1"use strict";(self.webpackChunkuser_handbook=self.webpackChunkuser_handbook||[]).push([[1565],{2869:(e,t,n)=>{n.r(t),n.d(t,{assets:()=>h,contentTitle:()=>a,default:()=>d,frontMatter:()=>o,metadata:()=>s,toc:()=>l});var r=n(5893),i=n(1151);const o={title:"Path to Hybrid Groups",description:"A look at how we plan on implementing the next generation of Cwtch multi-party messaging",slug:"path-to-hybrid-groups",tags:["cwtch","hybrid-groups"],image:"/img/hybridgroups.png",hide_table_of_contents:!1,toc_max_heading_level:4,authors:[{name:"Sarah Jamie Lewis",title:"Executive Director, Open Privacy Research Society",image_url:"/img/sarah.jpg"}]},a=void 0,s={permalink:"/blog/path-to-hybrid-groups",source:"@site/blog/2024-01-05-path-to-hybrid-groups.md",title:"Path to Hybrid Groups",description:"A look at how we plan on implementing the next generation of Cwtch multi-party messaging",date:"2024-01-05T00:00:00.000Z",formattedDate:"January 5, 2024",tags:[{label:"cwtch",permalink:"/blog/tags/cwtch"},{label:"hybrid-groups",permalink:"/blog/tags/hybrid-groups"}],readingTime:5.31,hasTruncateMarker:!0,authors:[{name:"Sarah Jamie Lewis",title:"Executive Director, Open Privacy Research Society",image_url:"/img/sarah.jpg",imageURL:"/img/sarah.jpg"}],frontMatter:{title:"Path to Hybrid Groups",description:"A look at how we plan on implementing the next generation of Cwtch multi-party messaging",slug:"path-to-hybri
1d-groups",tags:["cwtch","hybrid-groups"],image:"/img/hybridgroups.png",hide_table_of_contents:!1,toc_max_heading_level:4,authors:[{name:"Sarah Jamie Lewis",title:"Executive Director, Open Privacy Research Society",image_url:"/img/sarah.jpg",imageURL:"/img/sarah.jpg"}]},unlisted:!1,prevItem:{title:"Enhanced Permissions",permalink:"/blog/enhanced-permissions"},nextItem:{title:"Cwtch 1.13 Stable Release Candidate",permalink:"/blog/cwtch-1-13"}},h={authorsImageUrls:[void 0]},l=[{value:"The Problem with Cwtch Groups",id:"the-problem-with-cwtch-groups",level:2},{value:"What Are Hybrid Groups?",id:"what-are-hybrid-groups",level:2},{value:"Levels of Hybrid Groups",id:"levels-of-hybrid-groups",level:3},{value:"Group Messaging Metadata",id:"group-messaging-metadata",level:2},{value:"A Rough Timeline (Q1: Week 0 - Week 10 2024)",id:"a-rough-timeline-q1-week-0---week-10-2024",level:2},{value:"Stay up to date!",id:"stay-up-to-date",level:2},{value:"Help us go further!",id:"help-us-go-further",level:2}];function c(e){const t={a:"a",em:"em",h2:"h2",h3:"h3",img:"img",li:"li",p:"p",strong:"strong",ul:"ul",...(0,i.a)(),...e.components};return(0,r.jsxs)(r.Fragment,{children:[(0,r.jsxs)(t.p,{children:["Back in ",(0,r.jsx)(t.a,{href:"/blog/cwtch-1-13",children:"September 2023 we released Cwtch 1.13"}),", the first version of Cwtch to be labelled as ",(0,r.jsx)(t.strong,{children:"stable"}),",\nand a major milestone in Cwtch development."]}),"\n",(0,r.jsxs)(t.p,{children:["With the Cwtch interface now stable, we are in a position to begin a new phase in Cwtch development: a Path towards\n",(0,r.jsx)(t.strong,{children:"Hybrid Groups"}),"."]}),"\n",(0,r.jsx)(t.p,{children:(0,r.jsx)(t.img,{src:n(1385).Z+"",width:"1005",height:"481"})}),"\n",(0,r.jsx)(t.h2,{id:"the-problem-with-cwtch-groups",children:"The Problem with Cwtch Groups"}),"\n",(0,r.jsxs)(t.p,{children:["One of the unique features of Cwtch is that ",(0,r.jsx)(t.a,{href:"/docs/groups/introduction",children:"groups"})," are dependent on ",(0,r.jsx)(t.a,{href:"/security/components/cwtch/server",children:"untrusted infrastructure"}),"."]}),"\n",(0,r.jsx)(t.p,{children:"Because of this, at their most basic, a Cwtch group is simply an agreement between a set of peers on a common\ncryptographic key, and a common (set of) untrusted server(s)."}),"\n",(0,r.jsx)(t.p,{children:"This provides Cwtch Groups with very nice properties such as anonymity to anyone not in the group, but it does mean\nthat certain other nice properties like member flexibility, and credential rotation are difficult to achieve."}),"\n",(0,r.jsx)(t.p,{children:"We want to allow people to make the right trade-off when it comes to their own risk models, i.e. to be able to trade\nefficiency for trust when that decision makes sense."}),"\n",(0,r.jsxs)(t.p,{children:["To do that we need to introduce a new class of group into Cwtch, something we are calling ",(0,r.jsx)(t.strong,{children:"Hybrid Groups"}),"."]}),"\n",(0,r.jsx)(t.h2,{id:"what-are-hybrid-groups",children:"What Are Hybrid Groups?"}),"\n",(0,r.jsx)(t.p,{children:"The goal of hybrid groups is to balance the security properties of Cwtch peer-to-peer communication with the\nproperties of untrusted infrastructure."}),"\n",(0,r.jsx)(t.p,{children:"This is done by augmenting existing Cwtch Groups with an additional layer of peer-to-peer communication in order to provide\nefficient participant management, key rotation, and other useful features."}),"\n",(0,r.jsx)(t.h3,{id:"levels-of-hybrid-groups",children:"Levels of Hybrid Groups"}),"\n",(0,r.jsx)(t.p,{children:"In practice, we imagine there will be a few different levels of Hybrid Group, reflecting different trade-offs between inter-peer trust,\ncommunication efficiency, and group security."}),"\n",(0,r.jsxs)(t.p,{children:["There are ",(0,r.jsx)(t.strong,{children:"Traditional Groups"}),", these have similar properties to the existing Cwtch Groups. Highly inefficient, but essentially\nrequire zero-trust on behalf of participants other than an expectation that the key is kept secret."]}),"\n",(0,r.jsxs)(t.p,{children:["We plan to introduce ",(0,r.jsx)(t.strong,{children:"Managed Groups"}),": A new kind of group where all participants explicitly trust a given always-online peer (e.g. a bot) with group operations. These\nwill be highly efficie
1nt, at the cost of that explicit trust (if that peer behaves maliciously then certain properties are broken). Managed groups will\nbe the first Cwtch groups to allow ",(0,r.jsx)(t.strong,{children:"Contractable"})," and ",(0,r.jsx)(t.strong,{children:"Expandable"})," groups, and more efficient ",(0,r.jsx)(t.strong,{children:"Key Rotation"}),"."]}),"\n",(0,r.jsxs)(t.p,{children:["To start with this ",(0,r.jsx)(t.em,{children:"trusted peer"})," will take the form of an external bot (powered by ",(0,r.jsx)(t.a,{href:"/developing/building-a-cwtch-app/building-an-echobot",children:"a cwtch bot framework"}),") however we\neventually plan to expose this capability as part of the Cwtch UI."]}),"\n",(0,r.jsxs)(t.p,{children:["And finally a category of ",(0,r.jsx)(t.strong,{children:"Augmented Groups"}),": An extension of Managed Groups that places configurable restrictions of the trust given to\nthe peer e.g. by requiring participants to take part in a meta-protocol that confirms certain actions before they are carried out (preventing\nthe trusted-peer from harming properties like ",(0,r.jsx)(t.strong,{children:"Participant Consistency"}),"."]}),"\n",(0,r.jsx)(t.h2,{id:"group-messaging-metadata",children:"Group Messaging Metadata"}),"\n",(0,r.jsx)(t.p,{children:"As with the rest of Cwtch, our ultimate goal is that no metadata (and specifically as part of this work, no group metadata e.g. membership, message timing) be\navailable to a party outside of the group."}),"\n",(0,r.jsx)(t.p,{children:"Traditional Cwtch Groups take this to the extreme, and the expense of long syncing times, and a high possibility of disruption. Managed Groups\nand Augmented groups will allow communities to make the right trade-offs allowing for greater resilience and faster syncing."}),"\n",(0,r.jsx)(t.h2,{id:"a-rough-timeline-q1-week-0---week-10-2024",children:"A Rough Timeline (Q1: Week 0 - Week 10 2024)"}),"\n",(0,r.jsxs)(t.ul,{children:["\n",(0,r.jsxs)(t.li,{children:[(0,r.jsx)(t.strong,{children:"Week 0"})," - Planning Q1 Cwtch Timeline (this devlog), minor bug fixes and other small UI-focused work originating from reports and feedback\nfrom ",(0,r.jsx)(t.a,{href:"/docs/contribute/testing",children:"Cwtch testers"}),"."]}),"\n",(0,r.jsxs)(t.li,{children:[(0,r.jsx)(t.strong,{children:"Week 1"})," - Work begins on exposing ",(0,r.jsx)(t.strong,{children:"Enhanced Permissions"})," in the Cwtch library. These are essential to implementing many of the aspects\nof the new group design, as well as improving other parts of contact management. (Expect more about this in a future devlog). Also, a formal model for Managed Groups will be created and documented.\nThis will form the basis of the implementation."]}),"\n",(0,r.jsxs)(t.li,{children:[(0,r.jsx)(t.strong,{children:"Week 2"})," - At this point we should be able to begin designing the Managed Group Extension to Cwtch. This will use the Cwtch Event Hooks API\nto respond to Peer events to manage groups. During this work, we also expect to migrate the legacy group code into it's own similar extension to make\nbest use of the APIs."]}),"\n",(0,r.jsxs)(t.li,{children:[(0,r.jsx)(t.strong,{children:"Week 3"})," - Towards the end of January we expect to have a complete formal model of Managed Groups and to be able to start integrating the new extensions into the\nCwtch-UI. We also expect to be in the process of releasing a new 1.14 version of Cwtch that supports Enhanced Permissions."]}),"\n",(0,r.jsxs)(t.li,{children:[(0,r.jsx)(t.strong,{children:"Weeks 4 - Week 6"})," - February marks the 6th anniversary of the founding of ",(0,r.jsx)(t.a,{href:"https://openprivacy.ca",children:"Open Privacy Research Society"}),", and our organizational year end. During this\ntime core members of the Cwtch team are often involved in administrative tasks that need to be done during this time, as such we are not planning to make too much progress on Cwtch during this time."]}),"\n",(0,r.jsxs)(t.li,{children:[(0,r.jsx)(t.strong,{children:"Weeks 7 - Week 10"})," - As we approach March, we will be formally integrating Managed Groups in Cwtch, and planning a Cwtch 1.15 release which will feature the new group type. During this time we will also be updating\nCwtch ",(0,r.jsx)(t.a,{href:"https://docs.cwtch.im/docs/category/groups",children:"Group Documentation"})," ."]}),"\n"]}),"\n",(0,r.jsx)(t.p,{children:"Once Managed Groups have been rolled out, we will assess what we have learned and proceed with similar steps for\nAugmented Groups in Q2 (more on that in a later devlog!)."}),"\n",(0,r.jsx)(t.h2,{id:"stay-up-to-date",children:"Stay up to date!"}),"\n",(0,r.jsxs)(t.p,{children:["As always, we will be regularly updating this devlog ",(0,r.jsx)(t.a,{href:"https://fosstodon.org/@cwtch",children:"and other channels"})," as we continue to make progress towards\nsurveillance resistant infrastru
1cture!"]}),"\n",(0,r.jsxs)(t.p,{children:["Subscribe to our ",(0,r.jsx)(t.a,{href:"/blog/rss.xml",children:"RSS feed"}),", ",(0,r.jsx)(t.a,{href:"/blog/atom.xml",children:"Atom feed"}),", or ",(0,r.jsx)(t.a,{href:"/blog/feed.json",children:"JSON feed"})," to stay up to date, and get the latest on, all aspects of Cwtch development."]}),"\n",(0,r.jsx)(t.h2,{id:"help-us-go-further",children:"Help us go further!"}),"\n",(0,r.jsxs)(t.p,{children:["We couldn't do what we do without all the wonderful community support we get, from ",(0,r.jsx)(t.a,{href:"https://openprivacy.ca/donate",children:"one-off donations"})," to ",(0,r.jsx)(t.a,{href:"https://www.patreon.com/openprivacy",children:"recurring support via Patreon"}),"."]}),"\n",(0,r.jsxs)(t.p,{children:["If you want to see us move faster on some of these goals and are in a position to, please ",(0,r.jsx)(t.a,{href:"https://openprivacy.ca/donate",children:"donate"}),". If you happen to be at a company that wants to do more for the community and this aligns, please consider donating or sponsoring a developer."]}),"\n",(0,r.jsxs)(t.p,{children:["Donations of ",(0,r.jsx)(t.strong,{children:"$5 or more"})," can opt to receive stickers as a thank-you gift!"]}),"\n",(0,r.jsxs)(t.p,{children:["For more information about donating to Open Privacy and claiming a thank you gift ",(0,r.jsx)(t.a,{href:"https://openprivacy.ca/donate/",children:"please visit the Open Privacy Donate page"}),"."]}),"\n",(0,r.jsx)(t.p,{children:(0,r.jsx)(t.img,{alt:"A Photo of Cwtch Stickers",src:n(5005).Z+"",width:"1024",height:"768"})})]})}function d(e={}){const{wrapper:t}={...(0,i.a)(),...e.components};return t?(0,r.jsx)(t,{...e,children:(0,r.jsx)(c,{...e})}):c(e)}},1385:(e,t,n)=>{n.d(t,{Z:()=>r});const r=n.p+"assets/images/hybridgroups-11c21d2516ceadabac8af92290b53a08.png"},5005:(e,t,n)=>{n.d(t,{Z:()=>r});const r=n.p+"assets/images/stickers-new-1e9b14bdd638b4907cce833e813a09ad.jpg"},1151:(e,t,n)=>{n.d(t,{Z:()=>s,a:()=>a});var r=n(7294);const i={},o=r.createContext(i);function a(e){const t=r.useContext(o);return r.useMemo((function(){return"function"==typeof e?e(t):{...t,...e}}),[t,e])}function s(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(i):e.components||i:a(e.components),r.createElement(o.Provider,{value:t},e.children)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.