Just a thought on a forum moderation

A few things to address here, since this thread has drifted into two very different territories.

The original feedback is welcome and stays in good standing. @corporateblush raised a fair question about whether closing the Mullvad topic created a one-sided impression, and @FranklyFlawless explained why we close rather than delete, so the reasoning stays visible. Debating a moderation decision is partly what this category is for. Debate, transparency and discourse is healthy and encouraged.

After then, things started to derail a bit though

@plankretriever your suggestion that the team may be collecting mouse-movement data from forum users without consent isn’t supported by anything that was actually said, and it’s contradicted by our published privacy policy: Privacy - Qubes OS Forum

  • The policy is public and specific. It lists exactly what this forum collects - your name and email at registration, the IP address your posts come from, server logs, and cookies, with retention limits (server logs kept no more than 90 days; IPs tied to accounts and posts no more than five years) and a clear statement that we don’t sell or trade your personal information. The forum runs on standard Discourse, hosted by Communiteq. There is no behavioural-biometric or mouse-movement collection described anywhere in it, because none happens. You raised the privacy policy as the standard; the privacy policy answers the question.
  • @unman’s reference to “large corpora of mouse and keyboard data” describes the public research datasets used in this field, the same kind of data behind the vmonaco work linked in the other thread. That’s standard academic material, not anything gathered here.
  • FranklyFlawless saying they reuse a behavioural-analysis framework “everywhere” referred to their own projects outside this forum, which they stated plainly.

Combining those into (paraphrased) “the team might be fingerprinting users illegally, behind the scenes” and urging some kind of action is not a conclusion those quotes support. Simply appending (again, paraphrased) a disclaimer “I’m not saying they are, but it might be worth investigating” doesn’t change that. Publicly implying that named volunteers are doing something against the published privacy policy using stitched-together quotes and “it all adds up” reasoning, is unprofessional as well as personal attacks, and it’s not something we host here regardless of how it’s framed. I believe your implication that there is some kind of propaganda agenda from the same users falls into the same category. Please have a read: Code of conduct — Qubes OS Documentation

Something I would note - what you are alluding to couldn’t be done by the people you’re naming anyway. Higher trust-level roles (including TL4) grant content actions only: the editing, splitting, merging, and flagging FranklyFlawless listed above. Moderator roles extend that permission to include things like user ban/warnings, user notes, and some other data (already covered in the privacy policy). Capturing mouse-movement telemetry would require injecting custom client-side code or server-level access, and only a site administrator or the host (Communiteq) has that. The moderator and contributor roles grant neither, so the contributors you are implicating here have no ability to gather this kind of data - and any client-side code that did would be visible in the forum sources to anyone who looked. Roles operate on the very well known “least privilege” process - we all have just enough permissions for the level of help we give.

If you have a genuine privacy concern about how the forum operates, the Privacy Policy lists a Privacy Policy moderators group you can message directly - please use that rather than seeding unsubstantiated speculation about conduct in a public thread.

The standard going forward is straightforward: real concerns are welcome, including pointed criticism of moderation or the project - state them directly and support them. Innuendo isn’t welcome: implying wrongdoing while simultaneously disclaiming that you’re making the accusation is not cool. If you believe a law is being broken, that’s a specific claim that needs specific evidence and a documented pathway for the team to consider when you bring forward - if you don’t have it, please don’t imply it with innuendo and FUD in a public thread.

I’m leaving your posts up, both because that’s how we operate and because this context belongs next to them. Please stay within the CoC moving forward.

6 Likes

Pretty much everything I do inside and outside of the Qubes OS Forum is serious:

You can take a look at my Forgejo instance to see what actual development work I am doing.

Everywhere in practice is limited to specific applications:

  1. Auditing GitHub, GitLab, and Codeberg repositories
  2. Verifying claims/citations/references on websites and news articles
  3. Investigating corporations/organizations with opaque structures and/or third-party dependency mappings
  4. Attending OWASP and/or other cybersecurity events in my local community, compare and contrast against my entire workflow, then harden against any discovered vulnerabilities

Security is a process, not a goal, so I have to constantly exercise it, otherwise I am at risk of complacency. That is why I red-flagged and closed the topic from earlier in order to preserve the integrity of the Qubes OS Forum. It may have been my first time deliberately and publicly closing a topic around here, but for me, it was just another day in the office.

3 Likes

You mean 3-letter office? :grin:

1 Like

I operate alone, so I have plenty of flexibility with my projects. I may require a legal team in the future to back up some of the most ambitious ones though. What I currently work on is just the start of a much harder road ahead of me.

Another topic has been closed by me:

Summary:

  1. First-time poster heavily implies using Qubes OS as a primary device while deciding to use Kicksecure for a secondary device, even though there is a TemplateVM for it.
  2. References GrapheneOS Discussion Forum topic about Kicksecure and/or Whonix.
  3. Shares feedback about Kicksecure’s signature verification instructions from the respective website.
  4. Inquires about whether Kicksecure and/or Whonix are currently considered to be trusted, secure, and/or anonymous by the community.

The leading question is redundant and counter-productive for discussion due to this logic:

  1. There is already a relevant reference to a GrapheneOS Discussion Forum topic.
  2. Perception and/or reputation of projects is not a reliable indicator of trust, security, and/or anonymity properties, as evidenced by the same reference.

The topic was ultimately closed because it is about perception of external projects from the community, which is off-topic, and the rest of the topic itself serves as an example of what happens when perception of consensus is prioritized over technical properties.

5 Likes

Another thank you has been DISclosed by me.

1 Like

I think it’s a mistake to post the explanation here. The affected people should read the explanation in the locked topic.
All you posted in that topic is “off topic” without elaborating like you did here. It’s a slippery slope if moderators can use these kind of actions without needing to explain.
I think it’s also a huge mistake ITL made to give normal users moderator powers without making them moderators.
It shows poor judgement giving those powers as a reward. It should be about responsibility. There should be a process which moderators follow. It should be transparent.
It’s a bit crazy actually that a team who are supposedly specialized in security don’t understand that. They give away these powers like candy.
Although, I think ITL got lucky that you are responsible with your power FranklyFlawless

1 Like

I agree. That is correctable.

Everything else is pretty easy to judge about, until not in the position. They don’t say without a reason: “Give an authority to people to reveal who they actually are”.

I wouldn’t accept at any cost to become moderator, and in turn I promised my self I wont be Statler and/or Waldorf too.

1 Like

Stating off-topic as a brief reason is sufficient in the original topics, whereas this topic can be used for my centralized decisions and explanations over time for our convenience. I am making a informed decision to be transparent about the reasoning instead of being opaque, which is typical in other communities, such as Privacy Guides, where they delete topics without providing explanations. The least I can do is exercise critical thinking and discretion throughout the process.

If you believe there is any moderation misconduct on my part, simply post it in this topic for public review. I will address any presented concerns about me as they continue to come up. I cannot answer for any other moderation actions outside of myself, so use the broader topic for that instead:

It is also very clear that I followed @unman’s feedback word-for-word, but I do not set slow mode for topics because I simply do not engage enough in the Qubes OS Forum at the moment, and I am technically not part of the moderation team either, so I am only assuming moderation responsibilities as resources become available.

2 Likes

This isn’t an ITL decision. First of all, the active moderation team for this forum is composed of volunteers from the Qubes community, not ITL members. (ITL members with forum privileges aren’t active in moderating and mainly use them for internal staff communication and admin tasks, like announcements. I stepped back from moderating years ago.) Second, the Discourse forum software has the trust level system built in and turned on by default. As users gain higher trust levels (from 0 to 4), they gain some mod-like abilities, but the powerful abilities are gated behind TL4, which requires manual promotion by default.

Your beef is primarily with the Discourse developers, because you disagree with their philosophy about how a web forum should work, which is fair. Your secondary beef is with the moderation team for not overriding the default trust level system in Discourse. Whether the trust level system is the optimal fit for the Qubes community is a reasonable question that the mod team has already considered pretty extensively, but I’m sure that if you present cogent arguments against it, the mod team will be happy to listen and consider your reasoning. Flinging around unfounded accusations and jumping to conclusions isn’t likely to further your cause, though.

One thing I’ll point out is that the amount of moderation this forum requires is significant, and the bandwidth of the mod team appears to be overwhelmed at times. Having high-trust-level users able to pitch in to help with some light mod tasks currently relieves some of the burden. If we, as a community, get rid of this mechanism, we’d either need to add more official mods to the mod team (hard to do when there aren’t enough suitable volunteers, plus they’d probably just be those same high-trust-level users anyway) or accept that more rule-breaking content will go unmoderated.

Our mods and high-trust-level users are giving up their free time to try to help make this forum a better place for all of us to enjoy – an often thankless task that most of us aren’t willing to volunteer for. By its nature, much of the work they do is invisible: When a bad post, thread, or account gets moderated, most of us never have to see it. As a result, we often don’t notice the good work they do; we only notice when there’s something we disagree with or don’t like. It’s fine to express that disagreement in a civil way, but let’s just try to remind ourselves that we’re enjoying the fruits of their labor and try not to take it for granted.

7 Likes

I would like to publicly say that I agree with @FranklyFlawless recent moderation actions. It is a valuable help. While I appreciate how you explain your decision, I don’t think you have to do that each time you close something. If someone has something to criticize, there are some options:

  • flag a topic or a post to tell the moderation team
  • send you a personal message
  • or send a post here or open a topic in Feedback > Forum Feedback

Thanks again.

3 Likes