When we talk about free and open source software it’s usually in technical terms – the source is available, anyone can inspect it, fork it, change it or contribute. But all those things only work and make sense in the context of a minimum level of honesty, good faith, reciprocity, patience and mutual recognition of each other’s humanity.
Trust and good faith
Contributors implicitly trust each other to:
- truthfully describe bugs
- not waste maintainer’s time with intentional distractions
- make code submissions intended to improve the project
- Give PRs the review they deserve
- not exploit undisclosed vulnerabilities
- and on and on.
There’s a lot of trust going on. No one assumes everyone is totally trustworthy but there is a baseline of trust that is necessary in order to function at all.
In an ideal world, contributors would also give others the space they need to understand things, appreciate each other’s different backgrounds, abilities, pressures and amount of free time. Ideally we would apologise, reconsider and change our minds sometimes.
But we’re all human – we make mistakes, we have bad days, we rub each other the wrong way. When these inevitable parts of life happen the project’s good vibes bank account needs to be full enough to absorb those shocks. There needs to be a safety margin so that there aren’t too many straws breaking camels’ backs. Phew, three metaphors in one paragraph! This buffer makes ongoing collaboration possible over time. A healthy project allows someone to occasionally be wrong, awkward, inexperienced, tired or ill without immediately turning that event into a judgement about their character. When someone makes a decision and other people jump to conclusions about transphobia, ableism, etc then it becomes a determinant of someone’s moral value. And that’s toxic. We need to recognise one another as human beings deserving of reasonable grace. Grace in the sense of how we interpret mistakes and disagreements – not as an obligation to tolerate behaviour that makes participation impossible for everyone else.
Openness creates opportunities for attack
The same transparency that makes open source so awesome also provides easy ways to attack it and a great source of material that can be selectively presented to build a narrative.
Code, commit messages, issue discussions, moderation decisions, chat conversations and design docs can all be taken out of context and presented as evidence of something. A code snippet can be selected without other code that determines how it functions, a screenshot of a real chat conversation can be cropped, a flaky LLM-generated security finding can be published and treated as if it was a confirmed vulnerability (all of this was done to PieFed). Selection, omissions and framing make all the difference.
Don’t get me wrong here – criticism is good and necessary. But there is good criticism that is an attempt to understand and improve the software and then there is bad criticism that is just an attempt to construct a damaging narrative regardless of the truth. Good criticism is true, contains relevant context, represents uncertainties as uncertainties and presents an opportunity for improvement.
And here’s the rub
Both the friendly culture with its safety margin and the openness are needed for the project to live. So to attack an open source project you don’t need to hack its software or disrupt it on a technical level – when someone makes people distrust the software, its maintainers, moderators, security or the motives of the people involved then that causes lasting damage. When people stop seeing each other as humans and instead start calling each other things like “transphobe” or “zionist” or “fascist” then there is no buffer, no room for compromise or giving each other the time to understand things. When someone is reduced to a subhuman label, any and all attacks on them are justified.
If you can decrease the safety margin of a community and at the same time use its openness against it, you have a really powerful strategy for collapsing it.
This isn’t just about PieFed
Some of a FOSS maintainer’s most valuable assets are their time, reputation, motivation and the willingness to continue doing the work even when it’s not fun. Bad-faith campaigns impose costs on those resources even when the underlying accusations are weak. Remember “Flood the Zone”? It takes waaay more energy and time to debunk a false narrative than it takes to construct and spread a false narrative. For example it’s really easy to claim “PieFed secretly hardcodes a blocklist” but disproving it requires
- finding the relevant code
- explaining it
- showing configuration
- demonstrating the UI
- answering follow-up claims
- dealing with people who never saw the correction, for months after.
Due to our natural love of controversy and negativity a false allegation can reach thousands of people while the boring truth might only reach a fraction of them.
Beyond just PieFed, in general we need software for the fediverse to be FOSS software, in order to perform its power-diffusing function – closed source centralizes power (to the developers and owners of it) which is antithesis to what the fediverse is trying to achieve. But if building and maintaining an open source federated service is socially toxic and every moderation decision or disagreement can become an attack on an administrator’s character, fewer people will be willing to take on that role. Protecting the fediverse means protecting not only the technical infrastructure but also the culture of good faith and grounded humanity that allows people to keep building and running it.
What now?
There will always be trolls and bullies, that’s just the internet. We can’t expect that to change.
I hope that people who want to see the fediverse thrive can show more solidarity when they see someone being attacked. There is a risk the mob will turn on them too but if everyone keeps taking the easy way out, doesn’t ask for receipts when allegations are made and immediately trusts the way those receipts are framed then things aren’t going to get better.
Fediverse maintainers don’t deserve immunity. But when you see an allegation ask yourself whether the claim is verifiable, is there another possible interpretation, what are the motivations of the accuser and has the accused been given a real chance to respond.
Please.
