy tech. [01:39.950 --> 01:41.490] I do a lot of work mostly with journalists. [01:43.910 --> 01:44.810] I'm Micah Lee. [01:45.430 --> 01:53.310] I'm an independent security researcher, an open-source developer, and a journalist, and I'm a member of the Lockdown Systems Collective. [01:55.250 --> 02:03.190] SopTalk is also a engineer and a member of our collective, but he's not here because he couldn't make it because he's in India. [02:06.950 --> 02:07.670] Hi, everybody. [02:07.790 --> 02:13.370] I'm Yael, and I'm also a member of the Lockdown Systems Collective, and I'm actually here at this workshop in my personal capacity. [02:14.750 --> 02:17.050] But I do journalism. [02:17.250 --> 02:23.730] I maintain a data broker opt-out list, and I work for the consumer rights nonprofit that was already mentioned. [02:27.770 --> 02:28.210] Oh, yeah. [02:28.410 --> 02:30.190] Lockdown Systems has three projects. [02:30.390 --> 02:39.290] So, we work on Onion Share, which is an open-source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. [02:39.790 --> 02:49.830] And we also work on the ICE detention map, which is an open-source dashboard and map showing information about ICE detention facilities, including the number of people in detention. [02:50.190 --> 02:54.590] But this talk is about CID, an open-source tool that helps you claw back your data from big tech platforms. [02:57.920 --> 03:03.820] So, I started using Twitter in 2009, and I eventually grew to become addicted to it. [03:04.740 --> 03:06.980] I was writing for The Intercept for a long time. [03:07.120 --> 03:09.720] I was doing reporting on the Snowden Archive. [03:09.720 --> 03:11.320] So, I had a ton of followers. [03:11.660 --> 03:13.420] At my peak, I had, like, 50,000. [03:13.720 --> 03:18.700] And I got obsessed with, like, the dopamine rush I would get every time something I posted went viral. [03:19.420 --> 03:22.300] But I also attracted a lot of trolls and haters. [03:23.100 --> 03:25.620] I distinctly remember this one harassment campaign. [03:25.620 --> 03:32.700] In 2018, I had published leaked chat logs from a private WikiLeaks Twitter DM group. [03:33.180 --> 03:43.480] And in the group, Julian Assange was explaining why he was backing Donald Trump over Hillary Clinton in 2016, and they plotted ways to discredit feminists. [03:43.480 --> 03:45.940] So, the WikiLeaks trolls attacked me. [03:46.400 --> 03:53.580] And one of them searched my Twitter history for the word, jew, and saw that in 2011, I had posted about going to a jewish wedding. [03:54.200 --> 03:55.940] And they started using that to harass me. [03:57.220 --> 04:02.580] So, this is around the time that I decided that I wanted to delete my old tweets. [04:03.540 --> 04:05.040] I care a lot about privacy. [04:05.660 --> 04:09.420] All my signal messages, even, like, the most innocuous ones automatically disappear. [04:10.260 --> 04:12.320] So, why should my tweets be online forever? [04:13.600 --> 04:17.680] But I, you know, was a very, like, heavy Twitter user. [04:17.820 --> 04:19.220] I didn't want to delete all of my tweets. [04:20.680 --> 04:24.800] I just... there was, like, you know, a bunch of Twitter threads that I had that I was proud of. [04:24.800 --> 04:26.500] There were a bunch of viral tweets that I wanted to keep. [04:26.900 --> 04:29.780] I just wanted to delete, like, most of them, like, 95% of them. [04:30.140 --> 04:35.480] And so, there were some existing tools out there to delete your tweets, but they all made you delete all of your tweets. [04:36.220 --> 04:41.120] So, I made my own tool, and I made it open-source, called semi-ephemeral. [04:41.660 --> 04:49.020] And so, semi-ephemeral made it so I could have a semi-ephemeral Twitter account, and then it also made it easy for everyone else, too, as well. [04:50.360 --> 04:52.080] But then came Elon Musk. [04:53.100 --> 04:59.160] So, in late 2022, Musk bought Twitter to restore free speech. [04:59.660 --> 05:05.000] He started by unsuspending the accounts of Nazis, and those are the only accounts that he unsuspended. [05:06.600 --> 05:10.960] So, here's an article that I wrote right after Elon Musk bought Twitter. [05:11.460 --> 05:18.340] Twitter had started censoring distributed denial of secrets in 2020 when they published the Blue Leaks dataset. [05:18.340 --> 05:26.380] Which is a 250-gigabyte dataset of hacked police documents that showed police misconduct during the Black Lives Matter protests. [05:27.000 --> 05:34.180] But Elon Musk refused to restore the account, or to stop blocking links to DDoS secrets website, and they're still blocked today. [05:35.720 --> 05:39.600] And here's another article that I co-wrote from around the same time. [05:39.600 --> 05:56.280] So, in addition to bringing back Nazis that have been banned, and not bringing back DDoS secrets or anyone else who was banned but not a Nazi, Musk also started banning prominent leftist accounts that didn't break any of Twitter's rules, but he did this based on the advice of Andy Ngo, a far-right conspiracy theorist. [05:58.400 --> 06:03.360] And it was all public, like Andy was tweeting at Elon Musk, and then he would ban someone. [06:04.900 --> 06:07.840] And then he started banning journalists, including me. [06:08.480 --> 06:18.280] So, I don't know if you remember, but there was this Twitter account called ElonJet that posted public records of where Elon Musk's private jet was flying to. [06:18.280 --> 06:21.280] And so, Elon Musk banned the ElonJet account. [06:21.840 --> 06:31.200] And then when the official Mastodon Twitter account tweeted that you can still follow ElonJet on Mastodon.social, he banned the Mastodon account. [06:31.200 --> 06:41.560] And then when I tweeted that Elon Musk is banning the Mastodon account, he permanently suspended my account for this tweet because I was posting assassination coordinates. [06:42.920 --> 06:46.160] And he also suspended like eight other journalists. [06:46.420 --> 06:49.700] And he eventually reversed his decision after a Twitter poll. [06:50.260 --> 06:55.320] But the episode kind of poked some holes into his claim that he's a free speech absolutist. [06:57.960 --> 07:02.940] So, turning Twitter into a fascist propaganda machine is pretty bad. [07:03.240 --> 07:08.440] But another big thing that Musk did to ruin Twitter was shut off free access to the Twitter API. [07:09.140 --> 07:13.740] He made API usage so expensive, in fact, that if you had been using Twitter for... [07:13.740 --> 07:22.320] If you, like, had a regular Twitter user and posted a lot for about ten years, it would cost thousands and thousands of dollars in API fees to delete all of your tweets. [07:24.080 --> 07:28.560] So, like every other Twitter app, semi-ephemeral was forced to shut down. [07:29.440 --> 07:33.780] It had deleted tens of millions of tweets, likes, and direct messages before its tragic death. [07:35.860 --> 07:39.260] Elon Musk killing the Twitter API is an example of enshittification. [07:39.940 --> 07:50.060] And right after Musk did this to Twitter, Reddit decided to also kill their free API, which killed... completely killed the third-party app ecosystem for Reddit. [07:50.700 --> 07:54.340] And Reddit CEO Steve Huffman said that he was inspired by Elon Musk to do it. [07:56.560 --> 08:02.940] The tech platforms that we all rely on are controlled by a tiny group of overwhelmingly powerful billionaires. [08:03.540 --> 08:13.480] Instead of using their vast wealth to solve global problems like the climate crisis, they spend their resources squeezing every bit of money possible from their users to make themselves richer. [08:14.600 --> 08:20.860] They've also been radicalized by their own platforms, and they've become more and more comfortable openly flirting with fascist politics. [08:23.160 --> 08:28.780] If you've ever posted anything to the Internet, it's a safe bet that people are getting obscenely rich off of your data. [08:28.780 --> 08:33.020] Here are some articles about Stack Overflow and Reddit selling user data. [08:33.360 --> 08:38.000] And I'm sure many other platforms that you post stuff to are also selling user data. [08:38.180 --> 08:48.440] And even if the platforms themselves aren't selling them, I promise that there are other companies that are scraping that data and selling it to other people and making a lot of money off of it. [08:49.760 --> 08:51.980] And here's an interesting story about Stack Overflow. [08:52.640 --> 08:59.080] Once they announced that they were selling user data, this developer decided to delete his top-rated answer on Stack Overflow. [08:59.560 --> 09:03.780] But if your answer is the highest-rated answer to a question, Stack Overflow doesn't let you delete it. [09:04.420 --> 09:10.200] So instead, he updated his answer to a protest message, and Stack Overflow suspended his account for a week. [09:11.240 --> 09:16.060] So this sucks, and it's time to opt out of this whole corrupt system. [09:21.040 --> 09:26.360] So a year ago, I found a really old social media account that I kept for a few months over two decades ago. [09:27.200 --> 09:29.520] I had an audience of maybe five or six friends. [09:30.000 --> 09:33.880] And I didn't realize this account and my handle were associated with my email address. [09:34.660 --> 09:37.100] So obviously, I didn't want that information floating around. [09:37.760 --> 09:41.000] Or I thought maybe there were some details I wouldn't want widely publicized. [09:41.060 --> 09:42.680] I didn't have time to reread the whole thing. [09:43.400 --> 09:47.060] And I think this is something that has happened to people if you've ever been active on Twitter. [09:47.060 --> 09:51.240] You might have hundreds or thousands of tweets that might not reflect who you are today. [09:52.520 --> 09:55.840] Maybe you like this celebrity who's been canceled, and you hate them now. [09:57.160 --> 10:05.200] What happens to a lot of people is they post personal things like family photos, and then they become more high-profile, and suddenly they don't want those up there anymore. [10:05.400 --> 10:07.240] Or maybe their account becomes a professional account. [10:08.500 --> 10:12.340] Sometimes people badmouth industries and then get jobs in those industries. [10:14.300 --> 10:17.200] Or maybe you just don't know what's in there, but don't have time to go through everything. [10:19.160 --> 10:30.580] And maybe you just don't want to be somewhere anymore because a company was taken over by fascists and fired its trust and safety team, and it's turned into a toxic cesspool, and you don't want to support it or contribute to its growth. [10:32.260 --> 10:34.640] Maybe not everything has to stick around indefinitely. [10:36.640 --> 10:42.800] And even if you don't want to detangle your data from a social media site, that doesn't mean that you don't have a lot of history. [10:44.000 --> 10:49.580] Or sorry, even if you do want... like, say you want to remove all your tweets, you might... there might be things in there that you need to look up in the future. [10:49.720 --> 10:53.880] Maybe you need to check receipts on something, because our memory can be unreliable. [10:54.780 --> 11:00.860] And it's also a form of research to see maybe what you wrote about in the past, because as we know, history echoes. [11:01.060 --> 11:03.940] Sometimes something pops up in the future, and you really need to find that information. [11:04.820 --> 11:09.720] So it's kind of a shame when it's just deleted forever, and you can't even look through it. [11:10.160 --> 11:15.180] And then sometimes tech companies also just block people or evoke access to data, which is terrifying. [11:15.720 --> 11:20.380] So I think that regularly archiving provides some level of protection against that. [11:21.100 --> 11:23.540] And I think that we should own our own data. [11:23.660 --> 11:28.120] Just because we choose to share it in a specific forum doesn't mean that that forum should own the data. [11:28.740 --> 11:33.600] And we should have control over where it goes, how long it stays, and be able to import it wherever we want. [11:33.600 --> 11:39.160] And companies should not retain control or ownership over data that we produce. [11:39.900 --> 11:43.500] And so I believe there should be no restrictions on data transfer. [11:47.450 --> 11:47.970] Okay. [11:48.150 --> 11:51.090] So we've discussed that archiving and deletion matter. [11:51.310 --> 11:52.290] What can we do about it? [11:52.430 --> 11:56.150] So the SID approach is that you stay in control as the user. [11:56.330 --> 11:58.050] So what's shown on the right is the SID application. [11:58.670 --> 12:02.970] It's an open-source desktop app that runs on your computer. [12:02.970 --> 12:06.670] It's written in Electron, so it has cross-platform support. [12:06.850 --> 12:13.670] And so we, as the developers, don't have access to any of your accounts, your account credentials, or any of the data in your accounts. [12:13.930 --> 12:23.710] So the way that it works is you sign into your social media accounts in an embedded browser, will download your data, and then prompt you to delete what you choose. [12:24.230 --> 12:30.670] So now let's look at some demos made using my Twitter account as Tribute. [12:31.050 --> 12:31.570] Okay. [12:31.710 --> 12:34.110] So here we see the embedded web browser. [12:34.630 --> 12:36.590] So you log in using your credentials. [12:36.590 --> 12:38.510] Again, the credentials stay on your system. [12:38.970 --> 12:48.230] And so once we log in, the first thing that SID is going to do is browse to populate your username and your avatar, your little profile picture. [12:49.690 --> 12:58.070] So the first thing that we want to do when we first use SID is populate a local database with all the data that's on Twitter in this case. [12:58.410 --> 13:02.330] So I'm saying, hey, I want to use the embedded web browser. [13:02.330 --> 13:06.210] So we also support using X's export tool, which we'll talk more about later. [13:06.210 --> 13:11.990] Here I'm unselecting the save my direct messages option so I don't embarrass myself in front of you all. [13:12.170 --> 13:14.670] And then SID lets you know what it's going to do. [13:14.790 --> 13:21.490] And then it's going to scroll down to the bottom of your Twitter timeline and then save them all. [13:21.590 --> 13:27.350] So it does the same thing with likes, bookmarks, DMs if you enable that option. [13:28.050 --> 13:30.330] So you get the general idea. [13:30.590 --> 13:34.210] So after a few minutes and how long that takes depends obviously on how much data you have. [13:39.790 --> 13:49.750] So once it finishes, it's going to build a database locally that has all of your tweet data, all the media, photos, videos, animated GIFs. [13:49.890 --> 13:52.570] And it's going to save that in a SQLite database. [13:53.890 --> 13:57.830] It also will populate a static site. [13:57.990 --> 14:00.070] So we generate a static site that you can browse locally. [14:00.070 --> 14:02.950] So here we'll scroll down. [14:03.150 --> 14:06.130] It has all your tweets, videos, images saved. [14:08.710 --> 14:13.150] So, you know, if for some reason you want to keep your Twitter data, you can do so. [14:14.470 --> 14:14.950] Okay. [14:15.130 --> 14:23.590] So now we've got a local database populated with all our Twitter data and we can delete our tweets or retweets. [14:24.830 --> 14:25.510] Or both. [14:25.870 --> 14:32.990] So here we've built a local database and I'm selecting, okay, yeah, I want to delete both tweets and retweets. [14:33.930 --> 14:36.250] So it's going to let you know, okay, here's what we're going to do. [14:36.350 --> 14:38.630] I had about 300 tweets and 300 retweets. [14:38.630 --> 14:46.090] And once we hit start deleting, you'll watch Sid slowly remove. [14:46.390 --> 14:46.590] Quickly. [14:46.770 --> 14:47.270] Quickly. [14:47.710 --> 14:48.210] Remove. [14:48.790 --> 14:49.710] So quick. [14:50.970 --> 14:51.630] Yeah. [14:51.690 --> 15:02.330] And so we have a beautiful quote here from Max Eddy at Wirecutter from New York Times, who was describing his emotional reaction to destroying his Twitter account. [15:02.330 --> 15:04.130] Photos from my wedding, gone. [15:04.370 --> 15:06.270] Photos of my pet rat, Peppa, gone. [15:06.670 --> 15:08.310] The process made me choke up a bit. [15:08.770 --> 15:11.710] He had a much stronger connection to his Twitter account than I do. [15:13.170 --> 15:18.510] But at the end of the process, all your tweets are deleted. [15:18.750 --> 15:22.130] And so now we'll talk a bit more about how Sid works. [15:24.430 --> 15:24.870] Okay. [15:25.050 --> 15:27.190] So Sid is an Electron app. [15:27.870 --> 15:32.370] And the reason why we picked Electron is because Sid needs to be able to control a web browser. [15:32.890 --> 15:40.410] And Electron has a web view tab that a lot of the other frameworks that we looked at don't have and don't support. [15:42.110 --> 15:55.510] And specifically, like, in this web view, we're able to load URLs, wait for the page to finish loading and then inject our own JavaScript into the web browser and get return values from, like, the functions that we call. [15:55.970 --> 16:02.230] So using that, we can, because we can inject JavaScript, we can basically completely control the browser and do whatever we want. [16:03.090 --> 16:06.710] And this, by the way, is why cross-site scripting is so bad, because it's the same thing. [16:06.830 --> 16:09.750] If you can inject JavaScript into a web page, you can do whatever you want. [16:10.430 --> 16:19.050] So this is what Sid was doing in that demo video where it's, like, scrolling down and loading all of your tweets to save them is it was just injecting JavaScript. [16:19.450 --> 16:30.730] So it would, like, load the page, wait for it to finish loading, inject some JavaScript to scroll to the bottom, and then wait for that to finish, and then inject some JavaScript to scroll to the bottom and wait for that to finish until it gets to the very bottom. [16:31.850 --> 16:41.150] It turns out that most of the data that Sid needs to collect when you're actually, like, Like downloading the local database isn't actually in the dom tree. [16:42.070 --> 16:45.030] But it is still in the browser context. [16:45.830 --> 16:51.750] So it's in API responses that get sent to the browser. [16:52.250 --> 16:54.630] So Sid doesn't directly use the X API. [16:55.370 --> 16:56.310] We can't. [16:56.450 --> 16:57.950] It's stupidly expensive. [16:58.330 --> 17:00.070] And this is like an open-source thing that anyone can use. [17:00.250 --> 17:03.930] But the X web application does use the X API. [17:04.310 --> 17:06.710] So when we load X. [17:07.470 --> 17:09.990] Then the browser is sitting there making all these API requests. [17:10.150 --> 17:13.510] And we can like look at those API responses in order to get the data. [17:14.530 --> 17:21.210] So here's a screenshot of Firefox web developer tools inspecting one of the API responses with a bunch of tweets. [17:21.430 --> 17:29.250] So each time you scroll down and it loads more tweets, this is the API response that it gets. [17:29.410 --> 17:38.690] And then here's a list of all of the tweets, including like all of the data that we want, like the number of retweets and the number of likes and things like that, which is not not easily available from the DOM. [17:39.350 --> 17:41.410] But it's a bit more complicated than this. [17:42.750 --> 17:50.490] So in Electron, Sid can monitor HTTP headers that are going through the web view tag. [17:50.730 --> 17:55.510] But it can't actually see the HTTP response bodies because they're using HTTPS. [17:56.110 --> 18:01.710] But what we can do is we can make all the traffic in the web view go through a proxy server. [18:02.290 --> 18:06.450] And we can also define exactly how certificates get verified in the web view. [18:07.130 --> 18:14.650] So what Sid does is on your own computer, it creates a little man in the middle proxy server with a local self-signed certificate authority. [18:15.330 --> 18:26.370] And so when it injects JavaScript into the web view to scroll down all the way, the man in the middle keeps an eye out for specific API response bodies. [18:26.670 --> 18:30.730] And when it sees the types of data that it's looking for, it saves it to your local database. [18:31.530 --> 18:37.110] And note that the man in the middle proxy is only enabled, like, when we need to pull data out of the API. [18:37.370 --> 18:40.430] So it's not actually enabled, like, when you're logging into your X account. [18:40.650 --> 18:43.390] Although it's all happening locally on your computer anyway. [18:45.390 --> 18:49.510] And Sid doesn't pass... just passively read data from the X API. [18:50.110 --> 18:52.190] It also writes to it when you're deleting tweets. [18:52.510 --> 18:57.230] So the first version of Sid deleted tweets one at a time basically like this. [18:57.350 --> 19:00.710] It would load a tweet, wait for the page to finish loading, click a menu, click a menu, click a menu, click a menu. [19:01.370 --> 19:05.590] Click delete tweet, click yes, I'm sure, wait for it to finish loading. [19:05.950 --> 19:07.630] And then when that's done, load the next tweet. [19:08.210 --> 19:09.910] And this would take a very long time. [19:10.090 --> 19:15.170] And just loading, like, like hundreds and hundreds of tweets would start triggering rate limits. [19:15.470 --> 19:23.630] And so the X rate limits are basically if you do enough stuff in a small period of time, it makes you pause for 15 minutes. [19:23.870 --> 19:26.750] So it would end up taking, like, a very long time. [19:27.910 --> 19:36.030] But we discovered that it's much faster to just send an API request to delete each tweet, but, like, from the web browser's browser context. [19:37.370 --> 19:40.070] So here's how Sid deletes tweets now. [19:41.330 --> 19:51.370] This way is basically equivalent to loading X.com, signing into your account, opening developer tools, and then copying and pasting some JavaScript into your console and running it. [19:51.910 --> 19:57.650] And it's hundreds or even thousands of times faster than manually deleting, clicking around to delete each tweet. [19:57.950 --> 20:03.330] And for some reason, the deleting tweet endpoint is not actually rate limited. [20:03.550 --> 20:04.950] So it just, like, goes through. [20:05.250 --> 20:08.830] But if it does become rate limited, Sid watches for that and respects it. [20:10.510 --> 20:14.550] And also, I'd like to thank Luca Hammer for this trick, which Sid copied. [20:15.210 --> 20:21.950] He made it this really popular project called TweetXer for quickly deleting all of your tweets using this trick. [20:22.210 --> 20:27.150] And it literally works by logging into your Twitter account and copying and pasting stuff into your console. [20:28.070 --> 20:31.050] And so Sid basically just does this, but it's very user-friendly. [20:31.230 --> 20:34.550] You just install it on your computer and click the button, and it just does it for you. [20:39.670 --> 20:40.150] Okay. [20:40.230 --> 20:46.530] So talking through a few of the other technical challenges that one encounters on a project like this. [20:47.310 --> 20:49.430] So reverse engineering platform. [20:49.730 --> 20:51.710] So there's really two sub-problems. [20:51.790 --> 20:54.550] One is reverse engineering how a new platform works. [20:54.590 --> 20:57.370] So we've talked a little bit about that. [20:57.510 --> 21:00.070] We've done some work trying to add Facebook support. [21:00.450 --> 21:02.070] And it's a huge effort. [21:02.230 --> 21:04.070] The platform is kind of a mess. [21:04.430 --> 21:06.410] And so that's a new platform. [21:06.810 --> 21:11.010] And there's also challenges just maintaining support for an existing platform. [21:12.030 --> 21:15.670] We need to detect when things change so that we can adapt. [21:15.670 --> 21:20.350] There have been times where a change on the web interface is broken Sid. [21:20.590 --> 21:26.150] There's also cases where changes occur in a subset of users when an experiment is occurring on the web app. [21:26.250 --> 21:27.930] So we also need to be somewhat flexible. [21:28.450 --> 21:33.250] And so the way that's been handled thus far is by having automatic reporting of errors. [21:33.430 --> 21:34.570] So that's what's shown on the screen. [21:35.090 --> 21:40.350] Along with optional, more detailed context data that helps us reproduce what's going on. [21:40.350 --> 21:44.390] So for example, a screenshot of what page and what the user is seeing. [21:44.490 --> 21:47.190] Obviously, if the user feels comfortable sharing that information. [21:47.490 --> 21:54.150] So if we start getting a lot of emails with these error reports, then it means we probably need to check if something changed on the web interface. [21:55.230 --> 21:58.210] Another challenge that we mentioned briefly are rate limits. [21:58.210 --> 22:02.310] So Twitter rate limits, most API endpoints. [22:02.590 --> 22:05.590] And so the X API provides information in HTTP headers. [22:05.690 --> 22:09.090] So I'm showing a screenshot of the developer docs here. [22:09.210 --> 22:13.990] So it provides information like how many more requests we can make in a particular time window. [22:13.990 --> 22:19.390] Or if we've triggered a rate limit, how long we need to wait before doing another request. [22:19.390 --> 22:22.030] So this is something we can and do look for. [22:22.910 --> 22:29.130] So here's a little snippet just from using BurpSuite proxy to capture the HTTP response from Twitter. [22:29.130 --> 22:32.010] And you can see one of the headers in the response. [22:32.150 --> 22:37.310] So what we do in the SID application is go as fast as we can until we hit a rate limit. [22:37.450 --> 22:41.850] Then wait the required time plus one second and then go as fast as we can again. [22:41.890 --> 22:44.910] So we're going as fast as the platform allows us to. [22:46.390 --> 22:55.270] Another challenge that you've probably seen on the Internet in general is now that AI is pretty capable of solving a wide array of problems. [22:55.590 --> 22:57.630] There's increasingly weird captures. [22:59.090 --> 23:06.190] This was a very strange one that I saw on Reddit when I guess AI were not yet doing advanced shape rotation. [23:07.250 --> 23:13.190] This isn't the worst for a project like SID because ultimately SID is a tool that the user is in control. [23:13.190 --> 23:14.810] They're sitting at their desktop. [23:15.670 --> 23:17.210] It's not fully automated. [23:17.410 --> 23:18.390] The user is a human. [23:18.610 --> 23:22.510] So if a capture pops up, we can have the user complete the capture. [23:22.730 --> 23:24.870] So we don't handle this super well right now. [23:25.090 --> 23:29.030] But it is an issue that SID's approach in general can handle nicely. [23:30.030 --> 23:34.430] And if you feel inspired to contribute to SID, there's a ticket there that is related to this. [23:36.250 --> 23:41.430] Another challenge is there are limits on building this database from scratch. [23:41.650 --> 23:44.470] So this is a snippet from our documentation. [23:44.790 --> 23:59.650] So you saw in the video, we started that process populating a database and we did it by scanning through my timeline, scrolling down repeatedly to see the end of my Twitter profile until we saw all of the tweets. [23:59.650 --> 24:07.810] But when you do this and I count that tweets a lot more than I did, it's not actually everything if you have more than about 2,000 tweets. [24:08.130 --> 24:13.310] In that case, you need to use Twitter's official export tool. [24:13.490 --> 24:17.130] So there are official data export tools provided by X. [24:17.250 --> 24:18.390] Meta has something similar. [24:18.390 --> 24:20.610] And that is a good thing. [24:20.750 --> 24:25.510] And we do support importing the data export file provided by X. [24:25.650 --> 24:31.230] And we've done a lot of work trying to support the same thing with meta exports with regard to Facebook data. [24:31.410 --> 24:34.770] So there are some caveats and challenges with this. [24:34.910 --> 24:39.970] The first is that the user needs to manually go and request this data file. [24:40.190 --> 24:45.290] The generation of this data file can take hours, sometimes days. [24:45.650 --> 24:53.490] So when the user decides, hey, I'm going to delete Twitter, it might be a multi-day process if they need to go the route of downloading their X archive first. [24:53.710 --> 24:55.750] So it's kind of a clunky experience. [24:57.250 --> 25:05.090] But if you have a lot of data and you want to delete your Twitter data, you should go to this page and request your data now. [25:06.510 --> 25:14.810] So even if you get past all of those like UX issues, the exports might not have the data that we need to do the deletion. [25:14.910 --> 25:24.390] So for Facebook, when we, you know, we were trying to replicate this process with Facebook, started with the exports and found that the exports don't have the information that we need, don't have the unique ID. [25:24.390 --> 25:29.150] We need to reference a particular post such that we could delete it. [25:29.270 --> 25:37.450] So that limits our options considerably and what we can provide to users because we wanted to provide the options of, hey, maybe only delete stuff that wasn't popular. [25:37.750 --> 25:38.350] Things like that. [25:38.770 --> 25:42.670] Which we can do with X, but we can't do with meta from the export. [25:43.290 --> 25:48.830] There's also the fact that you're trusting that this is going to continue to exist relying on these export tools. [25:48.830 --> 25:51.530] They can turn this off whenever they want. [25:51.710 --> 25:57.990] And we do also have reports that some more high profile users have been unable to use these export tools. [25:59.570 --> 26:01.830] So kind of switching gears a little bit. [26:02.010 --> 26:09.550] Another feature that Sid supports is migrating your tweets to another platform like Blue Sky. [26:09.750 --> 26:11.490] So here we'll show a little demo of that. [26:12.050 --> 26:15.250] So here Sid real quick, maybe we'll just pause for a second. [26:15.430 --> 26:17.870] So it's showing me what can be migrated. [26:17.870 --> 26:27.490] So migrating replies doesn't really make sense, but regular tweets of images, videos, animated GIFs, and so on can. [26:27.870 --> 26:36.810] And so in this case, it's going to go through and post the tweets that can be migrated to the Blue Sky account that I authenticate with. [26:36.810 --> 26:39.830] So it takes a little second. [26:40.390 --> 26:41.730] And then, yeah. [26:42.610 --> 26:53.310] Once it finishes, you can see on Blue Sky, now this is in the Blue Sky web app, the migrated tweets, which you can then click on. [26:53.530 --> 26:58.130] And one of the nice features is there's a backdated timestamp support in AppProto. [26:59.150 --> 27:05.570] So on each post, it shows, hey, this is an archive post from a particular time, which is the original post time on Twitter. [27:05.790 --> 27:09.130] And Blue Sky is clear that, you know, they don't have a way to validate that. [27:09.650 --> 27:11.190] So it's presented fairly nicely. [27:14.650 --> 27:15.130] Okay. [27:16.850 --> 27:17.330] Okay. [27:17.490 --> 27:24.050] So when we added, started to add Blue Sky support to Sid, it was like a breath of fresh air compared to working with X. [27:25.210 --> 27:34.890] And so if you're not familiar with it, Blue Sky is based on the AppProto, which is an open and decentralized network for building social apps. [27:35.190 --> 27:37.390] And Blue Sky is only sort of decentralized. [27:38.150 --> 27:39.850] Right now, it's mostly centralized. [27:40.090 --> 27:43.610] There's mostly just one Blue Sky, but it has 38 million users. [27:43.610 --> 27:54.410] But it supports migrating those users to and all of their followers and everything to other app proto social apps if they ever start appearing. [27:55.070 --> 28:02.650] And then it also has a bunch of other decentralized components like custom algorithmic feeds that people are running and labeling services and things like that. [28:03.350 --> 28:13.510] And adding the migrate to Blue Sky feature was really easy because we could just use Blue Sky's open APIs and libraries and don't have to do all this browser automation stuff. [28:16.350 --> 28:20.410] And like Redshift Zero was saying, one of the cool things is backdated timestamps. [28:21.190 --> 28:27.310] So if you migrate your tweets into a Blue Sky account, the posts will have two timestamps. [28:28.050 --> 28:33.270] The time that you actually just migrated it and then the historical time that you originally posted it to Twitter. [28:33.430 --> 28:37.130] And this is what it looks like when you click on the archived tweet thing. [28:37.130 --> 28:46.110] And we've also talked about trying to support migrating into Mastodon also, but Mastodon doesn't support backdated timestamps. [28:46.410 --> 28:52.850] And there's also complicated things about different instances supporting different lengths of posts and things like that. [28:54.430 --> 28:55.110] Yeah. [28:55.110 --> 28:57.590] We can't do that yet, but maybe someday. [29:00.330 --> 29:04.290] And yeah, so when I first made semi-ethemoral, it was pretty popular. [29:04.530 --> 29:10.970] And it turns out that a lot of people really wanted to just be able to delete their old tweets, but not actually stop using Twitter. [29:11.190 --> 29:13.370] They wanted to have an ephemeral account. [29:13.570 --> 29:21.490] So you continually, like, you know, are glued to your phone and tweeting all the time or whatever, but only the last, like, month of tweets is available. [29:21.490 --> 29:23.250] And then everything else automatically deletes. [29:24.010 --> 29:28.590] But one issue that we're having with Sid right now is that nobody wants to keep using X. [29:30.710 --> 29:35.470] Some people are still using it, but the consensus is that X is fucking awful. [29:37.190 --> 29:46.470] So most people who use Sid basically use it once to back up their data, delete their tweets, and just say good riddance to the Nazi site. [29:47.950 --> 29:55.390] So this is why, in the future, we're planning on adding blue sky, like, full blue sky support to Sid, so that people... [29:55.390 --> 29:58.330] So that basically Sid could be kind of, like, semi-ethemoral for blue sky. [29:58.490 --> 30:03.330] So that you could actually just have an ephemeral blue sky account where things automatically get deleted. [30:03.550 --> 30:10.010] And, you know, with all of the same settings where you could actively be posting to blue sky, and if something goes viral, you can keep that. [30:10.210 --> 30:14.530] But you can just delete all of the, like, 95% of the crap you don't care about, basically. [30:19.910 --> 30:21.930] So far, Sid's been pretty popular. [30:23.430 --> 30:28.310] It's indexed over 37 million tweets and 17 million retweets. [30:28.770 --> 30:34.470] Sid has also deleted 29 million tweets and almost 13 million retweets. [30:34.790 --> 30:36.410] And then migration is a paid feature. [30:37.090 --> 30:42.150] But even so, people have used Sid to migrate just under 83,000 tweets to blue sky. [30:44.150 --> 30:46.550] So Lockdown Systems is a worker-owned collective. [30:46.550 --> 30:51.950] And our goals are to build freedom and privacy tech to enable consumers to... [30:51.950 --> 30:54.230] Sorry, users to take control of their data. [30:54.690 --> 31:00.110] Choose what to reveal to the world and protect themselves from unwanted surveillance. [31:00.910 --> 31:05.970] So Lockdown Systems exists to help people pry back their data from big tech. [31:05.970 --> 31:11.770] And we wanted to try something a little different with the collective structure by using consensus decision-making. [31:12.290 --> 31:16.210] And while we do accept donations and grants, we still operate as a company. [31:16.910 --> 31:19.370] And next, we're going to talk about our two other projects. [31:22.650 --> 31:33.190] So onion share is an open-source tool that I started in 2014 to make it easy to anonymously and securely share files using Tor onion services. [31:34.050 --> 31:39.350] It works by running a local web server on your computer and then turning that into a Tor onion service. [31:39.630 --> 31:45.270] And then you can just share the Tor URL with people and they can connect directly into your computer and download files. [31:46.070 --> 32:00.910] I initially made onion share to make it easier for journalists that I was working with to send Snowden documents over the Internet without having to risk physically carrying USB sticks like over borders and stuff while they traveled. [32:01.690 --> 32:06.030] And since then, it's turned into a big open-source project with a large community of contributors. [32:06.870 --> 32:20.170] It supports sending files to other people and turning your computer into like an anonymous dropbox where people could just upload files to you and hosting static websites and hosting anonymous like ephemeral chat rooms. [32:20.830 --> 32:23.190] It's for windows and Linux and Mac. [32:23.470 --> 32:26.190] And there's also Android and iPhone versions. [32:27.030 --> 32:34.570] And soft talk, who is our collective member who couldn't make it to hope is one of the maintainers of the onion share project. [32:34.830 --> 32:40.630] So we decided that since we started this rad collective, we would just move this project under its control. [32:42.070 --> 32:43.670] Oh, this one's cool. [32:45.430 --> 32:46.090] All right. [32:46.230 --> 32:48.310] So this is our ICE detention map. [32:48.530 --> 32:55.690] So you've probably heard the Trump administration talk about how they're targeting murderers and human traffickers and other criminals for deportation. [32:56.310 --> 33:00.770] But ICE's own data, which we're showing here, demonstrates that this is a false narrative. [33:01.030 --> 33:10.330] So it turns out that ICE is required to publish weekly data on the population of individuals detained, including the facilities and the addresses that they are being held in. [33:10.410 --> 33:12.830] So you can look at this and watch ICE.org. [33:13.290 --> 33:18.970] It's a map so you can scroll around and zoom in, see your local area and see how many folks are being held. [33:19.910 --> 33:23.350] And there's information about who was considered a criminal. [33:23.350 --> 33:25.490] And there's this thing called the ICE threat level. [33:25.490 --> 33:31.030] So in this particular export, 71% of folks had no criminal records. [33:31.570 --> 33:36.950] So what we're doing is publishing each immigration detention center along with its population breakdown. [33:37.610 --> 33:43.450] And so the technical side is basically we're downloading the data from the ICE website. [33:43.590 --> 33:46.370] So ICE publishes this data in kind of an obscure page. [33:46.370 --> 33:47.850] You've got to scroll right to the bottom. [33:48.030 --> 33:49.930] And then there's an Excel spreadsheet. [33:50.090 --> 33:56.050] So we pass it, geocode all the facilities, and then republish this static site whenever new data comes out. [33:56.330 --> 34:00.230] And so this, like almost all our projects, is open-source and you can contribute. [34:08.080 --> 34:11.540] Your data is yours and SID gives you the power to take it back. [34:12.120 --> 34:15.800] And you can get involved by contributing to SID or our other projects. [34:15.800 --> 34:16.900] We also have a workshop. [34:17.540 --> 34:20.660] It's in an hour at 7 p.m. [34:20.740 --> 34:22.480] and the workshop seats hope into 23. [34:23.180 --> 34:24.780] We're also tabling during hope. [34:25.000 --> 34:26.380] We're selling these adorable stickers. [34:27.840 --> 34:32.260] And we have 20% off of SID premium with the code hope 2025. [34:33.220 --> 34:35.280] And we are, and we have time for questions. [34:36.340 --> 34:38.880] Oh, and also, so SID is open-source. [34:39.460 --> 34:45.720] But we are trying to figure out how to make it so that we can like spend more time working on lockdown systems. [34:46.180 --> 34:47.460] Instead of paid work. [34:48.300 --> 34:49.760] Because right now we're not really getting paid for it. [34:50.180 --> 34:55.500] So, so SID is a, it has like premium plans that you can buy. [34:55.660 --> 34:56.760] And so some of the features are premium. [34:57.020 --> 35:00.680] And then, and there's also like SID for teams. [35:00.860 --> 35:04.160] If you want to get like everyone at your workplace, the premium plan or whatever. [35:05.400 --> 35:08.960] And so like migrating tweets to blue sky is a premium feature. [35:09.160 --> 35:12.900] But we have 20% off coupon that works until the end of the month. [35:14.400 --> 35:14.840] Yeah. [35:17.160 --> 35:18.040] Any questions? [35:34.380 --> 35:37.120] Oh, and here's my mic for this side. [35:40.540 --> 35:42.020] Now that I'm all the way over here. [35:43.360 --> 35:45.020] Thank you all for, for what you're doing. [35:45.180 --> 35:45.680] It's amazing. [35:45.960 --> 35:53.180] I was curious as, as to whether you've had any pushback or, or fighting back from Twitter against things like SID working. [35:53.360 --> 35:54.860] Have there been countermeasures you've encountered? [35:55.100 --> 35:55.540] Things like that. [35:59.240 --> 36:02.340] We are unaware of any targeted countermeshes. [36:04.560 --> 36:08.240] We are, but humble programmers tending to our code bases. [36:08.940 --> 36:11.620] So, so I have a few questions. [36:11.620 --> 36:14.520] Um, how often does it break? [36:15.660 --> 36:20.460] And how, uh, how many platforms are you trying to support? [36:22.100 --> 36:23.380] That is a good question. [36:23.540 --> 36:27.400] So I think it's actually broken only like three times. [36:27.400 --> 36:33.160] Like there's been various bugs in SID, but there's been a, uh, that, you know, we still need to, to fix that are pending. [36:33.400 --> 36:39.080] But in terms of a change on X's website, breaking it, I think that's only happened like two or three times. [36:39.080 --> 36:45.940] It's, it's been kind of rare, but it's basically been like suddenly they like slightly changed the format of their API responses. [36:46.640 --> 36:50.760] And we suddenly realized that something that it like wasn't working to index tweets anymore. [36:50.940 --> 36:55.380] And then we'd have to go and like re reverse engineer it and fix the bug and then make a new release. [36:55.940 --> 37:04.140] Um, so basically at the moment we support X and, um, we have some basic support for Facebook, but not very much. [37:04.260 --> 37:07.300] But it's like hidden behind a feature flag because it's not ready yet. [37:07.300 --> 37:11.080] Um, and then we are going to add support for blue sky. [37:11.680 --> 37:13.500] Um, I mean, I don't know. [37:13.560 --> 37:19.860] At first I wanted to support like tons of stuff, but it turns out that it's a lot of work when you don't, when you can't use the API. [37:20.400 --> 37:28.740] Um, so I think that, that like, it'll be way easier to just add support to stuff that, you know, isn't a piece of shit where you're able to use the API. [37:29.420 --> 37:30.740] Cause it'll be way easier. [37:31.240 --> 37:38.820] Um, so like, so yeah, like I think that blue sky support will probably come long before, like, you know, Reddit or other things. [37:41.120 --> 37:45.300] As the non-coder on the team, I'm always really impressed by how quickly the bugs get fixed. [37:45.780 --> 37:52.140] Uh, thank you very much for the work you're doing, especially on the ice tracker. [37:52.140 --> 37:54.840] I've come across it and it's yeah. [37:55.080 --> 37:55.420] Great work. [37:56.020 --> 38:02.940] Um, for the, um, Twitter slash X, what if you've already like deleted the account? [38:03.140 --> 38:04.340] I mean, archive the stuff. [38:04.540 --> 38:08.520] Are you able to use it to upload that archive? [38:08.740 --> 38:12.580] Or is it only if you've actually used it to remove it? [38:12.580 --> 38:16.840] So if you have the archive, then yes, you can load the archive. [38:16.980 --> 38:17.880] We just released that feature. [38:17.920 --> 38:21.720] Like in the last month, you can use the archive to migrate stuff to blue sky, for example. [38:21.900 --> 38:22.720] So that does exist. [38:22.940 --> 38:27.380] So when you first load it and you click X, there'll be a little button that says archive only mode. [38:27.760 --> 38:28.160] Yeah. [38:28.260 --> 38:28.560] Thank you. [38:31.520 --> 38:32.900] Who did the illustrations? [38:34.180 --> 38:36.220] Oh, this is a one dark one. [38:36.400 --> 38:38.300] She is awesome. [38:38.300 --> 38:43.100] And she made all of the art for us and all of the collective members. [38:43.120 --> 38:44.220] We all have our own turtle. [38:44.460 --> 38:46.240] So we're kind of like the Ninja Turtles. [38:46.480 --> 38:46.960] Yeah. [38:48.280 --> 38:48.760] Yeah. [38:48.900 --> 38:53.280] I'm gonna, uh, uh, like bring this back to my company. [38:53.940 --> 38:54.680] Thank you. [38:54.880 --> 38:55.040] Yeah. [38:55.320 --> 38:58.840] Uh, hot iron creative is the name of her like design logo design thing. [39:01.320 --> 39:04.960] I have some questions from the online audience. [39:08.120 --> 39:10.700] So the first one that comes from ghost potato. [39:11.420 --> 39:15.260] Is I never really used Twitter, but I did use Facebook for many years. [39:15.620 --> 39:18.860] I've wanted to clean out that entire account, but it's brutal to handle manually. [39:19.160 --> 39:24.840] Is there any plan to have Sid also support scrubbing data out of other sites such as Facebook in the future? [39:25.840 --> 39:27.740] Out of other sites as well as Facebook or? [39:27.940 --> 39:28.700] Such as Facebook. [39:28.720 --> 39:29.120] Such as Facebook. [39:29.480 --> 39:30.500] Um, yes. [39:30.680 --> 39:36.380] And we actually, we are going to implement, uh, deleting stuff from Facebook. [39:36.560 --> 39:46.520] It's just take, it's taking way longer than we thought it would, because Facebook is like a really sloppy nightmare that was, you know, crafted over the course of like 20 years of spaghetti. [39:47.060 --> 39:51.000] So, um, uh, but yeah, we are going to, to make it. [39:51.180 --> 39:54.880] I mean, it's also, Facebook is also challenging because there's so many different types of data. [39:54.880 --> 39:57.720] We're definitely going to make it so you could delete posts on your wall. [39:58.080 --> 40:04.140] But, um, you know, it's a whole other story about like, what about all of the Facebook groups that you're an admin of? [40:04.220 --> 40:05.260] What about Facebook Messenger? [40:05.420 --> 40:06.500] What about like all of that stuff? [40:07.000 --> 40:11.460] Um, uh, but yeah, we're definitely going to have at least partial support for Facebook. [40:11.460 --> 40:12.140] Great. [40:12.500 --> 40:14.340] And another one that comes in in case... [40:14.780 --> 40:16.660] I think you've talked a little bit about this, Mike. [40:16.820 --> 40:20.060] But, uh, this question is from Prestle Pirate. [40:20.440 --> 40:22.840] Will CID support migration to Mastodon? [40:23.000 --> 40:24.480] I think it was the backdating issue. [40:25.420 --> 40:27.680] Yeah, uh, we have an open issue for it. [40:27.800 --> 40:28.400] And it may be. [40:28.580 --> 40:37.260] I mean, part of, part of one of the things that we are running into is that like, we have limited time because we're not actually making money off of this yet. [40:37.260 --> 40:40.240] And so we're like spending our time on work that pays. [40:40.400 --> 40:50.520] And so when we do spend our time on it, it's like one of the reasons why I'm really more into blue sky at the moment is because blue sky has like 38 million users. [40:50.900 --> 40:53.300] And the entire fediverse has like less than a million. [40:53.520 --> 40:59.600] And so it just seems like it might be like positively affecting way more people to go with blue sky. [40:59.780 --> 41:06.920] But I would like, uh, it'd be awesome if Mastodon was, uh, uh, support existed and it's an open-source project. [41:06.920 --> 41:12.240] So if anybody wants to work on Mastodon support, we will absolutely like review your pull requests. [41:13.040 --> 41:24.980] And that's probably a good segue into another question from, this is BX Roberts who asked, uh, can you talk a little bit about how you are a worker owned collective? [41:25.160 --> 41:27.020] How do you approach decision making and all that? [41:27.920 --> 41:29.040] Do you want to? [41:29.140 --> 41:29.220] Sure. [41:30.620 --> 41:32.540] Uh, yeah, so it's actually pretty fun. [41:32.540 --> 41:33.960] We have, uh, regular meetings. [41:34.220 --> 41:39.160] We take turns, um, with facilitation and, um, et cetera. [41:39.640 --> 41:42.260] Um, and yeah, we make decisions collectively. [41:42.360 --> 41:48.080] So we make proposals and they're voted or not voted on, but it's like, uh, by the consensus. [41:48.180 --> 41:50.120] So we all, uh, agree to it. [41:50.240 --> 41:53.580] It's kind of a new, it's kind of new to me, but it's pretty cool. [41:55.420 --> 42:00.980] Um, yeah, it's like, so it's, it's decision make, like our whole decision making process. [42:01.140 --> 42:02.260] There's no one in charge. [42:02.560 --> 42:03.320] There's no leaders. [42:03.560 --> 42:05.200] We're all like collective members. [42:05.200 --> 42:23.220] We all each have like one vote in a decision, except that the way decision making works is like, if we want to do something like, oh, let's, uh, you know, uh, switch from, uh, for example, switch from using like proton drive to using a self hosted next cloud, [42:23.560 --> 42:29.980] then we, um, someone makes a proposal and then, you know, we talk about it and then to see if anyone has concerns. [42:29.980 --> 42:35.940] And if, uh, someone has a concern, then we like, you know, make a competing proposal that addresses that concern. [42:36.080 --> 42:39.580] And then when everyone agrees, that's consensus and we've made a decision. [42:39.980 --> 42:44.740] Um, so it's kind of, it's kind of cool to not have, uh, a boss. [42:58.350 --> 43:00.570] Um, I don't really have any questions, but I have a question. [43:00.570 --> 43:08.050] But I just wanted to like make a comment, which is you guys are very, doing very important work and I'm inspired and, um, keep doing what you're doing. [43:08.090 --> 43:10.790] And I hope to get involved in different ways. [43:10.990 --> 43:12.550] And, uh, thank, thank you so much. [43:13.110 --> 43:13.790] Thank you. [43:20.000 --> 43:30.860] To what extent are you confident that in the aftermath of deletions as seen from the UI and public sphere, that backend deletions are actually occurring within a fixed, uh, predictable retention? [43:32.360 --> 43:32.920] Wait. [43:33.320 --> 43:33.860] Sorry. [43:33.940 --> 43:34.440] Can you say that again? [43:34.660 --> 43:35.260] Yeah, sure. [43:35.300 --> 43:36.020] I don't quite understand. [43:37.020 --> 43:44.960] Uh, you're using the API to delete things or using, you know, effectively the API to delete things through the user interface and the browser simulation. [43:45.940 --> 43:55.880] Uh, this does address the threat model of information being publicly findable by a not particularly resourced adversary. [43:55.880 --> 43:58.960] To what extent are you confident that Elon no longer has backups? [43:59.700 --> 44:00.960] Oh, I see what you mean. [44:02.020 --> 44:02.300] Do you want to? [44:02.400 --> 44:02.560] Yeah. [44:04.520 --> 44:04.960] Yeah. [44:05.060 --> 44:06.380] I mean, there's like several problems. [44:06.600 --> 44:11.380] One is, you know, just cause Twitter says they've deleted something doesn't necessarily make it so. [44:11.580 --> 44:14.660] And we don't know, I think is the honest answer to that. [44:14.860 --> 44:21.060] There's also the case that we know of various, uh, government contractors that are scraping social media. [44:21.240 --> 44:21.720] Volunteer. [44:22.020 --> 44:22.340] Sorry. [44:23.420 --> 44:23.900] Yes. [44:24.020 --> 44:24.760] They ruined that name. [44:24.920 --> 44:26.520] Um, yeah. [44:26.720 --> 44:28.220] And so that's the thing that we know is happening. [44:28.600 --> 44:32.120] Um, and so once that scrape has been done, like it's going to be hard to remove. [44:32.300 --> 44:32.380] Yeah. [44:37.560 --> 44:48.260] So you mentioned that the, uh, Twitter web app uses the Twitter API internally, but is presumably not subject to those API costs. [44:48.260 --> 44:59.320] I assume the web UI manages to authenticate itself somehow to, to Twitter, uh, to, to, well, whatever you, whatever we're going to call it. [44:59.960 --> 45:04.780] Um, how does that, how does that work? [45:05.020 --> 45:13.860] And did you explore the possibility of reverse engineering it so that you could use the API directly? [45:16.260 --> 45:21.240] I mean, we, we sort of do use the API directly for the deleting posts, sort of. [45:21.780 --> 45:26.100] Um, but the way that it works is x.com is a web application. [45:26.500 --> 45:32.680] Uh, when you sign into an account, it sets a cookie in your browser that says, like, okay, you have an active session. [45:32.860 --> 45:39.740] And so, um, and then whenever you, now that you're logged in, when it makes requests to the API server, it's authenticated as you. [45:39.740 --> 45:51.780] And so the fact that we are not just like using curl to make these API requests, but we're making the API requests from within the context of the signed in web browser is why, is how the API knows who you are. [45:51.900 --> 45:53.300] So that's how, that's how it works. [45:53.880 --> 46:02.380] Um, it, I mean, it might be pop, like, I'm pretty sure actually we, you probably can from within that context, make whatever API requests you want. [46:02.380 --> 46:11.140] And, uh, you know, you might get rate limited eventually for some of them, um, that, that it supports, uh, uh, uh, but we haven't actually really done that. [46:11.220 --> 46:13.120] But I, I do think that that is like a way around that. [46:13.240 --> 46:28.480] So if you wanted to, for example, um, scrape somebody else's, all of the, everything that, you know, like, uh, JD Vance has ever tweeted, then you can probably do that and get around the API limits from within the context of your own logged in account. [46:29.680 --> 46:30.240] Right. [46:30.600 --> 46:43.380] I guess what I'm wondering is, is there anything stopping you from, you know, using a browser to log into Twitter, extracting that token, and then using it from some program outside the browser, and if there's any benefits to doing that? [46:43.440 --> 46:44.520] There's nothing technically. [46:47.100 --> 46:51.240] Yes, there is nothing technically stopping us from doing something like that. [46:51.540 --> 46:51.620] Yeah. [46:51.920 --> 46:54.120] But potentially their terms of service. [46:54.560 --> 46:56.480] Yeah, there's like some legal gray area. [46:56.900 --> 46:57.560] Got it. [46:57.840 --> 46:57.960] Yeah. [47:02.390 --> 47:02.790] Yeah. [47:03.210 --> 47:05.190] I, I think this was timed perfectly. [47:05.490 --> 47:07.070] Do we, you have one more quick question? [47:07.250 --> 47:07.310] Yeah. [47:07.390 --> 47:08.610] We got to make it really quick though. [47:09.190 --> 47:13.010] Um, my question was around like plugability of making something like this. [47:13.130 --> 47:16.770] I see other people who are engaged in other people taking back their data, cleaning stuff up. [47:17.210 --> 47:24.730] How do you see this becoming a pluggable item for like a tool chain for other people to, to build ways for others, people to do more than just cleaning up their X? [47:26.310 --> 47:37.070] One of the nice things about Sid is when you save your date, like browse through your own account to save all your data, or even when you import from an archive, it saves it all in a SQLite database. [47:37.070 --> 47:39.830] It's just like in a file in your documents folder. [47:40.310 --> 47:43.850] So, I think that that could be, and it's, I mean, we're not using a standard or anything. [47:43.990 --> 47:45.110] We just like have our own schema. [47:45.570 --> 47:55.090] Um, but I do think that you could use Sid to like scrape a bunch of data and then you can like, you have a SQLite database, you can do whatever else you want with it with other tools. [47:55.090 --> 47:58.150] Um, so, so that is one thing. [47:58.190 --> 48:03.950] I mean, I think if, because it's a desktop app, it's kind of hard to like chain it together with other apps. [48:04.230 --> 48:08.610] Um, and it's kind of hard to not make it a desktop app, especially like the authentication stuff. [48:08.750 --> 48:14.250] Like if you're using a YubiKey to like sign into your X account, uh, how are you going to do that? [48:14.390 --> 48:16.970] You know, on a server when the script that you're running or whatever. [48:17.410 --> 48:24.650] Um, but you know, it is all like very transparent, how it's stored on your computer and it's just in a SQLite database. [48:25.270 --> 48:25.710] Thanks. [48:26.430 --> 48:27.030] All right. [48:27.130 --> 48:27.350] Wonderful. [48:27.650 --> 48:28.950] I think this is perfectly timed. [48:29.130 --> 48:31.070] Thank you everybody for your thoughtful questions. [48:31.230 --> 48:34.470] Let's give it up for Redshift Zero, Yael and Micah.