Submind YouTube summaries
Thumbnail for Keynote: Lessons learned Open Sourcing the UK's Covid Tracing App  by Terence Eden

Keynote: Lessons learned Open Sourcing the UK's Covid Tracing App by Terence Eden

Watch on YouTube

Video summary

Terence Eden recounts his experience leading the development of the UK's NHS COVID-19 contact tracing app during a period where open source principles collided with urgent health policy needs. Before the pandemic, he worked tirelessly to normalize open source within government and political circles by consistently advocating for it in every meeting, ensuring that releasing code as open was seen not as an optional extra but as standard operating procedure. This cultural shift meant that when the crisis hit, there was no debate over whether to make the app open; instead, the focus immediately turned to technical implementation under immense pressure and strict deadlines set by politicians who publicly committed to keeping the source code available from day one. The project faced significant challenges, most notably a critical bug in their custom Bluetooth algorithm that prevented effective use on iPhones due to Apple's security restrictions. Faced with this reality, Eden describes the difficult decision to abandon their sovereign technology and switch to Google and Apple's exposure notification framework, highlighting the tension between ideological purity and practical necessity for public safety. Beyond technical hurdles, the team endured severe cyberbullying and misinformation campaigns from trolls who spread conspiracy theories about government surveillance, forcing them to invest heavily in community moderation and legal protection while trying to maintain morale amidst a hostile online environment that often confused non-technical stakeholders with complex architectural choices like hosting on GitHub versus private servers. Ultimately, Eden concludes that the true legacy of this project extends far beyond the software itself, which was eventually shut down once vaccines reduced transmission rates. The open sourcing initiative successfully built public trust, saved lives by encouraging app adoption, and established a lasting precedent for government transparency where future digital services are expected to be open source. He emphasizes that while technical code is important, the real victory lies in fostering an inclusive community where diverse voices can participate, proving that open source is fundamentally about people rather than just lines of code or specific licenses like MIT or GPL.
Read the full video transcript
Okay. Uh, I think we're about ready to go. Uh, hello Eurobsdcom. Uh, thank you so much for getting up so early uh to see me uh and my talk. I'm very pleased that I'm not doing uh the talk tomorrow after a 4 a.m. drinking session. Um, it's It's lovely to be here in Zagreb. It's lovely to see uh so many uh friends and uh and new faces. My name is Terrence Eden. Uh I'm going to be talking you through a very strange period in recent history. Uh a time when open source met politics uh and where health policy and technology policy clashed. Um and I think a time when we all went just a little bit crazy. So before we start um I want to take a moment to acknowledge the terrible toll that CO 19 had on all of us. I'm sure everyone here has lost family, friends, colleagues, and loved ones. And I invite you take to take just a moment to remember all the people who should be here with us in this room today, but who sadly aren't. I am going to try and make this talk fun and entertaining, but I do realize this is a painful subject for lots of people. Uh, by way of a content warning, this talk does discuss death uh and cyber bullying, and it does feature clips of various British politicians. So, let's talk contact tracing apps. Uh this is what the UK one looked like. I'm sure most of you had one which was very similar to to this. At the start of the pandemic, I was uh the head of open technology in the UK's health service. Uh and I'm going to discuss what I learned from the experience of open-sourcing this app, a major piece of critical national infrastructure. what lessons I learned and the lessons that you can take away when it comes to open sourcing your own very important work. This uh this is a screenshot I took. This is a ping I received on my phone telling me that I had been near someone who was uh possibly infectious. Um and the reason I'm showing you my screenshot is because these are my recollections. This is what I remember uh happening. I I was working for an organization called NHSX uh which was part of the UK's health service uh which was set up to provide new technology to the health service and and this is our launch party. Uh that's me there. Um and and there were the reason I'm showing you this is there were hundreds of people involved in this app. Uh all of them doing a brilliant job under very difficult circumstances. Um, as I said, I'm I'm going to be talking about my memories, what I learned. Uh, but I don't want you thinking that this was the, you know, the Terrence Eden show. It wasn't. It was hundreds of people. I was a small cog in a big machine. And, and open source is always about more than one person. This story that I'm going to tell you is not about one person in their bedroom on their laptop. It's it's a story about all of us. The story starts before the pandemic. So I had spent the year before um building up to this project without really knowing that it was uh it was going to happen. I uh spoke around the world about open source and open data and open standards. Um and I did lots of blog posts saying hey isn't open source fantastic? Um, and in every single meeting I was in, I made it a point to mention open source. If someone said, "Oh, yeah, and we've got this new piece of software we're developing." I went, "Oh, can we open source that?" If someone started talking about data, wow, that's brilliant. Can we release that as open data? Is is there an open API that we can use for that? In every single meeting, people were probably sick of me. Um, but it normalized it. I If you take nothing else away from this talk, you have to normalize the idea of open source, not just within your communities, but to to your managers, to to politicians, to to people who might be around your project, but who don't really understand what it is you're doing and why you're doing it. Every single opportunity you can, mention open source. Don't make it sound like this weird scary thing. Open source is normal. It's just the way we do things here. Um, we we got so much positive feedback whenever I spoke in public and said and you know the NHS, the UK's health service, we we're going all in on open source. Um, people started feeding back to us saying, "Oh, this is fantastic." They would write to politicians, they'd write to our managers saying, "Wow, this is wonderful. I'm so pleased you're open source." And it all led to this, a complete culture change in our organization. This is what you need to do. You you need to to do the work obviously, but you need to signal intent. You need to tell people that you are open and you need to tell people why you are open and you need to tell people why it is a good thing that you are open. You've got to build consensus with your peers. By the time the pandemic struck, we started talking about do we need a contact tracing app? And at no point did we ever discuss whether it was going to be open source or not because of course it was going to be open source. That that's the way we do things in our organization. We everything we do is is open source. Yeah, we discussed like the license and where to host it and a bunch of other stuff, but no one ever said, "Oh, do we need to open source this?" It was just this is normal. This is what we do. Um, you need to demystify open source in your organizations and in the wider society. Um, don't make open source sound esoteric or scary um or radical even though it is those things. You've got to make it just a normal accepted part of what everyone in the organization does. So the pandemic started. We decided we're going to release a contact tracing app. And I was given a very specific mission. It was Albert Hubbed who said, "All you need to succeed is a definite plan and not quite enough time." And you know, we had a definite plan. And the plan was this. On the day that people can download the app from the app store, the source code must be open. It must be available to download as well. Having deadlines is vital. I cannot stress that enough. If we'd said, uh, we'll open source it when it's done or, you know, oh, yeah, we'll get round to it's going to be open source. We but we'll get round to it. If we'd said that, it never would have happened. Just wouldn't have. Having a deadline was vital. Having a publicly stated deadline is what made it happen. Um, so we made public commitments and those were backed up by our managers and by politicians speaking in public saying and it is going to be open source and you will be able to get the source code. We had politicians on the nightly news saying and yes the app will be open source. Once someone that senior says something like that in public, you cannot go back. It provides a huge amount of positive pressure uh on you. But of course pressure isn't always positive. The you know the reality is the pressure on the team was enormous. It it was unfathomable. It was pressure like I have never felt before. So, um, we started developing our app and it was going pretty well and we were alpha testing it with with people in in public and we thought this was going really well and then a bug, a really big bug. This is me smiling on the outside, hollow on the inside. So you that is the only similarity between me and Barbie. Um so you've all been there, right? You're you're working on something, it's going great, and then boom, this bug hits and you're like, I don't know what to do. We're going to have to change everything. Before Google and Apple had announced anything to do with contact tracing, the UK had built its own Bluetooth contact tracing algorithm. Um, it was something that we had developed. It was ours. It was self-hosted. It was sovereign and it worked. It worked pretty well. Mostly there was a bug we couldn't fix. Uh, we're going to take a look at the problem. I'm going to hand you over to my former boss who's the secretary of state for health and uh, social care. I think there's sound going out on the stream. Uh for everyone else, um uh you'll just have to read the subtitles. Because of this testing, we discovered a technical barrier that every other country building their own app is also now hitting. We found that our app works well on Android devices, but Apple's software prevents iPhones being used effectively for contact tracing unless you're using own technology. >> I hope everyone heard that or or read the subtitles. Um, isn't that weird? Can you imagine one of your bugs being discussed by a government minister on the nightly news? I can see the blood draining from people's faces. That's that's the pressure we were under. Our bugs were being discussed not just online and in the technical press on the nightly news everywhere. It was it was mortifying. So because of this bug we made the difficult decision to stop developing our own Bluetooth contact tracing algorithm and switch to the Google Apple exposure notification framework. Which brings up a really interesting question. What does it mean if your nation's health policy is controlled by some American mega corporations? Now, you can argue whether politicians have our best interests at heart, but ultimately they are democratically accountable. You can vote them out. You can't do that with Google and Apple. You can send freedom of information requests to your government and you can get source code out. You can't do that with American mega corporations. The original technology that we had developed ourselves worked and it worked pretty well but not well enough. We had to deal with reality. You we take this as a lesson that we learned. You cannot always afford to be ideologically pure. If we had remained ideologically pure and kept everything open source and everything under our control, it would have caused people harm. that was too high a price for ideological purity. And in the end, saying no, no, no, we have to do it this way doesn't doesn't change society. What does change society is incremental progress, saying okay, we didn't get 100% of what we wanted, but we got part of the way there, and next time maybe we can go further, but I don't know if we made the right choice. So, I'm going to put it to the vote with all of you. We're going to have a a hands up. Um, two choices here. Hands up, we were I'll tell you the two options. Uh, we should have kept everything 100% open source and 100% under our control or hands up, we were right to swap to the Google Apple Exposure notification framework. So, hands up, we should have kept everything 100% open source. Yeah, a few hands. Uh, hands up. We were right to switch to Google Apple notification framework. A bit of a majority there. Interesting. Like I say, I don't know what the right answer is. I think I can justify the choices we made. I don't know whether it was right. But this is the same for every open-source project. These are the choices which will bind you. You've got to make a choice. Do we do we host it ourselves on our own customuilt hardware or do we just put it on AWS? do do we build this library or oh do do we integrate this closed source one from someone else you know do do we build our own thing do we use someone else's API these are all choices these are choices you have to make and these are choices which are going to piss people off I'm assuming most countries had troll dolls yeah so these are trolls >> it is chief trolling officer is somewhere in there. It is really easy to bully people online. It's fun, too. Apparently, you shouldn't be encouraged. >> In a world of lockdown with nothing else to do, lots of people vented their fears and frustrations at us. If you've read about the XZ backdoor issue, you know that it is terrifyingly easy to bully people in open source. Our number one job as a community is to find ways to protect ourselves, our colleagues, and our friends. Working in the open makes you a target. Working in the open for the government makes you fair game in some people's eyes. I'm going to show you a real tweet which was sent uh at the time. Um I I've anonymized it slightly. Um so so someone sent a message which was a pretty good question which is why is the government developing its own app? That's that's a fair that's a very fair question. Uh, and then this person uh says all of this, it's old boys, uh, it's vote leave, it's all to do with circle, everyone went to eat and and and this is all None of this is is true. And and this is the worst thing about working in the open is that people will just lie about me. Um, for the record, I didn't go to Eaton. I don't think anyone on my team worked on the vote leave campaign. There was no one from Ciro that I saw. They didn't even let me email people like Dominic Cummings. But, you know, other than that, all very accurate, I'm sure. Paradoxically, this is the superpower of open source. When people said, "Oh, the app is going to track you using GPS all the time." We could point to the source code and say, "Show me where. Show me where in here we turn on GPS and track you." you you can't because it doesn't exist. Now look, I I believe in the phrase public money, public code. If the taxpayer has paid for the development of something, as they did with this app, then they should have the right to see the source code. I believe open source is a moral good. But the cynical and practical reason to be open source is that when people start chatting rubbish about you, you can point to the source code and say, "I'm sorry, it doesn't do that. Show me where not everyone agreed with our approach to open sourcing it though. You know, I thought open sourcing it would be a good thing. Uh not everyone agreed. This is again uh a real message that was sent to us while we were you know trying to work on this life-saving technology. Um here we go. I have 40 years of software development, including top level Apache projects. Not minor Apache project, top level Apache projects. I think I can tell the difference between open-source and a PR stunt. Well, that told me, didn't it? Well, if you're employed in the public sector, you cannot reply to messages like this. Uh, I am no longer employed by the public sector, so I can reply to messages like this. Um, if you're employed by a large company, your PR team do not want you replying to this guy. Um, if you are the sole developer on an open-source project, it can be dangerous for you to feed the trolls like this. When I blocked people like this, they complained to my boss. When I muted them, they tried to instigate pylons. uh if I ignored it, it got worse. I get in the early days of the pandemic, people were scared. But it is very difficult to maintain enthusiasm for a project when people are, you know, trying to rile you up. Um I had people publicly denouncing me. People wrote blog posts saying that I was evil for working on a COVID tracing app. I had people sending me direct messages with all sorts of things. It was horrible. It was a very dark time in my life. And I'm incredibly grateful to the support of my wife, my friends, my trade union for for helping me get through this. The lesson learned here is you've got to protect yourself. You've got to protect your friends and your co-workers. Let them know that you support them no matter what. Um, let your project members and your team members know that you've got their backs and check in on your friends, especially when they can't defend themselves. I'm I'm being a bit negative because for every message like this, we had hundreds which were, "Oh, wow. The app is open source. Oh, wow. That's so cool. You're doing this. Oh, this is brilliant. I love that it's open source." And every time we got one of those messages, we took a screenshot. We emailed it to our boss. We emailed it to the politicians and said, "Look, people really like uh that that it's open source." But but perhaps just perhaps perhaps this guy has a point. How can you tell if something is or isn't open source? As it's really easy. You look at the license. Um now I I would be delighted to spend hours discussing every single open-source license that there is with with anyone here. I I truly I love talking about open source licenses. The only the only stipulation is you need to buy me one beer for every license you want to talk about. Two, if it's a GPL license. Um [Music] that was that was a cheap shot. I don't mean that. Um so >> so in internally and privately we did discuss which license we were we were going to choose and we settled on the MIT license and we did that for for three reasons. The first reason for choosing MIT was laziness. Other government departments had already used MIT for releasing their source code. So, it had already been approved by government people and we could just go, "Yeah, we'll we'll do that one." Lesson learned. Never underestimate the power of group think. Someone else has already approved it. That's good enough for us. The second reason is we weren't trying to make money out of this app. We didn't care if people reused it. So, we didn't need that sort of verality of GPL, AGPL, or or anything like that. If people wanted to use it and take it, great. We we didn't care. Um, and the third, but possibly the most important reason for choosing the MIT license is the MIT license is short. It's really short. When you're dealing with government lawyers who charge by the word, a short license is really important, but it also means that if you're talking to non-speists, you can give them the MIT. It's very readable and they go, "Oh, yeah. No, I get it. Is the MIT license the best? I don't know. But this goes back to ideological purity. It was the quickest way that we could get this open without endless discussions. But I'm prepared to believe that I was wrong. So, we're going to do another public vote and it's going to be a straight up and down again. We're going to say yes, we were right for choosing MIT or no, we were wrong. We should have chosen some other license. I don't mind what. So, hands up, we were right to choose MIT. Quite a few. Thank you. Uh, and hands up. We should have chosen something else. Anything else? Does no one want to buy me a beer afterwards? Oh, man. Okay, one person. One person there. Okay. So, of course, we we announced this is going to be MIT licensed and uh men on the internet had opinions, genuine message. MIT is a license of choice for people who don't understand open source. So all of you who put your hands up, you do not understand open source. A man on the internet has said so. Um >> such a neutral name. >> Such a neutral nickname. Yeah. Um I I have redacted it. I don't think that was that person's real nickname. But um I there is an interesting point here. There is a lesson to be learned. The license that you choose for your project will have a direct impact on what people think the license is for and it will have a direct impact on how they think of you. When you are not public about why a license has been chosen as as we weren't, people will ascribe malice where there is at best indifference. Now it doesn't give me any pleasure to to say this uh but this person was wrong. Um we did release the back end. Uh you can download all the code for the servers and all the tests and all the documentation. And yes the MIT does let you do that. Um but okay there is a there is another lesson to be learned here which is how do you explain what opensource is to people who don't understand it. So, you know, to to I hate using this phrase, normal people, uh people who don't come to Eurobd Con. Um, so I had the the number 10 Downing Street press team uh asked me a question, and it's a really good question. They said, "Why are you releasing two versions of the source code?" I was like, "What? What do you mean?" and they said, "Well, you've released an Android version of the source code and an iPhone version of the source code. Why are they different?" That's a pretty good question. I think if you don't know about techno, why are they different? Now, I'm very happy to give a 6-hour lecture on the architectural differences between these two platforms, but I don't know how to condense that answer into a single paragraph that can go into a press release, which will then be regurgitated into one sentence, which will go out on the news or in the newspapers. Um, internally we had to justify uh internally and externally we had to justify lots of choices. So we hosted everything on GitHub which is run by Microsoft. Boo. The alternative was spinning up our own git instance which would have cost lots of taxpayers money. Boo. You know there is no right choice here. Um but you know you have to talk uh about these things so that people understand why you have made these choices. Um, now speaking of GitHub, this this is a little vain. Um, but but I captured the moment that I I I set this live. This is my my wife recording me do pressing the big button on GitHub which says go live. Um, and the reason that I had to do this is because we were working in a private repository. We were not developing in the open. On the launch day, I received lots of contradictory messages. I got an IM from my boss saying, "Yeah, go for it." And then immediately I got one from uh the press team saying, "No, no, hold off." And then my boss's boss said, "Yeah, yeah, go for it." And then the number 10 press team said, "No, no, no. We need to wait until the prime minister has said something." It was it was so stressful and so maddening. You know, it was pandemic pandemonium. So I think we can be forgiven. But the lesson here is you need a robust launch plan. You need something you have agreed to in advance. Otherwise, it will just be too stressful. Um, so anyway, the the app was released in in in the various app stores and you could download it and the source code was open at the same time. But even though I think we did a pretty good job of explaining what open source was, why we were doing it, uh, some people still weren't happy. As I said, uh, we we released it, we made a big announcement saying, "And it is now on GitHub." Um, and this is I love this. This is a genuine message uh that that was sent and was copied into a politician uh which was that GitHub is the sharewware developers free-for-all site. It is written by hobbyists. So I I haven't heard the word shareware in at least 20 years. So you know there you go. Don't use GitHub. It's it's just for shareware. But look, it is it is tempting to laugh at people like this and I do. But how how do you explain to everyone in your community what open source is, why you were doing this, why you're using GitHub, why you're doing this. Um, and internally it wasn't that hard, but you know, we had people, you know, talking to developers, they get what open source is. Most designers who work in in digital get it. But you have lawyers coming on board and politicians and people who are very good at their jobs and very intelligent, but they've never heard of open source before. You need to find a very simple way to explain to everyone in your community why you were doing these things. Otherwise, it causes confusion. Um, so, so I mentioned before uh that we were developing in private and then releasing in public. Um, so I'm going to talk a little bit about our git history. Um, so you know that on GitHub, GitLab, any any git project, you type, you make a commit and you boom and there you can see all the commits that everyone has made and when they've made them, who made them. We didn't have that. We developed in private and then every time there was a new release of the app, we uploaded a new version of the source code. So you can see a diff between the two versions, but you cannot see individual commits. You cannot see that an made this commit and that Bob made that commit. All of our history was squashed. Now, why did we do this? Well, the first was security. Maybe someone committed something they should have. Maybe someone left in a debug key which, you know, maybe we quickly revoked it, but we weren't quick enough. Maybe someone left in some information which would have been useful to an attacker. I do not believe in security through obscurity but this was an app which was going to be used by every single person in the country. This was an app which was going to be scrutinized by every uh foreign intelligence agency. This was going to be examined by everyone who wanted to do us ill. So we made that difficult decision. We're going to squash the history. We didn't want anyone seeing individual commits which might contain uh something we didn't want them to see. Um the second uh was the privacy of our developers. As as I've shown you, this this was being spoken about on the nightly news. We didn't want our developers to be under any more pressure than they already were. Can you imagine being Twitter's main character because you left off a semicolon in a commit message? I mean, no one wants that pressure, right? Um, we we didn't want them to be targeted by fishers or state sponsored attackers. You know, if you can see that this GitHub user is committing to the government's repo, wouldn't it be tempting to send them a message, please click here to reset your 2FA token? Um, you know, this is what we saw happen recently with with the npm supply chain uh issue. it it is depressingly and distressingly easy to fish people who are working on high-profile uh code. So with each new release of the app, we squashed the history. We uploaded a new version. Again, I don't know if that's the right choice or not. I think I can justify it to you and I can justify it in public, but we're going to put it to a vote because I know people have strong feelings on whether you should be able to see, you know, individual commit history. So again, a straight vote. we were right to um squash a history or we were wrong. Every single git commit should have been public. So hands up, we were right to strip the history. Okay, quite a few of you. Thank you. And hands up, we were wrong. We should have released everything. More than a few I like I say, I can't necessarily recommend doing it this way, but I think it is justifiable for some things and I completely respect the the difference of opinion there. Um, and incidentally on on the open- source uh licensing point of view, I had this argument with someone. I I don't know of any license which entitles you to every commit. You're entitled to the source code but not the history. I don't know. Again, that's one to discuss over a few beers until 4:00 a.m. Um, so here's another problem that we faced and you might face too. Um, we had comments in our code. Comments help people understand what the code is. Comments are normal. Um, but we wanted to leave them in obviously, but we had a problem and it's that programmers programmers think they're funny. We had to let them know, do not put anything in the comments that you don't want to see on the front page of a tabloid newspaper tomorrow morning. Um, I mean, I would I would love that, you know, if if the tabloids ran with the government says tabs, not spaces, and it's and it's you who are [Music] they're never going to run that story. Um, so we we, you know, we went through this tedious exercise of sort of sanitizing comments. You know, people left comments about their frustration. Oh, I can't believe this bloody API doesn't work. Yeah, getting rid of that. Or bits of personal info. Can can you tell Sue to fix tod do tell Sue to fix this? You know, we we didn't want any of that in there. Um but there was still some problems with comments. So we had oh this is very boring. We we had um a process which spawned lots of subprocesses and sometimes they would time out and they had to be res and so there was a comment about that and it was all very normal and boring. But the the comment was this. When the signal is received, terminate all nonresponsive children. Do not log any data about this and spawn a new doom. [Applause] This is accurate. This is accurate. You know, like everyone here knows what this means, right? I know what this means. You know what? But imagine you've been soaking up 5G COVID conspiracies and you think, I'm going to look through the source code and you see this doesn't look good, does it? Um, [Music] so [Music] here here's a lesson for you. If someone wanted to maliciously or, you know, maybe through ignorance misunderstand your your code, could they do it? You we talk about self-documented code. Your do comments have to be so clear. Um, so how how do you curate a culture where non-coders can understand what you're doing, where they can get involved and understand? So we had people wrote to their members of parliament uh and they asked questions and we we answered them. We had blog posts which had comments open and we also had technical forums. We had open issues on GitHub. Uh but as anyone who has managed a forum knows, technical questions very quickly slide into political questions. So, uh this is me moderating a conversation and shutting it down, saying, "I'm sorry, we're not talking about this." We had a very strict code of conduct, and I encourage you in all of your projects, have a code of conduct. Um it it is an impossible balance to get right. People will complain when you do moderation like this, but it is better than the alternative. It is better than letter letting discussions go off the rails and fester and people going completely off topic. Um you have to moderate and and that's not just get rid of the spam. It's going I know where this conversation is going and we're stopping it now. People will be pissed off with you, but sometimes you need to keep your community safe. And that does mean saying, "Look, there are better v venues for discussing this thing. We're here to talk about this other thing." You need to invest in moderation. Moderation is a professional skill and it is a skill I do not possess. I I don't We We ended up getting a professional moderator team. We paid people to do it. You need volunteers. You need paid people who will who are dedicated to this. Um, now look, I am being really down. Um, and and I don't mean to be because for every negative message we received, we've received hundreds which were positive. We had loads of people in GitHub saying, "This is brilliant. I'm so pleased it's open source." We had people sending pull requests. We had a bug bounty. We had lots of people talking about it in the press. And it was just getting better and better and better. And then one day this happened. It just stopped. I received a message on my phone saying that they were shutting down the project I was working on. And it was like a punch to the gut. This was the biggest project I had ever worked on. It is probably the most important thing I will ever work on. And they were killing it off. Whenever you work on a big open source project, you want it to last forever, right? You just want it to go on and on, but it can't. All all things come to an end. If this app was still running today, it would mean that we had failed. It was right that it was shut down. It had done its job. But here's the lesson for you. How do you prepare to shut down an app? What's the groundwork that you need to do? You need to have a document which says, well, these API keys have to be revoked. We need to shut down the servers in this order. We need to put out announcements. We need to give people this much notice. It is v. It is just as important, I would say, as starting a project as stopping a project. I don't think we're ever going to be truly post pandemic, but through a combination of changed behaviors and vaccines and yes, this app, we we turned a corner. And the legacy of open sourcing the app is is a mixture of things. Primarily, it's this. It saved lives. The app saved lives. Um, open source wasn't the only bit of that. But if the app wasn't open source, I know a few people in this room who wouldn't have installed it, would have told their friends and family not to install it. I would have I would have said the same. It being open source increased the trust in the app. We now understand what technology works, what doesn't. We know what vaccines work, what doesn't. This is me getting my first vaccine all those years ago. I was so excited. All of us have learned lessons from this horrific experience. And I hope the lessons that governments and health services have learned is that opensource is vital. It any new app that governments create has to be open source. Um and it's not just the UK that learned those lessons. Uh I was dealing with counterparts from from across the world talking to them about the problems they were facing, we were facing. We shared tips and tricks and code. Um now as far as I can tell, these are all the countries that open source their apps. I apologize if I've missed any off. And you can see they all used a variety of technologies. Not all of them used Google Apple exposure notifications. Some used their own Bluetooth. Some use um uh DP3T or GPS. That that's fine. Uh not all of them use MIT. So the the people who said other licenses, yeah, plenty of countries did that. Um is there anyone from Latvia here? Uh Dexter, are you here? I want to know why Latvia chose Creative Commons for their source code license and I will buy you a beer if you can explain it. Um so I I'm want to leave you with a speech that um the UK's then prime minister Rishi Sunnak made just before the general election. So this is the prime minister of our country in a bid for reelection and and this is a transcript of his speech. We are pro- opensource. This is I I really can't tell you how much this blows my mind that in a major speech to try and get reelected, the prime minister says there must be a very high bar for any restrictions on open source. We're open sourcing what we've built. There's going to be an opensource day. it you know it is so enormously gratifying that you know between our team and all the other teams working in government open source made such an impact that Rishi Sun the prime minister said we are pro- opensource now of course he did lose that election but you know I don't think it was his stance on free BSD versus open BSD or you know GPL versus MIT that that caught him out um Yeah. So, um, in in the spirit of, uh, political neutrality, here is, uh, the the UK's current prime minister, K star, also talking about open source. Uh, and there's a reason AI, one of the champions of open have just announced a UK office. This this is the legacy of that co tracing app being open source. The words open source aren't in a technical document. They're not page 500 of a treaty. They're not something that is referred to over there. Open source is being spoken about at the highest levels of government and it's being spoken about positively. And that legacy of open- source triumph belongs to everyone here. It belongs to everyone who has released code. It belongs to everyone who was sat in a meeting with their manager and said, "Oh, can we open source that?" It belongs to everyone who's written to their politicians and says, "I demand that this be open source." It belongs to everyone who raises issues uh who comments on something who gives praise to open source projects who releases open source codes that makes it the you know the the thing which powers the modern world. This is the lesson that I learned from helping open source the UK's co tracing app is that opensource is not about code. Open source is about community and it is you the community who saved the day. So thank you very much indeed. Thank you. Thank you. Thank you. I really appreciate Thank you. That that that is enormously gratifying. I um those are my contact details. I think we've got time for a couple of questions. Someone will shout at me if we don't. Um there is a mic. Um so if you do have any questions, please stick your hand up or uh come and find me. Um I'm going to be around all weekend. Probably not staying up till 4:00 a.m. drinking. We'll see. Um so any questions? Uh or we all very eager to get to uh the coffee break? >> Tabs or spaces? >> Tabs versus spaces. It's a trap. Um, tab tabs for indenting, spaces for formatting. Um, I really wondered where that was going to go. Um, all right. Thank you so much uh for for coming to my talk. Thank you so much for being here. Um, and I will see you in the corridor later. Thanks everyone. Cheers.