FLOSS-879
Jonathan: [00:00:00] This week we're talking with Nathan Freitas of The Guardian Project, talking about their work with Tor and the Butter Box some things for Signal, and a whole lot more. You don't wanna miss it, so stay tuned. This is Floss Weekly, episode 879, recorded Tuesday, August the 25th. Easy like butter
It's time for FOSS Weekly. That's the show about free, libre, and open source software. I'm your host, Jonathan Bennett, and today we have a treat. We have a returning... I don't remember if it's a returning guest, at least a returning topic. I think it's the same guest. We're talking about the Guardian Project, and we've got Nathan Freitas with us, and he is the founder, the director.
He's the guy from Guardian Project. He's also the director of reality at Proof Mode. And he's been around for a while. His first open source work was back in 1996 over at UC Santa Barbara working [00:01:00] on an NSF/NASA-funded digital library project, Alexandria, a precursor to Google Maps. And a bunch of other things from doing Java at Palm to Tor, the first port of Tor to Android.
He's- Nathan's been around. He's been around the block. And we're gonna talk to him, get an update on things that the Guardian Project is doing, and I think probably just talk a bit about the state of the world, which is a little dangerous, but we're gonna, we're gonna brave it. We're gonna do it. So without any further ado, Nathan, welcome to the show.
Glad to have you here.
Nathan: Thanks so much. Yeah. Returning guest and have talked, yeah with Doc and folks in the past on- ... pre- previous incarnations. And I definitely enjoy this podcast because we can get into the weeds, and people love it, the details.
Jonathan: Absolutely.
Nathan: The packets, the patches, the- whatever you wanna talk about.
Jonathan: I reached out, yeah, for sure. I reached out to both Doc and Simon to be able to co-host today, and didn't hear back from either of them. I think they're both super busy and didn't get a chance to get back to me. [00:02:00] But
Nathan: it's- It is summer still, though.
Jonathan: Yes.
Nathan: We're s- my kids are in s- camps and things, so you know.
It feels like summer here in Boston, so I don't mind if they're out on the beach or somewhere.
Jonathan: Yeah, absolutely. Absolutely. Were you at, I should have asked this before the show. Did you make it to DEF CON this year?
Nathan: I didn't, and I missed Hope as well. As a East Coaster, I'm a big Hope guy generally. And yeah, I- I'll admit COVID got me off going to big things, and I just haven't mentally gotten back.
There's a couple things I do. But the beauty of being in the Boston area often is it's feels like a constant hackathon of ideas and code- ... and meetups, and you've got so many big brains and open source history and things to do that I often o- feel already overwhelmed by stuff, I unders-
Jonathan: I understand.
Nathan: But I know a lot of great people were at both New York and Vegas,
Jonathan: yeah. So I'm in southwestern Oklahoma. Long-time listeners of the show know this, but I'm in southwestern Oklahoma, and great, amazing people here, but not a hotbed of open source and technology most of the [00:03:00] time. So I really enjoy being able to get out to things like DEF CON.
I made DEF CON for the first time this year, and really had a blast. Already making plans for going back with a bigger presence next year. Awesome ... but it was a, yeah, it was really cool. I saw there was a Tor booth at DEF CON, actually. Yeah, absolutely. And I did not get a chance to stop by and talk to them.
I really wanted to because Tor, Tor is one of those technologies that I've been interested in for a very long time. I it's one of the things that got me started with the security aspects of technology, 'cause I had a buddy that was d- at a college behind a firewall, and we had to do something to get his internet traffic out.
Yeah. And then I had at least one person I was helping for a while try to run Tor through the Chinese fire, or the, the great firewall of China. And it's like, it's a really interesting project. It's got a weird history. And you've been you've been involved with Tor for a long time, right?
You did the first Android port of Tor?
Nathan: Yep. Yeah, 2009. So the the history is a great success of open source- ... of free and open source software, really. It, [00:04:00] the u- the fundamental Ac- research for this of Onion routing came from the US Navy research lab, right? Yeah. Paul Syverson and others said, "Hey, the internet is fundamentally insecure and broken.
We need to do something to make it actually trustworthy." And so Onion routing, I just wrote a whole email response to someone because everyone comes to me and worries about, "Oh, how can you Tor on a phone? It's not anonymous, right?" They're expecting full anonymity. I said, "Okay, let's break it down."
Onion routing is about adding confidential authenticated routing of IP packets. It means you can route a packet without everyone in between knowing where it's coming from and going to, and you can be ensured that the packet was sent is the packet that you receive, and that everyone in between is authenticated to take it to the right place.
That's what Onion routing is, right? Anonymity is this idea that I can go to any website or use any app and they, nobody will know who I [00:05:00] am, right? And that's a whole other stack of user interface and app and brow- Tor browser, which is separate from... So the history really is that there was this really important idea to let's make the internet more secure, and it had this weird side effect- of being able to get around firewalls.
And to reduce surveillance. That actually, it was kind of the goal, but not in the way that it became something that it went from the US Navy to the Electronic Frontier Foundation- ... in a matter of years. And so then EFF really was a big supporter, and then Tor became its own nonprofit, and has really matured in so many ways to both not only continuing to ship Tor browser as a premier browser, open source built on Firefox thing you can trust.
But the secondary impacts of Tor, where we're sharing patches to other browser makers, we're c- creating other research and technology around surveillance, anti-censorship. People continually use Tor as a test bed to try to break the internet, and then we make Tor stronger and better [00:06:00] to to counteract that.
And, in the last year, we've been supporting about anywhere from 300,000 to 500,000 active users of Orbot, which is Tor on Android and iOS- ... in Iran. That's just in Iran, and Iran's had the most severe internet shutdown in the world, in the history, the longest in this last year, and it's been terrible.
And we've not only been able to provide an option, a free, trustworthy option for people in Iran to just be able to send a telegram message to their family or WhatsApp, but the, the iterative engine of research that basically says, "We think people who try to shut down and block the internet suck, and we wanna stop them from doing that," is amazing as a collective.
So yeah, Tor's had a long, strange history, diverse funding and diverse... and really a lot of transparency around, like- How they work, how the funding is- ... how, and it's... I really admire Tor as an organization, and they've really been supportive [00:07:00] of my work over 15-plus years.
Jonathan: So what, and I'm sure we covered this last time we talked to you, but how does Guardian Project sort of interface with Tor?
What's the what's the landscape? What's the relationship there?
Nathan: Yeah. We're fully, contributor member of the organ- of the open source project, right? So we submit code and patches, and we are- have been really focused on we'll take the main Tor release and compile it for Android and iOS, and we'll, "Ooh, something's broken.
Doesn't work anymore. Here's a patch," so that's a fundamental thing. We'll take the pluggable transports that are the way that Tor stays unblockable, things like Lyrebird, which used to be called obfs4, Snowflake, all of these cool tech add-on plugins to make Tor hard to block. And we say how can you actually get this to run on, again, Android, iOS?"
And so that's all kind of the core work and working with the paid and unpaid contributors to the Tor project. Some people are paid on grants, some people are staff. [00:08:00] We then also do our own fundraising, grant fundraising, human rights, humanitarian kind of people like the Open Technology Fund that also funded Signal to be created.
So we get a grant, said, "Okay, now take that and build an app like Orbot, and make it work well for people in Iran," as an example. So we have our own grant-raised fundraising organization that then funds our specific ideas.
And then, most... So as two examples of that, we created something called Orfox, which was our experimental version of Tor Browser for Android.
Got it. And it worked so well that Tor said, "Hey, can we make that Tor Browser for Android?" So we handed off that, and now there's an official Tor Browser for Android. Similar, we created Orbot for many years, and then they said, "You know what? Android really is important to us. We understand that now as Tor Project, the organization."
"We wanna make Tor VPN for Android. Is that okay if we take over that space?" And they have now released a beta 1.0 of that, and we're in this transition [00:09:00] between Orbot as a community project and the official Tor Project Tor VPN. So my mission is to pull Tor into the modern mobile age.
We've achieved that on Android, and we're now doing that on iOS through things like Onion Browser, Orbot for iOS, and soon a full Tor Browser for iOS. So-
Jonathan: Has that been a challenge on iOS? This is not necessarily- Oh, yeah ... the direction I was gonna take this interview, but it's very apt and interesting.
What... Because on iOS and for those that don't know you can go download Google Chrome for iOS. Google Chrome for iOS is Safari with a Chrome-shaped theme on top of it. Yeah. And that is the case for any browser that is officially in the Play Store. What, what's been you guys' approach?
Do you do it through the Play Store, or is this for jailbreak an iPhone? Yeah. Or because we now have thanks to our European friends, you can install a third-party Play Store on iOS if you live in Europe. Yeah. I'm waiting for that to come to the United States.
Nathan: Exactly, yeah. [00:10:00] So for years we've it was a project called Onion Browser we participated in.
Originally Mike Tigas, who's a great hacker/journalist built it. Then Benjamin Ehrhardt, who I- is on our team, is really great iOS developer, has maintained it. And we built Onion Browser for iOS, built on s- the Safari engine, Web- WebKit. We do everything we can to tweak it to be as close to Tor Browser, but it, but we can't...
The reason we don't call it Tor Browser is it's not Tor Browser. We can't give the same guarantees. We've done, we've hit the limit. So yes, couple things. One sideloading apps has gotten even easier now thanks to Alt Store, a bunch of other open source sideloading third-party app stores that don't even rely on the European ruling.
There's just been a lot more innovation around getting around the Apple App Store. So there's ways to build sideloadable apps where you just have to load it from your computer, but you don't have to jailbreak. So [00:11:00] that's one. Two, in a lot of places in the world that we support people, they're they're definitely already like jailbreaking their iPhones and just to get around their government and country restrictions.
So- Sure ... there's growing interest and capability there. And then third, yeah, the European Digital Markets Act and some of their rulings that not only allow you to have third-party app stores, but they actually require third-party browser engines to be allowed. So now we can actually port Gecko to iOS, Mozilla can or we can- Oh
and actually build the official thing for people in Europe, and that's a start. And Japan, I think. It's Europe and maybe Japan. So we're base- we're excited about this opportunity to actually build a Gecko-based, Firefox-based version of Tor Browser for iOS, and there's already some people working on this and hacking away at it.
And, of course, we all want like a Deb- our phones to run Debian or Arch or whatever. And I have that. For years I've had Linux, but [00:12:00] that's not our reality, and we all love GrapheneOS and Calyx and, Play Market, Play... All those like third-party- ... things, but... and we love that community, but our goal is to support, half a million people in Iran, for instance, and a lot of them actually have iPhones we're trying to-
Jonathan: Yeah
Nathan: do what we can.
Jonathan: Yeah. I- it surprised me so much to see in the US the courts going after Google and Android so hard when it's always worked there. It's always been relatively easy to install a third-party app, but then in the US courts, basically, "Oh no, iOS is fine. That's fine." And I just, I've been I've been so befuddled by that, and I've been thankful that Europe has gone after iOS and strong-armed them into this.
And I will say, like I gotta just as an aside here, I am like economically very conservative and like usually I'm on the side of no, the government should not get involved with this." But it's like no, this touches everybody's daily lives, and it's it's kind of an ownership principle as well, so- Exactly
maybe it's a good thing the governments, the courts are getting involved in this one.
Nathan: Exactly, [00:13:00] yeah. It's ownership and it's, kind of- Security as well because, these components on iOS are just these black box components that we actually don't know. They're not you can't just go to a source repo and see the WebKit that you're getting- Yeah
in iOS. True that. And there's also leaks oh you can set a proxy on the WebKit component, but if you're streaming media or doing WebRTC, it'll bypass that. Yeah. It's just it's actually worse security, not better- Yeah ... like they're promising.
Jonathan: Yes, for sure. I, I do wanna lean into this question about Android, because one of the other, one of the other partners that you guys have is F-Droid, and you've in fact got a you've got a banner here that Android will become a lockdown platform in six and a half days.
I know. I know what's up with that, and I have thoughts about it, but for those that don't know what's the story? What's going on with Android?
Nathan: Yeah this connects exactly to what we just talked about and yeah, boy, that s- that, that countdown came came fast. I think the, Maybe it's, it keeps [00:14:00] extending, so I need to there was 2027 requirement.
So I might need to update our JavaScript. But the point is, while Google has claimed to allow third-party app stores due to the Epic ruling and other things-
...
Nathan: They've also, they're, this is, it's like a malicious compliance. It's the same thing Apple's doing in Europe where they're like, "Sure, you can do a third-party app store, but you have to register with Google and pay Google money and give us your signing key and give us all the apps."
It's not what F- F-Droid does. It's like some vision of what a third-party app store that maybe Epic would run so that they can sell Fortnite. But has nothing to do with free and open source software, has nothing to do with decentralized distribution, has nothing to do with, like, all the reasons that we've supported F-Droid for so long- Yeah
and all the real-world issues. So I think they just, and at the same time, the sideloading is getting harder to enable.
So it's really concerning and yeah, we're definitely, like, supporting this [00:15:00] campaign that F-Droid has really been leading the charge on, along with the European Free Software advocates and global, a lot of people are involved.
And if you go to, yeah, the keep, keepandroidopen.org is a great place to learn more.
Jonathan: Yeah. I'm I'm gonna play devil's advocate for just a moment because I've followed this for a long time as well. I was actually really encouraged to see that Google did put in an escape hatch and it is a pain.
I believe there's a reason why it's a pain, and it may not be the reason that everybody else thinks. So you, so here's their instructions. For when they roll this out, here's how you can still install F-Droid. You go into your system settings, you go to About Phone, and instead of tapping the, or I guess it is.
It's the same, it's the same thing that we've always done to turn on developer mode, right? You tap the build number multiple times, and it'll, it eventually start going, "You're three taps away from developer mode. You're two taps away. Blah, blah, blah." Yeah. So you go into developer mode, and then it's going to tell you essentially, "Did someone ask you to do this?
Maybe you don't wanna do this." And then you have to put your pin in. You [00:16:00] have to essentially re- re-authenticate. It wants you to restart, and then Google wants you to wait 24 hours before it's going to turn this on. And at this point, you can then say, "I understand the risks. I want to be able to sideload."
And- I know that has everybody at F-Droid really up in arms. I don't love it either. I will say that I've also covered the security beat for years and years, and one of the things that we see continually over there was, this attack happened because y- an ad redirected someone to go download an APK.
Yeah. And that's how this malware got on their phone. And so I am genuinely convinced, I don't think Google cares about F-Droid. I think they care about stopping APK malware. Yeah. And trying to make F-Droid and all those folks still work was... we're dragging them kicking and screaming into that, and I think the courts are helping as well, forcing them.
But I don't see any of this with Google as an attack on F-Droid. I just, I see it as kind of an unfortunate side effect.
Nathan: [00:17:00] Oh, yeah. Yeah, I totally agree. I think there is another user experience that, that could be enabled for, Saying we, we wanna allow trusted third party app. We wanna, let's kill sideloading.
R- definitely years ago we decided even on Windows I would say, "Just don't download an EXE file from a website and run it," right? We know this is bad. But people still do this all the time, by the way. On, even on macOS, right? Sometimes you
Jonathan: have to, right? Sometimes- Sometimes
Nathan: you have to
Jonathan: Let's just be real. I still will go, now it's a website that I know and trust, but I'll still go download EXEs to make something happen. Yeah.
Nathan: Yeah. So I think what we so one, one thing on what Apple does, they have these special entitlements, which is a great word, but you say, "Look, I want to be a VPN app, so I'm gonna ask for this entitlement for my app to be a VPN."
And I think similarly, F-Droid would be willing to say, "We're going to submit F-Droid to Google Play, and we want the I Want To Be An App Store entitlement, which gives me certain abilities to silently install, do [00:18:00] background updates, all of that stuff." And we go happy, we're happy for F-Droid to go through...
They are happy. They have a, they're not, have a board of directors, they have a track record, history, all, all the things you would need. Similar to even what Apple is requiring for third-party app stores. It's possible. And then they say, "Okay, this is now a trusted organization who we can trust that they have a process for the apps that...
and if they get through that process, then F- and the user can then trust that third-party app store to do what you need to do. The, and the liability is perhaps on them as well. I think what this is requiring is a, is that, A, every single developer who wants to ship their app through F-Droid or any third-party store has to also register with Google.
So that is one thing. This escape hatch, by having regular people turn developer mode on, I think that's worse- ... [00:19:00] than anything else. So anyway, it's- Well,
Jonathan: The, the unfortunate thing- ... I have- The unfortunate thing about the escape hatch is that it's a binary choice, right? Yeah. Yeah. Y- you, you either completely turn off the requirement that APKs be signed or you don't install F-Droid.
And, Yeah ... yeah, I would 100% agree that it would be nice to have a bit more of a granular control over that. I want F-Droid to be trusted and not anything else.
Nathan: Yeah. And we've, I think unlocking bootloaders and across the hardware s- History of like doing something else with the hardware you own, there's lots of you can do it, but we're gonna make you turn off all of these security capabilities so that you can do something that you should be able to do."
And I never liked that kind of binary toggle, be it if it's my car or my laptop or my gaming machine or my Chromebook or my oven, it feels like we're often forced into that compromise to run- ... free software.
Jonathan: Yeah. And it's funny though because there's al- there's almost always a reason, maybe not a good reason, but there's [00:20:00] almost always a thought process that ended up in that point.
I- I've, I've-
Nathan: Oh, yeah ...
Jonathan: And so like you, you mentioned unlocking bootloaders. It's like once you've unlocked your bootloader, that's a way to get to a whole bunch of information on the phone. That- that's legitimately a security risk. And at the same time, I 100% agree that I should be able to unlock the bootloader on my hardware if I choose to.
It's a weird place- Yeah ... that we've ended up in.
Nathan: It's definitely weird.
Jonathan: All right so let's talk more about about Guardian Project. Like what's the overall sort of mission statement? What is it that you guys are trying to accomplish?
Nathan: I, so I came out of both academic and kind of Silicon Valley software and product technology development, and was at the same time in my personal life working in human rights and humanitarian work, somewhat tech, this is 20 plus years ago, 25 years ago. And I just, I was seeing that most of the tech that world was using was like trickling down from the business world. They were [00:21:00] like, "Oh, BlackBerrys are cool. Let's use a BlackBerry to try to do human rights." Or, they would say, "Oh, someone donated like Cisco VPNs to something," and I was... I didn't like that we were getting the sort of castoffs and that things weren't being designed with the kind of situations I was seeing in mind. Or things were very expensive and built for global like hedge fund managers and things like that who needed- ... like security and, wall.
And that, it was just like, or for government, right? It was like, "Oh, we can get some government tech, but we can get two secure phones 'cause they cost $50,000 each," so my goal was just- Yep ... to broaden both design from the be- ground up for regular people around the world who might find themselves suddenly becoming an activist, whether they want to or not or a journalist or, human rights advocates of all kinds.
And then also just that moment of we don't need crazy, hardware anymore for this stuff. You can just buy like a $50 phone and do [00:22:00] something with it, so it's been yeah, from day one just focused on that. I have a, a long connection with the Tibetan independence and human rights organization...
Oh, look at that. I just lost all my beautiful background. Anyway and it's not so bad. And T- Tibetan human rights and Chinese human rights and sovereignty and obviously that's been also like for a long time like the, the biggest bad guy on the block in terms of cyber warfare, spying- filtering, censoring. And so that's, the kind of the ultimate threat model has been China for me, sure. So yeah, that's what we've been doing, and through that we- I've worked on everything from Tor to open app stores to secure messaging through XMPP and Matrix to privacy preserving analytics because we saw a lot of people just dropping in like Google and Facebook analytics into their supposed secure stuff.
And then [00:23:00] most recently, like internet shutdown technologies 'cause we've seen countries and places go from "Hey, we're going to filter a website" to, "We are turning off the whole internet." Yeah ... and so yeah, just along the way I've been doing what we can to help.
Jonathan: Have you ever run into problems like US export controls getting in the way of trying to send some of these technologies various places?
Nathan: Yes. And I have-
Jonathan: No further comment about that? Is that the way that's gonna go?
Nathan: No, I do everything we're- We do everything we're supposed to do we're required to do. The, the cool thing is increasingly we're not using any... Mostly we're not using any novel cryptography. So in fact- Right
we're just using what's available on the platform. Sure. But I do everything I can to register and follow those restrictions and then also navigate. Like France is actually a hard place to distribute a cryptography app, for instance. And obviously- Yep ... there's restrictions in Iran and China and Russia, so I [00:24:00] think, the fact that we make... We don't profit. It's all free stuff. We're not a business selling stuff.
Our code is open source, and we, people often are building and redistributing our code, or maybe they're downloading a binary, but we're just distributing that through the normal mechanisms that, either Apple or Google Play provide for us.
We're just following the rules where we can. And, I'm also an ac- I am an activist. I've gone to jail. I've done scary things and put my life and people's life and, responsibly on the line and freedom on the line. This is real life for me.
And why I do it is based on some, I don't know, how I was raised and the, and stories and inspiration of other people. And when you're doing tech and human rights, you're exposed to people that have given their lives or are willing to give their lives and freedom up every day.
If I feel like I'm doing the right thing and I'm not harming people, then I do it and I think about it later in some ways.
Jonathan: It's such a weird... It's a [00:25:00] weird time where France makes that list of countries where it's difficult to do human rights stuff. It's so bizarre. We're in a bizarre world.
Nathan: Yeah. And, I'll say the other thing obviously is for so long our work was like- the early era of what I've done, 20 whatever, 20 years ago, was all about China.
Over there in China, the Chinese firewall. And of course, increasingly, since Snowden, and even before then, since 9/11, of course- ... concerns here in the US about our privacy- Sure ... about surveillance. And it's both the sort of Snowden stuff, but also- ... we know, like, how horri- horribly compromised our mobile telephone operator company software is.
We've, over and over again, we've heard about T-Mobile, AT&T, all these being compromised, all of our metadata, about who we call, when we... I don't trust the phone companies to keep my stuff safe, right? Yes. So-
Jonathan: I have heard some stories. I...
Nathan: Yeah. So- And that's, third countries I, I am, [00:26:00] I want people in the US to use all of this stuff, both to protect their rights of privacy that we have in our Constitution- and also to protect from the increasingly likely massive cyber attacks that could disable our country.
Jonathan: Yeah. What a, w- what an interesting dichotomy. W- it, so what, i- is, speaking, thinking about here in the US, like, how successful has that been trying to get these problems and these tools into the mind of the average citizen?
Nathan: Yeah, T- Tor and VPNs have had their moments obviously. Yeah, moments like Snowden raise a lot of awareness and we see huge spikes. I think we have so many users, a, a big section of users of things like Orbot and Tor in the US. Obviously, you can... signal is a huge success by any measure and, and- Absolutely
Not our project, but we've, the database we worked on SQL Cipher, which is the database that Signal uses. That's a big part of our, proud of [00:27:00] our legacy is bringing that to Android and promoting that and basically telling Signal, "Stop writing your own secure database and start using SQL Cipher", and they finally did, which was great.
And really just being an advocate for them and, so proud of... And, and they're an open source project that- ... we've contributed some other things that they're like the you can hide this Signal icon on your phone. You can change it to something else, and that's work, we contributed that and- Oh, nice
you can also blur faces in the photos, and that came from work that we've done with other groups. Anyway, that's... But you can also then say this, the secondary effect of Signal and then encryption then on WhatsApp and Apple Messages and everything else has really been, like the vast majority of text messaging moving from unencrypted SMS to encrypted SMS- even if it's not all great, is hu- is a huge success I think in the US. ... In the recent years, like I've liter- literally done digital security trainings for retired mostly women at [00:28:00] churches. Who are like, "I am helping with XYZ cause," pick your cause, "and, I want my s- communications to be private.
And I'm like, I'm happy to show up and do talk to the church ladies about digital security and privacy." And they care.
Jonathan: I'm sure. Yeah. No, that's really interesting. I didn't expect that at all. Yeah. What are some of the other projects that you guys work with? I see multiple logos, some of which I don't recognize on your partners and collaborators.
Yeah.
Nathan: The, the... we've worked with Calyx off and on for a long time. They, And that's not up there, but in terms of, yeah, on our homepage WITNESS is Peter Gabriel, the musician years ago when he saw what happened with Rodney King speeding by the LAPD, and the video recording of that event- having a huge impact, he said, "What if we gave everyone in the world video cameras? Wouldn't that help with human rights?" And he's and WITNESS has been the leader in, like- ... what happens when we give rights defenders cameras. And we've worked with them on something called Proof Mode, and basically, it's now, like, [00:29:00] how we fight deep fake AI slop in the world, so that's awesome.
We've been doing that forever with them. Tibet Action is a great partner who do all our work around Tibet and China with F-Droid. OkayThanks is an amazing design firm. If you're, if anyone's looking to help with branding, design, UX, they've been doing s- they- ... are in this security privacy world so deep, and know, like, how to make this stuff beautiful and come to life.
And then yeah, SR2 is awesome UK-based, our, all of our ops and infrastructure, e- essentially, and they're like the, the guy behind the guy often in terms of run, actually keeping stuff running, and then the last one is Benjamin Erhard, who's our lead on iOS. We like to just lift up.
We are a organization, but we also... The realities of what we do are such that- I'm- I describe it as like a movie studio or like Industrial Light & Magic often is my dream. But, [00:30:00] we get called like, "Hey, there's gonna be a movie." "We've got a couple years of money to make this film. We need you for the special effects."
I say, "All right, I'm gonna put together my best crew," and then we pool in all these people. It's when you watch the credits of the movies and there's like a ton of people and with different names. That's what we do. Yeah. And so I put together a team to produce something with a certain amount of funding because we're not a company where I have 50 employees and- Yeah
unlimited money. We I put together a squad for a heist, and we do it,
Jonathan: yeah. Beautiful. What- tell me more about ProofMode, 'cause this is definitely something that we are seeing more and more on a daily basis. The, so the problem statement here is that weaponized outrage, and unfortunately weaponized outrage pays money because so many platforms now are paying you for what's the term they use? Basically people watching your thing and clicking on and interacting, right? Yeah. And so the more outrageous that you can make something, the more interactions you get with it, and therefore, the more money you make. And that's not [00:31:00] even at all covering the idea of there's governments out there and special interest groups that wanna put their thumb on the scale, and weaponized outrage is one of the ways to do it.
And one of the easy ways to get to that is just make an AI video. Now, make an AI video that shows what you want it to or, selectively edit or there's a bunch of different ways to do it, but AI is becoming the go-to tool. And so what is ProofMode and how does it help?
Nathan: Yeah, y- so years ago, we, it was an event in like 2010 at NYU, and it was related to the visual images on the internet.
And back then, we just we realized there was two issues. One was, You could easily, there was like early cameras then that would like make you smile or would like manipulate thing. My niece who was, had this toy camera and I was like, it made you smile somehow.
It like changed the pixels in your face. Like that's weird. That's unfortunate. But you were also seeing cases of Photoshop of imagery to add or remove convenient item, items- ... for a, [00:32:00] a certain message. So at this event we actually came with two ideas. One was Obscura, and we built an app called ObscuraCam that's been around, which was, "Hey, let's make it easy to redact and blur photos right on your phone."
And that we could even use face detect and auto blur faces. So that came out of- Nice ... previous rounds of protests in Iran, saying let's just, how do we remove data from imagery and protect people? That was- ... and then we had In- InformaCam, which was how do we add, how do we digitally sign every photo, basically?
Because PGP's hard. People don't know how to do hashing. Just take a photo and add a hash to every one. That was the initial. And then we said what if you take a photo, add a hash, notarize that hash on a third party and then grab a bunch of other sensor data, like all your GPS data and your phone data and all this stuff so you have this manifest, you notarize it, you timestamp it, and that is what a photo should now be in this modern world."
So we've been working on that idea since then, and it was, I think just around [00:33:00] 2020, big movers and shakers in journalism, news, tech world started worrying about deepfakes. And that early, what they were starting to see and and this problem of easily increasing capabilities of things like Photoshop to, Magic Lasso and remove stuff and da.
So yeah, so Witness really worked as our partner there with groups like Project Origin, BBC, Microsoft, Adobe, Google eventually, and this thing has emerged called the Coalition for Content Provenance and Authentication or C2PA. And it's like EXIF with digital signatures- ... it's the easiest way. And we've been a part of that, and we are- we developed the mobile SDKs for C2PA, C2PA Android and iOS, and then ProofMode is our flagship it's our Firefox of this world essentially.
Yeah. It's a camera app, it's a verification tool, there's a server. It's all free and open source again, and- ... people use it to document war crime evidence. [00:34:00] People use it to document land theft in Latin America. People use it to document their catch, bass fishing catches for bass fishing contests.
People use it in Europe to document like an Amazon delivery, but it's an independent organic fruit delivery to say, "We delivered a box of fruit to this school on this day," so that the government will pay them. So it's become a, the u- the idea is that it's a photo or video you can trust, and it has the receipts, and the receipts are digitally cryptographically backed, and it's pretty great.
And we've found a way to, like- ... both work with the vision that Adobe and Google have. So this is built into Pixel now in some ways, right? It's built into Leicas, Nikons. That's great. They... Yeah, so they have a vision for C2PA that is one thing. We can do that v- version, but we also have a fully decentralized, anonymous, open source version of it, too- where you're not, like, submitting to s- [00:35:00] surveillance by Adobe and Google just because you want a photo trusted, right? So we're trying to balance... some people see this as as a global s- stamp on every photo, and it's gonna harm you because now every picture you take can be tracked back to you.
And we don't want that.
So we're navigating that. And so ProofMode, we really think is that balance of it's built with the same values where we build stuff like Orbot and Tor, but we're building a camera.
Jonathan: Yeah.
Yeah, interesting stuff. It looks like i- built into ProofMode is also some detection for AI?
Nathan: So yeah, so our, we have a web-based tool called ProofCheck which you don't u- it's all a progressive web app. You don't upload your photos or... It's all in your browser. And so we do some detection. We're not, It's more like, ProofCheck's more like a Swiss Army knife, where we're just trying to provide you all the tools to see what metadata is there- Oh
in any file, [00:36:00] like a media file. And then if we see something that looks like an AI d- fingerprint we'll let you know. Okay ... and then, but it's also if someone says, "Hey, I use ProofMode, here's a bunch of photos," you could drop it into ProofCheck and we'll tell you about 'em and do all the verification, okay. Again, it's this idea that normal people don't know how to verify a SHA-256 hash, and we wanna make it easy.
Jonathan: It's true. It's it's ironic, sometimes tech people don't know how to actually verify- ... a SHA-256. Oh, the first six characters match, it must be good. Like-
Nathan: Yeah. Well- Yeah, so we're- ... maybe
Jonathan: not.
Nathan: And the other, the like, another sort of hilarious offspring of this is we worked with Evan Henshaw-Plath, otherwise known as Rabble, who's a longtime hacker, worked on Twitter. And he created just something recently called Divine, which is a reboot of Vine, built on Nostr, which is another decentralized protocol.
It's open source and it's uses ProofMode and C2PA underneath. So we wanted to build, it's Vine, no AI, just for humans. [00:37:00] So this is you may not be a fan of six-second videos, and I know it kind of fries my brain- ... but we're so excited that there's an app like this which is for whatever ridiculous you want, and we can help ensure that it's a human-only space.
Jonathan: Yeah. Yeah, interesting. One of the other things looking at the Guardian Project homepage that stuck, that caught my eye, is Butterbox.
Nathan: Yeah. So that a whole other branch of work and stories, ... and but I think I, I might have mentioned earlier is that increasingly We are not just seeing internet censorship and blocks in the world, we're seeing internet shutdowns, right?
So around an election, they'll just shut down the internet, or there's some protest, internet will be shut down. Yes ... also, there's a lot of more severe weather events, we'll call them. And- ... we can do more to help people in those places with temporary servers, bring in some Starlinks.
But we need little [00:38:00] boxes, little Raspberry Pis, for instance. But it doesn't have to be a Raspberry Pi. We can talk about that. So we've been around long enough that we've seen things like PirateBox, FreedomBox lots of ideas around... LibraryBox was an awesome one by a f- a colleague of mine, jason Griffey. How do you take a little router or thing and make it a server you can carry around and it can allow some people to connect and do stuff? Upload, download, share files. That's the idea. There's also a Internet in a Box, another great one. So our thing was we wanna be, make it...
Butter is about, here's my butter towel, but make your life easier and smoother. There's a phrase in Spanish, "Como la mantequilla," like the b- easy like butter. Easy like butter. And we wanted to put an F-Droid App Store on there with apps that work without the internet, so that was a basic idea.
We wanted a chat room. We wanted open street maps you could download. And so yeah, we've been working on this for a while and f- we've now recently we're [00:39:00] adding in Delta Chat, which is a really cool signal-like decentralized encrypted messenger. So you can have multiple Butterboxes and relay messages.
We've been testing with things like Wi-Fi Halo for long range Wi-Fi, and also pairing one with a Starlink as a kind of a bridge into a Starlink server. And then, yeah, we've been working on Meshtastic pairing. So y- now you're carrying these things around in your bag with a battery. Yeah.
And ch- because someone may not know how to... If you have a box at a relief center in a central place and people can come and just see a message board of stuff coming in off of the mesh and chat and different things, we're open to adding different technologies as long as they are focused on this, how do we help people when they're in trouble and how do we make something hard easier?
Yeah. So yeah. Awesome ... and last thing, it's been a kind of a Raspberry Pi thing for a while, [00:40:00] Pis zero, 3, 4, all of that. The, the cool thing recently is we rebuilt everything on Debian, so now we have builds- Oh, yeah ... that are AMD64.
Jonathan: Everything.
Nathan: So everything You have it on
Jonathan: everything now. Yeah.
Nathan: Yeah.
So you just, here's my old beautiful ThinkPad and a little router And this is now a Butterbox. And this was, like, so important for people in places that can't get this hardware. And have lots of l- old laptops around. And old laptops are great- Yeah ... for so many cool things. Yep. But we're also excited we have a lot of partners in Africa, both in Kenya, South A- southern Africa And there's...
You can reliably get Pi 3s full Pi 3 kits there, and that's good enough for most people- Oh, yeah ... to use this with a small group. And so we're... Yeah, so Butterbox is really just trying to, we know the internet isn't always available, and can we do something that is straightforward and [00:41:00] simple for people to use?
Jonathan: Yeah, absolutely. It brings to mind, so the little router you had hanging off of that was a GLI Net, and it runs openWRT. Yeah. And it makes me think, is there room for a Butterbox Mini that's right inside of openWRT?
Nathan: I'm always asking what, thinking that. We've also thought about, an Android ROM or an app version- or a docker that runs in an Android phone. Sure. And yeah, we love, openWRT, those are... And I think Librarybox used to run on kind of openWRT type stuff. We've been pushing it because we're running a Matrix server and a Delta Chat server and... But I think a lot can be done on just the cheapest.
Even this this is the bigger GLI Nets-
...
Nathan: Can do a lot.
Oh, yeah, they're actually really
Jonathan: capable.
Nathan: Yeah, so-
Jonathan: Es- especially the, the ones that have the USB ports on them that you can, you can mount the file
Nathan: system on. Yeah, exactly. Yeah.
Jonathan: Yeah. Do a lot.
Nathan: So we're, in some ways, Butter is not only a specific tech, but we also- help [00:42:00] communities prepare in different ways and just understand what they can do without the internet, right?
And so people have become so dependent in the world on WhatsApp and Telegram and Signal and things and we, it doesn't have to be that way.
Jonathan: So it's an interesting experience to to do a, like a war game, a exercise of what happens if you don't have the internet? I've heard of guys that'll do things like, okay, 24 hours and go out and just shut the power off.
And then- Exactly ... how does it go for the next 24 hours? And at first it's real easy, and then you go to cook supper and it's oh no, I didn't, I was not as prepared for this as I thought I was. Or go turn your water off or turn your internet off. There's there's a bunch of these different scenarios that you can play through and it is, it's a l- real learning experience.
How would we cope without this for a while?
Nathan: Yeah, and I'm, the Meshtastic and Mesh Core and all these communities are interesting because, it's people just playing around, saying, I can buy this cheap gadget off of wherever and start dabbling [00:43:00] and say hello to I can reach people in New Hampshire it seems from he- from Boston, and that kinda makes me feel good- Yeah
that there's this little like someone out there, and if something went down and and I've unfortunately had to live through 9/11 in New York, the blackout in New York. I've lived in India through a number of issues of blackouts. Even the Boston Marathon bombing the, which I was not far from.
All your cell phones stop working, everything breaks. And and then now r- recently supporting people in Iran where there's been months and months without internet. And, or, one of our team members is from Mexico and she, there was a hurricane there a number of years ago, and she went back to assist them.
And so yeah, this stuff is real and it's it's real and- It's educational and fun to think of, sure. And I think the other interesting thing we were working with MIT OpenCourseWare, and they distribute a four terabyte drive which has all of [00:44:00] their courseware ever. Wow.
Jonathan: That's great.
Nathan: And so you can take this four terabyte drive, plug it into a Butterbox- and you have, like, all of MIT anywhere in the world, you know, on about... it's So we've actually worked with communities to do that. And we became a real easy go-to-
...
Nathan: For MIT to say, "Hey, this is a nice platform for a classroom," because we have chat and other stuff, too.
And so that's the other part, is like people in Cuba are, have this whole weekly packet. They also distribute terabyte drives with Netflix and games and apps and stuff. And so sneakernets, especially at the terabyte level-
...
Nathan: Are wild in terms of-
Jonathan: Oh, yeah ...
Nathan: if you actually think with that in mind what you can do,
Jonathan: yeah, the, the old adage was the station wagon full of tapes hurtling down the road. A sneakernet of somebody with a one terabyte in their pocket actually has some reasonable bandwidth.
Nathan: Truly, yeah. And, going back to, Delta Chat is really [00:45:00] interesting technology, by the way, because it's just email underneath.
And so all the old tricks of sneakernetting mail spools or trickling mail spools over low bandwidth networks work. So it's not... Signal's amazing, but the infrastructure's controlled and there's all this kind of highfalutin stuff it's doing. Delta Chat is just email, but it has the same end-to-end guarantees.
It basically made PGP super usable. But I love it because underneath we all know how to creatively handle mail spools. And so in fact, one of the modes we're working on for Butterbox is a s- is a sneakernet of mail, so you're just walking around a major city handing off drives, and the mail gets relayed through the drives being plugged into various Butterboxes.
Jonathan: I was not familiar with Delta Chat, and I'm now very intrigued. I will have to learn more about this.
Nathan: It's a good backup for Signal, if you ever need that.
Jonathan: I wonder what's... i'm switching hats here for a moment. When they say low bandwidth, I wonder how low bandwidth they're talking about.
Nathan: Yeah. We've wondered the same thing.
Jonathan: Yeah, I mean- if you've played around with [00:46:00] Meshtastic, we're... We do low dial-up speeds, like 1K in some cases, right?
Nathan: Yeah.
Jonathan: Very low bandwidth.
Nathan: I think... again, it's email. So we've all f- we've all- Synced our pop mail over a dial-up modem.
Not all, but many of us a little older, and that was the experience. And it's- Yeah ... not so bad. We also, I mentioned Wi-Fi HaLow. We've done some work- Yeah ... with that. It's really interesting and promising, and it seems to be coming out of the hacker maker s- phase into something that is more of a normal product.
The bandwidth you can get on, a, a one kilometer link is pretty good,
Jonathan: yeah. Yeah, it's really, it really is pretty interesting. All right. What have we not talked about that I should ask you about?
Nathan: I mentioned Matrix a bit. There's another thing that we are just starting to talk about more publicly.
It's called Convene. It's on the Butterbox, actually. So we built our own Matrix client and it is browser-based, it's encrypted and it's at [00:47:00] letsconvene.im. And it's not... We've had to lock it down because we can't just offer it free to the world 'cause we don't have the money to run s- servers for everybody.
Sure. But it's a great Matrix client to deploy if you're running your own Matrix infrastructure. It's built into Butterbox as the kind of Matrix chatroom, the web-based chatroom. It also, what I'm really excited, tying back to Proof Mode, it's kind of our demonstration app for a messaging app that also has photo verification in it.
So that, you upload a photo or video. If there is provenance and metadata we pull that out. If something looks like AI or it's been edited or it's old, we flag that. So we're using it as a way to say, "Hey, we think all messaging apps should do this kind of thing," where you're flagging stuff around the photos being shared.
But it's also a totally ephemeral... you don't have to have a Matrix account, you just click a link and join. So it, in a sense, works more like a Jitsi room or one of these temporary call [00:48:00] rooms. And it looks and works really well and, Okay ... you can find the code anywhere and, and it's I think for...
We're big fans of the, of Matrix as a platform for messaging. And and again, being able to build it in, and we've tried a bunch of different things, but yeah we're excited for that. But overall, yeah, we really, we have a pretty good set of contributors on the Tor stuff.
I think, Proof Mode and Butterbox, we're really excited. They're at kind of moments where we're seeing increased adoption, and the timing for both of these things is really needed and, whether you're interested in the Meshtastic pieces or- ... helping us support different hardware, or you're really into, yeah, wanting to build C2PA stuff into different things.
A lot of what we do is, like, empowering other developers and acting as a home for developers who wanna, and technologists of all kinds, who want to help the world. So I think ultimately that is, our mission is this could be... used to be that I could [00:49:00] w- funding is tricky right now overall, I'll say.
We had a pretty- Sure ... good run. ... I think obviously the current US administration and just the current funding environment's gotten really- ... complicated. So I'm not gonna say "Hey, everyone, come knock on our door and we can help make this your day job," but there's a lot of open source developers opportunities out there.
We're a great place to learn and to improve your skills around this kind of tech.
And also a great resume builder. And we love students, so I think that whole... I've done a lot of Google Summer of Code mentoring- ... and things like that. So yeah. Yeah. So we're always open to people that wanna get involved for whatever reason.
And who
Jonathan: knows? Do you think there's, do you think there's still a path for somebody that wants to make human rights technology their career?
Nathan: Yes, absolu- absolutely. There's, whether it's the Open Technology Fund in Europe there's a group called The Prototype Fund- that f- basically funds new ideas by new people that, yeah, you do it based in Europe. And there's academic environments that kind [00:50:00] of support this work. I'm a affiliate at the Berkman Klein Center at Harvard which is always looking for mixture of tech and academic and research. And I think, the cybersecurity front is always a great career path, which- Oh, yeah.
For sure ... which then you can do a lot of good in that path for lots of people and you can do pro bono work, and you can work in certs and other things that are really- ... helping the health of the internet. So yeah I think it, it still is, for sure. And we're just adjusting.
There's been various booms. There was a early internet freedom boom that produced Signal, for instance- ... and our work. Then there was the crypto boom where all the Bitcoin folks were, like, handing out money because they had lots of money. Now that has come down. Yep. The boom we're in right now is an AI boom.
Of course. And I think it's not really compatible with some of our values. All
Jonathan: right, everybody, take a drink. He said it.
Nathan: So most of the funding offers we get are like, "We'll give you a million dollars in [00:51:00] tokens," and I, I-
Jonathan: I mean, that's not nothing. Are, so are you guys doing the LLM coding thing?
Or do you stay away from that?
Nathan: We mostly stay away from it. We definitely aren't like, yeah, one-shot vibe coding. I think adverse- the adversarial au- code audit stuff is really interesting. It's really great, yeah. That has been... Basically, we'll pay, we're human auditors. Right now we're getting 7A Security is doing an audit of Orbot- and we're paying them a good chunk of money to do that. And we love people to do that. We love Trail of Bits and Radically Open Security and Cure53, and there's all these really great auditors out there that have been doing it for years. And we wanna keep doing that. However if we have the ability to run a security-capable model as a lint check like every day, that's great, and I think if- So that, that is my current interest, and there's also, we see more AI popping up in pen testing tools and- Of [00:52:00] course ... scanning tools. So I'm comfortable with it there. I'm sure that just like our developers in the past would probably find code from Stack Overflow and copy and paste it into their work, they're probably- Oh,
Jonathan: surely not.
We never did that.
Nathan: That's why we get audits, but I know that- ... yeah, some amount of our code is being written by Smart Code Complete in Android Studio because you can't, it's hard to avoid, sure. So yeah, it's an interesting time, and I think we're... we're also, there is some great research in algorithmic machine learning-generated anti-censorship-like protocols.
Protocols that are using algorithmic evolution rather than a human having to figure out how to do it, we can actually build stuff that a human wouldn't think of in terms of getting through, a certain deep packet filter. Yeah, absolutely. So yeah, we're trying to approach this in the right way and be cautious of course, as always, so
Jonathan: yeah.
Yeah. I saw I saw the funniest thing. I think it was today, [00:53:00] earlier today I saw this. It was one of those, it was a PR review that was obviously made by AI, and at the end of the review, it finally got to the point to where it's like, "Green check mark. No issues found. Ready for human eyeballs."
Nathan: Yeah. Yeah. And I know Tor specifically has got, when those first... this is not that long ago. A few months ago, when we ha- every, every open source project was getting this flood of-
Jonathan: Yes ...
Nathan: of vulnerability reports you needed machine assistance just to get through it all- Just, yes ... and try to figure out what was real.
Jonathan: Yeah. So here's the crazy thing in just those few months that it's gone from the flood of bogus vulnerabilities to now a slightly less flood of real vulnerabilities that we are getting from AI. It has gotten so much better so quickly. Yeah. It's been amazing to watch, and terrifying, but amazing to watch at the same time.
Nathan: Yeah, and it's, that's [00:54:00] definitely... Yeah it's a wonderful problem to have. I think a lot of us humans are still adjusting to how to deal with that scale and- Absolutely ... how to respond appropriately and, and I think we're, it's also r- yeah, it's a weird time because you will see some well-meaning person just vibe code, a human rights app and announce it to the world on, Hacker News, and you're just like, "Oh," like- it feels the speed at things, that things are happening, there's so many opportunities for things to go wrong or not have care- Right
Especially in critical areas. So we're, there's a huge... I'm part of a number of groups that are like AI for democracy and AI for human rights, and there's great ideas, and people can whip up a really impressive prototype quickly. It just we're-
Jonathan: You're in an industry, though, where oversights get people killed.
Nathan: Yeah. Or lose elections, or, or in a way that shouldn't have happened, things like [00:55:00] that. Or- Yeah ... big gaps in There, there's a whole range of bad outcomes that can come from lack of care, and yeah, getting people killed is probably the worst. I think we are also evolving to say, what else is needed?
So like I said, auditing and logging and, we've, with ProofMode, we wrote a whole National Science Foundation proposal with a UC Santa Cruz lab called the Explainable AI Lab, which does a really amazing work there, and we didn't get the funding unfortunately, but we're keeping at it.
Basically saying, look, if you're allowing kind of machine processing of like science through a, a pipeline and you're not auditing every step of manipulation of that data or that sensor data- ... that image, the AI will just try to please you and will just make up stuff and add things and change stuff, and that we need notarization, just like with ProofMode photos along the way of like data sets and stuff so that- Oh, yeah
Just like a Git history you can roll back the history and find who to blame. And so we're, that's a lot of what we're also talking about is the lack, [00:56:00] the kind of AI safety around, you know, transparency of logs and operations and provenance of the data that's being sent through because, we've clearly seen that in so many like court filings already where citations are just invented.
Yeah.
Jonathan: Yeah. For sure. All right. We are unfortunately, we could go longer. I would be thrilled to, but we are out of time. I gotta ask you a couple of final questions, and that is what is your favorite text editor and scripting language? You personally.
Nathan: I still use plain old VI often and it's still just the muscle memory. Yep. I use, I just it's the, the muscle memory of my late teens and early 20s and anything that looks or feels like it is my favorite, so I'll stick with that. All right. And scripting language I really enjoy when I have the chance to write make files.
Jonathan: Okay.
Nathan: So it also... there's something that feels so good about when you [00:57:00] automate a build thing completely- This is true ... and a- and it's just it like, really, you feel responsible and grown up that you've taken something hack. And it's an interesting kind of scripting language.
So yeah, I just- Yeah ... there's, so the great satisfaction I get in something like that,
Jonathan: got it. That's fun. All right. N- Nathan, thank you so much for being here. It has been a blast. Real joy to talk to you.
Nathan: Thank you so much. Yeah. Keep it up. Really also am a listener, and appreciate o- obviously this work needs so much continued advo- advocacy and highlighting of all the people putting in so much energy, so- Yeah
thank you.
Jonathan: Yeah, absolutely. All right. Wonderful conversation with Nathan. We've got some fun stuff coming up. We actually mentioned it. Next week we're talking to Trail of Bits, and then the week after that we're talking with Oliver Vernon of updatecli, and then after that is the Open Source Automation Development Lab.
So we've got the next three weeks booked, and then the week after that, no show on the 22nd because I am out traveling. But hey, we hope everybody comes back next [00:58:00] week and for the next three shows. We plan to have a lot of fun. It'll be a blast. Appreciate everybody that is here today, whether you watch or listen or get us live or on the download.
Thank you so much for being here, and we'll be back next week on Floss Week.
Avsnitt sparat!
Du hittar sparade avsnitt på Mina sidor.
Kunde inte spara avsnitt
Något gick fel. Försök igen.