Bonum Certa Men Certa

Open Source Initiative (OSI) Privacy Fiasco in Detail: Seeking Class Action Against the OSI

posted by Roy Schestowitz on Apr 09, 2025

Coffee Beans On Weighing Scales

IN THE introduction and the following two parts we gave sufficient background for people who are not familiar with this fiasco. The previous part showed parts of the complaint (as a PDF) and today we show more.

There is a "LETTER SEEKING CLASS ACTION REPRESENTATION". To quote the complainant:

Please note, I did not reach out to OSI about this release of my personal information after realizing it was still showing by shared 3rd party after 4 years. This does not affect my complaint case. I did, however, contact a LA privacy lawyer the other day:

I was contacted by someone on LinkedIn who had my information from when I was a member and voted in 2021 at the open source initiative. This corporate organization is located in West Hollywood California and upon further investigation I came to see that the third-party vendor, Helios that performed the election

Still had the list of 589 members showing publicly on the web. The open source initiative didn’t even know how the list of names was released at the beginning, and even after filing a notice to the community that there was no breach, the list still remains publicly available.

There was an expectation of privacy and certainly after four years, so I filed a complaint with the CPPA.

This organization (OSI) is the “steward" of our open source definition yet can’t even keep our information private. Like I said there was an expectation of privacy and four year seems like quite a bit of time.

There are 589 names on that list and I really believe that this release of our names and whether we voted or not, is negligent.

As a free software advocate, having affiliation with the open source initiative could do serious harm to my reputation.

Additionally, not protecting our privacy for this long is truly distressing.

I would like to be represented in a class action against the open source initiative based on their failure to protect my privacy. If a class action is not possible a single action is also something I am open to. However, almost 600 people were exposed and for four years.

Thank you.

Complaint to CPPA (response via email):

Letter sent via email

RE: Privacy complaint about Open Source Initiatives: A California corporation Helios: Third party vendor used by the Open Source Initiative for elections. Deb Nicholson, previous Interim Director and current director - Stefano Mafulli as well as their IT staff and those working/volunteering at OSI who may also be held accountable for this neglect of private data.

Dear [redacted]:

Thank you for submitting a complaint to the California Privacy Protection Agency (“Agency”).

Complaints are important for our enforcement efforts. We will retain the information you provided in our files and may contact you if we need additional information, for example to request additional facts about the complaint. No further action is required from you at this time. Investigations are generally confidential unless and until a matter becomes public through an enforcement action. For more information about the law and answers to frequently asked questions, please see https://cppa.ca.gov/faq.html.

Please note that we cannot represent you, advocate for you with the business, or force the business to satisfy individual requests for relief. If you would like to consult an attorney, you can obtain a referral to a certified lawyer referral service through the California State Bar at (866) 442-2529 (toll-free in California) or (415) 538-2250 (from outside California), or online at https://www.calbar.ca.gov. If you cannot afford to pay an attorney, contact your local legal aid office to see if you qualify for free or reduced-rate legal assistance. For a referral to local legal aid offices, visit https://lawhelpca.org/ and click on the Search for Legal Help tab.

Thank you again for contacting the Agency about this matter.

Sincerely,

CALIFORNIA PRIVACY PROTECTION AGENCY Complaints Unit

The complainant did not ask the OSI or self-identify; that's the correct approach because the OSI tends to defame critics and censor/deplatform them.

Other Recent Techrights' Posts

UEFI "Secure Boot Doesn’t Play Nice at the Moment"
UEFI "Secure Boot" does not improve security. It's an artificial obstacle in service of monopoly.
If You Want to "make your 'Windows PC' lean, mean, and fast" You Will Install GNU/Linux or Some BSD
That kind of article says a lot about IDG
 
Links 15/09/2025: Bitcoin ATMs Scam and "Conservative Cryptography" (Backdoors Fantasies)
Links for the day
EPO Imitates Microsoft: "Three Days or More Per Week" Inside the Office to Get a Desk to Work on; "the Office Breaches Its Promise Towards Staff and Acts in Breach of Its Duty of Care"
The EPO serves no actual function in Europe
Links 15/09/2025: Political Affairs, Censorship, and Copyrights
Links for the day
Gemini Links 15/09/2025: Music Genres, Invisible Networks, and Akademy 2025
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, September 14, 2025
IRC logs for Sunday, September 14, 2025
Satya's Plan B: Try to Hide the Massive Extent/Scale/Scope of Microsoft Layoffs
fewer people buy Microsoft
Red Hat News About De Facto Mass Layoffs (Bluewashing) Gone From Reddit (Censored by Gatekeepers), Still Online in The Register
With RTOs, PIPs, relocation etc. expect IBM to "shed off" many Red Hatters
Gemini Links 14/09/2025: ROOPHLOCH, Music, and Reddit
Links for the day
Slopwatch: Google News Infested With Slop (About Half of the Results for "Linux" Today)
This is the sort of junk one finds when looking for "Linux" in Google News these days
Links 14/09/2025: Ricky Hatton Dies and McDonald's Declares War on Tipping Culture
Links for the day
Links 14/09/2025: Disasters for CEOs Obsessed With Slop and Slop Companies School Like Fish
Links for the day
"Bad Shim Signature" (Microsoft 'Secure' Boot)
"Fresh install not booting"
What Microsoft Garrett and Microsoft Lunduke Have in Common
Similar tactics, different "wings"
Links 14/09/2025: US "Economy Sagging", "Michigan Economy Wobbles From Tariffs"
Links for the day
Gemini Links 14/09/2025: Minimalist Snippet Manager and Omarchy Linux
Links for the day
The Face of the Digital Far Right: Microsoft Lunduke
Microsoft Lunduke is an online extremist that belongs to and panders to the far right
20 Years Later and Academia Isn't the Same
"I never dreamed of being a professor"
'Cancel Culture' by the Right: Microsoft Lunduke Contacts People's Employers Trying to Get Them Fired
Microsoft Lunduke panders to extremists online
"Bad Shim Signature"; So 'Secure' That It Overrides Users' Preferences and Turns Itself Back on (Coercive Measure)
This was a few hours ago
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, September 13, 2025
IRC logs for Saturday, September 13, 2025
Microsoft is Rapidly Dropped From Web Servers, Shows Survey
Microsoft lost about 8% "market share" in just 3 months
Many GNU/Linux Users Report MOK (Machine Owner Key) Issues in Recent Days
many people don't report this online and never post in Reddit
We Covered UEFI 'Secure Boot' Scandals. The World Listened.
To hell with UEFI 'secure boot'
Links 13/09/2025: Escalations in East Europe and POTUS’ Health Cover-Up
Links for the day
Gemini Links 13/09/2025: Lagrange Turns 5 and Lagrange 1.19.2 Released
Links for the day
Microsoft Inside Your Linux: "Security vulnerability that allowed an attacker to bypass UEFI Secure Boot."
2 hours ago
A New Low for "Linux Journal": Promoting MICROSOFT WINDOWS Using LLM Slop
They've just jumped the shark entirely
Fake News With Fake Numbers About Microsoft
"This is what happens when the world's economy is governed by sick old men"
Slopwatch: "Google News" is Fast Becoming a Mashup of Slopfarms, Linux Journal ("LJ") is a Dump of LLM Slop
Well done, Google News. Google itself can flourish as a slopfarm mashup.
Torturing Users Who Just Want to Run GNU/Linux on Their Own PC
"Linux does not want to install"
The Register MS Still Takes Money to Hype Up "AI" in Articles by Microsoft Resellers With the Term "AI" 30+ Times in Them
Notice how many times they mention "AI"
The Apache Logo News is VERY Old, Racists and 'Anti-Woke' Bigots Look for Something to Incite Other Bigots With
Nothing to see here, move along
Linux Mint 9/11: "4th One Today..." (in Reddit)
Remember that not everyone having an issue reports it to social control media like Reddit
Nepal Will Fall Without a Single Shot Fired, Thanks to Social Control Media
Or very few shots (by the authorities)
European Corruption in the European Patent Office (EPO) Targets Culture
"In reality, the project includes a new “legal instrument” shifting administrative burden and liability on EPO staff while creating new uncertainty and externalising Amicale activities."
European Authorities, Already Bribed and Infiltrated by Microsoft, Won't Help You Find BigBlueButton, Jami, Ring, and Jitsi
Because they're paid by Microsoft and are Microsoft 'addicts' themselves
UEFI Secure Boot Failing, as Expected for Nearly 15 Years Already (Techrights Said This Since 2012)
in the media
Debian 9/11
people report this issue
Gemini and Web Links 13/09/2025: MElon's Slop Grift and "Autonomous Trains"
Links for the day
Moving From Content Management Systems (CMSs) to Static Site Generators (SSGs) Saves You Time, Makes You a Lot More Productive
try to reduce the cost (financial and computational) of running your site
Pursuing Peace Through Violence
You cannot "see" a person's mind, until the mouth opens
Leak: European Patent Office (EPO) is Now Attacking Amicale Clubs
corruption has become the norm and scientists are robbed of any dignity
Can We Please Stop Celebrating Shooters?
"An important point to hammer on is that CoCs were never intended for uniform or symmetric application"
Oracle Fraud (or Defrauding Shareholders)
"the obvious [lie] is that watts are (wasted) electricity [and] and FLOPS are computing capacity"
Geminispace is Growing Faster in 2025 Than It Did in 2024
What matters is that corporations haven't ruined it and LLM slop is extremely rare
Links 13/09/2025: China Punishes for 'Negative' Posts, US Police Unable to Find Shooter
Links for the day
Who's the Mystery Financier of SLAPP Against Techrights and Is That a Millionaire/Billionaire?
Whose idea was it to fund meritless lawsuits against my wife and I?
Slopwatch: Slow Slop Day
This distracts from or may take traffic away from the original articles, actually written by actual people
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, September 12, 2025
IRC logs for Friday, September 12, 2025