A while ago, I published an article explaining how AI scrapers were placing a heavy burden on Open Source projects; though that is still true, some tools have been developed to address that (such as Anubis).

Even earlier, we talked about whether Open Source projects should allow AI code contributions or AI-generated bug reports. Many projects, such as Servo, decided not to allow them at all.

However, things are moving, and these discussions are taking place increasingly more often. Thus, I'd like to briefly address the question: how are Linux and the FOSS ecosystem dealing with AI?
Let's start with this article by ZDNET. They claim that AI is "creeping into the Linux kernel - and official policy is needed ASAP".

An example of that is AUTOSEL, which is a "Modern AI-powered Linux Kernel Stable Backport Classifier".

According to the announcement,
AUTOSEL automatically analyzes Linux kernel commits to determine whether they should be backported to stable kernel trees. It examines commit messages, code changes, and historical backporting patterns to make intelligent recommendations.
This has been praised as a positive example of modern LLM usage, as it's meant to support a developer without replacing one; and it does not perform any action, as it only presents advice with a reasoning for it, and it's up to the developer whether to take it or not.
However, AI usage in the kernel goes beyond the use of such tools.
During the 2025 Open Source Summit, NVIDIA Developer Sasha Levin shared that a patch that was credited to him was entirely AI-generated, though he did review and test it himself.

Note that this was not disclosed when the patch was submitted for review, at least to my knowledge.
Please note that AI agents are used here, meaning that the LLM is allowed to run git commands to learn about the repositories; though, I'm assuming that the access is read-only for them.
Another example is the git-resolve script that will "resolve an ambiguous ID into a full commit"; this was also fully generated, and it included a set of testcases, which is unusual for kernel scripts.

AI code in the kernel includes some particularly sensitive work. In early 2024, the kernel took on the responsibility of assigning Common Vulnerabilities and Exposures numbers. This began as a collection of bash scripts, but it quickly grew unmaintainable; the team decided to use an LLM to translate those scripts to Rust, making CVE assignment code entirely AI-generated.

This raised many questions, even just during Levin's presentation: isn't there a risk of trusting LLM outputs too much? What's the licensing of AI-generated content?
Levin believes that if an LLM produces code, he is free to make use of it. This is somewhat debatable, as some complex legal issues depend on the country you live in, but this could be the topic of an entire other article.
He's not the only one experimenting with this. Another example are these patches by Kees Cook, who was experimenting to see how much code he could reasonably generate.

Turns out, he had success with some reasonable unit tests, which - he claims - saved him some time, though some prompting was required to nail it. However, he did not manage to save any time on non-testcase patches.

Shortly after his talk, Levin sent a Request For Comments set of patches to introduce AI coding assistant configuration files to the Linux kernel documentation.

Specifically, this consisted of two different patches.
The first patch adds unified configuration files for various AI coding assistants (Claude, GitHub Copilot, Cursor, Codeium, Continue, Windsurf, and Aider). These are all symlinked to a central documentation file to ensure consistency across tools.
The second patch adds the actual rules and documentation that guide AI assistants on Linux kernel development practices, including:
- Following kernel coding standards
- Respecting the development process
- Properly attributing AI-generated contributions
- Understanding licensing requirements
Interestingly enough, the AI is instructed to add itself as the co-author of all patches, but to only let a human sign off the commit, as that "represents a legal certification".

Along with this documentation for AI agents, there is a patch being reviewed to introduce guidelines for human developers using AI.

Please note that these guidelines only apply when a significant portion of the patch content is generated; smaller tweaks, such as spelling and grammar fixes, variable renamings, reformattings, etc. are out of scope.

The guidelines ask to disclose which tools were used, the input of those tools (such as the prompts you chose), and which content exactly was AI-generated.

It's then up to the maintainers to choose what to do with that information. They might want to reject the patch outright, review it more carefully, suggest a better prompt, or just ask for more details. (Though I'm a bit worried about this creating very different policies within the kernel.)

The Great™ Linus Torvalds has, of course, commented on this proposal as well; here's what he had to say:
Honestly, I think the documented rule should not aim to treat AI as anything special at all, and literally just talk about tooling. [...] IOW, this should all be about "tool-assisted patches should be described as such, and should explain how the tool was used". [...] people should mention the tool it was done with, and the script (ok, the "scripts" are called "prompts", because AI is so "special") used.
I would like to quickly mention that the Linux Foundation also has its own rules for the usage of generative AI tools. As a quick reminder, the work of the Linux Foundation goes well beyond Linux kernel development, as it also sponsors and works on hundreds of open-source projects.
The Linux Foundation only puts two rules on AI-generated content. Firstly,
Contributors should ensure that the terms and conditions of the generative AI tool do not place any contractual restrictions on how the tool’s output can be used that are inconsistent with the project’s open source software license, the project’s intellectual property policies, or the Open Source Definition.
These seem to be in line with the question we asked earlier: what's the exact license of content generated by AI? Since, again, the answer is not easy to obtain, the Linux Foundation seems to have this policy to, well, blame the developer if anything goes wrong.
The second term is the following:
If any pre-existing copyrighted materials (including pre-existing open source code) authored or owned by third parties are included in the AI tool’s output, prior to contributing such output to the project, the Contributor should confirm that they have have permission from the third party owners–such as the form of an open source license or public domain declaration that complies with the project’s licensing policies–to use and modify such pre-existing materials and contribute them to the project.
This rule exists because LLM models have been found to generate exact excerpts of their training data in a small number of cases. This means that the developer should always check that the generated code does not contain any copyrighted material (though it's unclear how they would do that).
Well, these were the Linux Kernel and the Linux Foundation, both of which are very big institutions within the FOSS world, and they are worked on by companies such as NVIDIA itself; I'm not surprised to see active work on how to use AI tools here.
But of course, the rest of the FOSS world is often a bit more hostile.
I already mentioned how Servo, the web engine currently developed by the Linux Foundation, entirely bans AI contributions. This is due to claims of maintainer burden, (lack of) correctness of these patches, and the above-mentioned copyright issues.

Multiple GNOME projects also have such a guideline, though I'm currently not aware of a project-wide stance on this. ElementaryOS does have one (which is directly inspired by GNOME's). Some goes for FreeBSD and Gentoo.

I can also share that there has been some internal discussion within KDE on what a policy on AI contributions should look like. This was started by one patch that was submitted by developer Mikhail Sidorenko, which was generated by Cursor.

Other projects have a more "moderate" policy, which is more akin to the Kernel one.
One such example is Fedora, which does allow for AI assistance, but requires the developer to follow some principles.

Namely, you (1) take responsibility for your contribution, regardless of how you made the patch. (2) You must disclose the usage of AI tools; the recommended method is to use the Assisted-by commit message trailer. (3) You must use AI as a tool to assist you; it should not be "the sole or final arbiter in making judgment on a contribution".

This brings me to Mozilla, which has recently been under fire for reportedly "pivoting to AI" (I'll make an example later).
They have guidelines that seem to be even more permissive of AI usage than the Linux kernel's, as they only place one real constraint on these contributions: you are accountable for all changes you submit, regardless of the tools you use.

Now, a few weeks ago, Firefox published a blogpost titled "Introducing AI, the Firefox way: A look at what we're working on and how you can help shape it".

According to them, they are making sure to protect your privacy by only running local models on your device, which means that no data leaves your machine. (More on this soon.)

They integrate Generative AI in many different places:
There's automatic alt text generation for images, which helps out with accessibility, and automatic translation of webpages.

On iOS, you can even shake your device to summarize the page you're viewing (this feature is also supported on the desktop, obviously).

They're also experimenting with AI suggestions for tab groups: if you have a lot of tabs of a similar topic and try to create a tab group, Firefox will suggest a proper name automatically. There's also Link preview, which will show you a snippet from a link you're hovering over.

You are also given the option to have a sidebar with a direct link to a chatbot (which could be any, from Claude to Gemini, and even Mistral). For obvious reasons, however, this feature can not run locally and requires you to accept the privacy policy of the selected chatbot. Effectively, it's a bit like a pinned webpage with that chatbot.

Finally, they want to take this a step further by creating "AI windows", where the AI assistant that you select will be able to interact with the webpage that you're seeing; though, this feature isn't publicly available yet.

It's interesting to see Mozilla try to strike a balance between being "modern and appealing" (to techbros!), but also not alienate their existing userbase. On one hand, I appreciate that most (if not everything) they are doing is opt-in and runs locally whenever possible. On the other hand, they'll still alienate a chunk of their users.
Since there was misinformation being spread around on this topic, I'd still like to stress that Mozilla in no way is collecting your data for anything related to AI training or selling it to AI companies. So at least there's that!
And, of course, Mozilla also has a dedicated subsidiary for AI.

All in all, with this article I tried to give a very brief overview of different approaches and reactions to AI-generated content within the FOSS world. As you can see, some projects are actively endorsing this change, some are being more cautious, and some are rejecting it outright.
I haven't published a video in a while, which means that I've missed out on all of the juicy drama of the past months. Let's catch up right away.
This is Omarchy. It's a "Beautiful, Modern & Opinionated Linux" by the creator of Ruby on Rails. It uses Hyprland on top of Arch, and whichever company promotes it, such as Frameworks, is up for some drama.

The issue is with the author, David Heinemeier Hansson. He does many things: he wrote four books, he's an investor in Danish startups, he's been on the Lex Fridman podcast, The Primagen's, and many more.

As Ruby developer Tom Stuart puts it in a 2014 lightning talk,
DHH is an intelligent and successful person. DHH invented ruby, and now I can get paid for writing ruby even though I enjoy it.
He also says, shortly thereafter:
DHH is the Fox News of Ruby. He's noisy, he's reactionary, he's anti-intellectual, he's very sure he's right and he enjoys being rude.
Maybe I should've mentioned that the name of the talk is "The DHH problem".
Things haven't changed much: ten years later, we've seen an open letter to the Rails Core team and Ruby community asking to cut ties with David.

This open letter has been signed by many: ruby maintainers, the co-founder of discourse and Stack Overflow, and more. However, it was ultimately unsuccessful in achieving its intended purpose or raising enough support.

Indeed, David's Arch-based Linux distribution is becoming extremely popular, and David claims to have a wide range of opinions, going from left-leaning to right-leaning, but all moderate and reasonable. And, if you haven't been following closely, you might not be aware of exactly why so many people are angry at him. So let's clear this up.
David believes that Israel's occupation of Palestine is an apartheid regime, that Abortion should be legal and accessible (with some restrictions) and that structural racism is a big problem in America.

He says,
If you take just those three, you're going to form an impression of someone on Team Liberal/Left.
He also believes that Russiagate was a mass delusion, that Parler's eviction from the internet was wrong, and that Trump was mostly right on trade with China.

But, at the same time, he thinks that cars don't belong in cities, that climate change is a catastrophic problem, and that bitcoin is bad. He also dislikes the usage of the word "snowflake" as an insult, and he believes it should be a compliment.

Why is he listing all of these takes? Well, his claims is that - just like everyone - he is a mosaic of different positions, some of which are more or less liberal, some of which are more or less controversial.
I agree with many of these takes - namely, all of the ones he presents as left-leaning. I'd also be willing to debate some of the right-leaning ones.
As an example, I do think that companies like Google and Apple can decide that they don't want to host right-wing social networks like Parler, and that is not related to freedom of speech. At the same time, I think that raises a question on the centralization of the web, and that we should be careful with allowing companies to fully control which apps can run on a given operating system. I'm happy that the EU is forcing Google and Apple to allow third party application stores and payment services. I think this would be an interesting discussion.

The same goes for Russiagate; I don't think it was a mass delusion at all, but I do think some aspects of it were overblown, and I'd find it personally very interesting to read a writeup (or, as many people call them, a book) on the topic, even though me and David are clearly on different starting points on this issue.
Well, is David up for debate on these topics? Yes, but. He says:
There are very few people who I'd willingly sit down to have a good-faith, substantial discussion with about those. Because the odds are that we'll run sour quickly. Those debates need the right context, the right people, the right frame of mind. And at work? No, never. Especially at work! Especially because work involves all sorts of delicate power balances already.
This sounds reasonable, though we'll discuss it later on. But right now I'd like to emphasize the narrative he's trying to create. Funnily enough, I'm not someone who likes to discuss politics, even though I actively take part in it: different people often have such different references and worldviews that it's hard for me to constructively build a discussion, and I agree that it's too easy to hit an identity bedrock and make no further progress. This is to say: I understand where he's coming from.
And indeed, he believes in this so strongly that he backed the decision by Basecamp CEO to ban societal and political discussions from within the company (David is Basecamp CTO and co-owner). The reasoning was the following:
Today's social and political waters are especially choppy. Sensitivities are at 11, and every discussion remotely related to politics, advocacy, or society at large quickly spins away from pleasant. You shouldn't have to wonder if staying out of it means you're complicit, or wading into it means you're a target. These are difficult enough waters to navigate in life, but significantly more so at work. It's become too much. It's a major distraction.
And indeed, David adds the following in a dedicated blogpost about this topic:
Basecamp should be a place where employees can come to work with colleagues of all backgrounds and political convictions without having to deal with heavy political or societal debates unconnected to that work.
He suggests that willing coworkers continue with political discussion, but he encourages them to do so using other platforms, such as Signal.

Of course, David still encourages employees to be active in politics outside the workplace, and he's active too, with his mosaic of positions.
He himself claims that his positions that end up receiving most pushback are "the most banal, mainstream positions".

And he repeats that:
[...] because you have some mainstream political takes on [...] immigration in Europe or any other topic that there might exist out there shared with literally millions of completely ordinary people.
A message just ever-so-slightly undermined by the fact that it was said during a video collaboration with Lunduke, someone who's against vaccines, denies climate change, thinks the 2020 elections were rigged, and thinks being trans is a sexual fetish – a set of views that's not quite "banal" or "mainstream", especially outside the US.

And really, this is where I'd like to start pushing back on the claims David has made so far. I'd like to argue that banning political discussions in the workplace is not effective, that the dislike towards him is not entirely based on politics, that his controversial views are not mainstream or banal, and - finally - that his "mosaic of opinions" tends heavily to the right. Let's go step by step, then.
The most controversial political takes by David were published on his blog between 2020 and now; therefore, if we want to set that aside, we can go back in time and see what people thought of him back then.
I've already mentioned the "The DHH problem" talk from 2014, which does not talk about politics at all. I recommend that you go check it out - it's merely three minutes long - but I'll quote here the important part:
DHH is the Fox News of Ruby. He's noisy, he's reactionary, he's anti-intellectual, he's very sure that he is right, and he enjoys being rude.
Just like Fox News, DHH appeals to "common sense" and makes a show of being "far & balanced", but in reality his arguments use aggressive rhetoric and rely on a fixed viewpoint. To pick a topical example: is TDD hard in rails apps because TDD IS DEAD, or because rails makes TDD hard? Is TDD not worth the effort because TDD IS DEAD, or because the complexity of seftware can be managed more effectively if you only work on one product for which you control the requirements?
If we only listen to DHH then we'll never know, because DHH is just one person and he only has DHH's experiences. All I'm saying is, the Ruby community is large and diverse and thoughtful and that is why I love it. Please listen to DHH, his experiences are valuable, but DHH does not speak for me, and he probably doesn't speak for you.
Even before this talk, in 2008, Jeff Atwood (co-founder of Stack Exchange and Discourse) wrote a blogpost titled "Douchebaggery", all about DHH.

Again, you're invited to check it out, but to quote the important part:
Of course, as David has said many, many times, he doesn’t care whether we agree with him or not. [...] if you accept the premise that this kind of statement won’t change anyone’s mind, and is ultimately ineffective – even counterproductive – what are we left with? What purpose does the statement “stigma of being a Windows developer” serve? I can only think of one: David gets off on putting other people down.
And that makes him kind of a douchebag.
Going even earlier, in a 2007 blogpost by Rob Conery (linked in the above quote), we get:
The Rails dudes are pretty damn smart. But they’re also pretty damn arrogant. As DHH says:
"I’m not in this world to create Rails for you. I’m in this world to create Rails for me and if you happen to like that version of Rails that I’m creating for me, than you are going to have a great time."
One of the more shocking presentations I’ve ever seen involves DHH telling his audience who he’s writing Rails for, and why he doesn’t really listen to the community when they suggest where he should take it
And this is the image from that talk that's quite popular when criticizing David.

Again, my goal here is not to perform some character assassination of DHH, but I do think that multiple reports of David being rude and arrogant will partly explain some of the negative sentiment towards him and part of his politics past-2020.
Let's get back to the "No politics in the workplace" rule in Basecamp. I would now like to argue that it's a very ineffective rule to apply.
The Verge has published a great article on the causes and consequences of this choice; again, you're recommended to go check it out.

Firstly, let's talk about the cause:
Basecamp customer service representatives began keeping a list of names that they found funny. Many of the names were of American or European origin. But others were Asian, or African, and eventually the list [..] began to make people uncomfortable. What once had felt like an innocent way to blow off steam [...] increasingly looked inappropriate, and often racist.
Of course, this sparked some internal discussions, and the rule was introduced to shut them off. However, some employees claimed that the only political discussions happening at Basecamp were about the company itself:
“At least in my experience, [the discussion] has always been centered on what is happening at Basecamp,” said one employee [...]. “What is being done at Basecamp? What is being said at Basecamp? And how it is affecting individuals? It has never been big political discussions, like ‘the postal service should be disbanded,’ or ‘I don’t like Amy Klobuchar.’”
And indeed, I think it's impossible to drive forward a company or organization without making explicit political choices.
Suppose, for example, that someone intentionally misgenders someone else. You could ban that person from the community or warn him, which would be seen as a political decision (and, as we'll see, DHH would disagree with the ban). Alternatively, you could ignore the misgendering, which would also be a political stance (you'd either not consider misgendering as a form of harassment, or you'd think that it's better to have free speech rather than a harassment-free organization or workplaces, both of which are quite political takes).
This is a rather specific example, but it's just one of many. Moderation requires constantly making political choices, and the same applies to building an international product: these kinds of issues will arise and have to be discussed.
The discussion around the list of names is a good example; Jane Yang, data analysis at Basecamp, makes another:
She said, the company’s profit-sharing plan gave more profits to people who have longer tenure — a group that is majority white and male. Making that discussion off-limits internally could ensure that inequality in profit sharing becomes a structural feature of the company.
Basecamp even let a Chicago mayoral candidate use their offices as campaign headquarters in 2018.

After the no-politics rule was announced, one employee wrote an open letter to Jason and David, which highlights even more political disagreement between them and the employees, and how they handled it:
[...] when our Use Restrictions Policy was first officially rolled out, neither hate speech nor harassment were included. One of my colleagues [...] and I [...] had debated vigorously for their inclusion, with David in writing while Jason gazed from the sidelines, intellectually making our case before ultimately being told: no.
In the end, banning political discussions simply means handing over the entire political power to the higher-ups of the company without allowing for pushback on any action, and it's telling that this happened two weeks after some employees started fighting back on DHH's accountability over the above mentioned list of names.
DHH politics are anything but banal and mainstream. Let's see why, in detail.
One post of his that's often quoted is titled "As I Remember London". He makes multiple debatable claims. As an example, he writes:

London is no longer the city I was infatuated with in the late '90s and early 2000s. Chiefly because it's no longer full of native Brits. In 2000, more than sixty percent of the city were native Brits. By 2024, that had dropped to about a third. A statistic as evident as day when you walk the streets of London now.
There are so many wrong things with this statement.
Firstly, the linked Wikipedia page claims that 59% of London's population was born in the UK, which seems to be in contrast with the idea that only a third is "native Brits". This comes from the 2021 census, and I have not found any more recent data about it.

Apparently, the criteria for being "native" run a little deeper than just being born in the UK. You could argue that, to be "native", your family needs to have lived in the UK for a certain number of generations. However, we don't have data about that: how did DHH come up with the "one-third" number?
My suspicion is that he's going after this graph, only counting "White British" as native Brits. I don't see any other way to interpret the data in a way that supports his data.

However, this is insanely misleading.
As an example, in 1981 and 1991 we know that 13% and 19% of London's population were already non-White, so I don't think we can dismiss all non-White as also non-native Brits (as the 2021 census also suggests); and this data was conflating "White British" and "White Other", which were later split apart.

He also considers all "White Other" ethnic groups to not be native Brits, which is particularly weird because he claims he can see how many people are native Brits by just walking through the streets of London.

Which seems to be an elegant way to write: when you walk the streets of London now, there are too many Black and Asian people, and not enough White people. I don't know how else to read this. It's weird to point at both white and non-white people, born and raised in London's culture, and claim that they are a problem (how would that be the case?).
And yet, according to DHH, what's happening is a "demographic nightmare". Another paragraph reads:
Which brings us back to Robinson's powerful march yesterday. The banner said "March for Freedom", and focused as much on that now distant-to-the-Brits concept of free speech, as it did on restoring national pride.
Again, let's stop. If you're not a "native Brit", you might need a reminder of who Robinson is.
He assaulted an off-duty police constable who had intervened in an argument between him and his girlfriend. He also assaulted another man in 2011.

In the same year, he was convicted of threatening, abusive, or insulting language for leading a group of football supporters into a brawl involving 100 people.

The following year, he was arrested for having entered the United States illegally, which is somewhat ironic. He had entered the US with a forged passport because he had been banned from entering the US due to his criminal record.

He was also charged with three counts of conspiracy to commit fraud by misrepresentation in relation to a mortgage application, to which he pleaded guilty. The fraud amounted to 160,000 pounds, and the judge described him as the "instigator, if not the architect" of frauds for a total of 640,000 pounds.

In 2021, Robinson went to the home of a journalist, accused her partner of being a paedophile, and threatened to return every night. He was issued an interim stalking ban order and later convicted of stalking the couple.

And, on top of that, in 2025, he was also charged with harassment causing fear of violence against two Daily Mail journalists in 2024, though he pleaded not guilty here.

There's much more, but we can stop here with the criminal charges for now. Politics-wise, Robinson has described himself as opposed to Islam, he promised to retaliate against every single Muslim, and he called for the blanket deportation of every adult male Muslim recently immigrated to the UI.

During the protest that DHH is describing, Robinson claimed that:
It’s not just Britain that is being invaded, it’s not just Britain that is being raped. Every single Western nation faces the same problem: an orchestrated, organised invasion and replacement of European citizens is happening.
During the same "powerful" march, we also heard statements like:
They are demanding the sacrifice of our children on the altar of mass migration. Let’s not beat about the bush — this is the rape, replacement, and murder of our people… Remigration is possible, and it’s up to us to make it happen. We are Generation Remigration.
For those wondering, "Remigration" means "ethnic cleansing via the mass deportation of non-white immigrants and their descendants, sometimes including those born in Europe, to their place of racial ancestry".

This is the political leader and their march that DHH is explicitly supporting. And he tries to explain that this gathering was completely "normal and peaceful", and that they should not be defined as far-right.
The easy way out of this uncomfortably large gathering of perfectly normal, peaceful Brits [...] is to tar them all as "far right". That's not just a British tactic, but one used across Europe [...].
However, if the Great Replacement theories, ethnic cleansing, and forceful mass deportation, mixed with strong nationalism, aren't far-right, then I do not know what is.
Now, weirdly enough, I do agree that labeling all participants as far right is probably incorrect, as all rallies have significant variance within it. However, the leadership and organization hearth of the rally that David specifically supports, such as Robinson, is objectively far right.
DHH goes on to complain about totalitarianism in the UK:
The totalitarian descent into censorious darkness in Britain has been as swift as its demographic shift. British police are now making 30 arrests a day for wrongthink, wrongspeech, and other online transgressions against "the regime narrative", as the BBC would have reported, if this were a statistic from a foreign nation.
Please note that this is false. The arrests are for communication that contains threats to assault other people, false rumors that someone has committed crimes, sending multiple messages with abusive language, false bomb threats, mocking tragedy in a way that's grossly offensive to the victim or to the public, and so on.

On top of that, the law that the article was referencing has already been repealed and replaced with the Online Safety Act in 2024, so it's no longer relevant.

Furthermore, the Crown Prosecution Service makes sure that free speech is safeguarded, even speech that offends, shocks, and disturbs (as covered by the European Convention on Human Rights).

As Emma Monk, who wrote a detailed blogpost about this, states:
People are not being arrested, let alone charged, for stating their political opinions on Facebook. As yet, I’ve not come across a single “thought police” story that has turned out to be true.
As examples, she mentions that claims of arrests due to criticism of a local councillor turned out to be actually caused by an accusation of harassment.
DHH also provides his own example:
Most recently, five officers(!) came to arrest comedian Graham Linehan for illicit tweets. When much of the media reports a story like this, it's often without citing the specific words in question, such that the reader might imagine something far worse than what was actually said. So you should actually read the three tweets that landed Linehan in jail, and earned him a legal restraining order against using X. It's grotesque.
The incriminated tweet says the following:
If a trans-identified male is in a female-only space, he is committing a violent, abusive act. Make a scene, call the cops and if all else fails, punch him in the balls.
Which is an invitation to violence.
It's worth saying that Twitter itself had already permanently suspended his account after repeated violations of their rules against hateful conduct and platform manipulation. Linehan evaded that ban by creating a fake account that impersonated a transgender man. That account was also banned, but he created another.

Linehan was reinstated on Twitter in 2022, when Elon Musk took over the platform. However, he was banned again when he tweeted the words "Durr imm gonna kill em", referring to trans right activists. Again, his account was later reinstated.

Finally, it's worth stating that the bail condition not to post on X that DHH is mentioning only lasted one week, and he was released with no charge.
All in all, if the UK government is attempting to be a totalitarian state, I don't think they are doing a good job: the worst they could do to someone who's very clearly opposed to them and who has multiple times (jokingly) incited violence, is to briefly detain him and then not let him use Twitter for a week.
Getting back to the post, DHH then starts to explain why he thinks that non-native Brits are a problem. He states:
I really feel for the Brits because it's not obvious how they get themselves out of this pickle. They're still reeling from the Pakistani rape gangs that were left free to terrorize cities like Rotherham and Rochdale for years on end with horror-movie-like scenes of the most despicable, depraved abuse of British girls.
And, similarly,
Unwilling to just let their society wither away while their bobbies chase bad tweets instead of the rampant street thefts or those barbaric rape gangs. Unwilling to resign the rest of the country to the kind of demographic replacement that befell London over the last two decades.
Again, I find these examples misleading.
As an example, according to the Centre of Expertise on child sexual abuse report of 2023/2024, White British people are actually over-represented in comparison with the general population of England and Wales.

This means that a higher population of non-white people would predict a lower amount of child sexual abuse, though the correlation is low enough that it wouldn't be by a significant number. As the Jay report about the Pakistani rape gangs writes,
[...] there is no simple link between race and child sexual exploitation, and across the UK the greatest numbers of perpetrators of CSE are white men.
Bringing up single examples, regardless of how popular they might be, cannot change the broader statistics.
Jake Lazaroff wrote a blogpost about the topic, which ends very appropriately:
Let’s ditch the superlatives and review David’s post objectively:
He thinks that even if you were born in the UK, you only count as British if you’re white.
He wouldn’t consider living in London specifically because it has too many people of color.
He uses racist tropes to accuse Asian men of being dangerous predators who attack white women.
He pushes debunked conspiracy theories about immigrants replacing white people.
He finds a march where speakers called for banning all non-Christian religions and ethnically cleansing immigrants “heartwarming”.
Finally — and maybe most alarmingly — he argues that all of the above is normal and not extreme.
I would also like to recommend the blogpost by Paul Jensen on the same topic.
Now, I've been focusing a lot on this post because I believe it's the best example of the attempt to pass far-right policies as "common sense"; however, we have to take a step back and check the bigger picture.
Even though David claims to be a mosaic of opinions ranging from left-leaning to right-leaning ones, in his blogposts he seems to more often lean one specific way.
As an example, he wrote two blogposts to celebrate the waning days of DEI and wokeness.

He also wrote an entire piece on why Trump's second term finally brought back some optimism to him, writing "we're so back".

He also complained that students at the Copenhagen International School had the option to join a student-led support group for students who identify as part of the LGBT community. This feels particularly wrong to me, as otherwise David is highly in favor of free speech above everything else; however, when students self-organize to give other students the option to talk about progressive topics, he jumps in to say that this shouldn't be happening.

Throughout his posts, we can find hints of nationalism and nostalgia towards the past. There's a piece praising America's freedom, where the God Bless the USA song is quoted in full as it rings poetically true.

Which would be fine, obviously, if only it wasn't justified with misinformation about other countries. As an example, we see again mentions of
Fast-track tribunals [have been] setup to hand out unbelievably harsh sentences for such terrible offenses as "anti-establishment rhetoric", criticisms of mass migration, and "obscene gesticulations at the police".
in the EU and the UK. There's also criticism of the EU for
threatening the owner of X, Elon Musk, with severe consequences if he does not abide by its arbitrary definition of what defending us all against "misinformation" and "hate speech" looks like.
"Threat" is a weird word to use here, since the EU only "threatened" to apply the existing laws (we all live under that "threat").
Furthermore, the letter he's talking about was in the context of riots that took place in the UK triggered by disinformation related to a fatal stabbing attack.

More specifically, posts went viral claiming that a murderer was Muslim, a refugee and/or a migrant. None of that was true: the perpetrator was born in the UK in an Evangelical Christian household. And yet, this false information was promoted by people like Adrew Tate and Elon Musk himself.

Thus, I feel like the EU had some legitimacy in warning Twitter about their amount of false information, given that one of the first thing Elon did was to dismantle safety guardrails aimed at curbing hate speech and disinformation, and doing mass layoffs of content moderation staff.

And, talking about Andrew Tate, DHH somehow felt compelled to write a blogpost to defend him, complaining about the dicothomy of "are you for or against Andrew Tate" and claiming that it's important to allow him his free speech. David says,
You don't have to like any of Andrew Tate's takes on men, women, wealth, or the world to see that this modern, coordinated unperson campaign against his "wicked words" is crazy.
It's worth noting that Tate was arrested on suspicion of rape in 2015, harassed a political activist by forcefully kissing her in 2018, kept two women in his apartment against their will and was then charged with human trafficking in continued form, he was investigated with trafficking minors, sex with a minor, money laundering and attempting to influence witnesses, and then his ex-girlfriend accused him of chocking and beating her.

I feel like this goes a bit beyond the "he has some bad opinions about women" stage.
This video is getting extremely long already, but it's worth making one further example and then move on. There are many posts where he seems to be overly confident, talking about seemingly absolute truths whilst not knowing much of the topic itself.
Take, as an example, his reaction to this ad from Calvin Klein, which appeared during the "2020 insanity" (as he calls it):

I passed it every day biking the boys to school for weeks. Next to other slim, fit Danes also riding their bikes. None of whom resembled the grotesque display of obesity towering over them on their commute from Calvin Klein.
That's the problem with the whole "representation" narrative. It proposes we're all better off if all we see is a mirror of ourselves, however obese, lazy, ignorant, or incompetent, because at least it won't be "unrealistic". Screw that. The last thing we need is a patronizing message that however little you try, you're perfect just the way you are.
Which, in my opinion, completely misses the point and makes a false equivalence between obese and lazy/ignorant/incompetent! We tend to project our personal situation onto others and assume they work the same as us; but they don't. It's easy for some of us to stay within a medically healthier weight range, as we don't have to actively fight against our own metabolism, instincts, and environment. The worst that could happen is that we gain some weight due to bad nutrition habits, and we can diet to get down a bit – how hard was that?
But other people work differently, and they might not have access to the required food for a healthy diet, or be in the economic position to afford it. Their body might also be unconsciously targeting a higher ideal weight, which means that the same meal that makes me full might leave somebody else still hungry.
And it's not as easy as exercising more, since physical workouts have a smaller impact on our calorie consumption than we'd expect, plus people who weigh more tend to also burn more calories every day in the first place. None of this is their fault or decision.
Therefore, getting back to what we call a "normal" weight range is more akin to what would be, in my experience, starving myself until I'm severely underweight, which is not something I'd be able to willingly do.
The point of representation is not to prevent people from working towards a healthier/better lifestyle, but rather to recognize that different people live different struggles; the first step to work on them is to acknowledge that it's perfectly normal to live with them. Your value as a person is not defined by your weight.
However, when you read DHH post, it reads as if obese people were just stupid folks who could just bike to work and have a slim body. And he comes off as overconfident and quite arrogant in his belief.
And he does this constantly! In another blogpost, he claims that ADHD is just an excuse to be lazy. I'm paraphrasing here, but not too much. Again, he is projecting his own personal experiences onto others. He does not have ADHD; therefore, nobody has. (Don't get me started on this topic or this video will be an hour long.)

Let's focus on free speech, then.
I would like to enter this section with this famous xkcd comic. I'm assuming you've heard about it before, but let's have it here, just for sure.

In 2022, David received the following email from Ruby Central, which was organizing the annual RailsConf.
With you having been mostly offline the last year, the program committee has decided it would be valuable for the community to start sharing the opening keynote stage with other contributors. We have a few in mind but if you have any suggestions of people who have been impactful this year, please share them.
This was David's reaction to the email:
It's a real shame that this is the world we find ourselves in now. One so sharply divided by politics and ideology that we can't even share the love of Ruby on Rails together at a conference without a need to settle scores.
Should companies that support RailsConf by sending employees, speakers, or sponsorship money expect retaliation or exclusion if they end up transgressing against whatever shrinking ideological ring surround the organizers or program committee?
Now, let's blindly assume that David is right in assuming that the organizers are lying about the reason for not asking him to host the 2022 keynote.
Even so, Ruby Centrail is under no obligation to invite people to keynotes who are claimed to be actively rude towards others and racist/nationalists. I don't find that choice to be particularly surprising myself.
Should companies that support RailsConf expect retaliation if they make openly racist/nationalist statements? How could they not expect retaliation?
As a result of this choice (and other factors too), in 2022 he co-founded the Rails Foundation, of which he is the chair. One of the first things the new Foundation did was to organize a competing Rails conference, called Rails World.

The conference was a success, with more than 700 developers attending in its very first year.

This meant that there were two Rails conferences: Rails World, organized by the Rails Foundation, and RailsConf, organized by Ruby Central. DHH chairs the Rails Foundation, but he's also the CTO of Shopify, one of the main sponsors of Ruby Central.
However, the space for Rails conferences isn't that big, and Ruby World eventually won it over. RailsConf, after not inviting David in 2022, had to shut down in 2025.

For its very last RailsConf, Ruby World decided to invite DHH back "for a special fireside chat".

This was received very negatively by the community, with many complaining about Ruby Central now deciding to platform a "white supremacist". (Is DHH a "white supremacist"? You can judge it for yourself, but I think you could easily argue he is).

Even beyond the internet outrage, the choice to platform him angered one other sponsor of Ruby Central, Sidekiq, who decided to withdraw its $250,000/year sponsorship. You don't have to wonder their explicit reason, as its creator was pretty clear.

Ruby Central suddenly found itself in a dire economic situation and without a Rails conference.
According to a reconstruction by Joel Drapper, Shopify (which has DHH on its board) asked Ruby Central to perform a hostile takeover of RubyGems code. Without getting technical, RubyGems were already hosted by Ruby Central, but the code repositories weren't, and Shopify reportedly wanted the organization to have full control over them.

You can read the full write-up to see exactly how it happened, but the gist is that the Ruby Central board voted to take over the project and succeeded. Reportedly, Shopify explicitly asked one of the RubyGems maintainers, André Arko, to be excluded from returning to the project.

Here's what one Ruby Central board member had to say about the vote:
if I had voted the other way, I felt I’d be voting to start the process of shutting down Ruby Central.
After the hostile takeover was publicly announced, DHH stated that he was happy to see it:
Ruby Central is making the right moves to ensure the Ruby supply chain is beyond reproach both technically and organisationally.
This concludes my quick recap of the recent drama in the Rails world. As a result of all of this, it seems that Ruby Central now finds itself in an extremely weak position, with the Rails Foundation taking over its conference and finding itself economically dependent on its sponsors to the point of performing hostile takeovers.
Well, I said everything I had to say. I hope that now you will understand the hostility that many people in this community have towards DHH, his ideas, and his projects.
I originally planned a longer conclusion, though I feel like this article took way too much time already. But, briefly, I think we should be careful when people present themselves as merely having common-sense opinions, and then start slowly drifting towards right-wing conspiracy theories like the Great Replacement.
This, however, does not mean that we should be overly aggressive towards everyone who has "moderate" opinions (whatever that might mean!). As an example, I've done an entire video about Hyprland and its developer, Vaxry. In my very humble opinion, he has made some mistakes in the past but managed to mostly move past them; he still has some ideas that I consider somewhat childish (sorry, Vaxry!), but he's definitely not a fascist, white supremacist, or anything like that.
However, when Frameworks decided to sponsor Omarchy, Ladybird, and Hyprland, all three were considered fascist by some people, and there was even a (troll-ish, I hope) proposal to add a fascism checker systemd plugin.

When I posted about this on Mastodon, I was told that I'm whitewashing Ladybird and Hyprland, doing pedagogy, and more. And yet, I think it's strictly necessary to still be able to distinguish fascism from conservative people.
DHH often feels like the former.
KDE Plasma 6.4 was released this week. However, I did not have the chance to make a video about it until now, leaving everyone wondering: what's new in this update, anyway?
But fear not: today I'll tell you about everything that's new in this update, talking about - in this order: the shell, window management, krunner, widgets, apps, settings and accessibility. There's a lot to cover today!
First of all, Breeze Dark is now… Darker. This is the second time it happens, and it's clear that by Plasma 8.9, Breeze Dark will just be a pure black color. We will get there eventually, and Plasma 6.4 is just another step in that direction (one that looks pretty good).

This update also saw multiple improvements to the behaviour of multiple panels. Firstly, it's now possible to have multiple panels on the same screen edge; on 6.3 they would position themselves weirdly, as if they were trying to avoid each other. Now, thankfully, they are all attached to the screen border.

Secondly, we also decided that horizontal panels will always take precedence over vertical ones. This is entirely arbitrary, but it finally avoids weird bugs where sometimes your setup would draw vertical panels first, and sometimes it would draw horizontal ones.
All in all, this means that you can now use multiple panel setups safely-ish again, after a few versions where the behaviour was somewhat quirky.
Notifications also improved a bit, as you now get a beautiful graph showing file transfer speed over time, similarly to what Windows was doing years ago. It's just really pretty. And, before you complain, yes, the UI here is broken, but that's because I'm using a screenshot of early development; all the spacings were fixed since then.

You can also now update your system by clicking on the "Update!" Discover notification, without the need to open the application: it will just do so in the background.
Another pretty cool feature is that during Do Not Disturb mode (which gets triggered automatically by, as an example, playing a game or watching a video fullscreen), all notifications will be inhibited (as expected), but as soon as you're done, you will get a summary that will tell you how many notifications you've missed during the Do Not Disturb.
There's also a couple of improvements done by myself which I'd like to mention: firstly, popups for centered short panels will appear centered as you'd expect, instead of having a weird offset.

And, the Panel settings representations now all match the position and size of the actual panel!

I implemented a feature that allows you to use floating applets even on non-floating panels. It's honestly a look I really dig, if you're into this kind of things! You can find the new option in the panel settings, under the Floating section.

Finally, I implemented some cute animations that play when you enter panel configuration, to better explain all the four visibility modes. I think they're quite pretty, and I should also say something completely unnecessary to make sure I have enough time to overlay the video in post.
Let's start with tiling. As you should know by now, pressing Meta+T will bring up a "Tiling interface", where you can create screen tiles; then, when moving windows around, you can hold Shift to place a window in the tiles you created. However, up until now, you could only use one layout; now, tiling layouts are bound to their virtual desktop, and you can create a different layout for each desktop. You still preserve, of course, the option to click the top-right button "Load Layout…" to change your current desktop to one of the built-in layouts. It's still not an automatic tiling manager, but it's already getting more powerful release-after-release.
There have also been various improvements on the HDR side of things, where there's an ongoing effort by Xaver and other developers to improve the status quo. This time around, we get a calibration wizard for HDR screen; it sets the peak luminance of the display, and that maximum SDR luminance.

There's also a new Kwin option called "Extended Dynamic Range", which makes SDR displays emulate HDR by changing the backlight's brightness.
There's also lots of work going on in the Portals department. If you're unaware of what Portals are, you're in luck, as I've just made a video about that topic specifically. This is the redesigned Global Shortcut portal, which shows which shortcuts were requested by the application with the proposed key combinations, but also allow you to change them, and highlight any possible conflict. This is a great improvement for handling global shortcuts of sandboxed apps!
The account details request portal was also improved, clearly showing what will be shared with the requesting application:

One big new krunner feature is the ability to understand and show colors! If you paste any kind of color code, it will show you that color and its RGB and CMYK values. This can be pretty handy, my muscle memory in the past was to just google hex values to see which color they were!

And, speaking of new krunner abilities, there's now a list of archaic units such as "furlongs". Which, if you didn't know, is about 200 meters. According to the feature request that prompted this change, "these units of measurement are still somewhat commonly found on older maps or diagrams".

In the most important widget ever - the application launcher - there's now a pretty "New!" green badge that's awarded to recently installed applications. This is similar to the "New!" badge for recently installed widgets that was also recently implemented, and I think it's a nice feature to have.

Another big update is that the Notifications applet will now display the notification buttons even in the history. This is a big deal, as previously the buttons were not displayed there due to technical reasons, making those notifications much harder to interact with.

The Audio applet will now display the name of the media that's currently being played. This allows you to distinguish between multiple instances of the same application; this is particularly useful for web browsers, where you previously had to sort-of guess which input to change the volume of.

Oh, and: when there's multiple input and output devices, the applet will now have section headers, similarly to all the other applets! I love consistency when I see it.

The Disks & Devices applet, which automatically pops up when a drive is inserted, will now check whether there are system errors in the newly inserted drive. If so, it will expose the option to try to magically fix them directly from the applet.

In the Bluetooth applet, you can now enable a badge that shows the number of currently connected devices. This badge is similar to the notification one, since it's a reusable component! This feature is also off-by-default, understandably: I think most users will have just one connected device at a given time, so it wouldn't really make sense.

Then, the Weather Report widget. Previously, just after adding it, the widget was quite useless, not displaying any information; to help you kickstart it, it now changes its title to "Set up Weather Report..." so that you know you have to set it up when you open the system tray.

In the Media Player, there's now an option to change the playback rate; this only works on supported source medias, but this does include, as an example, YouTube through the Plasma Browser Integration!

Within Dolphin, you can finally get rid of the dialog that opened every time you drag-and-dropped something around. I say "finally" because this was a 18-years-old feature request, but I loved this feature: you could just hold shift or control to move or copy the file, or let the dialog to its job. But, if you have a strong preference, then yes, you can just configure a single action to be done by default on the drag and drop.
The System Monitor received a lot of work this time around. Firstly, the Overview page was improved as it now contains more information, such as GPU usage and individual disk capacities.

It's now also a bit easier to use, as all of the background services that you have get now grouped in a "Background Services" item instead of endlessly crowding the list of open applications; of course, you can switch to the Processes tab to still see them.

The System Monitor also now lets you monitor GPU usage on a per-process basis, though this is only supported on Intel and AMD so far.
The History page was also improved, and now has two different kinds of graphs: a total one, and a per-core one, which should make it easier to read.

Another Plasma application that was completely overhauled is "KMenuEdit", which allows you to see all installed application, group them, move them around, and change their metadata. The UI looks much better now, showing a hamburger menu by default and using the consistent tool view component.

Discover was also improved this time around; firstly, it will stop showing wallpaper and plugins results when you search, unless you had specifically selected that category beforehand. This will avoid crowding your app searches with unrelated items.
It also improved visually; as an example, the progress bar for app installation is now displayed in place of the "Install" button, where your move was probably hovering already anyway.

Then, Spectacle: this app now launches in "Rectangle Region overlay" mode out of the box, which is quite similar to what GNOME does. You'll be able to immediately select a region, or just press enter and take a fullscreen screenshot. You'll also be able to annotate your screenshot right away, even cropping it further! It's another nice step forward after the complete redesign that was released a couple of years ago.
Spectacle also added support for pinch-zooming a screenshot after you've taken it. As Nate says, "[this] can be especially useful when annotating [the screenshot] using a touchscreen". And, speaking of touchscreens, another improvement by yours truly is that you now can use the Widget Explorer using one; previously, trying to scroll would start a drag and drop. Now, vertical movements are interpreted as scroll, and horizontal ones and drag and drops.
The Welcome Center was also updated to look prettier; that's the application that pops up after an update to tell you all about it, rendering this video completely unnecessary. Or is it? You tell me in the comments.

We have a new settings page! It's called "Animations" and it allows you to configure the speed of the animations, and which action will perform which animation. Options are: Window open/close, maximize, minimize, full screen, peek at desktop, and virtual desktop switching. You can also enable and disable certain animations, and configure them – all from this page! Previously all of these options were part of the Desktop Effects page, which was overcrowded. Now, there's two much more usable setting pages!

I have also completely redesigned a settings page! I think I talked about this already, but it did land in 6.4, so let me mention it again: the Time Zone settings page now uses a map, visually showing all timezones, instead of just displaying a list! Same goes for the digital clock timezone settings, since it's a reusable component.

The Drawing Tablet page has received some love. It now has a graphical representation of your stylus so it's easier to know what you're configuring, along with the existing pen pressure graph.And the calibration process was also improved, with "reset" buttons, timers with confirmations, and more; so you should never have issues with that step ever again.
Furthermore, there's now support in Wayland for "relative mode" whes using a drawing tablet, which allows you to use the stylus as if it was a mouse, moving the pointer around, instead of jumping directly to its absolute position on the pad.
Another redesigned page in the Info Center's Energy page; the graph is now in a pretty card, it uses the system accent color, it will come with animations with the next release of Plasma, and margins look better all around.

One new accessibility feature which should be interesting for everyone is that there's a new touchpad gesture to zoom in the screen! Instead of pressing Meta+"+", it's now possible to just pinch in using three fingers to zoom in on the cursor. I learned about this by mistake and I fell in love with how intuitive it is.
Another accessibility change is that you're now able to move the pointer around using numberpad buttons, instead of the touchpad only. This worked on X11 already, but was ported to Wayland in this version, with the goal of having feature parity on accessibility.
There's also lots of accessibility work that's flying under the radar. Just to quickly mention a few things: various places (Kicker, Wi-Fi settings pages, and so on) are now entirely keyboard-navigable, screen readers now report scrolling amounts in a better way, and much more; this is also helped by the fact that KDE's testing stack directly uses accessibility features under the hood to work!
As a nice feature, if an application tries to record your microphone audio but you had previously disabled it, a OSD will appear to remind you that, hey, you disabled the microphone, and the app is not hearing anything!

X11 is going to die.
It's not going to die completely—nothing ever does—but it will become a very niche product, used only by a few dedicated fans, whereas all mainstream distributions will switch over to Wayland.
It's also not dead yet; rather, it's in this gradual process of becoming less and less used, with more and more distributions getting rid of it. And truth be told, that's for the best.

I have talked about this more in length previously, but the main reasons are that the developers themselves of X11 — something like 5, 10 years ago — realized that to make a better product, they had to get rid of the structure that they had created significantly, and it didn't make sense to keep X11 around for it. The switch to Wayland made possible some core essential things that X11 just couldn't do, such as a permission systems and better safety.

It should come as no surprise that the number of commits measured over time decreases every year in the X11 project. That was until 2024, when — surprisingly enough — it went up by quite a lot to the levels of 2013. So, 12 years ago.

And it was all thanks to one developer called Enrico, the same developer that, in recent days, has announced a new fork of X11 called XLibre. In order to understand whether it's something that we should keep an eye on or not, we need to first dive into who he is.

Firstly, you might be surprised to hear that it's not the first time that we've heard of the guy. He has already been in the "Linux news" (let's say it like that) when he sent an email to the kernel mailing list claiming that vaccines were bad and they were an experiment of governments that will make all of us humanoid.

His email was so senseless that even Linus Torvalds himself wrote an angry reply saying that - well… - first of all, this kind of "bullshit" doesn't have any place in the Linux kernel mailing list. But even if it did, it still makes no sense at all — because vaccines are, you know, useful.

And I do want to stress the difference between somebody believing that vaccines actually hurt or have more side effects than normal, and somebody who thinks that they're a tool of the government to make us a humanoid. Those are pretty different stances, and I feel like the latter is a symptom of some sort of unease. This is the context that we're starting from.
People with, let's say, "weird opinions" in the past have proven to be great developers. And I think a valid question is: well, all of this work that he has done for the Linux kernel—is that any good? Is he going to be able to bring this fork forward and make it a good, improved product? And to be clear, given that I'm not that good of a developer, I don't have any chance to be able to understand myself whether his commits were any good or not.
However, people who could do so are the developers themselves of the X11 project, who have been maintaining it for the past years—the people with the most commits in the past few years after, well, obviously Enrico, who stepped in and took the leadership immediately.
Well, the first red flag is that we have a couple of bug reports of very significant regressions that were caused by his code.

And we're not talking about some little regression, but—as an example—he completely broke xrandr, which stopped working entirely in an attempt of his to fix a single bug. And this prompted multiple developers to start asking him, "Are you even testing your own changes before pushing them? Because your fix to xrandr completely broke xrandr".

And even though he justified his mistakes, saying that he had gotten some technical things of the testing wrong, nonetheless this got the other developers annoyed enough that multiple times they considered just stopping accepting merge requests from Enrico.
Even worse, the other developers seemed to think that apparently his changes were not really fixing anything and only introducing possibly new bugs without fixing any. The discussion escalated multiple times, with at least three or four developers angry, saying that he was a net negative on the community and that they should stop accepting merges from him.

On top of that, his tone in his commits whenever a discussion arose was always quite aggressive and implying that there was some sort of conspiracy by big corporations to prevent any X11 release and to keep the project stagnant and eventually kill it. Behavior that didn't stop even when one of the other lead developers said that they were planning to make a release of X11 eventually.

He started pushing so many merge requests that apparently other developers didn’t have time to review — or maybe, given the previous regressions, they didn’t want to accept. He reached a point where he had something like 100, even 150, open merge requests, and he was annoyed enough that he created a new issue listing all of these 150 or more merge requests and asking for reviews more intensely.

And this is where the disconnect with the other developers became clear enough, as he said that these merge requests were absolutely necessary in order to get X11 back to being commonly used software instead of, you know, letting it be killed.
As an example, another developer said that if you think that X11 can come back from the dead, then you're delusional. Though it’s some strong wording, and I do not totally appreciate this kind of tone, he is right: X11 is not coming back. And honestly, it's to soon to say that we should just trust the fact that he is able to be a prolific developer for X11, that he's going to be able to bring the project forward simply because he has made a very large number of commits and a very large number of merge requests, even though a lot of these commits and merge requests are very small ones and mostly moving things around, and at the same time another developer told us that they bring little benefit.

We need to have some more information and maybe wait for the next release of this fork. But let's not get ahead of ourselves here. Let's actually start talking about the fork.
Last week, he decided to fork the X Server project and make XLibre, and he did so in the FreeDesktop GitLab where the X.Org project is also hosted.
And he had a bit of a README to explain the project to the other people, and in doing so, he explained that there were other toxic members in the group, he said, that were preventing the project from moving forward. And he started saying that there's corporate interest that want to kill off the project. And he started heavily criticizing—indirectly but in a pretty clear way—the companies that are currently supporting FreeDesktop development.

He went on to implicitly criticize the companies that support X11, saying that XLibre is "not affiliated with BigTech or any of their subsidiaries or tax evasion tools, nor any political activists groups, state actors, etc". And then on top of that, he started injecting his own politics into it. We already had a hint of it when he said that vaccines make us subhuman. But he also said that this XLibre project was going to get rid of DEI—Diversity, Equity, Inclusion—and that it was a place that is free for everybody who wants to contribute.

Which is an interesting claim, because of course any project wants to be open and inclusive for anybody who wants to contribute. But then, when you start taking into account the fact that people are people and are going to behave in certain ways, you realize that you start to have some kind of limit to what people can do, such as: they cannot harass other people, they cannot insult other people. And then you need to take their sensibilities into account: what does "harassing" mean, exactly? And if somebody is actively transphobic, then (hopefully!) we can decide that, yeah, that's also the type of behavior that’s going to hurt people. And we do not want that to happen to our contributors, especially because a lot of the software that we all use— even transphobic people — is written by trans people. So let’s maybe not let people harass them.
And of course, he also decided to end the README saying "Make X Great Again," mimicking Trump’s slogan; which is not the worst thing that could happen, but you can’t say "let’s keep politics out of this" and then mimic Trump’s slogan (come on!). And, obviously, even saying that you want to get rid of DEI is a political statement. There were quite some politics on this fork!

Understandably enough, when the FreeDesktop project — and especially the Code of Conduct committee — realized that there existed a fork within the FreeDesktop GitLab repository that implicitly criticized the FreeDesktop project and even went against its very values of being inclusive to people, and mimicked Trump’s slogan — they decided against it. They deleted the fork and banned Enrico, who did not let that be an obstacle to the XLibre project’s success.

Of course, he started claiming to be censored by freedesktop. He did so in an email that is incredibly deaf to the actual reason he might have been banned. I have to read some quotes here:
So much for freedesktop.org being "indipendent" and embracing freedom. Perhaps we should nominate them for the next Orwell award.
It's now clear that freedesktop.org is the Redskirts, and they want to kill X. By the way, the same corporation that tried to proprietarize a lot of FOSS code, including the Linux kernel.

And again, I feel like it’s pretty important to say here that when you own a project, a GitHub instance, and you decide that somebody’s values do not align with yours and you decide not to host their project on your server, you're not censoring them. You’re just saying, “Well, I’m not going to give you my free resources for your project that actively goes against my values.” And it’s not like censorship: you can use other instances. And that’s what Enrico is doing — he just moved to GitHub.
I don’t exactly think that being banned from the FreeDesktop repo is going to be a great damage to the XLibre project, which is flourishing anyway — as much as such a project can flourish. All in all, I think that this XLibre fork still has to prove that it can survive with the help of this just one developer with very strong political ideas and that has technical knowledge of the codebase that’s maybe a bit debatable. Of course, he says that he’s very good at it and he's going to bring a lot of improvements; but, at the same time, other X11 developers say that he hasn't brought new features so far.
So I think we’re just going to have to wait and see whether this project is able to reach the goal that it gave itself. Let's talk about Brodie, now.
Brodie made a point that banning this person from the FreeDesktop repository was a mistake because in this way they gave him much more force compared to just if they shut up about it—which is a reasonable point. However, at the same time, I don’t feel like the FreeDesktop repository can just completely ignore what’s going on on their very own server which goes against their very own values just because they’re scared to give them even more visibility by banning them.

If it goes against their values then it would be newsworthy even if they decided to keep them on their own repository. Imagine the titles: “FreeDesktop decides to host a fork that goes against FreeDesktop’s values, that is against DEI, and that has a Trump slogan.” They just cannot allow that to happen.
One more thing: all of this was mostly reported by one right-wing QAnon anti-vax anti-climate-change tech journalist. (I feel bad for using this term, but let’s call him a journalist). I still feel like we could have just ignored this whole thing if it wasn’t just for him.
Of course, he just went on to create more made-up news, claiming that as a reaction to this fork, a lot of major distributions such as Ubuntu, Fedora, decided to just get rid of X11 immediately.

Because yes, it is true that Fedora and Ubuntu have just announced that they are discontinuing their X11 distributions, but this was actually planned for months before this. It’s not a reaction to XLibre, because to put it bluntly: we don’t give a fuck about XLibre. That’s really not on our minds when we decide to, you know, roll out—make—this kind of change, very important changes to a distribution. Again, there’s public record of both distributions planning to do this. So it’s not exactly news. It just happened very shortly after this unrelated news.
So yeah, I’m skeptical about all of this. But I also realize that maybe actually he has shitty political views, but he is also a great developer, and this actually birth thing is going to be great and distributions are going to switch to it. I don’t think that’s going to happen. I don’t think barely anybody is going to switch to it. But maybe I’m wrong. We’ll see.
Last week, I started receiving private messages from users warning me that my Mastodon instance, Fosstodon, had a fascist moderator. Thus, they were deciding to de-federate it and suggested I move elsewhere. I decided to wait a few days to see how this would play out.
It turns out that Fosstodon will probably close down. Both of the main owners of the instance have communicated that they are fed up with managing it and are stepping down. The crowd that was loudly asking to "cancel" Fosstodon has won, but were they right?
The story is about one Fosstodon moderator called Carrotcypher. Though there are no complaints against his behavior on the Mastodon instance itself, he has expressed personal opinions on other social networks, such as Reddit, which raised concerns. Let's check whether there indeed is reason to be worried here.

Let's start from the law that unclosets transgender children. This discussion happened two years ago: a school policy that required the students' consent to disclose their gender identity to their parents was struck down by a federal judge. According to him, the law "harms the child who needs parental guidance [...] to determine if [gender dysphoria] is organic or whether it is the result of bullying, peer pressure, or a fleeting impulse". (I strongly disagree with this decision, but this video isn't about what I think.)

Someone in the Reddit comments asked: Regardless of whether it was a good policy, shouldn't privacy be protected by default? To which, Carrotcypher replied: as long as the DOJ prosecutes parents for the action of their children [...], psychologist believe children shouldn't be allowed to consent to drugs, sex, alcohol, etc. [...], 10% of students will experience sexual misconduct by a teacher, [then] you'll have a hard time arguing that they deserve absolute privacy from their parents.

Though, he quickly agreed that - unless there's an immediate danger - then what he was saying probably does not apply for preliminary injunctions.

There's further discussion, which I found to be quite respectful. In short, he does not believe that children have the right to a complete privacy under the current legal framework, and thus he thinks that the judge decision was justified (though he does not say it was morally correct, and mentions that "can argue to change it", which is what "honest debate is for").

Moving forward to two months ago, an article was published titled "Mahmoud Khalil is the first activist to be disappeared by Trump". One comment points out: "Disappeared? It's called Deported". To which, Carrotcypher replies with "But that doesn't fit the yellow journalism agenda so...". (If you don't know, and I didn't, yellow journalism is the usage of eye-catching headlines and sensationalized exaggerations).

Carrotcypher also seems to be a moderator for the subreddit r/privacy, along with 50 other subreddits. Whilst being a moderator, he was accused of removing an article titled "DHS removes protection of LGBTQIA+ community for targeted surveillance" multiple times, claiming first that the article had paywall, and - later - that it was "too specific to a company or single product".

In a deleted comment, the poster claims that he had been banned for "conspiracy spreading", though of course we cannot confirm.

For reference, the article was about the Department of Homeland Security removing policies that prohibited personnel from conducting intelligence activities based solely on a person's gender identity or sexual orientation. Multiple articles about the DHS have already been published in the same subreddit, but only this one seems to have been removed.

Furthermore, he has replied to "You're in a cult" to a post in the politics subreddit which asked people to vote Democrat even if they dislike both candidates, not to repeat what happened in 2000 and 2016. He made a similar comment in two other threads, with a similar contexts.

He also claimed that "the snowflake nonsense that gets reported [on Mastodon] as 'harm' these days is laughable".

Overall, I think it's clear that Carrotcypher often adopts right-wing points of view and arguments, to the point where it's probably safe to say that he indeed is a right-wing person.
I consider some of the above examples as strongly worrying: the removal of articles without clear explanations, the snowflake argument, and calling certain Democrat supporters as "part of a cult".
I also think that we should be careful with ostracizing some of his other comments. I'd be careful with equating a criticism of sensationalist journalism to supporting the deportation of activists, or claiming that he is blanketly against the earlier-mentioned school policy.
Many people are calling him an extremist or a far-right member. I'm not sure I agree yet: I do not feel like any of the opinions expressed above are extreme, only right-wing (and, in my opinion, wrong). Others have been calling him a Nazi and a Fascist: I'm extremely uncomfortable with using these terms, and I'd prefer to use them for people more fitting for the definition rather than the regular "leftists are snowflakes" and "children don't have a right to privacy" rigthwingers.
Nonetheless, my overall evaluation is that this individual is not someone I'd like to moderate my instance. I say this because I'm worried about his previous moderation mistakes (again, the removal of posts without explanations, in a way that seemed politically motivated) and his explicit downplay of "what snowflake nonsense gets reported these days".
I'm not the only one who arrived at this conclusion. A user named "lo" wrote, "Carrotcypher seems like a uniquely inappropriate person to represent your community, let alone moderate it. [...] Is this appropriate behavior for your moderator, and if it is not, is the moderator trustworthy enough to continue deciding what gets approved or removed from your instance?".

Mike, one of the two owners of Fosstodon, replied with:
You're asking for the removal of one of our moderation staff based on that moderators interaction with you and others on Reddit. Your description of that behavior seems more than a little hyperbolic, and unfortunately there doesn't seem to be much "meeting half way" in your demand to us. Every action taken by our moderation staff is auditable, and they can be all be reversed with the exception of post deletions. He's done that 23 times during his time as a member of our moderation staff, 22 of those removals being for non-Fosstodon accounts. [..]

To be quite frank, his opinions on CNN and Foxnews aren't particularly relevant. We have a code of conduct, and his job as a moderator is to determine if a post follows that code of conduct. It's obvious you can agree with the spirit of a post and still know it violates the instance rules. I've seen no indications that Carrotcypher is doing anything other than what we've asked him to do. We're happy with the effort that Carrotcypher has put in as a moderator at Fosstodon.

Which raises an interesting question: if someone has shown a lack of skills in moderating online communities elsewhere, but has so far done a great job at moderating yours, should you nonetheless take action and remove the moderation? Though I probably would, I'll say that I can also understand Mike's position here.
I think he's wrong still, but hey, we're all humans. All of this was four days ago.
Since then, Carrotcypher has both deleted his Reddit account (and, as such, all of his comments now appear to be from a deleted account) and Fosstodon account, making him de facto no longer a Fosstodon moderator.
Now, I sadly do have to point out that we also might have an email from Carrotcypher, though the only source for it is Lunduke, who reached out to Mike - one of the co-founders - to ask for contacts, and - according to him - contacted Carrotcypher.
Assuming that Lunduke decided to publish this email unaltered, then we get statements like:
There is some thick irony of being called a fascist because you believe in following laws while those calling you fascist stalk, harass, bully, lie, spread misinformation, and seek to silence and destroy you simply for not agreeing with their politics.

I.e., the usual unconvincing right-wing talking points. We also learn that
I don't apologize btw, I've done nothing wrong. [...] These events make me think it's a cesspool of ignorance and someplace that I shouldn't be donating my time to (No offense Fosstodon, I'm talking about all the fediverse.)

The rest of the e-mail has the same tone, and I believe you won't gain anything by reading it further.
These days, Fosstodon was also de-federated by multiple other instances, though I don't have numbers on that (nor do I know how I'd get any).

During the last two days, both founders of Fosstodon have published blog posts about what happened; we also got one from Corey, who was a Fosstodon user. This latter blog post is linked by one of the cofounders as a more reasonable take, so I'll start from that one.
Corey says:
As a supporter, I have access to a group chat with other supporters and the admin team. I asked about the rumors and reports, and received a nice thoughtful reply from the mod in question. He shared that he has a long history as a privacy advocate and FOSS and contributor, and he feels he's being unfairly characterized as a nazi for expressing certain political views. He also had very reassuring things to say about the neutrality and fairness of the fosstodon moderation process, essentially that all moderation decisions require concensus among mods and that all mods recuse themselves from any decisions where they have a vested interest. Basically, his politics have never been a factor in any of the moderation decisions there, nor could they be. Importantly, he also shared that he has stepped down as a mod and would also be deleting his account.

Overall I'm satisfied with the moderation process and neutrality on Fosstodon. When I asked about current events I received very satisfactory answers. They could probably do a better job with public communication, but I think it's important to remember that most fedi admins are volunteers and most mastodon infrastructure runs on a shoestring budget.

I want to point out here that the only public statement that we received by "the moderator in question" is the email that I read to you a few seconds ago, which is anything but "nice" and "thoughtful". Whatever convinced Corey of the goodwill of Carrotcypher, we do not have access to it.
Nonetheless, Corey says he's going to leave Fosstodon:
What to do? As a Fosstodon user, it's hard to see any future path with the instance that works in my favor. The court of public opinion has already condemned the name "Fosstodon". The picture is complete and the paint is dry for many, many people. Most will never know anything about the name other than "the instance which allowed a nazi mod". While I believe the characterization is 100% untrue and unfair, the die is cast for lots of people.

Given the tradeoffs, I have decided to leave Fosstodon and move my account and financial support to hachyderm.io. I don't feel great about this decision, and I am particularly sad to leave what I consider to be a well-run instance with good people, because of public perception.

Though I have not found this article to be particularly convincing on why we should trust Fosstodon ("I was told privately" is as good as "This was revealed to me in a dream"), this is an interesting point to stop and ask ourselves what we are trying to achieve.
If the point was to remove the moderator who we did not feel like was up to the job, we have now achieved that. Sure, there was some pushback from the founders, but he has decided to resign and delete his account by himself. Should we stop and federate back to Fosstodon, now?
If instead we demand that the Fosstodon founders publicly state that they will change the selection process for moderators and will act on such incidents more effectively in the future, I believe it's now clear that this won't happen. Is this enough to try to burn Fosstodon down to the ground? I use this figure of speech not lightly, since the public has achieved for both founders to step down now.
Let's move to their blog posts:
Here's two paragraphs from Kev:
I'm done with the drama, the constant name calling and abuse, the stress, the late nights, the whole thing. The fact of the matter is, by moving away from Fosstodon I'll have more free time, far less stress, and more money in the bank. No brainer, really.

The last point I'll make is this - the fedi is supposed to be a friendly, welcoming online space, right? But the fact is, it isn't. It's just like everywhere else online - the vocal minority are just as loud, and just as obnoxious as everywhere else.

And here's Mike instead; this is a quite lengthy excerpt, but I believe it's worthy to read it entirely:
We were hoping that by cutting off new registrations for the most part and people leaving through attrition for whatever reason they chose, Fosstodon would shrink back down to a level that was more manageable. Maybe that was naive. No, that was definitely naive, and it didn’t happen. The growth slowed, but it didn’t stop. More people still came in than were leaving. We could have cut off the invites I suppose. We didn’t. Another mistake. Another step in the process. That brings us to today. I’m sitting here and looking at the fourteen reports that haven’t been resolved. I’m looking at the 100+ messages sitting in my notifications. This is work. This is not something I love. The part of this that I loved leeched out a long time ago. I wake up in the morning, and I dread signing in to Fosstodon. To make matters worse, this is the worst kind of work. It’s not something I’m being compensated for in any way. I spend hours of time away from my friends and family. I spend my own money to keep things going. I burn my own mental health. For what?

I understand that Kev is at his limit. I am too. I’m done. Enough is enough. I do want to say that it hasn’t been all bad. Occasionally, someone will do something or say something that puts a smile on my face. Unfortunately, those times are like drops of water in the dessert. There will be far more people lining up to tell me I wrote “dessert” instead of “desert” than will have gotten the point I was trying to make.

Again, I want to reiterate that I believe that Kev and Mike did not handle this correctly and were wrong in defending Carrotcypher. It wasn't a disastrous and terrible mistake, but it was a mistake nonetheless.
That said, I believe that this uncovers a much, much deeper problem that's intrinsic to Mastodon. Though I love the concept of a federated social network, this type of structure has consequences.
Firstly, we have put an unreasonable amount of responsibility and work on too few shoulders; even worse, we have not compensated those people. Sure, they could've stepped down, but when you have a public and growing instance, it's not easy to shut it down or close it entirely to new accounts. As a result, these people (whom we collectively decided to render core maintainers of one of the largest Mastodon instances) were underpaid, overworked, and burned out.
But - even worse - they were human, they were not necessarily experts in political dynamics and how to handle them, and thus when people started asking to remove a moderator that had done nothing but help them so far, their first reaction was: ehm, no? Which quickly brought them an exaggerated amount of criticism.
Again, this is not to say they haven't done anything wrong, or that they hadn't agreed to take this much responsibility (by continuing to handle the instance). Nonetheless, I believe that we should be particularly careful in how we structure the federated open internet, as handling it is a difficult task that should be split between multiple, well-paid, skilled actors.
A few weeks ago, a proposal was made for the Servo project to allow for AI contributions, which are currently prohibited. The proposal comes with strict guidelines: only allow for code completion like Copilot, tag all AI contributions as so, and more.

After a few weeks of intense discussion, the Servo Technical Steering Committee decided not to go forward with the proposal and keep their AI policy as it is now.

Namely, this policy states that all contributions "must not include content generated by LLM or other probabilistic tools, including but not limited to Copilot or ChatGPT". This cover both code and documentation.

You might be wondering why they have decided to take this path. It comes down to four reasons.
Firstly, AI makes it easy to generate lengthy but incorrect diffs, which the contributor might not check or test. It becomes then the maintainers' responsibility to go through them and realize they are incorrect.

Secondly, code generated by AI has no guarantee of being correct, and it might have security issues. Again, contributors using AI tools might not be able (or want) to catch those manually.

Thirdly, copyright. We know that these large models are trained on copyrighted content, and Servo claims that their output often includes that content verbatim, which would expose Servo to potential legal headaches.

Finally, there are ethical issues. According to Servo, AI models require an "unreasonable amount of energy and water to build and operate, their models are built with heavily exploited workers in unacceptable working conditions, and they are being used to undermine labor and justify layoffs". The project does not want to perpetuate that, even indirectly.

What's interesting is that Servo is not the only project that takes this stance, but an increasing amount of repositories are now off-limits for AI generated code.
As an example, Loupe, GNOME's image viewer application, also recently added a section about Generative AI on their contribution guidelines.

This policy states, and I quote,
This project does not allow contributions generated by large language models and chatbots. [..] We are taking these steps as precaution due to the potential negative influence of AI generated content on quality, as well as likely copyright violations. This ban of AI generated content applies to all parts of the projects, including, but not limited to, code, documentation, issues, and artworks.

A month later, this guideline was added by Alice to: GNOME's app Elastic, libadwaita, libmanette, libhighscore, and the Highscore application. I wouldn't be surprised to see this list grow over time.

Three weeks ago, ElementaryOS also added the same policy, directly taken from Loupe's. AI code is a no-go there, too.

Other older examples of this are NetBSD, which explicitly states that code generated by LLMs "is presumed to be tainted code and must not be committed without prior written approval by core."

Finally, there's Gentoo: "It is expressly forbidden to contribute to Gentoo any content that has been created with the assistance of Natural Language Processing artificial intelligence tools".

Let's discuss this decision on its merits. I want to firstly point out the obvious, and address the very first question that was raised on each of these discussions: how will they know what code is AI-generated?
The answer is that there's no way to know for certain: all of these guidelines above are entirely unenforceable. A few people claimed that they "can tell" whether a large contribution is made by AI, and I do believe that we can mark some contributions as most likely written with those tools, but I also believe that we cannot ban people on "most likely" considerations or personal intuitions. Either the author admits to AI usage, or this request is entirely based on trust between the contributor and the project.
Though, as Sophie points out, the same applies to people owning the code they are submitting: there's no way for a certain project to check whether the submitted code isn't just stolen by the contributor from elsewhere.

Personally, I'm not completely sold on this equivalence. When I submit code to an open-source project, I'm taking (legal!) responsibility for it, and if it's stolen, I'll get in trouble; it does not, however, limit how I can write that code. Instead, the AI section is trying to limit the kind of tools I can use to write my code, such as whether I can use autocompletion, and this is a much stronger request.
I'm not even convinced that a project has the right to make this request to the contributor. To make an example, if there were a text editor that was sponsored by fascists and whose owner said some disgraceful things, would the project be justified in prohibiting contributors from using that text editor to write the code? I believe not, as it should instead be a choice of the contributors themself (though, they can ask).
As another user points out in the Loupe discussion, the kind of person who will contribute large patches entirely generated by AI is most likely also the kind of inexperienced contributor that's willing to ignore Contributor guidelines. And, if they do ignore the guideline, there won't be any way to punish them, as there's no way to know for sure that the code is AI-generated (and you certainly don't want to ban people by mistake).

From the same thread, Emmanuele Bassi adds that "the only people that end up using LLMs are people that are not learning to code but want to submit something anyway".

I also take issue with this claim. Though I won't deny that there are plenty of people who do use AI tools to avoid learning a certain language, I also see plenty of already-skilled people use it to speed up their workflow, myself included.
As an example, I've used Python throughout my whole life, and I have given multiple talks at PyCon about the language and some of its more obscure aspects. I'm not a great Python developer, but I can quickly get things done using it. That said, I often use AI to generate parts of some Python scripts, because it's easier and it gets it right most of the time; it's significantly faster for me to check that something is written correctly than to write it myself from scratch, and I can always make my changes to the code where I think it's needed.
Of course, since I do know Python, I make sure that the generated code makes sense and works properly. All code that I submit to any project is code that I would've written like that, and I take full responsibility for it. I won't deny the existence of people who just copy-paste code from ChatGPT without having a clue what it means, of course.
But what about all the other claims? Legal issues, the impact on climate change, and more?
Legally speaking, unless there are other contributor agreements in place (or employment situation), all contributors preserve the ownership of their contributions to open source projects. If it turns out that a certain piece of code was stolen by the contributor, they will be the ones who will get in trouble for it. To the best of my knowledge (I'm not a lawyer!), the same would happen if the code submitted by the contributor turned out to be taken as-is from another project. This means that the decision of whether to take this legal risk or not falls on the shoulders of the contributors, and not of the project, which would be unaffected.

I believe that the same applies to the ethical and climate issues of AI tools; though it's important to raise awareness of their problems, I believe it's ultimately the contributors' choice on whether to use these tools despite that. Again, I decide to use AI tools because I'm currently convinced that the claims about climate impact are overblown, and I believe that using copyrighted material for training is fair use, though I do take issue with the usage of underpaid third-world workers for alignment (and, of course, I'm willing to change my mind if presented with more evidence). I think that this should be ultimately my choice (or, at worst, my employer's choice) instead of the project I'm contributing to.
Really, since I believe they don't have legal responsibilities of it, I believe the only impact that the project has to deal with is the additional maintainer's burden of reviewing completely bogus AI merge requests, which do exist. However, I also believe that this policy will be entirely ineffective at stopping this, for the reasons explained above.

Going further, I'm a bit shocked by some of the replies that the Servo proposal of allowing for just AI autocompletion in code received.
As an example, user "multiplealiases" wrote that "A good chunk of people [...] are going to see this and consider servo tainted. Merely entertaining AI these days is a statement, and that statement is "we don't care about quality, we don't care about contributors, all hail the slop machine".

If you think about it, this statement is pretty shocking: almost all of the open source projects currently have no guidelines for AI, only a few ones do. By this logic, the entire open source world, with only a handful of exceptions, is tainted.
The same applies to developer mcclure, who would've stopped donating and contributing to the project if the proposal had been approved, as they "will not contribute code on a project where you don't know if code you are interacting with [..] was written by a human or randomly generated".

Again, this means not donating nor contributing to the entirety of open-source, with only a few exceptions. It seems to me like these comments completely fail to take in account the broader context of the open-source world, where AI contributions are currently accepted almost everywhere.
This is to be found throughout the thread. Even though the proposed AI policy would still be significantly more strict than almost every other open-source project, since it only allows for code completion and requires tagging of AI-generated code, people would be considering Servo as actively "embracing AI".

There's even someone who says that they will never use Servo because it contains AI-generated code; which, again, forgets how the vast majority of open-source projects, even open-source ones, contain AI-generated code by now.

Of course, the overwhelmingly negative feedback on the proposal eventually prompted the Technical Steering Committee to change their minds and not go forward with it.

Though I can understand hostility towards AI tools, and I'm frustrated myself by the over-promises and the hype bubble, I nonetheless think there's a lot of irrationality when discussing it. A good example, in my opinion, is the video by The Linux Experiment where he says he'd ditch Firefox. Though the fundamental issue was a lack of understanding of the actual policy changes, he started saying that he did not trust Mozilla anymore, as he believed they'd start selling data to AI companies, though there was no evidence of that whatsoever. It was completely irrational.
I also believe it is a bit irrational to try to force contributors to avoid specific tools when there's no way to enforce that or ever ban a bad actor who would lie about using them, and I think it would be more useful to continue to advocate against AI through other means.
A few months ago, I discovered a project called "EU OS." It seemed interesting, so I added it to the list of article ideas and quickly forgot about it. A month later, it somehow reached every news and YouTube homepage. And yet, I believe most of them completely missed the point; let's discuss that.
EU OS is a proof-of-concept operating system based on Fedora and built by developer Robert Riemann, head of the Digital Transformation sector in the Technology & Privacy Unit at the European Data Protection Supervisor.

To be clear, EU OS is the free-time project of Robert, and it's not embraced by EU institutions in any way; currently, it's a one-man project, though it's quite a skilled "one-man".

The end goal is to transition the public European infrastructure towards an open-source, Linux operating system. This brings some extra deployment requirements which EU OS has to address, such as the ability to provide an easy way to adapt to different regions and sectors, and ease of management for system administrators on a large scale.

As such, EU OS is described as "not meant for home users, but for system administrators who want to deploy automatically Linux to many corporate computers/laptops". EU OS wants to "propose a common Linux OS based on bootable container technology [...] and a common method to manage users and their data".

Let's immediately place EU OS within a larger context. The broader initiative is "Public money, public code", which aims to make all software created through taxpayers' money as released as Free Software (and, more generally, to push for the usage of open-source within public institutions).

There have been a few local successes of this initiative. The most notable example was the city of Munich, which had migrated more than 80% of all of its desktops to a Linux derivative called LiMux. However, the move has been reverted, and the city has returned to using Microsoft Windows. Nonetheless, LiMux has been the first Linux desktop certified for industry use by the German Technical Inspection Association, and had managed to save more than 10 million euros.

On an international level, we have three examples: Astra Linux, widely deployed in the Russian Federation, Kylin and Neokylin, with a 90% market share in the Chinese government sector, and Nova Linux, used within the Cuban public sector. You might notice some connection between these, though we will get back to it later on.

Nonetheless, Robert points out that these examples leave "no doubt on the feasibility of large-scale Linux deployments in the public sector. It is only a matter of political support, priority, and funding".
So, why isn't there political support for this? Especially considering the clear benefits that this migration would bring; we're talking about tax savings, since you wouldn't have to pay for licences of commercial products. You'd also avoid software suppliers and vendor lock-in: with Windows, you're entirely in Microsoft's hands regarding support of a certain operating system, and - even worse - the type of hardware you need to run the supported versions of Windows. And, of course, open standards foster innovation, they take fewer IT administrator resources, and benefit from the worldwide free software community.

Is all of this what brought China and Russia to ditch Windows in favor of Linux? If I had to bet, there's some other reason that is better explained through our favorite topic ever, politics.
Obviously, China/Russia and the US are not what I'd call friendly allies. Thus, these countries probably started internal efforts to make their governmental sections independent from closed-source US-based software, such as Windows. By pivoting to Linux, they're able to check for backdoors in the operating system and develop their own flavor, which they control entirely.
On the other hand, the EU has been considered an ally to the US for years now; however, thanks to the latest US administration, this statement is beginning to be a bit more doubtful. Thus, the timing of this EU OS initiative is most likely not as random. Indeed, I also agree that the current political climate makes the usage of locked-down proprietary software from the US somewhat risky, and it might be time to consider sovereign options.
However, a lot of discussion has been raised on exactly what we should mean by "sovereign options". Many, such as Brodie Robertson, have criticised EU OS for their usage of Fedora, which is an international project but has ties with the US company RedHat.

The Register even decides to call Fedora an "American distro", which – is not something I would say, like, ever. Again, Fedora is not developed by or in any specific country, and the team is international; it is however true that many core (code, legal, …) contributors are also RedHat employees.

However, applying this sort of thinking gets complex quickly. As an example, Brodie also mentions that EU OS uses the KDE Plasma desktop, and he says he's fine with that since the KDE e.V. is based in Germany (and, thus, it's "fair to say that KDE is German").

First of all: no, it's not fair to say that. KDE is an international project that's not developed by or in any specific country. The KDE e.V. non-profit is, yes, German, but it's a different entity compared to KDE and products such as Plasma are not products made by the KDE e.V.. This might seem stupid to say, but it's relevant both legally (as in, KDE products are not legally developed in Germany), and practically (as in, the most common country of origin of KDE developers is not Germany).

And, if you want to go further, I want to point out that many core KDE contributors, such as myself, are employed by Tech Paladin, which is a US country yet again. Even worse, the primary owner of Tech Paladin, Nate Graham, is also on the board of the KDE e.V.. Thus, by the same logic as Fedora, KDE also has direct and strong ties with an American company. Brodie should be well aware of this, since he has just interviewed Nate – I haven't watched the video yet, I'm really sorry, I promise I will.

And we could go on: sure, Linux is an international project, but it has direct ties and gets funding from the Linux Foundation, which is US-based. Mozilla Firefox is developed by a for-profit American company. Even OS components like PipeWire have direct ties to, again, RedHat. Thus, if our criteria for sovereign software is "has direct ties with US companies" then let's just give up, there's nothing we can do.
However, I believe that to be flawed logic. Let's instead talk more practically: the issues with using American software is security (as in, they might contain government backdoors) and independence (as in, future decisions by American companies might have a direct negative impact on EU institutions using their software). These are the main risks we want to mitigate.
Evidently, by using FOSS software, we're safe on the security part of this. Since development happens publicly, the US government cannot go to, e.g. RedHad and kindly ask them to add a backdoor in – they wouldn't be able to, or it would at least be orders of magnitude harder compared to Windows, since you'd have to do it publicly (thus, fooling the entire world).
Let's talk indpendence. FOSS software also provides a good layer of protection here: if RedHat decides to try to kill Fedora tomorrow, they wouldn't be able to; the project would get forked and the existing community would continue development, though certainly at a slower pace. If necessary, the EU could also create its forks of the software it relies on, and fund their development. This means that open-source here provides an exit strategy in case something goes wrong, which is all we need.
I think that the strength of my arguments here is proven by the fact that both AstraLinux and Kylin are entirely based on Linux distributions and FOSS software that's developed around the world, US included. They have strong reasons to want independence, and yet they're fine with using FOSS software even when it has ties to other countries.
Robert also agrees with me, because he's smart. He says,
EU OS shall not confound sovereignty and protectionism. There is no problem per se in relying on international FOSS components and often times it is in practice unavoidable.

However, EU OS promotes to maintain strict control on business data and telemetry data. This includes the free choice where to store such data (on-premise or cloud of choice). Furthermore, the availability of know-how for a given FOSS component within the EU shall be considered.

Also, I feel like we're getting sidetracked on this sovereignty part of the discussion, whereas the point of EU OS was to be a proof-of-concept that you can deploy Linux desktops at a large scale within the EU, which is a different goal entirely.
That said, do allow me to briefly make fun of a couple of news articles about this.
I've already criticized The Register's "American distro", but I believe that the Linux Journal also seriously missed the point by publishing "EU OS: A Bold Step Toward Digital Soverignty for Europe".

A… bold step? Are we really calling an unofficial one-man project… a bold step towards digital sovereignty? It would be a bold step if the EU embraced this, but they did not so far.
The article by It's FOSS is good, but I love the very first comment: There won't be privacy and such if an American is corporate behind it, in America you are forced to let the government have access to your software security or you go under. Which not only is just straight-up false, but also misses the point entirely that RedHat doesn't own Fedora nor can they hide backdoors in it.

Let's move on, though.
The EU OS project has gained the attention of OpenSUSE too; they recently released an article offering some criticism of the project.

They say,
The current Fedora+KDE direction is mature, but relying on one distro and one desktop environment introduces avoidable risks. Instead, it would be wise for all governmnets to embrace alternatives like Aeon with GNOME, alongside another immutable Plasma-based choice of Kalpa. Why? Security. Different distributions and desktops reduce the risk of a single point of failure. If vulnerabilities emerge, they won’t simultaneously impact every system.

This is an understandable position: by only offering one distribution and one desktop, you are more exposed to events related to those projects specifically.
However, I believe that EU OS mostly picked Fedora and KDE as placeholders, as the real proof-of-concept is about the deployment of the systems.

I do want to bring forward one criticism of my own, though, and I accept that I might be incorrect. Are we sure that we're not just talking about a name, here?
If we go check the project itself, the only repository is almost devoid of any code. Almost all of the folders that I'm currently showing on screen are empty.

If we go ahead and see future planned tasks, we have things like: document use cases for EU OS, document requirements for EU OS, document the goals and the scope of the proof-of-concept, list required applications, publish manifest to call for EU OS support by governments, add EU OS branding, and more.

All of this is necessary work, but it makes me think that this project is well within the concept phase where it's not even sure what it wants to be, or how. There's nothing concrete about this.
And, again, this is a one-man project, and none of this is backed by any EU institution. I might be wrong, but to the best of my knowledge, right now EU OS is an idea of one person, and I do not understand why are we talking about it.
Or, I think I do: it's not about the project itself. Rather, EU OS is an excuse to discuss an abstract concept that does not yet exist, but that applies to the current times: the idea of an EU independent operating system. I think this is why everyone seems interested in the sovereignty part of EU OS (even though the large scale public sector distribution is the key part): right now, we want to discuss EU sovereignty, we need to discuss EU sovereignty; and, to do so, we've taken what would've otherwise been a negligible topic, and all started talking about it.
Robert, by the way, feel free to reach out to tell me that I'm wrong about this, and that EU OS is much more important than I think it is; I'm ready to admit that I may be missing something.
Nonetheless, let's try to go further. What is the Eurepean Union doing to embrace open-source and digital sovereignty? This video is long already, but let's try to provide a rough overview.
We can do so thanks to a petition that has been presented to the European Commission. This petition asked the EU to develop and implement a Linux-based operating system called "EU Linux" across public administrations in all EU member states. Again, benefits are listed: independence from Microsoft, compliance with GDPR, transparency, and so on.

Before you get excited, the response by the Commission is "there is currently no formal project to establish an EU Linux", understandably so (these are not the type of things that are achieved through Commission petitions; they're more similar to information requests).

Nonetheless, the response also highlights all of the current efforts by the EU in regard to open-source software in the public administration.
Firstly, there's legislation. I've covered many of them, such as the Digital Markets Act, but more recently we've seen the Interoperable Europe Act "foster seamless cooperation between digital systems, prioritizing the use of open source and open standards".

There are also programs such as the Digital Europe Programme, CEF Telecom, and the ISA2 interoperability programmes, to "support the EU's digital transformation through open source solutions". Horizon Europe also funds a "wide range of projects that involve development and use of open source software and hardware", with its Next Generation Internet having invested "more than EUR 140M in over 1000 community-led open source projects".

There's also a body called the Open Source Observatory who has been tracking "news, reports, and case studies, demonstrating the growing adoption of open source across the EU. This includes recent national governments' efforts to develop and implement open source alternatives to proprietary office collaboration suites, closely aligned with the petitioner’s intention".

The Commission also uses open-source software internally; as an example, the majority of their websites are built and Drupal, and they mostly use Linux in data centers.

There's also a Commission Open Source Strategy which "encourages the use of open source within the organization, promotes collaboration through code.europa.eu, and paves the way for more sustainable and transparent digital infrastructures. The Commission organizes bug bounties and hackatons on open source solutions that are of interest, such as Nextcloud, and supports open source adoption in critical areas".

Now, all of this is still miles away from Linux being the standard operating system in the government sector; and, honestly, Linux itself needs to improve for corporate usage before we get there. This is why I absolutely embrace projects like EU OS, don't get me wrong! However, I feel like this round of news got a bit too excited and misunderstood the current goal and size of the project.
I have a few considerations I'd like to share about this topic, but let's first see what happened. Let's go chronologically.
On the 25th of March, Linux developer Danilo Krummrich sent a series of patches to the mailing list titled "DRM Rust abstractions". As he mentions in the email, the series have been worked initially by Asahi Lina, who has since then stepped down, sent a private email to him saying "feel free to take anything that's useful and use it/submit it in any way", and hinted at the fact that she was fed up with kernel development and didn't want to have anything to do with it anymore. Danilo credits Lina as a co-author in all the patches, and asks her whether she's fine being co-author (instead of primary author, which Danilo set himself to be).

This last sentence is particularly important; let me quote it verbatim: if you, however, feel uncomfortable with any of the co-developed-by tags, due to the major changes, please let me know. Given the context, it seems to me somewhat clear that this refers to Lina being Co-author instead of primary author, and offers to swap the two around.

However, Asahi Lina instead interpreted this to mean that, if she was uncomfortable with being set as co-author, Danilo was willing to remove her as co-author, thus not crediting her at all. This immediately frustrates her, as she perceives that Danilo is open to demoting her to zero credit instead of promoting her to primary author. I'm still somewhat surprised that she jumped at this conclusion, but we'll get to that later.

As a result, she asks Danilo why she was not set as primary author, and specifically says "I'm really tired of kernel politics and I don't want to spend more brain cycles looking at all the other patches or having to argue (in fact I usually don't look at patch emails at all recently), but I would appreciate if you keep my authorship for files that I did largely author myself. After everything I've been going through the past weeks (some of the people on Cc know what that's about...) this feels like yet another slap in the face". Again, Danilo already offered to change the primary author, but Lina did not catch that at this time, and already uses some strong wording like "slap in the face".

Regarding the question of primary authorship, Danilo then explains that he thinks the patches have been changed extensively by him, thus warranting the primary authorship.

He points out that keeping Lina as primary author on patches heavily reworked by him would've meant misrepresenting her work instead, which is potentially an issue (let's say the code ends up not working: you wouldn't want Lina to get blamed for some change Danilo did). He also points out, again, that in Lina's email she said that Danilo was "free to take anything useful from my past patch submissions and use it / submit it in any way", and that he preferred not to bother her since she said she did not want to deal with kernel development anymore at all, to have a mental health break. Then, Danilo again offers more explicitly to set Lina as the primary author of some patches, and asks Lina which patches she would like to see changed.

Lina then replies to reiterate that she just assumed that primary authorship of her patches would be preserved out of kernel etiquette, and that "I don't have the spoons to make some deep analysis here, you should know how much of the code you changed, added, or just moved around. I'm not going to litigate this further. If you think splitting up a commit into multiple commits and moving code around warrants taking over primary authorship of a project I've been working on for years now, so be it. I'm just disappointed".

And then we're back to Danilo. He says, "the broader context of the private mail was about you stepping back on kernel development. You did so with a few more details that made it clear to me that you don't want to be bothered with kernel development any more. In combination with you giving permission to "use it/submit it in any way", I thought it's better to just pick a safe path to not misrepresent you given all the changes that I've made".

He also makes the point that Lina underestimates the extent of the changes he has made to her original code. He provides a full diff that contains all of his changes, and points out that Lina has both claimed that she "doesn't have the spoons to make some deep analysis here", but also accuses Danilo of not having made enough changes to warrant taking over primary authorship, two statements that seem somewhat contradicting: how do you know that, if you don't have the time to check properly? He again says that he's ready to change primary authorship, and points out that Lina hasn't yet asked to be set as primary author on any set of specific subset of patches, and instead spent time to stir up drama with some quite strong words. He says: "I neither have the time, nor am I willing to deal with random drama like this. If you want something changed, just go ahead and tell me what, without more drama and without more accusing me of things".

And this is where Lina completely breaks down:
Alright, then please remove my authorship entirely from this series, including Co-developed-by and signoff lines. I hereby release my code as CC-0, which means you don't need the signoffs, it's yours now. The same applies to any future code submitted that I originally authored as part of the Asahi kernel git tree. That way we don't need to argue about any of this. I thought asking for patches that I mostly authored to keep my Git authorship would be an uncontroversial request (and not unreasonable to ask you to figure out which those are, since you made the changes/slips, and #3 clearly is one), but apparently even that gets you flamed on Linux threads these days. I regret having been part of this community.

Thus, the root of the conflict so far is that Lina and Danilo disagree on the extent of the changes made by him; he's still willing to change primary authorship of the patches, but since he believes he significantly changed all of them, he's asking Lina which one to author to her. Lina wants Danilo to figure it out by himself, even though the whole point is that Danilo thinks that he's made significant changes to all of them, and thus can't just "figure it out himself". The solution by Lina is to just throw the table over, release everything as creative commons, even though Danilo was pretty professional and willing to collaborate throughout.
Here another Linux developer - Dave Airlie - pitches in, trying to convey the absurdity of the behavior of Lina. He says,
The project will maintain authorship/signoffs on any patches that are clearly still authored by you, we will err on the side of caution and on rewritten patches which share some decent amount of history shall retain your authorship. In this case it does appear instead of putting in the 5 minutes of looking at Danilo's reasoning and supplied diff, and either saying "my bad, this is sufficiently new code and I don't feel I wrote it" or "I'd still prefer to retain authorship despite your changes", both of which Danilo indicated would be respected, you somehow picked door number 3 which probably took more time and effort than either of the above options. Again no need to pick door number 3 here, you can let the bus go below 50, it won't explode.

At this point in time, people started to notice about this entire discussion. The fact that one of the previoully lead developers of a major project in the Linux world was releasing all of her code as Creative Commons was somewhat newsworthy, and as such, people started talking about it.
As such, a thread was created about it on the Linux subreddit, where people reading the entire discussion mostly sided with Danilo (understandably so, in my opinion).

This further frustrated Lina, who at this point felt compelled to go through the patches to understand whether she should've been primary author or not. She did so in a mathematical way, arguing that she wrote around 75% of the code, and she thought Danilo's changes to be minor. Which is fair – however, she then adds "And I'm sure Danilo knows this, having done the refactoring/rearranging/modification work to get here". Through this sentence, Lina is de-facto claiming Danilo to be lying, since Danilo instead saying that he thinks he has made significant changes.

She then went back to the mailing list to post the following message:
I wanted to keep this private, but apparently it is impossible for me to send two emails in reply to a Linux kernel thread without it ending up all over the news and the entire world speculating about why I am so upset. I would be a lot more willing to work with the kernel community if I hedn't been traumatied by a major Linux kernel maintainer having privately admitted to siding with an abuser and harasser who has attacked me relentlessly for over one year now, mocking me for it, using their arguments and wording against me, lying to their peers to cover up actions and collusion against me, and more. Now please, let me leave this community in peace. You all figure out what to do with my code and whether you care about proper attribution. I just want out.

At this point in time, I think it's clear that Lina is in too much distress to handle the discussion. She has misinterpreted the initial offer by Danilo, and then shown that she assumes Danilo to be lying instead of acting in good faith, and now she's explaining that her frustration in this discussion is also caused by prior bad behavior by other Linux kernel maintainers; all of which make it impossible to resolve the central conflict of the discussion, which is the disagreement over the significance of Danilo changes.
And, again, Lina wants Danilo to understand by himself which patches to author to Lina, but Danilo won't be able to do that, because he thinks he has made significant contributions to all the patches.
Lina then comes back to the thread, also explaining that she believes to have written 75% of the code of the patches, and asks Danilo to put her as primary author of the patches from 3 to 7. Note here that she says she has been "forced" to do this analysis, which I don't believe to be completely true.

Danilo then decides to point out that code authorship is not about who authored the largest percentage of codelines, and he decides to list out all of the changes that he's made to the original patches by Lina, pointing out that they are not minor reworks. Then, he says that he's fine with changing ownership of the patches 3 through 7, but points out that it would include one patch that has been authored by him, from scratch (and thus, it doesn't make sense to ask to change the authorship there).

At this point, he's also clearly frustrated by Lina's assumption of bad faith from him, and he says that
First of all, you keep talking as if I would have been restisting to do any changes, even though I offered you to change things from the get-go. Instead of taking the offer, you decided to go with wild accusations, without even properly looking at things and understanding my intentions. [...] The decision I took is clearly reasonable and nothing about it is uncommon. [...] However, I understand that you prefer to have primary authorship, even if the code has been re-organized in new commits, moved, modified or rewritten. This really is totally fine for me, and I won't argue about it (even though one could).

I think he's right, really: when assuming good faith from him, he has been completely reasonable throughout, and very available to fix things. The issue is that, apparently due to previous bad experiences, Lina is assuming bad faith instead - she said it herself - and is not willing to collaborate. This results in drama and discussions, which make Lina even more frustrated. In her next emails, she says that
Though given the mess this turned into, as soon as this conversation is over, I will be sending all kernel-related emails directly to sieve-discard. While a simple question would have been fine and encouraged, this mess is not, and I do not have the time or mental health cycles to deal with any more of this going forward. So indeed, if you ever find yourself questioning something about my code going forward, please take your best guess, because I'm now really done with kernel involvement completely.

And, later,
See? You could have started with that story about drm::Device being a more major change than the others and spared us all the blind arguing and wasting of time.

The discussion goes on, but it does so in circles, and I think I can spare it to you; at this point, you probably understand the main points of disagreement and arguments on both sides. I have a few things to say myself.
Firstly, should I not have made this video? Again, the previous developer of a significant project in the Linux space breaks down in the Linux kernel mailing list and tries to make all of her code CC0. A Reddit thread about this is trending, and even Brodie did a video about this a few hours ago (you should go watch it, by the way, he goes into more detail in the discussion). Is this unwarranted?
On one side, I think not. If you stir up drama in a public place, and you are a content creator and significant contributor of a well-known project, you should expect people to be interested in your actions and report about what you do. I think it's unfair to expect everyone to avoid the topic altogether, even though all the information is publicly available, and people are interested in it.
Brodie also points out (and I had not thought of it) that Lina could've also tried to resolve this privately with Danilo by sending him only an email. By replying publicly, you're accepting that eyes will be on your email. This is particularly important given that Lina is a content creator, which - I'm sorry to say - means that you have more responsibility in public than other people.
On the other side, there's an interesting point to be made in open source vs closed source development. Not every good developer might have the social skills to handle attention and Reddit threads about them; however, in open-source development has to happen publicly, whereas Windows kernel developers don't have to be held accountable in the same manner. This might insert some extra burden on open source developers that they don't necessarily want, making software development a bit harder for us. However, I don't think the solution to this can be "ah, you people should just close your eyes and pretend not to see this". That won't work.
Finally, another important point this raises is how we should handle developers who are not in the mental space to be contributors and participate in development discussions. I believe that, given Lina's current situation, there was no way to resolve this without stirring up drama and being respectful to Danilo at the same time – though I might be wrong.
So, if we want to preserve the mental health of our contributors, how do we react when someone is already in burnout and they're making things worse for themselves? I would like to see big projects organized with people who are experts in mental health and can jump in when conflicts happen to help everyone involved; the status quo is letting those arguments play out in public and without guardrails.
I've been part of the KDE VDG ("Visual Design Team") for many years, though I'm not very active there anymore. Nonetheless, as a quick metric, I've written more than 16 thousand messages in the VDG chat, and I'm still somewhat in the loop as far as design goes.

I've never been part of the GNOME Design team, though. That said, Tobias Bernard has recently held a talk called "GNOME Design: A Report From The Trenches", which gives us some insights into them. I have also done some further research, and I'll do my best to accurately represent their processes.

Let's start with the teams themselves.
Over the GNOME side of things, there's a Design team. According to Tobias, it's currently composed of five to ten people ("depending on how you count them"), with a mix of full-time employees and volunteers, and it has been somewhat stable over time.

As a rough explanation of how the Design team operates within the larger context of GNOME, Tobias explains that at the core there are the modules, such as the desktop and the apps, then there are other contributors on the outside, and other teams that coordinate specific areas. If a change that affects the UX is required, the Design team is involved in some way, and "everyone understands that to be the case" - which, believe me, is noteworthy.

Simple enough. On the KDE side of things, we have the Visual Design Group or VDG. It's been around for various years, and - akin to the three-body problem - it has stable eras (with various active contributors) and chaotic eras (when the situation is not as good).

I think we're currently in a Chaotic Era. There's no one that's specific to the VDG, and all those working within it are application developers that somewhat re-invent themselves as designers too, out of need. Formally, around thirty people are subscribed to the group, but it doesn't feel like so. We certainly don't have anyone working fulltime on it.
Due to this bad state of things - in my opinion - a second design team has formed within KDE, and it's called KDE Next. I did a video about the project a few months ago. They describe themselves as
a designer-led effort to revamp KDE's Plasma desktop. We share mockups, ideas, designs, thoughts, etc. We also work on icons, design systems, and much more.

Plasma Next has one to two regularly active members and a few more occasional ones. They're still all volunteers, which limits the amount of available time they have. De facto, the team is driven forward by Andy, who's the only designer-only regularly active person in KDE right now. Which isn't great.

Now, it's easy to make fun of KDE, saying things like "you can see there's no design team!", but that wouldn't be very honest. This situation is somewhat recent, and just a few years ago the Visual Design Team was much more active, and great design work was done. Some of the people who were in the VDG are still active KDE contributors, though they interact in other spaces.
Both GNOME and KDE heavily use Matrix and Gitlab for internal communication within the two teams.
But GNOME does it better. The Design team's Gitlab has dozens of projects, ranging from apps and system mockups to resources helpful for creating mockups to sounds, icon references, and more.

These work as a somewhat centralized source of design information and references; there's a place to see how other designs intended components, and from which developers can take inspiration.

There's also SVG files with templates; however, these aren't kept up to date, and when a designer uses Inkscape for their designs, they generally copy assets they've made in previous mockups instead of a template file. This somewhat raises the barrier to entry for designers.

The GNOME Design team also holds weekly calls to discuss plans for the future (open merge requests, big initiatives, design proposals, and so on), and - even better - the notes for each call are archived in a design-calls folder within the - you guessed it - same GitLab team, so that everyone can see them.

By contrast, the KDE VDG GitLab project only holds two projects, Issues and Device Assets.
The former is used for Design discussions, and it details a precise decision-making process. For each issue, there's a facilitator assigned by the team, and there's a discussion for three weeks. At the end of that, a decision is taken either by consensus or by voting (still through the facilitator).

That said, I haven't personally seen this process much in action. Most of the issues are currently hanging: from proposed redesigns, user requests, and so on; only a few are actively in discussion.

The "Device Assets" repository, on the other hand, is completely empty. Whops!

As mentioned, both projects also use Matrix as the official communication channel. That said, it's worth noting that KDE's VDG is also bridged to Telegram, which might make it a bit easier to join if you already have an account there. It sure helped me a lot to get involved.

I've briefly mentioned mockups. Which applications are used to create them? As far as I understood it, both KDE and GNOME are in the same boat here, so I'll make a general overview here.
Currently, there's no clear standard to design applications in the free and open-source world. One appealing option, which is the one I usually go for myself, is Inkscape.

Indeed, you can see that the mockup files provided by GNOME are SVGs, and they also offer inkscape tutorial resources (it does not seem very up-to-date, but still).

However, Inkscape is not the correct tool to do application design. You can't easily add standard elements, such as drop shadows and correct borders, nor a proper way to have templates, and so much more. It's not a Figma alternative.
Then, there's Figma. It's used by some people and designers; as an example, both Manuel and Andy use it, on the KDE side of things. It's the status quo for this type of things, but it's also proprietary, and we would all prefer to avoid it.

Finally, there's Penpot. They're an open-source alternative to Figma, and they're developing quickly; KDE is trying to move to it over time, but they still lack many of the necessary resources to replace a tool like Figma. However, the team is very reactive, and they're collaborating with the KDE Next project to address those missing features.

There are no formal plans for GNOME to move to Penpot, however. There are a couple of fans of it who want to push for it more, but most designers will probably be stuck on Inkscape for a while longer.
If you want more details specifically about KDE Next and Penpot, I've talked more about it in my video about KDE Next specifically, but you can also go check Andy's youtube channel for more.

Both KDE and GNOME have something called Human Interface Guidelines. These are supposed to contain some reference information on how to develop designs for their respective ecosystems. Cool.
KDE's guidelines have been recently rewritten by Nate Graham, and has been then further developed by many others.

It begins with some "philosophical" instructions (what makes a KDE app a KDE app, how to be simple by default but powerful when needed); then, the categories you'd expect: layout and navigation, displaying content, getting input, communicating status changes, text and labels, icons, and accessibility.

If you were wondering what makes a KDE app a KDE app, it's allowing for diverse workflows and adapting to preferences, and not being afraid to grow to cover multiple different usecases. Keep these sentences in mind, as you'll see that the GNOME guidelines have a somewhat different take on them.

You can have some fun going through these sections; as one example, the KDE guidelines recommend against distinguishing between "Basic" and "Advanced" in an app's UI. This is because the word "Advanced" communicates nothing about what might be inside that section, and the distinction between "Basic" and "Advanced" depends on the opinion of the user.

GNOME's guidelines also begin with design principles. These are: Design For People (and thus, accommodating different physical abilities, cultures, and device form factors); also, Make It Simple: "resist the pull to try and make an app that suits all people in all situations. Focus on one situation, one type of experience", and "The best apps do one thing and do it well". This seems radically different from KDE's principles.

GNOME's guidelines also include tools and resources. The former include applications to find icons, select text styles, preview app icons and symbolic icons, and a reference app for the color palette. There's also a GTK inspector (like the web browsers ones, but for GNOME apps), and a demo application for libadwaita. Ah, and the above-mentioned app SVG templates.

The rest of the guidelines (that is, most of them) are divided between a subsection called "guidelines" (yes), "patterns" and "references". Unsurprisingly, the patterns very closely reference libadwaita, the library that GNOME uses to build applications. They also have very nice graphical elements to indicate the various chapters.

Let's talk (third-party) app ecosystem. Though this topic isn't strictly about design, its quality is often a direct consequence of it. Are available APIs easy enough for new developers to start using? Do they have sensible designs out of the box? Are developers able to build more complex apps with it?
This will be the topic of another video, but quickly: KDE offers a library of application components called "Kirigami". These include front-end UI elements from pages, to buttons, actions, drawers, cards, form layouts, inline messages, and so on; but it also includes spacing, colors, typography, and so on.

Similarly, GNOME offers a set of components called Libadwaita. This also comes with a variety of UI elements, which are often direct implementations of their human interface guidelines. Libadwaita thus makes it real easy to create third-party apps following the GNOME design.

So far, I feel like GNOME is somewhat winning this battle, featuring a wider selection of applications with consistent design. They've also started an initiative, called GNOME Circle, which is used to give direct feedback to third-party app developers to steer them toward the GNOME way to do things, and rewarding them with more resources.

Finally, to do design, it's often very useful to have some data about how users interact with a certain system. This is called telemetry, and proprietary applications have no trouble inserting it everywhere; open-source projects, less so.
KDE has an opt-in telemetry system called KUserFeedback. User-wise, it's a slider (again, off by default) that lets you choose how much to share with KDE, and provides a list of exactly what is being shared.

Developer David Edmunson shared a few conclusions that were obtained thanks to these data. As an example, one time a developer claimed that "no one is using a screen smaller than 1024x768", but was then quickly proved wrong by the data. Similarly, "no one still uses only OpenGL2" was disproven by a 5% that were.

It also allowed KDE to track the usage of X11 vs Wayland; as you know, Plasma 6 recently switched from the former to the latter. Did the user agree with this, or had to switch back? Well, overall, the percentage of Wayland users is only at 45%, though it's increasing over time:

However, if we filter for Plasma 6 users, we see that only 20% decided to change the default from Wayland back to X11.

There are a few criticisms of this method too. One that I have myself is that the VDG does not really use it, or only uses it extremely rarely. For privacy, only a few members have access to the data (as an example, I don't).
Secondly, it's really hard to add new data to be tracked; to the users who already opted-in, what should happen? Should they be automatically opted-in to the new tracking too (which wouldn't be honest towards them)? Should they have to go back to settings to change the setting? Should they be notified and asked upon upgrading? It's not clear.

GNOME had a few more mixed feelings about telemetry. A while ago, they published a script called gnome-info-collect that users could intentionally download and launch on their systems to share - as a one-time favor - some data to GNOME. Two and a half thousand people did so.

Turns out, most of the people who run the script use Fedora (Arch is a distant second) and use a Lenovo computer. Half use the Online account's features, mostly to connect to Google. 93% have Flatpak installed, and 73% use Firefox as their default browser. Also, only less than 17% did not have any extension installed.

They also looked for which extensions were installed, and which apps the user had on their systems. The most common ones were GIMP, VLC, and Steam.

Overall, this feels like a very interesting exercise in data collection, and one that might even result more useful compared to KDE's current telemetry system. However, for it to continue to provide feedback, it would have to be run once in a while. There are benefits and issues on both sides, I would say.
Overall, I'm not completely happy about the status of the KDE design team, and I think we have something to learn from GNOME in this aspect. I hope that we will be able to attract more design-first contributors, and maybe the Plasma Next initiative by Andy, who's also working on better Figma / Penpot design kits, might help that.
Did you know that more than half of the Tor browser's funding comes from the U.S. government? In the fiscal year 2021-2022, they received more than $3M, whereas individual donations only accounted for 28% of the revenue.

Similarly, just a few months ago, F-Droid announced that it had won a grant of slightly less than $400k, also paid by the U.S. government. As they explained, this would allow them to "refactor and integrate code with other maintained projects", "establish clear policies and legal strategies", "improve our localization workflows", and so on.

Of course, we're not currently in the best time to rely on U.S. governmental funds. We've recently covered how the dismantling of the USAID agency directly affected Mozilla-selected projects to bring open internet awareness in other countries, and the funding that I mentioned above is now at risk as well.

Let's start from the beginning. On March 14th, a Presidential Action was published that ordered the "elimination to the maximum extent consistent with applicable law" of seven governmental entities, including the "United States Agency for Global Media", or USAGM.

As a direct result, the USAGM senior advisor Kari Lake (a Republican politician who endorsed the current US president) has vowed to "fully implement President Trump's executive order", and claimed that USAGM was "not salvageable" as it is "a giant rot and burden to the American taxpayer".

You might be guessing where this is headed: USAGM funded (funds?) various external entities, from "Voice of America" (a news source with a weekly international audience of 361 million people) to "Radio Free Asia" (a domestic news corporation in six Asian countries) and, of particular interest to us, the "Open Technology Fund".

The OTF is an independent non-profit organization that, according to them, aims to "advance global internet freedom. We support projects focused on counteracting repressive censorship and surveillance, enabling citizens worldwide to exercise their fundamental human rights online".

Going through the list of supported projects, there's a clear pattern: we have OONI anonymous credentials, projects to measure internet censorship in foreign states, projects to make it easier to document human rights violations, supporting exiled and underground media organizations, and so on.

This includes multiple open-source projects, even notable ones. We've already mentioned the Tor browsers - and I hope I don't have to explain why that's a big deal for internet privacy - but there's also Let's Encrypt, providing secure certificates, and Tails, a portable Linux distribution that runs from a USB stick.

Finally, I've also mentioned F-Droid, which is an application store of FOSS applications that assumes a particularly important role in countries where the built-in application store might be particularly government-controlled.

Let's put some numbers on all of this. The OTF's total budget slowly raised from ~$10M in 2019 to a grand total of $40M in 2023, almost half of all allocated funds by Congress to promote Internet freedom globally.

F-Droid received around ~$400k, Let's Encrypt received $800k exactly, and the Tor project received just shy of that over two years. Though these numbers are certainly a significant help for open-source projects, which sometimes struggle to find funding, I would also like to argue that they're extremely small in the context of the U.S. budget - which is in the order of magnitude of trillions per year - and yet it has a high return on investment, making sure that core internet privacy infrastructure gets developed actively.

More recently, Congress had directed that - for both the fiscal years of 2024 and 2025 - the funding should be "not less than $43,500,000", which guaranteed an income stream for 2025 too.

However, on March 15, the OTF received a letter from the above-mentioned Lake, where she said that "the award no longer effectuated agency priorities", and would thus "terminate all grant funding".

The OTF has decided to fight against this by opening a lawsuit; according to them, the Congress directives do not allow for the USAGM to arbitrarily stop the funds. According to them, "the termination of its grant, the mechanism by which OTF receives its Congressionally-appropriated funds, is unlawful".

The OTF was not the only one; other entities that were funded by the USAGM, including Radio Free Asia, RFE/RL, and Lake and Victor Morales (the USAGM acting CEOs) all decided to sue USAGM to prevent the grants from being withhold.

To fight that, USAGM disbursed $7.5M to these entities, in "what seemed to be an effort to delay the hearing or woo the judge". Regardless, the latter has sided against USAGM, and just a few days ago, the agency has decided to back off and release the funds for the 2025 fiscal year.

Even though it's great that the OTF survived the attempt of being shut down, this does leave me worried for its future. Congress is now under Republican control, and they must approve funds every year.
Let's immediately acknowledge that the title is lighthearted, and that "communist company" is an oxymoron. The better choice would've been, "which is the most worker-owned, egalitarian, power-structures-free cooperative?", which SEO experts told me was too long of a title. With that said, let me tell you about Igalia and other tech cooperatives.
Igalia is an open-source consultancy with Spain headquarters focusing on browsers, "client-side web technologies, " and much more. They're the company contracted to work on Servo, the open-source independent browser engine after Mozilla dropped it. So far so good. The company was founded in 2001, and now employs 140 people in 25 countries; they are a pretty big player in the open-source space.

They've also been the second largest contributor to both Chromium (after Google) and WebKit (after Apple), have a partnership with Valve to work on the SteamDeck, and much more. So, what's different about them?
Well, in Igalia there's no CEO, no managers, no bosses, they all make the same amount of money, and they all have equal decision-making power. It's also fully worker-owned. This is a pretty interesting pitch, isn't it? But how does it work?

Now, very quickly: I'm not paid by Igalia to talk about them, I don't have any ties to them at all. I just learned about how they do things and thought it was worth highlighting.
When you are hired to work at Igalia, you enter the "Staff" stage, which lasts a year. It's similar to an onboarding year. Then, you become a pre-partner for two years, which renders you a full decision-maker. After the third year, you become a partner, which is a full co-owner of the company.

The goal is for everyone to eventually become a partner; most people are partners, which contrasts with "normal" companies, where only a few people have full decision-making powers.
The partners and pre-partners compose the Assembly of Igalia, where choices are taken; I will talk more later about this. Igalia makes a point that waiting for a year before giving new hires access to the Assembly gives time for everyone to fully trust the new hire, yes, but also for them to trust that the Assembly is indeed operating in their best interest.
Partners are also paid "slightly more to account for their additional legal responsibilities", which is reasonable.
Before we talk about the Assembly, I do want to mention that they also provide some solid benefits to those working at Igalia. Not only they are very remote-friendly (again, 140 people from 25 countries!), but all parents (of any gender) receive 8 weeks of paid parental leave, you can design your own work schedule, they cover work-related hardware costs, and more.

Every two months, the Assembly gets together and holds two half-days of meetings to discuss anything and everything about the company. Otherwise, all topics are discussed in an email list.

This is pretty crazy when you think about it: it means that the entire management of the whole company is done through, (a) a mailing list, and (b) half a day of meetings per month.
The scope of the Assembly is to keep Igalians informed about the status of the company, discuss problems that need to be solved, get feedback on company-wide proposals, and eventually approve them. This includes whether to accept new clients or contracts, whether to hire new people, whether to change salaries, make donations, change the working conditions, and so on: it's all done through the Assembly.

There's also rarely a "voting" moment for these Assembly proposals; instead, they work on a consensus-building model where a small group of Igalians creates a proposal, gets feedback on it, maybe run some non-binding polls to gather the opinion of the colleagues, and eventually the adjusted proposal becomes part of the Agreements. Oh, let's talk about those.
The Agreements are the documents that contain the values of the company, their bylaws, terms of employment (such as salary and vacation days), benefits, and so on. They are written down and version-controlled.

It contains information about how to progress through the stages of Igalia, as mentioned earlier on; but it also contains information on how to handle difficult financial times, how to amend the agreements, which decisions need consensus from the assembly, and so on.

Amongst the values in the Agreements, there's Free Software: it specifically states that Igalia will give higher priority to the projects (both internal and external) where the outcome of our work is licensed and published in an open and free way, and it prefers the usage of free and open source software (when possible).
The Agreements can be changed, but some parts require full consensus; the fact that everyone is paid the same is an example. Imagine the Assembly unanimously voting that some people should be paid less!
If there are no bosses and managers, there's still an open question about how work is managed and distributed between people. The answers are teams and commissions.

Firstly, there are technology teams that are consultants for a specific kind of technology; currently, the teams are: web platforms, compilers, graphics, chromium, webkit, core, multimedia, and systems. Each team both has "consultant" people (such as programmers), and "support" people (who manage sales, contract negotiation, running team meetings, and so on). Some people also do both, because why not?
Then, there's an entire support team (which includes some people from the technology teams, and more), which does some more company-wide work. These maintain the finances and payroll systems, do system administration and work on internal tools, run assembly meetings and polls, do communication and marketing, and more.
Igalians are also assigned roles within their teams; these are things such as "work on sales", "work on strategy", "recruiting and interviewing", "communication", and so on. It's work that should only take a few hours a month, and that's shared by both consultants and support people.

Then, Assembly members can create a commission throughout teams. These work on company-wide coordination tasks; examples are the DEI commission, the strategy commissions, the Corporate social responsibility commission, and so on.

As an example, the Corporate social responsibility commission, or CSR, donates 0.7% of their income to NGOs and non-profits decided by Igalians. As an example, they donated to native re-forestation efforts in Spain!

The roles, commissions, and teams are "voluntary and dynamic", meaning that they change based on the interest of each person, the need, and encouragement. Some commissions rotate through members, which have a limited-time mandate in them.
I love this quote: at Igalia, you're not hired to a specific job description to fit like a gear to a machine, whether or not you like the parts of it or you're even good at the parts of it (that are listed in that job description), you don't have a boss that's micromanaging you or interested in offloading specific kinds of work to you.
Well, there are a few issues that they are dealing with. Firstly, on-boarding and training new members is difficult, especially brining in junior developers; you "kind-of have to be pretty good at learning by yourself". There's an effort to address this, but it's an ongoing problem.

Overall, though, it does work. Igalia has an employee turnover rate of 5%, i.e. the number of people who leave divided by the average number of employees that year. The industry average is 13%, almost three times as high. And, Igalia does keep growing and has been alive and well for more than 20 years, never experiencing a single year of contraction, where they had less employees than the previous.

There have been issues in the past; as an example, there's a mention of one time when they lost a big client that, back then, was a good chunk of the revenue of the company. No one was fired, but they had to "adjust" salaries until everyone was fully booked again, and that money was eventually paid back. So, it worked out in the end.
Spanish law does provide for cooperatives, similarly to most countries. However, that comes with some extra requirements, such as having 85% of the partners be from Spain, a limitation that Igalia did not want. Thus, they are not registered as a cooperative, but rather as a limited-liability corporation.

If you are from Spain, you can be a direct employee of Igalia; if you are outside of it, you'll be a freelancer. After three years, you have the option to become a legal partner in the business, purchasing an equal share of it at a fixed price. It's not mandatory, but it's expected.

Technically speaking they do have some legal administrator, since that's required by law; however, the position rotates every three years.

Finally, I want to mention that there are a lot of tech cooperatives, all working in different ways. You can even endless lists around the web! However, I believe that Igalia is the biggest cooperative that has had such a direct impact on the FOSS world, and I love how they work!

Hi! Long time no see. I'm happy to report that from now on, this newsletter will be back to being delivered weekly, as promised. So, what's new in LibreNews?

Firstly, I published another members-only interview with Micheal Horn! It's one hour long, and we go in-depth on how he makes videos. This is the second interview I have published, with the first one being about VeronicaExplains! I hope to build a good backlog of interviews over time, to discover how different content creators approach video-making.

I wrote an article about AI scrapers DDoSing FOSS infrastructure, and it sort of went viral! It's now the most-read article of the entire website. I was really happy to hear that people liked it!

Just today, I published a comparison between Servo and Ladybird. It talks about the pace of development, budget, and performance. Long story short: Ladybird has overall better financial and web support, but Servo seems to have a significant edge on performances.

Another article is about Asahi Lina, though this was very difficult to write. I talked a lot with Luca about whether and how to address the topic, and I believe I did so in a thoughtful way. Opinions welcome.

This article also received a lot of attention! Some parts of it have been criticized too, which is fair. I have done some further investigation, and I believe the article to still hold up pretty well, though - had I known more from the start - I probably would've phrased a few paragraphs differently.
This week there's no article from Luca, mostly because he was working on other things behind-the-scene, and also he finally got his degree.
Thanks everybody for following along, and see you next week with more exciting news! 😄
In this article, we'll compare the different approaches that Servo and Ladybird are taking to shake up the current browser engine scene, check their rate of progress, and what's in the best development state. That said, for those out of the loop, I'll also start with a brief history of each project, starting with Servo.
Servo was born in 2012 as a research project, trying to draft up a browser engine that takes advantage of the "memory safety properties and concurrency features" of Rust, speeding up webpage rendering through GPU acceleration.

Two years later, Servo passed the basic Acid2 test, which checks for some aspects of HTML, CSS 2.1 styling, PNG images, and data URIs. By 2016, Servo was already able to beat other engines in some specific tasks, such as animating various background, transform, and border radius concurrently.

Thus, efforts then started to bring these components from the experimental Servo to Gecko, the stable rendering engine behind Firefox. This project was called "Quantum", and it included the parallelized CSS style system, renderer, compositor, DOM, and so on.

These were the golden days for Servo, and back then it was even used in augmented reality browsers; both the "Magic Leap" headset and the Firefox Reality browser were relying on it. However, both projects had short lifespans.

In 2020, the entire Servo team was fired from Mozilla, amongst others. This was done by the then-CEO Mitchell Baker, who said that Mozilla had to "adapt its finances to a post-COVID-19 world and re-focus the organization on new commercial services". Evidently, developing an experimental web engine was too expensive for them.

The guidance of Servo was moved to the Linux Foundation, though without any funding; there were some volunteer efforts, but the project was as good as dead for years.

This brings us to January 2023, when "thanks to new external funding" (from whom, we do not know), "a team of developers will be actively working on Servo".

The team is from Igalia, and they've been quite public in releasing frequent updates about the status of development. You can see here a presentation they held at the last Ubuntu Summit.

This means that Servo is now in active development, and getting better every month. However, before focusing on the latest speed of development, let's also give some context to Ladybird.
Ladybird is an open-source web browser born in 2022 by the single developer Andreas Kling. His stated goal was to create a "Qt GUI for SerenityOS's LibWeb browser engine".

However, if we want more of a fair comparison, the LibWeb engine that powers Ladybird began development back in 2019, and it already had contributions from hundreds of people before Ladybird was born.

Back in 2022, Ladybird (or, more correctly, LibWeb) was already passing the Acid3 test (again, including "a bunch of basic CSS layout features, and various DOM/HTML APIs").

All of this - mind you - was sponsored by patrons on Patreon and GitHub sponsor, YouTube ad revenue, and Merch. He explicitly refuses to do sponsored advertising or venture capital firms. However, it also means that it was mostly a one-man project (though, that's no longer true, more on this later).

A couple of years later, he recognized that Ladybird and SerenityOS were "two big projects in one space", sharing all the resources and infrastructure, but with a diminishing overlap between them. He thus decided to separate Ladybird from SerenityOS, and he stepped down as Benevolent Dictator For Life.

This made Ladybird an independent project, and it has only grown since then; he still publishes videos about Ladybird development, though there hasn't been one in a few months.

A few things to point out immediately are that Ladybird is a browser whereas Servo is a browser engine. It seems stupid, but it isn't.
Servo does come with a proof-of-concept interface called servoshell, featuring the very basic features you'd expect out of a browser: creating and closing tabs, entering URLs, back and forward buttons, and a loading spinner.

This might seem like a small difference, but it isn't: Servo is thought from the very beginning to be embeddable everywhere, so that it's easy to build custom browsers or applications with it. They're also putting effort into simplifying the process and documenting it so that everyone can do it.

On the other hand, Ladybird's engine LibWeb is mostly focused on, well, Ladybird. That said, there has been some effort by third-party developers to bring to make the engine easily embeddable; as an example, there's a LibWebGTK project that wraps LibWeb for embedding in GTK apps.

Then, Servo was written from the very beginning in Rust with memory safety and concurrency in mind; parts of the engine managed its way to the Mozilla browser, speeding it up, whereas Ladybird is its own project written in C++.
During a podcast with Igalia, Andreas Kling has also talked about the perceived differences between the two browsers. According to him,
I always understood Servo to be an experiment, above all. And I think a lot of great things have come out of that. And I hope that they carry that forward and continue to be experimental, or experiment friendly at least, because there's so many things that you could do in a browser engine that is very inconvienent to do in the big engines because there's so much code you would have to rewrite just to try out new architectures and new ways of doing things.

Though we don't know what "external funding" allowed the Servo project to be brought back to development through Igalia, we do know that it allowed four developers to work on it in 2023:

This then grew to five developers during 2023; to the best of my knowledge, that's the current size of the team behind Servo, at least on Igalia's side of things.

Since then, the Servo project has also pushed for donations and sponsors, opening a GitHub sponsor and an OpenCollective. On the former, they have 313 current sponsors, which adds up to around $20k yearly.

Whereas, on OpenCollective, they also received an anonymous donation of $10k, $2.7k from The Linux Foundation, and many more; in less than a year they've raised $44k, and the estimated annual budget of the project is $61k, which - according to the project itself - should be able to cover six full-time developers.

As far as expenses goes, they have been mostly going towards servers to improve CI times, and not on development directly. Since the servers ad up to "only" $350 a month, most money is accumulating in their Collective, to be used later on.

This also suggests that all of these donations are on top of the mysterious "external funding", which is great news for Servo, as it means that the team could potentially expand over time.
What about Ladybird? Well, Kling has created the Ladybird Browser Initiative, a non-profit to "drive work on the browser and make it easier for supporters to sponsor development".

Since then, the board was joined by Mike Shaver, a founding member of Mozilla, Tim Flynn, who's been contributing to the project for four years, and Chris Wanstrath, GitHub co-founder.

Chris (and "his family") has also donated $1M to Ladybird's non-profit, wich - obviously - is pretty crazy!

Previously, Ladybird had received $100k in funding by Shopify, as the project is "a love-letter to the web, and proof that open technologies enable innovation by organizations of all sizes".

Since then, the project has also received $100k from Futo, another $200k total from Proton VPN, Ahrefs, Guillermo Rauch, and ohne-makler, plus various other minor sponsorships.

This allows the team to currently have 7 paid full-time engineers working on Ladybird, plus volunteers. They also strive to maintain 18 months of runway at all times. Note that board spots are "not for sale", and all sponsorship come in the form of "unrestricted donations".

Finally, Ladybird also accepts DonorBox donations from users, though it's impossible to know what they sum up to.
This makes a direct comparison with Servo extremely difficult, especially since Servo - again - does not disclose their external funding, but we do know that Ladybird is in a great financial position, and - as far as I know - has a couple more devs working on the project full-time, though the team size is nonetheless similar. Thus, I believe that Ladybird has a slight edge here, though it's arguable that it's not a significant one.
There's a few ways to compare the number of tests that each browser [engine] passes, so let's quickly go through them to have a rough comparison of the development status of the two.
Let's start with Acid3, though it's a bit of a dated test. I've already mentioned that LadyBird passes the test with a full score, but Servo only reaches an 83 out of 100 score on it.

A (much!) more comprehensive test suite is the web platform tests. These include around 2 million tests divided into tens of categories, from accelerometer to accessibility, cookies, CSS (obviously!), and more.

If we look at the raw number of passing tests, Servo managed to pass 76% of the tests, whereas Ladybird passes 88%, with a solid advantage. For reference, Chrome achieves a 97% score.

However, things are not so clear if we go category-per-category. As an example, Servo does beat Ladybird in CSS tests passing (49% vs 42%). It's the only "important" category where Servo holds a significant advantage, but it's nonetheless a pretty important one.

This is because most CSS tests are focus areas of improvement of Servo, where the Igalia team is dedicating the most resources; as an example, Servo wins in CSS2 tests, cssom, flexbox, and a few others, all of which are focus areas for the team.

It's worth noting that, until 5 months ago, Servo had the edge on the web platform tests, but Ladybird managed to catch up quickly.

Indeed, Andreas Kling has provided a graph over time of the score of various browsers on the web-platform-test over time; I'll have to admit, I was not able to understand how to generate it myself. In the graph, the purple line is Servo, the red line is Ladybird, and the orange line is another browser engine called Flow, whereas the group at the top are Chrome, Edge, Safari, and Firefox.

Overall, my impression here is that Ladybird has an overall faster pace of development when purely giving attention to compliance to web standards, though Servo does win in the few areas it's focusing on.
Well, it's very hard to compare performance on browsers that are mostly fighting to work at all on most webpages, rather than doing so quickly. Nonetheless, we can try to find benchmarks that work on both browsers and compare the scores to have a rough idea of where things are right now.
Let's start with JetStream, which mostly measures the JS engine performance. I'm afraid to say that the test crashes on Ladybird, but it does work on Servo with a resulting score of 129.833; for reference, Chrome achieves 243.338, so there's still some work to do.

Octane does run on both browsers. It's a test that's too focused on the JS engine according to Servo developers, but it's worth noting that here Servo has an easy win, with a score that's more than an order of magnitude higher than Ladybird.

Speedometer v2 also works on both browsers. Again, Servo easily beats Ladybird, with a score roughly seven time higher (and, believe me, it did feel like an eternity to wait for Ladybird to finish the test here). This test measures the "responsiveness of web applications, and uses a demo web application to simulate user actions such as adding to-do items".

For reference, Chrome manages a score of 294, finishing the test within seconds (instead of, well, twenty minutes). I'm not sure how much this will be representative on the day-to-day, but nonetheless it's another data point.

Please note that the Ladybird version I'm using is the latest one from git, and it's built on my computer following the official instructions; I'd be surprised if it lacked some optimization, though such a stark performance difference leaves me a bit speechless.
I have done a few tests on randomly picked governmental webpages, and indeed I found Ladybird to often load significantly slower compared to Servo on most of them. However, these were not scientific tests at all, which means I don't have concrete data for them; however, they do align with the benchmarks that we saw.
Overall, my impression is that currently Servo has significantly better performance (this does not surprise me too much, as that was a bit the whole point of the Servo experiment).
Three days ago, Drew DeVault - founder and CEO of SourceHut - published a blogpost called, "Please stop externalizing your costs directly into my face", where he complained that LLM companies were crawling data without respecting robosts.txt and causing severe outages to SourceHut.

I went, "Interesting!", and moved on.
Then, yesterday morning, KDE GitLab infrastructure was overwhelmed by another AI crawler, with IPs from an Alibaba range; this caused GitLab to be temporarily inaccessible by KDE developers.

I then discovered that, one week ago, an Anime girl started appearing on the GNOME GitLab instance, as the page was loaded. It turns out that it's the default loading page for Anubis, a proof-of-work challenger that blocks AI scrapers that are causing outages.

By now, it should be pretty clear that this is no coincidence. AI scrapers are getting more and more aggressive, and - since FOSS software relies on public collaboration, whereas private companies don't have that requirement - this is putting some extra burden on Open Source communities.
So let's try to get more details – going back to Drew's blogpost. According to Drew, LLM crawlers don't respect robots.txt requirements and include expensive endpoints like git blame, every page of every git log, and every commit in your repository. They do so using random User-Agents from tens of thousands of IP addresses, each one making no more than one HTTP request, trying to blend in with user traffic.

Due to this, it's hard to come off with a good set of mitigations. Drew says that several high-priority tasks have been delayed for weeks or months due to these interruptions, users have been occasionally affected (because it's hard to distinguish bots and humans), and - of course - this causes occasional outages of SourceHut.

Drew here does not distinguish between which AI companies are more or less respectful of robots.txt files, or more accurate in their user agent reporting; we'll be able to look more into that later.
Finally, Drew points out that this is not some isolated issue. He says,
All of my sysadmin friends are dealing with the same problems, [and] every time I sit down for beers or dinner to socialize with sysadmin friends it's not long before we're complaining about the bots. [...] The desperation in these conversations is palpable.

Which brings me back to yesterday's KDE GitLab issues. According to Ben, part of the KDE sysadmin team, all of the IPs that were performing this DDoS were claiming to be MS Edge, and were due to Chinese AI companies; he mentions that Western LLM operators, such as OpenAI and Anthropic, were at least setting a proper UA - again, more on this later.

The solution - for now - was to ban the version of Edge that the bots were claiming to be, though it's hard to believe that this will be a definitive solution; these bots do seem keen on changing user agents to try to blend in as much as possible.
Indeed, GNOME has been experiencing issues since a last November; as a temporary solution they had rate-limited non-logged in users from seeing merge requests and commits, which obviously also caused issues for real human guests.

The solution the eventually settled to was switching to Anubis. This is a page that presents a challenge to the browser, which then has to spend time doing some math and presenting the solution back to the server. If it's right, you get access to the website.

According to the developer, this project is "a bit of a nuclear response, but AI scraper bots scraping so aggressively have forced my hand. I hate that I have to do this, but this is what we get for the modern Internet because bots don't conform to standards like robots.txt, even when they claim to".

However, this is also causing user issues. When a lot of people open the link from the same place, it might happen that they get served some higher-difficulty exercise that will take some time to complete; there's one user reporting one minute delay, and another - from his phone - having to wait around two minutes.

Why? Well, a GitLab link was pasted in a chatroom! Similarly, the same happened when the Triple Buffering GNOME merge request was posted to Hacker News, and thus received a lot of attention over there. As the developer said, it's a nuclear option for crawlers, but it also has human consequences.

Over Mastodon, one GNOME sysadmin, Bart Piotrowski, kindly shared some numbers to let people fully understand the scope of the problem. According to him, in around two hours and a half they received 81k total requests, and out of those only 3% passed Anubi's proof of work, hinting at 97% of the traffic being bots – an insane number!

That said, at least that worked. Other organizations are having a harder time dealing with these scrapers.
As an example, here's Jonathan Corbet, who runs the FOSS news source LWN, warns users that the website might be "occasionally sluggish"… due to DDoS from AI scraper bots. He claims that "only a small fraction of our traffic is serving actual human readers", and at some point, the bots "decides to hit us from hundreds of IP addresses at once. [..] They don't identify themselves as bots, and robots.txt is the only thing they don't read off the site".

Many expressed solidarity, including Kevin Fenzi, sysadmin for the Fedora project. They've also been having issues with AI scrapers: firstly, one month ago they had to fight to get pagure.io to stay alive:

However, things got worse over time, so they had to block a bunch of subnets, which has also impacted many real users. Out of desperation, at one point Kevin decided to ban the entire country of Brazil to get things to work again; to my understanding, this ban is still in effect, and it's not so clear where a longer-term solution might be found.

And, as Neal Gompa points out, even this blocking an entire country only gets you so far, and apparently the Fedora infrastructure has been "regularly down for weeks" because of AI scrapers.

Another project that's been hit by this issue in the last week is Inkscape. According to Martin Owens, it's not "the usual Chinese DDoS from last year, but from a pile of companies that started ignoring our spider conf and started spoofing their browser info. I now have a Prodigius block list. If you happen to work for a big company doing AI, you may not get our website anymore".

And, well, Martin is not the only developer who has built a "prodigious block list". Even BigGrizzly from Frama software was flooded by a bad LLM crawler, and built a list of 460K IPs with spoofed user agents to ban; he's offering to share the list around.

One more comprehensive attempt at this is the "ai.robots.txt" project, an open list of web crawlers associated with AI companies. They offer a robots.txt that implements the Robots Exclusion Protocol and a .htaccess file that will return an error page when getting a request from any AI crawler in their list.

We can get some more numbers about the crawlers if we go a few months back. Here's a post by Dennis Schubert about the Diaspora (an Open Source decentralized social network) infrastructure, where he says that "looking at the traffic logs made him impressively angry".

In the blogpost, he claims that one fourth of his entire web traffic is due to bots with an OpenAI user agent, 15% is due to Amazon, 4.3% is due to Anthropic, and so on. Overall, we're talking about 70% of the entire requests being from AI companies.

According to him,
they don’t just crawl a page once and then move on. Oh, no, they come back every 6 hours because lol why not. They also don’t give a single flying fuck about robots.txt, because why should they. [...] If you try to rate-limit them, they’ll just switch to other IPs all the time. If you try to block them by User Agent string, they’ll just switch to a non-bot UA string (no, really). This is literally a DDoS on the entire internet.
A similar number is given by the Read the Docs project. In a blogpost called, "AI crawlers need to be more respectful", they claim that blocking all AI crawlers immediately decreased their traffic by 75%, going from 800GB/day to 200GB/day. This made the project save up around $1500 a month.

The rest of the article is pretty impressive too; they talk about crawlers downloading tens of terabytes of data within a few days, or more. It's hard to block them entirely, since they use various different IPs.

I do wonder how much of this is scraping for training data, and how much instead is the "search" function that most LLMs provide; nonetheless, according to Schubert, "normal" crawlers such as Google's and Bing's only add up to a fraction of a single percentage point, which hints at the fact that other companies are indeed abusing their web powers.
But it's not just scrapers, or I would've titled this "AI scrapers", not "AI companies". Another issue that Open Source community have been fighting with is AI-generated bug reports, as an example.
This was first reported by Daniel Stenberg of the Curl project, in a blogpost titled "The I in LLM stands for Intelligence". Curl offers a bug bounty project, but lately, they've noticed that many bug reports are generated by AI. These look credible and take up a lot of developer time to check, but they also contain the typical hallucinations you'd expect from AIs.

It's pretty crazy to have to go through your own code because a bug report confidently tells you there's some critical security issue to fix, and … not finding it, because the whole issue is just AI hallucination.

A similar issue was reported by Seth Larson, who's on the security report triage team for CPython, pip, urllib3, Requests, and more. He says,
Recently I've noticed an uptick in extremely low-quality, spammy, and LLM-hallucinated security reports to open source projects. The issue is in the age of LLMs, these reports appear at first-glance to be potentially legitimate and thus require time to refute.

This is a pretty big issue. As he points out, responding to security reports is expensive, and responding to invented but credible bug reports causes some significant additional burden on maintainers, which might drive them out of the Open Source world.

The article ends with a request: please, do not use AI or LLM systems for detecting vulnerabilities. He says, "These systems today cannot understand code, finding security vulnerabilities requires understanding code AND understanding human-level concepts like intent, common usage, and context.".

Again, I want to point out that these issues impact disproportionately on the FOSS world; not only do Open Source projects often have less resources compared to commercial products, but - being community-driven projects - much more of their infrastructure is public and thus susceptible to both crawlers and AI-generated bug reports or issues.
Asahi Lina, who was working on Apple GPU drivers, has decided to take a break from Asahi Linux development.
She did so through a Bluesky post; she said:
For personal reasons, I no longer feel safe working on Linux GPU drivers or the Linux graphics ecosystem. I've paused work on Apple GPU drivers indefinitely. I can't share any more information at this time, so please don't ask for more details. Thank you.

She then added:
If you think you know what happened or the context, you probably don't. Please don't make assumptions. Thank you. I'm safe physically, but I'll be taking some time off in general to focus on my health.

I do not know why she might've decided to step back, so there's no risk of me making assumptions or guesses.
For context, Asahi Lina is a VTuber who's been active for a couple of years, mostly doing lives regarding Asahi Linux development. Some of these were quite popular, reaching 50/60k views.

Now, there is something weird about this story.
This is the Phoronix article about Asahi Lina pausing development. It mentions that it "is a hit to the Linux graphics support for the Apple Silicon GPU especially with the DRM kernel driver not yet being finished and upstreamed as well as still targeting the older M1/M2 hardware generations", which is all fair and correct.

However, if we check the Phoronix forum about this article - where people can post comments - you'll notice that the thread has been changed to a redirect to the forum homepage, making it inaccessible.

Similarly, the comment thread in the Reddit post about the news, in the Asahi Linux subreddit, has also been locked down; no one can add comments now.

There even was a thread in the Linux subreddit, which has since been entirely removed "awaiting moderator's approval". A few hours ago the post was public, which makes me think it was not an auto-mod decision.

Finally, doing some extra background checks - which I will not mention here - I can say that there had been an additional thread created in the Asahi Linux community, which was also quickly removed.

What's up with that? Well, some more work gave me a likely answer to this question. However, it's an answer that puts me in a difficult spot: do I want to report back to you, now that I know that there's a reason for hiding some content? Or should I avoid the topic entirely, and pretend I did not see anything?
After some thinking, I have decided to only partially reveal some of the information I found. Firstly, let's introduce you to the internet cesspool that Kiwi Farm is.
Let me simply read the Wikipedia description, as it's perfect already:
Kiwi Farms [...] is a web forum that facilitates the harassment of online figures and communities. Their targets are often subject to organized group trolling and stalking, as well as doxing and real-life harassment. Kiwi Farms has been tied to the deaths of three people who were victims of harassment and died by suicide.

One of the three people whose suicide was tied to this forum is Near, a developer who was known for their work on the video emulator higan. I will not get into details about this specific story, but it's worth noting that Near had some common friends with Asahi Linux developers, and they are the ones who reported the suicide in the first place.

Kiwi Farms decided that they did not have enough proof of the death of Near, and began a harassment campaign against those Asahi Linux developers. They claimed they were lying and acting weirdly, and went on for months about this. When - finally - the death was confirmed, they claimed that Asahi Linux developers were "utterly incompetent" in providing information about it.

I mention this because this is what prompted Kiwi Farm users to start harassing Asahi Linux developers, even outside the scope of the death.
Most importantly - for this article, at least - is that they tried doxxing Asahi Lina, attempting to reveal her real identity. In all of the comment threads that I've mentioned - except for the Phoronix one, which I wasn't able to access - some users were sharing the name provided by Kiwi Farm, which - I think - is why the comments were locked and hidden away.
Now, I have reviewed the evidence that Kiwi Farm (and Reddit commenters) brought to the table, and it's circumstantial.
One thing they did is to pitch down the voice and compare speech patterns and accents. I have listened to the provided audio samples and I have not found the similarity to be that striking, but what do I know.

Other pieces of evidence include Asahi Lina and this other person having similar software configuration and hostname, and Asahi Lina showing a home folder with the name of the other person.

If I had to guess, I would say it's more likely than not that Kiwi Farm is right, but there's no hard proof and they've been wrong before anyway. Regardless, it seems like many platforms decided that it was enough to be considered doxxing, and restricted comments.
Now, in the past Asahi Lina had complained about attempts of Kiwi Farm to dox her. This quote comes from a document where Lina was clarifying her interaction with Luna, another VTuber (a long story in itself, but for another time).

This, finally, brings me to the reason I decided to still make this video in the first place: when I first encountered the doxing, I had no idea it came from a place like Kiwi Farm and sort of assumed it was correct. I was not the only one: I talked with other people who had read the thread, and they were also lacking this context.
Thus, I thought it was important to point out what's behind this type of information. They might even be correct for all we know, but they are brought up by people who specifically try to harass others and are even linked to some suicides. This has been, for me, a reminder of how important it is to be careful when handling these kinds of information publicly.
I've often been asked whether people could follow me on Bluesky, and the answer is no. I don't have that platform, and though I might join it in the future, I'd like to explain what makes me skeptical about it.
Bluesky as a company was born between 2022 and 2023, with a goal that shifted from building a protocol that Twitter could eventually use, to becoming its alternative and competitor to X.

Back then, ActivityPub - the protocol that powers the Fediverse, such as Mastodon - was already developed (obviously!) and had somewhat widespread usage amongst fans of decentralized systems.

However, Bluesky rejected the idea of using it (or bridging to it) and instead decided to build their own protocol, called AT proto. Why? Well, according to their documentation (we'll get back to this):
Account portability is a major reason why we chose to build a separate protocol. We consider portability to be crucial because it protects users from sudden bans, server shutdowns, and policy disagreements. Our solution for portability requires both signed data repositories and DIDs, neither of which are easy to retrofit into ActivityPub. The migration tools for ActivityPub are comparatively limited; they require the original server to provide a redirect and cannot migrate the user's previous data.

Now, I've never been particularly sold on this argument. When talking about social networks, having an interconnected web of users is a priority to be successful, and building your protocol is a great risk. Is it worth refusing to connect with an already-existing community because switching one account to another server is not a great experience? Still, we'll come back to this point.
Another major reason is scalability. ActivityPub depends heavily on delivering messages between a wide network of small-to-medium sized nodes, which can cause individual nodes to be flooded with traffic and generally struggles to provide global views of activity.

This sounds more reasonable, though I don't have the skills to know whether this is a satisfying explanation or not. Let's assume it is.
Thus, Bluesky started accepting users through an invite-only system in early 2023 and soon offered an Android application as well. It's worth noting that, back then, the social network was fully centralized and run by the Bluesky company, which promised federation and decentralization to come soon.

It did: in February 2024, they published a blogpost announcing that they were allowing users to federate. However, the federation system that the AT protocol proposes is quite different from ActivityPub's, and it's worth getting a bit technical about it to understand the differences.

On the Fediverse, everyone can run their own ActivityPub instance. This could be Mastodon, which looks like a Twitter competitor, but it could also be Pixelfed (more picture-oriented), or Peertube (video-oriented). If you sign up at one instance, you can still follow and interact with people on other instances; thus, the Fediveres is an interconnected web of decentralized ActivityPub instances, which you can sign up for.

Bluesky works differently. Each user has its data, which is hosted in a Personal Data Server, or PDS. That data is gathered by Relays, which then "output it in one big stream for other services to use". The data goes through labelers, which handle the moderation (more on that later), and is given to the AppView (which might be any third party application), which can use various Feed Generation algorithms to decide the order to show them it.

This is a very different architecture compared to the Fediverse. There's no such thing as single instances talking to each other (a "message passing" system), but instead, there's a "shared heap" where all content gets thrown together into Relays.
By default, all of these services are offered by the Bluesky company themselves. However, you can go ahead and host yourself pretty much any of these components that I've mentioned, which renders the system decentralized.
Or does it? Let's start with PDSs. Yes, this makes it much easier to self-host your data: you'd be able to do it even on a very cheap or potato server. However, this only allows you to self-host your data, whereas all social network aspects are handled elsewhere. If we want a federated network, we're more interested in the other components.
Which brings us to Relays. Quoting Christine Lemmer-Webber, a co-author of ActivityPub,
The physical world equivalent for a fully decentralized fediverse then is that every user sends mail to every other user's house, as needed, similar to how sending letters works in the physical world. This is decidedly not the case with a fully decentralized ATProto. The physical world equivalent would be that every user had their own house at which they stored a copy of every piece of mail delivered to every other user at their house.

Effectively, this means that each Relay is required to bring at least 5 terabytes of storage and a significant amount of system and network resources; and it would still only have part of the data that's in the public heap. This means that you might end up missing messages in a thread unless you also fetch data from a bigger Relay.

On top of that, Relays are going to host any kind of content that's posted in Bluesky, and it's their responsibility to filter off illegal material. This also gives them a high legal burden to uphold.

Thus, one year after announcing that Bluesky is federated, how many third-party Relays are there? According to SoftwareMill, the answer is none:
Currently, there's only one relay operated by Bluesky (the company); however, in theory, there might be multiple ones.

The required storage is also growing very quickly, and it will keep growing as more users join the network. This means that, in the long term, it will get harder and harder to create an independent Relay, to the point where only companies might be able to. And, until then, Bluesky will still be run de facto in a centralized way.

Even worse, I have not found any figure about the number of Personal Data Servers running independently, but the general idea is that almost all of them (probably more than 99%) are run by the Bluesky company. This gives them even more (again, de facto) power over its user base.
Now, I've mentioned that labeling (which includes moderation for content that should not be displayed) is also decentralized, as in, everyone can run their labeler. Of course, Bluesky also runs its central labeler.

I can see the appeal of this system; as an example, there's an "AI images detection" labeler that will, well, label AI images. You can opt-in to use that, which is cool.

What's less cool is that the Bluesky application hardcodes its labeling system; this means that, if you want to opt out of the Bluesky company moderation system, you have to build your independent application to do so.

This effectively means that, if you get banned by the Bluesky company, you're out. Sure, you could still host your own Personal Data Server, wait for a non-existent independent Relay to fetch your data and interact with users of third-party Bluesky applications. But you won't: you're effectively at the mercy of the Bluesky company.

You might argue that it's Bluesky's right to ban someone entirely from their servers if they want to, but that becomes a problem if (a) 99% of the infrastructure is run by them, and (b) it's hard to provide an independent alternative. Then, you're effectively a centralized system.
There are a few other problems as well. Firstly, all private messages between users are centralized; they go through the Bluesky servers, and there's no way to self-host that service. They don't even claim the DMs to be federated, they only hope that they'll be able to change that in the future.

Secondly, the ID mechanism, which assigns each user with a unique key to keep track of them, is also centralized. This is already too technical for me, but Bluesky currently offers two "Distributed ID" mechanisms, called did:web and did:plc, both of which are centralized and controlled by Bluesky.

I think this is particularly incriminating since the reason they wanted to provide an alternative to ActivityPub was to make it easier to transfer your data to "a different instance". I guess that's true since it's easy to self-host a PDS, but the ID that's associated to your data, and by which you're indexed by, is still centralized and controlled by them. In my opinion, that's worse than "it's hard to move data between instances".
Thirdly, Bluesky is unable to handle private information; everything is public on the giant heap. This does not include private messages, because - again - those go through a different centralized system, but it does include other information you'd prefer not to have public, such as who you blocked.

Overall, the Bluesky "federation" promise relies on two main points.
Point one: it's going to be decentralized later. When creating Bluesky, the most important thing was to provide a viable alternative to Twitter as soon as possible, and that meant moving quickly; yes, some parts of the network are still centralized, but they won't be in the future.
Fine; I therefore think it's fair for me to wait until then before starting to use Bluesky. I don't need a Twitter alternative now. Nonetheless, I'm still not sold on the fact that it was necessary to build a whole new protocol at all, instead of assuming ActivityPub could not scale enough to be a viable alternative.
Point two, and more importantly: this approach provides an "exit strategy" in the event that Bluesky "goes evil". Right now, that's false: parts of the social network are still centralized and it's impossible to avoid that. But even if we limit ourselves to PDSs and Relay, the current situation is that federation is only achievable in theory and no one has done it in practice yet.
On top of the (IMO!) flaws of the AT proto approach, I think it's important to highlight some benefits of ActivityPub that are not translated well over Bluesky.
Let's start with a personal story. A few months ago, I was running an activity to explain to some boys and girls how to use social networks safely. As part of that, I decided I wanted to run a "private" social network, that would only allow sign-ups from people I selected; I looked into self-hosting some sort of social network, and turns out it's a mess.
However, since Mastodon is quite known software, it's easy to find a service that will set up the server for you, at a very low price; you can also lock down a Mastodon instance to make sure it cannot interact with other instances, if necessary.
But if I wanted to go on, I could've made more instances for other groups of my organization, and all of these instances could've interacted between them. Even better, the younger generations aren't really that into Twitter-like socials anymore, but I could've just set up some Pixelfed instances to give them an Instagram-like experience.
And there still would've been room to grow; some activities require videos, so there could've been a Peertube instance as well to host those, and it still would've been completely interconnected with the others. All of this would still be run entirely by me, which is a requirement since I (legally) need to keep an eye on what these teens are doing and be able to step in immediately.
This is something that I could've done today, not potentially in the future. And honestly, it would not even have taken that much effort: I'm just a bit lazy.
And, if we talk about "potentially in the future", there's even more cool stuff that might happen over time. I'm a big fan of existing social networks federating with ActivityPub; I'm really happy that Threads made this choice, but there's WordPress as well, and even Ghost - the blog system that I use - is working towards that.
I'm also really happy that all of my videos are automatically uploaded to Peertube, and that people on Mastodon can follow my channel there and automatically get the videos on their feeds.
Ultimately, the Fediverse feels to me like a better alternative all-around. I think user onboarding should be improved somewhat; but, if you were to ask me which social network I'd recommend, I'm not going to pick Bluesky. Quite the opposite: I view it as a centralized social network that jeopardizes the future of the (IMO) better alternative, the Fediverse.
Nate Graham is widely known in the KDE world; he is a board member of the KDE e.V., the non-profit company that supports KDE development. He also writes the "This Week in KDE" blogposts, has done various interviews talking about KDE software, and so on.

Yesterday he has announced that he created a for-profit company that hire various KDE developers, and that will become a KDE e.V. Patron as well. The company is called Techpaladin, and it's co-owned by David Edmundson, another very public developer (who's also given interviews on KDE!).

On top of that, I'm happy to announce that I am one of the contractors of Techpaladin, and I'll be continuing my KDE Plasma development work with them. This might sound exciting, but - as usual - to understand the full scope of this news we need a few additional bits of context.
Firstly, both mine, Nate's, and David's previous employer was Blue Systems. BS is a German company that actively works (or, worked) on projects such as KDE Plasma, Netrunner OS, Plasma Mobile, Manjaro, KDE Neon, MAUI, the Calamares installer, and more.

Blue Systems was founded by the German businessman Clemens Tönnies Jr. If you just search that name this guy will pop up, and you'll discover that he own 46% of a meat processing industry, and has an estimated wealth of around 1.6B dollars. This is the senior Clemens, not the junior, who is his nephew.

Clemens Tönnies Jr. left the meat processing company by transferring his shares to the brother, and there's very few public information about him. He has given an interview back in 2012 to "golem [dot] de", and back then he was a 36 years old computer scientist and self-described philanthropist.

Clemens started sponsoring the KDE e.V. and, back then, even hired Johnathan Riddel, who packaged releases of Kubuntu, after Canonical discontinued support for that distribution.

In 2012, Blue Systems "had no business model, at least not yet". However, more recently, they had added Valve's SteamOS to the list of official collaborations; as I have previously covered on this channel, Valve had decided to sponsor KDE development work through Blue Systems, which led to many KDE developers becoming contractors for Blue Systems whilst sponsored by Valve.

As I - somewhat privately - announced a bit less than two years ago, this also included myself; I've been a contractor for Blue Systems, sponsored by Valve, for quite some time now.

To be clear, Blue System was not the only Valve-sponsored company. As another example, Igalia also had (and, I think, still has?) a contract to work on the graphic stack of the SteamDeck.

Yet another example is Collabora, who also briefly talked about their work with Valve regarding SteamOS:

But then, what happened to Blue Systems? According to Nate, about a dozen of Blue Systems' current people moved to the new Techpaladin company; this comes after six years of BS employing Nate.

The reason for the change is not stated, but according to Nate it has not been any kind of "hostile takeover", but rather a "mutual decision made between the owner of Blue Systems, myself and David Edmundson, and Blue Systems' other personell who are moving over".

We currently know that the company has more than a dozen contractors and employees "sread across 7 countries and 2 continents", plus a co-owner.

This is not the first time that Nate runs a company; he also talks about the fact that from 2011 through 2014 he had a two-person 3D printer company, named - hold for it - Techpaladin Printing. They sold parts and kits, and according to Nate, it was his first exposure to the Free and Open Source Software movement.

According to the Nate, TechPaladin also inherited the Valve contract that Blue Systems had, as their first (and currently, only) client. As they say on their webpage (or should I say, our webpage) "we're responsible for the user experience of the Steam Deck in desktop made".

Techpaladin seems to also be currently looking for other clients. As Nate says, if you see an awful bug that you're experiencing, you can get in touch and the company will help you sponsor that bug fix, or maybe a new feature, or any kind of custom development.

Most likely, Techpaladin is also looking for other corporate clients; following Valve example, other companies that use KDE Plasma on their hardware might benefit from paying Techpaladin to improve the desktop specifically for their devices.
Nate will be running the business, and he's also currently a KDE e.V. board member, but he plans to still publish This Week in Plasma, still do technical work, review other people's merge request, triage bug reports, and so on. So, the work is not stopping.

Really, what this means is that, from now on, the contract that Valve has to improve KDE Plasma is now in the hands of, well, KDE developers (Nate and David). It will be interesting to see how this company grows, and how it will maintain its relationship with the KDE e.V. non-profit.

And, if you know anyone who wants to sponsor some feature, or any company that needs KDE development of any kind, feel free to reach out to Techpaladin to get those things done!

They have also sent an email that explains that the affected programs are the Responsable Computing Challenge and Mozilla Common Voice, the latter of which is the largest open, crowd-sourced speech recognition dataset.

Now that I've been given the hat of the official "Mozilla Shill", I thought I might just as well dig a bit into how much this money exactly is and what it has been used.
Let's start with the narrative that's been built up by an infamous tech journalist who I shall not name here, and then I will clarify what's correct and what's wrong.
Firstly, he claims that the Responsible Computing Challenge is specifically funded by the USAID, which should account for $2.5M of the above-mentioned number.

He claims that the page that shares that USAID supports Mozilla is not findable through search engines, as a sign that Mozilla is probably trying to hide this through robot texts and such.

He then starts reading all the grants, focusing on the ones that sounds more "political", i.e., that focus most on social justice, inclusiveness, and marginalized groups – all in the context of computing and the internet, mind you.

He claims the money is also going towards in-person kick-off meetings with keynotes on critical race and gender studies, which are - of course - also presented as the evil in this world.

But why is Mozilla doing all of this now? Well - he claims - since the deal with Google that's giving them 80% of their revenue might be soon disappearing, they "need every couple millions they can get, which includes that of USAID".

He also wonders, at this point, if these taxpayer dollars are going to be funding the "most extreme ideological" Mozilla projects, such as a "feminist AI Alliance for Climate Justice"?

He also complains that all of this USAID income from the US government was not declared on their public finance documents, and thus, these shady ways of them receiving money were kept a secret until now.

I decided to bring up all of these points because I thought it would be useful to address them and show you how people try to intentionally mislead you into thinking that a nothingburger actually has any meat in it.
Let's start with what we know happened, to the best of our knowledge.
Firstly, the Common Voice project. This is a free and open source platform to collect scripted speech, spontaneous speech and language text, with the goal of developing technologies such as voice recognition or voice synth that are open source and based on a dataset of people who willingly gave their voices for the project.

This is a very worthy project, with parters that go from Germany, to the Bill & Melinda Gates Foundation to even NVIDIA - who is probably interested to such a public dataset.

Now, the Common Voice project has received $1M from the National Science Foundation in 2024.

The goal was to collect various kinds of languages and dialects within the US so that voice recognition software would be able to, well, recognize any of them instead of just a handful.

This would be done through open-source platforms and infrastructure to ensure public accessibility, and the program should ensure a good diversity of voices to allow voice recognition software to work on any dialect.

However, this grant has already been paid off by the NSF; thus, I'm not sure why it's being brought up at all by Mozilla. Maybe there could've been more grants in the future about this that won't materialize? It's hard to know. That said, this isn't USAID money, so let's move on.
The real deal is the Responsible Computing Challenge. This started in 2018 under the name of "Responsible Computer Science Challenge", and the goal was to "support the conceptualization, development, and piloting of curricula that integrates ethics with undergraduate computer science training".

The first round of funding indeed happened in 2018, and it was only privately funded. I quote:
With funding from Mozilla, Schmidt Futures, and Craig Newmark Philanthropies, awardees from the first round of RCS across the U.S. have created 100 distinct classes with more than 15,000 students.

This makes sense since the 2018 grantees were all U.S. based, and thus outside the scope of a program like USAID. Thus, we can safely assume that these programs did not use "taxpayer money" as claimed, and we can cross them off.

USAID came into play in 2022, and in the same year, the program changed its name to the "Responsible Computing Challenge" that we all know and love today. Between 2022 and 2023, they have announced the following:



In 2024, they also announced a total of $192K in grants towards South Africa, and awardees are supposed (or were supposed) to be nominated this year.

Not counting this latest fund, which has not been granted yet, we are left with just two cohorts funded by USAID: the 2023 India and Kenyan ones, for a total of $1.4M. Again, these have already been paid out (to the best of my knowledge), but let's roll with it.

To be clear, this $1.4M has never been even touched by Mozilla. Instead, the non-profit only acted as the organization that helped to raise proposals and find the judges to select them, and the money has been granted from USAID directly to the awardees – Mozilla got none of it.
Now, my thinking is that the funding at risk of being canceled by the new administration is the South African one. However, it might also be the case that even Indian and Kenyan funding was somehow not paid off yet; we can't know for sure unless Mozilla decides to share more info about these $3.5M that the government might not grant them.
Finally, if you were wondering why is the Mozilla Foundation doing all of this instead of developing Firefox, it means you haven't watched my - very helpful! - video about how Mozilla works.
The Mozilla Foundation does not develop Firefox. They are a non-profit organization that wants to "shape a healthier digital world", and they do so in various ways, such as by working towards grants to developing world countries regarding a healthier and more fair internet. The Mozilla Foundation does not receive money from Google, and they do not have a CEO.

What you're thinking about is the Mozilla Corporation, which is a different company entirely. They are a for-profit, they develop Firefox, they receive money from Google, and so on; they're also a subsidiary of the Foundation, but they are nonetheless a different entity that works on different things.

To recap: Mozilla Corporation, works on Firefox, has nothing to do with grants or USAID. Mozilla Foundation, is a non-profit that does not work on Firefox and instead works on grants, even USAID ones.
Now that I've hopefully cleared up what's happening between Mozilla and USAID exactly, let me go back and focus on the narrative that's been built by the above not-mentioned tech journalist.
Firstly, let's address the idea that Mozilla is somehow trying to hide its involvement with USAID. This is blatantly false. Firstly, the blogpost that I've shown you appears immediately when doing a Google search:

On top of that, this partnership with USAID has been very public since 2022; I've found countless articles promoting it publicly and even LinkedIn posts highlighting it. Nothing was ever hidden away, and a simple "USAID" search on the Mozilla blog gave me all the information I was looking for.

But why, then, is no USAID money declared on the Mozilla financial documents? Well, I can't know for sure, but maybe it's because - as I mentioned - Mozilla did not receive any money from USAID – they "merely" selected the organizations that would receive those grants. But, again, Mozilla didn't really touch that money.
But why was USAID used for such evidently left-wing programs in the first place? Well, it sort-of wasn't. What the journalist showed you were all U.S. based grants, which were not funded by USAID.

Again, only the Indian and Kenyan grants were funded by USAID, and those are much less "politicized". You can go to the Responsible Computing Challenge page and see for yourself: there's no scary words like social justice or diverse perspectives.

Finally, he claimed that the point of these programs was to gain as much money as possible in the event of Google stopping their funding. Now, even setting aside that these programs are about the non-profit Mozilla Foundation - whereas the Google money flows to the for-profit Mozilla Corporation - again we're missing the fact that Mozilla is not receiving anything (as far as we know) out of these grants. Why would you try to turn a profit from something you don't get any money from?
Of course, the idea that this money is then used for entirely unrelated political events like the AI feminist meetup is completely made up. Not only does Mozilla not touch the money, but the awardees of these grants are clearly outlined in the webpage. If you take something completely unrelated and say, "ooh, maybe this is also funded by USAID, for all we know!" then you're just lying.

Now, to be clear, if you're a right-wing conservative person, you're still probably going to be angry about the fact that USAID was sponsoring Kenyan and Indian programs about ethical computing; I disagree, but you do you. The point here is that the very shallow investigation from this journalist, on top of his intentionally misleading framing of the facts, leads you to hold factually incorrect information, like the idea that Mozilla receives USAID money.
But it doesn't.
We only run on donations. We have a goal of reaching 300 subscriptions, which would allow us to hire staff.
If you subscribe, you'll gain access to a few members-only pieces, though we aim to keep most of our content free for all.
no ads · no trackers · cancel whenever