Hi,

thanks for your proposal.

On Sun, 2026-07-26 at 09:11 +0200, Marc Haber wrote: 
> We expect 
> our contributors to design their workflows with due dilience, and to 
> keep AI tools away from confidential materials, private comunications
> and cryptographic keys regarding the Debian infrastructure and 
> community.

I suggest to leave out this part: if you already trust cloud providers
like Riseup or Google with that private communication, say mails to d-
private@, then it probably doesn't matter whether you trust them just
for mail processing or also for AI services.  I'm also not sure how
realistic it is to completely avoid AI tools with those providers?

Contributors should of course consider which providers they use and
take their agreements with the provider into account for which data to
trust them with. This also depends on the concrete data: IRC messages
or mails are probably different than private signature keys.

Maybe it should also include a reminder that larger automated actions
like mass-bug filing should have prior discussion.

Ansgar

Reply via email to