Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. I didn't want to be break this story over here but since no one else seems to be posting about it here I am sharing a screenshot from the other side with @scan's post.

I didn't want to be break this story over here but since no one else seems to be posting about it here I am sharing a screenshot from the other side with @scan's post.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
129 Indlæg 45 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • liaizon@social.wake.stL liaizon@social.wake.st

    Soooooo @Mastodon is using @OpenSourceCollective as their fiscal host...

    https://opencollective.com/mastodon

    liaizon@social.wake.stL This user is from outside of this forum
    liaizon@social.wake.stL This user is from outside of this forum
    liaizon@social.wake.st
    wrote sidst redigeret af
    #54

    RE: https://mastodon.social/@poohlaga/116218374295960280

    the Executive Director of @OpenSourceCollective replied:

    liaizon@social.wake.stL 1 Reply Last reply
    0
    • opsocket@mamot.frO opsocket@mamot.fr

      @liaizon what's up @Betree ?

      betree@framapiaf.orgB This user is from outside of this forum
      betree@framapiaf.orgB This user is from outside of this forum
      betree@framapiaf.org
      wrote sidst redigeret af
      #55

      @opsocket @liaizon copy-pasting the reply I've made on the Github issue:

      We (opencollective.com) are agnostic to the KYC provider that fiscal hosts use. Our integration was built primarily as a manual KYC tool, and you can use any backend you want - or even run your own program.

      betree@framapiaf.orgB opsocket@mamot.frO 2 Replies Last reply
      0
      • betree@framapiaf.orgB betree@framapiaf.org

        @opsocket @liaizon copy-pasting the reply I've made on the Github issue:

        We (opencollective.com) are agnostic to the KYC provider that fiscal hosts use. Our integration was built primarily as a manual KYC tool, and you can use any backend you want - or even run your own program.

        betree@framapiaf.orgB This user is from outside of this forum
        betree@framapiaf.orgB This user is from outside of this forum
        betree@framapiaf.org
        wrote sidst redigeret af
        #56

        @opsocket @liaizon

        We're indeed adding a persona integration on the platform to help Open Source Collective manage their KYC program. It is not something we're forcing on anyone, just a bridge we're creating for fiscal hosts relying on this service.

        For the rest, I'll let Open Source Collective comment.

        They're aware of this thread and are preparing a reply as we speak.

        li@tech.lgbtL 1 Reply Last reply
        0
        • liaizon@social.wake.stL liaizon@social.wake.st

          RE: https://mastodon.social/@poohlaga/116218374295960280

          the Executive Director of @OpenSourceCollective replied:

          liaizon@social.wake.stL This user is from outside of this forum
          liaizon@social.wake.stL This user is from outside of this forum
          liaizon@social.wake.st
          wrote sidst redigeret af
          #57

          RE: https://framapiaf.org/@Betree/116218444650414138

          the developer who is currently adding this Persona integration into @opencollective has replied to this thread here:

          malte@anticapitalist.partyM irishmasms@defcon.socialI 2 Replies Last reply
          0
          • betree@framapiaf.orgB betree@framapiaf.org

            @opsocket @liaizon copy-pasting the reply I've made on the Github issue:

            We (opencollective.com) are agnostic to the KYC provider that fiscal hosts use. Our integration was built primarily as a manual KYC tool, and you can use any backend you want - or even run your own program.

            opsocket@mamot.frO This user is from outside of this forum
            opsocket@mamot.frO This user is from outside of this forum
            opsocket@mamot.fr
            wrote sidst redigeret af
            #58

            @Betree @liaizon I just read it, thanks for trying to shed some light here

            1 Reply Last reply
            0
            • liaizon@social.wake.stL liaizon@social.wake.st

              Soooooo @Mastodon is using @OpenSourceCollective as their fiscal host...

              https://opencollective.com/mastodon

              nextgraph@fosstodon.orgN This user is from outside of this forum
              nextgraph@fosstodon.orgN This user is from outside of this forum
              nextgraph@fosstodon.org
              wrote sidst redigeret af
              #59

              @liaizon @OpenSourceCollective another I never liked about open collective is that they store all their data on AWS in the US, unencrypted. that means all the fiscal data, invoices, payment details, of all their users, including all collectives using their online platform. as open collective is difficult to self host, everybody uses their website. when i asked for more details, they said they are a US based organisation, that they won't care, and that GDPR does not apply to them. i stop using it

              betree@framapiaf.orgB 1 Reply Last reply
              0
              • liaizon@social.wake.stL liaizon@social.wake.st

                RE: https://framapiaf.org/@Betree/116218444650414138

                the developer who is currently adding this Persona integration into @opencollective has replied to this thread here:

                malte@anticapitalist.partyM This user is from outside of this forum
                malte@anticapitalist.partyM This user is from outside of this forum
                malte@anticapitalist.party
                wrote sidst redigeret af
                #60

                @liaizon @opencollective i don't understand any of this. is this one second away from them implementing a persona *killswitch*, and debating what "persona" actually *means*?

                liaizon@social.wake.stL 1 Reply Last reply
                0
                • liaizon@social.wake.stL liaizon@social.wake.st

                  @poohlaga hi Lauren, sorry to make your acquaintance on such an unpleasant matter. While I am glad to hear that you are using them only in "rare edge cases" it seems that their API is getting directly integrated into Open Collective's code base (https://github.com/opencollective/opencollective-frontend/pull/11988)

                  I think for the present moment there needs to be a very clear statement about *exactly* how you are using Persona and what data and what edge cases would end up triggering you to initiate sending *any data* to their API.

                  poohlaga@mastodon.socialP This user is from outside of this forum
                  poohlaga@mastodon.socialP This user is from outside of this forum
                  poohlaga@mastodon.social
                  wrote sidst redigeret af
                  #61

                  @liaizon Yes, I have a draft response on how we intend to use the platform connection, but I'd like the engineers to review it for accuracy, as the feature is still in development.
                  I will say it was fundamental for us that any personal data entered in Persona remain in Persona and any user information on the platform remain on the platform. We are not passing any user data from the platform to Persona. And if a user elects not to do our KYC with Persona, then we do our best to find another way.

                  liaizon@social.wake.stL saucerlost@mastodon.socialS fluffykittycat@furry.engineerF 3 Replies Last reply
                  0
                  • malte@anticapitalist.partyM malte@anticapitalist.party

                    @liaizon @opencollective i don't understand any of this. is this one second away from them implementing a persona *killswitch*, and debating what "persona" actually *means*?

                    liaizon@social.wake.stL This user is from outside of this forum
                    liaizon@social.wake.stL This user is from outside of this forum
                    liaizon@social.wake.st
                    wrote sidst redigeret af
                    #62

                    @malte which part don't you get? why they are shooting them selves in the foot?

                    malte@anticapitalist.partyM 1 Reply Last reply
                    0
                    • liaizon@social.wake.stL liaizon@social.wake.st

                      @malte which part don't you get? why they are shooting them selves in the foot?

                      malte@anticapitalist.partyM This user is from outside of this forum
                      malte@anticapitalist.partyM This user is from outside of this forum
                      malte@anticapitalist.party
                      wrote sidst redigeret af
                      #63

                      @liaizon what this "bridge" is, and who the hosts are that potentially need a kyc-persona. i'm lost when people start using abbreviations, and i'm doubly lost when they shroud those abbreviations in vague abstractions.

                      benjaoming@social.data.coopB 1 Reply Last reply
                      0
                      • liaizon@social.wake.stL liaizon@social.wake.st

                        @poohlaga hi Lauren, sorry to make your acquaintance on such an unpleasant matter. While I am glad to hear that you are using them only in "rare edge cases" it seems that their API is getting directly integrated into Open Collective's code base (https://github.com/opencollective/opencollective-frontend/pull/11988)

                        I think for the present moment there needs to be a very clear statement about *exactly* how you are using Persona and what data and what edge cases would end up triggering you to initiate sending *any data* to their API.

                        poohlaga@mastodon.socialP This user is from outside of this forum
                        poohlaga@mastodon.socialP This user is from outside of this forum
                        poohlaga@mastodon.social
                        wrote sidst redigeret af
                        #64

                        @liaizon Regarding edge cases, the most common are when we are unable to verify the payee's identity or when they are in a jurisdiction flagged by US sanctions. Roughly .005% of expenses each month are flagged. Additionally, for each flagged expense, we communicate what is blocking us from moving the payment forward and offer alternatives so we can resolve the issue in a way the payee also feels comfortable with.

                        li@tech.lgbtL 1 Reply Last reply
                        0
                        • poohlaga@mastodon.socialP poohlaga@mastodon.social

                          @liaizon @scan Hi, Lauren here. I'm the ED of OSC and happy to chat. In this expense, the payee was presented with options that would not require a KYC with Persona; they confirmed, so we will be able to pay them through this method. KYC's are a rare edge case for us and are not issued on all expenses.
                          I will publish a general statement on the OSC updates page - but yes. We started using Persona before the news broke. We are currently looking for non-US providers and are open to suggestions.

                          wcbdata@vis.socialW This user is from outside of this forum
                          wcbdata@vis.socialW This user is from outside of this forum
                          wcbdata@vis.social
                          wrote sidst redigeret af
                          #65

                          @poohlaga @liaizon @scan As a USian, I'd strongly recommend you get the org off any Thiel-connected platform and tools that share data with law enforcement without a valid judicial warrant.

                          poohlaga@mastodon.socialP 1 Reply Last reply
                          0
                          • poohlaga@mastodon.socialP poohlaga@mastodon.social

                            @liaizon Yes, I have a draft response on how we intend to use the platform connection, but I'd like the engineers to review it for accuracy, as the feature is still in development.
                            I will say it was fundamental for us that any personal data entered in Persona remain in Persona and any user information on the platform remain on the platform. We are not passing any user data from the platform to Persona. And if a user elects not to do our KYC with Persona, then we do our best to find another way.

                            liaizon@social.wake.stL This user is from outside of this forum
                            liaizon@social.wake.stL This user is from outside of this forum
                            liaizon@social.wake.st
                            wrote sidst redigeret af
                            #66

                            @poohlaga the statement "We are not passing any user data from the platform to Persona" makes no sense in this context. You are integrating Persona's API into the platform. You are paying money to Persona to process the personal data of people on Open Collective. Why are you even considering using Persona at all? Using them is antithetical to every point that Open Source Collective lists in your "Values"

                            poohlaga@mastodon.socialP 1 Reply Last reply
                            0
                            • liaizon@social.wake.stL liaizon@social.wake.st

                              Because of Open Collective's belief in transparency, you can see directly how much @OpenSourceCollective is paying to use Persona and when those payments started:

                              https://opencollective.com/opensource/transactions?searchTerm=persona&kind=ALL

                              liaizon@social.wake.stL This user is from outside of this forum
                              liaizon@social.wake.stL This user is from outside of this forum
                              liaizon@social.wake.st
                              wrote sidst redigeret af
                              #67

                              hey @Wtebbens have you seen this thread? seeing as you just set up a fiscal host on Open Collective and have been talking about the need to move away from Big Tech I would think chiming in, in this situation would be useful

                              wtebbens@social.coopW 1 Reply Last reply
                              0
                              • liaizon@social.wake.stL liaizon@social.wake.st

                                Open Collective is adding KYC from Peter Thiel backed Persona. If you are not familiar with Persona: https://www.openrightsgroup.org/press-releases/roblox-reddit-and-discord-users-compelled-to-use-biometric-id-system-backed-by-palantir-co-founder-peter-thiel

                                Here is the github issue where its being worked on:
                                https://github.com/opencollective/opencollective/issues/8609

                                jdp23@neuromatch.socialJ This user is from outside of this forum
                                jdp23@neuromatch.socialJ This user is from outside of this forum
                                jdp23@neuromatch.social
                                wrote sidst redigeret af
                                #68

                                @liaizon yikes! thanks for getting the word out about this!

                                liaizon@social.wake.stL 1 Reply Last reply
                                0
                                • jdp23@neuromatch.socialJ jdp23@neuromatch.social

                                  @liaizon yikes! thanks for getting the word out about this!

                                  liaizon@social.wake.stL This user is from outside of this forum
                                  liaizon@social.wake.stL This user is from outside of this forum
                                  liaizon@social.wake.st
                                  wrote sidst redigeret af
                                  #69

                                  @jdp23 your welcome, I wish I didn't have to be in the position to be posting about this at all. But open collective is super important as a funding source and the one that so much of the fediverse relies on. I think we really need to convince them to change course on this.

                                  1 Reply Last reply
                                  0
                                  • liaizon@social.wake.stL liaizon@social.wake.st

                                    RE: https://social.wake.st/@liaizon/116206925371202010

                                    I didn't want to be break this story over here but since no one else seems to be posting about it here I am sharing a screenshot from the other side with @scan's post.

                                    ohir@social.vivaldi.netO This user is from outside of this forum
                                    ohir@social.vivaldi.netO This user is from outside of this forum
                                    ohir@social.vivaldi.net
                                    wrote sidst redigeret af
                                    #70

                                    @liaizon @scan
                                    > you can see directly how much @OpenSourceCollective is paying to use Persona

                                    I am more interested in the reverse flow. As I just can not imagine someone within the FLOSS environment did not due dilligence about "third party contribution". The first page of nojs DDG search is full of "persona" warnings so it flashes.

                                    1 Reply Last reply
                                    0
                                    • poohlaga@mastodon.socialP poohlaga@mastodon.social

                                      @liaizon Regarding edge cases, the most common are when we are unable to verify the payee's identity or when they are in a jurisdiction flagged by US sanctions. Roughly .005% of expenses each month are flagged. Additionally, for each flagged expense, we communicate what is blocking us from moving the payment forward and offer alternatives so we can resolve the issue in a way the payee also feels comfortable with.

                                      li@tech.lgbtL This user is from outside of this forum
                                      li@tech.lgbtL This user is from outside of this forum
                                      li@tech.lgbt
                                      wrote sidst redigeret af
                                      #71

                                      @poohlaga @liaizon hello yes just dont comply with sanctions thanks

                                      1 Reply Last reply
                                      0
                                      • liaizon@social.wake.stL liaizon@social.wake.st

                                        @poohlaga the statement "We are not passing any user data from the platform to Persona" makes no sense in this context. You are integrating Persona's API into the platform. You are paying money to Persona to process the personal data of people on Open Collective. Why are you even considering using Persona at all? Using them is antithetical to every point that Open Source Collective lists in your "Values"

                                        poohlaga@mastodon.socialP This user is from outside of this forum
                                        poohlaga@mastodon.socialP This user is from outside of this forum
                                        poohlaga@mastodon.social
                                        wrote sidst redigeret af
                                        #72

                                        @liaizon Not antithetical at all. If someone chooses to not do the KYC with Persona, we respect their privacy and will offer other solutions. And no, we are not passing any user data to Persona. The integration is only intended for us (fiscal host admins) to copy/paste the persona inquiry ID into a reference field in the OC platform to make it easier for us to link into Persona later to check on the verification status. That's it. The ID# and the status is all we bring from Persona to OC.

                                        poohlaga@mastodon.socialP blogdiva@mastodon.socialB 2 Replies Last reply
                                        0
                                        • poohlaga@mastodon.socialP poohlaga@mastodon.social

                                          @liaizon Not antithetical at all. If someone chooses to not do the KYC with Persona, we respect their privacy and will offer other solutions. And no, we are not passing any user data to Persona. The integration is only intended for us (fiscal host admins) to copy/paste the persona inquiry ID into a reference field in the OC platform to make it easier for us to link into Persona later to check on the verification status. That's it. The ID# and the status is all we bring from Persona to OC.

                                          poohlaga@mastodon.socialP This user is from outside of this forum
                                          poohlaga@mastodon.socialP This user is from outside of this forum
                                          poohlaga@mastodon.social
                                          wrote sidst redigeret af
                                          #73

                                          @liaizon and again, it's the user's choice, and they can always opt out.

                                          li@tech.lgbtL 1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper