libraryh3lp logo

LibraryH3lp Blog

LibraryH3lp is software used by libraries, educators, and non-profits for better customer service.

Showing posts with label admin dashboard. Show all posts
Showing posts with label admin dashboard. Show all posts

Saturday, May 22, 2021

End to End Encryption (E2EE) for chats

Saturday, May 22, 2021

From the beginning, LibraryH3lp has been designed as a privacy-first application. Guests chat anonymously as there is no requirement or option for guests to enter any sort of identifying information such as email address or name to begin a chat. As a customer, you are the main custodian of your subscription data and control your internal users, queues, and transcript retention (which is an opt-in feature). In this vein, we are excited to offer a new optional feature for web-based chats -- end-to-end encryption.

Released as follows:

  • Canada: May 22, 2021
  • Europe: May 29, 2021
  • Singapore: May 29, 2021
  • Main (North America): June 20, 2021

What is end-to-end encryption (E2EE) and off the record messaging (OTR)?

End-to-end encryption (E2EE) means that only the two parties (ends) participating in a chat can read the messages. No one else (including LibraryH3lp support personnel) can read the messages because the messages are encrypted. The specific cryptographic protocol used to encrypt chat messages is Off the Record Messaging (OTR).

As a further proof against man-in-the-middle (MITM) eavesdropping, operators answering chats in the webclient for staffing can optionally provide the private key from a Digital Signature Algorithm (DSA) key pair so that the guest's chat box (which has the matching public key fingerprint) can confirm that the answering operator is authorized to communicate with the guest.

Note: E2EE/OTR is not available nor planned for SMS (texting) chats.

Wait. Aren't chats encrypted by default?

Yes. Even without setting up E2EE, guest chat boxes use HTTPS by default and the operator's webclient for staffing always uses HTTPS. With HTTPS, chat messages are encrypted in transit over the network. However unlike with E2EE chats, these chat transcripts can also be read by authenticated users that have appropriate permissions in Chat History while a chat is active, and also after a chat has ended if transcript storage has been enabled. Chat transcript retention provides the ability for later access and can be useful for things like training, data assessment/analysis, and personnel review.

Even though this OTR chat is active, its transcript cannot be seen in Chat History.

If my chats are already encrypted, why would I want to set up E2EE/OTR?

Actually we anticipate that most customers will not set up E2EE/OTR, since messages are encrypted in transit via HTTPS and the ability for later transcript review is an important part of quality assurance, assessment, and training for many organizations.  

However customers in countries with very strong data privacy regulations or any customer with stringent privacy requirements might be interested in E2EE. For example, if E2EE is configured, then there is no way for LibraryH3lp support staff to access chat transcripts, and that can be an important feature.

Generally how does OTR work?

The guest does not have to do anything special to initiate an OTR chat. Your local administrator sets up OTR ahead of time as part of the chat skin used for the chat box. When the guest sends a message to begin a chat, they'll see a brief "Connecting..." indicator which indicates the start of the OTR negotiation process which happens automatically and behind the scenes between the two ends of the conversation (the guest and the answering chat operator).

When the chat goes out to the operator(s) in the webclient, the operators see a note that the chat is OTR and, instead of plainly seeing the guest's initial message(s), the operator(s) must first claim the chat by clicking a button. Only after an operator claims the chat, will the operator actually see the guest's message(s). The operator can close the chat window if the operator does not want to claim the chat, leaving it open for another receiving operator to claim.

The chat operator cannot see the guest's messages until the operator claims the chat. Alternatively the operator can close the chat window, leaving the chat available for another receiving operator to claim.


How do I enable OTR for my chat box skins?

To get started, the local LibraryH3lp administrator generates a public key fingerprint / private key pairing for all chat box skins within the admin dashboard (US, CA, EU, SG) using the "Manage Off the Record Chat (E2EE)" button. We recommend regenerating the public key fingerprint and private key on a routine schedule as a best practice. Using keys for up to one month is generally considered safe, and the typical recommendation is to regenerate keys weekly.

Refer to our how-to guide that walks you through the process and has lots of extra details and screenshots.

Saturday, November 14, 2020

Updates to the Webclient, 3mail, and Admin Dashboard

Saturday, November 14, 2020

Where is this update?

The updates outlined in this post are being rolled out progressively across our service regions.

  • sg.libraryh3lp.com: Update live as of November 14, 2020.
  • eu.libraryh3lp.com: Update live as of November 21, 2020.
  • ca.libraryh3lp.com: Update live as of November 28, 2020.
  • libraryh3lp.com (main server): Update live as of December 19, 2020.


IMPORTANT! With this kind of update, it's a great idea to clear your web browser's cache to ensure you have the latest release.

Webclient Updates

Initial Staffing Assignments dialog

When the box for a queue assignment is checked and you see the green "I'm staffing" indicator, you will receive incoming chats on that queue.  Otherwise, chats on that queue will not be routed to you (red "I'm NOT staffing"). In this way, you can control on which queues you receive guest chats. This is all unchanged, but the new feature is an alert.

Now if at least one of your queue assignments is unchecked (shows a red "I'm NOT staffing"), a warning will appear letting you know that you won't receive chats on that queue.

Alert if you're not opted into staffing a queue.

Updated canned message management page.

The big win in the new canned messages page is a spacious editor for composing personal canned messages which includes a link tool along with other common formatting tools.

Updated editor for canned messages includes formatting tools

Updated preferences page

  •  Webclient settings are now organized into groups and given headings.
  •  We've added a play button next to sounds so you can easily preview when choosing sounds.
  •  We've added an avatar gallery so you can easily replace the default avatar.

Updated webclient preferences page

3mail Updates

Our 3mail (shared email boxes) module gets a super handy update: integration with the FAQ module.  If you have a FAQ site, you can search your FAQ site for the answer to an email question and insert either a link to it, or insert the FAQ's content and then edit further.  

Plus the existing ability to use answer templates within 3mail remains.  The new FAQ integration is yet another way to re-use existing content to save time and avoid re-writing the same answer over and over.


Inserting an answer from your FAQ (searchable knowledgebase module)


Instantly search your FAQ for an answer to share

Insert either a link to a FAQ OR the FAQ content directly


Admin Dashboard Updates (for full administrators or mini-admins)

User Management: Beta

We're offering a new user management page for beta testing side-by-side with the familiar user management page. You can access the new user management page via a green banner at the top of the current user management page.

Navigation to BETA users management page

The new user management page aims to streamline the process of creating new users and managing existing users. In particular, here is a list of new features available exclusively through the new user management page:

  • User creation wizard which includes an option to set up a new user identically to an existing user (copy).
  • Search function to quickly locate users by username, chat status, queue assignment, permissions group, folder, or email address (if set for a user).
  • Integrated management of conference rooms, canned messages, and permissions groups!
  • Revised contact management tool to simplify setting up buddies for users.
Screenshot of cloning a user
Copying an existing user

Conference Rooms

The conference room management page features a refreshed design but no new features or settings.  

Updated interface for managing conference rooms


Shared Canned Messages (Pools)

The canned message management page also features a refreshed design. 

A noteworthy improvement is the addition of a super spacious editor which supports basic formatting constructs such as links, bold, underline, etc. 

Updated canned messages management with much improved editor.

NEW! RefTracker Integration

We are excited to offer a LibraryH3lp integration with Altarama's RefTracker platform. The integration connects LibraryH3lp's tag for follow-up feature with RefTracker's customizable forms so you can easily pull chat information from LibraryH3lp for later follow-up and tracking within RefTracker.

Permissions Groups

The permissions groups management also features a refreshed design, but there are no changes to the underlying permissions management options or new settings.

Subscription Management and SSO

The subscription management page has been updated and re-organized slightly.  


The BIGGEST addition is a section for setting up Single Sign On (SSO) which is labeled "Authentication." Initially, LibraryH3lp is offering SSO via Shibboleth as part of a beta program. 

If your organization supports SSO via Shibboleth, you would be able to use your organization's login credentials to log into LibraryH3lp. If you are interested in participating in the beta program, please contact support via email.

Once we have organizations using beta SSO via Shibboleth, you'll see two ways to login to the webclient, 3mail, or the admin dashboard. 
  • If you opt to participate in the beta program, you and your colleagues will use the "Sign in via your institution" option.
  • If you do NOT to participate in the beta program, you'll use the same "Sign in" option that you've always used where you provide your LibraryH3lp username and password to login.
login screen
Login screen showing regular "Sign in" option along with beta SSO login option via Shibboleth