Bonum Certa Men Certa

Debian Conflict of Interest Register

posted by Roy Schestowitz on Mar 13, 2024,
updated Mar 13, 2024

Reprinted with permission from Daniel Pocock.

Does Debian need a Conflict of Interest register?

People have asked for it several times. Cabal members have always refused.

Over the last few years, I've had various questions from people about how much they can really trust certain people in Debian.

Vigilantes claim to have a Code of Conduct for Debian. But a Code of Conduct is worthless without any process for managing Conflict of Interest. Last weekend the DebConf8 room allocation data was published somewhere on the Internet and this gives some scary insights into Conflict of Interest.

Privacy of accommodation data

Most people would assume that a data set like this is somewhat private and an organization like Debian would be competent in keeping it private.

Maintaining the privacy of the data requires both technical and social best practice. As we saw in the evidence about Debian harassment culture being a factor in suicides, it isn't the best social environment. A poor social environment is going to struggle to maintain effective privacy.

In relation to the privacy of DebConf personal data, one of the most glaring lapses came with the Albanian scandal. The former Debian Project Leader, Chris Lamb, first visited Albania in 2017. One of the women spent two years visiting events with Lamb. She was seated next to Lamb at the DebConf19 dinner in Brazil. Eight weeks later, she was selected for a $6,000 Outreachy internship.

When you look at the photos and travel itineraries, there is no evidence that the woman did anything wrong. There is a strong hint that Chris Lamb was smitten with this girl. All the rules on funding were relaxed.

When they gave the woman the Outreachy placement, she writes that she had to begin learning Git and at the same time, they simply gave her access to the DebConf Git repository. The repository contains a lot of private information about participants throughout the whole history of DebConf.

I do not believe this woman is any less trustworthy than any other volunteer. On the other hand, the ease with which Lamb gave a smiling newcomer access to this data and the manner in which funding rules were violated suggests that Debian security has some soft spots.

DebConf8 bed allocation: a fresh perspective on DebConf6 violence

A few weeks ago, I wrote about the manner in which two volunteers, Moray Allan and Holger Levsen, allegedly assaulted and physically expelled Ted Walther from DebConf6.

The summary of the incident includes the following text:

At this point Holger and Moray, as mentioned above, manhandled Ted across the dining hall to the door, where they were intercepted by John.

In my subsequent blog about the topic, I published an email from Amaya Rodrigo Sastre where she appears to be justifying violence towards Mr Walther, the victim:

I explained to her that what was going on had nothing to do with her, that it was a problem with Ted and that I believed Ted was a dangerous person and that she should be careful.

Amaya's defamatory emails have been made available to over 1,000 Debian Developers who have had access to the debian-private archives. 16 years have passed. Many people will not know or remember that Amaya had a conflict of interest.

In fact, Amaya had a relationship with Holger, one of the aggressors. She was writing these emails to disparage Mr Walther and take the pressure off her unstable boyfriend.

The relationship appears to be confirmed in the DebConf8 room list, here we see Amaya and Holger sharing a room:

Amaya Rodrigo Sastre, Holger Levsen, Margarita Manterola, Maximiliano Curia, Damian Viano, Martina Ferrari, Gregor Herrmann

Amaya could have added a disclaimer to her emails to declare a conflict of interest but she didn't do so. How can we ensure that people who see her emails in future will be aware of this vital fact?

Another thing to notice in the room list is that Margarita Manterola and Maximiliano Curia were able to share a room. Marga is the Google employee who sent me a hideous email telling me that Carla was not welcome to share the food at DebConf. Looking at the DebConf8 room list, we can see that these people behave like the pigs in Animal Farm. George Orwell has simplified the Code of Conduct down to just one sentence:

All animals are equal but some animals are more equal than others

This is significant for all users and contributors to Debian. This type of toxic social phenomena creates friction against innovation, it undermines privacy and it undermines security of the final software product.

Please see some of my other pages about how Outreachy fell into disrepute.

Other Recent Techrights' Posts

Microsoft XBox Staff Know They're in Trouble, They Try to Unionise Ahead of Mass Layoffs
As the slang goes, it's going to be a "bloodbath"
SLAPP Censorship - Part 72 Out of 200: Microsoft's Graveley and Garrett Signed Documents That Hold Them Accountable to Truth and Liable for Lies
Such collaborations are unsavoury and apparently unprofessional, too
 
Today the Whole European Patent Office (EPO) is on Strike and Next Monday an Even Bigger Strike
the media refuses to cover these and is thus complicit
The Corrupt Lecture the Non-Corrupt - Part IXX - EPO Management Speaks of Reputation and Integrity While Putting Cocaine Addicts in Management
If the EPO values its "reputation", then it needs to start by ousting the management
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, May 10, 2026
IRC logs for Sunday, May 10, 2026
Links 11/05/2026: Security Breaches, Politics, and Energy Crunch
Links for the day
Gemini Links 10/05/2026: "Accidental Cameras" and "Addictive" Interfaces in Social Control Media
Links for the day
Codecs and Software Patents - Part V - A Reminder That GAFAM and the European Patent Office (Which Serves American Monopolists) Do Considerable Harm to the Commons and Culture
some 'breaking' developments
Gemini Links 10/05/2026: Inkscape, Guix, and Alhena 5.5.8
Links for the day
The "Alicante Mafia" at the European Patent Office (EPO) Experiments With New Methods for Crushing Industrial Actions
Open letter to VP1 and the COO [...] What does this tell us about the status quo at the European Patent Office, Europe's second-largest institution?
The Corrupt Lecture the Non-Corrupt - Part XVIII - "The European Patent Office (EPO) has a zero-tolerance policy for fraud" (except when managers do it)
The guidebook of the EPO says fraud is not to be tolerated, but who enforces or revisits such "Red Lines"?
Links 10/05/2026: Hantavirus Brings Back 'Contact Tracing' Surveillance, "Staple Food Prices Soar in Iran"
Links for the day
Links 10/05/2026: Fake Suicide Notes and New EU Restrictions on Slop
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, May 09, 2026
IRC logs for Saturday, May 09, 2026
Gemini Links 10/05/2026: Travelling to Van and "Dark Mode" as Passing Fad
Links for the day
IBM's Kyndryl Holdings Inc Sank 70-75% in 'Value' in 10 Months, Will IBM Follow?
Kyndryl Holdings Inc now has a debt considerably higher than this company is said to be 'worth'!
Belated Sovereignty: GNU/Linux in Iran Skyrockets to 6% Amid Armed Conflict
unless they're truly in control of their networks, hardware and software, somebody else can control them
Gemini Links 09/05/2026: Liberation, The Nocturnals, Rediscovering Internet Radio, and More
Links for the day
Links 09/05/2026: Kremlin’s Biggest Day of the Year and FBI's Attack on the Media (to Save Face)
Links for the day
Google is "Bullshit"
Fix your slop, Google. It's broken.
SLAPP Censorship - Part 71 Out of 200: 5RB Barristers Made Tens of Thousands of Pounds by Changing From Plural to Singular for Microsoft's Graveley and Garrett
Could not even get the client's name right
Links 09/05/2026: "Grand Theft Oil Futures" and Mass Layoffs at Verizon
Links for the day
Gemini Links 09/05/2026: Inkscape "Copy Text Style" and NomadNet
Links for the day
The Corrupt Lecture the Non-Corrupt - Part XVII - European Patent Office (EPO) Management Not Sharing Responsibility for Financial Resources
For those who wonder, EPO strikes are still going on
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, May 08, 2026
IRC logs for Friday, May 08, 2026