Keynote: Lessons learned Open Sourcing the UK's Covid Tracing App by Terence Eden
Watch on YouTubeVideo summary
Terence Eden recounts his experience leading the development of the UK's NHS COVID-19 contact tracing app during a period where open source principles collided with urgent health policy needs. Before the pandemic, he worked tirelessly to normalize open source within government and political circles by consistently advocating for it in every meeting, ensuring that releasing code as open was seen not as an optional extra but as standard operating procedure. This cultural shift meant that when the crisis hit, there was no debate over whether to make the app open; instead, the focus immediately turned to technical implementation under immense pressure and strict deadlines set by politicians who publicly committed to keeping the source code available from day one.
The project faced significant challenges, most notably a critical bug in their custom Bluetooth algorithm that prevented effective use on iPhones due to Apple's security restrictions. Faced with this reality, Eden describes the difficult decision to abandon their sovereign technology and switch to Google and Apple's exposure notification framework, highlighting the tension between ideological purity and practical necessity for public safety. Beyond technical hurdles, the team endured severe cyberbullying and misinformation campaigns from trolls who spread conspiracy theories about government surveillance, forcing them to invest heavily in community moderation and legal protection while trying to maintain morale amidst a hostile online environment that often confused non-technical stakeholders with complex architectural choices like hosting on GitHub versus private servers.
Ultimately, Eden concludes that the true legacy of this project extends far beyond the software itself, which was eventually shut down once vaccines reduced transmission rates. The open sourcing initiative successfully built public trust, saved lives by encouraging app adoption, and established a lasting precedent for government transparency where future digital services are expected to be open source. He emphasizes that while technical code is important, the real victory lies in fostering an inclusive community where diverse voices can participate, proving that open source is fundamentally about people rather than just lines of code or specific licenses like MIT or GPL.
Read the full video transcript
Okay. Uh, I think we're about ready to
go. Uh, hello Eurobsdcom. Uh, thank you
so much for getting up so early uh to
see me uh and my talk. I'm very pleased
that I'm not doing uh the talk tomorrow
after a 4 a.m. drinking session. Um,
it's
It's lovely to be here in Zagreb. It's
lovely to see uh so many uh friends and
uh and new faces. My name is Terrence
Eden. Uh I'm going to be talking you
through a very strange period in recent
history. Uh a time when open source met
politics uh and where health policy and
technology policy clashed. Um and I
think a time when we all went just a
little bit crazy.
So before we start um I want to take a
moment to acknowledge the terrible toll
that CO 19 had on all of us. I'm sure
everyone here has lost family, friends,
colleagues, and loved ones. And I invite
you take to take just a moment to
remember all the people who should be
here with us in this room today, but who
sadly aren't.
I am going to try and make this talk fun
and entertaining, but I do realize this
is a painful subject for lots of people.
Uh, by way of a content warning, this
talk does discuss death uh and cyber
bullying, and it does feature clips of
various British politicians.
So, let's talk contact tracing apps. Uh
this is what the UK one looked like. I'm
sure most of you had one which was very
similar to to this. At the start of the
pandemic, I was uh the head of open
technology in the UK's health service.
Uh and I'm going to discuss what I
learned from the experience of
open-sourcing this app, a major piece of
critical national infrastructure. what
lessons I learned and the lessons that
you can take away when it comes to open
sourcing your own very important work.
This uh this is a screenshot I took.
This is a ping I received on my phone
telling me that I had been near someone
who was uh possibly infectious. Um and
the reason I'm showing you my screenshot
is because these are my recollections.
This is what I remember uh happening. I
I was working for an organization called
NHSX
uh which was part of the UK's health
service uh which was set up to provide
new technology to the health service and
and this is our launch party. Uh that's
me there. Um and and there were the
reason I'm showing you this is there
were hundreds of people involved in this
app. Uh all of them doing a brilliant
job under very difficult circumstances.
Um, as I said, I'm I'm going to be
talking about my memories, what I
learned. Uh, but I don't want you
thinking that this was the, you know,
the Terrence Eden show. It wasn't. It
was hundreds of people. I was a small
cog in a big machine. And, and open
source is always about more than one
person. This story that I'm going to
tell you is not about one person in
their bedroom on their laptop. It's it's
a story about all of us.
The story starts
before the pandemic.
So I had spent the year before um
building up to this project without
really knowing that it was uh it was
going to happen. I uh spoke around the
world about open source and open data
and open standards. Um and I did lots of
blog posts saying hey isn't open source
fantastic? Um,
and in every single meeting I was in, I
made it a point to mention open source.
If someone said, "Oh, yeah, and we've
got this new piece of software we're
developing." I went, "Oh, can we open
source that?" If someone started talking
about data, wow, that's brilliant. Can
we release that as open data? Is is
there an open API that we can use for
that? In every single meeting, people
were probably sick of me. Um, but it
normalized it. I If you take nothing
else away from this talk, you have to
normalize the idea of open source, not
just within your communities, but to to
your managers, to to politicians, to to
people who might be around your project,
but who don't really understand what it
is you're doing and why you're doing it.
Every single opportunity you can,
mention open source. Don't make it sound
like this weird scary thing. Open source
is normal. It's just the way we do
things here. Um, we we got so much
positive feedback whenever I spoke in
public and said and you know the NHS,
the UK's health service, we we're going
all in on open source. Um, people
started feeding back to us saying, "Oh,
this is fantastic." They would write to
politicians, they'd write to our
managers saying, "Wow, this is
wonderful. I'm so pleased you're open
source." And it all led to
this, a complete culture change in our
organization. This is what you need to
do. You you need to to do the work
obviously, but you need to signal
intent. You need to tell people that you
are open and you need to tell people why
you are open and you need to tell people
why it is a good thing that you are
open. You've got to build consensus with
your peers.
By the time the pandemic struck, we
started talking about do we need a
contact tracing app? And at no point did
we ever discuss whether it was going to
be open source or not because of course
it was going to be open source. That
that's the way we do things in our
organization. We everything we do is is
open source. Yeah, we discussed like the
license and where to host it and a bunch
of other stuff, but no one ever said,
"Oh, do we need to open source this?" It
was just this is normal. This is what we
do.
Um,
you need to demystify open source in
your organizations and in the wider
society. Um, don't make open source
sound esoteric or scary
um or radical
even though it is those things. You've
got to make it just a normal accepted
part of what everyone in the
organization does.
So the pandemic started. We decided
we're going to release a contact tracing
app. And I was given a very specific
mission.
It was Albert Hubbed who said, "All you
need to succeed is a definite plan and
not quite enough time."
And you know, we had a definite plan.
And the plan was this.
On the day that people can download the
app from the app store, the source code
must be open. It must be available to
download as well.
Having deadlines is vital. I cannot
stress that enough. If we'd said, uh,
we'll open source it when it's done or,
you know, oh, yeah, we'll get round to
it's going to be open source. We but
we'll get round to it. If we'd said
that, it never would have happened. Just
wouldn't have. Having a deadline was
vital. Having a publicly stated deadline
is what made it happen. Um, so we made
public commitments and those were backed
up by our managers and by politicians
speaking in public saying and it is
going to be open source and you will be
able to get the source code. We had
politicians on the nightly news saying
and yes the app will be open source.
Once someone that senior says something
like that in public, you cannot go back.
It provides a huge amount of positive
pressure uh on you.
But of course pressure isn't always
positive. The you know the reality is
the pressure on the team was enormous.
It it was unfathomable. It was pressure
like I have never felt before. So, um,
we started developing our app and it was
going pretty well and we were alpha
testing it with with people in in public
and we thought this was going really
well and then
a bug,
a really big bug.
This is me smiling on the outside,
hollow on the inside.
So you that is the only similarity
between me and Barbie. Um
so you've all been there, right? You're
you're working on something, it's going
great, and then boom, this bug hits and
you're like, I don't know what to do.
We're going to have to change
everything.
Before Google and Apple had announced
anything to do with contact tracing, the
UK had built its own Bluetooth contact
tracing algorithm. Um, it was something
that we had developed. It was ours. It
was self-hosted. It was sovereign and it
worked. It worked pretty well.
Mostly
there was a bug we couldn't fix. Uh,
we're going to take a look at the
problem. I'm going to hand you over to
my former boss who's the secretary of
state for health and uh, social care. I
think there's sound going out on the
stream. Uh for everyone else, um uh
you'll just have to read the subtitles.
Because of this testing, we discovered a
technical barrier that every other
country building their own app is also
now hitting. We found that our app works
well on Android devices, but Apple's
software prevents iPhones being used
effectively for contact tracing unless
you're using own technology.
>> I hope everyone heard that or or read
the subtitles. Um,
isn't that weird? Can you imagine one of
your bugs being discussed by a
government minister on the nightly news?
I can see the blood draining from
people's faces.
That's that's the pressure we were
under. Our bugs were being discussed not
just online and in the technical press
on the nightly news everywhere. It was
it was mortifying.
So because of this bug
we made the difficult decision to stop
developing our own Bluetooth contact
tracing algorithm and switch to the
Google Apple exposure notification
framework.
Which brings up a really interesting
question.
What does it mean if your nation's
health policy
is controlled by some American mega
corporations? Now, you can argue whether
politicians have our best interests at
heart, but ultimately they are
democratically accountable. You can vote
them out. You can't do that with Google
and Apple. You can send freedom of
information requests to your government
and you can get source code out. You
can't do that with American mega
corporations.
The original technology that we had
developed ourselves worked and it worked
pretty well but not well enough.
We had to deal with reality. You we take
this as a lesson that we learned. You
cannot always afford to be ideologically
pure.
If we had remained ideologically pure
and kept everything open source and
everything under our control, it would
have caused people harm.
that was too high a price for
ideological purity. And in the end,
saying no, no, no, we have to do it this
way doesn't doesn't change society. What
does change society is incremental
progress, saying okay, we didn't get
100% of what we wanted, but we got part
of the way there, and next time maybe we
can go further,
but I don't know if we made the right
choice.
So, I'm going to put it to the vote with
all of you. We're going to have a a
hands up. Um, two choices here. Hands
up, we were I'll tell you the two
options. Uh, we should have kept
everything 100% open source and 100%
under our control or hands up, we were
right to swap to the Google Apple
Exposure notification framework. So,
hands up, we should have kept everything
100% open source.
Yeah, a few hands. Uh, hands up. We were
right to switch to Google Apple
notification framework.
A bit of a majority there. Interesting.
Like I say, I don't know what the right
answer is. I think I can justify the
choices we made. I don't know whether it
was right. But this is the same for
every open-source project. These are the
choices which will bind you. You've got
to make a choice. Do we do we host it
ourselves on our own customuilt hardware
or do we just put it on AWS? do do we
build this library or oh do do we
integrate this closed source one from
someone else you know do do we build our
own thing do we use someone else's API
these are all choices these are choices
you have to make and these are choices
which are going to piss people off
I'm assuming most countries had troll
dolls yeah so these are trolls
>> it is
chief trolling officer is somewhere in
there.
It is really easy to bully people
online. It's fun, too.
Apparently, you shouldn't be encouraged.
>> In a world of lockdown with nothing else
to do, lots of people vented their fears
and frustrations
at us.
If you've read about the XZ backdoor
issue, you know that it is terrifyingly
easy to bully people in open source.
Our number one job as a community
is to find ways to protect ourselves,
our colleagues, and our friends.
Working in the open makes you a target.
Working in the open for the government
makes you fair game in some people's
eyes.
I'm going to show you a real tweet which
was sent uh at the time. Um I I've
anonymized it slightly. Um so so someone
sent a message which was a pretty good
question which is why is the government
developing its own app? That's that's a
fair that's a very fair question. Uh,
and then this person uh says all of
this, it's old boys, uh, it's vote
leave, it's all to do with circle,
everyone went to eat and and and this is
all
None of this is is true. And and this is
the worst thing about working in the
open is that people will just lie about
me. Um, for the record, I didn't go to
Eaton. I don't think anyone on my team
worked on the vote leave campaign. There
was no one from Ciro that I saw. They
didn't even let me email people like
Dominic Cummings. But, you know, other
than that, all very accurate, I'm sure.
Paradoxically, this is the superpower of
open source.
When people said, "Oh, the app is going
to track you using GPS all the time." We
could point to the source code and say,
"Show me where. Show me where in here we
turn on GPS and track you." you you
can't because it doesn't exist.
Now look, I I believe in the phrase
public money, public code. If the
taxpayer has paid for the development of
something, as they did with this app,
then they should have the right to see
the source code. I believe open source
is a moral good.
But the cynical and practical reason to
be open source is that when people start
chatting rubbish about you, you can
point to the source code and say, "I'm
sorry, it doesn't do that. Show me where
not everyone
agreed with our approach to open
sourcing it though. You know, I thought
open sourcing it would be a good thing.
Uh not everyone agreed. This is again uh
a real message that was sent to us while
we were you know trying to work on this
life-saving technology. Um here we go. I
have 40 years of software development,
including top level Apache projects. Not
minor Apache project, top level Apache
projects. I think I can tell the
difference between open-source and a PR
stunt.
Well, that told me, didn't it? Well,
if you're employed in the public sector,
you cannot reply to messages like this.
Uh, I am no longer employed by the
public sector, so I can reply to
messages like this.
Um,
if you're employed by a large company,
your PR team do not want you replying to
this guy. Um, if you are the sole
developer on an open-source project, it
can be dangerous for you to feed the
trolls like this.
When I blocked people like this, they
complained to my boss. When I muted
them, they tried to instigate pylons. uh
if I ignored it, it got worse. I get in
the early days of the pandemic, people
were scared. But it is very difficult to
maintain enthusiasm
for a project when people are, you know,
trying to rile you up. Um I had people
publicly denouncing me. People wrote
blog posts saying that I was evil for
working on a COVID tracing app. I had
people sending me direct messages with
all sorts of things. It was horrible. It
was a very dark time in my life. And I'm
incredibly grateful to the support of my
wife, my friends, my trade union for for
helping me get through this. The lesson
learned here is
you've got to protect yourself. You've
got to protect your friends and your
co-workers. Let them know that you
support them no matter what. Um, let
your project members and your team
members know that you've got their backs
and check in on your friends, especially
when they can't defend themselves.
I'm I'm being a bit negative because for
every message like this, we had hundreds
which were, "Oh, wow. The app is open
source. Oh, wow. That's so cool. You're
doing this. Oh, this is brilliant. I
love that it's open source." And every
time we got one of those messages, we
took a screenshot. We emailed it to our
boss. We emailed it to the politicians
and said, "Look, people really like uh
that that it's open source."
But but perhaps just perhaps perhaps
this guy has a point. How can you tell
if something is or isn't open source? As
it's really easy. You look at the
license.
Um now I
I would be delighted to spend hours
discussing every single open-source
license that there is with with anyone
here. I I truly I love talking about
open source licenses. The only the only
stipulation is you need to buy me one
beer for every license you want to talk
about.
Two, if it's a GPL license. Um
[Music]
that was that was a cheap shot. I don't
mean that. Um so
>> so in internally and privately we did
discuss which license we were we were
going to choose and we settled on the
MIT license and we did that for for
three reasons. The first reason for
choosing MIT was laziness. Other
government departments had already used
MIT for releasing their source code. So,
it had already been approved by
government people and we could just go,
"Yeah, we'll we'll do that one." Lesson
learned. Never underestimate the power
of group think. Someone else has already
approved it. That's good enough for us.
The second reason is we weren't trying
to make money out of this app. We didn't
care if people reused it. So, we didn't
need that sort of verality of GPL, AGPL,
or or anything like that. If people
wanted to use it and take it, great. We
we didn't care. Um, and the third, but
possibly the most important reason for
choosing the MIT license is the MIT
license is short.
It's really short. When you're dealing
with government lawyers who charge by
the word,
a short license is really important, but
it also means that if you're talking to
non-speists, you can give them the MIT.
It's very readable and they go,
"Oh, yeah. No, I get it.
Is the MIT license the best? I don't
know. But this goes back to ideological
purity. It was the quickest way that we
could get this open without endless
discussions.
But I'm prepared to believe that I was
wrong. So, we're going to do another
public vote and it's going to be a
straight up and down again. We're going
to say yes, we were right for choosing
MIT or no, we were wrong. We should have
chosen some other license. I don't mind
what. So, hands up, we were right to
choose MIT.
Quite a few. Thank you. Uh, and hands
up. We should have chosen something
else. Anything else?
Does no one want to buy me a beer
afterwards? Oh, man. Okay, one person.
One person there. Okay.
So, of course, we we announced this is
going to be MIT licensed and uh men on
the internet had opinions,
genuine message. MIT is a license of
choice for people who don't understand
open source. So all of you who put your
hands up, you do not understand open
source. A man on the internet has said
so. Um
>> such a neutral name.
>> Such a neutral nickname. Yeah. Um I I
have redacted it. I don't think that was
that person's real nickname. But um I
there is an interesting point here.
There is a lesson to be learned.
The license that you choose for your
project will have a direct impact on
what people think the license is for and
it will have a direct impact on how they
think of you.
When you are not public about why a
license has been chosen as as we
weren't, people will ascribe malice
where there is at best indifference.
Now it doesn't give me any pleasure to
to say this uh but this person was
wrong. Um we did release the back end.
Uh you can download all the code for the
servers and all the tests and all the
documentation. And yes the MIT does let
you do that. Um
but okay there is a there is another
lesson to be learned here which is how
do you explain what opensource is to
people who don't understand it. So, you
know, to to I hate using this phrase,
normal people, uh people who don't come
to Eurobd Con. Um,
so
I had the the number 10 Downing Street
press team uh asked me a question, and
it's a really good question. They said,
"Why are you releasing two versions of
the source code?" I was like, "What?
What do you mean?" and they said, "Well,
you've released an Android version of
the source code and an iPhone version of
the source code. Why are they
different?"
That's a pretty good question. I think
if you don't know about techno, why are
they different? Now, I'm very happy to
give a 6-hour lecture on the
architectural differences between these
two platforms, but I don't know how to
condense that answer into a single
paragraph that can go into a press
release, which will then be regurgitated
into one sentence, which will go out on
the news or in the newspapers. Um,
internally we had to justify uh
internally and externally we had to
justify lots of choices. So we hosted
everything on GitHub which is run by
Microsoft. Boo.
The alternative was spinning up our own
git instance which would have cost lots
of taxpayers money. Boo. You know there
is no right choice here. Um but you know
you have to talk uh about these things
so that people understand why you have
made these choices. Um, now speaking of
GitHub, this this is a little vain. Um,
but but I captured the moment that I I I
set this live. This is my my wife
recording me do pressing the big button
on GitHub which says go live. Um, and
the reason that I had to do this is
because we were working in a private
repository. We were not developing in
the open.
On the launch day, I received lots of
contradictory messages. I got an IM from
my boss saying, "Yeah, go for it." And
then immediately I got one from uh the
press team saying, "No, no, hold off."
And then my boss's boss said, "Yeah,
yeah, go for it." And then the number 10
press team said, "No, no, no. We need to
wait until the prime minister has said
something."
It was it was so stressful and so
maddening. You know, it was pandemic
pandemonium. So I think we can be
forgiven. But the lesson here is you
need a robust launch plan. You need
something you have agreed to in advance.
Otherwise, it will just be too
stressful. Um, so anyway, the the app
was released in in in the various app
stores and you could download it and the
source code was open at the same time.
But even though I think we did a pretty
good job of explaining
what open source was, why we were doing
it, uh, some people still weren't happy.
As I said, uh, we we released it, we
made a big announcement saying, "And it
is now on GitHub." Um, and this is I
love this. This is a genuine message uh
that that was sent and was copied into a
politician uh which was that GitHub is
the sharewware developers free-for-all
site. It is written by hobbyists. So I I
haven't heard the word shareware in at
least 20 years. So you know there you
go. Don't use GitHub. It's it's just for
shareware.
But look, it is it is tempting to laugh
at people like this and I do. But how
how do you explain to everyone in your
community what open source is, why you
were doing this, why you're using
GitHub, why you're doing this. Um, and
internally it wasn't that hard, but you
know, we had people, you know, talking
to developers, they get what open source
is. Most designers who work in in
digital get it. But you have lawyers
coming on board and politicians and
people who are very good at their jobs
and very intelligent, but they've never
heard of open source before. You need to
find a very simple way to explain to
everyone in your community why you were
doing these things. Otherwise, it causes
confusion.
Um,
so, so I mentioned before uh that we
were developing in private and then
releasing in public. Um, so I'm going to
talk a little bit about our git history.
Um, so you know that on GitHub, GitLab,
any any git project, you type, you make
a commit and you boom and there you can
see all the commits that everyone has
made and when they've made them, who
made them.
We didn't have that. We developed in
private and then every time there was a
new release of the app, we uploaded a
new version of the source code. So you
can see a diff between the two versions,
but you cannot see individual commits.
You cannot see that an made this commit
and that Bob made that commit. All of
our history was squashed.
Now, why did we do this? Well, the first
was security.
Maybe someone committed something they
should have. Maybe someone left in a
debug key which, you know, maybe we
quickly revoked it, but we weren't quick
enough. Maybe someone left in some
information which would have been useful
to an attacker. I do not believe in
security through obscurity
but this was an app which was going to
be used by every single person in the
country. This was an app which was going
to be scrutinized by every uh foreign
intelligence agency. This was going to
be examined by everyone who wanted to do
us ill. So we made that difficult
decision. We're going to squash the
history. We didn't want anyone seeing
individual commits which might contain
uh something we didn't want them to see.
Um the second
uh was the privacy of our developers. As
as I've shown you, this this was being
spoken about on the nightly news. We
didn't want our developers to be under
any more pressure than they already
were. Can you imagine being Twitter's
main character because you left off a
semicolon in a commit message? I mean,
no one wants that pressure, right? Um,
we we didn't want them to be targeted by
fishers or state sponsored attackers.
You know, if you can see that this
GitHub user is committing to the
government's repo, wouldn't it be
tempting to send them a message, please
click here to reset your 2FA token? Um,
you know, this is what we saw happen
recently with with the npm supply chain
uh issue. it it is depressingly and
distressingly easy to fish people who
are working on high-profile uh code.
So with each new release of the app, we
squashed the history. We uploaded a new
version.
Again,
I don't know if that's the right choice
or not. I think I can justify it to you
and I can justify it in public, but
we're going to put it to a vote because
I know people have strong feelings on
whether you should be able to see, you
know, individual commit history. So
again, a straight vote. we were right to
um squash a history or we were wrong.
Every single git commit should have been
public. So hands up, we were right to
strip the history. Okay, quite a few of
you. Thank you. And hands up, we were
wrong. We should have released
everything.
More than a few I like I say, I can't
necessarily recommend doing it this way,
but I think it is justifiable for some
things and I completely respect the the
difference of opinion there. Um, and
incidentally on on the open- source uh
licensing point of view, I had this
argument with someone. I I don't know of
any license which entitles you to every
commit. You're entitled to the source
code but not the history. I don't know.
Again, that's one to discuss over a few
beers until 4:00 a.m. Um,
so here's another problem that we faced
and you might face too. Um, we had
comments in our code. Comments help
people understand what the code is.
Comments are normal. Um,
but
we wanted to leave them in obviously,
but we had a problem and it's that
programmers
programmers think they're funny.
We had to let them know, do not put
anything in the comments that you don't
want to see on the front page of a
tabloid newspaper tomorrow morning. Um,
I mean, I would I would love that, you
know, if if the tabloids ran with the
government says tabs, not spaces, and
it's and it's you who are
[Music]
they're never going to run that story.
Um, so we we, you know, we went through
this tedious exercise of sort of
sanitizing comments. You know, people
left comments about their frustration.
Oh, I can't believe this bloody API
doesn't work. Yeah, getting rid of that.
Or bits of personal info. Can can you
tell Sue to fix tod do tell Sue to fix
this? You know, we we didn't want any of
that in there. Um
but there was still some problems with
comments. So we had oh this is very
boring. We we had um a process which
spawned lots of subprocesses and
sometimes they would time out and they
had to be res and so there was a comment
about that and it was all very normal
and boring. But the
the comment
was this.
When the signal is received, terminate
all nonresponsive children. Do not log
any data about this and spawn a new
doom.
[Applause]
This is accurate. This is accurate.
You know, like everyone here knows what
this means, right? I know what this
means. You know what? But imagine you've
been soaking up 5G COVID conspiracies
and you think, I'm going to look through
the source code and you see this
doesn't look good, does it? Um,
[Music]
so
[Music]
here here's a lesson for you. If someone
wanted to maliciously or, you know,
maybe through ignorance misunderstand
your your code, could they do it? You we
talk about self-documented code. Your do
comments have to be so clear. Um,
so how how do you curate a culture where
non-coders can understand what you're
doing, where they can get involved and
understand? So we had people wrote to
their members of parliament uh and they
asked questions and we we answered them.
We had blog posts which had comments
open and we also had technical forums.
We had open issues on GitHub. Uh but as
anyone who has managed a forum knows,
technical questions
very quickly slide into political
questions.
So, uh this is me moderating a
conversation and shutting it down,
saying, "I'm sorry, we're not talking
about this." We had a very strict code
of conduct, and I encourage you in all
of your projects, have a code of
conduct. Um it it is an impossible
balance to get right. People will
complain when you do moderation like
this, but it is better than the
alternative. It is better than letter
letting discussions go off the rails and
fester and people going completely off
topic. Um
you have to moderate and and that's not
just get rid of the spam. It's going I
know where this conversation is going
and we're stopping it now. People will
be pissed off with you, but sometimes
you need to keep your community safe.
And that does mean saying, "Look, there
are better v venues for discussing this
thing. We're here to talk about this
other thing."
You need to invest in moderation.
Moderation is a professional skill and
it is a skill I do not possess.
I I don't We We ended up getting a
professional moderator team. We paid
people to do it. You need volunteers.
You need paid people who will who are
dedicated to this. Um, now look, I am
being really down. Um, and and I don't
mean to be because for every negative
message we received, we've received
hundreds which were positive. We had
loads of people in GitHub saying, "This
is brilliant. I'm so pleased it's open
source." We had people sending pull
requests. We had a bug bounty. We had
lots of people talking about it in the
press. And it was just getting better
and better and better.
And then one day this happened.
It just stopped.
I received a message on my phone
saying that they were shutting down the
project I was working on. And it was
like a punch to the gut.
This was the biggest project I had ever
worked on. It is probably the most
important thing I will ever work on. And
they were killing it off.
Whenever you work on a big open source
project, you want it to last forever,
right? You just want it to go on and on,
but it can't. All all things come to an
end.
If this app was still running today, it
would mean that we had failed.
It was right that it was shut down. It
had done its job. But here's the lesson
for you. How do you prepare to shut down
an app? What's the groundwork that you
need to do? You need to have a document
which says, well, these API keys have to
be revoked. We need to shut down the
servers in this order. We need to put
out announcements. We need to give
people this much notice. It is v. It is
just as important, I would say, as
starting a project as stopping a
project.
I don't think we're ever going to be
truly post pandemic, but through a
combination of changed behaviors and
vaccines and yes, this app, we we turned
a corner. And the legacy of open
sourcing the app is is a mixture of
things. Primarily, it's this. It saved
lives. The app saved lives. Um, open
source wasn't the only bit of that. But
if the app wasn't open source, I know a
few people in this room who wouldn't
have installed it, would have told their
friends and family not to install it. I
would have I would have said the same.
It being open source increased the trust
in the app.
We now understand what technology works,
what doesn't. We know what vaccines
work, what doesn't. This is me getting
my first vaccine all those years ago. I
was so excited. All of us have learned
lessons from this horrific experience.
And I hope the lessons that governments
and health services have learned is that
opensource
is vital. It any new app that
governments create has to be open
source. Um and it's not just the UK that
learned those lessons. Uh I was dealing
with counterparts from from across the
world talking to them about the problems
they were facing, we were facing. We
shared tips and tricks and code. Um now
as far as I can tell, these are all the
countries that open source their apps. I
apologize if I've missed any off. And
you can see they all used a variety of
technologies. Not all of them used
Google Apple exposure notifications.
Some used their own Bluetooth. Some use
um uh DP3T or GPS. That that's fine. Uh
not all of them use MIT. So the the
people who said other licenses, yeah,
plenty of countries did that. Um is
there anyone from Latvia here? Uh
Dexter, are you here? I want to know why
Latvia chose Creative Commons for their
source code license and I will buy you a
beer if you can explain it. Um
so
I I'm want to leave you with a speech
that um the UK's then prime minister
Rishi Sunnak made just before the
general election. So this is the prime
minister of our country in a bid for
reelection and and this is a transcript
of his speech. We are pro- opensource.
This is I I really can't tell you how
much this blows my mind that in a major
speech to try and get reelected, the
prime minister says there must be a very
high bar for any restrictions on open
source. We're open sourcing what we've
built. There's going to be an opensource
day. it you know it is so enormously
gratifying that you know between our
team and all the other teams working in
government open source made such an
impact that Rishi Sun the prime minister
said we are pro- opensource
now of course he did lose that election
but you know I don't think it was his
stance on free BSD versus open BSD or
you know GPL versus MIT that that caught
him out um
Yeah.
So, um, in in the spirit of, uh,
political neutrality, here is, uh, the
the UK's current prime minister, K star,
also talking about open source. Uh,
and there's a reason AI, one of the
champions of open have just announced a
UK office.
This this is the legacy
of that co tracing app being open
source.
The words open source aren't in a
technical document. They're not page 500
of a treaty. They're not something that
is referred to over there. Open source
is being spoken about at the highest
levels of government and it's being
spoken about positively.
And that legacy of open- source triumph
belongs to everyone here. It belongs to
everyone who has released code. It
belongs to everyone who was sat in a
meeting with their manager and said,
"Oh, can we open source that?" It
belongs to everyone who's written to
their politicians and says, "I demand
that this be open source." It belongs to
everyone who raises issues uh who
comments on something who gives praise
to open source projects who releases
open source codes that makes it the you
know the the thing which powers the
modern world.
This is the lesson that I learned from
helping open source the UK's co tracing
app is that
opensource
is not about code.
Open source is about community and it is
you the community who saved the day. So
thank you very much indeed. Thank you.
Thank you.
Thank you. I really appreciate
Thank you. That that that is enormously
gratifying. I um those are my contact
details. I think we've got time for a
couple of questions. Someone will shout
at me if we don't. Um there is a mic. Um
so if you do have any questions, please
stick your hand up or uh come and find
me. Um I'm going to be around all
weekend. Probably not staying up till
4:00 a.m. drinking. We'll see. Um so any
questions? Uh or we all very eager to
get to uh the coffee break?
>> Tabs or spaces?
>> Tabs versus spaces.
It's a trap. Um,
tab tabs for indenting, spaces for
formatting.
Um,
I really wondered where that was going
to go. Um, all right. Thank you so much
uh for for coming to my talk. Thank you
so much for being here. Um, and I will
see you in the corridor later. Thanks
everyone. Cheers.