1
00:00:00,020 --> 00:00:04,660
it's very dangerous for people to have an illusion that nobody observes their IP address. There will

2
00:00:04,660 --> 00:00:10,160
be always that somebody, they have a choice of who this somebody is. Hello everybody and welcome to

3
00:00:10,320 --> 00:00:14,900
Techlore Talks. Today I'm really excited to have Evgeny on who's the founder of the SimpleX chat

4
00:00:15,120 --> 00:00:19,020
platform but it's also more than chat as we'll talk about a lot today. He's going to talk about

5
00:00:19,070 --> 00:00:24,040
the decentralized network and how it works, the privacy and security implications, why this

6
00:00:24,740 --> 00:00:29,220
decentralization exists and how it's different from other decentralized models, usability challenges

7
00:00:29,240 --> 00:00:33,200
multi-device functionality. Pretty much, if you've never heard of SimpleX, or even if you have heard

8
00:00:33,200 --> 00:00:37,820
of it and you want to learn a lot more about the nitty-gritty details, this is the place for you.

9
00:00:38,040 --> 00:00:41,740
Of course, we're going to zoom out a bit too and touch on the broader implications of privacy

10
00:00:41,920 --> 00:00:46,620
technology in society and the challenges faced by developers in navigating the legal landscape.

11
00:00:46,890 --> 00:00:51,680
One small disclaimer, Evgeny does reference other projects like Session and Signal quite a bit,

12
00:00:51,770 --> 00:00:56,699
and this interview was recorded a couple months back before things like Session's V2 protocol

13
00:00:56,880 --> 00:01:01,580
concept was released. So please keep that context in mind as Evgeny covers it. And now to the

14
00:01:01,780 --> 00:01:06,360
interview. Welcome to Techlore Talks. I've been meaning to have you on for the longest time. Do

15
00:01:06,360 --> 00:01:12,180
you want to introduce yourself and say a few things? Hi, Henry. Thanks a lot for having me

16
00:01:12,300 --> 00:01:21,280
here at your show. I'm Evgeny. I'm the founder of SimpleX Chat that many people believe is the most

17
00:01:21,380 --> 00:01:26,480
private and secure messaging network. We've been working on it for almost four years now.

18
00:01:26,660 --> 00:01:30,760
So, yeah, so like I think everything that happened with me before is not so interesting.

19
00:01:31,640 --> 00:01:31,860
Got it.

20
00:01:31,860 --> 00:01:36,800
Yeah, so when I put in SimpleX into my search engine, sometimes your Messenger does not pop up.

21
00:01:37,240 --> 00:01:41,980
So do you mind explaining the name of SimpleX and the origins of that and the branding?

22
00:01:43,220 --> 00:01:43,580
Sure thing.

23
00:01:44,180 --> 00:01:51,540
So we came up with a novel design for the messaging network long before it even started as a project.

24
00:01:51,640 --> 00:01:55,200
It was probably late 2019 when this design emerged.

25
00:01:55,980 --> 00:02:03,240
The idea was to create a communication network when people can connect without having an identifier on the network.

26
00:02:04,290 --> 00:02:12,920
That kind of flips the traditional network design completely upside down to the point that when I was kind of explaining the idea to many even technologists,

27
00:02:13,050 --> 00:02:14,780
they were saying, man, you must be lying.

28
00:02:15,420 --> 00:02:19,120
It's just not possible because you need to some identifiers to connect to people.

29
00:02:19,780 --> 00:02:24,600
And the reason it got SimpleX name for two things, right?

30
00:02:24,720 --> 00:02:30,860
So first, it's simplex means unidirectional as opposite to duplex, right?

31
00:02:31,050 --> 00:02:35,100
You know, like all those old ham radios when you have to press a button to talk and it

32
00:02:35,240 --> 00:02:36,980
transmits signal only in one direction.

33
00:02:38,110 --> 00:02:43,460
And also high security networks are also designed as unidirectional network when the data can

34
00:02:43,620 --> 00:02:44,640
flow only in one direction.

35
00:02:45,420 --> 00:02:52,619
So the whole network is constructed from rather simple messaging pipes or queues that can

36
00:02:52,640 --> 00:02:54,240
only transmit messages in one direction.

37
00:02:54,540 --> 00:02:55,960
And to have a conversation, people

38
00:02:56,000 --> 00:02:57,180
have to have two of those.

39
00:02:58,140 --> 00:02:59,940
And literally every single connection of the network

40
00:02:59,940 --> 00:03:01,960
is constructed from two of those pipes.

41
00:03:02,640 --> 00:03:05,520
And they can use different servers, actually

42
00:03:05,960 --> 00:03:07,520
a pair of different servers each.

43
00:03:07,720 --> 00:03:11,660
So yeah, so that's where the name simplex came from originally.

44
00:03:11,820 --> 00:03:17,420
And then we made a pun on simplex because simple

45
00:03:18,220 --> 00:03:20,699
is probably the simplest message queue design

46
00:03:20,720 --> 00:03:25,440
I've seen comparing with the existing message queue designs and also X for secure.

47
00:03:25,760 --> 00:03:27,880
So that was the origin of this name.

48
00:03:28,560 --> 00:03:28,820
Very nice.

49
00:03:28,960 --> 00:03:31,760
And yeah, for people who looked it up, I went in there.

50
00:03:31,780 --> 00:03:33,500
It is not the crypto thing.

51
00:03:33,780 --> 00:03:35,120
It is the SimpleX Messenger.

52
00:03:35,460 --> 00:03:38,699
That is just to be precise because I...

53
00:03:39,940 --> 00:03:40,160
Correct.

54
00:03:40,560 --> 00:03:43,060
We call it SimpleX Chat.

55
00:03:43,240 --> 00:03:50,300
And it has nothing to do with SimpleX Cryptocurrency, even though some people get confused.

56
00:03:50,660 --> 00:03:54,120
And many people say, when on earth are you going to change the name?

57
00:03:54,780 --> 00:03:58,040
And a small hint to the future, this will happen, obviously.

58
00:03:58,400 --> 00:04:01,340
And SimpleX will remain as a name for the underlying network.

59
00:04:01,600 --> 00:04:07,300
But we're going to consider, kind of have a good candidate for a new name for the opt-in mail-in.

60
00:04:07,660 --> 00:04:09,520
Got it. No, I definitely want to touch more on that.

61
00:04:09,620 --> 00:04:14,280
Because it sounds like, to myself and many people, when I say SimpleX Messenger,

62
00:04:14,560 --> 00:04:16,019
it's kind of just all one thing.

63
00:04:16,140 --> 00:04:18,060
But it sounds like it's a bit more nuanced than that.

64
00:04:18,079 --> 00:04:20,120
So I definitely want to touch on the architecture side of things.

65
00:04:20,640 --> 00:04:24,300
Before that, what's your team size? Where are you guys based? What's your structure?

66
00:04:25,480 --> 00:04:32,260
We have a very small team. At the peak, we had six people, and currently we have four people in the team.

67
00:04:32,470 --> 00:04:38,540
So we're trying to be as lean as possible without any single geographic location for the team.

68
00:04:38,940 --> 00:04:42,420
Everybody is in different places, which we're not advertising.

69
00:04:43,680 --> 00:04:47,380
I'm personally in the United Kingdom. The company is registered in the United Kingdom,

70
00:04:47,460 --> 00:04:52,160
which draws lots of criticism for, which I disagree with strongly.

71
00:04:52,280 --> 00:04:53,560
We can talk about it if you're interested.

72
00:04:53,660 --> 00:04:54,580
We can talk later about that.

73
00:04:54,680 --> 00:04:59,860
So I think I honestly agree with the view that was recently published in some post

74
00:05:00,100 --> 00:05:03,240
that jurisdiction doesn't really matter if the code is open source

75
00:05:03,480 --> 00:05:09,320
and the network is decentralized and nobody should care about where this is all happening.

76
00:05:10,520 --> 00:05:10,760
Got it.

77
00:05:10,800 --> 00:05:13,000
And so, you know, to someone new to this podcast,

78
00:05:13,200 --> 00:05:14,920
before we start diving into the technical stuff,

79
00:05:15,120 --> 00:05:24,520
Just very quickly, what would you define as the core difference between your messenger and just a typical mainstream messenger, something like WhatsApp or Facebook Messenger or even Telegram?

80
00:05:26,180 --> 00:05:29,600
We don't even see what we built as a messenger, to be honest with you.

81
00:05:29,740 --> 00:05:39,639
We created a new network topology and designed for transmitting messages over this network topology.

82
00:05:41,140 --> 00:05:47,220
But messages is a building block for any internet application, right?

83
00:05:47,320 --> 00:05:49,180
And it doesn't matter what it does.

84
00:05:49,180 --> 00:05:50,920
It can be access to content.

85
00:05:50,960 --> 00:05:51,740
It can be communication.

86
00:05:52,060 --> 00:05:55,300
It can be any commerce activity.

87
00:05:55,940 --> 00:06:00,080
And we just wanted to build the fabric for those applications,

88
00:06:01,840 --> 00:06:04,420
which would allow people to build decentralized applications

89
00:06:04,660 --> 00:06:05,940
that can work over the internet,

90
00:06:06,200 --> 00:06:09,620
providing people out-of-the-box authentication

91
00:06:10,680 --> 00:06:11,820
so you know who you're talking to.

92
00:06:11,860 --> 00:06:13,120
If you connect it at the same time,

93
00:06:13,200 --> 00:06:15,640
providing them security from the network operators

94
00:06:16,300 --> 00:06:20,460
so that while users have security and authenticity between them,

95
00:06:20,700 --> 00:06:24,160
the network operators don't really know who uses their network

96
00:06:24,280 --> 00:06:25,720
and they shouldn't know that

97
00:06:26,000 --> 00:06:28,740
because otherwise that undermines security of the users.

98
00:06:30,200 --> 00:06:31,380
And that's a fundamental difference.

99
00:06:31,660 --> 00:06:34,879
So we're not a platform

100
00:06:34,880 --> 00:06:38,140
and they're not a messenger and they're not a service.

101
00:06:38,370 --> 00:06:44,200
We created an application that philosophically is the most close to the web browser.

102
00:06:44,580 --> 00:06:49,480
Currently, there is only one new generation of application which we develop,

103
00:06:49,590 --> 00:06:52,080
but it doesn't mean somebody else can't create this application

104
00:06:53,250 --> 00:06:56,000
and connect the same network using this application.

105
00:06:56,600 --> 00:07:02,380
And anybody can run the servers and anybody can have conversations or communities or channels.

106
00:07:02,740 --> 00:07:16,200
And currently, the biggest development that's happening right now is robust support for large content channel or large communities, which was the biggest point of criticism because the network wasn't built for large communities.

107
00:07:17,060 --> 00:07:23,280
So, yeah, so I think fundamental difference from WhatsApp or Telegram is that they own everything.

108
00:07:23,450 --> 00:07:24,340
They own the users.

109
00:07:24,410 --> 00:07:26,140
They own the content that users post.

110
00:07:26,150 --> 00:07:27,200
They own the conversations.

111
00:07:27,370 --> 00:07:28,940
And they can do what they want.

112
00:07:29,260 --> 00:07:34,160
And with us, we see ourselves as technology providers.

113
00:07:34,840 --> 00:07:36,320
We don't own the content.

114
00:07:36,340 --> 00:07:37,440
We don't own the users.

115
00:07:38,100 --> 00:07:42,560
We are developing technology which people can use to create

116
00:07:42,640 --> 00:07:46,660
and to have conversations between them, to distribute content between them.

117
00:07:47,100 --> 00:07:51,400
But our role here is effectively a user agent.

118
00:07:51,580 --> 00:07:53,060
The browsers are called user agents.

119
00:07:53,280 --> 00:07:56,600
So something that allows users to connect to this network.

120
00:07:56,880 --> 00:07:59,500
and we develop client software and server software,

121
00:07:59,840 --> 00:08:01,340
but we do not see ourselves,

122
00:08:02,060 --> 00:08:04,140
and we are not a service provider on this network.

123
00:08:05,180 --> 00:08:05,420
Got it.

124
00:08:05,460 --> 00:08:07,540
So why have you taken this approach then?

125
00:08:07,880 --> 00:08:10,420
But what do you feel like is missing from the space?

126
00:08:10,600 --> 00:08:14,180
Like, what's the value that this brings a regular person that you're seeing?

127
00:08:14,460 --> 00:08:19,740
Well, open web is the only decentralized network design

128
00:08:19,980 --> 00:08:21,600
that really managed to become mainstream,

129
00:08:22,640 --> 00:08:33,099
And open web is still to date remains the network design, which gives its users the largest amount of freedom.

130
00:08:33,150 --> 00:08:34,380
How can they use the network?

131
00:08:34,729 --> 00:08:34,940
Right.

132
00:08:34,950 --> 00:08:37,440
You don't even think about it as a web.

133
00:08:37,539 --> 00:08:39,620
For most people, web is Internet.

134
00:08:39,950 --> 00:08:40,140
Right.

135
00:08:41,400 --> 00:08:47,840
And when they use the browser and go to some website, this website can do anything they want.

136
00:08:47,940 --> 00:08:54,760
I mean, not any specific website, but generally the web as a network can provide any sort of utility, right?

137
00:08:54,960 --> 00:09:01,600
It's not seen as something to access content on, right?

138
00:09:01,670 --> 00:09:03,320
There are social networks that run on the web.

139
00:09:03,320 --> 00:09:05,080
There are commercial sites that run on the web.

140
00:09:05,270 --> 00:09:09,820
And there is no limits to what people can develop using web as a network.

141
00:09:10,160 --> 00:09:19,300
But web has kind of reached limits in its development because of bureaucracy, because of lack of vision for what the web should go further.

142
00:09:19,800 --> 00:09:25,019
And we see more and more than the web is being replaced by large centralized applications.

143
00:09:25,760 --> 00:09:30,140
And a lot of user activity is now centered not around the open web.

144
00:09:30,150 --> 00:09:32,320
And they control, like you remember the old days.

145
00:09:32,430 --> 00:09:33,380
I do remember the old days.

146
00:09:33,380 --> 00:09:34,000
You create a website.

147
00:09:34,240 --> 00:09:35,480
You're a webmaster of this website.

148
00:09:35,530 --> 00:09:36,580
You control this website.

149
00:09:36,700 --> 00:09:37,640
You own this website.

150
00:09:37,780 --> 00:09:42,400
You have 100% ownership of what happens on this website.

151
00:09:42,900 --> 00:09:43,640
Yes, it's very basic.

152
00:09:43,900 --> 00:09:44,640
It's rudimentary.

153
00:09:45,520 --> 00:09:51,560
But you own everything you put there and you own connections with people who come to your website, right?

154
00:09:52,060 --> 00:09:57,800
And now if you create a community on, you name it, Facebook, Discord, Twitter, whatever, right?

155
00:09:58,000 --> 00:09:59,100
You don't own this community.

156
00:09:59,660 --> 00:10:01,080
The platform does, right?

157
00:10:01,580 --> 00:10:03,820
You can do only what platform allows you to do.

158
00:10:04,120 --> 00:10:06,200
This platform can take it from you at any point.

159
00:10:06,540 --> 00:10:07,680
That's what we want to fix.

160
00:10:08,090 --> 00:10:10,980
We want to build a network when people own what they create,

161
00:10:11,220 --> 00:10:14,440
when people own connections with the users which they create,

162
00:10:14,780 --> 00:10:17,940
which gives them exactly the same utility they can get from Facebook

163
00:10:18,140 --> 00:10:20,280
or from Twitter or from Discord,

164
00:10:21,040 --> 00:10:25,700
but without surrendering ownership to content that they put there

165
00:10:26,040 --> 00:10:28,360
and without surrendering ownership of the connections

166
00:10:28,490 --> 00:10:30,260
with the users that they build.

167
00:10:30,380 --> 00:10:33,440
It's effectively, I've been saying to my supporters,

168
00:10:33,700 --> 00:10:38,000
investors from day one, like that we're not building a messenger, we're building the next web,

169
00:10:38,520 --> 00:10:44,640
the network that enables connections between people, the network that facilitates distribution

170
00:10:44,910 --> 00:10:51,800
of content and information in the same way as the web does, but accounting for evolved

171
00:10:52,120 --> 00:10:57,760
expectations and requirements, because we don't want to author HTML anymore. We don't want to just

172
00:10:57,940 --> 00:11:01,840
publish documents. We want to exchange messages. We want it to be much more interactive and instant,

173
00:11:02,040 --> 00:11:08,700
right? So you can think about it like new kind of instant web. Yeah, so okay, I'm getting it,

174
00:11:09,500 --> 00:11:15,960
but it's not very tangible to me and probably some people listening. So can you maybe just give

175
00:11:16,190 --> 00:11:22,340
a short example of what a day in the life might look like for me if, you know, looking 10 years

176
00:11:22,580 --> 00:11:29,840
ahead, if the SimpleX network is widely adopted, how does this look? I don't know. Honestly, I have

177
00:11:29,800 --> 00:11:32,100
I don't know what 10 years from now it will look like.

178
00:11:32,820 --> 00:11:39,240
The closest thing that you're describing to me is if I want to host a website on OnionShare.

179
00:11:39,390 --> 00:11:42,820
I open the OnionShare desktop app, I load all the HTML documents there,

180
00:11:43,300 --> 00:11:47,520
and then it's kind of going through, it's Onion-routed, it's decentralized,

181
00:11:48,280 --> 00:11:50,660
and then someone else via an OnionLink can access my website.

182
00:11:51,500 --> 00:11:56,420
But how is what you're doing different for that and definitely hopefully more streamlined than that?

183
00:11:57,000 --> 00:12:22,740
Correct. We don't want people to be technical to be able to build those communities. We want to provide people some composable primitives to construct the point of presence on the internet. We can call it site, right? So for example, your site can be just your channel, right? You publish your posts there daily or hourly or weekly and people can come and read them and people can come and comment there. So it's indistinguishable from your Twitter feed.

184
00:12:23,680 --> 00:12:30,400
And how would they access that? Is that accessed via the ClearNet or do they have to have something that utilizes like a SimpleX protocol?

185
00:12:30,840 --> 00:12:39,300
We're actually going to offer both. And when you say ClearNet, SimpleX, we're not sure what we call ClearNet, right?

186
00:12:39,730 --> 00:12:49,560
So yes, it will be something that utilizes SimpleX protocol, but we are going to offer option to the owners of the channel to make them viewable by the browser.

187
00:12:50,580 --> 00:12:55,980
So let's say if you created a channel and you wanted, like, because there are pros and cons, right?

188
00:12:56,070 --> 00:13:02,180
By making it viewable via the browser, you get more people access your content, but you don't know who they are.

189
00:13:02,290 --> 00:13:04,340
You don't have any feedback loop with them.

190
00:13:04,370 --> 00:13:05,160
They can't comment.

191
00:13:05,640 --> 00:13:08,000
So some channel owners may not want it, right?

192
00:13:08,100 --> 00:13:17,180
Some channels owners may want to only offer a preview of the channel and say that you have to join via this app to connect to this channel, right?

193
00:13:17,280 --> 00:13:25,140
So what we are saying is that ultimately the owner of the content or of the channel or of the community should make 100% of decisions.

194
00:13:25,740 --> 00:13:28,880
What is the user experience of people who come to this community?

195
00:13:29,260 --> 00:13:31,880
Do they want it to be just a stream of content?

196
00:13:32,340 --> 00:13:32,640
That's fine.

197
00:13:32,760 --> 00:13:33,300
That's really possible.

198
00:13:33,500 --> 00:13:36,420
Do they want it to be a group and people can participate and comment?

199
00:13:36,620 --> 00:13:37,320
That will be possible.

200
00:13:37,780 --> 00:13:44,200
Do they want it to look like multiple rooms when they can have multiple conversations, which may be interesting for large communities, right?

201
00:13:44,320 --> 00:13:49,440
If your community is over 100,000 members, then you probably don't want them all to talk in one room.

202
00:13:49,520 --> 00:13:57,080
You want to offer them some variety of ways they can consume information and engage with each other and with you.

203
00:13:57,860 --> 00:14:06,860
So what we will give people, you can think about it's like a modular constructor to put these elements together and make it look.

204
00:14:07,700 --> 00:14:10,900
I think the closest analogy you can think of is a Discord server.

205
00:14:11,300 --> 00:14:16,780
but with 10 times more flexibility about how the user experience will look like for people who come

206
00:14:16,900 --> 00:14:24,220
to you. Got it. And so that's if I look in many years ahead. Yeah, yeah, yeah. I assume so. And I

207
00:14:24,520 --> 00:14:28,500
definitely want to touch on, I guess, timelines for things and what the future looks like. But

208
00:14:29,100 --> 00:14:34,000
when it comes to the architecture, and then kind of the federated aspect of this, how does the whole

209
00:14:34,300 --> 00:14:41,020
relay server model actually work? I think I think federation is the wrong term here, because

210
00:14:41,040 --> 00:14:45,760
Federation is, by definition, is a unity of multiple networks, right?

211
00:14:45,920 --> 00:14:50,500
So to federate, you have to have multiple isolated networks that decided to connect with each other.

212
00:14:51,260 --> 00:14:58,620
And that happens if some owner of the server or some operator has multiple user accounts,

213
00:14:58,680 --> 00:15:02,420
and they can all talk to each other using this particular server, right?

214
00:15:03,000 --> 00:15:04,540
And the network is not federated yet.

215
00:15:05,060 --> 00:15:09,380
And to make this network federated, there will be some other operator with its own users,

216
00:15:10,140 --> 00:15:14,540
And then they can allow users of each other to talk to each other.

217
00:15:14,810 --> 00:15:15,780
And that's what we call federation.

218
00:15:17,220 --> 00:15:22,320
But each of the server owners, they own their own cluster of users and conversations.

219
00:15:22,690 --> 00:15:30,560
And they can decide to leave this federation or join this federation or to restrict federation with some operators.

220
00:15:30,670 --> 00:15:39,100
And we see how it leads to actually more censorship in federated platforms than in centralized platforms.

221
00:15:39,400 --> 00:15:45,980
If you compare the level of censorship in Mastodon, it's stronger than in some centralized platforms,

222
00:15:46,380 --> 00:15:52,920
exactly because censorship decisions of multiple operators of Mastodon multiply each other.

223
00:15:53,270 --> 00:16:00,280
So if I own the server, I can decide to censor my users, but I can also decide to censor users of another server,

224
00:16:00,790 --> 00:16:03,440
and I can also decide to censor the whole server if I want.

225
00:16:04,900 --> 00:16:11,480
So in a way, while the federated model kind of promised initially more freedom of speech,

226
00:16:12,900 --> 00:16:17,400
it de facto resulted in less freedom of speech than some centralized platforms.

227
00:16:17,720 --> 00:16:25,020
Just because moderation decisions, censorship decisions of different operators, they compound with each other, right?

228
00:16:25,060 --> 00:16:25,520
They add.

229
00:16:26,540 --> 00:16:31,400
Yeah, I guess it depends on the definition of freedom of speech because that can vary a lot.

230
00:16:31,720 --> 00:16:35,640
I know some people's view of freedom of speech is that it's just from the government.

231
00:16:36,070 --> 00:16:44,640
And so by their definition, actually, a Mastodon person deciding how they want their platform to be run is actually a perfect use of freedom of speech.

232
00:16:44,690 --> 00:16:50,920
But I can understand how to a user in terms of whatever they say, they don't know if it's going to be blocked by the platform or not.

233
00:16:51,120 --> 00:16:55,640
Federation gives them actually a little bit less control than some centralized platforms might.

234
00:16:56,980 --> 00:17:00,980
Exactly. So what we did is not federation by this definition.

235
00:17:01,320 --> 00:17:06,220
we see operators, server operators, as there are no user accounts, right?

236
00:17:06,250 --> 00:17:09,120
And the user is not attached to any particular server.

237
00:17:09,839 --> 00:17:12,780
From the point of view of the servers, users don't even exist.

238
00:17:14,220 --> 00:17:21,339
All servers know about is this small dump unidirectional pipes that transmit messages.

239
00:17:23,220 --> 00:17:26,760
It's user devices that know which pipes to use to reach their contacts,

240
00:17:26,829 --> 00:17:28,700
to reach their friends, and to reach their communities.

241
00:17:29,360 --> 00:17:32,080
And the user devices know how the network is organized.

242
00:17:33,200 --> 00:17:35,040
But server operators don't know any of that.

243
00:17:35,340 --> 00:17:37,080
They simply provide the messaging pipes.

244
00:17:39,100 --> 00:17:42,180
And currently, like if I talk to you on simplex,

245
00:17:42,480 --> 00:17:45,520
we'll have one messaging pipe, depending on one operator.

246
00:17:46,020 --> 00:17:50,660
And that obviously creates some problems with reliability,

247
00:17:51,380 --> 00:17:53,940
because if the server goes down, then we can't talk anymore,

248
00:17:54,560 --> 00:17:55,080
et cetera, et cetera.

249
00:17:55,180 --> 00:18:12,060
So we obviously plan that it will be, A, using multiple servers of different operators and also automatically rotating them to create reliability from any technical malfunctions or from some unreasonable censorship decisions.

250
00:18:12,370 --> 00:18:23,100
So I think it would be fair to say that the design we're moving towards from the very beginning would be closer to Nostra design, which is also not federation.

251
00:18:23,500 --> 00:18:26,580
So rather than choosing which server to publish a content on

252
00:18:27,120 --> 00:18:29,060
and then let servers design decide

253
00:18:29,720 --> 00:18:31,460
how the network should function, right?

254
00:18:31,820 --> 00:18:33,100
That's the federation approach.

255
00:18:33,600 --> 00:18:35,160
It's effectively the network of servers.

256
00:18:36,180 --> 00:18:37,240
Nostra takes another approach.

257
00:18:37,480 --> 00:18:39,660
You as a user decides which servers to use

258
00:18:39,670 --> 00:18:40,940
to publish a content to

259
00:18:41,320 --> 00:18:44,400
and the network is formed by the users, not by the servers.

260
00:18:46,260 --> 00:18:49,240
And the simplex has similar approach to network topology

261
00:18:49,420 --> 00:18:53,460
when it's users who decide how network is structured

262
00:18:53,940 --> 00:18:58,580
and not the servers and servers don't even know about how network is structured because all servers

263
00:18:58,900 --> 00:19:04,060
see is connections but they don't see the nodes of the network right they don't see how those

264
00:19:04,320 --> 00:19:11,100
connections organized are into the network and the users are free to rotate change operators use

265
00:19:11,280 --> 00:19:17,779
multiple operators at the same time so effectively we want network operators to be a disposable

266
00:19:17,800 --> 00:19:24,880
redundant portable commodity right that you bought you can buy off the network or there may be some

267
00:19:25,040 --> 00:19:31,780
free capacity allowance to you but you effectively buy it as network capacity rather than as a service

268
00:19:31,910 --> 00:19:36,280
from a particular company so you you don't necessarily choose one company like if you use

269
00:19:36,420 --> 00:19:40,160
email you have to choose a mail provider right if you use mastodon you have to choose your mastodon

270
00:19:40,380 --> 00:19:44,539
provider right if you use master you don't have to choose which master provider you use because you

271
00:19:44,520 --> 00:19:49,280
multiple and simplex has similar approach to the design you're not choosing which network provider

272
00:19:49,300 --> 00:19:55,460
to use because you you can choose the long list of them to use and use them all at the same time

273
00:19:55,560 --> 00:19:59,580
and some conversations will use one operator some other conversations will use other operators

274
00:20:00,340 --> 00:20:07,660
and the future will look like each conversation will use more than one operator concurrently in

275
00:20:07,780 --> 00:20:12,099
parallel to provide redundancy it's already using multiple operators today right so like because

276
00:20:12,260 --> 00:20:14,880
There is direct messages, response messages.

277
00:20:14,970 --> 00:20:17,220
They would use different servers of different operators already.

278
00:20:18,020 --> 00:20:20,800
But in the future, there will be redundancy and message pass.

279
00:20:20,920 --> 00:20:29,440
And every time you send the message, it will be sent via several channels to ensure that it reaches the destination, even if one operator has malfunction.

280
00:20:30,420 --> 00:20:30,980
Got it.

281
00:20:31,040 --> 00:20:38,340
And so to make this more tangible to especially myself, but I'm sure some people listening as well, can you maybe go through the different models?

282
00:20:38,440 --> 00:20:42,160
Because right now, you know, it's pretty confusing for people, especially if they're not more technical.

283
00:20:42,520 --> 00:20:45,820
Do I use Session? Do I use Signal? Do I use SimpleX?

284
00:20:46,920 --> 00:20:49,540
So can you kind of walk through very, very briefly?

285
00:20:49,680 --> 00:20:51,600
Like, we don't need to get super thorough into each one.

286
00:20:52,140 --> 00:20:54,940
But what does the model look like when someone registers for Signal?

287
00:20:55,660 --> 00:20:58,320
And how does that compare to Session? And how does that compare to you guys?

288
00:20:58,600 --> 00:21:00,360
What's actually going on behind the scenes?

289
00:21:00,860 --> 00:21:07,140
So, look, Signal has managed to build a fantastic product that everybody uses as inspiration.

290
00:21:08,020 --> 00:21:20,460
And they designed a cut-on-edge protocol algorithm for end-to-end encryption called also Signal, which people obviously confuse with Signal, the product, right?

291
00:21:22,040 --> 00:21:29,880
But the Signal protocol remains state-of-the-art in end-to-end encryption, provides some very important qualities, right?

292
00:21:29,890 --> 00:21:30,840
And we use it as well.

293
00:21:31,700 --> 00:21:33,060
We also use Signal algorithm.

294
00:21:33,560 --> 00:21:36,440
We have slightly different approach to post-quantum encryption.

295
00:21:36,780 --> 00:21:41,860
think what we do is a bit more secure than what Signal does, but Signal recently improved and

296
00:21:42,090 --> 00:21:49,120
caught up to a slightly better level. So when you go to Signal, you know what you do. You provide

297
00:21:49,120 --> 00:21:54,820
your phone number, right? And Signal verifies that you're the owner of this phone number,

298
00:21:55,260 --> 00:22:01,340
and they create a username for you, and that creates your account on Signal. And when somebody

299
00:22:01,540 --> 00:22:05,240
wants to connect to you, they have to go to Signal servers. They can't go anywhere else.

300
00:22:05,860 --> 00:22:16,260
And Signal would effectively see inevitably, because that's how a network functions, who connects to whom and how often messages are being sent.

301
00:22:16,400 --> 00:22:25,640
At some point, Signal introduced the interest in cryptographic scheme called sealed senders that was supposed to hide information about who it took to whom.

302
00:22:26,340 --> 00:22:28,900
But long story short, it doesn't work.

303
00:22:28,900 --> 00:22:33,320
I mean, it is not providing protection on all system layers.

304
00:22:33,720 --> 00:22:37,880
It only provides protection in a specific component, but not in the system as a whole.

305
00:22:38,400 --> 00:22:41,120
And it also is vulnerable to statistical analysis.

306
00:22:41,360 --> 00:22:45,900
So I would strongly, I can comment more on that if it's interesting to somebody.

307
00:22:46,240 --> 00:22:51,660
But generally speaking, we should consider that it's not something that really works or

308
00:22:51,880 --> 00:22:52,980
provide any meaningful protection.

309
00:22:53,100 --> 00:22:57,540
So fundamentally, Signal knows what's your phone number and knows who talks to whom.

310
00:22:57,960 --> 00:23:03,680
So while Signal provides very strong content privacy of your messages, Signal does not provide

311
00:23:03,700 --> 00:23:10,500
protection of your conduct from itself and from any parts that may get access to signal information.

312
00:23:11,000 --> 00:23:15,800
Just a quick note there before we move on to session. How come if a government, you know,

313
00:23:16,320 --> 00:23:19,520
asks signal for what they have, they only give two pieces of data?

314
00:23:19,740 --> 00:23:23,520
They might not hold on it. I don't quite understand was there a compliance requirement

315
00:23:23,540 --> 00:23:29,540
and for how long they are supposed to store this information. But if they diligently deletion this

316
00:23:29,520 --> 00:23:34,780
information if they're sticking to their privacy policy then they obviously would not be able to

317
00:23:34,940 --> 00:23:40,840
provide this information on request it doesn't mean that anybody who compromised signal can't

318
00:23:40,880 --> 00:23:45,940
access this information it doesn't mean that some malicious parts inside signal can't make a

319
00:23:46,200 --> 00:23:51,100
recording of this data we're talking about possible attack vector it's not about what actually happens

320
00:23:51,320 --> 00:23:56,340
so i i do strongly recommend people in many cases use signal we use signal as a fallback channel if

321
00:23:56,360 --> 00:24:02,140
something happens with our servers right so signal is objectively is one of the best products out

322
00:24:02,260 --> 00:24:08,140
there because of its like longevity because of how long it was developed because of how much money

323
00:24:08,140 --> 00:24:13,440
was spent on developing signal so i certainly do have very strong recommendation to use just but

324
00:24:13,510 --> 00:24:18,920
people have to be realistic if they if they do not want their communication provider know who

325
00:24:19,060 --> 00:24:23,279
they're talking to which may be very important for a large category of people for different reasons

326
00:24:23,420 --> 00:24:28,220
then they shouldn't use Signal, right? Or for example, if people do not want to be reached via

327
00:24:28,480 --> 00:24:34,240
Signal, because Signal allows to reach out to any user who you know the username of, right? Or the

328
00:24:34,360 --> 00:24:38,120
phone number of. And you know what spammers do, they just guess, right? You don't need to know,

329
00:24:38,150 --> 00:24:44,340
you just send messages to multiple numbers, some of them respond, and then you can build various

330
00:24:45,060 --> 00:24:50,140
scams or attacks or whatever, right? So simple accent comparison makes it an option. You can

331
00:24:50,160 --> 00:24:55,800
create an address, a public address that multiple people can connect to, but it's an option. It's

332
00:24:55,800 --> 00:24:59,480
not a requirement. You don't have to have such address. And even if you created such an address

333
00:24:59,880 --> 00:25:03,780
and suddenly you start to receive lots of spam via this address, you can just disable this address.

334
00:25:04,200 --> 00:25:07,660
You will not lose any of the contacts that you created via this address before.

335
00:25:08,740 --> 00:25:14,500
So in simplex network design, we see address that you created as first optional and second

336
00:25:14,860 --> 00:25:19,620
disposable. You can delete it without any consequences to already existing conversations.

337
00:25:20,500 --> 00:25:20,960
Very cool.

338
00:25:21,180 --> 00:25:25,520
With the signal, your address and your contacts, they're all intertwined.

339
00:25:25,550 --> 00:25:27,440
You can't delete your address, right?

340
00:25:27,540 --> 00:25:31,360
If your address became public, you may start receiving spam.

341
00:25:31,430 --> 00:25:36,300
There is nothing you can do other than changing this address, and that will undermine all

342
00:25:36,300 --> 00:25:37,120
your existing connections.

343
00:25:37,490 --> 00:25:41,820
So that's the problem with any design that requires users to have an address.

344
00:25:42,260 --> 00:25:43,120
And then what about session?

345
00:25:43,700 --> 00:25:48,160
Session started as a fork of Signal app, which was great.

346
00:25:49,080 --> 00:25:53,240
They made a copy of the code, it had signal protocol inside, and they removed the requirement

347
00:25:55,040 --> 00:26:00,320
to have a phone number to use Session, and the network of service was more decentralized,

348
00:26:00,860 --> 00:26:02,940
obviously, and that was a good start.

349
00:26:03,020 --> 00:26:10,340
But then later, around 2021 or 2022, I think, Session decided to remove signal protocol,

350
00:26:10,440 --> 00:26:10,600
right?

351
00:26:11,200 --> 00:26:16,040
And they are on a defensive since then about this decision, right?

352
00:26:16,200 --> 00:26:24,400
So I think it was a very big mistake to remove signal protocol without adapting it to the decentralized network design.

353
00:26:24,510 --> 00:26:25,960
The argument was that it's hard.

354
00:26:26,030 --> 00:26:26,900
Yes, it is hard.

355
00:26:27,280 --> 00:26:31,040
The hardest thing with signal protocol is not decentralization.

356
00:26:31,300 --> 00:26:32,820
It's multi-device, right?

357
00:26:33,120 --> 00:26:39,260
So because you have to make some decisions around how, and we still didn't solve this problem for multi-device on simplex network, right?

358
00:26:39,440 --> 00:26:45,340
So signal protocol obviously stands in the way of using the same user profile across multiple devices.

359
00:26:46,000 --> 00:26:51,280
Session's decision resulted not in just removing Signal protocol.

360
00:26:51,580 --> 00:26:57,400
Unfortunately, it became literally the least secure end-to-end encryption implementation across the board.

361
00:26:57,920 --> 00:27:04,260
There is literally no other messenger with end-to-end encryption that has recent end-to-end encryption than Session has.

362
00:27:05,740 --> 00:27:09,340
Many are happy people for me saying that, but that's just objective reality.

363
00:27:09,560 --> 00:27:11,920
It doesn't have forward secrecy. It doesn't have break-in recovery.

364
00:27:12,040 --> 00:27:14,440
It doesn't have any patent to this encryption.

365
00:27:14,640 --> 00:27:16,660
There is no key rotation at all.

366
00:27:17,280 --> 00:27:19,060
Messages are stored long-term,

367
00:27:19,620 --> 00:27:21,480
and the key used to encrypt these messages

368
00:27:21,710 --> 00:27:23,560
is easily accessible through the device.

369
00:27:24,500 --> 00:27:27,300
And also, unless you put a pin on your app,

370
00:27:27,620 --> 00:27:30,060
then the device can be easily,

371
00:27:30,100 --> 00:27:32,380
this encryption key can be easily accessed

372
00:27:32,410 --> 00:27:33,960
and cloned to another device,

373
00:27:34,070 --> 00:27:36,800
and whoever got temporary access to your device

374
00:27:37,020 --> 00:27:38,500
can, from this point forward,

375
00:27:38,690 --> 00:27:39,660
read your messages forever.

376
00:27:40,460 --> 00:27:41,400
We've been discussing that,

377
00:27:41,700 --> 00:27:46,140
And I don't know if they want to fix those problems or what's their plan.

378
00:27:46,920 --> 00:27:52,160
But I think at this point, saying to users that Session is secure is just gaslighting, unfortunately.

379
00:27:52,700 --> 00:27:56,600
It'd be interesting to get you all in a room to maybe discuss these different implementations.

380
00:27:56,600 --> 00:27:57,120
Yeah, I would be happy to.

381
00:27:57,130 --> 00:27:58,080
I actually offered that.

382
00:27:58,180 --> 00:27:58,920
I'd be happy.

383
00:27:59,140 --> 00:28:07,940
I know all the arguments that Session has against simplex design and the argument that simplex design is less decentralized than Session.

384
00:28:08,060 --> 00:28:09,720
It's an interesting comparison.

385
00:28:09,750 --> 00:28:11,140
And we can go into that.

386
00:28:11,420 --> 00:28:16,660
have something to say on that as well. But I think the big difference with our approach to

387
00:28:17,560 --> 00:28:25,000
problems that we have is not to hide the head in the sand and to remain in denial about these

388
00:28:25,200 --> 00:28:29,960
problems. We listen to what users say. We make objective assessments about whether we think it's

389
00:28:29,960 --> 00:28:34,400
a problem worth solving or we want to live with that. And we acknowledge that and we talk about

390
00:28:34,560 --> 00:28:41,380
that. And then at some point we may solve it. We recently evolved from the design that didn't

391
00:28:41,400 --> 00:28:46,820
protect user IP addresses from each other to the design that not only protects user IP addresses

392
00:28:46,910 --> 00:28:54,160
from each other, but that also prevents any of the network operator observing which IP address talks

393
00:28:54,170 --> 00:28:58,840
to which IP address. So that was a major change. It was a very complex change. We launched it with

394
00:28:58,910 --> 00:29:04,900
like zero breakages to connections or any kind of negative consequences to the users. So currently

395
00:29:05,280 --> 00:29:09,300
the design to have it both protects your IP address from your contacts.

396
00:29:09,790 --> 00:29:15,460
And also it prevents network operators from seeing which IP address talks to which IP address.

397
00:29:15,790 --> 00:29:20,020
So you like, they know which IP address is connected to their, so like, for example,

398
00:29:20,230 --> 00:29:25,100
one of the criticism that I don't know who invented this simple X servers can see users

399
00:29:25,220 --> 00:29:26,180
IP addresses, I guess.

400
00:29:26,490 --> 00:29:32,360
So can Tor relays and VPN providers, it literally doesn't matter how you use the network intranet,

401
00:29:32,500 --> 00:29:37,720
right? There will be some servers that will see your IP address. You can only choose which one

402
00:29:37,860 --> 00:29:42,360
will do it. So yes, if you connect to simple like servers directly without any overlay,

403
00:29:43,020 --> 00:29:47,840
like VPN or Tor or any other overlay network, then yes, the servers you connect to will see your

404
00:29:47,940 --> 00:29:52,800
IP address. That's true. But what's important that the servers will not be able to see which

405
00:29:52,920 --> 00:29:56,320
IP address connects to which IP address. Got it. And so what would you say is the

406
00:29:56,600 --> 00:30:02,460
limitation in your guys' approach compared to the other two options? I think the big limitation is

407
00:30:02,840 --> 00:30:07,520
obviously this this this this approach decentralization creates lots of technical

408
00:30:07,820 --> 00:30:13,760
complexities and that makes it harder to scale the network we're currently right in the middle

409
00:30:13,900 --> 00:30:19,540
of process of scaling this we did find a solution obviously how to scale it but i would say it's

410
00:30:19,960 --> 00:30:26,460
way more complex than using a traditional approach when user has an identity on the server and server

411
00:30:26,460 --> 00:30:33,380
knows who the user is, this traditional network technology is much simpler to develop the code for,

412
00:30:33,720 --> 00:30:41,040
I would say. And it also makes it much easier to scale. So I think it's harder on us, better for

413
00:30:41,180 --> 00:30:47,440
the end users. I think that was fundamentally the trade-off that we bought into, like that will do

414
00:30:47,640 --> 00:30:52,980
harder work to make better value for the end users. Got it. So before I touch on the encryption

415
00:30:53,000 --> 00:30:56,800
and security and kind of go into how you guys use the signal protocol and all this stuff.

416
00:30:57,260 --> 00:31:02,100
I had two notes as we were talking here, scaling and different ways to use SimpleX,

417
00:31:02,280 --> 00:31:07,500
because when I open SimpleX, I think I have the option to use just a regular, you know,

418
00:31:07,680 --> 00:31:08,680
default operator.

419
00:31:09,080 --> 00:31:11,360
Please correct any terminology on my end.

420
00:31:11,600 --> 00:31:13,760
You can self host something, I believe, as well.

421
00:31:13,940 --> 00:31:18,480
So if we can talk about scaling and then also the different ways to use SimpleX and kind

422
00:31:18,520 --> 00:31:19,520
of the trade-offs between them.

423
00:31:19,840 --> 00:31:24,100
I think it's not a very connected subject, but let's start from how it is.

424
00:31:24,430 --> 00:31:29,220
So currently, if you just use the app without making any advanced configurations,

425
00:31:30,080 --> 00:31:33,280
then you will be using two different companies as network operators.

426
00:31:33,430 --> 00:31:35,060
One of those companies will be us.

427
00:31:35,150 --> 00:31:36,200
We provide some servers.

428
00:31:36,960 --> 00:31:38,320
And another company will be Flux.

429
00:31:38,350 --> 00:31:39,520
They also provide some servers.

430
00:31:41,500 --> 00:31:43,900
We have the same privacy policy.

431
00:31:43,950 --> 00:31:46,180
We have an agreement between each other, obviously,

432
00:31:46,500 --> 00:31:51,580
which obliges them to adhere to the same privacy policy as we do.

433
00:31:52,320 --> 00:31:58,020
And when users agree to conditions of use, they agree with both of us.

434
00:31:58,050 --> 00:32:02,320
And that provides more privacy than if there was just one operator.

435
00:32:03,820 --> 00:32:08,820
This is objectively worse than having 100 different known,

436
00:32:09,180 --> 00:32:13,760
10 different known operators who commit to the same terms.

437
00:32:13,980 --> 00:32:17,360
And that's the model of the network we work towards

438
00:32:18,280 --> 00:32:22,660
is when we build the commercial model into the network

439
00:32:22,880 --> 00:32:25,880
that will incentivize operators to offer their servers.

440
00:32:27,120 --> 00:32:31,000
And by incentivize, I don't mean maintain some shit coins.

441
00:32:31,340 --> 00:32:34,840
No, I mean like community owners funding their channels

442
00:32:35,040 --> 00:32:36,300
in the same way they fund websites

443
00:32:36,560 --> 00:32:38,100
and that provides revenues to operators.

444
00:32:38,380 --> 00:32:41,860
So we don't want to skew the balance, right?

445
00:32:42,060 --> 00:32:45,040
So that's something that we're working towards right now.

446
00:32:45,110 --> 00:32:46,880
So there will be some big announcements.

447
00:32:47,600 --> 00:32:49,480
So effectively, we want to be in a world

448
00:32:49,700 --> 00:32:51,920
when without any advanced app configuration,

449
00:32:52,800 --> 00:32:55,380
by default, you're using tens or even hundreds

450
00:32:55,550 --> 00:32:57,600
of different known companies

451
00:32:58,910 --> 00:33:01,060
who contractually obliged to stick

452
00:33:01,070 --> 00:33:02,360
to the same privacy policy.

453
00:33:02,700 --> 00:33:03,240
That's the future.

454
00:33:03,660 --> 00:33:04,360
We're not there yet, right?

455
00:33:04,460 --> 00:33:06,140
We currently offer only two companies

456
00:33:06,900 --> 00:33:08,660
and we're in conversation to add a third,

457
00:33:09,360 --> 00:33:10,720
which may happen rather soon.

458
00:33:10,860 --> 00:33:15,860
But that's, again, that's objectively worse than having 10 or 100.

459
00:33:16,800 --> 00:33:20,900
Now, if you compare it with network designs like Tor or Session,

460
00:33:21,520 --> 00:33:26,180
on one hand, you have hundreds of nodes there, right?

461
00:33:26,980 --> 00:33:31,600
And traditional view is that this is the better model of decentralization.

462
00:33:31,890 --> 00:33:34,420
The problem is that you don't know who runs nodes,

463
00:33:35,220 --> 00:33:37,540
and your whole security model is based on the assumption

464
00:33:37,650 --> 00:33:40,000
that these nodes are run by different parties, right?

465
00:33:40,160 --> 00:33:40,780
But you don't know that.

466
00:33:41,640 --> 00:33:44,420
And second, they don't have any contractual obligations to you.

467
00:33:44,720 --> 00:33:46,940
They don't promise you any privacy terms.

468
00:33:47,010 --> 00:33:48,900
They don't promise you anything at all.

469
00:33:49,280 --> 00:33:49,380
Absolutely.

470
00:33:49,900 --> 00:33:50,980
They can log IP addresses.

471
00:33:51,110 --> 00:33:51,760
They can log them.

472
00:33:51,830 --> 00:33:53,080
They can do whatever they want, right?

473
00:33:53,440 --> 00:34:01,720
So all the networks with anonymous operators in comparison to what we did has the downside,

474
00:34:01,930 --> 00:34:02,040
right?

475
00:34:02,070 --> 00:34:08,560
So multiple nodes can be run by the same party and multiple nodes can cooperate and share

476
00:34:08,580 --> 00:34:12,540
data in order to determine and effectively de-anonymize user connections.

477
00:34:13,340 --> 00:34:14,360
They wouldn't violate anything.

478
00:34:14,540 --> 00:34:17,040
They would violate the spirit of the network, no doubt about that.

479
00:34:17,600 --> 00:34:21,960
But since when it stopped people who are commercially motivated, right?

480
00:34:22,100 --> 00:34:27,560
So like if there is a demand for Tor traffic data and there is demand for Tor traffic data,

481
00:34:27,580 --> 00:34:31,480
there are suppliers of Tor traffic data or session traffic data, there is demand for that,

482
00:34:31,639 --> 00:34:32,700
then there will be supply, right?

483
00:34:32,899 --> 00:34:36,139
Like some operator nodes will be selling their traffic data for aggregation.

484
00:34:36,280 --> 00:34:38,540
That effectively undermines the model.

485
00:34:38,760 --> 00:34:44,200
And the argument is that a small share of nodes will be owned by malicious parties.

486
00:34:44,399 --> 00:34:44,960
Yes, that's true.

487
00:34:45,240 --> 00:34:51,679
But statistically, if you choose the nodes randomly, we published this calculation somewhere.

488
00:34:51,760 --> 00:34:56,879
So let's say even if 2-3% of nodes in a large decentralized network are controlled by one party,

489
00:34:57,220 --> 00:34:59,340
this party can't subvert the whole network.

490
00:34:59,840 --> 00:35:05,520
So when people think about Sibyl attack, Sibyl attack is not possible unless there is a huge number of.

491
00:35:05,680 --> 00:35:07,440
But the problem is we're not talking about civil attack.

492
00:35:07,640 --> 00:35:10,900
We're talking about determining who talks to whom through the network.

493
00:35:11,620 --> 00:35:13,920
Because the purpose of Tor network or session network

494
00:35:14,380 --> 00:35:15,660
is to hide this information, right?

495
00:35:15,800 --> 00:35:18,020
Because people don't connect to each other.

496
00:35:18,120 --> 00:35:19,660
They connect through intermediaries.

497
00:35:20,280 --> 00:35:23,200
And the purpose of the network is to protect those connections.

498
00:35:24,560 --> 00:35:27,580
But even if a small number of nodes are run by the same party,

499
00:35:27,980 --> 00:35:29,680
then this guarantee no longer holds.

500
00:35:30,200 --> 00:35:32,380
Like after many random choices,

501
00:35:32,580 --> 00:35:37,920
you will be hitting multiple nodes controlled by the same party eventually, right?

502
00:35:38,080 --> 00:35:40,720
Just because you choose them randomly, statistical occasion is this.

503
00:35:40,730 --> 00:35:45,820
If you have 2% of nodes controlled by one party, you have to make something like 700,

504
00:35:46,620 --> 00:35:52,000
1,700 random choices to hit nodes of the same attack, which is not too many choices, right?

505
00:35:52,260 --> 00:35:58,100
Like you use the app for, say, half a year, and eventually you'll be hitting problematic

506
00:35:58,620 --> 00:35:59,220
connection paths.

507
00:35:59,760 --> 00:36:01,100
So again, that's answering the question

508
00:36:01,160 --> 00:36:03,000
of how people use on decentralization model

509
00:36:03,140 --> 00:36:04,200
and what's the alternative, right?

510
00:36:04,420 --> 00:36:08,120
So many people use the app by their own servers, right?

511
00:36:08,140 --> 00:36:12,840
So we know about lots of like work groups or teams

512
00:36:13,140 --> 00:36:14,520
that run their own simplex servers

513
00:36:15,680 --> 00:36:18,920
and use their servers to connect to each other.

514
00:36:19,360 --> 00:36:21,380
The great thing about the design of the deal

515
00:36:21,380 --> 00:36:23,600
is that users decide which service to use.

516
00:36:23,700 --> 00:36:26,060
Like when you use Tor, it's hard to make those decisions.

517
00:36:26,180 --> 00:36:27,400
When you use Session, it's impossible

518
00:36:27,440 --> 00:36:28,500
to make those decisions, right?

519
00:36:28,680 --> 00:36:29,760
like the app decides for you.

520
00:36:30,340 --> 00:36:32,360
We give this control to the users, 100%.

521
00:36:32,450 --> 00:36:34,040
So users can configure the app,

522
00:36:34,700 --> 00:36:36,920
which operators to use and how to use them.

523
00:36:37,560 --> 00:36:39,260
And they can be their own servers.

524
00:36:39,700 --> 00:36:40,920
So users can, for example,

525
00:36:41,320 --> 00:36:44,680
use our servers to store messages in delivery

526
00:36:45,180 --> 00:36:47,540
and then use some low reliability servers

527
00:36:47,760 --> 00:36:50,100
as a proxy for connections or vice versa.

528
00:36:50,300 --> 00:36:52,740
They can use their own servers for delivery

529
00:36:53,140 --> 00:36:54,580
and our servers as proxies.

530
00:36:54,740 --> 00:36:56,400
And we've heard about all those combinations.

531
00:36:56,720 --> 00:37:04,080
So we give people configuration about which servers to use and how to use them in which role on the network.

532
00:37:04,860 --> 00:37:13,900
What we don't yet is we don't have currently the same level of configuration for custom servers as we have for preset operators.

533
00:37:14,180 --> 00:37:14,940
That's coming very soon.

534
00:37:14,950 --> 00:37:20,920
But nevertheless, lots of users use their own servers in combination with servers that are pre-configured in the app.

535
00:37:21,300 --> 00:37:21,740
I see.

536
00:37:22,060 --> 00:37:26,640
And I always forget to ask these questions early on because for me, it's just obvious.

537
00:37:27,060 --> 00:37:29,340
But, you know, everything you guys do is open source, right?

538
00:37:30,200 --> 00:37:31,040
A hundred percent, yes.

539
00:37:31,120 --> 00:37:31,620
Yeah, okay.

540
00:37:34,040 --> 00:37:40,440
No, look, I have been doing open source for a very long time, you know, and I think it gives you much higher quality.

541
00:37:41,100 --> 00:37:48,360
It gives you much, like I was saying many years ago, long before we had ChatGPT4 or Grog4,

542
00:37:48,840 --> 00:37:53,000
that there will be very little benefit of having closed source code

543
00:37:53,060 --> 00:37:58,220
because we're moving to the world when advanced LLM can take your binary code

544
00:37:58,640 --> 00:38:02,560
and literally reverse engineer it and write it.

545
00:38:02,580 --> 00:38:07,980
So by hiding your source code, you're only protecting it from small players

546
00:38:08,380 --> 00:38:11,880
who don't have large LLMs, and you're not protecting it from large players

547
00:38:11,920 --> 00:38:13,480
who have large LLMs at all.

548
00:38:14,140 --> 00:38:15,700
So there is very little benefit.

549
00:38:15,960 --> 00:38:17,560
So licensing works, right?

550
00:38:17,740 --> 00:38:19,340
So like if you license your code under,

551
00:38:19,680 --> 00:38:22,040
like for example, we license under AGPL V3,

552
00:38:22,420 --> 00:38:23,460
which allows people to use it,

553
00:38:23,460 --> 00:38:25,300
but it imposes the requirement on them

554
00:38:26,200 --> 00:38:28,920
to make code available to their users

555
00:38:29,040 --> 00:38:29,980
if they modify it,

556
00:38:30,900 --> 00:38:32,020
which provides both security

557
00:38:32,360 --> 00:38:36,140
and also protection from any kind of changes

558
00:38:36,340 --> 00:38:37,340
that users wouldn't know about.

559
00:38:37,860 --> 00:38:42,220
So yeah, so it's both the app code

560
00:38:42,380 --> 00:38:43,460
and mobile apps code

561
00:38:43,680 --> 00:38:45,460
and core of the app

562
00:38:45,660 --> 00:38:47,260
that does cryptography and messaging.

563
00:38:47,280 --> 00:38:49,320
and service code.

564
00:38:49,740 --> 00:38:51,160
And we had quite a few situations

565
00:38:51,280 --> 00:38:53,980
when users were pointing a box in those code

566
00:38:54,140 --> 00:38:54,620
before the release,

567
00:38:54,840 --> 00:38:59,160
and we had quite a few important contributions to it.

568
00:38:59,160 --> 00:39:01,140
And I think literally 100% of people

569
00:39:01,280 --> 00:39:04,480
who are in the team were contributors

570
00:39:04,680 --> 00:39:05,980
who literally found the project,

571
00:39:06,260 --> 00:39:07,640
liked the project, did some contribution,

572
00:39:08,000 --> 00:39:09,160
then did some other contribution,

573
00:39:09,380 --> 00:39:10,240
then they said, like,

574
00:39:10,320 --> 00:39:12,240
why are you not working with us 100% of time yet?

575
00:39:13,160 --> 00:39:14,540
So I think I see only upsides.

576
00:39:14,540 --> 00:39:17,180
I don't see any downsides to the code.

577
00:39:17,280 --> 00:39:25,340
The whole idea that if you don't close your code, you can't make a commercially viable business is just wrong.

578
00:39:26,180 --> 00:39:31,120
It just means that you have to figure out a commercial model that's not based on the idea of hiding your code.

579
00:39:31,280 --> 00:39:37,100
And your competitive advantages should be not based on hiding your code, but should be based on something else.

580
00:39:37,620 --> 00:39:39,280
But we want the competition to exist.

581
00:39:39,280 --> 00:39:46,200
We are competing with such big networks that we absolutely cannot compete if they are the only developers.

582
00:39:46,420 --> 00:39:53,060
So we literally are moving to the point when developing alternative apps will be easier.

583
00:39:53,360 --> 00:39:55,200
Because again, obviously, we move very fast, right?

584
00:39:55,200 --> 00:39:58,700
The protocol documentation a bit lags, and it's really hard.

585
00:39:58,720 --> 00:40:02,060
So we didn't do what Matrix did, for example, from the very beginning.

586
00:40:02,860 --> 00:40:06,520
When Matrix development started, it started from a point, okay, let's make a protocol.

587
00:40:06,700 --> 00:40:07,320
Let's make it public.

588
00:40:07,600 --> 00:40:11,840
Let's create a committee that decides on the protocol evolution, right?

589
00:40:12,100 --> 00:40:14,680
And let's multiple people build multiple apps.

590
00:40:15,920 --> 00:40:18,480
In a spirit of open source and transparency, et cetera, et cetera.

591
00:40:18,960 --> 00:40:20,580
The problem is it's a dead end, right?

592
00:40:21,720 --> 00:40:25,920
Because you get products to some early adoption this way, right?

593
00:40:26,060 --> 00:40:27,740
You may even get faster early adoption

594
00:40:29,020 --> 00:40:31,820
because multiple developers develop, promote, et cetera, et cetera.

595
00:40:31,920 --> 00:40:34,200
But then you realize you need some fundamental protocol changes.

596
00:40:35,660 --> 00:40:37,900
And you have, let's say, three or four different apps.

597
00:40:38,560 --> 00:40:39,940
You now need to agree those changes.

598
00:40:41,060 --> 00:40:42,340
It's almost impossible.

599
00:40:42,860 --> 00:40:50,360
And the whole conversation about how we evolve it from the one to the two, and then from the two to the three of the protocol becomes really, really, really hard.

600
00:40:50,860 --> 00:40:58,200
So we kind of want to do what happened with the web more like when, you know, when there was a moment in the web, in the history of the web, right?

601
00:40:58,720 --> 00:41:06,160
Before the 2000s, there were like 30 odd competing browsers, more than 30 startups that were competing with Netscape at the time.

602
00:41:06,200 --> 00:41:07,440
Nobody knows their names, right?

603
00:41:07,940 --> 00:41:09,300
So Netscape took it upon themselves.

604
00:41:09,420 --> 00:41:10,820
They said, all right, we have a web protocol.

605
00:41:11,020 --> 00:41:11,300
That's great.

606
00:41:11,560 --> 00:41:14,520
It's not suitable for a widely used product.

607
00:41:15,140 --> 00:41:15,780
Let's evolve it.

608
00:41:16,620 --> 00:41:21,040
Netscape single-handedly added SSL, which is transport encryption, right?

609
00:41:21,220 --> 00:41:21,760
TLS now.

610
00:41:23,400 --> 00:41:24,400
Then they added cookies.

611
00:41:24,640 --> 00:41:28,700
People think cookie is a bad thing, but cookie is abused to be a bad thing.

612
00:41:28,800 --> 00:41:30,820
But without cookie, a website can't function, right?

613
00:41:30,900 --> 00:41:34,440
The fact that you can log into Facebook depends on cookies, right?

614
00:41:35,040 --> 00:41:35,940
It wouldn't be possible.

615
00:41:36,200 --> 00:41:39,120
Anybody would be able to log into your account, right, if there were no cookies, right?

616
00:41:39,300 --> 00:41:41,560
The cookie allows Facebook to recognize you.

617
00:41:42,140 --> 00:41:43,220
And then they edit JavaScript, right?

618
00:41:43,260 --> 00:41:47,980
So fundamentally, Netscape in a matter of a couple of years and many millions of dollars

619
00:41:49,060 --> 00:41:53,900
and losing completely compatibility with the rest of the browser, they created a new product

620
00:41:54,280 --> 00:41:57,200
based on the web, and it became a mass market product because of that.

621
00:41:57,400 --> 00:42:03,220
So we see currently the protocol we have, Mastodon has, Magix has, is kind of version

622
00:42:03,440 --> 00:42:04,140
one, right?

623
00:42:04,200 --> 00:42:09,260
It has to evolve quite rapidly to version three with much more funds and with much more

624
00:42:09,280 --> 00:42:14,420
but with an absolutely ruthless focus on doing what users need

625
00:42:14,760 --> 00:42:19,580
and not trying to have competition across development teams.

626
00:42:20,000 --> 00:42:23,240
Yeah, so on that note, you know, let's talk a little bit about the encryption

627
00:42:23,500 --> 00:42:25,460
that you guys use and the security model.

628
00:42:25,900 --> 00:42:27,400
I want to start by Signal.

629
00:42:27,530 --> 00:42:29,300
So why did you guys pick the Signal protocol?

630
00:42:29,880 --> 00:42:31,760
And are there any modifications that you make to it?

631
00:42:31,840 --> 00:42:33,440
You know, I think we've been super lucky.

632
00:42:33,960 --> 00:42:36,940
When we designed the Signal, it's like it's almost an anecdote.

633
00:42:37,180 --> 00:42:44,680
I'll tell you that when we designed the network design, it was before it was widely used.

634
00:42:44,700 --> 00:42:48,100
We just developed some early stage prototype of conversations.

635
00:42:48,820 --> 00:42:49,540
And there was circle.

636
00:42:49,700 --> 00:42:50,760
It was all in terminal.

637
00:42:50,840 --> 00:42:52,560
There was no user interface, et cetera, et cetera.

638
00:42:52,760 --> 00:42:55,620
And then I asked Mozilla.

639
00:42:55,700 --> 00:43:01,080
Mozilla gave me a grant to my previous open source project library for the day.

640
00:43:01,180 --> 00:43:03,260
It's a very successful library, by the way.

641
00:43:03,700 --> 00:43:08,980
So I just asked them, can they maybe recommend me someone to look at what I did?

642
00:43:09,070 --> 00:43:11,040
Because I don't understand cryptography much.

643
00:43:11,090 --> 00:43:11,500
I don't.

644
00:43:11,680 --> 00:43:13,080
It was like early 2022.

645
00:43:13,770 --> 00:43:17,020
And they gave me somebody who eventually became our advisor on protocols.

646
00:43:18,060 --> 00:43:21,360
He looked at it and he said, I don't want to help you.

647
00:43:22,600 --> 00:43:23,120
I said, why?

648
00:43:23,600 --> 00:43:27,440
He was very like, he was very reticent to give me any feedback.

649
00:43:28,320 --> 00:43:30,300
I said, look, man, I have a tough skin.

650
00:43:30,300 --> 00:43:31,360
You can tell me how it is.

651
00:43:31,360 --> 00:43:32,420
I don't need nice words.

652
00:43:32,520 --> 00:43:34,920
I just need you to tell me what it is and maybe we can make it better.

653
00:43:35,600 --> 00:43:39,040
So he said, all right, what you've done is a complete shit.

654
00:43:41,020 --> 00:43:43,580
You have a good seed of the idea there, which is message routing.

655
00:43:43,880 --> 00:43:47,560
You invented a fantastic message routing protocol like nothing I've seen before

656
00:43:48,120 --> 00:43:51,160
and your cryptography is a complete shit and nobody does it like that anymore.

657
00:43:53,220 --> 00:43:54,320
That was early 2021.

658
00:43:57,200 --> 00:43:57,400
Right.

659
00:43:58,240 --> 00:43:59,420
I said, all right, how everybody does it?

660
00:43:59,560 --> 00:44:00,380
So everybody uses Signal.

661
00:44:00,720 --> 00:44:04,140
Signal a state of art, Android encryption, just use signal and stop inventing shit.

662
00:44:05,200 --> 00:44:06,560
Don't invent stuff you know nothing about.

663
00:44:09,360 --> 00:44:13,840
And then he said, and also he pointed out some other possible attack vectors and everything.

664
00:44:14,030 --> 00:44:16,720
And he eventually became our advisor.

665
00:44:18,320 --> 00:44:23,220
So I think what he was surprised is that we actually did all that he suggested.

666
00:44:23,480 --> 00:44:27,940
We switched to signal protocol in a matter of less than two months.

667
00:44:28,380 --> 00:44:30,820
and we fixed all the vulnerabilities.

668
00:44:30,930 --> 00:44:34,160
So when we released SimpleX Protocols version one,

669
00:44:34,530 --> 00:44:39,080
it was a complete full rewrite of the whole,

670
00:44:39,380 --> 00:44:43,360
like it retained the engine for message passing

671
00:44:43,660 --> 00:44:45,200
and it retained some semantics,

672
00:44:45,310 --> 00:44:49,440
but fundamentally we changed more than we kept

673
00:44:49,820 --> 00:44:52,620
in the core of the network design, addressing everything.

674
00:44:52,940 --> 00:44:53,540
And that's why Signal,

675
00:44:53,740 --> 00:44:57,480
simply because it provides three very important qualities

676
00:44:57,500 --> 00:44:59,300
for what is end-to-end encryption.

677
00:45:00,190 --> 00:45:02,000
So one is forward secrecy.

678
00:45:03,000 --> 00:45:04,240
What forward secrecy is?

679
00:45:04,320 --> 00:45:06,680
It means that if somebody somehow manages

680
00:45:06,870 --> 00:45:09,000
to crack encryption of a single message,

681
00:45:10,180 --> 00:45:11,240
maybe via brute force,

682
00:45:12,200 --> 00:45:14,720
or maybe they obtained the state of your design

683
00:45:14,790 --> 00:45:16,340
from some date and they have the key

684
00:45:16,340 --> 00:45:18,180
that was used to encrypt this particular message,

685
00:45:18,820 --> 00:45:21,740
it wouldn't allow them to decrypt past messages.

686
00:45:22,180 --> 00:45:24,380
I find this terminology very counterintuitive

687
00:45:24,450 --> 00:45:25,120
for the wrong people

688
00:45:25,230 --> 00:45:27,120
because when we talk about forward secrecy,

689
00:45:27,320 --> 00:45:31,960
actually talking about the security of past messages from the future compromises. Maybe

690
00:45:32,100 --> 00:45:37,980
that's why it's forward secrecy, but it's about security of your past, right? From future attacks.

691
00:45:38,200 --> 00:45:41,860
That's what forward secrecy is. And forward secrecy is very widely used. Like every modern

692
00:45:42,160 --> 00:45:46,100
browser uses forward secrecy. So literally every single person on the planet, one way or another,

693
00:45:46,720 --> 00:45:51,700
uses forward secrecy. And it's like a staples of encryption. So forward secrecy is exceptionally

694
00:45:52,040 --> 00:45:56,200
important because otherwise your whole correspondence, your whole history of messages

695
00:45:56,220 --> 00:45:58,740
becomes compromised from a compromise of a single message.

696
00:45:59,480 --> 00:46:00,580
But Signal doesn't stop there.

697
00:46:01,020 --> 00:46:03,860
Signal invented a different attack vector.

698
00:46:03,860 --> 00:46:06,640
He said, all right, because very common attack is a break-in, right?

699
00:46:06,960 --> 00:46:10,320
When attacker gets temporary access to your device.

700
00:46:10,600 --> 00:46:14,520
Break-in attacks are easier than compromising your device permanently

701
00:46:14,620 --> 00:46:16,040
because to compromise your device permanently,

702
00:46:16,160 --> 00:46:17,860
you have to install some software in it,

703
00:46:18,000 --> 00:46:20,920
and there may be some protection from installing software, etc., etc., right?

704
00:46:20,960 --> 00:46:24,440
So, although, and then there may be some network connectivity issues.

705
00:46:25,080 --> 00:46:38,880
And what Signal Protocol does is regularly rotate encryption keys in such a way that if your device was compromised, then your future messages will become protected after some time.

706
00:46:39,260 --> 00:46:44,380
And this quality is called post-compromised security or break and recovery.

707
00:46:44,600 --> 00:46:48,960
I prefer the term break and recovery because it's a process, right?

708
00:46:49,100 --> 00:46:54,420
It's something that protocol proactively does in order to recover the security after the compromise.

709
00:46:55,360 --> 00:46:58,000
and after the specific type of the compromise, which is break-in.

710
00:46:58,160 --> 00:47:01,240
Because obviously, for example, I've heard the argument from many people

711
00:47:01,440 --> 00:47:06,260
that we don't care about protection from long-term key compromise

712
00:47:06,540 --> 00:47:09,580
because if your long-term key compromise, everything is compromised.

713
00:47:09,880 --> 00:47:13,960
But this assumes that attacker retains access to a compromised device,

714
00:47:14,380 --> 00:47:16,020
which is a harder attack, right?

715
00:47:16,180 --> 00:47:18,900
And there is a separate class of attack called break-in for a reason

716
00:47:19,120 --> 00:47:24,100
because in many cases break-ins are easier to execute than terminal compromise.

717
00:47:24,160 --> 00:47:29,540
right so so like this post-compromised security of signal and breaking recovery in signal protects

718
00:47:29,980 --> 00:47:35,500
uh recovers the security after compromise happened and that's actually exactly why

719
00:47:36,500 --> 00:47:41,760
running multiple devices hard with signal because if you even if you make a copy of your database

720
00:47:42,380 --> 00:47:46,780
from the point of view of encryption algorithm it's a compromise right and if you try to run

721
00:47:46,820 --> 00:47:53,080
this copy in parallel on another device one of them will stop working because it will be seen as a

722
00:47:53,080 --> 00:47:58,360
compromised copy. There are solutions, right? For example, SignalUp has a very elegant and simple

723
00:47:58,600 --> 00:48:02,780
solution with its own downsides, but it works literally making every conversation a group,

724
00:48:03,240 --> 00:48:08,780
right? When you connect with somebody, then each of your devices affects a separate participant in

725
00:48:08,900 --> 00:48:15,780
this group. And there is break and recovery between devices, but they all kind of send messages to all

726
00:48:16,060 --> 00:48:19,440
participants in a small group. So like you say, we have three devices, I have two devices,

727
00:48:20,060 --> 00:48:24,180
We will have like five participants in this small group that from the user

728
00:48:24,400 --> 00:48:27,580
experience will look like their conversation, but from the protocol design

729
00:48:27,800 --> 00:48:28,440
point of view, it's a group.

730
00:48:28,570 --> 00:48:29,340
So that's what signals are.

731
00:48:29,540 --> 00:48:30,920
That's what probably we will do as well.

732
00:48:31,340 --> 00:48:35,280
The downsides of this approach, obviously, is that you can see which device was

733
00:48:35,400 --> 00:48:36,320
used to send the message.

734
00:48:36,760 --> 00:48:38,020
There are various attack on this.

735
00:48:38,160 --> 00:48:39,000
So there are some downsides.

736
00:48:39,350 --> 00:48:39,500
Okay.

737
00:48:40,040 --> 00:48:45,160
So, and the third thing about a signal also very important called the non-repudiation.

738
00:48:45,580 --> 00:48:46,580
Sorry, repudiation.

739
00:48:47,000 --> 00:48:49,720
Non-repudiation is ability to prove who sent the message.

740
00:48:50,180 --> 00:48:52,860
And repudiation is lack of such ability,

741
00:48:53,340 --> 00:48:56,560
which means that if you send me a message on my device,

742
00:48:57,130 --> 00:49:00,720
then I cannot prove to a third party that this message came from you.

743
00:49:01,010 --> 00:49:03,560
I can prove it to myself, but I can prove it to myself

744
00:49:03,830 --> 00:49:05,660
only because I know that I didn't send the message.

745
00:49:06,060 --> 00:49:09,740
But I have the same encryption key, and I could have encrypted that as well.

746
00:49:10,000 --> 00:49:13,340
So I do not have a cryptographic proof to another party

747
00:49:14,180 --> 00:49:15,440
that you have sent the message.

748
00:49:15,660 --> 00:49:18,540
And I technically can fake messages on my device.

749
00:49:19,100 --> 00:49:25,300
So I can construct a proof that the look on my device as if you sent the message.

750
00:49:26,100 --> 00:49:31,740
And it will be indistinguishable from if you, in fact, did send the message, right?

751
00:49:32,080 --> 00:49:33,760
If you didn't send the message, you can deny it.

752
00:49:33,760 --> 00:49:35,280
And I can't prove it cryptographically.

753
00:49:35,760 --> 00:49:38,340
Now, many people say, okay, this is not an important call.

754
00:49:38,400 --> 00:49:41,280
Let's say this was never successfully used in court.

755
00:49:41,600 --> 00:49:42,740
This defense was never tried.

756
00:49:43,300 --> 00:49:44,280
I find this all mode point.

757
00:49:44,380 --> 00:49:48,680
The whole kind of concept of deniability was invented less than 20 years ago, right?

758
00:49:48,690 --> 00:49:54,900
If you look like off-the-record messaging, this whole concept was published as a paper before 2010.

759
00:49:55,460 --> 00:50:00,100
Signal was the first messaging application that adopted this approach in Signal protocol.

760
00:50:01,040 --> 00:50:04,520
And it wasn't even mass market up until when?

761
00:50:05,390 --> 00:50:05,520
2020?

762
00:50:06,260 --> 00:50:07,540
Probably 2017.

763
00:50:08,090 --> 00:50:12,940
Even now, Signal is used by maybe less than 2% of the population, right?

764
00:50:13,120 --> 00:50:19,380
So the fact that it was never successfully used in court is irrelevant because court precedence

765
00:50:19,550 --> 00:50:22,400
sometimes takes many decades to evolve, right?

766
00:50:23,100 --> 00:50:26,060
But the problem is, if you're a high-profile person, right?

767
00:50:26,080 --> 00:50:29,260
Imagine you're a CEO of a large company that runs multi-billion contracts.

768
00:50:30,060 --> 00:50:33,900
So somebody will try to abuse the communication with you.

769
00:50:34,040 --> 00:50:38,380
Somebody will be trying to fake messages with you.

770
00:50:38,620 --> 00:50:45,720
or somebody can use the messages you sent on confidence against you or fake messages against

771
00:50:45,740 --> 00:50:51,740
you. So the liability provides an interesting defense line in the court of law. I think it

772
00:50:51,740 --> 00:50:57,520
should be used by some people sooner or later, right? Because if you, in fact, didn't send the

773
00:50:57,660 --> 00:51:02,340
message, then the other party will not be able to prove it. Today, the common practice today is that

774
00:51:02,420 --> 00:51:06,720
people accept screenshots, people accept device copers, people don't go into high profile

775
00:51:06,740 --> 00:51:12,600
expertise to establish if deniability is important quality or not. Technology usually is many decades

776
00:51:12,840 --> 00:51:17,780
ahead of law and legal precedents. I see deniability as an important concept, right?

777
00:51:18,020 --> 00:51:22,920
SimpleX network provides full-stack deniability, so both on server levels and on client level.

778
00:51:23,290 --> 00:51:28,220
And I think that there will be some profile cases when this defense will be successfully used.

779
00:51:29,220 --> 00:51:35,200
Yeah, maybe it'll be some of the people in security positions in the US administration.

780
00:51:35,640 --> 00:51:43,100
For example, for example, a journalist claims to be in a group with all of them, they could say, well, exactly.

781
00:51:43,430 --> 00:51:44,320
We never sent those messages.

782
00:51:44,560 --> 00:51:44,940
It's not real.

783
00:51:45,100 --> 00:51:45,360
Exactly.

784
00:51:45,940 --> 00:51:46,460
For example.

785
00:51:46,770 --> 00:51:46,880
Right.

786
00:51:47,080 --> 00:51:51,740
So, again, I'm not I'm not advocating that people should lie in court, but nobody should lie in court.

787
00:51:51,930 --> 00:51:52,020
Right.

788
00:51:52,070 --> 00:51:52,900
You should say the truth.

789
00:51:53,320 --> 00:51:56,080
But you understand that your message can be taken out of context.

790
00:51:56,620 --> 00:51:56,680
Right.

791
00:51:57,100 --> 00:52:07,740
And what you say in context can be interpreted and misconstrued to mean exactly opposite to what you have said within the context, right?

792
00:52:08,920 --> 00:52:13,660
And if that's what is used against you, you would be right to say, I didn't send this message.

793
00:52:13,840 --> 00:52:18,540
Because, yeah, you may have sent exactly those words, but the meaning of those words was completely different, right?

794
00:52:18,720 --> 00:52:19,880
And they cannot really.

795
00:52:20,200 --> 00:52:21,060
And then you have a choice.

796
00:52:21,240 --> 00:52:25,680
Either you can say, okay, this is the whole transcript, but this transcript can reveal other sensitive information.

797
00:52:25,880 --> 00:52:31,380
or you may take a defense line okay this is not what i said so i would say that there will be there

798
00:52:31,600 --> 00:52:37,200
should be high profile cases that would rely on this technical parameters of signal protocol and

799
00:52:37,260 --> 00:52:42,780
it's also very important parameters so anyway so so we it's a long kind of journey around how signal

800
00:52:42,880 --> 00:52:48,120
protocol is different from everything else there is nothing else comparable today which would combine

801
00:52:48,320 --> 00:52:54,880
all three equalities i just like listed and node-based signal protocol right and nobody so far

802
00:52:54,900 --> 00:53:00,780
managed to improve on top of that say okay we have this three quality but then something else as well

803
00:53:01,080 --> 00:53:05,200
there's literally no alternative today if you want to have a secure end to encryption you will be

804
00:53:05,310 --> 00:53:12,860
using signal radical as a huge credit to inventors of it most moxie moran spike and i think trevor

805
00:53:13,120 --> 00:53:17,780
perrin was uh the other guy so i think i think that's that's their huge contribution to technology

806
00:53:18,160 --> 00:53:22,520
and to encryption and my today understanding of cryptography obviously it's very different from

807
00:53:22,540 --> 00:53:27,960
early 2022. We understand cryptography really well. We amended Signal Protocol with post-quantum

808
00:53:28,040 --> 00:53:32,740
encryption before Signal did it. Signal did it just recently, but we did it on the same principles,

809
00:53:33,060 --> 00:53:39,580
right? So we created some very strong cryptography around short links that we recently introduced.

810
00:53:39,800 --> 00:53:43,480
So we now understand how we should design cryptographic schemes. And every time we get

811
00:53:43,640 --> 00:53:49,780
through, like we had two security audits, we'll have security audits next year again. So I think

812
00:53:49,780 --> 00:53:56,520
we get so far a rather encouraging alignment with much higher cryptography experts about us doing

813
00:53:56,960 --> 00:54:02,000
a good job when it comes to cryptography. Now, one thing, you mentioned Matrix earlier,

814
00:54:02,570 --> 00:54:08,800
a really big criticism that I have actually, and I see a lot online, is that the home server sees

815
00:54:09,620 --> 00:54:14,320
a lot, a lot of metadata, not just, you know, there is end-to-end encryption if you enable it

816
00:54:14,340 --> 00:54:16,360
in Matrix, but there's still a lot of other data there.

817
00:54:16,910 --> 00:54:19,880
So what does Relay see in SimpleX?

818
00:54:19,970 --> 00:54:21,940
What kind of metadata protection is built in

819
00:54:22,220 --> 00:54:23,420
when someone's messaging on it?

820
00:54:23,600 --> 00:54:26,500
- I think it's wrong to compare Matrix

821
00:54:28,099 --> 00:54:30,760
and SimpleX message directly.

822
00:54:31,120 --> 00:54:34,400
Because Matrix server provides you a place

823
00:54:34,660 --> 00:54:35,620
to host your conversation.

824
00:54:35,960 --> 00:54:38,640
And in particular, if your conversation is public,

825
00:54:39,360 --> 00:54:40,800
then you don't want to hide content.

826
00:54:40,810 --> 00:54:43,220
The problem is that in Matrix design,

827
00:54:43,520 --> 00:54:46,640
you have the same server that's used as a transport

828
00:54:47,400 --> 00:54:49,340
and as a hosting for the conversation,

829
00:54:49,740 --> 00:54:50,700
if you understand what I mean, right?

830
00:54:50,920 --> 00:54:53,060
You connect to the server, it delivers your messages,

831
00:54:53,500 --> 00:54:56,760
but it also hosts the actual messages, right?

832
00:54:57,520 --> 00:54:59,800
And that's the problem, because in this case,

833
00:55:00,500 --> 00:55:01,320
I'll get to the question.

834
00:55:01,340 --> 00:55:04,500
I'm just trying to explain why, what's the real problem.

835
00:55:04,680 --> 00:55:07,160
The real problem is not that the server in Matrix

836
00:55:07,500 --> 00:55:09,400
sees some metadata, but it's the same server

837
00:55:09,780 --> 00:55:11,060
that also sees the message content.

838
00:55:12,220 --> 00:55:14,720
So it not only sees who sends messages

839
00:55:15,040 --> 00:55:17,080
and it not only sees what messages are,

840
00:55:17,330 --> 00:55:20,420
it can connect sender identities with messages.

841
00:55:21,040 --> 00:55:23,440
And that's where the fundamental problem happens, right?

842
00:55:23,560 --> 00:55:25,880
Because if somebody says something problematic,

843
00:55:26,060 --> 00:55:28,180
but nobody knows who they are, it's not a problem.

844
00:55:28,420 --> 00:55:29,300
And vice versa, right?

845
00:55:29,360 --> 00:55:30,220
If somebody sends messages,

846
00:55:30,360 --> 00:55:31,600
but nobody knows what they sent,

847
00:55:31,690 --> 00:55:33,400
again, it's not much of a problem, right?

848
00:55:33,680 --> 00:55:34,740
Something is being sent.

849
00:55:35,120 --> 00:55:37,480
But when you can connect identity to content,

850
00:55:37,960 --> 00:55:40,620
that's when the personal security gets compromised, right?

851
00:55:40,820 --> 00:55:45,380
So with our current messaging relay, they obviously don't see the content.

852
00:55:45,470 --> 00:55:46,540
They don't see the conversations.

853
00:55:47,600 --> 00:55:49,960
And they, of course, see some metadata.

854
00:55:50,090 --> 00:55:56,360
I think protecting metadata is just an oxymoron, frankly, because you cannot protect it if you

855
00:55:56,510 --> 00:55:57,440
use metadata, right?

856
00:55:57,580 --> 00:55:59,860
You have to use some metadata to deliver messages.

857
00:55:59,990 --> 00:56:03,720
And what you want is to minimize the metadata, not protect, but to minimize the metadata that

858
00:56:03,730 --> 00:56:07,400
you use and minimize the metadata that you can observe and minimize the metadata that

859
00:56:07,400 --> 00:56:07,920
you can record.

860
00:56:08,440 --> 00:56:11,280
So if you're talking about metadata and communication, we're talking about three different things, right?

861
00:56:11,380 --> 00:56:13,180
Metadata you can observe, that's one thing.

862
00:56:13,540 --> 00:56:18,120
Metadata that you actually need to transmit messages, right?

863
00:56:18,560 --> 00:56:19,780
You need some metadata.

864
00:56:20,740 --> 00:56:22,580
And metadata that you record long term.

865
00:56:22,840 --> 00:56:24,320
And they can be three different things, right?

866
00:56:24,540 --> 00:56:29,940
So if you connect to MessagingRelay, they obviously can observe your IP addresses inevitably.

867
00:56:31,060 --> 00:56:32,280
They don't record this information.

868
00:56:32,360 --> 00:56:33,820
We put it in our privacy policy.

869
00:56:33,880 --> 00:56:36,600
We don't have any need to record those addresses.

870
00:56:36,760 --> 00:56:40,560
so we don't record those addresses, but technically they can observe the IP addresses.

871
00:56:41,780 --> 00:56:44,320
They cannot also observe connection times, right?

872
00:56:44,350 --> 00:56:49,080
They know when you connect to the server and they can see when each address connects to the server.

873
00:56:49,360 --> 00:56:52,120
Again, they don't use this metadata and they don't record this metadata,

874
00:56:52,520 --> 00:56:53,860
but that's an observable metadata.

875
00:56:54,380 --> 00:56:56,140
And the same will be true for any kind of network.

876
00:56:56,380 --> 00:56:59,100
Tor relays can observe the same, session relays, VPN providers.

877
00:56:59,300 --> 00:57:01,100
It's all kind of universal, right?

878
00:57:02,880 --> 00:57:06,800
What they do use, what they can't observe, though, is very important.

879
00:57:06,820 --> 00:57:08,200
They cannot observe the message size.

880
00:57:09,300 --> 00:57:19,860
Because SimpleX network is probably, I think it's the only network that uses fixed packet size of a rather large size in comparison.

881
00:57:20,180 --> 00:57:22,360
Kitech also uses fixed packet size, slightly smaller.

882
00:57:22,900 --> 00:57:25,580
So every single message you send is 16 kilobytes.

883
00:57:27,380 --> 00:57:28,980
It's paid to 16 kilobytes.

884
00:57:29,760 --> 00:57:31,580
Doesn't matter how large it is.

885
00:57:32,020 --> 00:57:37,360
It can be a long text, which takes, it can be like image preview that takes

886
00:57:37,540 --> 00:57:40,220
six kilobytes, or it can be just a thumbs up reaction.

887
00:57:40,850 --> 00:57:45,260
Uh, what network will observe will be six and kiloby traffic, which is

888
00:57:45,400 --> 00:57:46,380
purposely wasteful.

889
00:57:47,310 --> 00:57:51,520
Uh, and obviously you don't need 16 kiloby traffic to send thumbs up

890
00:57:51,720 --> 00:57:52,500
reaction, right?

891
00:57:52,500 --> 00:57:57,720
You need several bytes, maybe a hundred bytes, but this design prevents a

892
00:57:57,940 --> 00:58:00,980
correlation by traffic, uh, across the network, right?

893
00:58:01,020 --> 00:58:10,700
Because if you send messages of variable size, then it becomes very easy to determine who talks to whom simply by seeing how those sizes correlates on different parts of the network.

894
00:58:11,010 --> 00:58:11,140
Right.

895
00:58:11,190 --> 00:58:16,540
And if every single message has the same size, then network observers can't establish who talks to whom.

896
00:58:17,080 --> 00:58:20,180
And servers can't observe it as well because they don't know their real message size.

897
00:58:20,210 --> 00:58:22,960
They only see the fixed block size of 16 kilobytes.

898
00:58:23,130 --> 00:58:25,940
They obviously have like destination address.

899
00:58:26,480 --> 00:58:28,280
But again, destination address is not the user.

900
00:58:28,920 --> 00:58:34,060
it's the messaging queue and the user can have tens of thousands of those message queues

901
00:58:34,300 --> 00:58:37,700
and they wouldn't, the server that sends,

902
00:58:39,940 --> 00:58:44,080
wouldn't, they wouldn't necessarily know which, how queues correlate to users.

903
00:58:44,540 --> 00:58:48,540
But the whole idea is like every time you send the message, it goes through two servers, right?

904
00:58:49,120 --> 00:58:53,920
And the first server knows your IP address and it knows the destination server,

905
00:58:54,380 --> 00:58:56,820
but it wouldn't know the destination address on the server.

906
00:58:57,040 --> 00:59:04,440
So, cumulatively, you send to this other server 100 messages, but they wouldn't know to how many contacts.

907
00:59:04,510 --> 00:59:08,020
It can be 100 messages to one contact, or it can be 100 messages to 100 contacts.

908
00:59:08,240 --> 00:59:12,620
The first server wouldn't know not which contacts nor how many.

909
00:59:13,680 --> 00:59:17,900
And the destination server would see the addresses, destination addresses.

910
00:59:18,230 --> 00:59:22,600
It would know which queues to put the messages in, but it wouldn't see which IP address sent them.

911
00:59:22,960 --> 00:59:32,320
And they wouldn't know even, like, again, is it, let's say, if messages arrive to 100 addresses, do they arrive from one user or do they arrive from 100 different users?

912
00:59:32,430 --> 00:59:33,120
They wouldn't know that.

913
00:59:33,640 --> 00:59:38,600
And the protocol is designed in a way that they simply can't share this information with each other.

914
00:59:39,000 --> 00:59:46,740
So they don't observe it because there is an end-to-end encryption tunnel, not just between the users, but between user and the destination server.

915
00:59:46,920 --> 00:59:51,920
There's a separate end-to-end encryption, like, not end-to-end, but let's say user to destination.

916
00:59:52,260 --> 00:59:53,500
is a separate encryption tunnel.

917
00:59:53,880 --> 00:59:56,120
It's kind of how Onion Routing is designed

918
00:59:56,120 --> 00:59:58,720
when you wrap encryption layers one on top of each other

919
00:59:58,920 --> 01:00:02,260
to protect information from intermeter relays.

920
01:00:03,340 --> 01:00:06,500
So in a way, SimpleX Network functions

921
01:00:06,790 --> 01:00:08,940
very similar to how Mixed Network function.

922
01:00:10,060 --> 01:00:11,700
It's just low latency Mixed Network.

923
01:00:12,100 --> 01:00:15,900
And the difference is it's very tailored

924
01:00:16,440 --> 01:00:19,680
to the problem of transmitting messages, right?

925
01:00:19,940 --> 01:00:25,960
It's very specialized to this particular need rather than being a generic.

926
01:00:26,600 --> 01:00:30,380
And it's very different from Tor because Tor establishes connections, right?

927
01:00:30,520 --> 01:00:34,800
So even if you connect via Tor, there will be a persistent circuit built via Tor

928
01:00:34,910 --> 01:00:38,540
and everything you send via the circuit can be attributed to you as a user.

929
01:00:39,400 --> 01:00:43,520
When you send your messages to the destination, there is no persistent circuit.

930
01:00:43,600 --> 01:00:51,860
there is just packet level encryption and security rather than circuit level like with Tor.

931
01:00:52,600 --> 01:00:57,720
If anyone is listening and they don't like the idea of their IP address being collected,

932
01:00:58,220 --> 01:01:03,400
I'm sure we can recommend people use VPNs or Tor when they're using SimpleOS.

933
01:01:03,460 --> 01:01:10,640
100%. We're not collecting them. What I'm saying is the IP address is theoretically observable,

934
01:01:10,860 --> 01:01:14,440
but that would be the same whichever network you use.

935
01:01:14,440 --> 01:01:18,220
If you use VPN, your VPN provider may be observing your IP address as well

936
01:01:18,280 --> 01:01:19,600
and may be collecting them.

937
01:01:20,100 --> 01:01:25,820
And if you use Tor, then your entry node on Tor is also able to observe your IP address

938
01:01:26,080 --> 01:01:27,100
and also collect your IP address.

939
01:01:27,500 --> 01:01:29,020
So the choice that people should be making,

940
01:01:29,560 --> 01:01:32,300
I think it's very dangerous for people to have an illusion

941
01:01:33,160 --> 01:01:36,560
that they can use intranet in a way when nobody observes their IP address

942
01:01:36,720 --> 01:01:38,080
because there will be always that somebody,

943
01:01:38,180 --> 01:01:40,480
they have a choice of who this somebody is, right?

944
01:01:40,520 --> 01:01:44,060
and they have to make the correct choice there.

945
01:01:44,560 --> 01:01:45,760
And yes, you're absolutely right.

946
01:01:45,860 --> 01:01:48,200
In many cases, by combining multiple parties,

947
01:01:48,740 --> 01:01:50,940
you may increase your security, right?

948
01:01:51,220 --> 01:01:54,800
But you can also reduce your security by combining multiple parties.

949
01:01:55,360 --> 01:01:55,460
Right.

950
01:01:55,610 --> 01:01:58,580
So I guess my question and what some people might be wondering is,

951
01:01:59,240 --> 01:02:02,920
is there a reason you haven't opted for built-in IP protection

952
01:02:03,200 --> 01:02:07,140
that would change the party away from, I guess, a relay?

953
01:02:07,440 --> 01:02:09,460
I know you already explained it to people,

954
01:02:09,720 --> 01:02:13,340
But I know some messengers might opt to do like a Tor onion routing.

955
01:02:13,520 --> 01:02:16,100
But then I assume that's just going to add a huge amount of complexity.

956
01:02:17,220 --> 01:02:18,160
No, it wouldn't add complexity.

957
01:02:18,540 --> 01:02:28,860
I think Tor is, I don't want to couple the message bus and network design to transport protection network design.

958
01:02:29,380 --> 01:02:34,260
We're currently allowed to use the app with Sox proxies.

959
01:02:34,300 --> 01:02:37,320
And Sox proxy allows to obstruct this transport network.

960
01:02:37,500 --> 01:02:39,340
So you can use, if you want to use Tor, you can use Tor.

961
01:02:39,400 --> 01:02:45,040
if you want to use I2P you can use I2P right or if you want to use some other design that we

962
01:02:45,440 --> 01:02:48,980
don't know about you can potentially also use it or you can use your own SOX proxies

963
01:02:49,420 --> 01:02:56,080
we just think this problem should be I think this problem should be kept separate and by putting

964
01:02:56,600 --> 01:03:02,600
both protections in one app we're not increasing the security we are reducing it right because there

965
01:03:02,600 --> 01:03:07,199
is no bulletproof sense right torque protection is not bulletproof so like if you wanted optics

966
01:03:07,200 --> 01:03:11,720
and look like, we don't want to look like the most secure message.

967
01:03:11,760 --> 01:03:14,540
We want to provide actual real security.

968
01:03:15,160 --> 01:03:19,500
And while optics of embeds in Tor may look good for some people,

969
01:03:20,100 --> 01:03:24,320
reality is bad because it means that now we're responsible for shipping Tor code, right?

970
01:03:24,820 --> 01:03:27,040
Now we're responsible for security updates in Tor code.

971
01:03:27,300 --> 01:03:31,200
Now they depend on us to provide integrity of Tor code.

972
01:03:31,580 --> 01:03:34,620
To me as a user, it all sounds like a horrible deal, right?

973
01:03:34,860 --> 01:03:39,940
Because if I want to trust Tor, I want to get Tor code from Tor developers, not from

974
01:03:40,200 --> 01:03:41,440
SimpleX developers, right?

975
01:03:41,770 --> 01:03:43,140
So they provide me the code.

976
01:03:43,470 --> 01:03:46,140
Because in this case, that provides additional security.

977
01:03:46,280 --> 01:03:50,520
Even if it do make some mistake, then I have Tor to protect me, right?

978
01:03:50,900 --> 01:03:54,960
But that all kind of predicated on the fact that I get Tor code from Tor developers and

979
01:03:54,990 --> 01:03:59,520
not from why would I, like, I'm putting myself in the shoes of a user.

980
01:03:59,870 --> 01:04:02,400
Why would I trust me to ship me Tor?

981
01:04:02,510 --> 01:04:03,460
I don't develop Tor.

982
01:04:04,000 --> 01:04:05,940
Like, why should I embed it in the app?

983
01:04:06,220 --> 01:04:11,480
It looks good for non-technical people, but reality is it's bad.

984
01:04:12,300 --> 01:04:20,660
And for even non-technical users, the time it takes to start using SimpleX Viator on Android device is exactly one minute.

985
01:04:21,160 --> 01:04:29,480
You go to the App Store or Play Store or AppDroid, you download Orbit app, you press start, then you go to, like, it's literally like it's a one-minute instruction.

986
01:04:30,180 --> 01:04:35,720
And if people find it technically complex, they honestly shouldn't use Tor at all.

987
01:04:35,940 --> 01:04:36,680
That's my strong opinion.

988
01:04:36,960 --> 01:04:39,840
Because Tor has some limitations to its threat model.

989
01:04:39,860 --> 01:04:42,140
You have to understand the limitations to the threat model, right?

990
01:04:42,320 --> 01:04:51,260
If you think that this kind of install the second app is technically complex, you'll make so many mistakes with your AT security that Tor is not going to help you.

991
01:04:51,260 --> 01:04:52,300
It's only going to hurt.

992
01:04:52,860 --> 01:04:59,960
So I generally think that by embedding Tor, we're doing a bad service to our users in all means.

993
01:05:01,420 --> 01:05:08,800
Got it. And then, you know, let's pivot more into the usability side of things, I guess, to go away from the technical side.

994
01:05:09,300 --> 01:05:15,880
So what are kind of the usability challenges right now? Because it's a complex network and it's a lot of stuff going on.

995
01:05:15,980 --> 01:05:20,160
So where do you feel like that's kind of increased complexity on the usability front?

996
01:05:22,099 --> 01:05:28,320
We're still in the world when many new users who don't come via the introduction find it

997
01:05:28,520 --> 01:05:32,420
difficult to connect to other people because obviously you can't enter the phone number

998
01:05:32,750 --> 01:05:33,440
as they used to.

999
01:05:33,440 --> 01:05:36,680
You can't search for users in the app.

1000
01:05:37,090 --> 01:05:39,820
You need to somehow search them outside of the app.

1001
01:05:40,140 --> 01:05:45,860
And we can see that if people come via the introduction of somebody who already uses SimpleX,

1002
01:05:46,060 --> 01:05:48,880
then normally they successfully get on boarded.

1003
01:05:48,900 --> 01:05:51,280
they start using it and they understand how to use it.

1004
01:05:51,320 --> 01:05:55,420
But if they simply download the app from Play Store or from App Store,

1005
01:05:56,300 --> 01:06:01,840
then the most common question we get in support, support contact is embedded into the app

1006
01:06:01,940 --> 01:06:02,980
so they can connect to us.

1007
01:06:03,140 --> 01:06:06,540
And one of the most common, not the most, but one of the most common questions is,

1008
01:06:07,000 --> 01:06:08,000
OK, how do I connect to people?

1009
01:06:08,140 --> 01:06:11,920
And we've iterated this user experience for new users many times

1010
01:06:12,180 --> 01:06:17,380
and we're still looking for better way to explain to the new users that,

1011
01:06:17,940 --> 01:06:22,200
okay, you have to create the link, you have to pass it via some other channel, just because

1012
01:06:22,880 --> 01:06:28,480
that provides security from us. And then you have this somebody else have to use this link in the

1013
01:06:28,520 --> 01:06:33,800
app. And even though we recently improved usability of links by a lot, right, we had like

1014
01:06:34,300 --> 01:06:40,760
huge 500 character links, which everybody considered malware. Not everybody, but everybody's

1015
01:06:40,770 --> 01:06:44,900
non-technical consider them malware. Right? They look at this, oh, look, it looks scary,

1016
01:06:44,920 --> 01:06:45,560
I'm not going to use it.

1017
01:06:45,950 --> 01:06:47,820
So now they're short and nice.

1018
01:06:47,950 --> 01:06:51,920
And if you tap it, you see the name of the person you connect to before you connect.

1019
01:06:52,190 --> 01:06:53,520
And you can send a message together.

1020
01:06:54,180 --> 01:06:56,780
It's really, really nice compared with what it was, right?

1021
01:06:57,620 --> 01:06:59,360
So still, it remains a challenge.

1022
01:06:59,660 --> 01:07:01,660
That's literally a simple thing, how people connect.

1023
01:07:01,800 --> 01:07:03,220
That's a basic thing.

1024
01:07:03,250 --> 01:07:05,140
And we still didn't figure it out after four years.

1025
01:07:05,340 --> 01:07:07,000
That's embarrassing, frankly.

1026
01:07:07,560 --> 01:07:08,880
But it's complex.

1027
01:07:09,280 --> 01:07:14,099
That whole kind of fundamental innovation that we created in unit work topology

1028
01:07:14,120 --> 01:07:15,720
when users don't have identifiers,

1029
01:07:16,060 --> 01:07:17,860
which means that you can't find users,

1030
01:07:17,950 --> 01:07:20,300
you don't even know how many users are there on the network,

1031
01:07:20,860 --> 01:07:23,980
that obviously creates a UX challenge that we didn't crack yet.

1032
01:07:24,320 --> 01:07:26,140
That's probably the main, remains the main thing.

1033
01:07:27,260 --> 01:07:29,900
So, and the second most important thing

1034
01:07:30,080 --> 01:07:32,960
is what is the complex development

1035
01:07:33,200 --> 01:07:34,740
is just making large groups work

1036
01:07:34,960 --> 01:07:37,240
because the current groups on SimpleX platform

1037
01:07:37,800 --> 01:07:39,080
is a client-side broadcast, right?

1038
01:07:39,180 --> 01:07:40,760
It's like mailing list under the hood.

1039
01:07:41,080 --> 01:07:42,580
You want to send a message to the group,

1040
01:07:42,700 --> 01:07:44,620
you have to send it to each member in the group.

1041
01:07:44,790 --> 01:07:45,880
It all happens automatically.

1042
01:07:45,990 --> 01:07:48,680
It looks like the usual group, but it creates lots of traffic.

1043
01:07:49,060 --> 01:07:51,760
It also means that messages may reach some users,

1044
01:07:52,000 --> 01:07:53,380
but not to reach some other users.

1045
01:07:54,000 --> 01:07:56,680
And then they see messages in different order on their devices.

1046
01:07:57,160 --> 01:07:59,860
And they can also see replies to messages they've never seen.

1047
01:08:00,580 --> 01:08:01,860
And it just comes with the territory.

1048
01:08:02,220 --> 01:08:06,060
So if the group doesn't have a single source of truth

1049
01:08:06,380 --> 01:08:08,180
that is reliable and always online,

1050
01:08:08,600 --> 01:08:11,539
then different people in the group are likely to see

1051
01:08:11,560 --> 01:08:13,480
on what divergent histories in the conversation.

1052
01:08:13,810 --> 01:08:14,820
So we are working on that.

1053
01:08:15,040 --> 01:08:16,540
That's technically complex development.

1054
01:08:16,569 --> 01:08:17,580
So we are going to introduce

1055
01:08:18,799 --> 01:08:20,560
what we call chat relays now.

1056
01:08:20,710 --> 01:08:23,120
So effectively a special client of client

1057
01:08:23,640 --> 01:08:26,100
that would probably act conceptually similar

1058
01:08:26,250 --> 01:08:27,779
to Matrix Server,

1059
01:08:28,000 --> 01:08:29,759
but unlike Matrix Server,

1060
01:08:29,940 --> 01:08:31,819
it will be based on client technology

1061
01:08:32,380 --> 01:08:34,100
and you'll never connect to it directly.

1062
01:08:34,350 --> 01:08:35,620
You would still connect to it

1063
01:08:35,710 --> 01:08:37,100
via simple X messaging network,

1064
01:08:37,940 --> 01:08:40,660
which means that even though this chat relay

1065
01:08:40,680 --> 01:08:42,680
They can see public conversations.

1066
01:08:43,480 --> 01:08:45,900
There will be end-to-end encrypted conversations as well via chat relays.

1067
01:08:46,270 --> 01:08:50,900
But even though it can see public conversations, it wouldn't be able to know which are the users

1068
01:08:51,089 --> 01:08:53,779
because there are no direct connections between the users and chat relays.

1069
01:08:53,950 --> 01:08:57,420
So if you use Matrix Server, you have to connect to it directly via the internet.

1070
01:08:57,640 --> 01:09:01,859
Yeah, you can use Tor or whatnot, but you still have to connect to the server via the internet.

1071
01:09:02,400 --> 01:09:08,100
In case of chat relays that we're developing now, you will be connecting to them as if they were your contacts,

1072
01:09:08,740 --> 01:09:12,100
meaning via two servers, messaging servers.

1073
01:09:12,299 --> 01:09:13,240
So there is no direct connections.

1074
01:09:13,430 --> 01:09:14,520
They don't see your traffic.

1075
01:09:14,609 --> 01:09:15,600
They don't see your IP address.

1076
01:09:15,710 --> 01:09:17,359
They don't know where you are on the network.

1077
01:09:18,299 --> 01:09:21,980
So that will address one big usability challenge with the groups.

1078
01:09:22,370 --> 01:09:24,520
But we can still see the interest of groups grow.

1079
01:09:25,900 --> 01:09:29,940
We have a small directory of groups approaching 500 groups

1080
01:09:29,990 --> 01:09:32,279
that people create on SimpleX Network.

1081
01:09:32,500 --> 01:09:35,440
Some of them have more than a couple thousand people.

1082
01:09:36,080 --> 01:09:40,020
And this directory is since recently available as a web page.

1083
01:09:40,310 --> 01:09:42,259
And that kind of makes it much more accessible.

1084
01:09:42,660 --> 01:09:44,680
It's easier to search for them on the web page.

1085
01:09:44,799 --> 01:09:48,140
We offer a chatbot that allows to use this directory,

1086
01:09:48,509 --> 01:09:51,380
but it's also available as a web page since not so long ago.

1087
01:09:52,160 --> 01:09:52,380
Got it.

1088
01:09:52,390 --> 01:09:54,560
And so a really, really quick one.

1089
01:09:54,760 --> 01:09:59,800
Is message delivery about the same speed as what people might expect from their typical app?

1090
01:10:00,420 --> 01:10:00,940
Normally, yes.

1091
01:10:01,220 --> 01:10:04,240
Normally, latency is determined by the network conditions.

1092
01:10:04,940 --> 01:10:11,860
And yes, people with slow network connection find it slower simply because of fixed block size.

1093
01:10:12,720 --> 01:10:22,960
So if your network is really bad, you will see it as slower than most other app because when other apps maybe send in like 100 bytes of data, you have to send 16 kilobytes of data, right?

1094
01:10:23,680 --> 01:10:26,900
And if your network is really slow, then there will be some difference, right?

1095
01:10:27,040 --> 01:10:37,420
But if your network is reasonably fast, which is like modern 4G or 5G networks, mobiles or Wi-Fi, then you would not see noticeable delays in message delivery.

1096
01:10:38,080 --> 01:10:44,880
And like, for example, when I send a message from my desktop client, I usually see second seek meaning that it's delivered to another device.

1097
01:10:45,060 --> 01:10:51,680
And I got the response confirming it was delivered in under like 300 milliseconds many times, like certainly under one second.

1098
01:10:52,240 --> 01:10:57,520
So, yeah, it's on par with more usable messaging apps.

1099
01:10:57,940 --> 01:11:03,360
Yeah, and on this note, you know, Facebook has outages, and Signal has had a couple outages.

1100
01:11:03,720 --> 01:11:06,940
Normally, when they get a huge influx of users, how does that work with your model?

1101
01:11:07,160 --> 01:11:10,820
Is it possible for SimpleX to be down, if that makes sense?

1102
01:11:11,040 --> 01:11:11,580
100%, yeah.

1103
01:11:11,660 --> 01:11:16,680
So, I mean, the whole network can't go down because it fragments it, right?

1104
01:11:16,980 --> 01:11:19,040
And each connection depends on some server.

1105
01:11:19,200 --> 01:11:25,140
And right now, if this server is down, then some of your contacts will be down.

1106
01:11:25,540 --> 01:11:26,660
Not all of your contacts.

1107
01:11:26,750 --> 01:11:30,520
So the simplex as a whole can be down because we don't control all servers.

1108
01:11:30,640 --> 01:11:32,000
Nobody controls all servers, right?

1109
01:11:32,700 --> 01:11:37,580
But because each conversation depends on just a specific, I mean, in each way, right?

1110
01:11:37,720 --> 01:11:40,820
So you can be in a condition when you can receive messages but can't send

1111
01:11:41,120 --> 01:11:43,140
or the other way around to a particular contact.

1112
01:11:43,480 --> 01:11:45,380
You can send but can't receive, right?

1113
01:11:45,440 --> 01:11:51,780
So because one way you will be using one server, another way you will be using another server, that they are both down is very unlikely.

1114
01:11:51,990 --> 01:11:56,180
We have a status page that shows the historic downtimes for all servers.

1115
01:11:56,330 --> 01:11:58,360
They are well over 99%.

1116
01:11:58,500 --> 01:12:02,140
Normally it's like 99.98% for many servers.

1117
01:12:02,610 --> 01:12:04,300
But they do have maintenance windows.

1118
01:12:04,580 --> 01:12:12,440
We recently migrated to new storage approach that reduces maintenance windows from minutes to seconds.

1119
01:12:12,950 --> 01:12:14,380
So that improves deliverability.

1120
01:12:14,560 --> 01:12:15,820
but the migration itself was painful.

1121
01:12:15,870 --> 01:12:18,480
So yes, so effectively people experience some downtime

1122
01:12:18,860 --> 01:12:19,960
with specific contacts

1123
01:12:20,350 --> 01:12:22,360
when this particular server is restarted.

1124
01:12:22,360 --> 01:12:24,620
And our answer to that going forward

1125
01:12:24,790 --> 01:12:28,020
is that each contact should use multiple servers,

1126
01:12:28,380 --> 01:12:31,600
not just one server to send another to reply,

1127
01:12:31,980 --> 01:12:35,020
but let's say you send each message through three servers

1128
01:12:35,440 --> 01:12:38,920
and each server lives with different operator

1129
01:12:39,100 --> 01:12:41,800
in a different data center in a different country.

1130
01:12:42,140 --> 01:12:47,020
the probability of all of them going down together is like literally zero.

1131
01:12:47,340 --> 01:12:51,820
Rather than having each connection, each contact on one company,

1132
01:12:51,880 --> 01:12:53,920
you will have a dependent on three companies.

1133
01:12:54,320 --> 01:12:58,020
And for it to stop working, they all three should stop working,

1134
01:12:58,160 --> 01:12:59,100
which almost never happens.

1135
01:12:59,120 --> 01:13:02,060
So we don't want to be in a situation when Facebook is down, right?

1136
01:13:02,160 --> 01:13:05,280
So like right now, a segment of the network can be down,

1137
01:13:05,360 --> 01:13:09,820
but we want to move to the design when even some part of the transport network

1138
01:13:09,840 --> 01:13:13,520
going down will remain completely unnoticeable by the end users.

1139
01:13:14,220 --> 01:13:14,660
Got it.

1140
01:13:14,660 --> 01:13:16,340
And then how about multi-device sync?

1141
01:13:16,680 --> 01:13:18,000
How does that work with SimpleX?

1142
01:13:18,420 --> 01:13:19,020
It doesn't.

1143
01:13:19,680 --> 01:13:27,340
No, we have a technology that allows to use mobile app from desktop interface as a remote

1144
01:13:27,440 --> 01:13:27,580
access.

1145
01:13:28,000 --> 01:13:33,260
But that requires that both devices are on the same network right now, meaning both mobile

1146
01:13:33,480 --> 01:13:33,840
and desktop.

1147
01:13:34,580 --> 01:13:39,800
And it's effectively just a convenience feature that allows you to type messages from bigger

1148
01:13:39,820 --> 01:13:43,560
on a bigger keyboard through the profile that you have on mobile device.

1149
01:13:44,100 --> 01:13:47,420
It doesn't fundamentally create any synchronization problems or anything.

1150
01:13:47,720 --> 01:13:52,880
You just use it as a remote connection to mobile device when you're using the desktop.

1151
01:13:53,080 --> 01:13:54,180
That works for some users.

1152
01:13:54,940 --> 01:14:00,660
Just to be clear, you can also just not use a mobile device and make the desktop client

1153
01:14:00,980 --> 01:14:02,180
your main device as well.

1154
01:14:02,500 --> 01:14:02,640
Correct.

1155
01:14:02,940 --> 01:14:03,700
Yes, you can.

1156
01:14:03,900 --> 01:14:06,740
But then you wouldn't be able to use this profile anywhere else.

1157
01:14:07,620 --> 01:14:08,160
So you have to pick.

1158
01:14:09,580 --> 01:14:17,100
yeah so for example for for our support we do an interesting thing here so we run our support client

1159
01:14:18,080 --> 01:14:22,520
like support is the account the profile that users connect to through the office says ask

1160
01:14:22,620 --> 01:14:29,340
simple x team in the app right so it's a it's a client that runs in the cloud online 24 7 and

1161
01:14:29,440 --> 01:14:35,560
whoever will be replying to those support requests will be connecting to this client in the cloud

1162
01:14:35,580 --> 01:14:37,920
via the same remote connection from desktop.

1163
01:14:38,100 --> 01:14:39,160
We have it documented somewhere.

1164
01:14:39,280 --> 01:14:42,920
So we effectively allow, like, we have an approach

1165
01:14:43,120 --> 01:14:45,020
that allows multiple people use the same profile

1166
01:14:45,940 --> 01:14:47,440
and reply to people in turns.

1167
01:14:48,080 --> 01:14:50,880
But what many people want, like, I have this profile

1168
01:14:51,080 --> 01:14:53,880
on two mobiles or on mobile and desktop,

1169
01:14:53,940 --> 01:14:56,420
and I can use them both together or in any order,

1170
01:14:56,620 --> 01:14:59,000
and I don't need to do anything to connect them.

1171
01:14:59,000 --> 01:14:59,700
That doesn't work.

1172
01:15:00,340 --> 01:15:02,280
So we consider several approaches,

1173
01:15:02,620 --> 01:15:07,980
And most likely will go with somewhat strengthened approach of Signal.

1174
01:15:08,860 --> 01:15:12,220
What Signal did is rather simple, as I explained earlier, right?

1175
01:15:12,380 --> 01:15:17,420
So they just put all devices in a conversation into a group under the hood, right?

1176
01:15:17,680 --> 01:15:22,680
So what for users looks like conversation between two people is effectively a group between five devices.

1177
01:15:23,040 --> 01:15:24,380
Let's say four devices, right?

1178
01:15:24,720 --> 01:15:29,700
That's a viable approach that has downsides, such as you can see which message is sent by which device.

1179
01:15:30,280 --> 01:15:31,560
That also has some attack factors.

1180
01:15:32,260 --> 01:15:37,880
So far, it looks the most reasonable and the most viable compromise for most people.

1181
01:15:38,360 --> 01:15:43,940
What we want to avoid and it's possible to avoid is the attack vectors that Signal introduced,

1182
01:15:44,090 --> 01:15:48,400
which allows to add device unnoticeably to the end users, right?

1183
01:15:48,450 --> 01:15:53,300
So like Signal relies on pin verification when adding another new device.

1184
01:15:54,140 --> 01:15:59,160
And that's effectively depends on trust to Signal, which I think is a bit thin generally.

1185
01:15:59,420 --> 01:16:03,220
If your security depends on trust to provider, then it's not very good security.

1186
01:16:03,390 --> 01:16:11,740
So our whole philosophy is that your security should depend on cryptography and not on an open source code and not on trust to a particular provider.

1187
01:16:12,100 --> 01:16:13,420
There is an interesting paper published.

1188
01:16:13,490 --> 01:16:14,760
I can send you the link if you're interested.

1189
01:16:14,760 --> 01:16:20,140
There is a good paper that cryptographers published about this vulnerability of signal around 2021.

1190
01:16:20,680 --> 01:16:32,260
I think it's really important that they address it because it effectively allows any attacker that managed to somehow compromise part of signal infrastructure to add a device to any conversation.

1191
01:16:32,940 --> 01:16:36,060
And the problem is users don't get notification when the device is added.

1192
01:16:37,040 --> 01:16:42,980
And they can see it in the list of devices, but you have to proactively look for it to see it.

1193
01:16:43,440 --> 01:16:43,640
Got it.

1194
01:16:44,580 --> 01:16:51,320
And the way the paper describes it, it's rather worrying a tech vector that I think Signal should address.

1195
01:16:51,420 --> 01:16:55,860
But Signal was good at addressing various vulnerability community was pointing out recently.

1196
01:16:55,960 --> 01:17:01,980
It was not very good maybe a couple of years ago, but I think nowadays Signal is a bit more responsive to community criticism.

1197
01:17:02,680 --> 01:17:10,920
And to me, that multi-device vulnerability remains the biggest downside of Signal security model.

1198
01:17:11,580 --> 01:17:12,820
And the solution is really simple.

1199
01:17:12,940 --> 01:17:17,080
Just let users scan the security code, even if you had another mobile, right?

1200
01:17:17,120 --> 01:17:22,440
So it's actually make trust between devices established on the client level without Signal

1201
01:17:23,360 --> 01:17:24,440
being involved, right?

1202
01:17:24,640 --> 01:17:28,820
So anyway, so if you go this way, then we'll obviously do it like this, and it will be

1203
01:17:29,280 --> 01:17:29,740
secure.

1204
01:17:30,060 --> 01:17:35,340
And the only downside that cannot be addressed is that your contacts now can see which device

1205
01:17:35,520 --> 01:17:35,900
you're using.

1206
01:17:36,260 --> 01:17:38,740
That's the main downside of this Signal model, right?

1207
01:17:39,060 --> 01:17:45,580
which may be okay for trusted contacts, but they may be not so good for participating in public groups, right?

1208
01:17:46,060 --> 01:17:51,580
Obviously, the future chat relays make it less important because only chat relays now can see which device you use,

1209
01:17:51,680 --> 01:17:53,700
but other members wouldn't be able to see.

1210
01:17:54,020 --> 01:17:57,640
So I think once we move to the new model for public groups,

1211
01:17:58,220 --> 01:18:02,700
this signal approach to multi-device becomes acceptable from a security point of view.

1212
01:18:03,820 --> 01:18:05,800
Great. And then how about, we're almost done with the usability,

1213
01:18:06,000 --> 01:18:10,220
And then it's just like business, finances, legal stuff.

1214
01:18:10,700 --> 01:18:17,320
But for battery impact, is there a battery impact for having to do background sync for things like notifications on mobile devices?

1215
01:18:17,620 --> 01:18:19,360
Is that different from something like Signal?

1216
01:18:20,300 --> 01:18:23,920
I think we reduced battery usage by a lot in the recent releases.

1217
01:18:24,380 --> 01:18:31,720
I think we did something rather stupid on Android early on by never releasing awake logs.

1218
01:18:32,320 --> 01:18:34,360
And we recently realized that.

1219
01:18:34,500 --> 01:18:43,020
I think the current Android releases do like much, much better and better usage than like even three months, maybe four months.

1220
01:18:43,190 --> 01:18:44,480
When did we do it? Several months ago.

1221
01:18:44,720 --> 01:18:47,060
Decentralization adds to better usage without question.

1222
01:18:47,210 --> 01:18:53,480
But I think 90% of the damage was self-inflicted through engineering mistakes.

1223
01:18:54,020 --> 01:19:01,920
We copied our approach from NTFI op in like NTFI op that is effectively used as a broker for push notification delivery.

1224
01:19:02,260 --> 01:19:05,300
And SimpleX app does the same on Android devices, right?

1225
01:19:05,690 --> 01:19:08,140
So we copied our approach from them.

1226
01:19:08,500 --> 01:19:10,880
And then they fixed this bug like about one year later.

1227
01:19:11,030 --> 01:19:12,100
And we didn't fix this bug.

1228
01:19:12,700 --> 01:19:14,860
So, yeah, so that was the story.

1229
01:19:15,080 --> 01:19:18,380
And then recently we discovered that, again, it's embarrassing, but here it is.

1230
01:19:18,920 --> 01:19:22,720
So right now, I think most users right now see usage as acceptable.

1231
01:19:22,890 --> 01:19:25,080
It would not be exactly the same as Signal.

1232
01:19:25,280 --> 01:19:26,780
You have larger block size.

1233
01:19:27,370 --> 01:19:28,700
But everything has costs, right?

1234
01:19:28,920 --> 01:19:30,940
You have higher security guarantees.

1235
01:19:31,220 --> 01:19:32,860
you have better decentralization.

1236
01:19:33,050 --> 01:19:34,180
But I think fundamentally,

1237
01:19:34,250 --> 01:19:37,660
the biggest usage comes from group decentralization.

1238
01:19:37,770 --> 01:19:41,340
And once we move large groups to chat relays,

1239
01:19:41,670 --> 01:19:43,580
the better usage will be on par with Signal.

1240
01:19:44,260 --> 01:19:44,420
Okay.

1241
01:19:44,910 --> 01:19:47,120
And then do you do background sync on iOS?

1242
01:19:47,920 --> 01:19:52,800
No, we do do background sync,

1243
01:19:52,980 --> 01:19:56,120
but iOS is very restrictive in how you allow it to...

1244
01:19:56,340 --> 01:19:58,740
We will periodically sync in the background.

1245
01:19:59,060 --> 01:20:05,000
It's effectively only works if you use the app a lot.

1246
01:20:05,160 --> 01:20:09,620
On iOS, we use push notifications using Apple push servers.

1247
01:20:10,050 --> 01:20:15,400
So it's a completely separate part of the network that unfortunately cannot be decentralized with Apple model.

1248
01:20:16,000 --> 01:20:19,160
But that's the only way for iOS to provide push notifications.

1249
01:20:19,460 --> 01:20:21,840
So we have a special service that we host.

1250
01:20:22,000 --> 01:20:31,760
Only we can host it because it has application keys on it that can push notifications when it gets notified about messages existence.

1251
01:20:32,220 --> 01:20:34,160
It's a highly secure approach, obviously.

1252
01:20:34,250 --> 01:20:36,800
The notification server doesn't see not just messages.

1253
01:20:37,000 --> 01:20:41,160
All the notification server sees is end-to-end encrypted metadata.

1254
01:20:41,780 --> 01:20:44,080
Not just the message, but the metadata itself is also encrypted.

1255
01:20:44,090 --> 01:20:46,360
And that's what you use on Android, but not on iOS.

1256
01:20:47,620 --> 01:20:49,780
That's what we use on iOS, but not on Android.

1257
01:20:50,020 --> 01:20:52,300
For iOS, we use push notifications using Apple servers.

1258
01:20:52,640 --> 01:20:53,180
Or Android.

1259
01:20:53,860 --> 01:20:55,480
You're saying you use on Android.

1260
01:20:55,910 --> 01:20:56,420
No, we don't.

1261
01:20:56,720 --> 01:20:56,800
Sorry.

1262
01:20:57,680 --> 01:21:01,700
Android just runs background servers in the same way as...

1263
01:21:01,720 --> 01:21:02,480
It's not background refresh.

1264
01:21:02,730 --> 01:21:02,860
No.

1265
01:21:02,950 --> 01:21:03,680
We use the same...

1266
01:21:03,680 --> 01:21:09,400
We use effectively push messages in the same way as NTFI...

1267
01:21:09,560 --> 01:21:11,260
Like, you know, the unified push system, right?

1268
01:21:11,520 --> 01:21:11,740
Yeah.

1269
01:21:11,820 --> 01:21:12,820
NTFI app, right?

1270
01:21:12,820 --> 01:21:14,200
You guys use unified push, but then...

1271
01:21:14,240 --> 01:21:14,600
We don't.

1272
01:21:14,730 --> 01:21:19,180
We don't use unified push, but we use the same technological approach as unified push.

1273
01:21:19,660 --> 01:21:23,080
And effectively, simple X messages and servers work as push servers.

1274
01:21:23,600 --> 01:21:24,980
You don't have to pull messages.

1275
01:21:25,320 --> 01:21:26,040
That's not how it works.

1276
01:21:26,460 --> 01:21:29,540
When you message, you remain open connection.

1277
01:21:30,440 --> 01:21:34,540
This connection can be maintained as open even when the app is slipping.

1278
01:21:35,120 --> 01:21:39,220
And if the message arrives, the server pushes it to this open connection.

1279
01:21:40,300 --> 01:21:42,800
And the app then wakes up and shows you a notification.

1280
01:21:43,020 --> 01:21:43,900
That's how it works on Android.

1281
01:21:44,260 --> 01:21:48,880
So that's the same approach pretty much as with NTFI app.

1282
01:21:49,360 --> 01:21:54,320
Got it. Pivoting over to the business and sustainability. So I always like to ask about

1283
01:21:54,640 --> 01:21:59,340
funding models. I've read some of your blogs. They're pretty spicy. I don't know if I'm on the

1284
01:21:59,440 --> 01:22:05,320
same page, but I still want to hear kind of which one. Which one do you mean? I think your takes on

1285
01:22:05,440 --> 01:22:11,460
VC funding. I'm not fully on the same page as you are, but it's an open podcast. We're open to

1286
01:22:11,530 --> 01:22:16,300
different opinions here. So I'd love to hear kind of your guys's funding model, your views on it,

1287
01:22:16,360 --> 01:22:19,620
and kind of the pros and cons between your guys' approach and other organizations?

1288
01:22:20,260 --> 01:22:23,920
I think the problem with investment is not who makes the investment,

1289
01:22:24,160 --> 01:22:26,620
but what is being surrendered in exchange of investment.

1290
01:22:26,720 --> 01:22:29,100
Like every investment deal is about two things.

1291
01:22:29,120 --> 01:22:30,340
It's economics and control.

1292
01:22:31,260 --> 01:22:37,040
And many inexperienced business people, they care about economics of investment,

1293
01:22:37,580 --> 01:22:40,280
is how much profit you share, but they don't care that much about control.

1294
01:22:40,720 --> 01:22:42,080
And investors like control.

1295
01:22:42,380 --> 01:22:45,500
They like put some control provisions into the investment agreements.

1296
01:22:46,340 --> 01:22:51,180
they give them the escape page if the business goes in the direction they disagree with that

1297
01:22:51,340 --> 01:22:56,000
allows them to replace executives etc etc and that's what's dangerous for the integrity of the

1298
01:22:56,500 --> 01:23:02,620
mission and when people criticize VC investment they effectively criticize not the economics of

1299
01:23:02,700 --> 01:23:09,999
VC investment they criticize control of the VC investment and many people believe that control

1300
01:23:10,520 --> 01:23:12,880
is inseparable from investment.

1301
01:23:13,380 --> 01:23:14,160
But that's just not true.

1302
01:23:15,100 --> 01:23:18,140
The world of small early stage business investment

1303
01:23:18,180 --> 01:23:19,480
has moved on dramatically

1304
01:23:19,980 --> 01:23:22,280
from this control-centered investment model

1305
01:23:22,520 --> 01:23:25,480
simply because there were lots of successful entrepreneurs

1306
01:23:26,200 --> 01:23:27,920
that have proven their investors

1307
01:23:28,300 --> 01:23:30,880
that by doing things investors disagree with,

1308
01:23:31,180 --> 01:23:32,980
they're making those investors more money.

1309
01:23:33,160 --> 01:23:35,380
So for example, if you look at like Snapchat pitch,

1310
01:23:35,580 --> 01:23:37,879
like literally like 99% VCs

1311
01:23:37,900 --> 01:23:41,320
who have seen Snapchat pitch about deleting messages

1312
01:23:41,470 --> 01:23:42,360
after they were sent.

1313
01:23:42,480 --> 01:23:44,440
They said, this is the stupidest idea we've ever seen.

1314
01:23:45,250 --> 01:23:45,740
Or Airbnb.

1315
01:23:46,300 --> 01:23:49,720
Many hugely successful startups had very kind of...

1316
01:23:49,920 --> 01:23:52,960
And whoever agrees to invest this idea,

1317
01:23:53,160 --> 01:23:55,420
they understand that they really would not be able

1318
01:23:55,880 --> 01:23:58,380
to meaningfully contribute to running this business

1319
01:23:58,470 --> 01:24:00,080
without disrupting founders' visions.

1320
01:24:01,400 --> 01:24:04,560
So the world of investment is hugely split

1321
01:24:04,650 --> 01:24:06,719
between investors who do want control

1322
01:24:07,540 --> 01:24:08,380
and investors who don't.

1323
01:24:08,840 --> 01:24:11,080
So when we were raising money in 2023,

1324
01:24:11,610 --> 01:24:13,940
I was lucky enough to have Jack Dorsey

1325
01:24:14,400 --> 01:24:16,760
offering this investment and some VC fund.

1326
01:24:17,770 --> 01:24:19,740
But there is literally zero control provisions there.

1327
01:24:20,320 --> 01:24:21,340
They don't have board seat.

1328
01:24:21,430 --> 01:24:25,080
They don't have even remotely close to control and share.

1329
01:24:25,360 --> 01:24:26,540
Like it's really a small stake.

1330
01:24:27,060 --> 01:24:31,260
And all they have is information rights, literally.

1331
01:24:31,580 --> 01:24:33,540
And again, when I say financial rights,

1332
01:24:33,540 --> 01:24:35,020
I mean information rights.

1333
01:24:35,020 --> 01:24:36,440
I mean like financial information.

1334
01:24:36,580 --> 01:24:38,140
We don't have to disclose corporate secrets.

1335
01:24:38,280 --> 01:24:39,820
We can have a Chinese wall.

1336
01:24:39,820 --> 01:24:42,560
We don't need to disclose who our kind of partners,

1337
01:24:43,020 --> 01:24:43,600
contractors are in place.

1338
01:24:43,820 --> 01:24:48,420
So they literally cannot participate in running the business in any way.

1339
01:24:48,780 --> 01:24:51,000
But they offer a huge resource of advice.

1340
01:24:51,100 --> 01:24:52,760
They offer a huge resource of support.

1341
01:24:52,880 --> 01:24:54,560
They offer a huge resource for introductions.

1342
01:24:55,200 --> 01:24:59,040
And you not just get money to build a business,

1343
01:24:59,100 --> 01:25:02,280
you get free advisors as well, which is fantastic, right?

1344
01:25:02,700 --> 01:25:06,160
So I think when people say that we see investment universally bad,

1345
01:25:06,300 --> 01:25:09,960
they're really talking about bad decisions that founders have made

1346
01:25:10,340 --> 01:25:14,520
when they surrendered control early on to wrong investors

1347
01:25:14,730 --> 01:25:16,680
who they're not necessarily strategically aligned with.

1348
01:25:17,100 --> 01:25:19,580
At the same year when we raised money in 2023,

1349
01:25:20,230 --> 01:25:21,980
we had two more term sheets.

1350
01:25:22,050 --> 01:25:24,500
We could have raised like three times more money than we raised.

1351
01:25:24,980 --> 01:25:27,800
And they both wanted control and they said no to them both,

1352
01:25:27,880 --> 01:25:29,720
even though economically they were very attractive.

1353
01:25:30,300 --> 01:25:33,420
So that's if you're talking about investment.

1354
01:25:33,560 --> 01:25:36,780
But investment doesn't really create financial model for the business, right?

1355
01:25:36,780 --> 01:25:39,940
So investment literally gives you money to do what, right?

1356
01:25:41,400 --> 01:25:42,260
Why investors?

1357
01:25:42,500 --> 01:25:47,220
Investors invest in your ability to figure out how to make money eventually.

1358
01:25:47,700 --> 01:25:54,980
And at this point, we have viable, our early theory about how to make money was traditional,

1359
01:25:55,660 --> 01:25:58,020
we should use premium features.

1360
01:25:58,500 --> 01:26:02,880
The problem with premium features is that people don't like them.

1361
01:26:03,140 --> 01:26:09,380
And when they are universally introduced, it gets into, like, the product gets incentivized, right?

1362
01:26:09,410 --> 01:26:13,240
The product starts getting optimized in order to sell those premium.

1363
01:26:13,400 --> 01:26:14,400
How do you sell premium features?

1364
01:26:14,660 --> 01:26:15,160
Premium features.

1365
01:26:15,210 --> 01:26:16,720
You get experience with everybody else's voice.

1366
01:26:17,040 --> 01:26:19,880
So, like, that's what's happening with Telegram, right?

1367
01:26:19,950 --> 01:26:23,500
So, unless you're a premium user, you get some progressively worse experience.

1368
01:26:23,890 --> 01:26:27,380
And that's the only way to drive the revenue up is to make your experience worse.

1369
01:26:28,020 --> 01:26:34,840
So at this point, I think that the commercial model we are going to build is not going to be based on premium features for the end users.

1370
01:26:35,780 --> 01:26:41,720
We may offer some badges, we may offer some tokens, but that's not the core of our strategy.

1371
01:26:42,200 --> 01:26:46,320
The core strategy is, again, we're going back to the principle of open web.

1372
01:26:46,820 --> 01:26:49,600
How open web got commercialized, right?

1373
01:26:50,240 --> 01:26:54,560
It created a platform for people to build businesses and communities.

1374
01:26:55,760 --> 01:27:01,540
And those communities are effectively, and businesses are paying customers of the web.

1375
01:27:01,820 --> 01:27:05,180
You don't pay to use the web, right?

1376
01:27:05,260 --> 01:27:06,480
You don't pay for the browser.

1377
01:27:06,740 --> 01:27:08,180
You don't pay for accessing the website.

1378
01:27:08,340 --> 01:27:11,460
Some websites try to charge for access, but that's their own decisions, right?

1379
01:27:11,700 --> 01:27:14,400
But fundamentally, the web is free to access for everybody.

1380
01:27:15,420 --> 01:27:16,500
But it's not free to host.

1381
01:27:16,900 --> 01:27:19,660
If you want to host a website, you have to pay some money.

1382
01:27:19,860 --> 01:27:23,060
What you get in return, you get 100% control of technology you use.

1383
01:27:23,060 --> 01:27:24,820
You get 100% control of your audience.

1384
01:27:25,060 --> 01:27:26,720
you get 100% control of your content.

1385
01:27:27,040 --> 01:27:30,640
You don't surrender IP ownership in any way or shape or form.

1386
01:27:31,040 --> 01:27:33,440
You have 100% control and ownership.

1387
01:27:33,800 --> 01:27:36,520
That's a classic what's called B2B2C model.

1388
01:27:37,540 --> 01:27:40,660
So we as a business want to see our customers,

1389
01:27:41,540 --> 01:27:44,580
other businesses or non-commercial communities

1390
01:27:44,940 --> 01:27:47,400
that use the network to host content,

1391
01:27:47,540 --> 01:27:49,820
to host communities, to engage those communities,

1392
01:27:50,400 --> 01:27:51,660
and they will be their customers.

1393
01:27:52,400 --> 01:27:53,380
My view is very simple.

1394
01:27:53,600 --> 01:27:57,200
this community should somehow cover the hosts and costs

1395
01:27:58,120 --> 01:28:00,720
in a way that creates profit for hosts and operators.

1396
01:28:01,120 --> 01:28:02,200
How will it cover the costs?

1397
01:28:02,820 --> 01:28:04,560
Maybe the community is created by somebody

1398
01:28:04,600 --> 01:28:07,180
who has some spare cash and want to spend it, right?

1399
01:28:07,520 --> 01:28:09,600
Or maybe the members of community will donate.

1400
01:28:11,200 --> 01:28:12,960
So we run some estimate, unit economics work.

1401
01:28:13,020 --> 01:28:14,480
So estimate is very simple.

1402
01:28:14,500 --> 01:28:16,620
So if community has, say, 10,000 members

1403
01:28:17,300 --> 01:28:19,360
and hosts, say, 10 gigabytes of file,

1404
01:28:19,940 --> 01:28:22,919
the price for this community on SimpleX network

1405
01:28:22,940 --> 01:28:29,060
will be something around five to seven dollars a month that will provide very healthy profit margins

1406
01:28:29,280 --> 01:28:34,340
for network operators privacy to community owners how they cover this five seven dollars a month i

1407
01:28:34,360 --> 01:28:39,600
honestly don't care but they get an exchange much more than they get for effective so effectively

1408
01:28:39,780 --> 01:28:45,080
for a price of website maybe slightly more than website but with website you don't get technology

1409
01:28:45,100 --> 01:28:51,880
right you get technology and the hosting and that's all in the ballpark of the website but you don't

1410
01:28:51,840 --> 01:28:56,260
have to develop messaging, you don't have to move files around as you described, it just

1411
01:28:56,350 --> 01:28:57,380
works out of the box, right?

1412
01:28:58,760 --> 01:29:00,500
So that's the model they're going for.

1413
01:29:00,900 --> 01:29:08,240
When communities effectively cover the costs of the network and the end users use, some

1414
01:29:08,250 --> 01:29:11,520
of the end users may donate to their communities and that will cover their costs, right?

1415
01:29:11,570 --> 01:29:15,060
So how they, or maybe it's communities run by the business and it's marketing expense

1416
01:29:15,150 --> 01:29:15,400
for them.

1417
01:29:16,240 --> 01:29:21,800
It shouldn't, it's like in the same way as web browser developers and web service developers

1418
01:29:21,840 --> 01:29:27,260
don't care how each website does their business and what source of money they use to cover

1419
01:29:27,320 --> 01:29:27,940
their costs, right?

1420
01:29:28,100 --> 01:29:32,680
Each website has their own commercial model, but all the hosts and companies care about

1421
01:29:32,760 --> 01:29:34,080
that they pay their bills, right?

1422
01:29:34,140 --> 01:29:35,680
And they're rather small bills.

1423
01:29:36,100 --> 01:29:38,520
If it's a small site, we're talking about several dollars a month.

1424
01:29:39,080 --> 01:29:40,600
If it's a large size, it can be substantial.

1425
01:29:41,220 --> 01:29:46,080
So the good thing about this model compared with premium model, premium model is rather

1426
01:29:46,280 --> 01:29:46,860
uniform, right?

1427
01:29:47,120 --> 01:29:50,580
Each user on their own, and you can't get too much money from a user.

1428
01:29:51,100 --> 01:29:54,960
But communities usually follow the parallel distribution, right?

1429
01:29:55,060 --> 01:30:00,600
Like every health network, you get 80% of traffic created by 20% of communities.

1430
01:30:01,220 --> 01:30:03,980
80% of traffic is created by 20% of groups, right?

1431
01:30:04,440 --> 01:30:07,940
So it means that you can make the rest 80% of group free.

1432
01:30:08,660 --> 01:30:10,180
And you only lose 20% of revenue.

1433
01:30:11,460 --> 01:30:15,900
So you charge the heavy users, you get free for everybody else.

1434
01:30:16,380 --> 01:30:20,340
And that kind of creates profits for everybody and sustainability for everybody.

1435
01:30:20,660 --> 01:30:24,280
without asking them to surrender any intellectual property right,

1436
01:30:24,520 --> 01:30:27,340
without asking them to accept the risks that they can be z-platformed,

1437
01:30:27,860 --> 01:30:30,160
because each community can also use multiple operators.

1438
01:30:31,240 --> 01:30:36,100
Even if one of them decides to z-platform, the end users wouldn't even notice that.

1439
01:30:36,520 --> 01:30:40,180
Got it. And then if we put it to kind of the legal side of things,

1440
01:30:40,540 --> 01:30:44,240
so you guys are legally based in the UK, right?

1441
01:30:44,420 --> 01:30:45,260
Correct, yes.

1442
01:30:45,680 --> 01:30:50,200
So with the, you know, I'm sure you get this a lot, and I'm sure people are asking,

1443
01:30:50,600 --> 01:30:54,560
I'm doing a lot of coverage as well on the channel about UK's attacks on encryption,

1444
01:30:54,880 --> 01:30:59,480
what they're doing against Apple, ADP, age verification, all of this stuff.

1445
01:30:59,690 --> 01:31:00,940
Does that impact you guys at all?

1446
01:31:01,260 --> 01:31:03,860
How does that impact what you're doing, if at all?

1447
01:31:04,260 --> 01:31:06,200
I don't think it impacts us in any way.

1448
01:31:06,480 --> 01:31:14,320
We are legally, we have very good legal advice from top tier firms.

1449
01:31:14,440 --> 01:31:17,880
We did it early on and we did analysis of all the applicable legislation.

1450
01:31:18,360 --> 01:31:23,320
So we are legally in a category of web browser developers rather than the server providers.

1451
01:31:24,420 --> 01:31:33,460
So we do not, like, the part of the business that provides software is not really providing any service.

1452
01:31:34,780 --> 01:31:42,680
And the fact that users can use our servers today is very temporary and coincidental, and we really cannot conflate this too, right?

1453
01:31:42,800 --> 01:31:49,760
So, like, can you oblige under the existing legislation web browsers developers to undermine

1454
01:31:50,300 --> 01:31:51,120
encryption in the browser?

1455
01:31:51,430 --> 01:31:52,040
The answer is no.

1456
01:31:52,220 --> 01:31:53,320
There is no legislation for that.

1457
01:31:54,380 --> 01:31:56,140
Not in the UK, nowhere else in the world.

1458
01:31:56,880 --> 01:32:00,620
Yeah, what about, because I'm seeing, definitely, you know, this is early on and it's very

1459
01:32:01,120 --> 01:32:01,400
preliminary.

1460
01:32:01,780 --> 01:32:03,220
It's just a concern that people have.

1461
01:32:03,480 --> 01:32:08,800
But you see cases like the TornadoCache developers where potentially the development of software,

1462
01:32:09,080 --> 01:32:11,120
even if other people do something malicious with it,

1463
01:32:11,120 --> 01:32:14,360
could still jeopardize the people who develop the software,

1464
01:32:14,460 --> 01:32:15,280
if this makes sense.

1465
01:32:15,520 --> 01:32:17,080
Are you guys concerned about a situation

1466
01:32:17,500 --> 01:32:19,400
where you can be held liable

1467
01:32:19,700 --> 01:32:22,660
for what someone else even does with your code?

1468
01:32:23,400 --> 01:32:25,700
I think what matters is the intent.

1469
01:32:25,920 --> 01:32:30,860
We actively develop features that prevent criminal usage.

1470
01:32:31,280 --> 01:32:36,760
We actively remove illegal content from our servers.

1471
01:32:37,100 --> 01:32:40,480
We actually do a lot to prevent such usages.

1472
01:32:40,590 --> 01:32:45,300
And I honestly think that what happened with TornadoCache developers is really bad, and

1473
01:32:45,300 --> 01:32:47,300
we should all be against that.

1474
01:32:47,310 --> 01:32:54,000
But I think TornadoCache was positioned really as something that would facilitate crime,

1475
01:32:54,720 --> 01:32:57,120
and nobody was particularly shy about it.

1476
01:32:58,280 --> 01:33:03,740
And we see what we do as a technology that protects people from crime.

1477
01:33:04,180 --> 01:33:05,520
Criminals can use any technology, right?

1478
01:33:05,660 --> 01:33:11,360
You can buy a car and start killing people, or you can buy a table knife and start killing people.

1479
01:33:11,580 --> 01:33:16,920
They're discussing in the UK that you should provide an instance to buy kitchen knives, right?

1480
01:33:17,620 --> 01:33:19,400
So criminals can use anything.

1481
01:33:19,820 --> 01:33:20,640
That's the problem, right?

1482
01:33:20,760 --> 01:33:32,480
But if technology is purposely developed to enable crime and it's not doing anything to prevent criminal usages at all,

1483
01:33:33,080 --> 01:33:36,180
then the question of neutrality is being raised.

1484
01:33:36,200 --> 01:33:39,640
I disagree with, I think technology should be seen as neutral regardless, right?

1485
01:33:39,760 --> 01:33:40,580
My personal view.

1486
01:33:40,980 --> 01:33:46,440
But I'm just like, also, while it's concerning to see that creators of technology

1487
01:33:46,540 --> 01:33:48,620
are being prosecuted for actions of other people,

1488
01:33:48,720 --> 01:33:50,440
and I don't think it should happen at all,

1489
01:33:51,260 --> 01:33:54,740
I think we take a rather different stance than neutral,

1490
01:33:55,460 --> 01:33:58,740
and our focus is to create technology that protects people from crime.

1491
01:33:59,580 --> 01:34:01,900
The fact that you cannot reach out to the end,

1492
01:34:02,160 --> 01:34:08,540
For example, the common subject, and this was being used in a lobbying of child control legislation in Europe,

1493
01:34:08,840 --> 01:34:11,180
is that children are being exploited, right?

1494
01:34:12,400 --> 01:34:13,680
But they're exploited by design.

1495
01:34:14,340 --> 01:34:21,880
The networks where the children are exploited are designed in a way that children are reachable by anybody.

1496
01:34:22,420 --> 01:34:26,800
And there is an open criminal case against Meta in multiple U.S. states.

1497
01:34:27,940 --> 01:34:33,920
It's a fascinating read if you look at this kind of witness statements and evidence materials

1498
01:34:34,540 --> 01:34:42,600
about how Facebook and meta technology knowingly enable traffic of children to child abusers

1499
01:34:42,830 --> 01:34:44,740
because it creates engagement in the network.

1500
01:34:45,080 --> 01:34:46,240
It's horrendous.

1501
01:34:46,500 --> 01:34:50,360
I think technology should play an active role in protecting its users from crime,

1502
01:34:50,770 --> 01:34:54,600
and it should avoid developing technologies that have purely criminal usages.

1503
01:34:55,480 --> 01:34:57,940
And that's a moral rather than legal view.

1504
01:34:59,020 --> 01:34:59,960
That's what I'm taking.

1505
01:35:00,620 --> 01:35:06,740
And it doesn't mean, even if technology is created in a way that...

1506
01:35:06,740 --> 01:35:09,740
So I think you follow what I'm trying to say.

1507
01:35:09,740 --> 01:35:12,740
I think the prosecution of trying out a developer is completely wrong and corrupt,

1508
01:35:12,900 --> 01:35:14,880
and the legal system should not be doing it.

1509
01:35:14,980 --> 01:35:16,420
It stifles innovation.

1510
01:35:16,630 --> 01:35:17,700
It stifles investment.

1511
01:35:17,810 --> 01:35:19,900
It has more harm than good.

1512
01:35:20,320 --> 01:35:25,340
And in no case, the developers of technology, rather than service providers,

1513
01:35:25,420 --> 01:35:29,560
should be prosecuted for whatever usages this technology has found.

1514
01:35:30,760 --> 01:35:31,620
That's my very strong view,

1515
01:35:31,950 --> 01:35:34,380
which doesn't mean that technology developers

1516
01:35:34,920 --> 01:35:37,940
shouldn't put some thought into how to protect their users from crime

1517
01:35:38,110 --> 01:35:40,780
and how to prevent criminal usages.

1518
01:35:40,910 --> 01:35:43,160
And again, it's not because they're legally obliged,

1519
01:35:43,170 --> 01:35:45,180
but because I think we're morally obliged

1520
01:35:45,790 --> 01:35:48,500
to find the ways that protect our users.

1521
01:35:48,720 --> 01:35:50,020
Earlier this year, for example,

1522
01:35:50,090 --> 01:35:51,940
we published the approach that we're going to take

1523
01:35:52,200 --> 01:35:54,660
how we can do privacy-preserving content moderation.

1524
01:35:55,180 --> 01:35:58,760
We believe that both community owners, but also server owners,

1525
01:35:58,890 --> 01:36:06,960
which have means to respond to user complaints and remove content that they find objectionable, illegal, or whatever, from their servers,

1526
01:36:07,340 --> 01:36:10,920
but it doesn't mean that it has to come by compromising user privacy.

1527
01:36:11,370 --> 01:36:14,040
So we had lots of conversations about that, and it's very controversial.

1528
01:36:14,210 --> 01:36:20,320
But what I'm thinking is we understand the risks, and we understand that there is some war in legal developments,

1529
01:36:20,340 --> 01:36:25,300
but we'll do our best to navigate it and to protect our users.

1530
01:36:26,320 --> 01:36:28,520
Yeah, I wish it was discussed more because it's a bit of a,

1531
01:36:28,980 --> 01:36:31,280
it's a subject people don't want to talk about in the privacy world,

1532
01:36:31,580 --> 01:36:36,200
how there are legitimate situations where there are bad things that are done

1533
01:36:36,340 --> 01:36:40,560
that can actually be prevented within reason without even invading people's privacy.

1534
01:36:40,810 --> 01:36:43,400
And I feel like that is something that should be discussed a bit more.

1535
01:36:43,760 --> 01:36:46,860
One of the big reasons that we shut down our matrix server back in the day

1536
01:36:46,860 --> 01:36:50,860
was because we kept getting spanned with CSAM all the time from people online.

1537
01:36:51,180 --> 01:36:54,220
It's a problem that many other people who host matrix servers were having as well.

1538
01:36:54,800 --> 01:36:58,760
And it's not a healthy community to ever be a part of or join.

1539
01:36:59,030 --> 01:37:03,580
Or like, you know, my goal is for people to associate privacy and digital rights

1540
01:37:03,700 --> 01:37:05,280
with something that's a universal thing.

1541
01:37:05,840 --> 01:37:10,180
And then if they join a server or a community that we are officially endorsing that's part of us

1542
01:37:10,740 --> 01:37:14,100
and they get spanned with CSAM, that's just bad for everybody.

1543
01:37:14,440 --> 01:37:15,760
It's just not a friendly environment.

1544
01:37:16,020 --> 01:37:18,460
So I'm glad that that's something that's being thought about because...

1545
01:37:19,980 --> 01:37:21,240
We're not just thinking about it.

1546
01:37:21,860 --> 01:37:29,880
We're very active in developing measures to prevent criminal usages without compromising privacy and security on everybody else.

1547
01:37:30,120 --> 01:37:36,320
I honestly think, right, like having been engaged with privacy community for four years, I'm going to say something extremely controversial.

1548
01:37:36,520 --> 01:37:40,560
And I think like if I'm not yet hated enough, some more people probably will hate me for that.

1549
01:37:40,900 --> 01:37:45,380
I honestly think that privacy community is compromised and corrupted as a whole.

1550
01:37:46,180 --> 01:37:49,520
Hard to say by whom, but probably by big technology companies.

1551
01:37:49,710 --> 01:37:54,340
And it really has completely lost its direction, right?

1552
01:37:54,460 --> 01:38:01,260
Because ultimately, any kind of leadership should do what benefits most people.

1553
01:38:01,780 --> 01:38:06,840
And most people in the world don't care about privacy, right?

1554
01:38:07,240 --> 01:38:10,960
They see privacy as a hurdle and inconvenience at best.

1555
01:38:11,460 --> 01:38:17,360
And they see privacy as an enabler of criminality towards governments.

1556
01:38:18,630 --> 01:38:26,980
And mass media is very united in attack on the right to privacy using this perception, right?

1557
01:38:28,520 --> 01:38:34,400
And what I see in privacy community is some reasonable people who really want to help everybody,

1558
01:38:34,680 --> 01:38:38,980
educate people, explain them why privacy is important and why it's not a means to an end,

1559
01:38:38,980 --> 01:38:43,820
but it really is the way to have individual security, right? Because imagine all your

1560
01:38:44,020 --> 01:38:47,820
financial information becomes public. You're likely to lose some money. You're likely to become the

1561
01:38:48,180 --> 01:38:54,760
victim of financial crimes, right? Or imagine that your children, like, whereabouts become public.

1562
01:38:55,480 --> 01:39:00,720
Again, you're putting the lives of your children at risk, right? So, and this is something everybody

1563
01:39:00,740 --> 01:39:06,300
cares about but i think privacy community is very focused on technological aspects of privacy and

1564
01:39:06,460 --> 01:39:12,460
legal aspects of privacy and completely doesn't talk to people about how it is a means to an end

1565
01:39:12,600 --> 01:39:19,020
that provides people individual security and freedom right ultimately right freedom to live

1566
01:39:19,050 --> 01:39:26,960
their lives without effect and and what we see is that the same lobby groups finance privacy advocates

1567
01:39:27,440 --> 01:39:32,280
and chat control legislation or non-profits that lobby chat control.

1568
01:39:32,480 --> 01:39:34,740
You can look at the list of non-profits that are lobbying,

1569
01:39:35,140 --> 01:39:36,500
actively lobbying chat control legislation,

1570
01:39:37,040 --> 01:39:39,020
and the sources of funding are exactly the same.

1571
01:39:39,760 --> 01:39:42,220
And what we got to is that privacy communities

1572
01:39:42,380 --> 01:39:44,480
become completely isolated from the rest of the world.

1573
01:39:44,940 --> 01:39:46,980
Literally, it doesn't care about the rest of the world.

1574
01:39:47,100 --> 01:39:51,760
All it cares about retaining the narrative is that privacy is a great thing,

1575
01:39:51,860 --> 01:39:52,760
everybody else is simple.

1576
01:39:53,420 --> 01:39:54,560
That's what we observe, right?

1577
01:39:54,940 --> 01:39:59,100
So I honestly think that the narrative of privacy is dead today.

1578
01:39:59,800 --> 01:40:02,120
And the best we can do is to refocus our efforts

1579
01:40:02,290 --> 01:40:04,000
and to provide some people individual security

1580
01:40:05,200 --> 01:40:07,940
and technology that protects them, protects their lives,

1581
01:40:08,180 --> 01:40:12,040
protects their children, protects them from cyber crime.

1582
01:40:12,440 --> 01:40:13,940
We're not going to compromise on privacy.

1583
01:40:14,070 --> 01:40:16,900
But again, I honestly think selling people privacy today

1584
01:40:17,440 --> 01:40:19,080
is almost like selling people HTTPS.

1585
01:40:19,270 --> 01:40:19,680
What is it?

1586
01:40:19,910 --> 01:40:21,040
Who knows what's HTTPS?

1587
01:40:21,360 --> 01:40:24,820
But you go to the website and you know it's secure because of HTTPS, right?

1588
01:40:24,920 --> 01:40:26,120
You don't know what HTTPS is.

1589
01:40:26,120 --> 01:40:27,220
You never heard about it, right?

1590
01:40:27,620 --> 01:40:29,620
So I honestly want to be in a world

1591
01:40:29,740 --> 01:40:31,160
when people don't know what privacy is.

1592
01:40:31,340 --> 01:40:32,180
Don't need to know that.

1593
01:40:32,330 --> 01:40:33,980
They just use technology that protects them.

1594
01:40:34,720 --> 01:40:35,700
Yeah, there's a lot there.

1595
01:40:37,820 --> 01:40:39,560
Yeah, I think, at least on my end,

1596
01:40:39,750 --> 01:40:41,980
I think there are a lot of people who see privacy this way.

1597
01:40:42,390 --> 01:40:43,120
And I see it a lot.

1598
01:40:43,900 --> 01:40:45,880
I know a lot of the listeners on our show

1599
01:40:45,950 --> 01:40:47,440
and stuff like this see it that way.

1600
01:40:47,760 --> 01:40:50,120
I feel like the people who are chronically online all day,

1601
01:40:50,520 --> 01:40:53,440
who like the identity becomes privacy

1602
01:40:53,520 --> 01:40:55,620
and then privacy is an end instead of a means.

1603
01:40:57,020 --> 01:40:57,760
That's where you see the problem.

1604
01:40:57,760 --> 01:40:59,460
But those are also typically the loudest people.

1605
01:40:59,660 --> 01:41:02,080
So it's really hard to make sense of everything going on.

1606
01:41:02,380 --> 01:41:05,240
But there are a lot of people who see it this way too.

1607
01:41:05,620 --> 01:41:07,480
100%. Look, I think what you do is really important

1608
01:41:07,650 --> 01:41:09,720
because you're trying to connect the world of,

1609
01:41:09,900 --> 01:41:11,360
and you're being criticized a lot for that.

1610
01:41:11,540 --> 01:41:14,380
Instead of being focused on the privacy elite,

1611
01:41:14,500 --> 01:41:16,660
you're trying to connect those technological concepts.

1612
01:41:16,920 --> 01:41:18,660
You're trying to connect the concepts of security

1613
01:41:18,790 --> 01:41:19,960
to mass market people, right?

1614
01:41:20,340 --> 01:41:22,260
So our engagement with each other

1615
01:41:22,280 --> 01:41:27,980
started that you said, I'm not going to recommend SimpleXUp because it's not ready for our audience.

1616
01:41:28,030 --> 01:41:28,800
Look, I'm not criticizing.

1617
01:41:29,350 --> 01:41:32,500
And when people said, like I said, that's fantastic because it means that this man cares

1618
01:41:32,550 --> 01:41:39,020
about their audience more than he cares about a small niche of privacy enthusiasts that nobody

1619
01:41:39,130 --> 01:41:41,920
cares about, which is critically important, I think.

1620
01:41:42,060 --> 01:41:43,480
And we see it in the same way.

1621
01:41:43,510 --> 01:41:48,001
We want really to build technology that will benefit the majority of people and not purely

1622
01:41:48,020 --> 01:41:54,340
a niche tool that can benefit only a tiny minority and half of them will be criminal users, right?

1623
01:41:54,560 --> 01:41:59,800
Unfortunately, right? It's a mindset shift that people need to make. So I just yesterday at the

1624
01:41:59,800 --> 01:42:06,280
time of recording, I put out a video on how F-Droid put out a blog pretty much saying, hey, due to

1625
01:42:06,540 --> 01:42:10,920
Google's new developer restrictions, it might kill F-Droid. The whole concept of F-Droid because

1626
01:42:11,220 --> 01:42:16,940
Google is essentially trying to end the whole... It's horrible. Yeah, of sideloading. And a lot of

1627
01:42:16,920 --> 01:42:20,280
people in the comments, and I actually addressed this because I already did coverage for this

1628
01:42:20,580 --> 01:42:24,320
back when Google announced this measure, and now FDroid talked about it, and then I covered FDroid's

1629
01:42:24,520 --> 01:42:29,120
response, essentially. A lot of people are saying, well, guess it's time to move to a custom ROM,

1630
01:42:30,580 --> 01:42:35,740
or good thing I'm going to move to a custom ROM now, or, you know, it's all about,

1631
01:42:37,300 --> 01:42:42,981
it's not about what's, like, the workaround, you know, it's not about what you can figure out to do

1632
01:42:43,000 --> 01:42:48,840
for yourself. It's about the fact that like 99% of people are never going to install a custom ROM.

1633
01:42:49,120 --> 01:42:53,020
Don't even know what that is. Don't even know what we're talking about. They don't know what

1634
01:42:53,180 --> 01:42:58,280
sideloading even is as a concept. To them, installing an app is just going to the Play Store.

1635
01:42:59,180 --> 01:43:03,980
And they don't actually know what they're losing because this is a pretty new concept to them. So

1636
01:43:04,260 --> 01:43:10,321
it's much more important to figure out like how to take this message and apply it to 99% of people

1637
01:43:10,340 --> 01:43:13,480
and make them realize, hey, there's this beautiful thing on your Android device you don't actually

1638
01:43:13,640 --> 01:43:18,440
know about that Google's trying to strip away, which is going to over time ruin the ecosystem

1639
01:43:18,660 --> 01:43:22,440
on Android and you're not even going to see it happen. That's a better argument. That's something

1640
01:43:22,440 --> 01:43:26,360
that needs to happen more than, oh, so how do we get around what's going on for each of you

1641
01:43:26,980 --> 01:43:33,260
500 people who know what you're doing? So side rant, but it is something I do see. But again,

1642
01:43:33,660 --> 01:43:38,700
when you do speak to the right people, the message is a lot louder. Like that video I put out

1643
01:43:38,700 --> 01:43:42,860
yesterday, it's reaching a lot more people than it would be than if I just said, here's how to get

1644
01:43:43,640 --> 01:43:49,540
around the F-Droid restrictions that might happen next year. That'll reach not even a hundredth of

1645
01:43:49,600 --> 01:43:53,580
the people as if you actually speak to the masses. So I think it's the right approach you guys are

1646
01:43:53,700 --> 01:43:58,440
taking as well. Yes. And we want, you're absolutely right, Henry. And we want to build technology for

1647
01:43:58,500 --> 01:44:05,380
majority. And that's why we are looking again to raise more funds without losing control again.

1648
01:44:05,740 --> 01:44:09,420
And this time we're going to do community-driven fundraise.

1649
01:44:09,480 --> 01:44:14,720
There will be, again, we're going to innovate cryptocurrency space as much as we innovated messaging.

1650
01:44:14,860 --> 01:44:20,720
So we have created a new design for payment solution for infrastructure capacity.

1651
01:44:20,880 --> 01:44:22,800
There will be utility token raised next year.

1652
01:44:22,820 --> 01:44:26,740
So there will be some big announcements from us this year.

1653
01:44:26,840 --> 01:44:31,620
So we'll announce this with lots of details, how the payments work.

1654
01:44:31,700 --> 01:44:36,640
I was talking before about B2B2C model, but that means that people have to pay for these services.

1655
01:44:37,360 --> 01:44:45,400
So we figured out the design that protects privacy without going into any compliance and financial regulation territory.

1656
01:44:46,300 --> 01:44:53,260
So yeah, I think it's really important to build technology for a wide range of users because then it can have security.

1657
01:44:53,340 --> 01:44:55,360
Then it can have resources to provide users.

1658
01:44:55,560 --> 01:44:56,620
And it's simply impossible.

1659
01:44:56,700 --> 01:44:58,520
If you stay in the niche, you die in the niche.

1660
01:44:58,540 --> 01:45:01,860
You simply never get enough resources to get a high-quality product.

1661
01:45:02,020 --> 01:45:03,480
People compare what we do with Telegram,

1662
01:45:03,660 --> 01:45:07,040
but Telegram has, what, 100 times more investment in the product, right?

1663
01:45:07,460 --> 01:45:10,900
Or WhatsApp, which has 500 times more investment into the product yet.

1664
01:45:11,260 --> 01:45:15,320
So it's literally impossible to build great and polished user experience

1665
01:45:16,440 --> 01:45:17,800
with the niche users, right?

1666
01:45:17,960 --> 01:45:20,840
You need to grow beyond this niche to improve quality for everybody.

1667
01:45:22,080 --> 01:45:26,240
So, yeah, that's why it's important to build for everybody.

1668
01:45:26,920 --> 01:45:28,940
Yeah, so what's next for you guys?

1669
01:45:29,340 --> 01:45:30,920
You kind of teased a new payment thing,

1670
01:45:30,960 --> 01:45:33,260
but is there anything else that people can expect that you can share?

1671
01:45:33,760 --> 01:45:37,620
Our current focus is channels, development focus, right?

1672
01:45:37,640 --> 01:45:41,060
So people will be able to host Telegram-style channels

1673
01:45:41,320 --> 01:45:43,720
that actually will work and scale to tens

1674
01:45:43,880 --> 01:45:45,940
and probably hundreds of thousands of followers.

1675
01:45:46,700 --> 01:45:49,580
We see a lot of interest from Telegram communities

1676
01:45:49,660 --> 01:45:51,440
to migrate to SimpleX network,

1677
01:45:51,980 --> 01:45:53,960
exactly because it gives them ownership of content,

1678
01:45:54,320 --> 01:45:56,640
ownership of the audience and control and security.

1679
01:45:57,280 --> 01:46:03,140
so that that's one big development that should land this year and at least as some better experiment

1680
01:46:03,760 --> 01:46:10,440
and uh for utility token asians this is something that will happen uh next year preliminary plan

1681
01:46:10,780 --> 01:46:17,380
end of march but there will be a preliminary registration for this token race so we kind of

1682
01:46:17,500 --> 01:46:24,579
working on the detail of this and the announcement should happen within probably this month we don't

1683
01:46:24,460 --> 01:46:25,740
have exact date for this announcement.

1684
01:46:26,000 --> 01:46:31,300
We're recording in October, if all future people are listening to this.

1685
01:46:32,060 --> 01:46:32,320
Yes.

1686
01:46:33,040 --> 01:46:40,160
So if it goes live in about a month, you may even have the link to the announcement put

1687
01:46:40,340 --> 01:46:41,560
next to the video, what we're talking about.

1688
01:46:42,220 --> 01:46:46,900
But I think it's great because I looked at lots of tokenations and they all look like

1689
01:46:47,080 --> 01:46:48,980
a scam to me, frankly, right?

1690
01:46:49,040 --> 01:46:52,660
Lots of money being pilfered by the people who create tokens.

1691
01:46:53,000 --> 01:46:59,600
absolutely we literally want to create a utility token that will be have one current and variety

1692
01:46:59,680 --> 01:47:06,580
of future usages that will be used to develop and to provide the technology where uh the team will

1693
01:47:06,720 --> 01:47:13,460
not get any any extraordinary financial rewards and no tokens allocated to the team other than

1694
01:47:13,840 --> 01:47:19,061
just from growing the business growing the technology growing the network so super transparent

1695
01:47:19,080 --> 01:47:27,820
super focused so we effectively will be doing token issuance in a very very focused way and it will be

1696
01:47:28,040 --> 01:47:32,720
used to both provide some services straight at the point of issues so that's why it's utility token

1697
01:47:32,850 --> 01:47:37,480
so people will be able to pay for channels and for communities to increase hosting capacity to

1698
01:47:37,680 --> 01:47:44,179
increase the number of members it can hold so yeah and but but that will also allow to develop the

1699
01:47:44,120 --> 01:47:49,800
future technology when the same payment mechanisms will be able to provide payment security and

1700
01:47:50,020 --> 01:47:56,220
privacy. So effectively, even if you use usual money to pay for your community, you still can

1701
01:47:57,160 --> 01:48:01,840
preserve the privacy of your identity. That can be very important for some situations. You may

1702
01:48:02,900 --> 01:48:08,179
publish completely legal content, but it may be sufficiently controversial and you don't want to

1703
01:48:08,120 --> 01:48:09,720
be exposed, right?

1704
01:48:10,000 --> 01:48:15,320
And if your payment connects to your usage, then somebody can leak this information as

1705
01:48:15,380 --> 01:48:16,560
we've seen happening, right?

1706
01:48:16,640 --> 01:48:22,000
And then people get attacked in real life for whatever opinions they publish online.

1707
01:48:22,230 --> 01:48:26,620
So I think for freedom of speech, you know, it's interesting that my whole motivation for

1708
01:48:26,720 --> 01:48:28,060
developing this network was not privacy.

1709
01:48:28,210 --> 01:48:31,440
I never thought privacy is an interesting thing, frankly.

1710
01:48:31,490 --> 01:48:33,160
I was more interested in freedom of speech.

1711
01:48:33,220 --> 01:48:35,260
I historically have a long history with publishing.

1712
01:48:36,220 --> 01:48:38,600
In my old life, I owned a magazine.

1713
01:48:38,730 --> 01:48:40,620
I worked in several publishing organizations.

1714
01:48:40,840 --> 01:48:42,800
Then I led the development team in MailOnline.

1715
01:48:43,200 --> 01:48:47,560
So to me, publishing and freedom of speech and messaging are all like two sides of the

1716
01:48:47,720 --> 01:48:48,140
same coin.

1717
01:48:48,290 --> 01:48:52,460
And I was looking for technology that can really provide freedom of speech and control

1718
01:48:52,550 --> 01:48:53,680
to small publishers, right?

1719
01:48:53,840 --> 01:48:58,781
Because there is literally no platform in the world when a small publisher, an individual

1720
01:48:58,780 --> 01:49:04,800
journalist can engage with their audience and have control of this audience right so that like

1721
01:49:05,060 --> 01:49:10,360
whoever gives them service can't delete them from existence like it happens on social networks right

1722
01:49:10,920 --> 01:49:16,140
so they either have to trust facebook or twitter to not delete them or they have to go to work to

1723
01:49:16,140 --> 01:49:20,120
some large publishing organization which will have their own views about what's right and what's wrong

1724
01:49:21,240 --> 01:49:26,081
and to me uh it's interesting that this starts at approximately the same time as noster

1725
01:49:26,400 --> 01:49:33,020
If you look at the first paper about Nostra, it was published pretty much at the same time we had the first design of the protocol.

1726
01:49:33,540 --> 01:49:44,020
But to me, it was more important to protect people's real identities to achieve freedom of speech than to provide technical censorship resistance.

1727
01:49:44,340 --> 01:49:48,900
Because Nostra focuses, okay, let's put the content on multiple servers so it's hard to delete.

1728
01:49:49,360 --> 01:49:49,860
That's simple.

1729
01:49:50,300 --> 01:49:52,580
I was always seeing it as a simple problem to solve.

1730
01:49:52,960 --> 01:49:54,220
And that's not the core problem.

1731
01:49:54,340 --> 01:49:58,440
The core problem is not content being delisted, but people being attacked in real life, right?

1732
01:49:58,540 --> 01:50:04,460
Their bank accounts being closed or they're being fired from their jobs because they say something unpopular, right?

1733
01:50:04,760 --> 01:50:07,520
Or they literally get physically attacked in real life.

1734
01:50:08,180 --> 01:50:16,120
And if you really want, you know, like Oscar Wilde said, you want somebody to say the truth, you give them a mask.

1735
01:50:16,440 --> 01:50:22,300
If you want the man to say the truth, you give this literal quote from like more than 100 years ago.

1736
01:50:22,820 --> 01:50:23,620
Nothing's changed, right?

1737
01:50:23,760 --> 01:50:29,560
it's only possible for people to be open and honest about their opinions if their identities

1738
01:50:29,700 --> 01:50:36,160
are protected it's really hard to discuss controversial subjects if your identity is

1739
01:50:36,600 --> 01:50:42,580
known and it's very important that we can discuss those identities freely and securely

1740
01:50:43,320 --> 01:50:51,382
because otherwise society will stagnate it wouldn't be able to get better right so that's that's

1741
01:50:51,400 --> 01:50:56,460
That's fundamentally the mission and the vision and what keeps us working.

1742
01:50:57,440 --> 01:50:57,960
Right.

1743
01:50:57,990 --> 01:51:01,700
So if people are interested in you or SimpleX, where can they find you?

1744
01:51:02,760 --> 01:51:05,360
I have an website called simplex.chat.

1745
01:51:05,540 --> 01:51:08,640
There is an app called SimpleX Chat on App Stores.

1746
01:51:09,360 --> 01:51:11,520
You can connect to our tip right by the app.

1747
01:51:11,520 --> 01:51:14,880
You can find some communities on SimpleX Network-wide website.

1748
01:51:15,940 --> 01:51:21,100
They're really interesting and vibrant discussions about interesting things.

1749
01:51:21,460 --> 01:51:28,340
most are focused on technology and cryptocurrency and privacy and security but some also like about

1750
01:51:28,560 --> 01:51:34,040
lifestyle for example there are like some communities about algorithm or whatever so yeah

1751
01:51:34,040 --> 01:51:38,740
so so yeah i think i think i think we have a very interesting very small yeah that's very early days

1752
01:51:39,000 --> 01:51:43,900
it's less it's close to 500 less than 500 communities there are groups listed in the

1753
01:51:44,020 --> 01:51:49,042
directory they're very selective because we really have limited resources to observe but they're great

1754
01:51:49,060 --> 01:51:54,060
people. They have their engagement with them and they're contributing a lot to product development

1755
01:51:54,240 --> 01:51:59,560
as well. But I mean, opinions, advice, suggestions. So I'm hugely grateful to all these people who

1756
01:52:00,060 --> 01:52:03,860
made SimpleX Network what it is. Without people, it wouldn't exist.

1757
01:52:04,820 --> 01:52:10,140
Very cool. Well, thank you for your time. I know we were recording two hours. It's going to be a

1758
01:52:10,140 --> 01:52:16,780
long one. Henry, I really appreciate you doing what you're doing. That's fantastic. Thank you so much.

1759
01:52:17,260 --> 01:52:17,900
And thanks, Evgeny.

1760
01:52:18,820 --> 01:52:20,140
And with all of that said,

1761
01:52:20,190 --> 01:52:21,640
I want to thank you all for being here

1762
01:52:21,860 --> 01:52:24,200
and learning more about how the technology you use

1763
01:52:24,290 --> 01:52:25,180
works behind the scenes.

1764
01:52:25,520 --> 01:52:26,880
And so you can better educate yourself

1765
01:52:27,260 --> 01:52:28,480
as well as the people around you.

1766
01:52:28,650 --> 01:52:30,260
I also want to thank Evgeny for being on.

1767
01:52:30,560 --> 01:52:32,280
And if you like these free interviews

1768
01:52:32,450 --> 01:52:33,540
and you want them to keep coming

1769
01:52:33,710 --> 01:52:35,180
and you guys get a lot of value from it,

1770
01:52:35,460 --> 01:52:36,520
consider supporting TechLaur.

1771
01:52:36,600 --> 01:52:37,760
We have a lot of ways to do it.

1772
01:52:37,790 --> 01:52:40,260
There are free methods down below on our website,

1773
01:52:40,540 --> 01:52:41,960
which include using affiliate links,

1774
01:52:42,240 --> 01:52:42,900
sharing our content.

1775
01:52:43,300 --> 01:52:44,400
And of course, there's paid options

1776
01:52:44,540 --> 01:52:45,540
like becoming a TechLaurian,

1777
01:52:45,800 --> 01:52:47,820
getting access to some of our exclusive communities,

1778
01:52:48,250 --> 01:52:49,800
and also getting access to early content

1779
01:52:50,080 --> 01:52:51,520
and other things out there as well.

1780
01:52:51,630 --> 01:52:53,380
So go check out all the ways to support Techlore.

1781
01:52:53,710 --> 01:52:55,000
And thank you all for watching again.

1782
01:52:55,260 --> 01:52:57,400
I'll see you next time on Techlore Talks.