RFC : DRAFT - Proposal for Fedora Privacy SIG #21

Open
opened 2026-08-22 17:57:54 +00:00 by q5sys · 4 comments
Owner

Draft posted her: https://forge.fedoraproject.org/security/tickets/src/branch/main/drafts/Privacy-SIG-proposal

Feel free to make suggestions for alterations in this ticket, or by PR.

Draft posted her: https://forge.fedoraproject.org/security/tickets/src/branch/main/drafts/Privacy-SIG-proposal Feel free to make suggestions for alterations in this ticket, or by PR.
Owner

We could add that we can also do some things. Presenting something tangible we can do other than just discussing might be useful and promising for some audiences. Such as packaging privacy-improving packages (I would not add specific examples though).

This text seems to be not only an elaboration for the wiki but intended to be presented to a specific audience. I assume this is intended to be presented at Discourse and the wiki elaboration to be derived from it?

Another question will be if we need a tag in discourse and if it shall be a sub-tag of security, though that is a minor question that can be tackled later...

We could add that we can also do some things. Presenting something tangible we can do other than just discussing might be useful and promising for some audiences. Such as packaging privacy-improving packages (I would not add specific examples though). This text seems to be not only an elaboration for the wiki but intended to be presented to a specific audience. I assume this is intended to be presented at Discourse and the wiki elaboration to be derived from it? Another question will be if we need a tag in discourse and if it shall be a sub-tag of security, though that is a minor question that can be tackled later...
Owner

For the record, this is the result of last meeting's agreement [1] concerning the ff-disable-ai-ml topic on the agenda back then.

For the record, this is the result of last meeting's agreement [[1]](https://meetbot.fedoraproject.org/meeting-3_matrix_fedoraproject-org/2026-08-20/security-sig.2026-08-20-15.00.log.html) concerning the [ff-disable-ai-ml](https://github.com/py0xc3/ff-disable-ai-ml) topic on the agenda back then.
Owner
This has been discussed during today's meeting (first topic) with some incentives to be further developed, and see where this is going to: https://meetbot.fedoraproject.org/meeting-3_matrix_fedoraproject-org/2026-09-03/security-sig.2026-09-03-15.00.log.txt https://meetbot.fedoraproject.org/meeting-3_matrix_fedoraproject-org/2026-09-03/security-sig.2026-09-03-15.00.log.html https://meetbot.fedoraproject.org/meeting-3_matrix_fedoraproject-org/2026-09-03/security-sig.2026-09-03-15.00.txt https://meetbot.fedoraproject.org/meeting-3_matrix_fedoraproject-org/2026-09-03/security-sig.2026-09-03-15.00.html
Owner

The suggested, more narrowed scope of the last meeting (details in the meeting logs) received positive resonance, so I refined it a little and add it here for further refinements and optimizations, I expect it's possible to simplify / shorten it:

Scope & activities of the Privacy SIG:

  1. privacy-related packaging,
  2. analyzing packages for privacy issues (e.g., when raised/reported by someone in a ticket),
    2.1) report packages (up to Council level) if they are not compliant or compatible to Fedora codes, agreements, guidelines or its charter, and/or
    2.2) provide counter-packages to mitigate or bypass privacy issues and, if applicable, lobby to have them adopted by default on applicable Fedora variants
  3. maintain a list of packages (or even Fedora variants, if applicable) that have privacy issues.

Privacy issues are transporting data off the system without explicit user consent if that data cannot be proven to be incapable to identify a person or entity in any circumstances. However, it does not consider data that is necessary to provide software/package updates or the type of data people reveal already when opening any website in a browser.

Legal perspectives and legal compliance evaluation are out of scope for the Privacy SIG.

The suggested, more narrowed scope of the last meeting (details in the meeting logs) received positive resonance, so I refined it a little and add it here for further refinements and optimizations, I expect it's possible to simplify / shorten it: > Scope & activities of the Privacy SIG: > 1) privacy-related packaging, > 2) analyzing packages for privacy issues (e.g., when raised/reported by someone in a ticket), > 2.1) report packages (up to Council level) if they are not compliant or compatible to Fedora codes, agreements, guidelines or its charter, and/or > 2.2) provide counter-packages to mitigate or bypass privacy issues and, if applicable, lobby to have them adopted by default on applicable Fedora variants > 3) maintain a list of packages (or even Fedora variants, if applicable) that have privacy issues. > > Privacy issues are transporting data off the system without explicit user consent if that data cannot be proven to be incapable to identify a person or entity in any circumstances. However, it does not consider data that is necessary to provide software/package updates or the type of data people reveal already when opening any website in a browser. > > Legal perspectives and legal compliance evaluation are out of scope for the Privacy SIG.
Sign in to join this conversation.
No labels
meeting
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
security/tickets#21
No description provided.