Bonum Certa Men Certa

Security Advisory: Debian falls for social engineering hacks

posted by Roy Schestowitz on Nov 08, 2024,
updated Nov 08, 2024

Reprinted with permission from Daniel Pocock.

As an expert on online privacy and information security, people regularly ask me questions about whether open source is really safer or could there be any such thing as perfect security online.

The phenomena of Code of Conduct gaslighting is not about ethical standards at all, it is really a form of social engineering. The rights of co-authors are similar to the rights of shareholders. Joint authorship is nothing like membership or employment. Co-authors can not give each other orders or exclude each other from recognition. The people trying to conjure up fantasies about expulsion, which doesn't exist under copyright law, are actually engaging in a social engineering attack on our authorship rights.

I began to learn about the JuristGate scandal on 14 April 2023. That is when one of the founders, Mathieu Parreaux, asked me to buy another insurance from his new company.

It became clear to me that the unsafe nature of this insurance product had been known for some time in the Swiss legal profession and most likely in the Swiss insurance regulator too. The fact that it had taken these organisations so long to act and the fact that even when they did act, Mathieu Parreaux could still steal their thunder and ask customers to pay in another year of premiums weeks before we received any official notice from regulators suggests that the regulators don't have the means to protect small business and consumers from this type of conduct.

The FINMA records show us that they made the decision to liquidate the rogue firm on 4 April 2023.

Here is Parreaux asking people to pay the next premiums to a new company (nouvelle structure). It is sent on 14 April 2023, that is 10 days after FINMA decided to shut him down. Customers never received any warning from FINMA before Parreaux sent these messages:

 
Subject:        Fermeture de Justicia SA - Organisation de notre nouvelle structure
Date:   Fri, 14 Apr 2023 16:53:18 +0200
From:   m.parreaux@justiva.ch
To:     m.parreaux@justiva.ch

Chers tous,
...

The liquidator, Walder Wyss, only sent the first warning to customers five days later on 19 April and it has very little detail:

Subject:        Justicia SA en liquidation
Date:   Wed, 19 Apr 2023 13:18:07 +0200
From:   Walder Wyss SA <newsletter@walderwyss.info>
Reply-To:       newsletter@walderwyss.info

WalderWyss Newsletter L'e-mail ne s'affiche pas correctement? Veuillez cliquer ici. <https://news-cdn.walderwyss.com/go/dv35o6fv7g1oafuax2pklhb1r61vozjsizhk4c0go1l5/1032> Walder Wyss Ltd.
Justicia SA en liquidation
walderwyss avocats <https://news-cdn.walderwyss.com/go/c8f5o6fv7g1af46a0u16f1fbx6cosxt9tffwogs441lc/1032>
*Madame, Monsieur,
*
*Par décision de l'Autorité fédérale de surveillance des marchés financiers FINMA du 4 avril 2023, Justicia SA a été exhortée de cesser ses activités, dissoute et mise en liquidation. L’Etude Walder Wyss SA a été nommée en qualité de liquidateur de Justicia SA en liquidation.*

On 5 September 2023, an order was submitted to rename the Swiss corporate entity to Open Source Developer Freedoms SA.

All companies eventually go into liquidation. For example, even if a company is bought by another company, the assets of one company are often transferred to the other company and the company without any remaining assets is technically liquidated.

Therefore, it is reasonable to suspect that at some point in time, the company name would subsequently add the suffix en liquidation and become something like Open Source Developer Freedoms SA en liquidation.

In January 2024, after I finished the cancelation of the Debian trademark in Switzerland, I then made the decision to order the liquidation of the company in good standing.

Liquidation is a process whereby a company sells its assets, pays outstanding bills and then gives the remaining money back to the shareholders. Some companies do not have sufficient money leftover to pay their debts and these companies choose to declare bankruptcy. Declaring a liquidation is not the same as declaring bankruptcy. When liquidations are reported in the media, they are usually the cases where debts are unpaid and many people have seen the word liquidation and bankruptcy used together in the news. Nonetheless, in many cases, companies proceed with an orderly liquidation and then quietly remove themselves from the corporate register without bankruptcy.

It has always been my intention as administrator that assets would be realized and the company would be dissolved in an orderly manner without bankruptcy. In Switzerland, a company must wait at least 12 months before completing the process.

Nonetheless, at the time I changed the company name, I had a sneaky suspicion that rogue members of Debian may cut-and-paste the full company name into some defamatory statement. In fact, they did exactly that. Therefore, by choosing this particular company name, I was able to put the text string "Open Source Developer Freedoms SA en liquidation" into the Debian.org web site. The string is a strong hint to everybody that freedom is in liquidation. I was able to place this string in the Debian web site without having any access rights to modify the Debian web site.

Therefore, I have proven that the people running Debian today are basically asleep at the wheel, cutting and pasting without thinking about what the words mean.

Far and wide, people suspect that was my intention all along and congratulate me for proving that Debian has become so gullible.

Of course other organizations have also been able to bend Debian to their will. Google is able to push out new versions of Chromium with thousands of lines of code changes and they get accepted into the Debian stable releases with relatively little scrutiny. Google has a lot of insiders in Debian to help achieve that. I was able to land that hint about freedom in liquidation on the Debian web site without help from anybody.

The current Debian Project Leader, Andreas Tille, was elected on Hitler's birthday. The fact that my social engineering hack landed in Debian.org on 6 June, the anniversary of the D-Day landings, was a bonus.

Here it is, Debian, under the influence of a German and Google, has confirmed that our freedoms are in liquidation. Long live freedom.

debian social contract, freedom in liquidation

Who will be next? First they came...

First they came..., Debian, Code of Conduct

Please see the chronological history of how the Debian harassment and abuse culture evolved.

Other Recent Techrights' Posts

Gemini Links 22/05/2026: Esperanto Music History, Suspicious Adoption of Signal, and Unauthorised LLM Slop in Code
Links for the day
Techrights and Tux Machines Subjected to Cyberattacks for Several Weeks
In the past I spoke to the cybercrime unit of British Police. Maybe it's time to do so again.
 
Links 22/05/2026: Inflation Fears and Thailand Tightens Visa Rules for Tourists From Dozens of Nations
Links for the day
EPO Staff Representation Speaks of This Week's Discussion With the EPO's Budget and Finance Committee (BFC) Amid Mass Strikes
The Central Staff Committee's outline (prepared in a rush) or the "flash report"
SLAPP Censorship - Part 84 Out of 200: New Legislation Against SLAPPs on the Way (After We Reached Out to Ministers)
They dealt with the matter individually too, but we won't share this in public, at least not at this time
The Corrupt Lecture the Non-Corrupt - Part XXX - Where Was "The Ethics and Compliance Team" When the Family of EPO President Campinos Was Caught Doing Cocaine?
It remains to be seen if national delegates will tolerate this in future meetings
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, May 21, 2026
IRC logs for Thursday, May 21, 2026
Links 21/05/2026: "Declining America" and Why Slop 'Code' is Made to Fail
Links for the day
The Register MS Has Become a 'Content' Farm Promoting Slop for Hostile Corporations
Now they call it "PARTNER CONTENT" - not "SPONSORED" - as if semantics make the difference
Latest Example of Widespread Fake Assertions (False News) About "Hey Hi"
The false narrative of "Hey Hi layoffs"
Links 21/05/2026: Facebook Rewarded With Tax Breaks to Destroy the Environment and Cause Global Warming, Shortages, Pollution; SpaceX (SPCX) Continues Losing Billions of Dollars
Links for the day
Codecs and Software Patents - Part VIII - GNU Audio/Video Team Has Chosen the AV1 Video Codec and It Explains Why (They've Researched Their Options)
AV1 video codec will be used to encode and share GNU videos online
Dr. Stallman Helps Establish Free Software Advocacy Outside the Free Software Foundation (FSF) as Well
The ideals or principles of Free Software needn't be centralised or monopolised; they can be federated
22 Years of Tux Machines and a Community Stronger Than Ever Before
We've already received some feedback from the community and improved it accordingly
Microsoft Under Investigation for Breaches of Law in the UK
Just like the Microsofters
More Microsoft Layoffs on the Way (June and July 2026)
with or without PIPs
LWN Sponsored by the Linux Foundation (Monopolies)
We must be able to casually point this out
The Corrupt Lecture the Non-Corrupt - Part XXIX - European Patent Office (EPO) Tells Staff "Speaking up" is Good, But Not When the "Brother-in-law" of EPO's President Does Cocaine
Do we still have a functioning democracy and potent press?
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, May 20, 2026
IRC logs for Wednesday, May 20, 2026
Gemini Links 21/05/2026: Immigration, Slop, and Slop 'Code' Suggestions Infesting Code Repositories
Links for the dayGemini Links 21/05/2026: Immigration, Slop, and Slop 'Code' Suggestions Infesting Code Repositories
GAFAM is Connected to Misogyny, Almost All Founders Divorced
They're not good people, even if they pay the media to pretend otherwise
SLAPP Censorship - Part 83 Out of 200: Religion is Still Alive, But for Many This Religion is Monetary (Greed, Monopolies, Corporate Power)
If all you keep boasting about is being able to afford a hotel room and some domestic flight, then maybe you have no real accomplishments and are more like a "Facebook serf" with a credit card
Oracle Seems to Have Popularised Overnight Layoffs, Now GAFAM Does the Same
layoff emails at 4 a.m. local time
A Lot of Fake News About Microsoft's LinkedIn Today, Some Comes From Slopfarms, Some Relies on Those Slopfarms
As usual, slopfarms make the Web a huge pile of garbage
IBM's Kyndryl is Circling Down the Drain, Say Kyndryl Insiders
"IBM Dinosaurs who were recycled and catapulted into the orange trash heap by IBM"
A Lot of Coverage Adding Hype Factor to Slop Bug Reports... is Made by LLM Slop
Local Privilege Escalation [...] the slop motivates some actual people to keep writing about it
Links 20/05/2026: Mass Layoffs at NPR (Bought by the Ballmers and Bill Epsteingate), Starbucks Korea CEO Fired Over ‘Tank Day’ Ad
Links for the day
Gemini Links 20/05/2026: Advantage of CD Collections, Geminaut's View of Nostr, and SSL / TLS Certificates
Links for the day
IBM is Becoming a Pile of Expired Patents and Abandoned Buildings, Assets of Little Actual Value
Having laid off a ton of people, borrowed lots of money to fake growth (by acquisition), and sent some jobs to low-paid regions where innovation isn't done
Links 20/05/2026: Looting of Americans for "White Grievance Reparations Fund"; "Mark Zuckerberg Used Shell Companies to Bully Native Hawaiians"
Links for the day
Web Browsers Are for Rendering Web Page, They Shouldn't Become PDF Editors
Linus Torvalds is quickly learning and speaking about this
SLAPP Censorship - Part 82 Out of 200: British Government Intervenes in the SLAPPs by Brett Wilson LLP
At this stage our matters are dealt with by a layer below that of the Prime Minister (adjacent to it)
LinkedIn Communications Reveal That LinkedIn - Like GitHub - Will Vanish Inside the Belly of Microsoft
This is definitely going to happen.
In Wall Street, Financial Difficulties Drive Shares Up
Wall Street doesn't work that way
The Corrupt Lecture the Non-Corrupt - Part XXVIII - European Patent Office (EPO) Guidebook Says Report Crimes Committed on EPO Premises. Some Did, But President Campinos Covers up for the Culprits.
The staff has long been on strike and the union (SUEPO) organised an enhanced day of action just two days ago
Gemini Links 20/05/2026: Fall of an Empire, "High Tech is a Social Exercise", and Big Cameras
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, May 19, 2026
IRC logs for Tuesday, May 19, 2026