Bonum Certa Men Certa

Nepotism and Conflicts of Interest in Free Software

Reprinted with permission from Debian Community News

AS the Mollamby affair has emerged, some people have rushed to defend the privacy of Chris Lamb and Molly de Blanc (Mollamby) or dismissed it as mere innuendo without understanding the ethical issues.



What is the difference between innuendo and public interest? Evidence.



Privacy is a valid consideration, but it is not the only one. We delayed publishing our own commentary about the subject while weighing the privacy implications against the ethical issues.



Let's consider some of the evidence backing up the facts about Mollamby. Parts of the evidence have been redacted for the privacy of third parties but the material presented here accurately reflects the situation.



This is the opening comment sent by a student applying for GSoC in 2018 (Fact 2):



Date: 14 March 2018



I am [redacted/student name], ... from [redacted/country]. I’m [redacted/relationship] of [redacted/full name]


The student clearly identified a conflict of interest, giving the name of the other party and the type of relationship. The other party had also sent a similar email:



Date: 12 March 2018



... there are some students who might be interested in [redacted/project]. Even my [redacted/relationship] has been ....


As they were honest and transparent from the outset, there is no question over their integrity and no need to discuss their identities.



This is the statement one volunteer made when agreeing to be a GSoC admin in 2018:



-------- Forwarded Message --------
Subject: Re: Google Summer of Code 2018
Date: Mon, 22 Jan 2018 08:41:49 +0100
From: Daniel Pocock <daniel@pocock.pro>
To: mollydb <deblanc@riseup.net>



On 22/01/18 02:25, mollydb wrote: > I mmissed this on the application before! We need 2-5 administrators for > the application. Who else wants to be one? >

You can use my name temporarily while looking for other people to help you in this role.

... [redacted/name of other community] ...

However, I can't officially commit to help with the duties of an administrator right now.

Regards,

Daniel


No volunteer is under any obligation to provide details of their personal life. This statement alone looks like it was made honestly and in good faith, that is what teamwork is all about.



A selection meeting was scheduled for 16 April 2018 and Pocock was the volunteer who reminded people about somebody having a conflict of interest (Fact 3). He was not a party to this conflict of interest. de Blanc both acknowledged and agreed with the way it was handled (Fact 6):



<pocock> yes, but [redacted] is not involved in the
  selection process because one candidate is [redacted]
<pocock> that could be one reason we are waiting
   until the last minute to confirm the selections
[redacted/other mentor acknowledgement]
<mollydb> nice responsibile decision making :)
<mollydb> thanks for being so consciencious


People had been reminded about it in a number of emails at each stage of the selection process, it wasn't sprung on people at the last minute. de Blanc had simply left the GSoC emails to other team members:



Date: 12 July 2018
From: Molly de Blanc <deblanc@riseup.net>



As an additional note, I generally check my email once a week. For anything immediate, -please- ping me on IRC as I'll be responsive there (and can know to dive into my email).


When alerts were sent about the conflict of interest in March and April, other team members were unaware that de Blanc wasn't reading them.



Technically, it was a special case that was not strictly covered by Google's official rules. Given the huge effort volunteers make interacting with students, nobody had made the extra effort to seek Google clarification.



Now let's look at the complaint that Stephanie Taylor from Google sent to Debian on 13 July 2018 (yes, that was Friday the 13th):



Subject: Concerns around Debian GSoC students and conflict of interest
Date: Fri, 13 Jul 2018 08:23:36 +0200
From: Stephanie Taylor <sttaylor@google.com>
To: [redacted/private gmail addresses of all Debian GSoC admins]



Hello Debian Org Admins,

It has come to our attention that [redacted/position in Debian], [redacted/full name], is the [redacted/relationship] of [redacted/name], ...

This is incredibly disturbing as the Debian folks have been valued members of the GSoC community for many years and this threatens the integrity of the program.


Taylor is complaining about conflicts of interest in Debian, this confirms Fact 7.



Who would investigate Taylor's complaint? Chris Lamb and Molly de Blanc. Mollamby.



Subject: Re: Concerns around Debian GSoC students and conflict of interest
Date: Fri, 13 Jul 2018 14:49:50 +0200
From: Molly de Blanc
To: Daniel Pocock



Just as a quick heads up, I'll be talking with the DPL later today to get on the same page -- I know he also contacted Stephanie off-channel.

If you'd like to ping me on IRC, I can try to be online and accessible (today turned into quite a busy day for me) at a time that works for you.

Cheers, Molly


Notice that de Blanc does not mention her conflict of interest (romantic relationship with the DPL, Chris Lamb) in that email. Lamb never mentioned it either. Neither of them recused themselves (Fact 8). Pocock was travelling that weekend and couldn't make time to join a hastily organized meeting. As boyfriend and girlfriend, Lamb and de Blanc, Mollamby, had a meeting without the rest of the Debian GSoC admin team. When the boyfriend is also the leader of the project and when the girlfriend's conduct is in question, is it any surprise that another volunteer is blamed and the girlfriend takes over the team?



That email is the smoking gun: two people at the very top of the free software ecosystem (Debian and OSI) using a volunteer as a scapegoat for a communication breakdown that one of them had been party to.



This farce is further compounded by the fact the original complaint was about conflicts of interest.



Mollamby hid their own conflict of interest while investigating a conflict of interest.

Is this a new style of disruptive leadership? Or is it simply good old fashioned cronyism?



Even this hidden conflict of interest may not be enough to justify discussing the relationship publicly. However, they have meted out severe punishments on numerous other volunteers. de Blanc even went to FOSDEM and gave a talk boasting about demoting somebody and putting volunteers behind bars. If these people want to take on leadership positions and preach about harming other volunteers they also need to accept that their own conduct will come under public scrutiny. It is clearly not possible to talk about the way they both concealed and benefitted from a conflict of interest without also making their relationship a public matter. In this situation, the ethical transgressions heavily outweigh the concerns about their privacy.



What's more, Pocock announced his resignation from the Debian GSoC team in August 2018, if people had not behaved immaturely after that, it is unlikely any of these facts would be under public scrutiny right now.



In a non-apology email sent by the new DPL Sam Hartman, Debian confirms there were conflicts of interest and that Debian is completely unprepared for these situations:



I regret that we didn’t have better tools for dealing with conflict
of interest and hope we will develop those tools going forward.



...

The conflict of interest issue had no easy answer... There was not a clear conflict of interest policy. Sometimes in situations like that you don’t have good options.


The GNOME community have also done an excellent job of reducing this complicated situation into a concise query to their own leadership. From the GNOME Foundation mailing list:



Nobody appears to be asking about Molly.



People are asking about you (Neil McGovern). You and Lamb both come from this Debian Cambridge grouping. You are the Executive Director.

How long did you know that your new hire was also your friend Lamby's girlfriend?

Please respond transparently, we would all like to see this cleaned up so there will be no discomfort or embarrassment at GUADEC.


It is interesting to see that a student applying to GSoC appears to be demonstrating more integrity than the leader of the Debian Project and the OSI board president combined.



OSI Board at Microsoft

Conflict of interest? OSI board meeting, Spring 2018, Microsoft, San Francisco

Recent Techrights' Posts

Further Media Cut-downs
media reporting about the media being cut
Gemini Links 09/09/2025: Moon Eclipse and ROOPHLOCH Reports
Links for the day
Official SUSE Blog Still Uses LLM Slop (Bots) to Make Fake Articles (Marketing)
The company is all about sound bites
Companies Realise That Slop Doesn't Work as Advertised, Accordingly Dump It
"Hype dims as a country-wide survey of US corporations shows a sudden drop-off in AI use among firms with more than 250 employees."
Microsoft-Funded Lawsuits Against Critics of UEFI 'Secure Boot'
Remember that no company (or law firm) ever survives collaborations with Microsoft
It's Only the Second Week of September and Already Two Waves of Layoffs at Microsoft, Slopfarms and Microsoft-Funded Sites Spin It as "AI Investments" Rather Than Commercial Failure
A very large third one expected next week
If Your Machine Still Has "Secure Boot" Enabled, Then Microsoft Has a de Facto Kill Switch (Even If Your Machine Doesn't Have Windows and Never Had Windows)
It is not incorrect to call UEFI 'secure boot' a "kill switch"
 
Those Who Helped Microsoft Weaponise "Secure Boot" Against GNU/Linux and BSDs Are Fleeing
Microsofters doing what they do best: they evade accountability
Simple is Better, Simplicity is Power
That is "the advantage of having commodity GNU/Linux systems," an associate notes
Much Ado About Nonsense
Microsoft Lunduke is still all dramatisation and sensationalism
Current Events in France
It needs to dump Microsoft and other GAFAM (US) giants, move to Free software
Links 09/09/2025: US-Korea Tensions and Meta Whistleblowers
Links for the day
Links 09/09/2025: “Torrents of Hate” and Political Crisis in France
Links for the day
Gemini Links 09/09/2025: "Dedigitizing" and Forgejo on FreeBSD
Links for the day
Google News (Not Just Google Search) Lets Itself by Gamed by One Slopfarm - to the Point Almost Half of "Linux" News is Bot-Produced Plagiarism (LLM Slop With Slop Images)
That says a lot about what Google thinks of quality, even in Google News
Bill Gates-Funded Media Inadvertently Refutes the Microsoft Lie That in 2025 Microsoft Had Just Two Waves of Layoffs
There were about 12 rounds of layoffs so far in 2025
From theregister.co.uk to theregister.com (US) to The Register MS (Run by Microsoft Operatives) and theregister.ai
The best way to break this racket (or cycle of hype and harm) is to break the chains of funding
Open Source Initiative (OSI) Culture of Censorship Necessitates More Speech
The OSI bans dissent or people who merely point out that the OSI is abusive
How to Reach Us Discreetly (Other Than Encrypted E-mail)
We're still managing to maintain a 100% source protection record. We soon turn 19.
LLMs Are Vastly Worse Than a Waste of Energy and the Externalities Are Huge
Worse than just higher power bills for everybody
LLMs Versus Search (Not Replacing Search But Engaging in DDoS Attacks Against Web Sites That Permit Searching)
The state of the Web isn't just bad; it's utterly terrible
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, September 08, 2025
IRC logs for Monday, September 08, 2025
The UEFI 9/11 - Part IX - Shunning Old Computers (in 2023 the Certificate Was Updated/Overridden, Underlying Aim May Be Herding/Forcing People to Get TPM and Other 'Novel' Restrictions)
the "upgrade treadmill"
Rumour: Second Wave of Microsoft Mass Layoffs in September to Commence Third Week of September
That basically answers questions like, "Any specific date or time of the month?"
Gemini Links 08/09/2025: Reality, ROOPHLOCH 2025, and Writing Another Gemini Client
Links for the day
Updating Firmware is Not the Solution But Only Additional Risk, Disable "Secure Boot" Today
firmware blobs are buggy, secret, impossible to audit, and barely tested
Microsoft Tim's DevClass (Part of The Register MS/Situation Publishing) is Full of Slop
Looking at many sites that are full of slop images is becoming an eye sore and hallmark of text too likely generated by LLMs or 'assisted' (tainted) by them
Microsoft Trying to Fake Demand for Slop. At What Cost?
That's a giant demotion and broken promises
Reddit is Corporate Propaganda
To make matters worse, Reddit ousted many original moderators
Jeff Geerling Shocked to Discover Many Metrics in YouTube Are Fake (His Audience Turns Out to be Much Smaller)
Maybe self-host all videos, don't rely on Google's "FOMO" cheating (addiction based on false assumptions)
Sunlight is the Best Disinfectant and Kryptonite/Garlic to Vampires
Transparency (sometimes described by words like "Sunlight" or "Truth") is paramount
The Register MS Uses Slop in Articles About Slop
we are fairly certain it's slop or CG based on other people's work
Visiting a Web Page or a Public URL Should be Safe, Predictable, and Benign
It's probably too late to "fix" the Web
The Register MS (Situation Publishing) is Paid to Spread Mindless Hype for the "Hey Hi" Ponzi Scheme and That's a Serious Problem
"Sponsored by Zoom."
Links 08/09/2025: Burger King Cracked, Cox v. Sony Analysed
Links for the day
Gemini Links 08/09/2025: Socialist Computer Museum and GAFAM/ByteDance/TikTok-Dominated Net
Links for the day
Links 08/09/2025: Tim Crook Disappoints Apple Faithfuls and Zuckerberg Lies (Financial Fraud) for Cheeto King
Links for the day
EPO Workers Point Out that the EPO is Destroying the Planet Under the Guise of "Hey Hi" (It Also Grants Many Invalid Patents Illegally
On 12 March and 16 June 2025, staff representation met with the administration in the Local Occupational Health, Safety and Ergonomics Committee (LOHSEC) in Munich
Turn Off Microsoft's Restricted Boot ("Secure Boot")
We're still running a series on this issue
Social Control Media Sites Have Become Bot Farms (Not Limited to LLMs and Automation)
linkedin.com was nothing but trouble and losses for Microsoft
Deep in Debt With the Magnitude of Losses Quickly Growing, Microsoft "Open" "Hey Hi" Now Uses Broadcom for Vapourware, Pretending It'll Do OK Next Year
At some stage it'll collapse
You Can Tell Microsoft is in Trouble When Its Own Fans and Staff Blast it
"Microsoft sinks billions into chasing artificial intelligence fads to hype up its share price."
Multiple Undersea Cable Cuts and We're Still OK
Microsoft customers experience problems
Lawyers Who Think They Are Online Assassins Don't Deserve a Licence to Operate
they've become a laughing stock in their "sector"
Microsoft Windows Fell to 3.9% "Market Share" in Bahamas
Based on statCounter
How the European Union (EU) Fell Out of Love With Free/Libre Software
Lots of bribery
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, September 07, 2025
IRC logs for Sunday, September 07, 2025
Gemini Links 07/09/2025: Scanner, Slop, and Chadobear
Links for the day
The UEFI 9/11 is 3 Days Away
Nobody denies that bad things will happen
Google Versus Journalism
Google played a big role in the demise of news sites
Gemini Links 07/09/2025: Advertising, Decentralized Archival, and Outsourcing to Bezos
Links for the day
Certificate Authority Let's Encrypt Has Almost Gone Down to Zero, Nearly Totally Extinct in Geminispace, the Few Capsules Still Using It Are Spam/Dead/Stagnant
This represents another decrease for Let's Encrypt; the last decrease was last week
Not Much Left in News Cycles
To be very clear, this does not describe "Linux" anything; it's true in just about every facet of news, except the paid-for fake "journalism" about "hey hi" (sites getting paid explicitly to maintain or rekindle hype)
Trying to Silence Techrights Was a Huge Mistake
Peter Thiel attacked a publisher for asserting, correctly, that he was gay. Now everyone knows it.
Throwing Away "Old" Computers (Mozilla and Other Climate Deniers)
Mozilla is not leftist
The UEFI 9/11 - Part VIII - Denial of Service and Selling Us WSL (Windows) Instead of "Risky" (Prone by Breakage by Microsoft) GNU/Linux
Restricted Boot (so-called 'SecureBoot') does not improve security. It is nothing but trouble. It's meant to trouble non-Windows users. In dual-boot setups, SecureBoot is a recipe for disaster because Microsoft keeps erasing or tampering with the boot sector, to paraphrase an associate
Slop is Extremely Rare in Geminispace, Slop Images Are Unheard Of (Despite Images Being Supported)
As long as Geminispace grows in terms of domains it's safe to predict the protocol will still be used in 2029 and hence Geminispace will turn 10
Links 07/09/2025: Robodebt Class Action, Fines, and Copyright Settlement
Links for the day
Links 07/09/2025: Yle Impersonated in Social Control Media, Boat-Attacking Orcas, Midjourney Sued Again
Links for the day
Slopwatch: LinuxSecurity, Linux Journal, and the Serial Slopper
Google won't tackle the issue because Google participates not only in relaying slop but also in generating lots of it
Links 07/09/2025: Google Fines in EU and "Your Internet Access Is at Risk"
Links for the day
Gemini Links 07/09/2025: Little Brother and Corporate Theatre
Links for the day
Links 07/09/2025: More Harms of Slop and Anthropic's Nightmare Scenario (Huge Legal Liabilities for Slop)
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, September 06, 2025
IRC logs for Saturday, September 06, 2025