Advice from Denise
May. 29th, 2023 03:16 amComments on
chestnut_pod's post:
(link)
tei:
synecdochic (also
denise, fwiw):
(link)
tei:
synecdochic:
(link)
synecdochic:
(link)
synecdochic:
Comments on
synecdochic's post:
(link)
zz9pzza:
(link)
synecdochic:
(link)
Thank you! I'm surprised that you were never consulted or involved in it-- I guess I assumed AO3's abuse toolkit was modeled more closely on LJ/DW, since that's where most of the AO3-type content used to be...
I've offered multiple times. The only time anyone contacted me about any of those offers was during the "CSAM being emailed to volunteers" incident, at which point it immediately became extremely clear the person in question was more interested in protecting the external reputation of the organization than in listening to any advice I had to give and the only reason they'd contacted me was to pressure me to remove my Twitter thread talking about steps volunteers could take to protect themselves. Because I apparently enjoy beating my head against a brick wall and I feel really fucking bad for the volunteers who keep getting fed into the meatgrinder that is the OTW's repeat organizational failures, I continue offering, but given that it has taken me about six tries to type up this comment without devolving into incoherent spluttering about how incandescently furious I am at their repeated organizational failures and the harm that they've repeatedly caused volunteers, I suspect that they have correctly identified that my advice would be to burn it to the ground and start over and they don't particularly want to deal with someone who will say so without softening the language they have rightfully earned.
(link)
Yeah. Someone on my rlist linked this thread https://fail-fandomanon.dreamwidth.org/595253.html?thread=3645324085#cmt3645324085 recently, which is a former PAC volunteer who ended up doing a lot of CSEM work— and I'm pretty sure I know who this is and that they ended up being kind of a "if you think you have a CSEM ticket, send it right over to x!" person. Which didn't and doesn't seem to me like a reasonable way to distribute that work— I would have been fine with doing that kind of work if it were delegated to me in an organized way, but not with... joining in on that kind of setup.
Which you're right, is hopeful in the sense that the material that makes up the workload doesn't necessarily present an intractable problem! There are people willing and able to handle it given the right conditions.
There are absolutely, 100% a number of best-practice ways to mitigate the worst of the psychological toll that moderating even visual CSAM takes on people. If AO3 is getting more-than-occasional reports of actual "there is visual CSAM embedded in this work" enough that PAC had a designated "this person handles CSAM" (ie, not "this underage fic is CSAM", and if that volunteer was dealing with NCMEC, then it sounds like they were), and they haven't implemented any of the industry standard best practices like PhotoDNA scanning and "convert the image to black and white, blur it, and display it upside-down in the ticketing system" I am genuinely and sincerely horrified.
(link)
Like, as in, we-as-in-DW have gotten significant pushback from OTW defenders that has caused us to drop certain feature plans in the past because "why are you doing this thing that will overlap with AO3, you evil for profit company" and I do not have the energy to deal with it. It's warping the entire space.
...
To be suuuuuper clear so that people don't misread or misrepresent me: this attitude has never been expressed to us from OTW leadership (and I don't know whether or not the people who have expressed it to us have even been members of the OTW). But it's a fairly frequent response when certain features are discussed, in a way that's qualitatively different from the "you're just trying to make Site A behave like Site B and if I wanted Site B I'd be on Site B" reaction that's extremely common whenever you propose a potential feature that's even slightly associated with Site B in people's minds.
(link)
I don't think that talking about working conditions and environment for PAC is a derail from the topic of racist harassment at all, because in order for a site to deal effectively with racist harassment (or any harassment at all), the people who are handling Trust and Safety need to be empowered to make decisions based on the individual case before them and the totality of the circumstances involved. Organizational failures on this level (and again, let me reiterate that this is a stunning organizational failure) lead to a T&S team that is demoralized, disempowered, and unable to handle the blatant instances of abuse that they see going on right in front of them because their hands are completely tied.
This actually relates to an ongoing discussion I've been participating in on Bluesky, about how Trust and Safety needs to adapt to the actual ways in which a service is being abused, and the topic over there has also been racist harassment -- in this case, discussing Bluesky not removing a racist dogwhistle account for several days. Unfortunately, Bluesky doesn't make it possible to link to content unless you have an account on the site (which is still in beta and invite-only), but the gist of it is that a service has to empower their T&S team to make decisions based on the totality of the circumstances, because people engaging in organized harassment -- racially motivated or not! -- and people who are trying to radicalize people into extremism are creative, adaptable, and looking to constantly push the boundaries of content and conduct policy. They will find the things that are not explicitly prohibited by the existing policy, and they will stay just one tiny bit back from the line, and they will do everything they can to harass their victims while remaining within the boundaries of technicalities. In order to effectively deal with them, you need to be able to say "your deliberate, systemic efforts to push the boundaries of acceptable conduct is, itself, a violation of the Terms of Service" and get rid of them. You don't need to empower every single one of your T&S agents to make that call, but your team needs to have someone -- and it needs to be someone who is an active member of the team who takes reports regularly and can see the patterns at play -- who can look at that pattern of behavior and is empowered to say "you know what, I was not fucking born yesterday, this systemic boundaries testing is itself a hostile act" and remove the account.
From what I have seen PAC volunteers, current and former, discussing, there is no person on PAC who is empowered to make that decision, and I've seen unverified reports that Legal's position is that they cannot allow anyone on PAC to make that decision because it would require a change to the ToS to change enforcement policies. That is absolutely the fundamental reason AO3 is having a problem with racist harassment: because PAC is not given the authority to handle the racist harassment and because the working conditions and environment are so miserable that they don't have the time and energy to effectively advocate for the ability to say "come the fuck on, I was not fucking born yesterday" to someone with a userpic of a swastika and a username of I-Love-Hitler leaving racist comments and then dirty deleting them.
...
And it's not just because that's important to the psychological health and well-being of the people doing the work -- although it does, and that's important -- but also because Trust and Safety work is incredibly variable and you need to be able to make decisions very quickly and based on the totality of the circumstances. People who are stressed out, disempowered, and demoralized can't do that, and that's how you get cases of blatant but complex abuse taking forever to get a response while the simple and objective things like "does this author's notes link to their ko-fi" get handled immediately: the team is so burned out and overwhelmed that just looking at the more complicated issues makes them want to throw up, so they go and handle five dozen low-priority "this person's fic is linking to their ko-fi" reports just to get the absolute numbers down instead of the one sprawling complex case of racist harassment that's been sitting for three months because it will take 15 hours to untangle the whole sockpuppet network and then the T&S agent can't do anything about it anyway because they've managed to find yet another edge case that isn't explicitly covered by the content policy and nobody has the ability to say "yeet it anyway".
Part of that is human nature -- we get satisfaction from "number go down" and even on a fully paid team where people are assigned work, the more complex stuff will sometimes sit. (Like, right now, I am typing comments in this entry instead of making a decision on a non-urgent edge case I've been dithering about for a while: because it's non-urgent and not time-sensitive, but it is complex and involves clarifying some policy stuff, I'm procrastinating on it hardcore and have been for ages.) But when the work that needs to be done is an ocean and all you have is a thimble, and you know you can't do anything with all of the really shitty stuff that people are actually getting hurt by and just thinking about those tickets makes you want to puke, you need to feel like you're doing something so hey: I can look at this author's note and there is zero question about whether there's a Ko-Fi link in it or not.
The OTW has built a system where the most trivial issues will get handled quickly because their T&S team has their hands completely tied on the big ones and they need to feel like they're doing something about the overall volume. Hearing people from PAC talk about their experiences has made the entire problem they're having with racist harassment being unaddressed make 100% crystal clear sense.
Comments on
(link)
Our primary datastore is a mysql database, we have 3 primary servers and 2 secondary servers. We make a full backup of each of the machines weekly on different days of the week. We store binlogs on the primary server for 90 days, which I felt at the time was more than enough for any emergency. Given the comments here I am happy to change the retention of the bin logs to 120 days on the primary database servers. Note the failed full backups at the start of the year when we were having issues. However you can see a full backup did succeed...
(link)
James, I have the utmost confidence in your technical skills and abilities and the work you do for AO3, and I have zero doubt that AO3 follows all best practices for backup, retention, rotation, storage, etc. But that's a different purpose than the data retention and preservation requirements of 2258(A)(h), and the Unix and MySQL tools for data backup and integrity are not the tools you need for preserving user data and metadata in a fashion that complies with the law and allows you to provide information in a forensically verifiable fashion.
You should not personally have to guess at what data backup and retention settings are necessary in order to comply with the organization's legal obligations. You should not personally be in a position where, if AO3 receives a subpoena from law enforcement that results from a report to NCMEC, you will need to grab or provision a spare machine, restore backups, and replay binlogs to advance the database to the exact state it was in at the exact second the report to NCMEC was made that triggered the data retention and preservation requirements of the law. It is irresponsible and quite frankly abusive of the organization to place you in a position where you, personally, will need to perform hours of work minimum (not to mention the risk of discovering that entropy or misconfiguration has corrupted the specific backup files you need that cover the specific time window in question!) in order for the organization to comply with its legal obligations.
Anyone who has experience in the Trust and Safety space knows that the best practice is one of two (or both!) options:
1) Upon account suspension, all contents of the account are removed from view, frozen at the time of suspension, and the user cannot edit, change, or alter any of the contents or the account metadata while the account is suspended;
2) The software itself should have a compliance tool that can take a snapshot of the single individual account, containing the full contents of a) all user-generated content uploaded by the user to any portion of the site and b) all metadata, logs, account history, and relevant actions taken by the user on the site that the site stores, each in a separate file stored in one directory per snapshot, when someone with the relevant admin privileges requests that the action be taken, and policy should be that immediately before hitting "submit" on the NCMEC report, that compliance tool is run to take a snapshot of the account.
I am assuming you do not have 2, because if you did, someone would have brought it up as a gotcha in that post about how I am very mean, so while you're here and since you're very likely the person subpoenas go through: it is a very good idea to have that kind of tool. A script that you run when necessary is fine; it doesn't need to be an on-site admin tool. You want to make it as fast as possible for you to assemble the information necessary to comply with the subpoena and minimize the chance you'll fuck up and miss something. (Genuine mistakes/oversights are unlikely to cause personal liability for you! But better to reduce the risk.)
The ideal subpoena compliance script lets you choose broadly what categories of information you include in the output. At the very least, the tool should store user-submitted data (posts, comments, bookmarks, submitted profile data, etc) separately from metadata (username, username change history, email address, email address history, IP log information, any logging of recorded actions taken on the site like deletions, collection ownership transfer, work authorship transfer, etc): the former are (sometimes) governed by the Stored Communications Act, the latter aren't, and it's useful to be able to separate them easily. Ideally you want to be able to do something like "./snapshot username" and get the full backup, or "./snapshot username --IP-history --email --email-history" if that's all the subpoena asks for.