Bonum Certa Men Certa

Debian Leadership Falsified Harassment Claims in Jacob Appelbaum (of Tor, Wikileaks Etc.) Expulsion

Reprinted with permission from Daniel Pocock

In 2016, there was an enormous amount of noise about Jacob Appelbaum from the Tor Project and winner of the Henri Nannen Prize for journalism.



An anonymous web site had been set up with allegations of harassment, abuse and rape. Unlike the #MeToo movement, which came later, nobody identified themselves and nobody filed a police complaint. It appears that the site was run by people who live in another country and have no daily contact with Appelbaum. Therefore, many people feel this wasn't about justice or immediate threats to their safety.



Long discussions took place in the private mailing lists of many free software communities, including Debian. Personally, as a I focus on my employer, clients and family and as there are so many long email discussions in Debian, I don't follow most of these things. I've come to regret that as it is now clear that at least some claims may have been falsified, a serious injustice has transpired and this could have been easily detected.



I don't wish to discount the experiences of anybody who has been a victim of a crime. However, in the correspondence that was circulated within Debian, the only person who has technically been harassed is Jacob Appelbaum himself. If Appelbaum does have a case to answer then organizations muddying the waters, inventing additional victims, may undermine the stories of real victims.



The Debian Account Managers (DAM) had sent various emails summarizing the situation. I quote one of those:



Subject: Re: What is true and what is false in accusations against Jacob Appelbaum
Date: Sun, 21 Aug 2016 14:32:03 +0200
From: Enrico Zini <enrico@enricozini.org>
To: Debian Private List <debian-private@lists.debian.org>



On Fri, Aug 19, 2016 at 02:33:53PM +0100, Dimitri John Ledkov wrote:

> No, the decision was not made based on those accusations but based on > Debian's own member contribution / testimonials to the appropriately > delegated team.

Indeed. I noticed a tendency, when famous people are involved, to put the celebrity at centre stage and give everyone else nameless walk-on parts.

In this story, and in Debian especially, there were several players on stage. In -private we have read first-person stories by Erinn Clark, Jérémy Bobbio, and Ximin Luo. In DAM's mailbox we have read stories from 3 more people who are well known and trusted in our community.

... snip ...

Enrico (with input from Joerg and Christoph), as DAM


I had taken comments like that at face value and not looked any deeper. Zini is referring to six "testimonies" in total, three have been hidden and Zini expects us to trust him. Secret evidence is normal in countries like North Korea but it has no place in Debian.



Nonetheless, in 2018 I resigned from some of my activities for Debian due to family circumstances. Later on, I heard that people who knew nothing about my family life and the death of my father had started trying to create gossip. This motivated me to get further away from these people but on the other hand, I became curious about finding the truth in Appelbaum's case.



I started with the quote above from the DAMs and went looking for the evidence of Erinn Clark, Jérémy Bobbio (Lunar) and Ximin Luo. I found messages from each of these people, which I quote:



From: Ximin Luo <infinity0@debian.org>
Date: 2016:06:15 16:21 +0200



I and several other DDs are also Tor Project members, which is where these accusations first surfaced. I myself have tried to stay away from the messy details of the situation, but I do know that some of these other DDs have personally spoken to some of the accusers, whom they have known as friends in real life for a while. These accusers are also known and respected within the infosec community, which is why you will see so many of them voicing opinions against Jake. It's probably not too hard to deanonymise some of them, if you tried.



From: Erinn Clark <erinn@debian.org>
Date: Wed, 15 Jun 2016 11:08:32 -0400



+1 I've been much more involved in Tor than Debian for the past 7 years, but I can personally vouch for at least 3 of anonymous victims (who are known to me). This is not a state-sponsored attack.



From: Jérémy Bobbio <ltlunar@debian.org>
Date: 15/06/2016, 18:39



I can personally vouch for 2 of the stories on the website. I also have direct experience of Jake playing with people's boundaries, mine included since I first met him in Florence four years ago.

-- Lunar lunar@debian.org .''`. : :A : `. `'` `- # apt-get install anarchism


I remembered Zini's words, "first-hand accounts", but that is clearly not true. These three emails do not say they are from victims. They are not even witnesses, only acquaintances. They made brief references to stories from a third party. They may all be referring to the same source(s). In four years that have passed, not one of the people referred to has filed a formal complaint, so these scant emails are nothing more than rumours and innuendo.



It appears that all the developers who trusted the analysis of the DAMs have had the wool pulled over our eyes. Zini had taken these three people who heard the story from a friend and told us they were victims with first-hand accounts. We took his word for it. Zini had implied there were at least three victims in the Debian community but there were none.



This deception prompted me to look more closely at the emails that Enrico Zini of the DAM team has been sending on behalf of the Debian community. The message that caught my eye was a message from Zini to the editor of ITWire. Zini is disrespectful to the journalist, Sam Varghese and he is lobbying the editor to try and change an existing news report. Zini uses exactly the same fake victims as part of the justification and he even asserts the DPL quote is correct:



Subject: On coverage of Abbelbaum being "banned" from Debian
Date: Wed, 22 Jun 2016 09:34:50 +0200
From: Enrico Zini <enrico@enricozini.org>
To: andrew.matler@itwire.com



Dear Editor in Chief of iTWire,

you may want to do something about this article by Sam Varghese on Debian revoking membership of Jacop Appelbaum: http://www.itwire.com/business-it-news/open-source/73441-appelbaum-banned-from-debian-events-after-sexual-misconduct-charges.html

While the first part is factually correct in its DPL quote, the article ends with baseless hints of Debian and Tor having fallen victims to manipulations by GCHQ psyops.

I consider that to be psycological violence[1] against the various well known people who came out to report abuse, and I wish that news coverage about this situation could rather contribute to creating a community that encourages victims of abuse to speak up.

Quoting the DPL again, "In reaching their decision, the Debian Account Managers took into account the public disclosures from members of the Tor project and others, and first-hand accounts from members of the Debian community."

We are not talking about vague rumors spread by a couple of infiltrators, we are talking about first-person accounts provided by well known and respected members of both communities, with a track record of contributions of many years.

These people who had the guts to speak up deserve credit and respect, and the article published on your site gives them none.

[1] https://en.wikipedia.org/wiki/Gaslighting

Regards,

Enrico


Enrico Zini, Debian, Falsified harassment claims, Jacob Appelbaum, Perjury

Enrico Zini, DebConf18, Taiwan



The Debian Project Leader (DPL) had copied the same words from Zini and used them in statements distributed to the press. I couldn't help wondering: if the illusion of victims in Debian hadn't been conjured up by Zini, Debian never would have made a public attack on Appelbaum.



Looking through the web, I was able to quickly find a range of news articles mentioning the first-hand accounts or Debian's expulsion of Appelbaum. Each of these journalists and editors had been deceived by Zini too, with staggering consequences for Appelbaum.



Here are some of them using the exact same words:





All the largest media outlets, including respected names such as The Guardian, NY Times, Wired and Washington Post had mentioned the story in one way or another. The ferocity with which accusations were spread and elaborated by people like Zini may well have contributed to this extraordinary impact.



While this looks like an incredibly serious deception, I still wanted to give Zini the benefit of the doubt and consider the possibility that this was an act of gross incompetence and not a deliberate lie. How can we reliably distinguish one from the other?



The first thing that makes me consider this was no accident is that the publicity didn't occur in January after the New Year's Eve party. A more thoroughly researched piece by Die Zeit notes the Tor Project supervisory board elections were imminent at the time of the accusations in June. This provides a clear motive for rivals seeking Appelbaum's position. The second major consideration is that Erinn Clark, one of the not-victims quoted above, was lobbying for Debian to make a public attack on Appelbaum. That is cronyism, Erinn Clark had a clear conflict of interest arguing for public revenge on behalf of a personal friend. Nevertheless, Debian's leader was pursuaded by Clark and others to make a damaging public attack on Appelbaum, including a reference to the fake victims. Thirdly, one of the three people had tried to correct Zini, but Zini never made any effort to correct the communications after this:



From: Ximin Luo <infinity0@debian.org>
Date: 21/08/2016, 17:31



... snip ...

To nitpick, I did not submit a "first-person" story about Jake. I said that the accusations were from credible people and not anonymous sources or government agents.

... snip ...


Zini's mistake was no typo.



People's lives are destroyed by vendettas like this and Debian has recklessly amplified them. The DAMs and other people who were appointed to consider such matters appear to take it no more seriously than running a WhatsApp group or a multi-user role-playing game. To this day, the falsified references to fake victims remain in the debian-private list archives accessible to all volunteers. Many newspaper editors would be keen to remove such statements and publish retractions but Zini has pursued a competing goal, lobbying them to make their reporting more adverse to Appelbaum, as the email to ITWire demonstrates.



Two years after the Appelbaum events, Zini gave a talk at DebConf18, Multiple People, where he comes out about his move into the queer space. That is not such a big world. Appelbaum, the accused, also explains that he identifies as queer: there is real concern that Zini may have had conflicts of interest with people who were mutual acquaintances of Appelbaum. According to the anonymous claim of rape published against Appelbaum under the pseudonym River, the victim was unconscious and woke to find she was not alone with Appelbaum: other people were in the room watching. If that assault really happened, with an audience from this inner circle of infosec specialists, how many of the people were from Debian? Was Zini in that room himself? If they saw this happening with an unconscious victim, why didn't they intervene?



Whenever I've asked about conflicts of interests in Open Source projects, people have responded unprofessionally, denouncing the questions as harassment with almost the same ferocity that they threw at Jacob Appelbaum. People have tried to ridicule these basic ethical concerns as mere conspiracy theories. In the worst cases, some people threatened never to talk to me again. That would be very convenient: helping me identify the remaining members of the Debian community who do have some integrity.



Open Source organizations have taken to vague and overgeneralized Codes of Conduct that say little about these issues, the Debian Code of Conduct being a typical example. Compare that to the Association for Computing Machinery (ACM) Code of Ethics, where point 1.3 makes it unambiguous:



Computing professionals should be honest about their qualifications, and about any limitations in their competence to complete a task. Computing professionals should be forthright about any circumstances that might lead to either real or perceived conflicts of interest or otherwise tend to undermine the independence of their judgment.


On the contrary, Zini did not have the competence to investigate a serious crime but he may have had multiple conflicts of interest.



Linux Australia had taken a more moderate approach than Debian, anouncing on 22 June 2016 they would wait for the matter to become clearer before any decision about Appelbaum's participation in events down under. They were persuaded to change their minds, either they were threatened like me or subject to a subversive lobbying campaign, similar to Zini's attempt to corrupt IT Wire's reporting. Barely eight days later, on 1 July 2016, they came out with a statement saying that Appelbaum would be banned from future events.



The attack statements from all of these organizations include monotonous texts about Codes of Conduct. None of them comment on how potential victims can seek support from people qualified to assist victims of crime. None of them remind people that the accused is innocent until proven guilty by a competent tribunal.



If I hadn't already resigned from my role in Debian, I would do so now. It is completely inexcusable that people in leadership positions can set up a kangaroo court, falsify evidence and hide their conflicts of interest when dealing with such a serious matter.

Recent Techrights' Posts

Mobbing at the European Patent Office (EPO) - Part IV - EPO Can Get Away With Murders, Suicide Clusters, and Systematic and Prolonged Bullying by 'Team Campinos' ("Alicante Mafia" as Insiders Call It)
Nobody in the Council or the EU/EC/EP gives a damn as long as laws are broken to fabricate 'growth'
Jeff Bezos Isn't Just Killing the Washington Post, He's Killing Thousands of News Sites/Newsrooms (in Dozens of Languages) That Rely on It for Many Decades Already
Not just slopfarms; even the Ukraine-based reporters are culled by Bezos, who's looking to please the dictators of the world
Central Staff Committee Confronted António Campinos for Giving His Cocaine-Addicted Friend Over 100,000 Euros to Do Nothing, Just Pretend to be Ill, While Cutting the Salaries of Everybody Else
"On the agenda: Amicale framework & Financial assistance for courses"
How to Win Lawsuits in 5 Simple Steps
Keep issuing threats every week and send 60 kilograms of legal papers to the target
Living in Freedom When 'False Flag Operations' Like EFF Get Captured by Billionaires to Take Freedom Away
There are many ways to think of Software Freedom
Changes at the Solicitors Regulation Authority (SRA)
SRA is basically a waste of money
 
Links 06/02/2026: Voter Intimidation and Press Shutdowns in US, Web Traffic Warped by LLM Sludge
Links for the day
Does Linux Torvalds Regret Having Dinners With Bill 'Russian Girls' Gates?
See, the rules that govern the Linux Foundation and its big sponsors aren't the same rules that apply to all of us
IBM: Cheapening Code, Cheapening Staff, Cheapening Everything
IBM's management runs IBM like it's a local branch of McDonald's. IBM is a junk company with morbid innards.
GNU/Linux Measured at 6% in One of the World's Largest Nations
Democratic Republic Of The Congo
Linux Foundation Operative Says We and Our Software All "Owe an Enormous Debt of Gratitude" to a Software Patents Reinforcer
The only true solution is to entirely get rid of all software patents
More Than 99% of "AI" Companies Aren't AI, They're Pure BS
We need to discard those stupid debates about "AI" and reject media that gets paid to participate in such overt narrative control (manipulation like The Register MS)
AI Used to Save Lives, Now "AI" is a Grifting Scheme That Burns the Planet and Will Crash the Economy
What the media calls "AI" (it gets paid to call it that) is the same stuff that could instead be dubbed "algorithms"
Amutable is a Microsoft Siege Against Freedom in GNU/Linux, Just Like the People Who Brought You 'Secure Boot' Controlled by Microsoft
Do whatever is possible to avoid Amutable and its "products"
Growing Focus on Publication
Over the past ~10 days we always served more than a million Web hits per day
"Going to be a large number of Microsoft layoffs announced soon"
Everybody knows a giant wave of layoffs is coming Microsoft's way
End of the 'GPU Bubble' and NVIDIA Finally Admits It Won't Bail Out Microsoft OpenAI Anymore
circular financing (financial/accounting fraud)
Corrupt Media Won't Hold Accountable Rich People for Role in Pedophilia
Journalistic misconduct or malpractice is a real thing
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, February 05, 2026
IRC logs for Thursday, February 05, 2026
EPO Management ("Alicante Mafia") Not Properly Sharing Information on Scale of Strikes by EPO Staff
disproportionate (double) deductions in salaries against people who participate in strikes, which are protected by law
Gemini Links 06/02/2026: Slop/Microslop, Home Assistant, and Valid Ex Commands
Links for the day
Blackmail evidence: Debian social engineering exposed in ClueCon 2024 talk on politics
Reprinted with permission from Daniel Pocock
Bitcoin crash: opportunity or the end game?
Reprinted with permission from Daniel Pocock
Claims That IBM Will Lay Off 20% (or 15%) of Its Workforce This Year Unless It Finds a Way to Push Them All Out by Threats, Shame, Guilt
Where are the articles about IBM layoffs?
IBM Isn't a Serious Company Anymore, It's a Ponzi Scheme Operated by a Clique and It Misuses Companies It Acquires to Prop Up or Legitimise the Scheme
IBM seems like it's nothing but a "Scheme"
Google News Drowning in Slop About "Linux" (Slopfarms Galore)
Google should know better than to link to any of these slopfarms, but today's Google is itself a pusher of slop
Links 05/02/2026: EU Commission Gutting Net Neutrality
Links for the day
Gemini Links 05/02/2026: NixOS Books and Monochrome Emojis
Links for the day
Links 05/02/2026: Canadian Government Uses US LLMs to Override Expert Opinions, NVIDIA Troubles Due to Enablement of Mass Plagiarism ('Piracy') Misleadingly Obscured as "Hey Hi"
Links for the day
Explaining the Letter From JUDGE SYKES FRIXOU, Threatening Me Around the Time GNOME's Nat Friedman Lost His CEO Job at Microsoft GitHub and His Best Friend Got Arrested for Strangulation
this letter (with annotation) is critical
Linuxiac Not Rehabilitated, It's Still Full of LLM Slop (Part of a Trend)
The Web as a resource/source of information is perishing
"Sponsored by Azul" to Write Fake 'Article' About Azul, Quoting Azul Itself
The "journalism" industry [sic] became so utterly corrupt
JuristGate is for sale: three billion Swiss francs for a domain name
Reprinted with permission from Daniel Pocock
Like Microsoft and IBM, the 'Alicante Mafia'-Governed EPO Does PIPs Nowadays (at the EPO, It's "Professional Incompetence Procedure")
So "PIPs" are definitely in the EPO and we saw letters sent to staff
Time for Change, More New Articles, Less Curation
The oligarchy wants to gut the real press and replace media with slop and social control media (or social control media with slop in it, i.e. their own voices, mechanised)
Gemini Links 05/02/2026: Coercion, Antibiotics, and LVDT Project
Links for the day
Almost 1,600 EPO Employees Went on Strike Last Week
There is another strike coming 2.5 weeks from now
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, February 04, 2026
IRC logs for Wednesday, February 04, 2026
Links 04/02/2026: Extreme Malice in Microsoft's Visual Studio Code on GNU/Linux, More Hey Hi (AI) Chaos
Links for the day
Sexism & GNOME: shaming men, hiding women, Sonny Piers update
Reprinted with permission from Daniel Pocock
You Know Microsoft's "Value" is 100% Fictional When in One Single "Trading" Day in Wall Street It Loses THREE TIMES More in "Value" Than It Was 'Worth' in 2009
Microsoft does not behave like a company riding trillions but like a company that struggles with payroll
Gemini Links 04/02/2026: Humanity and Animality, systemd (Controlled by Amutable, a Proxy of Microsoft) Moves on to "Extinguish" Phase
Links for the day
Better Outcomes When Facing the Discomfort of Conflict
Don't take the easy way out when the "hard way" is the right way and it can result in positive revelations
Certificate Authority Let's Encrypt Used to be Widely Used in Geminispace, Now It's Down to Just 0.2% of the Whole
Let's Encrypt is not your friend
What IBM Does Is Clearly Illegal in the US: Tying Severance Packages to NDAs (Non-Disparagement Agreement/Clause)
The NDAs make things worse; they keep people isolated and silent
Microsoft's Giant Snowball of Layoffs and PIPs (in 2026)
They would delay until March or April if they wanted to, but then we can expect numbers exceeding 10,000 layoffs (Microsoft always low-balls the real figure/s)
Mozilla Turned Firefox Into Shovelware, Adding 'Kill Switch' for Slop Still Means Mozilla is Participating in a Pyramid Scheme, Plagiarism, Grifting
Mozilla is still a slop pusher
Leaving the United States 3 Years Ago Was the Best Decision We Made
A lot of stuff is being consolidated
Links 04/02/2026: "Laws of Succession" and Microsoft's VS Code as Code-Stealing Malware
Links for the day
BillBC (BBC) Covered Up Pedophilia, Now It's Covering Up for Its Sponsor Bill Gates by Reprinting His Lies, Which His Own Wife Disputes
Is Bill Gates having orgies (group sex)?
Phoronix Swims With the Real Trolls, People Who Fancy Proprietary Software and Back Doors
If Larabel begins to actively participate in provocation with the "Microsoft GitHub fans club", what does this tell us about Phoronix?
They Know Microsoft Layoffs Are About to Hit Them Hard
The gaming division at Microsoft is a complete catastrophe, lots of money (debt) down the drain [...] Buying Activision was all about misleading shareholders or hiding the deep trouble/problems XBox was having
Red Hat is Not a Linux Company, It's IBM's Ponzi Scheme Enabler
Had we still been stuck in 2021, perhaps IBM would plaster "NFT" or "metaverse" all over RedHat.com
Keep Grinding
"Don't let the bastards grind you down"
Mobbing at the European Patent Office (EPO) - Part III - Who's Going to Pay for the EPO's Corruption? (Aside From European Citizens)
Some people inside the EPO reached out to us
"Investors Are Concerned About an AI Bubble" (That GAFAM and IBM Ride)
A few decades from now IBM will only be remembered in the same sense many so-called 'AI' companies will be remembered
EPO Staff Union: "Very High Strike Participation on Friday 30 January", Another Strike Starts 19 Days From Now
EPO management in a bit of a panic
Censorship/Free Speech and Social Control Media
It's important to have a grasp of how contemporary censorship works and how to tackle it
Google News as Slop Booster
this is what Google links to
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, February 03, 2026
IRC logs for Tuesday, February 03, 2026
Gemini Links 04/02/2026: "Raspberry Pi Relaxes the Rules for Its RP2040 Hacking Challenge" and "Long Web Society"
Links for the day