But if you think that "passive" political action (i.e just being present at a rally, not being a speaker) outside a community should not have consequences inside the community, i think i agree with you (for now, i don't have put much thought into it, my opinion is not definitive).
I think for most people, the lines are determined by the magnitude of the crime, but where those lines lie is a personal and communal preference. At what point is an injustice so great that it cannot be overlooked even in different contexts? And at what point is it so great that it cannot ever be redeemed in thr future?
No, but what does pedophila or rape have to do with software? You don't let convicted child molesters hang out with kids for obvious causal reasons but no such relationship exists with software.
Setting aside the question of "should Internet have reacted like it did" - the reality is that her employer had little choice, given the circumstances. Yes, it was "outside-the-community behaviour", but the business impact was immediate & considerable, I argue that for the employer there was only one reasonable/rational way to handle the crisis.
[edit] Or to take a somewhat extreme hypothetical example - I presume that if you found out that, for whatever reason, a prominent Mozilla exec was secretly funding anti-Net-Neutrality lobby (i.e "out of the community behaviour"), you would expect Mozilla to talk about it and "handle the issue", not just say that "sorry, his own money, his own personal time, he can do whatever he wants to".
What if you find out that the other other person supports strong enforcement of existing immigration laws? What if supporters of that policy are being labeled as a "white nationalists" by others? Is that really evidence of "white nationalism"? What if that person simultaneously supports significant changes to the immigration laws that would result in more legal immigration?
If the answer is no, I would kick them out just the same and that's ok.
People who are actively sharing white supremacist screed are not nearly in the same category.
Ex-cons have a shitty past. White supremacists are currently and actively shitty.
Here's an example situation: you know that a person trying to join a project related to managing money has a history of defrauding employers, starting mlm/Ponzi schemes, scamming people, selling personal information. Do you let them get involved with the project and wait until any problem occurs, because all the problems so far were caused outside of this community?
Exactly - a lack of trustworthiness can be demonstrated long before any crime has been committed.
> And how do you rehabilitate them without giving them the opportunity to participate in the community?
Your use of 'community' in this argument precludes there being an inside and outside, so it is not relevant to the question posed in the article's title. Furthermore, there is an answer - rehabilitation starts in environments where the risk is limited.
Authoritarian liberals seem to forget that what goes around, comes around.
I care about the security and correctness of the code. I only care about the author who wrote it if they are someone known for low-quality, insecure, or malicious code.
If Linus Torvalds is convicted of genocide and child abuse tomorrow I'm going to continue using Linux as usual.
If you're part of a group and a chunk of them decide to leave, there's no point saying "why do you care about X? It doesn't affect the group."
It's their right to leave.
The other side is that who you associate with defines that group. So if it was a murderer that wrote a file system, then the software project gets defined by that.
It becomes hard to attract contributors when the project gets defined by the actions of one of its participants. Project leaders then have to make a decision since inaction is also a decision.
There is a point where the shaming and shunning stops being useful and becomes bullying.
We see this all the time in politics worth people liking "their team" too much and denigrating normal citizens just for their opinions and choices.
I'm unaware of anyone ever making a decision about contributing to a software project based on secret police level surveillance of current team members political or religious opinions. Even classified DoD stuff I've been involved in isn't that creepy.
Its important to focus discussion on extremes such as murders when the actual goal is to make sure Republicans are unemployable.
I would not give their contributions extra attention (you should be suspect of all changes, regardless of the author) and I would not ban them from contributing unless they became disruptive or subversive to the project.
They served their time; you don't need to punish them further. They are probably even less likely to commit fraud when their employer is aware of a previous fraud conviction.
The worst fraudsters don't come with a "convicted of fraud" warning—they have evaded being caught and will seem just like any other contributor.
It is not about punishing them, it is about reducing the risk of others. Having served time is, at best, no indication of whether a person will revert to their former behavior.
> The worst fraudsters don't come with a "convicted of fraud" warning—they have evaded being caught and will seem just like any other contributor.
This is no reason for not using what information you do have.
Note: I see that you have edited your original post to address these points, but I think they still stand, as expanded on in the continuing discussion below. Your statement "they are probably even less likely to commit fraud when their employer is aware of a previous fraud" seems to be in agreement with what I have been saying.
- Small (and well scrutinized) patches from this person are fine
- At some point forgiveness is due, maybe 3 years is at that point depending on the severity of their backdoor