libraryh3lp logo

LibraryH3lp Blog

LibraryH3lp is software used by libraries, educators, and non-profits for better customer service.

Showing posts with label chat box. Show all posts
Showing posts with label chat box. Show all posts

Saturday, May 22, 2021

End to End Encryption (E2EE) for chats

Saturday, May 22, 2021

From the beginning, LibraryH3lp has been designed as a privacy-first application. Guests chat anonymously as there is no requirement or option for guests to enter any sort of identifying information such as email address or name to begin a chat. As a customer, you are the main custodian of your subscription data and control your internal users, queues, and transcript retention (which is an opt-in feature). In this vein, we are excited to offer a new optional feature for web-based chats -- end-to-end encryption.

Released as follows:

  • Canada: May 22, 2021
  • Europe: May 29, 2021
  • Singapore: May 29, 2021
  • Main (North America): June 20, 2021

What is end-to-end encryption (E2EE) and off the record messaging (OTR)?

End-to-end encryption (E2EE) means that only the two parties (ends) participating in a chat can read the messages. No one else (including LibraryH3lp support personnel) can read the messages because the messages are encrypted. The specific cryptographic protocol used to encrypt chat messages is Off the Record Messaging (OTR).

As a further proof against man-in-the-middle (MITM) eavesdropping, operators answering chats in the webclient for staffing can optionally provide the private key from a Digital Signature Algorithm (DSA) key pair so that the guest's chat box (which has the matching public key fingerprint) can confirm that the answering operator is authorized to communicate with the guest.

Note: E2EE/OTR is not available nor planned for SMS (texting) chats.

Wait. Aren't chats encrypted by default?

Yes. Even without setting up E2EE, guest chat boxes use HTTPS by default and the operator's webclient for staffing always uses HTTPS. With HTTPS, chat messages are encrypted in transit over the network. However unlike with E2EE chats, these chat transcripts can also be read by authenticated users that have appropriate permissions in Chat History while a chat is active, and also after a chat has ended if transcript storage has been enabled. Chat transcript retention provides the ability for later access and can be useful for things like training, data assessment/analysis, and personnel review.

Even though this OTR chat is active, its transcript cannot be seen in Chat History.

If my chats are already encrypted, why would I want to set up E2EE/OTR?

Actually we anticipate that most customers will not set up E2EE/OTR, since messages are encrypted in transit via HTTPS and the ability for later transcript review is an important part of quality assurance, assessment, and training for many organizations.  

However customers in countries with very strong data privacy regulations or any customer with stringent privacy requirements might be interested in E2EE. For example, if E2EE is configured, then there is no way for LibraryH3lp support staff to access chat transcripts, and that can be an important feature.

Generally how does OTR work?

The guest does not have to do anything special to initiate an OTR chat. Your local administrator sets up OTR ahead of time as part of the chat skin used for the chat box. When the guest sends a message to begin a chat, they'll see a brief "Connecting..." indicator which indicates the start of the OTR negotiation process which happens automatically and behind the scenes between the two ends of the conversation (the guest and the answering chat operator).

When the chat goes out to the operator(s) in the webclient, the operators see a note that the chat is OTR and, instead of plainly seeing the guest's initial message(s), the operator(s) must first claim the chat by clicking a button. Only after an operator claims the chat, will the operator actually see the guest's message(s). The operator can close the chat window if the operator does not want to claim the chat, leaving it open for another receiving operator to claim.

The chat operator cannot see the guest's messages until the operator claims the chat. Alternatively the operator can close the chat window, leaving the chat available for another receiving operator to claim.


How do I enable OTR for my chat box skins?

To get started, the local LibraryH3lp administrator generates a public key fingerprint / private key pairing for all chat box skins within the admin dashboard (US, CA, EU, SG) using the "Manage Off the Record Chat (E2EE)" button. We recommend regenerating the public key fingerprint and private key on a routine schedule as a best practice. Using keys for up to one month is generally considered safe, and the typical recommendation is to regenerate keys weekly.

Refer to our how-to guide that walks you through the process and has lots of extra details and screenshots.

Friday, January 15, 2021

Updates to the Chat Box for Guests

Friday, January 15, 2021

We recently announced a new emoji set for the chat box that guests use on your website and teased that there were more changes to come. We've made good on that promise with even more chat box improvements. 

These improvements are being rolled out progressively across our service regions.

  • sg.libraryh3lp.com: released January 15, 2021
  • ca.libraryh3lp.com: released January 29, 2021
  • eu.libraryh3lp.com: released January 31, 2021
  • libraryh3lp.com (main server): coming soon!

Simplified Mobile Experience

Previously, we offered two separate layouts for the chat box -- one layout was shown to guests chatting using a desktop or laptop and one layout that was shown to guests using smaller mobile devices like phones. Now guests will see the same chat box layout no matter what device they choose to use to chat with you.

The history behind the two layouts stems from the early days of mobile where there was spotty support for chat box features such as file upload and even reliably getting the Enter button to send a message. These days mobile devices are much more sophisticated and support for all the chat box features is commonplace.

Bug Fixes

1) The chat box should clearly identify the sender of an uploaded file or image. It used to be that the upload was always attributed to the operator. One caveat with this bug fix is that on occasion the guest may still encounter the original behavior within Chrome; we expect that Chrome will iron out that remaining wrinkle with a future update.

2) When a guest pops out the chat box on a web page (like you can do with our support chat box in the sidebar of this blog) into a separate window, the conversation will update in real time in both places. It used to be that only the operator's messages updated in real time in both places. Now the messages from the guest will also appear.

Embedded chat box screenshot showing the pop-out button

Even more to come!

One last thing... and we've saved the best for last! We are actively developing a next generation chat box. Its default view is sleek and sexy, has built-in offline contact handling, plus a whole bunch of new features that folks have been requesting. More details as well as how to upgrade (if you want to upgrade, no pressure) will follow closer to release. And don't worry, the upgrade won't cost you anything extra -- it's included as part of your base subscription.

Thursday, December 31, 2020

Updates to Chat Box and Webclient for Staffing

Thursday, December 31, 2020

On the heels of recent updates to the webclient, 3mail, and admin dashboard, we're updating the chat box for guests too! We have more changes to the chat box in the works, but to kick things off we've modernized and expanded the emoji available to guests and operators during a chat. 

The new emoji set is being rolled out progressively across our service regions.

  • sg.libraryh3lp.com: released December 31, 2020
  • eu.libraryh3lp.com: released January 8, 2021
  • ca.libraryh3lp.com: released January 8, 2021
  • libraryh3lp.com (main server): January 16, 2021

Emoji for Chat Box

On the guest's side, the new emoji (as with the old emoji) can be inserted into a chat via shortcuts typed as part of a chat message.

Emoji in Webclient

On the operator's side, the new emoji (as with the old emoji) can be inserted into a chat via shortcuts typed as part of a chat message or via the emoji selector in the webclient for staffing (screenshots below).

emoji button
Screenshot of emoji button available for chats within the webclient


Screenshot of emoji selector dialog that appears when you click the emoji button