This is Brunei Telecom. The number you have dialed is incorrect. Please check the number before dialing again. Thank you. Thank you for listening to Off the Hook. The telephone keeps ringing, so I ripped it off the wall. I cut myself while shaving, now I can't make a call. We couldn't get much worse. But if they could, they would. One big leap on, but the best expected was. I hope that's understood. One big leap on. One big leap on. We'll be right back. And we have Rob T. Firefly. Good evening. Booming in like a thunderstorm. We have Gila. Hello. And I believe we have Alex somewhere in the world. That's correct. Good evening, everybody. I'm in Slovenia tonight. So, hello. Oh, I was going to guess that. Wow, Slovenia. Good. That's pretty cool. Ljubljana, I believe. No, I'm actually in Porto Rose tonight. So, I'm right on the Adriatic Sea, just down the street from Pirano. And next week, I'll be in another country, if we're on next week, that is. Okay. Well, that's okay. On assignment. Alex over there in Slovenia. Looking for maybe some statues to topple over. We'll see. We have not one special guest tonight. Not two, but three special guests. I don't think we've ever had three guests other than a pre-Hope show at the same time. But we're going to get to that in just a moment. I wanted to preamble that just a little bit by calling attention to the fact that you can't do anything on the Internet these days without being monitored in one way or another. Have you noticed that? I just started to realize that this week. You know, obviously, you buy something, you're tracked. You connect to something, you're tracked. One of your computers connects to another computer someplace, and it's just constantly giving your information out. And it just doesn't feel like it used to feel, you know, way back in the good old days. And that's what we're going to be talking about tonight, is something different, something new that's been introduced. In fact, The Register had a great headline about this new project, which is called VEILID. It's spelled V-E-I-L-I-D, VEILID. A secure peer-to-peer network for apps that flips off the surveillance economy. How could you not love that right away? Joining us tonight, we have, and I'm going to use your handles, if you want to inject your real names as well, you're welcome to. We have Dildog. Feel free to say hi. Hey there. Okay. I exist. We have Medusa. Hi. How you doing? And we have The Gibson. Hi, everybody. Nice to see you. And if I mispronounced any of those names, let me know. But now, you folks just gave a big presentation over at DEF CON in Vegas, introducing this new peer-to-peer network, which seems like nothing I've ever really heard before. It's very ambitious. Wikipedia describes it this way. A peer-to-peer network and application framework released by Cult of the Dead Cow, which, yes, you folks are part of that amazing organization that's existed since 1984. It's a peer-to-peer network, described by its authors as like Tor, but for apps. We'll explain that in a moment. It is written in Rust, runs on Linux, Mac OS, Windows, Android, iOS. And in browser WASM, VALID, I'm sorry, VALID chat is a secure messaging application built on VALID. It borrows from both the Tor anonymizing router and the interplanetary file system to offer encrypted and anonymous peer-to-peer connection using a 256-bit public key as the only visible ID. Even details such as IP addresses are hidden. Well, let's start with where the inspiration for this came from. And I imagine the inspiration probably came from the incredible surveillance we find ourselves under on a daily basis, increasingly. Yeah, I'll go ahead and start with a little bit of the history here. It was about four years ago, I was talking with Metas4 over here about the problems of social media. And we had started to see the cracks in the veneer of Twitter. And we've had a long history of problems with surveillance and monitoring of Facebook. And the question came around of how do we build something better? What would be the foundation that we would need to build to make privacy more accessible to everyone? Because, you know, you've got these great privacy frameworks like Tor and some initiatives around distributed storage. And you've got, you know, the federation-type social networks like Mastodon starting to come up. But a lot of the problems that these had were around accessibility, you know, making sure that, you know, your grandma or anybody else, the regular people out there that aren't, you know, Linux system administrators would have a hard time sort of understanding and reaching those things. So, you know, we talked about this for like a good long year, thinking about how to make something that could reach those people. And we settled on designing a privacy-oriented framework that people could build apps with, regular apps that look like any other app, except the key difference being that these apps could talk directly to each other. Instead of relying on a cloud run by some billionaire that's hoovering up all your personal data, you know, finding a way to use the fact that we all have supercomputers in our pockets these days. You know, we all have these thousand-dollar iPhones and Android devices with – and you're paying for bandwidth already. You know, you're already paid into this, you know, huge computer powerhouse that you carry around with you. Why not leverage that to build a cloud that is everyone's computer instead of some centralized thing? You know, there's naturally going to be some challenges around data provenance, like where does the data live? How do you keep it safe? How do you keep people's IP addresses safe? And how do you, you know, give developers a choice, a better choice about how to build applications so they don't feel the need to monetize every little thing about their users? I mean, maybe they want to sell ads. Maybe they want to do that stuff. But right now, if you have a big cloud bill to pay, you kind of have to. You can't offer free software because you've got bills, you know. So let's build a better system that removes some of the sort of perverse incentives to monetize people. You know, what strikes me is that why did it take so long for somebody to do something like this? Because this has been a problem for a while. It's getting to be more and more of a problem, obviously. But what you described, assuming it's easy to use, and that is key, that it's easy for non-technical people to be able to get a handle on this. But it would seem like somebody would have come up with an idea like this. Maybe it's just they didn't have the technical ability to put it together. Is that possible? There was some prior art, you know. You know, there's, you know, other little pieces of this. And again, you know, you've got a solution for private routing with Tor. But Tor kind of requires that you know how to set up a proxy and that you know what a proxy is. You know, there's IPFS, but you, again, have to set up a server someplace, and you don't have to know how all that works. So really, this is an accessibility thing. And, you know, there's so many technologists that build great tools but don't focus on accessibility in the end user. You know, getting all of the right things together in one place but with the only success criteria being zero configuration, make it accessible to everybody, make it work with every kind of app. You know, I want VALID in messengers and social networks, but I also want it in video games. You know, I want it, you know, in every kind of app, you know. And that's the, you know, it was one of the critical design requirements of VALID was that, you know, it would be a framework that every app could use, not just, you know, pigeonholing us as a, you know, privacy-specific browser or a privacy-specific framework. It's really got to provide the tools to build any kind of app. So that's what's going to make it successful, I think. Okay. Alex, I know you have something to say. Alex, go ahead. Yeah, we've got a little lag here because I'm on the other side of the world, and it's a little late. But I do have a couple of things. I have a couple of questions for you, Dildog or Gibson or Medusa, in terms of how this framework works. Could you explain to our listeners how this framework, this privacy-enhancing framework on which other things can be built would necessarily break this surveillance capitalism system that we see being employed universally throughout social media and throughout every popular app these days? So how does that – excuse me, how does that work with respect to Twitter or Facebook or whatever the newest idiotic thing from Facebook is called, threads or something like that? Yeah, well, I'm going to have everybody answer this alongside me because I think we all have different perspectives on this. But from my perspective, it's not necessarily going to be embraced by those who have a vested interest in the data economy. You're not going to rehabilitate Facebook or Twitter with this. But maybe it's time for people to build accessible alternatives to those services that don't have advertising or tracking built into them. I can tell you that I'm working on a chat app right now, and the chat app has zero cost to me. I write it. I publish it on the App Store. People – it's in beta right now in TestFlight. My cost is zero. There is no cloud bill. There's nothing. I don't have to make a choice to monetize anything about anybody. I don't have to sell ads. It literally costs me nothing to run the infrastructure here because it's all just the users using the app their way. Anyway, that's my perspective. Anybody else want to chime in there? I think one of the things that is really underlooked as far as a motivation for people to do things and pour their time and their energy into projects is the desire to do something that's worthwhile. Greed has kind of taken over our entire Internet, our industry, beyond just keeping the lights on and taking care of your family. I mean, these paychecks are getting huge, and people are used to that. And they don't feel like, you know, some people have the idea that they just need to get paid. And I think there's a way to, you know, balance that. I remember when I was invited more recently just a few years ago into the cult of the dead cow and how it felt to finally feel like I could maybe make a difference and do something with the platform that I was given. I wanted to get out there and half the planet, and I hope other people feel the same way. And that's why we wanted to do this, you know, not only as individuals but as a cult of the dead cow because I want to feel inspired. I want to feel motivated to get out there and do something that matters, and I hope that other people do too. And we're building a great community of people that all have that same ideal, and I'm really excited to see where it's going. Any thoughts from you, Gibson? Yeah, I mean, you know, I'm going to kind of double down on what both of you said. I ran Hackers.Town starting in 2017, and starting that process and seeing if a community showed up for it was kind of mind-blowing to me that people actually are there. I know, for example, Rob has an account there and hangs out with us pretty regularly. One of the things I've been saying since the very beginning, two things I've been saying since the very beginning. You know, I built that place, Cargo Culting, off the work of the Cult of the Dead Cow. And I knew it when I did it, and I will freely admit to that if anybody that asks, because I didn't see enough of that early hacker era mentality showing up in the modern age. And I may have been radicalized by political events around that time period. So, you know, I wanted to build something that was safe and allowed us to collaborate. And that happened, and people showed up for the party, and it was great. But, you know, even federated solutions like Mastodon have problems. Scrapers, ways that data can be mined off of those sites that are against the will of the people of the site or even the admins of the site. And having a distributed model like this that doesn't really have exit nodes onto the Internet, so to speak, and makes it very difficult to mine that data, makes that data mining experience so expensive at the end of the day that there's no profit in it. So, to me, there's two sides. As Dildog said, actually, there's three sides because I'm throwing everything here. As Dildog said, there's, you know, there's very little cost, if any, to running these apps. So it reduces the need for making money on the apps for the app to survive. Secondly, it's about community for me. I want a safe place for my people to go and not feel like they're being watched every second or every day, and not even necessarily for malicious reasons. You know, I don't want them feeling like their data is being mined to be used against them or to market to them. It's not fair. It shouldn't be there. And I feel like we dropped the ball 20 years ago as a community when we didn't be louder about this. Kudos to the people in this room. I know we were all pretty loud. But, you know, as a whole, we didn't fight back enough to slow this down and kind of said, oh, that's great. You know, we've got Facebook. That's cool. I don't have to host stuff anymore. Except at the end of the day, we still did because that data was just being hoovered up. So now we get to this point. And my last third point here is that, you know, we're restoring the future that was supposed to happen is the way I look at it. We are talked about this a lot, but we are in the position now where we're able to give people their own user agency back over their data, their data construct, if you will. And I don't see a difference between that data construct that you put out on the Internet and your physical or mental self that you contain within you. So they're all part of you and those rights belong to you. And we shouldn't be able to give those away at the click of a agree to EULA button. So that's why I'm here and why I think this is such a great turn of events, because we have finally some tooling that allows us to engender these values in the developer community at large. Go ahead, Alex. I love all three of those answers. I think they're fascinating. And the way in which you articulated the economic incentives underlying this foundation, I think, is what could really be very disruptive here. Because if you think about how Twitter works or how any of these massive platforms, it's all about this cloud computing bill that they have at the end of the month that is going to cause them essentially to be enslaved to that surveillance economy model. Because they are indentured servants to AWS, or they're indentured servants essentially to Microsoft Azure. So if you give developers an economic incentive to use this framework, namely avoidance of this massive bill every single month, the way I see this is maybe this is going to be something akin to a rebirth or a renaissance for things like free software. I remember way back in the 90s when we saw shareware coming out, and it was great because you could play around and you could download shareware where there's a lot of open source things going on. It was just such a greater sense of collaboration and more communities popping up where people supported each other in these types of endeavors. And it seems to me like this might create that kind of community again, unless I'm getting it wrong. I'd love to hear your thoughts on it. We've jokingly referred to this internally as Web 1.5 instead of Web 3 or Web 2 or whatever I said, taking it back to kind of those principles that we saw that were good about the Internet back in the 90s and making them modern and setting up a way to succeed at that, and while at the same time respecting user agency. Now, I have to ask, what has the reaction been so far since you guys introduced this? So far, the reaction has been fantastic. We built a small community on Discord for now, and thus far it's grown to about 1,400 people that are all working together, that are sharing different ways, that they are building and putting nodes on different things. I've seen nodes being put on – people are kind of trying to put them on the craziest things they can, and it's been wonderful to see just people come together. And it's not only the people that are, you know, technically capable enough to put nodes on. We've also got a lot of people in there that are, you know, want to make sure that they'll be able to help out with accessibility or, you know, marketing and getting this in the right hands and making sure that it's going to be approachable and usable for everyone, not just, you know, the people that are in – on this phone call or, you know, listening to this, the people that, you know, understand computers. You know, we have an entire generation of people that use maybe one to three websites. One of them is Facebook, they got Google, and maybe one more, but they're being tracked in every way, shape, or form, and we're kind of stuck using those websites because of them. And there's a lot of people that still use Facebook because they – that's the only way they really can connect with, you know, Aunt Sally or their neighbor growing up, and they can show off pictures of the kids and, you know, share with their life with them without having to actually make a phone call. And we're all kind of stuck using Facebook too, so if we can get those folks comfortable enough to get off the only social media platform that they've ever used, if we can get our parents off of Facebook, we are free. Wow. Kyle, go ahead. I just – I wanted to ask what – for some of our listeners who may not be developers and may not be working on the project, what is it like to use something that has implemented this and – or what can people expect when they do find it in different places? Is there anything different about using it with all of these different layers having increased protection? What does that look like functionally for users? Well, currently, there are no practical apps that use the framework yet. We are working on it. However, we do have a demonstration app called Valid Chat that should be open-sourced very soon. I am just working on cleaning up some of my ugly source code. But in general, you can expect that the apps that use Valid will feel practically the same as any other app. One of the sort of primary design constraints was that it was mobile first. So we're talking Android and iOS as well as Windows, Mac, Linux, et cetera, and web apps. But for that to really work, you have to be plugging into the kinds of frameworks that mobile app developers expect. So we chose Flutter as a sort of first flagship UI platform. So Flutter apps are things like – they'll look like your DoorDash app or the Instacart app. Those kinds of apps, React Native is coming along very quickly as well, support for that. So all of the sort of professional, smooth, web-oriented but mobile-first development frameworks that all these professional apps are written in, Valid is a first-class plug-in for all those things. So you won't really notice the difference. For Valid Chat, maybe signing up is a little different experience because you're not like putting in an email and a password and then have it email you to verify that you're at that email. You don't have to give Valid Chat your email. When you sign up, you put in a name you'd like to be referred to as, and it creates an invitation, which is like a little QR code or a little blob of text that you can paste to your friend, and your friend can accept your invitation by pasting that into their copy of Valid Chat. The actual sort of sign-up process is going to feel a little different. Right now, Valid does not have a concept of identity as like one blessed way to refer to people. That's sort of a feature as well as, you know, an early development constraint. But the idea here is that you're not going to be going through a lot of the same authentication systems that you might be used to. You're not going to log in with Apple or log in with Google. You're not going to be using – they're not going to have that opportunity to use your identity as like a convenient login. And that's sort of where the data collection process starts, you know, and we're trying to make sure that that isn't part of the apps that people write with Valid. Fascinating. Gila, did you have something? You're muted, Gila. Sorry. Let's try that again. I am actually transmitting a question that we have been asked over Mastodon from a listener who goes by the name Adam. So here's the question. Can you explain how Valid is different than I2P and why Valid doesn't leverage I2P under the hood? Wow. Okay. Well, I'm no expert on I2P, first off. Second, there are a lot of other frameworks out there. I started working on this four years ago specifically with mobile devices in mind. None of the other frameworks out there really considered the reality of switching between networks on a regular basis and having really high node churn. So a lot of these node-based systems have like an expectation of uptime to some extent. Valid was designed for something that might be offline and then come online on a cellular network and then get on a Wi-Fi network and then you drive past Starbucks and then switch to another one and then you get home and you're on your private network. Having nodes that are actually truly mobile does complicate some of the underlying routing and node liveness checks and things that you have to do. Designing with that in mind I felt was really important because that's how a lot of the sort of ad hoc nature of networks is going to be going forward. You're just not always going to have nodes that are static IPs or running on a little server in your house. I looked at a lot of the sort of Web 3.0 style cryptocurrency-based networks like this and a lot of them did sort of require some kind of either a device or some kind of server that you run. So we're not designing with this use case in mind. This way, I got a lot of design flexibility. Between that and some – I'd say that private routing is one of the big things we do differently and we do pretty well. But there's a lot of other design choices we made in Valid that did not translate from other systems. Like our distributed hash table model is very different. When you get down to it, it's faster. It has more data locality. I could go on and on about the technical reasons why I made those choices, but I wanted that creative flexibility, and I couldn't get that just embracing IPFS. Frankly, IPFS is slow. Tor, also kind of slow. But the reasons why they're kind of slow, for my use case anyway, kind of fade away a little bit if I can just take all the parts that are slow and optimize those down to just the parts we need. So, yeah, it was a performance and choice, but also you've got to get that core small enough that it could fit into a mobile app without any trouble. So there's a lot of technical design constraints. Rob, go ahead. Yeah, I think I'd like to go back a little bit to, I think, what Kyle mentioned and some others, which is the user end of this and how this is not an app in itself. It's a framework for apps. I think a lot of the power of this idea is in the security. When somebody, when a user, even a non-technical user, gets hold of an app that's built with this framework, it's going to be pretty much push a button and go. It's not going to require separate things like if you were using Tor or if you were using some sort of proxy or something else, the other common privacy-protecting methods out there. So, like, could you talk a little bit about that as just sort of what it means for the end user to be able to just use something that was developed on this? Yeah, and keeping in mind that most of our audience is non-technical. We're broadcasting in New York City. So, as if you're talking to an elderly relative, if we can get them excited about this. I think that's the mission here. I mean, ultimately, Caitlin, go ahead. Okay, well, somebody has to go. Ultimately, you know, thus far, a lot of privacy-focused apps have been very just difficult and kind of a pain to use. You know, it's very difficult to convince somebody that has been using, you know, their method of remembering passwords to even switch to something like a password manager, even though they know it's in their best interest. Just the, you know, absolute overwhelmingness of it all can be enough to turn somebody off from trying it. One of the things that we really want to build in from the beginning is making sure that these apps don't feel any different. Mastodon is wonderful in the way that it connects people and the way that they are, you know, handling privacy. And I'm not here to talk any smack about Mastodon, but they also make it extremely difficult for a person to sign in on mobile. And they did not put mobile first. And that's how most of us use social media these days. They didn't make it easy to, you know, sign back in after you had made a username. It just was very off-putting for most people. And that's why it didn't get widely adopted outside of the tech communities or, you know, the generations of people that grew up with the Internet. The difference with Valid is we want to create usable apps and helpful apps that don't feel any different. There is not going to be a time or a frustration cost to having that extra privacy. So, yeah, to speak to Rob's point, too, that's the whole point of the framework, right? Ultimately, we're providing that tool so that other developers can come in and develop apps that bake this in right from the layer zero, right? So whenever they start to build an app, they have a great idea for an app. They don't have to worry about figuring out how to make it private or secure it. And they can rely on the Valid framework to do that for them. So ultimately, it puts us in a position of being able to help anybody that wants to do this, anybody that wants to move into a more private model for the data economy, if you will. It gives them the tools to do that. So at the end of the day, the ease of use for that privacy becomes much simpler for all users because they're just downloading an app from an app store, right? And the privacy is baked in because it's at the base layer of everything that's programmed to operate. So ultimately, the idea is to change the entire way that your personal data's privacy is approached and make it easy for developers to do so so that everybody can benefit from this in the water. Something else that I think might be of interest to some of our casual listeners, you all mentioned Cult of the Dead Cow, and we've talked about that quite a bit. Can we say anything, perhaps something reassuring about it's not really a cult, there are no dead cows? What does it actually mean? Because we obviously all revere this organization, but why? I guess that's what I'm looking for. Why Cult of the Dead Cow? CDC, having a very long view on the computer social revolution, acknowledges that there's a lot of opportunity to sort of connect with people over different kinds of media. CDC's first publications were things that people would not get from Walden Books or your local bookstore. It was weird text files that you could get only from downloading from a bulletin board system, but it was homebrew publication. It was a way of reaching people with weird alternative ideas and cool stories and narrative fiction and the lyrics to Metallica songs. I mean, whatever it was, we had a channel to distribute the message of CDC. You know, over the years, we've done our best to sort of constantly, you know, we pull down the pants of Microsoft on a regular basis. You know, we got to be a thorn in the side of a lot of different organizations with either security advisories or various hijinks at different conferences. You know, our members have gotten involved in a lot of different political movements as well. You know, CDC is not just hackers. CDC is about a worldwide artistic and scientific effort to extend people's accessibility to weird information and cool things that they should, you know, be able to build communities around. You know, the hacker community is just one, but, you know, we've got, we're full of artists and musicians. You know, if anything, CDC is trying to be a worldwide organization and that requires a worldwide skill set. You don't build the revolution of application privacy on the back of just some hacker privacy mindset. You have to look at it from people and the way they communicate. CDC has a fundamental understanding of how people communicate. We've leveraged it sometimes for our own gain, sometimes for entertainment, you know, sometimes just for, you know, for the heck of it. You know, we've done some pretty loud and boisterous things. People pay attention. We're leveraging that. We're trying to, you know, use that pulpit that we have to spread the word that privacy is something that everyone deserves and it shouldn't be as hard to get as it is today. And if I'm not mistaken, you guys have been around for 40 years now? Yeah, some of us longer than others. That's, I mean, we have been too, but wow, that's, that's simply amazing. Alex, I believe you had some question. You're muted, Alex. Yeah, yeah, no, I'm, I'm just, I'm a little bit of a lag here. I love the history of the CDC. And I mean, I remember revering CDC back when I was 15 years old and was so excited to meet CDC members at the first HOPE conference back in 1994. And I think, was it the first HOPE conference or maybe the second one when the CDC revealed back Orifice? That was, you know, you talk about being a thorn in the side of Microsoft. That was, was that the first HOPE? That was actually at DEFCON 6. Oh, was it at DEFCON? The Sir Dystic released it at DEFCON 6 in 1998. Yeah, so that's quite some time ago. Oh, I thought it was at HOPE. Well, we were at HOPE shortly there after that. You probably ran into us at HOPE. Yeah, we talked about it. Yeah, we did. We did have a presentation. Gotcha. We've been celebrating the 25th anniversary of back Orifice. Oh, wow. Oh, wow. That is amazing. But, but I had, you know, another point, Kate, to go back to Vailant for a second, if we don't mind. And, but I think it really does dovetail with the evolution of CDC here. The point that I'm trying to make is that the times have changed. Things are different. A lot of the original CDC members were all grown up now. Some of us are, you know, cybersecurity professionals, politicians, lawyers, poets, et cetera. But a lot of us have kids, right? It's a lot of, you know, and, and here's where I think Vailant could be so interesting and, and really find a niche area. Because you think back to, God, was it last year? We're, we're in the throes of another election cycle. We're talking about my, he was eight or nine years old at then, my oldest child. But watching YouTube videos while we, we live in New York. We have a little house over in Pennsylvania. You know, I often do the radio show from there and he was bombarded because of his IP address being in Pennsylvania. And it was the midterm elections with political ads on kids, YouTube videos about John Fetterman and how he was going to release criminals out in the wild and destroy the character of Pennsylvania. You know, and this really upset my son. He didn't know what the hell was going on there. And so I see perhaps these apps that could be developed on the Vailant framework could be very parent-friendly or be very child-friendly in a sense because they are anti-surveillance. You know that your child is not going to be surveilled or tracked. And just the whole idea that my child has a profile on YouTube and is being tracked and psychologically profiled from such a young age, and that data will track with him forever if he's not careful about it, is really disquieting to me. I see Vailant as something that can break that cycle by not letting it even happen in the first place. Absolutely, and it gets more sinister than that, too. Not only are they, you know, advertising things to our children, but they're also collecting our data, and they're selling that off to the highest bidder. And I'm talking about various platforms here, but say you join a group, you know, a support group on Facebook about, you know, your depression or a health issue that you have. Do you think that somehow that's not going to, you know, find its way in the data economy to, you know, insurance carriers? And then someday, generations from now, that may be held against the people that you care about the most. And we're not really looking at the very sinister aspects of all of this. We just saw, you know, somebody was arrested recently due to planning to get some health care over Facebook Messenger. And that just shows that this is taking a very sinister turn. And we need to put a stop to it, not only for us, but, yes, for the future generations to come. And we're just talking about this country. Imagine in other countries where things might be even worse. This kind of a tool could be a lifesaver in many cases, I think. Absolutely. We talked about that extensively in the early days of this. Ultimately, the idea is to help engender that privacy of communications that we all feel like we can take for granted but doesn't exist anymore. And whether that be, you know, someone in an oppressive state or someone that's just looking to communicate quietly with someone they love, it doesn't matter. Right? Those things all come into play here. Good use is good use. And I think one of the other jokes we've had internally is calling this chaotic good as a service. Right? Ultimately, we want to empower people to be people. Now, are there any safety concerns that you've discussed? We know of good people that want to use this tool. What about bad people who might want to use this tool? Is there some kind of a freedom that you might inadvertently be giving evil people to carry on with their work? That was one of the things that, you know, Dill had brought to me from the very beginning. My history, personally, as far as any of this, where I found myself in life these days, and everything was a few years ago, somebody stole my ex's phone and shared some pictures on the Internet that I didn't want to be out there. And I got angry, and I started organizing other victims of what is commonly referred to as revenge porn, but I prefer to the term non-consensual image abuse. I started organizing the victims, helping change laws, and, you know, essentially, without realizing I had done it, I was doing a hacktivism. And, you know, that was the first time that I was introduced into any sort of community here, cybersecurity, hacking, any of that. And, you know, when Dill first approached me, he was, you know, a little concerned about that. He said, you know, we want to make sure that we are building something that is a net good for the world. And so we have really spent a lot of time discussing the various, you know, methods that we can use to keep this safe and to make sure that this isn't going to just turn into a big old monster. And we've got some ideas to address that when we get there, though, because as of right now, it is a framework. It is something for people to build with, and, you know, it's just the code. Once we get to the part where we're actually building apps and working with developers and getting those out there, that's when we're really going to be able to show some of the unique ways that we have started to address this issue and that we plan on approaching it. Yeah, there are, you know, going to be a lot of apps using Valid. The thing to remember is that Valid itself is just a framework for building apps. It doesn't make an effort to somewhat, I don't know, police what apps do with the framework. That said, it has been designed with sort of data provenance in mind. The one thing that, if anything, we've decided was a net good for the world was to make it difficult to simply dragnet the data of a bunch of innocent people. There are so many opportunities for people to get mislabeled or to accidentally stumble into these sort of data dragnets that have become, you know, fashionable letters to Facebook where they just dump everyone's private messages to law enforcement. You know, you know, you don't get a pass in the law enforcement community for simply, you know, warrantlessly searching everyone's information. Certain kinds of law enforcement actions should require more care from law enforcement than they, you know, and more sensitivity to the people being searched than they get today. It is somewhat of a reckless process by which people's data is hoovered into mass surveillance. This does not mean that, you know, criminals are given a pass to operate over Valid. Individual applications that do not adhere to, say, the app store policies of Apple or the Google Play store will still have their apps removed. You know, you know, you can't just go and, you know, do whatever you want over Valid and get away with it. You have to still follow the rules of these platforms that distribute the applications in the first place. So I don't think this makes things more difficult or any worse. You know, if people are going to do bad things today, they're going to do it over Tor. They're going to do it over other mediums. You know, the biggest, you know, non-consensual and underage, you know, pornography and, you know, image abuse, you know, the biggest offenders here are going to be the large social networks anyway. It's going to be the Facebooks. You know, they've got all this stuff. If anything, you know, they've started to tackle those issues by using technologies like Microsoft Photo DNA to scan pool, you know, scan people's uploads and, you know, look for missing and exploited children, stuff like that. You know, those are closed source technologies. Those are not accessible to every single app developer out there. And that's somewhat of a shame, you know, if Valid helps people demand access to libraries like that and tools. These databases, you know, you know, if you if you get enough people in charge of their own content instead of just outsourcing it all to Facebook, you're going to see making those kinds of like reports and collaborative efforts to, you know, unmask, you know, you know, people committing crimes or whatever you're going to you're going to have an opportunity to do that on a more personal level than simply centralizing everything and just drag netting people who might not actually have anything to do with it. You know, it's interesting because we talk about how people are being surveilled and monitored and watched, but I don't think people realize the extent of it. And Dildog, you mentioned Tor just a moment ago, and I believe at DEF CON, you said that the NSA runs 100 Tor exit nodes. I don't think most people realize that. What are the implications of something like that? Well, you know, it's, you know, not it turns out that it's not as hard as you'd think to to monitor systems like that when you have control over the the way people use it from the entry point to the exit point. You know, with valid, you know, with valid, you're looking at millions and millions of nodes, it becomes harder to, to monetize, sorry, monetize, I keep saying that word, but to monitor, you know, when you have that many nodes. The more data, the long and short is that if you keep the data in the network, it becomes a lot harder to, to, to monitor it and to, to, to spy on it. But as soon as you leave the network, then, you know, you're back on the regular internet, unencrypted and, you know, so if there is no edge, you, you don't get anything by monitoring the edge that doesn't exist, you know? So we're trying to make sure that everything can be done in network and it will make things a lot safer for people. Last question I have to ask, tell us about the name. It, this was my creation. It is valid, veiled ID. Okay. Just a bunch of words that I just put together and it works. And there has been a lot of, you know, you asked earlier what the response was, has been thus far. And there's been a lot of talk about our name. And that seems to be the thing that everybody is, you know, the most upset about thus far. So, Hey, if we're, I like the name, why people have said it, the name? I mean, maybe you could, you could capitalize ID if you want to make it more obvious, but I don't, I don't think you need to. People keep mispronouncing it or they just, they don't like the name, but we're rolling with it. It doesn't matter. Just say it's a framework and say like, no, it's not an app. It doesn't have to be, it's like whiz bang. I didn't like the name 2600 when we started and look what happened. So it's a, yeah, don't listen to them. Right. Okay. We're in our last minute, contact info, ways that people can, can get involved, learn more. Go for it. Everything is on valid.com. That's spelled V E I L I D.com. You can check out the code. There's links to the community. We talk about our ideals there. People that, you know, have questions can always join our discord. That's also listed on there, or they can follow us on various social media apps. If anybody wants to talk about those. Does anybody? Yeah. Yeah, we have, uh, they're all listed on the site. Um, you know, we actually have Vela networks at hackers.town, uh, which is one of the, uh, one of the official accounts. Uh, we have accounts on, uh, X slash Twitter, blue sky. Um, I'm, I'm sure I'm missing some others, uh, because the entire social media landscape is on fire and there's too many, uh, too many offerings, but, uh, those are all listed on the site. If you choose to follow us there, you can also submit questions to us through any of those accounts. And you guys, according to your site, you are not looking for investor funding. Is that correct? We are purely a non-profit small, small dollar amounts can be donated through the site, but we are not looking for investor funding. This is meant to stay non-capitalist and free to the world. Awesome. Wow. I hope you can stick around for overtime at eight, um, uh, all three of you or any of you, uh, and, um, uh, best of luck with all this. Congratulations on, on, on starting it. I know there's a long road ahead, but what you're doing is, is truly amazing and you're the right people to be doing it. So thank you. Thank you for having us. You can write to us at off the hook OTH at 2600.com. I believe we're on next week. And if so, then tune in at seven o'clock on WBAI. In the meantime, stay tuned to WBAI or join us over on YouTube. Follow the link on the 2600.com webpage, or just go to channel 2600 and we'll continue this conversation over there. And you can even call in. We'll see you next time. Good night. We'll be right back. And welcome everybody on YouTube to off the hook overtime Let's make sure we all made it Kyle. You're with us. Yes. I'm right here Rob Gila. Did you make it? We're here. Awesome. And are we actually on YouTube? That's always a good question We are okay, and who has all three of our guests are with us. I think we lost Alex. Is that is that true? Alex had to step away and sleep in you know, Slovenian bed. So that's a fairly complex. I'm given understand He'll do anything to avoid overtime money. I'll go all the way to Slovenia Wow, and while staying on with us we have our special guests from from the veiled project and From the veiled project and Want to make sure I did if I made it as well. We have dildo. We have Medusa and we have the Gibson and You're welcome to give us a call if you have any questions Concerning this amazing new thing. That's that's being designed right now our phone number eight zero two three two one four two two five eight Oh two Three two one hack. I got it right tonight. Yeah You did Anybody else I wanted to go ahead No, I'm just like people the the chatter going on on on our socials during the show and everything people are rather excited about This whole thing as they should be It's it's great that you could all join us It's great that you could all hang out for this this after show and folks out there if you have questions for the valid crew the Gibson Christian dildo agree you or Caitlyn Medusa for both Bowden. Sorry caught myself there Um, am I supposed to give us four am I supposed to pronounce the four guys a Medusa? I don't know how to inject the four It's okay. I it started as Medusa But I don't speak leaps. I am I speak user So now it has become metas for and I'm really enjoying watching everybody use reaction to it because they get very angry People have to get angry at something. So yeah, why not? This is something to really get angry about though And it's a story I didn't get to in the previous hour It's it's called verifying your identity on Twitter will now require taking a selfie And this just speaks to all the things we were talking about there They're basically trying to verify users identities and what that involves is submitting a selfie alongside government issued ID and then having all of that Forwarded to some company in Israel that is going to verify your identity It's Twitter for God's sake or X if you want to be really silly It's it's it's really turning into a nightmare. I mean The the internet used to be completely Anonymous if you chose for it to be anonymous and if you wanted to reveal yourself, then okay, that's that's your problem But this just seems to be coming the the norm lately My Yeah, it is a hard no hard no for me as well, you know it it used to be that people trusted people and That's how you build trust networks as individuals trusting each other when you start seeing these things creep in what they're asking you to do is trust Twitter and Then Twitter will tell you who to trust It's a man-in-the-middle Attempt by these big corporations to inject themselves into personal trust networks completely unnecessary you know if you can just talk to people and Invite people you trust and talk to people you trust and don't talk to people. You don't trust if you don't want to Why should there have to be anybody in the middle mitigating and mediating your trust? You know, it's only a side effect of the construction of these networks that any of that's even needed You know, we got along just fine, you know making friends in real life and then talking to each other and deciding who we wanted in our circles and who we didn't Go ahead. Yeah, I'm gonna I'm sorry. Oh, I mean Gibson if you want to keep going we have a first question out of the YouTube chat Yeah, look that that verification man in the middle that Chris is speaking about This is an attack on human freewill and humanity in many ways, right ultimately we should be able to make these choices for ourselves and having that that Clearing house in the middle of this is offensive to me it's a face should be offensive to everybody, but most people are willing to go with that because it's Inexpensive for them to trust and they can kind of offload that decision-making process But the truth of the matter is, you know, we we have to be responsible for who we are who we choose For us right and and those decisions should be on each one of us individually But when we have a system like this that takes away that ability to make that choice So, you know, like I said hard. No, I'm out Mm-hmm Go ahead. Yeah I mean, I was just gonna say I was looking at the article and I can't believe you don't want to give Twitter your biometric data anyway the question Because you have to let them keep your biometrics, okay, if all users are nodes is a question What is the impact and performance like for mobile devices whose routes go through mobile user nodes Well, that's a great question valence Internal routing table Is mostly a statistical exercise to figure out what nodes are up You know, you know with what frequency how reliable they are how stable they are You know how frequently they switch around to their IP address and they're dialing information so That's sort of valence job is to figure out What is the best most private routes you can go through and maintain connectivity? if your node for example is a mobile device and It is on Wi-Fi and it seems like it's been there for an hour We kind of expect that it might be there for another hour if it's only been there for a minute Then we probably aren't gonna route anything through you until you've proven that you're gonna be stable and at that same IP address for a while In general though, we also keep a whole bunch of routes allocated in the background so Valid it's sort of a call-and-response protocol at the base We can send over one route and if it goes down we know immediately and we can switch to the next one so we have like this Backlog of prepared routes ready to go and when routes disappear we just switch to the next one and it's already there so we kind of have some sort of a bits in our algorithm for the route allocation that make dealing with high churn environments less problematic Okay, thank you Fabulous I have a question now we've talked about the reaction so far from from people like us Have you gotten any kind of a reaction from the people we're talking about namely people in the industry that live for tracking and and recording IPs and basically Turning the internet into some kind of a commercial mall where everybody knows who you are Not so at DEF CON we had a couple of interesting interactions, but not directly in regards to that but with people who represented some of the larger organizations you would expect to have a stake in this and you know some of the questions were very interesting because they they were Unexpectedly kind of you know could this be used to reduce cloud cost and and you know I know we talked about that earlier, but that's that's a little ways off in the future for the scale They're talking about in my opinion But we also had people from other ones seeing ways to secure relatively insecure authentication methods and such that their companies may use by using this this routing capability to Mask that so it's been very interesting. We haven't had anybody directly come to it at least not to me yet about You know the data economy if you will But we have had people check in with us wondering if this could be used in kind of innovative ways for business that I don't think I planned on having those questions come at me, but But certainly we we live some ideas and some people in unexpected places Go get him Next question off of the live chat. Someone asks Direct quote does valid work through the great firewall of china? Does valid work through the great firewall of china? We are excited to find out Yeah, we haven't actually tried um We I am i'm unaware of any nodes running in china at this point, but that doesn't mean that it Hasn't happened. Um Side effect of running a giant private network is I don't know where all the nodes are Um, we have some idea and we have some people working on You know some rough mapping technology that might be able to give us some idea of where nodes are at, um, generally speaking um But I can't confirm that as of yet Again our phone number 802-321-4225 Uh, do we have a call kyle? No, not yet. Uh, and our phone line is open So if you want to speak to our our friends here from veiled um This is your opportunity And I think we have more online questions Um, oh, okay Uh, keep them coming guys who stores this routing table information? Would this allow someone to track users ips across multiple connections? Who stores the information, uh, well every node has their own view of the valid network Not every node is going to be able to reach every other node um In fact, i'd say that the routing table itself probably caps out at about 256 nodes per node so you only get A view of a small part of the network, but that's all you really need to be able to construct your own routes um, you only need a couple nodes to hop through really, um, and if you pick ones that are You know fast but geographically dispersed you're going to be bouncing around all over the place and you know Your communications themselves are end-to-end encrypted on valid uh, so You know, it doesn't really uh, there's there's nothing about uh valence construction right now that Prevents people from knowing that you are running valid Like if you were to do a network scan, yeah, we use port 5150 And you could probably find valid nodes out there right now But you wouldn't know what they were doing and you wouldn't know who was using them. There's no connection between a a node id and your actual identity That is a completely broken link, uh, so yeah there you're gonna see nodes online Uh that said, you know, you we know where all the the tor nodes are in the world today as well You just don't know who's using them or for what? But you know if people are running a node Um, the same is true for valid, you know, you use the internet you're going to have traffic on the internet Uh that said that we've also got some projects right now to see if we can Make it even a little bit harder to detect. Um, making us look more and more like random data. Um, randomizing ports and things like that um But basically you're going to stick out running valid a little bit right now unless you look just like regular HTTPS traffic going to all of the regular sites that you would go to, you know, if you're sniffing the network It's going to look like a different kind of thing than most people's regular web traffic We can't really do too much about that right now. I mean they're stuck into graphic stuff There's a whole field of research around having valid Uh, or any other thing become deniable there's a big difference between deniability and an anonymity Deniability says that you don't you can say that you weren't even using it and people can't prove. Otherwise Anonymity says that you can say I wasn't the one using it. It could have been anybody um, and that's the difference between Sort of node level identity and user level identity and we are anonymizing that user level identity Interesting, wow, go ahead Oh, we're caught up I had a question does increased use of it perhaps discourage further surveillance from Corporations in other words if more people were using this kind of software assuming things go great Would it have an effect do you think on the affordability? I think you mentioned that a little bit like making the cost of of this just uh, this rampant spying or dragnet stuff so high to to um Make usable that it's just not it's not worth it sort of taking the floor out in theory one of the The That was one of the original, you know design concepts that we had going on was we wanted to disrupt the data economy itself if we give users the option To you know opt out of having their data scraped and sold then we hope that it will Kind of destroy that economy on its own um, that is one of the ideas here is just giving people the option and hoping that they understand what that means and Also helping them realize the value of the data that's being taken from them What is the value of their privacy? And what does that mean exactly? We've been doing a lot of educational work around that so that people can make the right decision when the time comes And we do hope to upend that economy Also, one of the things that in theory will happen as we get a density of nodes it starts to grow um, we should see the cost of Running the network itself, which is effectively zero still because everybody's kind of distributing it But those resources shouldn't go up The speed of the network theoretically could go up And the privacy of the network should get better as more nodes come online because you're gonna have more randomized routes That was that was kind of where I was going with it. So yeah that that answers a lot of where I was headed So thanks for clearing. I believe we have a phone call. Yeah, there's a call on the line Good evening, you're on off the hook overtime. Go ahead Hello, emmanuel and mom. Well, i'm famous now. I'm on the youtube, uh radio here, but anyways, um about the um, obfuscating, uh The like you actively run an availed node Would you be able to like, you know barring the given latency with it? Could you um, you know route that through like a wire guard connection a vpn and uh, you know Sort of not have to worry about being Seen as running a node Well something is going to be seen as running a node it'll be the other end of your wire guard um So something is going to be seen as running a node as it connects to the network But yes in theory you can tunnel if you tunnel at the layer two. Um, You know then Yes, anything that you want to do could be passed over a vpn if you wanted to i've accidentally done it I thought I was running a valid node, uh from a hotel room. Uh, Just to test on the wild, you know crazy hotel networks that exist out there And found myself that I had accidentally been routing it all over my vpn to my house um It worked great. I had no trouble running it over. Uh, um You know open vpn or or whatever I was using at the time and uh, Yeah, transparently worked over a vpn without any trouble. Uh, Unfortunately for me it it made me feel pretty dumb because uh, I didn't realize that it was actually tunneling from my house until uh, Uh, I I was wondering what the heck was going on. But yeah, no, it does work. I can't well that maybe I can confirm that I'm sorry, go ahead I was just saying that maybe a good sign that uh, you know that it was a pretty seamless and uh, you know Yeah painless Works great. Um, yep, just tunnel so you can tunnel if you can tunnel your interface Uh, you could have your valid node appear from wherever your endpoint is Cool. Also one more question. Uh, what brand of hot dogs did you throw at us? Those were kosher uh Hebrew national beef franks You know for those of us who weren't there I'm, not sure if we want to know what this is all about but that's part of your presentation, I guess So a few weeks before uh, we were going to give the presentation our esteemed colleague death veggie That's mr. Vegetable. No, wait, that's not mr. Vegetable. Uh, he uh, he started Vegetable, uh hair doctor professor death vegetable. He got the doctorate good for him Yes, so he um, we started talking in our private chats about uh, We had a we had a rule set up way back when we first got in touch with defcon to do this Because of an incident from back in like 2002 or three where they said no rommy you can't throw any rommy into the crowd And we all kind of said what? Okay, sure. Why was that? Okay well It may have happened in the past that some raw meat was thrown into the audience it Yeah If you had to be there But that means you could have thrown you could have thrown cooked meat at the crowd then that would have been okay Technically hot dogs. Well, that was the idea hot dogs are pre-cooked. They are pre-cooked Yeah, one of the best things to come out of this was um, uh Somebody who got uh, one of these packs of hot dogs Made the most quote unquote cursed defcon badge ever by slapping a cdc sticker on one and attaching it to his lanyard Uh, and so we got to be part of badger Wow Does that answer your question caller? Uh, yes, sir, and man saw out there. Yeah All right. Well, thank you all very much. Uh, look forward to run run node Cool. Thanks for calling Our phone number 802-321-4225. Go ahead gila Okay, two more questions have come in First one does veiled used post quantum algorithms for encryption? Not today today it uses uh a curve 25519 based algorithms, um as well as blake3 for hashing these are Properly strong for the kinds of use that we have today um, but uh, we have Uh built-in crypto upgrade ability into the protocol. So in the event that a practical post quantum crypto system Uh is implemented by crypto crypto cryptographers that we trust Uh, it's the kind of thing that could be slipstreamed into veiled as a crypto system without Uh, any of our apps or developers having to do anything differently um, so You know, I know this is it's a hotbed of crypto research right now thinking about what to do when quantum computers change the game for the mathematics behind crypto cryptography and crypto crypt analysis So we're prepared for that. Um As soon as the cryptographers that they're prepared for uh for it Awesome. Okay. That was one. Here's two You talked a little bit about traffic obfuscation Are you familiar with v2ray? Shadow stocks and are you going to try to implement their techniques? Uh, I am not familiar with those i've studied a bunch of things, uh, we are looking at alligator ellig ator, um as a way to Make our traffic look like completely random data, uh, so Uh, if you want to look up alligator that that's currently our our focus right now is looking at that. Um, That may end up being a a sidecar obfuscator for for valid Okay, go ahead rob All right, um while we're waiting for our next call, um someone on uh mastodon is taking issue with our claim during the radio hour that uh Tor runs a hundred um I mean, uh rather excuse me. I'll start again that the nsa runs. Uh, A large amount of tour exit relays. They're citing a talk from ccc camp 23 by tour project And of course, we can't watch the video while uh broadcasting so we I can't address what specifically they're talking about But uh that is being disagreed with That's fair, uh, we've been working with the information that we have Uh, we love tour. We're not here to tear down tour or talk smack about tour Um, we're only acknowledging the fact that tour has a really big gap to fill when it comes to uh Its users its end users and you know the technology itself, uh And it has a marketing issue to be frank. Um Those are the only things that we really have said any That we really have anything negative against tour. Uh We didn't know that but thank you for sharing and I will watch that talk afterwards, uh And we're always open to learning something too. So what i'm what i'm curious about Our apologies. I mean what i'm curious about is is it at least conceivable that the nsa could run a tour exit node? And if if it is absolutely why not a hundred is it is conceivable and you know while We obviously can't prove it. They wouldn't be doing their job if we could well We could call the nsa and ask them, but I don't think they'll tell us exactly, you know, you're not gonna Know for sure But if I go right now and I look up all of the exit nodes that I can find there's a map of tour exit nodes I can find some odd hundred running out of the isle of man off the coast of england right now in some data center that You know sure as heck looks like I don't know It looks like a concentration point for this stuff. Uh You know, I can't tell you you know that that's what it is, but You know, uh any kind of concentration On a map of exit nodes is going to give me kind of pause a little bit, you know, um Again doesn't have to be the nsa, you know, that's just sort of a straw man boogeyman here It could be anybody it could be the mob it could be any one who has a vested interest in understanding uh You know and monitoring torque, right? That's meant to be a good thing though that anybody can do this So nsa there any anybody like anybody else is so they could be doing this as well. It applies to anything really yeah, I mean so in general, I think that that kind of uh Correlative analysis is something that we have to fight against I think veiled's model of keeping as much as possible in network rather than being a generalized internet proxy is going to have An effect over time of making things a whole heck of a lot harder to correlate You're not going to have external signals as well as internal signals that you can put together uh, it'll all be in network and uh You know, it won't be obvious uh where the the the the end points of Communication are you know, if it could be that you're in the middle of a of a route It could be that you're at the end or the beginning It's going to be a lot harder to monitor unless you're Monitoring a whole lot more devices and it's going to become very prohibitively expensive to do All right, i'm just going to invite people give us a call get to a phone and dial us phone number 1-802-321-4225. That's 802-321-HAC and thanks to the gipson who had to take off For the evening, but we've still got dildog and meduse for here to answer your questions I didn't know who left because we can't see them We're uh, so so somebody left but i'm glad you clarified that go ahead. Yes Um, so another question which i'm again going to assume is aimed at dildog and metas for because they're the ones with the answers Um, if an app unveiled is doing something problematic. Can you stop it from proliferating itself? Not really, um Yeah We don't really have any control over what valid nodes do there's no um, it's quite possible that valid as an organization someday may not even run its own notes at all when we do just because You know help making this framework and stuff but it's going to be the apps themselves that are going to be responsible for the The content of the of what their apps enable people to do. Um you know, I we won't have Any kind of sort if we don't have any kind of sort of policing capability over over this network um All we can do at this point and we've released it to the world. There's hundreds of nodes out there right now I can't tell what those nodes what to do And I can't tell what they're doing and I can't tell them. No, um, so uh, if you're going to write a valid app, uh, we request that you Make an effort to adhere to the valid code of conduct and try to build apps that are for everybody And uh, you know, we're trying to build community that builds responsible applications. We encourage this behavior We acknowledge that not everyone is going to want to do that But that is a general social problem and that's something that valid can do much about We don't really have Uh any kind of authority over that right a code of conduct for apps It would be nice if you know people built apps that You know, uh, we're built in a in an open respectful community that said uh, you know, we Willingly acknowledge that You know when you put code out in the world people are going to do what they want with it um, we're trying to move the needle toward uh respectful communities But you know the world is what it is. Um, we're not going to change You know all of the social paradigms that exist out there today um We know we know what we stand for it's on our website. Um And we hope that people will follow us, uh, and we encourage that kind of development, uh you know ethos um but we'll fully acknowledge that uh You know people come in all stripes all stripes and different colors, uh, you know different attitudes Uh, and you know, we're not the we're not the police of application development at all. Uh, we just read a tool Framework and ask that people try to use it for good But we aren't also going to be quiet if someone is using it for bad one of the nice things about not having um, you know vc money or things like that is we don't have to Cater to anyone telling us. Oh, well just you know, don't make waves uh, we're gonna Be obnoxious and be a thorn in the sides of people that are trying to use this for bad and i'm not afraid of that Uh, also, you know, we're building a community of people that we are encouraging to take ownership of You know this whole project feel like it's your own build on it. Have fun with it. It Is all based on what the community? Is you know wanting to do with it and the community is going to self-select And if you do allow people to take ownership over the project, they're going to protect it, too Uh, and I think that matters. I think that the community that we are building of people That care that see the vision that Understand what's at stake here are going to you know make this happen in the way that we are hoping it's going to happen or it may Take another route, but it's either way. We're I believe everybody is here for good. I believe in the good of people And i'm not going to give up on that. That's a great starting point at least until until they prove otherwise You know give people the benefit of the doubt and hopefully uh, we get the best of the people Yeah, we don't we don't have to uh Remain quiet for fear of like our funding drying up. We wrote this for free. It costs us. Nothing we'll say what we want and there's And you know, it's not like uh, it's going to hit us in the wallet That said has anyone tried to talk you out of this Um the the only feedback i'm going to let some people remain anonymous here, but the only feedback that i've gotten that um Was somewhat negative came from people that had a vested interest in the data economy and from cryptocurrency folks who feel that uh you know blockchain solutions and smart contracts and You know putting You know transactions at the base of everything is uh the way forward. Um, so i'm not gonna I'm not gonna highlight those projects or those people but I can say that the biggest pushback we've gotten was from uh either big data collectors or people that we know that work at them or from the cryptocurrency folks who feel that You know, uh the way forward is Monkey pictures and whatever And I have heard i've seen a little bit of pushback, uh This is simply on a home frontier uh, but You know, my husband is also involved in the project jc And uh when we went to our parents and we started telling them about this They both, you know, both sets of parents were like wait, so there's no money You're not making money off of this Why why are you doing it? Um and that's kind of the only people that have really tried to talk us out of it in any way shape or form is just people that you know, don't really understand the the point Of doing this without you know monetization You know Talking to that and some of the other things you mentioned. I just want to quote from your frequently asked questions section of your website Is veiled looking for funding answer veiled is not seeking venture capital or investment We are accepting tax-deductible donations to our non-profit foundation veiled foundation inc Does veiled have a cryptocurrency heck? No Veiled does not have a cryptocurrency does veiled use ai Heck, no, veiled does not use ai does veiled use blockchain. Heck. No veiled does not use blockchain first of all, I think it can be stronger with the with the uh language there, but um, yeah good for you for uh for uh Standing your ground Well, those are all things that you know, um You know sort of in in ensconce a level of classism Uh into programming and into development And we didn't want to build a framework Where people had to pay to play? You know use a blockchain at some point you're going to pay for gas. You're going to pay for transactions You're going to have to have bitcoin. You're going to have to give your users sign into a wallet Uh to me that just rubs me the wrong way. There's a whole lot of investment people already You know did when they bought a giant thousand dollar iphone, you know, uh It's a slap in the face to require everybody to hook up their wallet to do basic communications, um Even basic storage. I mean there's stuff that we take for granted like, you know Valid has storage built into it not a ton of storage necessarily. It's not as guaranteed as you know your favorite backup service, but You know, there's a lot more that can be done for free or cheap um that You know is is being aggressively monetized today by a lot of other solutions The most investment we've put into this is time And that's all we're asking of anyone else time and energy and passion and putting your skills to use um And I think that should be the cost here for anything. I mean you're spending time on an app you're giving Your time and energy to you know billionaires who are just funding Cage fights with each other or sending each other into mars so that is the currency that I feel matters more than anything else is the time the energy and uh, you know, our entire lives are put on the internet and That's to me the most important, you know commodity that we're working with Okay, we have gotten a bunch of questions For our guests, but just wanted to share something interesting that apparently happened during the show that we didn't know about because we didn't hear it but apparently Uh, the emergency alert tones went off during the show for about 15 seconds. Really? Well, you see we don't hear those so Exactly. This is what i'm saying over the web stream Seems okay. Um, wait, just just the tones or is it a test? Um, it seems to be just the tones people have only mentioned hearing the tone But we've gotten mentions of it both on macedon and in the street in the chat So so that means there's an emergency of some sort but the way the system is designed they don't tell you what the emergency is or somebody hit the wrong button or our robot overlords have arrived and You know, uh earth. It's been nice knowing you. Thank you everybody for clarifying just the tones um Okay, so several several questions have come in Um, and i'm just going to take them in the order in which they arrived in the chat I mean the debate's coming up at nine o'clock that you think that could be that you know, the republican debate That that might have triggered somebody That's totally fair, okay First question is anyone in the community working on bsd or haiku support to run valid nodes? The answer to that is yes. I actually just had a conversation with someone today doing a free bsd port Uh, it is early We have linux support today Obviously, there's low level operating system differences there, especially around network interfaces, but they are working on it So that's the the long answer the short answer is yes, absolutely people are working on it If you want to join in join our discord then work with them Okay, so um the next answerable question, um philosophically Uh, the human rights aspect is interesting. What benefits do you think could work for people who live in a place with repressive governments? I think that This will be the answer to their communication needs. We've seen people over in uh, france that were They were holding protests against some aspects of their government and their internet got shut off And suddenly they weren't able to connect with each other or talk. I believe it was france It's been a bit of a blur the past few months to be completely honest. So but I do remember that there was uh Some protests happening where people's You know ability to connect with each other and organize online was cut off and this is going to be one of those things that isn't going to be Necessarily able to be cut off so easily because it's not going to be uh, the the typical networks that people are used to They are the typical networks that people are used to and they're not going to be able to connect with each other They are the typical networks that people are used to and it's not the typical networks that the government necessarily has access to um so we uh I foresee this as being a net positive for those who are living in those circumstances uh, and We are uh excited to see what comes of that from a pragmatic standpoint, um The fact that this is end-to-end encrypted is a big deal Um people on our discord are actively working on hardware and embedded Nodes, so putting it on smaller and smaller hardware Um, which is going to enable it to be used in like ad hoc mesh networks Um right now we use the public internet as an overlay routing domain But veiled also internally has support for other routing demands like local networks uh, you know wi-fi only Uh ad hoc networks and things like that, uh radio networks, etc uh, so I you know as veiled uh matures, I think you're going to start seeing a lot of the uh, sort of ad hoc network creation, uh stuff, uh Immediately being able to just work with all the apps that people have built so, you know the The fact that you uh, you know if you have veiled chat and you're just used to using it on your regular home wi-fi But then you you know go and take it into a protest zone. It'll still work even if they cut off the internet uh, because you'll be routing through all of your friends and maybe one of those people has a You know a connection to the internet still um, or just talking amongst the people that are there, um, so yeah, you know, I think the construction of the network is going to Enable a whole lot of uh interesting developments in the ad hoc, uh networking space Also want to correct myself it was not france it was iran Uh where they did cut off the internet to those protesting That's those are not very similar countries well And their handling of encryption policy. They're actually kind of similar. Okay, it's kind of sad that that's you know I think I think most governments want that kind of encryption policy or kind of communication policy They want to be able to control people. They want to be able to watch over people I don't know of any country that doesn't wish that even if they don't say it publicly That's true government that is Um, okay. We have some shy people I think uh that are afraid to call So we're just gonna issue the number one more time. Hopefully somebody will uh, Give us another call eight zero two three two one four two two five eight. Oh two three two one four two two five Um, you don't have to be an expert. You don't have to be a technical whiz you can ask Any question you want or just reveal anything that you want to share with us? 802-321-HACK is the phone number, but we're only going to be on for a few more minutes So please give us a call if you have something to say Um, I do have a question for our listenership we are getting the sense that the emergency tones were played on The simulcast on the live stream if anybody actually Heard us on the actual fm radio if you could let us know if you heard the tones Now we're just curious. I hear sirens as you're saying this what's going on in queens there We live like two blocks from a hospital um Or you know, the world is on fire robot overlords. So the world is on fire. I mean it's been documented Know that All of this is true, but yes folks who were listening on the actual radio Um in your car your alarm clock, what have you if you heard the tones on the radio? um, please give us a holler also Um gila this wouldn't the radio be the only place where emergency alert tones would be sounded Apparently people heard it on the live stream. They heard it on their amazon devices. They heard it on the website so Now i'm curious. Um, also someone wrote in and i'm going to Absolutely butcher this word Thank you for calling. Okay. Apparently it was on the radio as well Uh, someone says just join the show. Are we speaking about the cybic co? um page 56 2600 volume 40 number two from 2000 We expect it to just call that up um I don't know. I don't know. I don't write some I just read them. I don't know they're referencing an article from 20 years ago 23 three years ago Which is weird because oh, I think I loaned that issue out. So volume 40 number two was pretty recent um but I I understand nothing you said 2000. Yeah, what was the 2000? Is that a type of equipment? Is that a model number? Is that okay? I am gonna copy this and paste it into Our chat so you guys can see because apparently I murdered the syntax um And if anybody wants to call us, by the way, and we have a we have a caller we have a call. Yes So calling us now you'll wind up being transferred someplace and we can't get you back. So, uh, Let's uh, let's say hi to this caller. Good evening. You're on off the hook over time. Go ahead Hello. Hi. Hi Um Good, thank you. Yeah, I I mean, I I don't know I I've listened to you guys on and off for I guess like two years now Uh, I guess just whenever I have time. I've never called in. I don't know. Um Felt like it today. So hi Welcome Yeah, hi. Um Just out of curiosity Is there any reason to switch to valid chat from signal right now um just because I try and use signal as a private messaging app and I mean other than the lack of sms verification as You know being required Yeah, I mean well I don't know First off valid chat is not fully released yet So I wouldn't switch to it because you're not going to be able to download it Um, but when it does show up, you know, I encourage you to try it See if it works for you. Um, there are going to be some environments maybe where signal is a better choice for the short term We are designing it to be a full replacement for that It does not require phone numbers or any other kind of identifier It may make you a little bit harder to find as a result Uh, you'll have to invite people over another medium. I would keep signal around. Um, there's nothing inherently wrong with it other than uh, you know the the bit with the phone numbers and I could say that there's been issues with them not choosing to encrypt certain things that were saved to your Your phone like the attachments you receive were not being encrypted so, I mean there are some Aspects of the of the app itself that I I personally disagree with some of the choices that were made there um but for regular daily driver chat use I'd say try them both see how you feel about it and uh You know if there's ways that you want to improve veiled chat, um, we're all ears. Uh, we'll make it the best chat program that we can so one Difference that I think is going to be key with Between signal and veiled chat is we're not going to ask for access to your contacts So your contacts aren't going to get a little pop-up letting them know that you have joined signal. Oh, that's so annoying It was so annoying that there is that I forgot about that. Jesus We don't ask for anything I don't need to know every time one of my exes that I haven't spoken to in years has joined signal. Thanks Or one of your exes thinks that you're sending them a message by saying you're on signal and then they contact you Or one of your dead relatives that still is in your contact list that had their phone Uh number reassigned to somebody else. I mean that's happened too. Wow Yeah. Yeah Signal is wonderful and we've done a lot of our work Um communicating with each other through that medium. So i'm we're not going to sit here and bash it We encourage everybody to try it out and see what works for them um And we're also going to be taking community feedback So if you you know, see something that we can improve on we hope you join the discord and talk to us And maybe we can make that happen Okay, yeah, I mean i'm i'm not I can't I don't know how to code at all, um, I want to learn me neither Okay Okay, so it's not like i'm gonna be a problem, I don't know It's not gonna be too tough I promise I am not a coder myself a lot of The tech explanations about bailid go over my head Uh, but I I assure you I will be testing every bit of it to make sure it is, you know Easy for us regular folks to understand Cool. Okay, cool. Thank you. All right. Thanks for your call Yeah, thank you. All right. Take care. Yeah. All right. See ya Go ahead get it Okay, we did get clarification. Thank you to listeners optical phoenix and nicker zero zero zero for clarifying the Cybiko or cybiko. I don't know how to pronounce it was a handheld personal messaging tool that was released in the year 2000 and you could like Yeah, I remember that Uh Ad hoc local networks for people close by And the picture on wikipedia is purple It's very spiffy and apparently you could like put a memory card into it and play mp3s um So the short answer is no, that's not what we're talking about. But thank you for that awesome blast from the past Um, and now I kind of want one I think we should be bringing back that colored plastic aesthetic myself uh So i'm all about it And it's really real uh cyber deck, uh vibes right there We have another call there is another caller yes another caller good evening you're on off the cover time go ahead Oh, yeah, I had a I had two questions actually one about uh running a valid node and one about a valid chat About the valid node like will there be a way to throttle the resources you contribute to the network like, you know, cpu gpu Like ipfs storage or bandwidth for people who are on metered connections or people who have limited resources and uh Will there be a namespace For uh users or will there uh, are you just going to be like a key pair like say with session? Um, okay, um two questions first one, um Yes, um, let me see, uh Let me get to the valid chat question first the um as far as a key pair, uh Your key is only shared to The people that you contact, you know, if you want to do it the way this works is you create a contact invitation The invitations are encrypted The invitations are placed onto our distributed hash table and The way this works is you basically pass a decryption key? For that invitation to your friend over some other medium. So I message or signal or whatever you choose They're not getting the key to your Node or to you or to your identity over that Over that, uh non-valid medium. They're just getting a password Basically that can be used to decrypt the the invitation off of our distributed hash table. So when you connect with people um You it's there's no such thing as a real like a namespace per se everything is done on the main valid network That said if you wanted to you could set up your own valid network today Uh, there is nothing special about any valid node All of the valid nodes right now are on the the main valid network, but you could set up your own valid network uh And we do have this notion of network keying So if you wanted to set up a private valid just for you and your friends you could do that Um that would allow you to run A group of nodes that is not connected to the main big huge valid now There might be security implications with that. Obviously, it's a pretty advanced use case. Um But yes, uh When you just run velichat by default you are in the same namespace if you would as everybody else Um because there is no server session does have this notion of servers. It's basically federated not completely You know distributed We you know especially also has this thing where you have to buy like eight thousand dollars worth of their cryptocurrency to run a node Because they don't want people just setting them up uh, so You know, we don't really subscribe to that. Um You know if that's what it takes to to get their network up and running, that's fine, you know Just that's not how we choose to do it And I didn't think I answered your first question what was the first question again Oh, I was just asking like say if you were to run, you know a valid node Uh, say if somebody were to be on like a metered connection or have yeah Resources or would just like to have it running in the background and not have it affect their bare metal hardware very much Are you able you could you could run a low resource? Yep. Yeah, there's a configuration file. You can you can tweak how much storage? um You can tweak what services you choose to offer if you don't want to do dhc storage at all If you just want to do routing table stuff, um, you could also choose not to private route um, you know, you could turn on and off capabilities in the config file, so all of the Limits and stuff like that are all tweakable In a future release available. It is also going to detect whether or not you're on a metered connection If you have on a mobile device, for example, and it's going to automatically throttle back those capabilities right now If you're on a slower connection or you're on Like a symmetric carrier grade nat Which is what you're going to get when you use a mobile device on a cellular network that's metered it already throttles back today Based on the type of network you're on So if you're not on like a static ip or a dynamic one that has upnp like your home router But you're on some kind of like carrier grade Symmetric nat it's going to notice it's automatically going to throttle back so it doesn't blow your bandwidth out So Cool. Thanks for the answers. Uh good and uh concise appreciate it Yep. Cheers Thanks for your call and um I'm going to get out the phone number one more time 802-321-4225, but we're running low on time So if you have any questions, uh for our guests concerning veiled and and the future of the internet and and all sorts of other things Um, give a call now 802-321-4225 802-321-HACK Yes, go ahead we got another one Um, how do you protect the private key on the device? Can it be placed in a yubi key or similar secure element? All right, um, well I gave this a lot of thought um right now it is not um uh, you cannot use an uh, yubi key or a uh external hardware, uh token, uh, the private key is Uh encrypted with another key that is stored on let's say a mobile device in the uh keychain uh, and that itself can be encrypted with a password so if you were to use a yubi key you could you have it like generate a password or something like that, but Um, we don't have support for like a time-based token or anything for that kind of unlock Um that said if you use the device uh protected store The hardware protected store in your device the keychain And you do not back that up along with the rest of the on uh, you know your iCloud storage whatever you are protected from iCloud backup dump attacks and from uh attacks where people might try to siphon off your backups from say the lightning port on your phone, uh, they would have to Crack the password that you use to unlock The device key that we bake into the into the protected store um, so keychain or key store on android or windows, uh, Protected store or linux secret service. Those all have um You know hardware Enclaves that they store those keys in um So that's the answer that says there we do we get a lot of thought our thought our threat model was, you know backup attacks and uh you know making sure that when you back up your device that uh, there's at least a password between Uh the attacker that downloads your backups and their ability to to get at your stuff Okay, and we have another call. Yes calls are coming in now. Good evening. You're on off the governor. Go ahead Hey, how are you guys good, how are you? All right. Um, I just wanted to give you the heads up as a fellow techie um at about 48 minutes is when you had your emergency tone And there was no warning beforehand and no warning after it Yeah, that's how they design these things. You're supposed to somehow know You send across that tone and uh, yeah, if you're not digitally tied into what you're listening to Uh, you don't have a clue, you know It's another example of how you know, the old days the ebs system was was very verbal They tell you what it was and eas they just send out these tones and they're supposed to activate something But if they don't then you're kind of left wondering just what the hell was that? Uh, it's it's really so we have a cable system people who use uh optimum Might notice at three in the morning what they almost always do Is just have a blue screen over all channels and pvrs That just say that they're they're testing a system for about five minutes And you can't watch anything and if you're watching something live you're gonna miss it It's ridiculous and they think that's how you're supposed to test the system and it's it's not It's not how the system works Anyway, that's not what you call it. And what do people do during the night shift if you're working the night shift? I have a question as well. Go ahead um I'm designing something that I believe is going to be really really big and I love What your female friend was saying before that you all agree with it's about the people and you don't want to have Any money commandeering and stuff like that. I so agree And i'm doing something along those lines My only problem is i've had so many digital problems and i've had a guy who was designing software For a specific thing that I found a secret take three problems from every person, you know And as I am a professional technician for 50 years and I have a really good discuss rate And I said, how would I fix it? And i've come up with something and I want to design some software and my software guy who lived in canada bailed out and never called me back and he Sounded like a good guy until we almost got done and then When he couldn't reflect The software to work, right? I think he didn't really know what he was doing as a young guy And then that was it. I never heard from him again. Would you happen to know anyone who can do software? Uh, there's a lot of Software development professionals out there. Um, you're looking for a contractor of some sort. Um, you know your best bet is to You know to probably go through uh An app development service. There's a lot of those online, you know, personally I roll my own. Uh, that's because i've been coding for You know 35 something years now. Um, so I know I write all my own stuff But I know there are a lot of contract programmers out there Um, you know feel free to to hit up linkedin and places like that for software development needs Also just want to chime in to say that i'm sorry that really sucks Yeah ham operator in the past. I'm, sorry. I cut you off. I'm, sorry guys Oh, no, I just wanted to say i'm sorry that sucks Yeah, it does Um, what were you saying caller? Oh What would it take for me to interest the gentleman who was just speaking to be involved? If you're interested in things for people I'm looking to do something on a very large scale and I think if I was off air I could Explain it better, but I don't want to do it on air My recommendation is if you want to pitch ideas to valid developers because you think valid is a relevant technology Come join our discord We have a lot of places where there's a lot of people that program and a lot of people that have the same kind of ideals and Uh, they might be looking for things to do with valid. Um, and if your idea lines up with some of their uh, The people that are there. It's a very welcoming community. Feel free to join the discord You can find it on our website on valid.com Uh, click in there and pitch your idea to some of the people in our in our uh, some of our ideas channels, um You know, i'm we're always We'd love to hear about ideas people have for their for apps and again, that's veilid Veilid.com that's that's the website. So, uh, thank you for that call Thank you. Keep up the great work. Thank you. Thank you for calling And um, that's going to do it for calls tonight because we had a we had a bunch of them in the end Uh gila, did you have more? Uh, I I do this has actually been A very active evening on the chat. We've had people involved who have not been here before. So, thank you very much Okay, question number one will an mvno add any issues? I don't know what an mvno is. I'm, so glad someone else doesn't I was feeling so stupid. I googled it, uh a mobile virtual network operator, of course Yeah, we all know that is a company that does not own a mobile spectrum license But sells mobile services under its brand name using a network of a licensed mobile operator. So this is basically uh subletting mobile network space so that like you know Uh foobar telecommunications could sell Services, but it would actually be back hauled out to say verizon. Uh, you know for the actual mobile network Um, I don't think that's uh gonna because this is an overlay network on top of the internet protocol Um, it's not really going to matter what the underlying topology is Um, they're probably going to use symmetric net because that's what all these, you know, big carrier grade networks do We do support that completely and You know, it won't be the most You know feature rich, uh node that you're running but you know, it'll run all the apps that you care about without it being an issue Okay Um, we had one additional question that was actually answered in the chat. So we are going to skip it. So last one Um before I say that though tim in connecticut Yes, if it had been the old way, they would have said if this were an actual emergency You would have heard news. We don't do that anymore Um, okay last question for our guests How difficult would it be for a malicious coder to build a map of all valid nodes? Could that have dangerous implications for people using valid under oppressive regimes? I'm sure it could. Um right now, uh, because the number of valid users is somewhat small uh it uh Would be like, you know back in the 80s, you know, how many people had modems at home? You know if you war dialed and you found people's home modems listening or something It would be a pretty small population and they're pretty easily exploited um you know if you're looking for somebody in a particular area code that Did a digital crime or something you just look and find all the people who had modems at home and go hunt them up It wasn't that common Um, the same is going to be true right now. Um The people are building mapping mechanisms for for valid because the at the ip layer. It's not again not trying to be deniable uh, but when you start looking at having millions or hundreds of millions of nodes eventually Uh building a map of those hundred million nodes isn't going to get you much It's just going to be like oh look everyone who has a computer is using valid you know as soon as we reach as soon as we reach that level of you know of saturation, uh, it's Going to be prohibitive to to try to build a map of it I had kind of a follow-on. I was curious what um your thoughts were about um I guess um Actors that create versions that are maybe intentionally broken in some way um and and and so like say it gets popular say you know section 702 gets reauthorized and Everybody freaks out and all of a sudden they they get popular it turns out the popular one's broken, you know It's like we all we all have like scenarios in our head I think sure even this show talking about news stories of different apps so forth so on and so forth So it just struck me that are you auditing in some way? Is there a way that you're encouraging? I I know you mentioned a little you touched on a little bit But how do you make sure that that continuity throughout like if it's in all different types of software that people are building? How are you even able to know is it just going to be naming and shaming that hey? This is a broken busted implementation of this don't use it or you know that kind of thing How do you get the word out on what's good and what's really um, maybe a little shabby in the future Yeah, uh, you know, it's going to be sort of like linux, you know, um You got this big kernel. That's sort of like Valid core, you know, and then there's going to be distributions that show up where people have packaged it with some Libraries that they like or whatever, you know, I like it to to the sort of linux kernel There are little forks that you can find of linux Your mileage may vary if you don't choose the big supported one Um, but there's a lot of distributions. There's a lot of different ways that it's packaged I have a feeling that valid Is going to do for networking and cloud Uh, you know mobile modern software development what linux did for operating systems. It's going to democratize things It's going to open it up Uh, it will have all a lot of the same problems in terms of like forks happening and whatever But the one thing that we've got going for us is that no node Invalid Has to trust any other node so if you build an adversarial version of valid that does bad things or You know doesn't perform the way you expect it to Other nodes are going to ban that node and not talk to it so You know, we've designed it for You know adversarial nodes existing And in fact, we encourage that we have people on our discord right now building adversarial node technology And committing it to our repository because we believe in building a better more secure valid We have people actively hacking our stuff And producing security advisories. We already have a cve Uh on the mitre database for a bug that we had that we got fixed in 24 hours, you know, so there's already a very hacker friendly adversary, uh You know adversarial, uh development accepting ethos going on here Uh, you know, we're not going to wait around and hope people don't hack this. We're going to hack it ourselves Wow, I just love the phrase adversarial making trophies We are making trophies for the people that um Break it in the most creative way. I'm actually gonna send them literal trophies to put on display Um, wait, I am allowed to swear here, right? Yeah, you can go ahead go for it I'm making fuck around and find out trophies. There you go. Wow Because that is the scientific method I want i'm encouraging people to fuck around with our stuff mess them out the code see what you can do Uh that way we know what we're expecting when we get this stuff on apps and in the hands of everybody um, you know, we are really encouraging people to you know think outside the box and be creative and Be a part of this and yes breaking it as a part of it you know this this reminds me so much of the early days of the net where it was all in front of us and this is the kind of of uh of tone that we had, you know, it was basically Uh break something or you know, uh, we'll make it better. It wasn't all about profit wasn't all about tracking. So I I can't thank you guys enough for for uh, bringing that back and I sure hope it succeeds Um, thanks a lot All right. Thank you. I mean That's what we're here for we hope Well, thanks, uh dildog and uh medusa. I'm gonna how do you pronounce the four? Metis four see you change it you change the syllables that way too. Okay And also thanks to the gibson who had to leave uh before And uh, everybody else who called in and wrote questions and of course, um, uh, kyle and uh, rob and gila and alex Um write to us oth at 2600 dot com We'd love to hear from you with any thoughts or comments. If you have more questions, we'll we'll forward them along We will follow the story, of course. Absolutely any uh innovations We'll figure out what emergency is going on where those crazy tones came across. I'm not sure if if the archive will have that or not um We have it was available. We have it could be the tones I would I would I would believe that But we might have an archive copy without it or we might have the tones. Maybe people want to hear the tones You know, it's kind of it's kind of cool If anyone else has any questions, we are super active in the discord. I jump in voice chat all the time I know dill does as well Because this is a community so feel free to join Um the veiled discord and get a part of this and together. I think we can take back control of our internet And how can people get to the veiled discord? Veiled.com v e i l i d dot com and there should be a link right there on the discord Cool or to the discord All right. Well, we'll be talking about this more in the future. I I know it so, um Thanks for all you do and and best of luck for everything in the future All right. Thank you. All right And welcome everybody on YouTube to Off the Hook Overtime. Let's make sure we all made it. Kyle, you're with us? Yes, I'm right here. Rob, Gila, did you make it? We're here. Awesome. And are we actually on YouTube? That's always a good question. We are. Okay. And who has, all three of our guests are with us. And I think we lost Alex. Is that true? Yes, indeed. That is exactly the case. Okay. All right. Alex had to step away and sleep in, you know, Slovenian bed. So that's a fairly complex, I'm going to understand. He'll do anything to avoid overtime, won't he? He'll go all the way to Slovenia. Wow. And while staying on with us, we have our special guests from the Valid project. And I want to make sure everybody made it as well. We have Dildog, we have Medusa, and we have the Gibson. And you're welcome to give us a call if you have any questions concerning this amazing new thing that's being designed right now. Our phone number, 802-321-4225, 802-321-HACK. I got it right, didn't I? Yeah. You did. So anybody, anything else they wanted to add? Go ahead, Rob. No, I'm just like people, the chatter going on on our socials during the show and everything, people are rather excited about this whole thing, as they should be. It's great that you could all join us. It's great that you could all hang out for this after show. And folks out there, if you have questions for the Valid crew, the Gibson, Christian, Dildog, Ryu, or Caitlin, Medusa4, Bowden, sorry, caught myself there. Am I supposed to pronounce the four? Can I say Medusa? I don't know how to inject the four. It's okay. It started as Medusa, but I don't speak leet. I speak user. So now it has become Medus4, and I'm really enjoying watching everybody's reaction to it because they get very angry. People have to get angry at something. So, yeah, why not? This is something to really get angry about, though, and it's a story I didn't get to in the previous hour. It's called Verifying Your Identity on Twitter Will Now Require Taking a Selfie. And this just speaks to all the things we were talking about. They're basically trying to verify users' identities, and what that involves is submitting a selfie alongside government-issued ID and then having all of that forwarded to some company in Israel that is going to verify your identity. It's Twitter, for God's sake, or X, if you want to be really silly. It's really turning into a nightmare. I mean, the Internet used to be completely anonymous if you chose for it to be anonymous. And if you wanted to reveal yourself, then okay, that's your problem. But this just seems to be becoming the norm lately. Yeah, my problem with all this is – That's a hard no. Yeah, it is a hard no. Hard no for me as well. It used to be that people trusted people, and that's how you built trust networks is individuals trusting each other. When you start seeing these things creep in, what they're asking you to do is trust Twitter, and then Twitter will tell you who to trust. It's a man-in-the-middle attempt by these big corporations to inject themselves into personal trust networks. It's completely unnecessary. If you can just talk to people and invite people you trust and talk to people you trust and don't talk to people you don't trust if you don't want to, why should there have to be anybody in the middle mitigating and mediating your trust? You know, it's only a side effect of the construction of these networks that any of that's even needed. You know, we got along just fine, you know, making friends in real life and then talking to each other and deciding who we wanted in our circles and who we didn't. Go ahead, Gil. I'm going to – oh, sorry. Oh, I mean, Gibson, if you want to keep going, we have our first question out of the YouTube chat. Let's go one real quick comment. Go ahead. One real quick comment. Yeah, look, that verification man in the middle that Chris was speaking about, this is an attack on human free will and humanity in many ways, right? Ultimately, we should be able to make these choices for ourselves. And having that clearinghouse in the middle of this is offensive to me. It should be offensive to everybody, but most people are willing to go with that because it's inexpensive for them to trust and they can kind of offload that decision-making process. But the truth of the matter is, you know, we have to be responsible for who we are and who we choose to trust, right? And those decisions should be on each one of us individually. But when we have a system like this, that takes away that ability to make that choice. So, you know, like I said, hard no, I'm out. Go ahead, Gil. I mean, I was just going to say I was looking at the article and I can't believe you don't want to give Twitter your biometric data. Anyway, the question, because you have to let them keep your biometrics. Okay. If all users are nodes, is a question, what is the impact and performance like for mobile devices whose routes go through mobile user nodes? Well, that's a great question. Valid's internal routing table is mostly a statistical exercise. It's to figure out what nodes are up, you know, with what frequency, how reliable they are, how stable they are, you know, how frequently they switch around to their IP address and their dialing information. So that's sort of Valid's job is to figure out what is the best, most private routes you can go through and maintain connectivity. If your node, for example, is a mobile device and it is on Wi-Fi and it seems like it's been there for an hour, we kind of expect that it might be there for another hour. If it's only been there for a minute, then we probably aren't going to route anything through you until you've proven that you're going to be stable and at that same IP address for a while. In general, though, we also keep a whole bunch of routes allocated in the background. So Valid is sort of a call and response protocol at the base. We can send over one route and if it goes down, we know immediately and we can switch to the next one. So we have like this backlog of prepared routes ready to go. And when routes disappear, we just switch to the next one and it's already there. So we kind of have some sort of bits in our algorithm for the route allocation that make dealing with high churn environments less problematic. Okay, thank you. Fabulous. Well, I have a question. Now, we've talked about the reaction so far from people like us. Have you gotten any kind of a reaction from the people we're talking about, namely people in the industry that live for tracking and recording IPs and basically turning the Internet into some kind of a commercial mall where everybody knows who you are? So at DEF CON, we had a couple of interesting interactions, but not directly in regards to that, but with people who represented some of the larger organizations you would expect to have a stake in this. And some of the questions were very interesting because they were unexpectedly kind of, you know, could this be used to reduce cloud cost? And, you know, I know we talked about that earlier, but that's a little ways off in the future for the scale they're talking about, in my opinion. But we also had people from other ones seeing ways to secure relatively insecure authentication methods and such that their companies may use by using this routing capability to mask that. So it's been very interesting. We haven't had anybody directly come to it, at least not to me yet, about, you know, the data economy, if you will. But we have had people check in with us wondering if this could be used in kind of innovative ways for business that I don't think I plan on having those questions come at me. But certainly we lit some ideas and some people in unexpected places. Go ahead, Gila. Next question off of the live chat. Someone asks, direct quote, does Valid work through the Great Firewall of China? We are excited to find out. Yeah, we haven't actually tried. I'm unaware of any nodes running in China at this point, but that doesn't mean that it hasn't happened. And the side effect of running a giant private network is I don't know where all the nodes are. We have some idea, and we have some people working on, you know, some rough mapping technology that might be able to give us some idea of where nodes are at, generally speaking. But I can't confirm that as of yet. Again, our phone number, 802-321-4225. Do we have a call, Kyle? No, not yet. And our phone line is open. So if you want to speak to our friends here from Valid, this is your opportunity. And I think we have more online questions. Oh, okay. Keep them coming, guys. Who stores this routing table information? Would this allow someone to track users' IPs across multiple connections? Who stores the information? Well, every node has their own view of the Valid network. Not every node is going to be able to reach every other node. In fact, I'd say that the routing table itself probably caps out at about 256 nodes per node. So you only get a view of a small part of the network. But that's all you really need to be able to construct your own routes. You only need a couple nodes to hop through, really. And if you pick ones that are fast but geographically dispersed, you're going to be bouncing around all over the place. And your communications themselves are end-to-end encrypted on Valid. So, you know, it doesn't really – there's nothing about Valid's construction right now that prevents people from knowing that you are running Valid. Like, if you were to do a network scan, yeah, we use port 5150. And you could probably find Valid nodes out there right now. But you wouldn't know what they were doing. And you wouldn't know who was using them. There's no connection between a node ID and your actual identity. That is a completely broken link. So, yeah, you're going to see nodes online. That said, you know, we know where all the Tor nodes are in the world today as well. You just don't know who's using them or for what. But you know if people are running a node. The same is true for Valid. You know, you use the internet, you're going to have traffic on the internet. That said, we've also got some projects right now to see if we can make it even a little bit harder to detect, making us look more and more like random data, randomizing ports and things like that. But basically, you're going to stick out running Valid a little bit right now unless you look just like regular HTTPS traffic going to all of the regular sites that you would go to. So, you know, if you're sniffing the network, it's going to look like a different kind of thing than most people's regular web traffic. We can't really do too much about that right now. I mean there's secondographic stuff. There's a whole field of research around having Valid or any other thing become deniable. There's a big difference between deniability and anonymity. Deniability and deniability says that you don't – you can say that you weren't even using it and people can't prove otherwise. Anonymity says that you can say I wasn't the one using it. It could have been anybody. And that's the difference between sort of node-level identity and user-level identity. And we are anonymizing that user-level identity. Interesting. Wow. Go ahead. Oh, we're caught up. I had a question. Does increased use of it perhaps discourage further surveillance from corporations? In other words, if more people were using this kind of software, assuming things go great, would it have an effect, do you think, on the affordability? I think you mentioned that a little bit, like making the cost of this just rampant spying or dragnet stuff so high to make usable that it's just not worth it? Sort of taking the floor out of it. That was one of the original design concepts that we had going on was we wanted to disrupt the data economy itself. If we give users the option to opt out of having their data scraped and sold, then we hope that it will kind of destroy that economy on its own. That is one of the ideas here is just giving people the option and hoping that they understand what that means and also helping them realize the value of the data that's being taken from them. What is the value of their privacy? And what does that mean exactly? We've been doing a lot of educational work around that so that people can make the right decision when the time comes. And we do hope to upend that economy. Also, one of the things that in theory will happen as we get a density of nodes starts to grow, we should see the cost of running the network itself, which is effectively zero still because everybody's kind of distributing it. But those resources shouldn't go up. The speed of the network theoretically could go up. And the privacy of the network should get better as more nodes come online because you're going to have more randomized routes. That was kind of where I was going with it. So, yeah, that answers a lot of where I was headed. So thanks for clearing that. I believe we have a phone call. Yeah, there's a call on the line. Good evening. You're on Off the Hook Overtime. Go ahead. Hello, Emanuel and Mom. Well, I'm famous now. I'm on the YouTube radio here. But anyways, about the obfuscating, like you actively running a valid node, would you be able to, like, you know, barring the given latency with it, could you, you know, route that through, like, a WireGuard connection of EPN and, you know, sort of not have to worry about being seen as running a node? Well, something is going to be seen as running a node. It'll be the other end of your WireGuard. So something is going to be seen as running a node as it connects to the network. But, yes, in theory, you can tunnel. If you tunnel at the layer two, you know, then, yes, anything that you want to do could be passed over a VPN if you wanted to. I've accidentally done it. I thought I was running a valid node from a hotel room just to test on the wild, you know, crazy hotel networks that exist out there and found myself that I had accidentally been routing it all over my VPN to my house. It worked great. I had no trouble running it over, you know, OpenVPN or whatever I was using at the time. And, yeah, transparently worked over a VPN without any trouble. Unfortunately for me, it made me feel pretty dumb because I didn't realize that it was actually tunneling from my house until I was wondering what the heck was going on. But, yeah, it does work. I can confirm that finding. I'm sorry, Carla, go ahead. I'm just saying that may be a good sign that, you know, that it was pretty seamless and, you know, didn't. But, yeah, painless. Worked great. Yep, just tunnel. You can tunnel. If you can tunnel your interface, you could have your valid node appear from wherever your endpoint is. Cool. Also, one more question. What brand of hot dogs did you throw at us? Those were kosher Hebrew National Beef Franks. You know, for those of us who weren't there, I'm not sure if we want to know what this is all about, but that's part of your presentation, I guess. So, a few weeks before we were going to give the presentation, our esteemed colleague, Death Veggie, that's Mr. Vegetable. No, wait, that's not Mr. Vegetable. He started jerking our chat. Hair doctor vegetable. Hair doctor professor Death Vegetable. He got the doctorate. Good for him. Yes. So, he started talking in our private chats about – we had a rule set up way back when we first got in touch with DEF CON to do this because of an incident from back in, like, 2002 or 2003 where they said, no raw meat. You can't throw any raw meat into the crowd. And we all kind of said, what? Okay, sure. Why was that? Okay. Well, it may have happened in the past that some raw meat was thrown into the audience. It – you had to be there. But that means you could have thrown – you could have thrown cooked meat at the crowd then. And that would have been okay. Well, technically, hot dogs are cooked. Well, that was the idea. Hot dogs are pre-cooked. They are pre-cooked. So, one of the best things to come out of this was somebody who got one of these packs of hot dogs made the most, quote-unquote, cursed DEF CON badge ever by slapping a CDC sticker on one and attaching it to his lanyard. And so, he got to be part of Badgel. Wow. Does that answer your question, caller? Yes, sir. And, man, it's out there. Yeah. All right. Well, thank you all very much. So, look forward to running the node. Cool. Thanks for calling. And our phone number, 802-3214-225. Go ahead, Gila. Okay. Two more questions have come in. First one, does Valid use post-quantum algorithms for encryption? Not today. Today, it uses Curve 25519-based algorithms, as well as Blake3 for hashing. These are properly strong for the kinds of use that we have today. But we have built-in crypto upgradability into the protocol. So, in the event that a practical post-quantum crypto system is implemented by cryptographers that we trust, it's the kind of thing that could be slipstreamed into Valid as a crypto system without any of our apps or developers having to do anything differently. So, you know, I know this is – it's a hotbed of crypto research right now, thinking about what to do when quantum computers change the game for the mathematics behind cryptography and cryptanalysis. So, we're prepared for that as soon as the cryptographers out there are prepared for it. Awesome. Okay. That was one. Here's two. You talked a little bit about traffic obfuscation. Are you familiar with V2Ray slash Shadowsocks? And are you going to try to implement their techniques? I am not familiar with those. I've studied a bunch of things. We are looking at Elligator, E-L-L-I-G-A-T-O-R, as a way to make our traffic look like completely random data. So, if you want to look up Elligator, that's currently our focus right now is looking at that. That may end up being a sidecar obfuscator for Valid. Okay. Go ahead, Rob. All right. While we're waiting for our next call, someone on Mastodon is taking issue with our claim during the radio hour that TOR runs 100 – rather, excuse me, I'll start again – that the NSA runs a large amount of TOR exit relays. They're citing a talk from CCC Camp 23 by TOR Project. And, of course, we can't watch the video while broadcasting, so I can't address what specifically they're talking about. But that is being disagreed with. That's fair. We've been working with the information that we have. We love TOR. We're not here to tear down TOR or talk smack about TOR. We're only acknowledging the fact that TOR has a really big gap to fill when it comes to its users, its end users, and, you know, the technology itself. And it has a marketing issue, to be frank. Those are the only things that we really have said any – that we really have anything negative against TOR. We didn't know that, but thank you for sharing, and I will watch that talk afterwards. And we're always open to learning something new. So if you were incorrect, our apologies. I mean, what I'm curious about is – is it at least conceivable that the NSA could run a TOR exit node? And if it is, then why not 100? It is conceivable, and, you know, while we obviously can't prove it, they wouldn't be doing their job if we could. Well, we could call the NSA and ask them, but I don't think they'll tell us. Exactly. You know, you're not going to know for sure. But if I go right now and I look up all of the exit nodes that I can find – there's a map of TOR exit nodes – I can find some odd hundred running out of the Isle of Man off the coast of England right now in some data center that, you know, sure as heck looks like – I don't know. It looks like a concentration point for this stuff. You know, I can't tell you, you know, that that's what it is, but, you know, any kind of concentration on a map of exit nodes is going to give me kind of pause a little bit, you know. Again, it doesn't have to be the NSA. You know, that's just sort of a straw man, boogeyman here. It could be anybody. It could be the mob. It could be anyone who has a vested interest in understanding, you know, and monitoring TOR. That's meant to be a good thing, though, that anybody can do this. So NSA, anybody, like anybody else is, so they could be doing this as well. It applies to anything, really. Yeah. I mean, so in general, I think that that kind of correlative analysis is something that we have to fight against. I think Valid's model of keeping as much as possible in-network rather than being a generalized internet proxy is going to have an effect over time of making things a whole heck of a lot harder to correlate. You're not going to have external signals as well as internal signals that you can put together. It'll all be in-network, and, you know, it won't be obvious where the endpoints of communication are. You know, if it could be that you're in the middle of a route, it could be that you're at the end or the beginning. It's going to be a lot harder to monitor unless you're monitoring a whole lot more devices, and it's going to become very prohibitively expensive to do. All right. I'm just going to invite people. Give us a call. Get to a phone and dial U.S. phone number 1-802-321-4225. That's 802-321-HACK. And thanks to the Gibson who had to take off for the evening, but we've still got Dildog and Meduse4 here to answer your questions. I didn't know who left because we can't see them. So somebody left, but I'm glad you clarified that. Go ahead, Gila. Yes. So another question, which I'm, again, going to assume is aimed at Dildog and Meduse4 because they're the ones with the answers. If an app on Valid is doing something problematic, can you stop it from proliferating itself? Not really. We don't really have any control over what Valid nodes do. There's no – it's quite possible that Valid as an organization someday may not even run its own nodes at all. We do just because, you know, I help making this framework and stuff. But it's going to be the apps themselves that are going to be responsible for the content of what their apps enable people to do. You know, we won't have any kind of sort of – we don't have any kind of sort of policing capability over this network. All we can do at this point, and we've released it to the world, there's hundreds of nodes out there right now. I can't tell with those nodes what to do. You know, I can't tell what they're doing, and I can't tell them no. So if you're going to write a Valid app, we request that you make an effort to adhere to the Valid code of conduct and try to build apps that are for everybody. And, you know, we're trying to build community that builds responsible applications. We encourage this behavior. We acknowledge that not everyone is going to want to do that. But that is a general social problem and not something that Valid can do much about. We don't really have any kind of authority over that. Right. A code of conduct for apps, though, that's something. It would be nice if, you know, people built apps that, you know, were built in an open, respectful community. That said, you know, we willingly acknowledge that, you know, when you put code out in the world, people are going to do what they want with it. We're trying to move the needle toward respectful communities. But, you know, the world is what it is. We're not going to change, you know, all of the social paradigms that exist out there today. You know, we know what we stand for. It's on our website, and we hope that people will follow us and encourage that kind of development, you know, ethos. But we'll fully acknowledge that, you know, people come in all stripes and different colors, you know, different attitudes. And, you know, we're not the police of application development at all. We just write a tool, a framework, and ask that people try to use it for good. But we are also going to be quiet if someone is using it for bad. One of the nice things about not having, you know, VC money or things like that is we don't have to cater to anyone telling us, oh, well, just, you know, don't make waves. We're going to be obnoxious and be a thorn in the sides of people that are trying to use this for bad, and I'm not afraid of that. Also, you know, we're building a community of people that we are encouraging to take ownership of, you know, this whole project. Feel like it's your own. Build on it. Have fun with it. It is all based on what the community is, you know, wanting to do with it. And the community is going to self-select. And if you do allow people to take ownership over the project, they're going to protect it, too. And I think that matters. I think that the community that we are building of people that care, that see the vision, that understand what's at stake here are going to, you know, make this happen in the way that we are hoping it's going to happen. Or it may take another route, but either way, we're – I believe everybody is here for good. I believe in the good of people, and I'm not going to give up on that. That's a great starting point, at least, until they prove otherwise, you know, give people the benefit of the doubt, and hopefully we get the best of the people. We don't have to remain quiet for fear of, like, our funding drying up. We wrote this for free. It costs us nothing. We'll say what we want, and there's – you know, it's not like it's going to hit us in the wallet. That said, has anyone tried to talk you out of this? The only feedback – and I'm going to let some people remain anonymous here – but the only feedback that I've gotten that was somewhat negative came from people that had a vested interest in the data economy. And from cryptocurrency folks who feel that blockchain solutions and smart contracts and putting transactions at the base of everything is the way forward. So I'm not going to highlight those projects or those people, but I can say that the biggest pushback we've gotten was from either big data collectors or people that we know that work at them or from cryptocurrency folks who feel that, you know, the way forward is monkey pictures and whatever. And I have heard – I've seen a little bit of pushback. Look, this is simply on a home frontier, but, you know, my husband is also involved in the project, JC. And when we went to our parents and we started telling them about this, they both – you know, both sets of parents were like, wait, so there's no money. You're not making money off of this? Why are you doing it? And that's kind of the only people that have really tried to talk about it in any way, shape, or form is just people that, you know, don't really understand the point of doing this without, you know, monetization. You know, talking to that and some of the other things you've mentioned, I just want to quote from your Frequently Asked Questions section of your website. Is VALID looking for funding? Answer, VALID is not seeking venture capital or investment. We are accepting tax-deductible donations to our nonprofit foundation, VALID Foundation, Inc. Does VALID have a cryptocurrency? Heck no. VALID does not have a cryptocurrency. Does VALID use AI? Heck no. VALID does not use AI. Does VALID use blockchain? Heck no. VALID does not use blockchain. First of all, I think it can be stronger with the language there. But, yeah, good for you for standing your ground. Well, those are all things that, you know, sort of ensconce a level of classism into programming and into development. And we didn't want to build a framework where people had to pay to play. You know, use a blockchain. At some point, you're going to pay for gas. You're going to pay for transactions. You're going to have to have Bitcoin. You're going to have to give your users sign into a wallet. But to me, that just rubs me the wrong way. There's a whole lot of investment people already, you know, did when they bought a giant thousand dollar iPhone. You know, it's a slap in the face to require everybody to hook up their wallet to do basic communications. Even basic storage. I mean, there's stuff that we take for granted, like, you know, VALID has storage built into it. Not a ton of storage, necessarily. It's not as guaranteed as, you know, your favorite backup service. But, you know, there's a lot more that can be done for free or cheap that, you know, is being aggressively monetized today by a lot of other solutions. The most investment we've put into this is time. And that's all we're asking of anyone else. Time and energy and passion and putting your skills to use. And I think that should be the cost here for anything. I mean, you're spending time on an app. You're giving your time and energy to, you know, billionaires who are just funding cage fights with each other or sending each other into Mars. So that is the currency that I feel matters more than anything else is the time, the energy, and, you know, our entire lives are put on the Internet. And that's, to me, the most important, you know, commodity that we're working with. Okay, we have gotten a bunch of questions for our guests, but just wanted to share something interesting that apparently happened during the show that we didn't know about because we didn't hear it. But apparently the emergency alert tones went off during the show for about 15 seconds. Really? Well, you see, we don't hear those. Exactly. This is what I'm saying. So over the web stream. Seems okay. Wait, just the tones or is it a test? It seems to be just the tones. People have only mentioned hearing the tone. But we've gotten mentions of it both on Mastodon and in the street in the chat. So that means there's an emergency of some sort, but the way the system is designed, they don't tell you what the emergency is. Or somebody hit the wrong button or our robot overlords have arrived and, you know, Earth, it's been nice knowing you. Thank you, everybody, for clarifying just the tones. Okay, so several, several questions have come in, and I'm just going to take them in the order in which they arrived in the chat. I mean, the debate's coming up at nine o'clock. Do you think there could be that, you know, the Republican debate? That might have triggered somebody. That's totally fair. Okay. First question. Is anyone in the community working on BSD or Haiku support to run Valid nodes? The answer to that is yes. I actually just had a conversation with someone today doing a free BSD port. It is early. We have Linux support today. Obviously, there's low-level operating system differences there, especially around network interfaces. But they are working on it. So that's the long answer. The short answer is yes, absolutely. People are working on it. If you want to join in, join our Discord and work with them. Okay. So the next answerable question. Philosophically, the human rights aspect is interesting. What benefits do you think could work for people who live in a place with repressive governments? I think that this will be the answer to their communication needs. We've seen people over in France that were holding protests against some aspects of their government. And their Internet got shut off. And suddenly they weren't able to connect with each other or talk. I believe it was France. It's been a bit of a blur the past few months, to be completely honest. But I do remember that there was some protests happening where people's ability to connect with each other and organize online was cut off. And this is going to be one of those things that isn't going to be necessarily able to be cut off so easily. Because it's not going to be the typical networks that people are used to. The typical networks that people are used to. And it's not the typical networks that the government necessarily has access to. So we foresee this as being a net positive for those who are living in those circumstances. And we are excited to see what comes of that. From a pragmatic standpoint, the fact that this is end-to-end encrypted is a big deal. People on our Discord are actively working on hardware and embedded nodes. So putting it on smaller and smaller hardware, which is going to enable it to be used in ad hoc mesh networks. Right now, we use the public internet as an overlay routing domain. But Valid also internally has support for other routing domains like local networks, Wi-Fi-only ad hoc networks and things like that, radio networks, etc. So as Valid matures, I think you're going to start seeing a lot of the ad hoc network creation stuff immediately being able to just work with all the apps that people have built. So the fact that you – if you have Valid chat and you're just used to using it on your regular home Wi-Fi, but then you go and take it into a protest zone, it will still work even if they cut off the internet. Because you'll be routing through all of your friends, and maybe one of those people has a connection to the internet still. Or just talking amongst the people that are there. So yeah, I think the construction of the network is going to enable a whole lot of interesting developments in the ad hoc networking space. Also, I want to correct myself, it was not France, it was Iran, where they did cut off the internet to those protesting. Those are not very similar countries. Well, in their handling of encryption policy, they're actually kind of similar. Okay. It's kind of sad that that's the case. You know, I think most governments want that kind of encryption policy or kind of communication policy. They want to be able to control people. They want to be able to watch over people. I don't know of any country that doesn't wish that, even if they don't say it publicly. That's true. Government, that is. Okay, we have some shy people, I think, that are afraid to call. So we're just going to issue the number one more time. Hopefully somebody will give us another call. 802-321-4225. 802-321-4225. You don't have to be an expert. You don't have to be a technical whiz. You can ask any question you want or just reveal anything that you want to share with us. 802-321-HACK is the phone number. But we're only going to be on for a few more minutes. So please give us a call if you have something to say. I do have a question for our listenership. We are getting the sense that the emergency tones were played on the simulcast, on the live stream. If anybody actually heard us on the actual FM radio, if you could let us know if you heard the tones. Now we're just curious. I hear sirens as you're saying this. What's going on in Queens there? We live like two blocks from a hospital. Or, you know, the world is on fire, robot overlords. The world is on fire. I mean, it's been documented. All of this is true. But yes, folks who are listening on the actual radio, in your car, your alarm clock, what have you. If you heard the tones on the radio, please give us a holler. Also. So, wouldn't the radio be the only place where emergency alert tones would be sounded? Apparently, people heard it on the live stream. They heard it on their Amazon devices. They heard it on the website. So now I'm curious. Also, someone wrote in, and I'm going to absolutely butcher this word. Thank you for calling. Okay. Apparently, it was on the radio as well. Someone says, just join the show. Are we speaking about the Cybico? Page 56, 2600, volume 40, number two, from 2000. We expected to just call that up? I don't know. I don't know. I don't write some. I just read them. I don't know. Sounds like they're referencing an article from 20 years ago. 23. Three years ago. Which is weird, because volume 40, number two, was pretty recent. But I understand nothing. You said 2000. Yeah. What was the 2000? Is that a type of equipment? Is that a model? Or is that? Okay. I am going to copy this and paste it into our chat so you guys could see, because apparently I murdered the syntax. And if anybody wants to call us, by the way, and again. We have a caller. We have a call? Yes. Great. So calling us now, you'll wind up being transferred someplace, and we can't get you back. So let's say hi to this caller. Good evening. You're on off the cover time. Go ahead. Hello. Hi. Hi. How are you doing? Good. Thank you. Yeah. I mean, I don't know. I've listened to you guys on and off for, I guess, like two years now. I guess just whenever I have time. I've never called in. I don't know. Felt like it today. So hi. Welcome. Yeah. Hi. Just out of curiosity, is there any reason to switch to Valid Chat from Signal right now? Just because I try and use Signal as a private messaging app. And I mean, other than the lack of SMS verification as, you know, being required. Yeah, I mean, I don't know. First off, Valid Chat is not fully released yet, so I wouldn't switch to it because you're not going to be able to download it. But when it does show up, I encourage you to try it, see if it works for you. There are going to be some environments maybe where Signal is a better choice for the short term. We are designing it to be a full replacement for that. It does not require phone numbers or any other kind of identifier. It may make you a little bit harder to find as a result. You'll have to invite people over another medium. I would keep Signal around. There's nothing inherently wrong with it other than, you know, the bit with the phone numbers. And I could say that there's been issues with them not choosing to encrypt certain things that were saved to your phone, like the attachments you receive were not being encrypted. So, I mean, there are some aspects of the app itself that I personally disagree with some of the choices that were made there. But for regular daily driver chat use, I'd say try them both. See how you feel about it. And, you know, if there's ways that you want to improve valid chat, we're all ears. We'll make it the best chat program that we can. One difference that I think is going to be key between Signal and valid chat is we're not going to ask for access to your contacts. So your contacts aren't going to get a little pop-up letting them know that you have joined Signal. Oh, that's so annoying. That was so annoying. That there is that. I forgot about that. Jesus. We don't ask for anything from your phone. No, I don't need to know every time one of my exes that I haven't spoken to in years has joined Signal. Thanks. Or one of your exes thinks that you're sending them a message by saying you're on Signal and then they contact you. That's the worst thing. Or one of your dead relatives that still is in your contact list that had their phone number reassigned to somebody else. I mean, that's happened too. Wow. Yeah. Yeah. Signal is wonderful. And we've done a lot of our work communicating with each other through that medium. So we're not going to sit here and bash it. We encourage everybody to try it out and see what works for them. And we're also going to be taking community feedback. So if you see something that we can improve on, we hope you join the Discord and talk to us and maybe we can make that happen. Okay. Yeah. I mean, I'm not – I can't – I don't know how to code at all. I want to learn. Me neither. No. Okay. Okay. So it's not like I'm going to be a problem – I don't know. It's not going to be too tough, I promise. I am not a coder myself. A lot of the tech explanations about VALID go over my head. But I assure you I will be testing every bit of it to make sure it is, you know, easy for us regular folks to understand. Cool. Okay. Cool. Thank you. All right. Thanks for your call. Yeah. Thank you. All right. Take care. Yeah. All right. See you. Go ahead, Gila. Bye. Okay. We did get clarification. Thank you to listeners, OpticalPhoenix and Knicker000 for clarifying. The Cybeco or Cybeco, I don't know how to pronounce it, was a handheld personal messaging tool that was released in the year 2000 and you could like – yeah. I remember that. I'm suddenly remembering this. Ad hoc local networks for people close by and the picture on Wikipedia is purple. It's very spiffy and apparently you could like put a memory card into it and play MP3s. So the short answer is no, that's not what we're talking about. But thank you for that awesome blast from the past. And now I kind of want one. I think we should be bringing back that colored plastic aesthetic myself. So, I'm all about it. Absolutely. It's really real cyberdeck vibes right there. Do we have another call? There is another caller, yes. Another caller. Good evening. You're on off-thuck overtime. Go ahead. Yeah, I had two questions actually. One about running a valid node and one about valid chat. About the valid node, like, will there be a way to throttle the resources you contribute to the network, like, you know, CPU, GPU, like IPFS storage or bandwidth for people who are on metered connections or people who have limited resources? And for valid chat, will there be a namespace for users or will there – are you just going to be like a key pair, like say with session? Okay, two questions. First one. Yes. Let me see. Let me get to the valid chat question first. First, as far as a key pair, your key is only shared to the people that you contact. You know, if you want to do – the way this works is you create a contact invitation. The invitations are encrypted. The invitations are placed onto our distributed hash table. And the way this works is you basically pass a decryption key for that invitation to your friend over some other medium, so iMessage or Signal or whatever you choose. They're not getting the key to your node or to you or to your identity over that non-valid medium. They're just getting a password, basically, that can be used to decrypt the invitation off of our distributed hash table. So when you connect with people, there's no such thing as a real – like a namespace per se. Everything is done on the main valid network. That said, if you wanted to, you could set up your own valid network today. There is nothing special about any valid node. All of the valid nodes right now are on the main valid network, but you could set up your own valid network. And we do have this notion of network keying. So if you wanted to set up a private valid just for you and your friends, you could do that. That would allow you to run a group of nodes that is not connected to the main big huge valid. Now, there might be security implications for that. Obviously, it's a pretty advanced use case. But, yes, when you just run valid chat by default, you are in the same namespace, if you would, as everybody else because there is no servers. Session does have this notion of servers. It's basically federated, not completely distributed. Session also has this thing where you have to buy like $8,000 worth of their cryptocurrency to run a node because they don't want people just setting them up. So we don't really subscribe to that. If that's what it takes to get their network up and running, that's fine. Just that's not how we choose to do it. And I didn't think I answered your first question. What was the first question again? I was just asking, like, say if you were to run a valid node, say if somebody were to be on like a metered connection or have resources or would just like to have it running in the background and not have it affect their bare metal hardware very much, are you able to run a low resource node? Yep, yeah, there's a configuration file. You can tweak how much storage. You can tweak what services you choose to offer if you don't want to do DHC storage at all, if you just want to do routing table stuff. You could also choose not to private route. You could turn on and off capabilities in the config file. So all of the limits and stuff like that are all tweakable. In a future release available, it's also going to detect whether or not you're on a metered connection. If you have a mobile device, for example, and it's going to automatically throttle back those capabilities. Right now, if you're on a slower connection or you're on like a symmetric carrier-grade NAT, which is what you're going to get when you use a mobile device on a cellular network that's metered, it already throttles back today based on the type of network you're on. So if you're not on like a static IP or a dynamic one that has UPnP like your home router, but you're on some kind of like carrier-grade symmetric NAT, it's going to notice it's automatically going to throttle back so it doesn't blow your bandwidth out. Cool. Thanks for the answers, good and concise. Appreciate it. Yep. Cheers. Thanks for your call. And I'm going to give out the phone number one more time, 802-321-4225, but we're running low on time. So if you have any questions for our guests concerning VALID and the future of the internet and all sorts of other things, give a call now, 802-321-4225, 802-321-HACK. Yes, Gila, go ahead. We got another one. How do you protect the private key on the device? Can it be placed in a YubiKey or similar secure element? All right. Well, I gave this a lot of thought. Right now it is not – you cannot use a YubiKey or an external hardware token. Again, the private key is encrypted with another key that is stored on, let's say, a mobile device in the keychain, and that itself can be encrypted with a password. So if you were to use a YubiKey, you could have it, like, generate a password or something like that. But we don't have support for, like, a time-based token or anything for that kind of unlock. That said, if you use the device-protected store, the hardware-protected store in your device, the keychain, and you do not back that up along with the rest of the – on, you know, your iCloud storage or whatever, you are protected from iCloud backup dump attacks and from attacks where people might try to siphon off your backups from, say, the lightning port on your phone. They would have to crack the password that you use to unlock the device key that we bake into the protected store. So keychain or keystore on Android or Windows-protected store or Linux secret service, those all have, you know, hardware enclaves that they store those keys in. So that's the answer. So we do – we give it a lot of thought. Our threat model was, you know, backup attacks and, you know, making sure that when you backup your device that there's at least a password between the attacker that downloads your backups and their ability to get at your stuff. Okay. Do we have a call? Another call, yes. Calls are coming in now. Good evening. You're on off the hook over time. Go ahead. Go ahead. Hey, how are you guys? Good. How are you? All right. I just wanted to give you the heads up as a fellow techie. At about 48 minutes is when you had your emergency tone and there was no warning beforehand and no warning after it. Yeah, that's how they design these things. You're supposed to somehow know. You send across that tone and, yeah, if you're not digitally tied into what you're listening to, you don't have a clue. You know, it's another example of how, you know, the old days, the EBS. The EAS system was very verbal. They tell you what it was. And EAS, they just send out these tones and they're supposed to activate something. But if they don't, then you're kind of left wondering just what the hell was that. It's really so. You know, we have a cable system. People who use Optimum might notice at 3 in the morning what they almost always do is just have a blue screen over all channels and PVRs that just say that they're testing a system for about five minutes. And you can't watch anything. And if you're watching something live, you're going to miss it. It's ridiculous. And they think that's how you're supposed to test the system. And it's not. Believe me, it's not how the system works. Anyway, that's not what you called it. And what do people do during the night shift if you work in the night shift? I have a question as well. Go ahead. I'm designing something that I believe is going to be really, really big. And I love what your female friend was saying before that you all agree with it's about the people and you don't want to have any money commandeering and stuff like that. I so agree. And I'm doing something along those lines. My only problem is I've had so many digital problems and I've had a guy who was designing software for a specific thing that I found a secret take three problems from every person, you know, and as I am a professional technician for 50 years and I have a really good success rate. And I said, how would I fix it? And I've come up with something and I want to design some software and my software guy who lived in Canada bailed out and never called me back. And he sounded like a good guy until we almost got done. And then when he couldn't reflect the software to work right, I think he didn't really know what he was doing as a young guy. And then that was it. I never heard from him again. Would you happen to know anyone who can do software? There's a lot of software development professionals out there. If you're looking for a contractor of some sort, you know, your best bet is to probably go through. There's an app development service. There's a lot of those online. You know, personally, I roll my own. That's because I've been coding for, you know, 35 something years now. So, you know, I write all my own stuff. But I know there are a lot of contract programmers out there. You know, feel free to hit up LinkedIn and places like that for software development needs. I also just want to chime in to say that I'm sorry. That really sucks. Yeah. I'm an operator in the past. I'm sorry. I cut you off. I'm sorry, guys. Oh, no. I just wanted to say I'm sorry. That sucks. Yeah, it does. What were you saying, caller? What would it take for me to interest the gentleman who is just speaking to be involved? If you're interested in things for people, I'm looking to do something on a very large scale. And I think if I was off air, I could explain it better. But I don't want to do it on air. My recommendation is if you want to pitch ideas to Valid developers because you think Valid is a relevant technology, come join our Discord. We have a lot of places where there's a lot of people that program and a lot of people that have the same kind of ideals. And they might be looking for things to do with Valid. And if your idea lines up with some of the people that are there, it's a very welcoming community. Feel free to join the Discord. You can find it on our website, on Valid.com. Click in there and pitch your idea to some of the people in some of our ideas channels. You know, we'd love to hear about ideas people have for apps. And, again, that's Valid, V-E-I-L-I-D.com. That's the website. So thank you for that call. Thank you. Keep up the great work. Thank you. Thank you for calling. And that's going to do it for calls tonight because we had a bunch of them in the end. Gila, did you have more? I do. This has actually been a very active evening on the chat. We've had people involved who have not been here before. So thank you very much. Okay. Question number one. Will an MVNO add any issues? I don't know what an MVNO is. I'm so glad someone else doesn't. I was feeling so stupid. I have no idea. I Googled it. A mobile virtual network operator. Of course. Oh, yeah. We all know that. Is a company that does not own a mobile spectrum license but sells mobile services under its brand name using a network of a licensed mobile operator. So this is basically subletting mobile network space so that, like, you know, FUBAR telecommunications could sell services but it would actually be backhauled out to, say, Verizon, you know, for the actual mobile network. I don't think that's going to – because this is an overlay network on top of the internet protocol, it's not really going to matter what the underlying topology is. They're probably going to use Symmetric NAT because that's what all these, you know, big carrier-grade networks do. We do support that completely. And, you know, it won't be the most, you know, feature-rich node that you're running, but, you know, it'll run all the apps that you care about without it being an issue. Okay. We had one additional question that was actually answered in the chat, so we are going to skip it. So last one. Before I say that, though, Tim in Connecticut, yes, if it had been the old way, they would have said if this were an actual emergency, you would have heard news. We don't do that anymore. Okay. Last question for our guests. How difficult would it be for a malicious coder to build a map of all VALID nodes? Could that have dangerous implications for people using VALID under oppressive regimes? I'm sure it could. Right now, because the number of VALID users is somewhat small, it would be like, you know, back in the 80s, you know, how many people had modems at home? You know, if you were dialed and you found people's home modems listening or something, it would be a pretty small population and they're pretty easily exploited. You know, if you're looking for somebody in a particular area code that did a digital crime or something, you just look and find all the people who had modems at home and go hunt them up. It wasn't that common. Again, the same is going to be true right now. People are building mapping mechanisms for VALID because at the IP layer, it's not, again, not trying to be deniable. But when you start looking at having millions or hundreds of millions of nodes eventually, building a map of those hundred million nodes isn't going to get you much. It's just going to be like, oh, look, everyone who has a computer is using VALID. You know, as soon as we reach that level of, you know, of saturation, it's going to be prohibitive to try to build a map of it. I had kind of a follow on. I was curious what your thoughts were about, I guess, actors that create versions that are maybe intentionally broken in some way. And so, like, say it gets popular, say, you know, Section 702 gets reauthorized and everybody freaks out and all of a sudden they get popular. It turns out the popular one's broken, you know. We all have, like, scenarios in our head, I think, from even this show talking about news stories of different apps, so on and so forth. So it just struck me that are you auditing in some way? Is there a way that you're encouraging? I know you mentioned a little, you touched on it a little bit, but how do you make sure that that continuity throughout, like, if it's in all different types of software that people are building, how are you even able to know? Is it just going to be naming and shaming that, hey, this is a broken, busted implementation of this, don't use it, or, you know, that kind of thing? How do you get the word out on what's good and what's really maybe a little shabby in the future? Yeah. You know, it's going to be sort of like Linux, you know. You know, you've got this big kernel that's sort of like Valid core, you know. And then there's going to be distributions that show up where people have packaged it with some libraries that they like or whatever. You know, I liken it to the sort of Linux kernel. There are little forks that you can find of Linux. Your mileage may vary if you don't choose the big supported one. But there's a lot of distributions. There's a lot of different ways that it's packaged. I have a feeling that Valid is going to do for networking and cloud, you know, mobile, modern software development what Linux did for operating systems. It's going to democratize things. It's going to open it up. It will have all a lot of the same problems in terms of, like, forks happening and whatever. But the one thing that we've got going for us is that no node in Valid has to trust any other node. So if you build an adversarial version of Valid that does bad things or, you know, doesn't perform the way you expect it to, other nodes are going to ban that node and not talk to it. So, you know, we've designed it for, you know, adversarial nodes existing. And, in fact, we encourage that. We have people on our Discord right now building adversarial node technology and committing it to our repository because we believe in building a better, more secure Valid. We have people actively hacking our stuff and producing security advisories. We already have a CVE on the MITRE database for a bug that we had that we got fixed in 24 hours, you know. So there's already a very hacker-friendly adversary, you know, adversarial development accepting ethos going on here. You know, we're not going to wait around and hope people don't hack this. We're going to hack it ourselves. Wow. I just love the phrase adversarial nodes. And actually, I'm making trophies. We are making trophies. I'm making trophies for the people that break it in the most creative way. I'm actually going to send them literal trophies to put on display. Wait, I am allowed to swear here, right? Yeah, you can. Go ahead. Go for it. I'm making fuck around and find out trophies. There you go. Wow. Because that is the scientific method. I'm encouraging people to fuck around with our stuff. Mess them out with the code. See what you can do. That way we know what we're expecting when we get this stuff on apps and in the hands of everybody. You know, we are really encouraging people to, you know, think outside the box and be creative and be a part of this. And, yes, breaking it is a part of it. Yeah, this reminds me so much of the early days of the net where it was all in front of us. And this is the kind of tone that we had, you know. It was basically break something or, you know, we'll make it better. It wasn't all about profit. It wasn't all about tracking. So, I can't thank you guys enough for bringing that back. And I sure hope it succeeds. Thanks a lot. All right. Thank you. I mean, that's what we're here for. We hope. Well, thanks, Dildog and Medusa. How do you pronounce the four? Medus. Medus4. Medus4. See, you changed the syllables that way, too. Okay. And also, thanks to the Gibson who had to leave before and everybody else who called in and wrote questions. And, of course, Kyle and Rob and Gila and Alex. Write to us, OTH at 2600.com. We'd love to hear from you with any thoughts or comments. If you have more questions, we'll forward them along. We will follow the story, of course. Absolutely. Any innovations. We'll figure out what emergency is going on, where those crazy tones came across. I'm not sure if the archive will have that or not. But we have... It was valid. We have... It was valid. We made the tones. I would believe that. But we might have an archive copy without it, or we might have the tones. Maybe people want to hear the tones. You know? It's kind of cool. If anyone else has any questions, we are super active in the Discord. I jump in voice chat all the time. I know Dil does as well. Because this is a community. So feel free to join the Vela Discord and get a part of this. And together, I think we can take back control of our internet. And how can people get to the Vela Discord? Vela.com. V-E-I-L-I-D.com. And there should be a link right there on the Discord. Cool. Or to the Discord. All right. Well, we'll be talking about this more in the future. I know it. So thanks to all you do. And best of luck for everything in the future. All right. Thank you. All right. Good night, everybody.