[personal profile] mjg59
Free software communities don't exist in a vacuum. They're made up of people who are also members of other communities, people who have other interests and engage in other activities. Sometimes these people engage in behaviour outside the community that may be perceived as negatively impacting communities that they're a part of, but most communities have no guidelines for determining whether behaviour outside the community should have any consequences within the community. This post isn't an attempt to provide those guidelines, but aims to provide some things that community leaders should think about when the issue is raised.

Some things to consider

Did the behaviour violate the law?

This seems like an obvious bar, but it turns out to be a pretty bad one. For a start, many things that are common accepted behaviour in various communities may be illegal (eg, reverse engineering work may contravene a strict reading of US copyright law), and taking this to an extreme would result in expelling anyone who's ever broken a speed limit. On the flipside, refusing to act unless someone broke the law is also a bad threshold - much behaviour that communities consider unacceptable may be entirely legal.

There's also the problem of determining whether a law was actually broken. The criminal justice system is (correctly) biased to an extent in favour of the defendant - removing someone's rights in society should require meeting a high burden of proof. However, this is not the threshold that most communities hold themselves to in determining whether to continue permitting an individual to associate with them. An incident that does not result in a finding of criminal guilt (either through an explicit finding or a failure to prosecute the case in the first place) should not be ignored by communities for that reason.

Did the behaviour violate your community norms?

There's plenty of behaviour that may be acceptable within other segments of society but unacceptable within your community (eg, lobbying for the use of proprietary software is considered entirely reasonable in most places, but rather less so at an FSF event). If someone can be trusted to segregate their behaviour appropriately then this may not be a problem, but that's probably not sufficient in all cases. For instance, if someone acts entirely reasonably within your community but engages in lengthy anti-semitic screeds on 4chan, it's legitimate to question whether permitting them to continue being part of your community serves your community's best interests.

Did the behaviour violate the norms of the community in which it occurred?

Of course, the converse is also true - there's behaviour that may be acceptable within your community but unacceptable in another community. It's easy to write off someone acting in a way that contravenes the standards of another community but wouldn't violate your expected behavioural standards - after all, if it wouldn't breach your standards, what grounds do you have for taking action?

But you need to consider that if someone consciously contravenes the behavioural standards of a community they've chosen to participate in, they may be willing to do the same in your community. If pushing boundaries is a frequent trait then it may not be too long until you discover that they're also pushing your boundaries.

Why do you care?

A community's code of conduct can be looked at in two ways - as a list of behaviours that will be punished if they occur, or as a list of behaviours that are unlikely to occur within that community. The former is probably the primary consideration when a community adopts a CoC, but the latter is how many people considering joining a community will think about it.

If your community includes individuals that are known to have engaged in behaviour that would violate your community standards, potential members or contributors may not trust that your CoC will function as adequate protection. A community that contains people known to have engaged in sexual harassment in other settings is unlikely to be seen as hugely welcoming, even if they haven't (as far as you know!) done so within your community. The way your members behave outside your community is going to be seen as saying something about your community, and that needs to be taken into account.

A second (and perhaps less obvious) aspect is that membership of some higher profile communities may be seen as lending general legitimacy to someone, and they may play off that to legitimise behaviour or views that would be seen as abhorrent by the community as a whole. If someone's anti-semitic views (for example) are seen as having more relevance because of their membership of your community, it's reasonable to think about whether keeping them in your community serves the best interests of your community.

Conclusion

I've said things like "considered" or "taken into account" a bunch here, and that's for a good reason - I don't know what the thresholds should be for any of these things, and there doesn't seem to be even a rough consensus in the wider community. We've seen cases in which communities have acted based on behaviour outside their community (eg, Debian removing Jacob Appelbaum after it was revealed that he'd sexually assaulted multiple people), but there's been no real effort to build a meaningful decision making framework around that.

As a result, communities struggle to make consistent decisions. It's unreasonable to expect individual communities to solve these problems on their own, but that doesn't mean we can ignore them. It's time to start coming up with a real set of best practices.
From: (Anonymous)
From your tweet: https://twitter.com/i/web/status/943785841910042624

> Good morning I am jetlagged and spent the morning writing a post on things a community may want to consider when deciding whether to discipline members for behaviour outside the community

"Discipline"? "Members"? What kind of "community" are you talking about?

The problems mentioned are real, and they happen in *society,* not in "communities." That's where we have to fix them. And it's not because some groups are being ghettoized out of society that it's a good idea for them to develop their own (illegitimate, not to mention badly amateurish) notion of justice.

Talking about "community" is too broad

Date: 2017-12-21 12:34 pm (UTC)
From: [identity profile] m50d.wordpress.com
Kicking someone out of a private club or dinner party is a small sanction. But removing someone from a software community could easily mean destroying their livelihood. It's not at the level of a criminal conviction, but we could compare it to a doctor being struck off or a lawyer being disbarred - things that rightly require an extensive formal process with significant protections for the accused.

All too often, we equivocate between treating online communities as private parties or as quasipublic institutions. Compounding the problem, a given software community can very quickly grow from the former into the latter. I don't have a good answer, but it's another thing to consider; I don't think we'll be able to come up with a single set of guidelines that's applicable to both small and large communities, and we need to think about what happens as a community shifts from one to the other.

Date: 2017-12-21 12:37 pm (UTC)
From: (Anonymous)
"It was revealed that he'd sexually assaulted multiple people"

You forgot an "allegedly", I will just link Jacob words http://www.twitlonger.com/show/n_1soorlp so every reader can make up his or her own mind.

To be frank I am always puzzled when coders act like they have the skills and technical background to act as a lawyer/philosopher/ethicist: we wouldn't let a footballer do the job of a math teacher or viceversa.

~Francesco

Interesting, but incomplete picture…

Date: 2017-12-21 03:30 pm (UTC)
From: (Anonymous)
As others have already noted; there is little context in your post, so this comment is more about general community behavior that I have observed.

There are some people who find it acceptable to silence a necessary community discussion by using the code of conduct as a means to avoid the discussion all together. Any passionate argument that might threaten the public opinion of a community or an individual member could easily be turned into a violation of the CoC and misdirected as a (personal) insult, regardless if it was well intended. Many of these community shepherds argue for stronger CoC when it comes to respectful interaction with each other, while at the same time feeling totally in their right to denigrate and publicly insult others as long as they do it on their personal social media accounts. In their opinion, the community Code of Conduct does not apply on the personal accounts because that would be censorship. Usually it goes something like: the other party obviously is a terrible person or has bad intentions and therefor any interaction with this person should be avoided and publicly ridiculed. If there is anything more toxic to a community it is this immature, hypocritical and polarizing behavior. Sadly very few people seem to want to draw attention to themselves by scrutinizing this kind of behavior, worst case they just become cheerleaders.

When it comes to individuals being able to separate business and community interests and have a sense of integrity, I usually picture the person in my mind with a giant sticker on their forehead that says “Includes paid promotion”. Than I try to figure out based on there actions in reality if that picture makes sense. For example in your case; constantly preaching how some companies are immoral or unethical while remaining mum when it involves your own employer is kinda silly.

Appelbaum

Date: 2018-01-16 10:56 pm (UTC)
From: (Anonymous)
http://laforge.gnumonks.org/blog/20160606-jake-in-recent-news/

When I'm reading this (with the comments)...

Date: 2018-04-26 04:41 pm (UTC)
From: (Anonymous)
... I'm happy to have a job that does not imply working in such 'communities' and remove any desire that I have to go spend some of my limited free time there.

Profile

Matthew Garrett

About Matthew

Power management, mobile and firmware developer on Linux. Security developer at Google. Ex-biologist. @mjg59 on Twitter. Content here should not be interpreted as the opinion of my employer.

Expand Cut Tags

No cut tags