[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [Debconf-team] Public participants list - Is it OK this way?



Hi,

On Thursday 16 February 2006 16:32, Gunnar Wolf wrote:
> I think maybe I could add a field allowing people to hide their
> arrival/departure times (defaulting to false). 

If you add this now, you have to default to true. You cannot publish peoples 
private data (*) without their consent. Well, at least, you should not.

The right thing would be to have a checkbox, defaulting to no, saying "it's 
okay for me to publish my arrival and departure dates". And for all people 
who already entered this data, you need to set this box to no. 


> [1] https://www.debconf.org/comas/general/participants

What are those "contributions" ?

Technically^w I do think the "country" is also private data, but I somewhat 
gave up on high privacy standards within debconf (*) already. Heck, the name 
of a person (and the fact that he or she is attending debconf) is private 
data. You could of course argue, that people who registered to debconf knew 
that this data was made public last year already, so they could have expected 
that this would happen this year again... So for next year I propose some 
checkboxes "I'm happy with this being public." Thanks for your consideration.

Oh, and the fact that the world is going crazy and only criminals and people 
in caves have privacy, doesnt make those mistakes right.

(*) The first time a picture of me was linked to my name on the internet 
happened at debconf3 - without my consent or even being asked.


regards,
	Holger, who _is_ happy that at least not all data is available to the general 
public without registration...


P.S.: that reminded me that we should remove (some of the contents) of the 
comas database from cmburns after debconf6 is over. I just looked into the 
Taskjuggler file to add this to the cleaning tasks, but I couldn't find any. 
Could someone please help me so we can add this, so we dont forget it. 

(Even the CCC (who has been praying this for long) "lost" private information 
once: someone hacked a ccc-server and found a complete db-backup of an event, 
with password data and all the participants listed within. 
See https://www.ccc.de/updates/2004/camp-server-hack?language=en for more 
information on this.)

Attachment: pgp4NuvD7LenA.pgp
Description: PGP signature


Reply to: