From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from lists.gentoo.org (pigeon.gentoo.org [208.92.234.80]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits)) (No client certificate requested) by finch.gentoo.org (Postfix) with ESMTPS id EA331158020 for ; Wed, 30 Nov 2022 21:32:04 +0000 (UTC) Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id 1DA6AE07C9; Wed, 30 Nov 2022 21:32:04 +0000 (UTC) Received: from smtp.gentoo.org (woodpecker.gentoo.org [IPv6:2001:470:ea4a:1:5054:ff:fec7:86e4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by pigeon.gentoo.org (Postfix) with ESMTPS id 06C7DE07C9 for ; Wed, 30 Nov 2022 21:32:04 +0000 (UTC) Date: Wed, 30 Nov 2022 15:32:01 -0600 From: John Helmert III To: gentoo-project@lists.gentoo.org Subject: Re: [gentoo-project] Re: [gentoo-dev] [PATCH] glep-0076: Require real name instead of legal name Message-ID: References: <20220712002836.20274-1-cyber+gentoo@sysrq.in> Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Project discussion list X-BeenThere: gentoo-project@lists.gentoo.org Reply-To: gentoo-project@lists.gentoo.org X-Auto-Response-Suppress: DR, RN, NRN, OOF, AutoReply MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="HUhi0bz8MhCkIx37" Content-Disposition: inline In-Reply-To: X-Archives-Salt: c9d90017-23bd-4980-9d25-b85c82ebbe4e X-Archives-Hash: 26383fbeb8c2f6d06625fcd43ed0620d --HUhi0bz8MhCkIx37 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable This was a topic in the last council meeting where many concerns were raised. Council tabled the topic until after further discussion on these issues happened on the mailing list. Is anybody going to raise those issues? On Tue, Jul 12, 2022 at 09:59:50PM +0000, Robin H. Johnson wrote: > (CC to gentoo-project as required by the GLEP itself). >=20 > On Tue, Jul 12, 2022 at 05:28:36AM +0500, Anna Vyalkova wrote: > > This patch uses more friendly language towards potential transgender > > and plural contributors. > >=20 > > No other projects require to use a legal name, e.g. Linux says to use > > your real name[0]. > >=20 > > Government issued documents are really a bad example since in some > > countries it's really hard to get your name changed there. > Hi Anna, >=20 > There was a very long discussion in #gentoo-council IRC about this > today, with many sides represented. >=20 > I apologize I didn't follow who suggested some of the ideas first, so if > something was mis-credited, the fault lies with me. >=20 > The need is for GLEP76's name requirement to balance copyright protection= with > complexities of jurisdictional naming complexities [4][5]. >=20 > The kernel DCO says: > "using your real name (sorry, no pseudonyms or anonymous contributions.)" >=20 > Copyright law itself, at various levels (including US law and WIPO treaty > [CR001EN]) treaty does permit copyright held by pseudonyms in many cases. > But Copyright law also makes assumptions that some body, be it publisher = or > government office, holds the "real" identity (which can be discovered by = legal > or other actions), and the publisher holds some liability in this process. >=20 > Thus Copyright law tries to impose the need to associate a person with a > a copyrightable work. >=20 > Thus it raises two questions: > - Is the open source organization that receives a contribution a publishe= r in > this case? > - If the organization is a publisher, does this mean they are required to > implement some level of Know-Your-Customer (KYC) system? >=20 > This is all so messy :-(. Maybe we can approach it from a different angle. >=20 > The older version of the GLEP did use the term "real name", and it was > changed to "legal name" because the advice at the time is that "real > name" wasn't well-defined. > https://bugs.gentoo.org/653118 > https://gitweb.gentoo.org/data/glep.git/commit/glep-0076.rst?id=3D5713e7e= 0fbeb37a74743f11c80da2d8bdd87acf2 >=20 > I previously proposed amending it further: > https://archives.gentoo.org/gentoo-project/message/26d68349541e4db54a93ed= f57d6e7404 >=20 > But in further discussion, even my proposal didn't go far enough. >=20 > Neither "real name" or "legal name" correctly convey the underlying intent > here, and both of them have additional unwanted baggage [1][2][3], and > disproportionately impact some population groups. >=20 > Tying this back together:=20 > The Foundation has *zero* desire to implement a KYC system, or to be the > holders of any non-public personal information. Esp. The Foundation does > not want to even have to look at ID documents. So it's not acceptable to > just have: "send your linkage between pseudonym and name-on-ID to > trustees". >=20 > What's really needed? > GLEP76 must show that Gentoo (as a legal entity: the current Foundation, = or > future umbrella), has undertaken due diligence in accepting the contribut= ion. >=20 > The discussion in #gentoo-council ended up producing a potential text tha= t I'll > attached as a patch. >=20 > I'd like to thank the following for their contributions to the text. >=20 > kuzetsa CatSwarm ** significant wording > Richard Freeman > John Helmert III > Ulrich M=C3=BCller > Alec Warner >=20 > [1] https://en.wikipedia.org/wiki/Battle.net#Privacy_and_Real_ID > [2] https://en.wikipedia.org/wiki/Facebook_real-name_policy_controversy > [3] https://en.wikipedia.org/wiki/Nymwars > [4] Depending where you are, it can range from very easy to almost-imposs= ible to change your name. > [5] In https://archives.gentoo.org/gentoo-project/message/26d68349541e4db= 54a93edf57d6e7404, I linked many other examples > [CR001EN] https://wipolex-res.wipo.int/edocs/lexdocs/laws/en/cr/cr001en.h= tml >=20 > --=20 > Robin Hugh Johnson > Gentoo Linux: Dev, Infra Lead, Foundation Treasurer > E-Mail : robbat2@gentoo.org > GnuPG FP : 11ACBA4F 4778E3F6 E4EDF38E B27B944E 34884E85 > GnuPG FP : 7D0B3CEB E9B85B1F 825BCECF EE05E6F6 A48F6136 > From 77a948ffecf97035a42359be0a0b40ad5059fe2f Mon Sep 17 00:00:00 2001 > From: "Robin H. Johnson" > Date: Tue, 12 Jul 2022 14:52:23 -0700 > Subject: [PATCH] glep-0076: clarify name policy >=20 > Signed-off-by: Robin H. Johnson > --- > glep-0076.rst | 29 +++++++++++++++++++++++------ > 1 file changed, 23 insertions(+), 6 deletions(-) >=20 > diff --git glep-0076.rst glep-0076.rst > index 2216483..ce98ac8 100644 > --- glep-0076.rst > +++ glep-0076.rst > @@ -5,12 +5,13 @@ Author: Richard Freeman , > Alice Ferrazzi , > Ulrich M=C3=BCller , > Robin H. Johnson , > - Micha=C5=82 G=C3=B3rny > + Micha=C5=82 G=C3=B3rny , > + kuzetsa CatSwarm > Type: Informational > Status: Active > -Version: 1.1 > +Version: 1.2 > Created: 2013-04-23 > -Last-Modified: 2022-07-02 > +Last-Modified: 2022-07-12 > Post-History: 2018-06-10, 2018-06-19, 2018-08-31, 2018-09-26 > Content-Type: text/x-rst > --- > @@ -136,9 +137,8 @@ the Certificate of Origin by adding :: > =20 > Signed-off-by: Name > =20 > -to the commit message as a separate line. The sign-off must contain > -the committer's legal name as a natural person, i.e., the name that > -would appear in a government issued document. > +to the commit message as a separate line. The Name used is discussed in > +the next section. > =20 > The following is the current Gentoo Certificate of Origin, revision 1: > =20 > @@ -179,6 +179,21 @@ commits with the Linux Kernel DCO 1.1 [#DCO-1.1]_. = This shall be > indicated by adding ``(DCO-1.1)`` at the end of the ``Signed-off-by`` > line. Using the Gentoo Certificate of Origin is strongly preferred. > =20 > +Contributor Name > +---------------- > +Contributors must sign off on contributions with a name that can be made > +public and would pass copyright due diligence. > + > +Nothing further is required if the name matches a government issued > +document of the contributor. > + > +If the name does not match any government issued document, it must be a > +name that can be verified by simple records search, and/or attestable in > +a written statement, with a witnessed signature as before a notary. > + > +For the purposes of this policy, the Gentoo Foundation will not request > +any verification of the name until such time as required by government > +action or legal proceedings. > =20 > Copyright Attribution > --------------------- > @@ -344,6 +359,8 @@ In particular, the authors would like to thank David = Abbott, > Roy Bamford, Kristian Fiskerstrand, Andreas K. H=C3=BCttel, Manuel R=C3= =BCger, > Matija =C5=A0uklje, Matthew Thode, and Alec Warner for their input. > =20 > +For revision 1.2, further thanks are extended to kuzetsa CatSwarm, > +Richard Freeman, John Helmert III, Ulrich M=C3=BCller and Alec Warner. > =20 > References > =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D > --=20 > 2.35.2 >=20 --HUhi0bz8MhCkIx37 Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iHUEABYKAB0WIQQyG9yfCrmO0LPSdG2gXq2+aa/JtQUCY4fL0AAKCRCgXq2+aa/J tVjFAQC10M3Q0l8bj9dBwVlUocjr7BMezqwQ1J4c6CrVP9FTxAD+PCVZId4ILhw2 lmcQ6Ulnc4N2h2I4ODU5KUjV2pvarQI= =ztXW -----END PGP SIGNATURE----- --HUhi0bz8MhCkIx37--