Bonum Certa Men Certa

Amandine 'Cryptie' Jambert, CNIL (Commission Nationale de l'Informatique et des Libertés) and FSFE Privacy Scandals

Reprinted with permission from the Free Software Fellowship

There have recently been concerns raised on various mailing lists about the identity of Cryptie in FSFE.



For many years, Amandine Jambert has wandered around the free software world using a pseudonym, Cryptie. While anybody else using an alternative name has been accused of trolling, Jambert has had some immunity. Why? As concerns grow about the hidden conflicts of interests and corporate influence in free software organizations and as these organizations use the weight of their reputations to shame and humiliate people, it is more important than ever to identify the controllers of the organizations.



Thanks to Wright's investigations, we can now search for information about Cryptie and search for information about Amandine Jambert @ CNIL and find they are the same person.



Amandine 'cryptie' JAMBERT, CNIL, FSFE

The Cryptie case is even more special than a regular conflict of interest. As Mr Wright pointed out in his explosive email, FSFE e.V. covered up the very type of privacy breach that Jambert's employer, CNIL, would be expected to investigate.



CNIL is France's Commission Nationale de l'Informatique et des Libertés. CNIL's mission clearly includes investigating and sanctioning data privacy breaches.



Many parts of the world now have mandatory reporting of privacy breaches.



On 15 March 2018, Matthias Kirschner, president of FSFE e.V., wrote an email to the internal GA mailing list:



Subject: [GA] Report about privacy problem with financial data
From: Matthias Kirschner
Date: 15 March 2018

The archives of finance at lists.fsfe.org, and thereby all the information
including full names, amount, credit card and bank details, were public
from 18 December 2017 until 13 March 2018.


It is incredulous that such data is managed on a mailing list, especially when the list runs on the same public server as Internet-accessible public lists. All serious organizations keep such data on servers in isolated subnets, with mail allowed in through an intermediate box in the DMZ. There is never direct access from the Internet to the box where sensitive data is actually stored.



Germany, where FSFE e.V. is based, has a clear requirement for organizations to report privacy breaches to regulators and victims. Yet in Kirschner's email, he writes that FSFE council chose not to report it: in other words, a cover-up.



It raises serious questions about how Amandine Jambert, an employee of one of the largest national regulatory bodies in Europe, can turn a blind eye. Jambert is a member of the internal FSFE GA mailing list and received the report and subsequent discussion there. Did she discuss FSFE e.V.'s privacy issues with her employer?



FSFE e.V. subsequently admitted further data breaches and used the minutes of their annual meeting to publish defamatory attacks against a former volunteer. This behaviour, deliberately naming and shaming somebody, is an assault on the principles of European data protection laws. It is not clear how Jambert or any CNIL employee can continue being a member of this organization.



This brings us to the question: why does Jambert use a pseudonym, Cryptie, in the FSFE? Why does she not want to use her real name? Is it because she knows that FSFE behaviour is so unprofessional and she wants to hide it from her workplace? Or is it the other way around, Jambert hiding her professional identity from the Free Software community so that they can make undercover investigations into the privacy practices of Free Software organizations?



Many people already feel that national privacy laws and the bodies enforcing them are toothless tigers, with companies like Google and Facebook running amok and doing as they please. With a CNIL employee moonlighting in a non-profit secretly bankrolled by Google, it will only add to the perception of incompetence.



sticker

Recent Techrights' Posts

Things Will Only Get Better (as We Go Backwards)
It only gets better. If you go back in time.
UK High Court Shows SRA is Totally Useless in Curbing SLAPPs, This Has Impact on Our Reporting on the SRA Next Week
We'll carry on our coverage and soon finish the current series that so we can get on with more time-sensitive ones
 
Gemini Links 22/09/2026: Scout Night, Cybernetic Capitalism, and Thoughts on Companies Forcing People to Adopt Plagiarism Engines
Links for the day
Links 22/09/2026: "An Arsenal of Surveillance" and Slop Bots Suggest Starting Wars
Links for the day
SLAPP Censorship - Part 193 Out of 200: Breaks GNU and Linux, Tries to Silence Critics, Loses All Money, Looks for Microsoft Allies and Sponsors
The latest emotional knee-jerk reactions serve to confirm what we have long said
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, September 21, 2026
IRC logs for Monday, September 21, 2026
Links 21/09/2026: "Lies of the Hey Hi (AI) Industry" and Solar Power Is Getting Cheap
Links for the day
Gemini Links 21/09/2026: Equinox and Beginner's Guide to Gemini
Links for the day
Links 21/09/2026: "Back On My Bicycle" and American Regime's War on Media Escalates Further
Links for the day
SLAPP Censorship - Part 192 Out of 200: The Hired Guns of Garrett and Graveley Sent Us USB Sticks (One to Me, One to My Wife) Showing Lozza Talking to Garrett About Censoring/Deplatforming Techrights the Same Time Graveley Was Copy-Pasting Garrett's Lawsuit
Next year we plan to bring this matter to the Court of Appeal
Linux Kernel Becoming a Slopfest - Part 6 - Seeing Who Contaminates Linux With Slop (And Also Admits It)
Today we begin looking at some culprits
2026: The Year Galleries Realised the Need to Flag or Cull Slop Images
Society needs to shun slopfarms, people who use LLM slop (for anything at all), companies that use bots (which they dub "agents"), and so-called 'coders' who volley garbage into project and software hubs
Software Freedom Day Celebrated in 5 or 6 Continent
Software Freedom Day (SFD) 2026 was big this year
SLAPP Censorship - Part 191 Out of 200: Garrett, Graveley and Lozza
They talk to and coordinate with one another
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, September 20, 2026
IRC logs for Sunday, September 20, 2026
Gemini Links 21/09/2026: Digital Hoarder, GTD, Minimalism vs Digital Minimalism, Rejection of LLMs
Links for the day
Links 20/09/2026: "Google Now Asking For Users’ Video Selfies" and Energy Prices Set to Rise
Links for the day
Enjoy the Giving/Sharing, Not Taking
We've long supported what we believed in, even with the little money we had
Links 20/09/2026: Amazon Layoffs, Flock 'Buyouts' (Silent Layoffs)
Links for the day
USCIS and Microsoft Rumours: Curbs on Lowering Salaries by Importing Cheaper Replacements?
It seems like Microsoft's mass layoffs and efforts to cheapen the workforce face obstacles
Gemini Links 20/09/2026: "Music While Working" and Radio Silence
Links for the day
Clownflare Data From Canada
We've like to think many people are attempting to install GNU/Linux over the weekend
SLAPP Censorship - Part 190 Out of 200: Plagiarism, Back Doors, and Sabotage of Linux
This can go on for a decade or longer
Linux Kernel Becoming a Slopfest - Part 5 - Kernel Dependency on Plagiarism Giant Microsoft is a Death Blow to Any Kernel
Microsoft is bringing copyright-infringing slop into Linux
GNU/Linux Has Grown a Lot Lately
Based on Clownflare
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, September 19, 2026
IRC logs for Saturday, September 19, 2026