India fails to restrict Bitchat
+ GrapheneOS, a lot on Open Models, and more.
This past week, the Indian Cyber Crime Coordination Centre ordered GitHub to disable access to Bitchat repositories, or risk losing its safe harbour and face criminal prosecution. This came in response to student protests and a subsequent internet shutdown, where it was reported that protestors turned to open-source software to communicate without access to the internet. The Indian government was notably threatened by the surge in downloads that it scrambled to restrict Bitchat and maintain its false sense of control.
HOWEVER, open-source software proved its resilience as the Indian government was ineffective in restricting access to Bitchat and repos live on. Even more impressive, the Bitchat application can now be shared from phone-to-phone with no internet required on Android devices.
Beyond its open-source qualities, and equally important to the story, is Bitchat’s resilient and highly-effective peer-to-peer network. The software operates locally on each user’s phone and users are able to relay messages, or even bitcoin, to each other across the network via Bluetooth. It’s one of the more advanced anti-censorship technologies and is proving effective. You can learn more about it by reading its whitepaper.
And you’re probably wondering about the student protests. Well, the movement—known as the ‘Cockroach’ movement—began as a response to corruption within the education system (but actually as online satire) and has grown to be a broader movement to establish government accountability. So far, it has proven successful with the resignation of India’s education minister after these recent protests. In the end, not only did the protests prevail in their objective, but so did open-source software and peer-to-peer networks, despite the order remaining in effect.
That’s a point for speech and assembly.
An American faces prison because GrapheneOS worked
Federal agents stopped American citizen Sam Tunick at the border and demanded access to his phone without a warrant. He provided a GrapheneOS duress passcode, which did exactly what it was designed to do: destroy the phone’s data rather than surrender it. The government responded by charging him with destruction of property to prevent seizure.
The indictment accidentally cites the “Untied States Code.” Serendipitous, because this is a constitutionally untied prosecution [Editor’s note: C’mon man]. Warrantless border searches are already a corruption of Fourth Amendment doctrine when applied to devices containing nearly the entirety of a person’s private life.
A note on the law from Jason:
Section 2232 compounds the problem by criminalizing interference with the government’s lawful custody of property—even perfectly lawful property. The charging choice matters. Prosecutors did not invoke Section 1519, the conventional evidence-destruction statute, which carries up to 20 years and requires intent to impede a federal investigation or other federal matter. Section 2232 carries a five-year maximum and asks a narrower question: did Tunick knowingly act to impair the government’s lawful authority to take the property? It does not require prosecutors to allege that the deleted data was contraband or evidence of any separate crime. The crucial word is lawful: the government must still establish that agents had lawful authority to seize what Tunick allegedly destroyed.
Agents invoked the most morally repugnant accusation available. But if you think the moral turpitude of an accusation should override procedural checks on police when apprehending Americans, then you do not understand American values. Constitutional protections matter most when the government’s accusation makes them unpopular.
Nor should useful technology be judged by its worst users. Every phone should have a self-destruct feature: if a thief takes it, it dies; if a kidnapper forces its owner to unlock it, it dies. In the language of contributory copyright liability, this technology is plainly capable of substantial lawful uses. Criminals do not get a heckler’s veto over everyone else’s security.
We saw the same inversion when OFAC sanctioned Tornado Cash because North Korea used it. The restriction burdened Americans seeking financial privacy without making the software disappear or stopping North Korea. When the government cannot defeat freedom technology, it tries to prohibit the technology and prosecute its users.
I (Peter) own a Pixel 10 Fold. This case has me thinking I’m long overdue to switch to GrapheneOS.
By the way, in discussing this case, we were reminded this guy guy eating something potentially incriminating while being arrested.
Open Models
First, this NYT explanation of the open weights situation is helpful to send to friends or anyone else who is trying to catch up.
Peter responded to some musings from our friend Joe Weisenthal. Joe was questioning the real intentions of the many AI business leaders who signed on the open letter supporting open AI models.
Peter argues that, even though there may be some meta business strategic jockeying happening, we should still be happy with the result: a coalition of powerful entities supporting open source technology.
Read the X article, which does not embed nicely into substack:
The censorship issue looms large when discussing Chinese AI models. Here’s two items that caught our eye on that front:
An explanation of “Open-Washing” and how open doesn’t always mean open.
This research, which suggests that open models originating in China can be freed of their baked-in censorship:
And this from Perry E. Metzger sums up the two major camps on AI safety well,
Then there are the people who accept that you cannot perfectly predict the future, that you cannot centrally plan the future, that there will be many players in any technological revolution, that mistakes will be made, that mistakes will be compensated for, that people will figure things out as they go along, that mostly things will be okay, that there is no other realistic pathway. We will muddle through as always, doing our best in an imperfect world, and it will be fine. (Indeed, it will be better than fine.)
And here Eli Dourado lays out why the “pacing letter” signed by numerous leading AI developers is a bit rudderless.
We also learned that FIRE has an AI policy substack that has been helpful in our tracking of all this. Check it out.
Debanking
Nick Anthony at Cato asks, “Is Debanking the New Immigration Policy?”
The Trump administration’s core argument is that undocumented immigrants present a risk to the financial system because if they are deported, then they will lose their jobs and be unable to repay their loans. Setting aside all of the problems with the immigration system (…) this argument can apply to no shortage of issues.
Should banks be required to investigate marital conditions because a divorce could impact a customer’s ability to repay? Should banks be required to investigate mental health conditions because a sudden crisis could result in a lost job? A line has to be drawn somewhere.
Regardless of where you stand on the particular issue, we must stay vigilant against any broadening of the use of bulk collected data. Frankly, they already have everything. The only thing stopping them from using it is our attention.
What else we’re reading
Alex Gladstein of Human Rights Watch is a close watcher of how people around the world are using tech to survive and organize under repressive regimes. He has a new essay explaining how dissidents are using AI to build “freedom agents” that aid them in their work: “How AI Agents Are Empowering Human-Rights Defenders,” and gave a sterling interview for the BBC on the subject.
A great number of New Yorkers have had their personal addresses and names released by the city government, based on their wealth
Criticism of a proposed “AI Kill Switch” in Reason argues “the bill is an ill-thought-out, knee-jerk reaction to a single incident that could have a whole host of unintended consequences.”
A new report from WIRED says HuggingFace models are easily used to create deepfakes. This could become an important part of the open model safety debate.













