The OTW’s Commitment to Safety: Responding to Recent Concerns About AO3

This post hopes to address some claims made yesterday by Rahaeli on Twitter and her site, Dreamwidth, for purposes of clarification. After the illegal attack on OTW volunteers in May, 2022, the OTW took numerous steps to protect volunteers, including hiring an outside law firm with expertise in cybersecurity, working with contractors and firms that investigate and handle security incidents, and comprehensively revising our internal volunteer practices and updating our technological tools, including email systems, as well as making all necessary reports to NCMEC and others.

These actions, revisions and updates are ongoing. We also communicated with volunteers, both through personal and organization-wide communications, providing advice on actions to take if they had been sent CSEM, information regarding safety precautions they could take regarding personal information we believed could have been compromised, and identification of further resources that they could use.

The Legal Committee has always worked closely and cooperatively with the Policy & Abuse Committee, and continues to do so. This work includes organization-wide policy and technological measures to reduce stress and strain on our Policy & Abuse volunteers, and these measures are ongoing and continuing. We, and everyone else at the OTW, have always taken CSEM very seriously and the OTW reports (and has always reported) as required to NCMEC and others. Our Abuse processes are not limited to what appears in the Archive code, as we have internal measures in place (including some which are intentionally confidential), and we are always seeking to improve them. People who try to abuse the Archive are, unfortunately, flexible and evolving — therefore, we are too.

We are confident that we are compliant with the laws, including U.S. and EU laws regarding privacy, data protection, and data retention, that apply to the AO3. (It is relevant to the legal analysis that the AO3 does not host images other than 100×100 pixel user icons, which cannot be “orphaned” within our system). As Rahaeli noted at the end of her thread, these laws do not include COPPA, the Children’s Online Privacy Protection Act, as it does not apply to nonprofits like the OTW, but as a matter of policy we do not allow children under 13 to make accounts, as noted in our Terms of Service.

Rahaeli is an expert in running an important social media/content hosting site, but not necessarily an expert about the facts in this instance, or about the OTW. We respect and have often listened to her expertise in the past; had she contacted us directly, we could have addressed her questions and concerns. We did not ignore her advice in 2022 and would not do so now.

Announcement, Archive of Our Own
  1. RattyManiac commented:

    This is a huge relief, thank you so much for the clarification!

  2. azarias commented:

    Hi! How does the Legal Committee retaliating against me for criticism of the OTW by falsely accusing me of approximately 900 felonies fit into the OTW’s safety plan? Interested to hear! https://fail-fandomanon.dreamwidth.org/596934.html?thread=3656005574#cmt365

    • K commented:

      Does it really count as retaliation/defamation when YOU were the first one to bring up the theory that you were suspended during the CSEM attack for being a suspect (Dreamwidth 2023-05-24)?

      Which then got linked by others in a Carrd in order to make a point about how OTW users and volunteers are being “abused” by the Organisation (https://ao3-volunteer-abuse.carrd.co/) (giving that link because it has more sources than I can provide here) which lead to some people demanding Answers of the OTW Very Loudly.
      (Personally, I don’t think being told something is not csem when YOU didn’t even believe it was CSEM [“Probably it was from regular porn” to quote you. Which goes for… most porn with young adults?], and later being lied to about not being a suspect of those email attacks – when you so very obviously were a suspect – count as abuse. You shouldn’t be allowed to report things as csem that aren’t that, and, while lying isn’t nice, suspects should not be told that they are suspects. The carrd isn’t on you, but it’s absolutely shit-stirring on a “no decent person would believe this guy would beat his wife” level, where I don’t know any of the people but I’m supposed to pick a side. But the guy sounds a bit sus going by what his defenders are like.

      I still do not get what you are supposed to have blown the whistle ON, btw? Legal porn not getting banned? In-transparency when it comes to communication with crime suspects? Unpaid volunteers not getting mental health care provided from their fellow unpaid volunteers? The legal team being referred to and being the authority when it comes to the questions on what content is legal and therefore allowed? What big secrets did you leak that I have missed that they are supposedly so mad at you about that they’d retaliate by… confirming what you already publicly suspected getting suspended for, and giving more info on that?

      Like, I don’t know if you were behind those attacks. I don’t know that you weren’t, either. But if you want to hold anyone accountable for framing you as a suspect, that should be you, first. Did you think non of the Dreamwidth anons would contact the OTW and ask for clarification, or spread rumours that would force the OTW to clarify that they did not just kick you out to get rid of an annoyance?

      • Impertinence commented:

        1. Azarias blew the whistle on volunteers not being provided with the support in policy, process, or tooling that they need to deal with reports of CSAM. “Legal porn” is not the problem here, “porn distributed in a way that makes it impossible to confirm legality” is. “Volunteers asked to try and find out if the porn is legal rather than requiring users to prove it” is. And BTW, the OTW disagrees with you on this, because after azarias left they changed their policy. 2. If azarias was genuinely a suspect in a federal investigation (protip: she wasn’t) then, actually, kicking her out of the org in this way would be interference with a federal investigation, and they shouldn’t have done it. If the feds had told them to do that, then that would be another story. But they didn’t. They’ve already admitted as much. 3. Trust & Safety departments the world over do not rely on legal teams to determine their policies. They rely on legal teams to tell them if their (T&S) interpretation of policies is legal according to the TOS. There is a very good reason for that: lawyers are not experts in running a website, and their policy recommendations are unlikely to be based in the decades of best practice that Trust & Safety professionals have established. Legal’s advice in this area is professionally inappropriate and, given that they are IP lawyers who do not specialize in the relevant law, unethical. This is handily demonstrated on this post, where they state their legal analysis indicates they are compliant, relying upon the false statement that they do not host images other than user icons. 4. There is no version of events and no interpretation of Legal’s expertise or domain that justifies smearing azarias internally to 900 volunteers, defaming her by implication, with communications that stress strange “coincidences” that imply they think she was the culprit even as they allowed her back into the org. That behavior alone demonstrates that Legal and the Board are inappropriate stewards of the organization.

        • K commented:

          1. That goes for a lot of online porn of young adults you come across (esp as you get older…). You rarely 100% know they AREN’T <18. But if you volunteer to do CSEM tickets, and you agree someone in a reported porn gif looks like a child, that's good enough to say the gif should be passed on to the authorities. But apparently that didn't happen, cause she said she wasn't sure and let someone else make that call, and didn't like their decision. Where can I find that policy change, btw? You can still embed visual materials and I see no exceptions for any tag or type of content.
          2. You make it sound like the OTW went against any advice from the authorities during an investigation of a suspect, when the whole thing sounds like there wasn't enough evidence to make anyone an official suspect. The feds aren't going to bring in anyone for possibly having enough personal info about others to do the email attack (cause azarias is by all accounts very social).
          3. Makes no sense. The OTW's content policy is based on "everything fannish, fictional, and LEGAL". 'Does the Underage tag make this CSEM when it doesn't clearly look like a child to me?' is a question for legal. 'Is this obscenity or defensible?' is a question for legal, cause they are the ones who'd have to defend it.
          4. People keep asking the OTW for transparency in their decisions. So, they made clear their reasoning for, let's say ostracising, their volunteer for a bit w/o coming right out and saying they suspect(ed) her of anything. Which you can argue is a dick move, but they still only did that after azarias herself posed the theory that she'd been a suspect. In a forum that had – according to some comments I've seen – several former and current volunteers. Might as well make a statement before the rumour mill gets going.

          • K commented:

            Let’s try this one more time. 1. That goes for a lot of online porn of young adults you come across (esp as you get older…). You rarely 100% know they AREN’T younger than 18. But if you volunteer to do CSEM tickets, and you agree someone in a reported porn gif looks like a CHILD, that’s good enough to say the gif should be passed on to the authorities, and then do that and suspend the account. But apparently that didn’t happen, cause she said she wasn’t sure and let someone else make that call/do her job, and didn’t like their decision. Where can I find that policy change, btw? You can still embed visual materials and I see no exceptions for any tag or type of content.
            2. You make it sound like the OTW went against any advice from the authorities during an investigation of a suspect, when the whole thing sounds like there wasn’t enough evidence to make anyone an official suspect. The feds aren’t going to bring in anyone for maybe having enough personal info about others to do the email attack (cause azarias is by all accounts very social, and people will talk about themselves to nice people). There apparently was just enough weirdness for suspicions, and I have no reason to (dis-)believe either side, here. YOU say it’s a smear campaign, I say they are just confirming that there *were* suspicions after people asked. (see 4.)
            3. Makes no sense. The OTW’s content policy is based on “everything fannish, fictional, and LEGAL”. ‘Is this a child?’ is NOT a question for legal. ‘Does the Underage tag make this CSEM when it doesn’t clearly look like a child to me?’ is a question for legal. ‘Is this obscenity or defensible?’ is a question for legal, cause they are the ones who’d have to defend it.
            4. People keep asking the OTW for transparency in their decisions. So, they made clear their reasoning for, let’s say ostracising, a volunteer for a bit w/o coming right out and saying they suspect(ed) her of anything. Which you can argue is a dick move, but they still only did that after azarias herself posed the theory that she’d been a suspect. In a forum that had – according to some comments I’ve seen – several former and current volunteers. Might as well make a statement before the rumour mill gets going.

        • K commented:

          Oh, cool, I didn’t lose the comment. Let’s try this again. 1. That goes for a lot of online porn of young adults you come across (esp as you get older…). You rarely 100% know they AREN’T <18. But if you volunteer to do CSEM tickets, and you agree someone in a reported porn gif looks like a child, that's good enough to say the gif should be passed on to the authorities, and then do that and suspend the account. But apparently that didn't happen, cause she said she wasn't sure and let someone else make that call/do her job, and didn't like their decision. Where can I find that policy change, btw? You can still embed visual materials and I see no exceptions for any tag or type of content.
          2. You make it sound like the OTW went against any advice from the authorities during an investigation of a suspect, when the whole thing sounds like there wasn't enough evidence to make anyone an official suspect. The feds aren't going to bring in anyone for possibly having enough personal info about others to do the email attack (cause azarias is by all accounts very social, and people will talk about themselves to nice people). There apparently was just enough weirdness for suspicions, and I have no reason to (dis-)believe either side, here. YOU say it's a smear campaign, I say they are just confirmung that there *were* suspicions. (see 4.)
          3. Makes no sense. The OTW's content policy is based on "everything fannish, fictional, and LEGAL". 'Is this a child?' is NOT a question for legal. 'Does the Underage tag make this CSEM when it doesn't clearly look like a child to me?' is a question for legal. 'Is this obscenity or defensible?' is a question for legal, cause they are the ones who'd have to defend it.
          4. People keep asking the OTW for transparency in their decisions. So, they made clear their reasoning for, let's say ostracising, their volunteer for a bit w/o coming right out and saying they suspect(ed) her of anything. Which you can argue is a dick move, but they still only did that after azarias herself posed the theory that she'd been a suspect. In a forum that had – according to some comments I've seen – several former and current volunteers. Might as well make a statement before the rumour mill gets going.

          • K commented:

            Goddammit, what?

        • K commented:

          They do not host images, apart from icons. Images/gifs/vids are data-heavy and their servers couldn’t take that. They let you embed images that are being hosted somewhere else. They also let you post links to somewhere else. Both of these functions can be used to distribute illegal material, yes, but show me a website with any user-generated content that doesn’t let you do that.

          • surskitty commented:

            They do host images, actually. Anytime you hit the Download button on a work that contains an image embed, the ebook maker downloads the image to embed it directly in the ebook. It is being hosted as part of that pdf etc. They don’t host images larger than icons long-term, but I don’t think the law cares if you’re only intending to host it for a few hours until it’s deleted from cache.

          • Satsuma commented:

            To build off what you’re saying a bit–the law cares in that evidence of CSAM images (which includes the images themselves, and any associated metadata which may help identify the poster or or producer) is required to be saved for ninety days to give NCMEC time to investigate (reporting said images to NCMEC is also mandatory)–hosting CSAM “only for a couple hours in cache” before deleting all of the evidence is actually part of the problem

          • surskitty commented:

            Thank you; realized a while after posting I was ambiguous. “We only hosted it for a few hours” is not something that will work as a defense. AO3 very much does host unscreened images, not just embeds, and does not save that data in a way that permits complying with the law. The existence of backups does not change that fact, as a backup taken every week does not include anything about a pdf created five days ago and scrubbed four days ago.

          • K commented:

            Any report to NCMEC would include the embed link to the hosting site, so the evidence would be there. There’s no good reason for every site an illegal pic was embedded into saving the pic on their server. Info of which IP embedded it and how often and by whom it was downloaded using on-site tools, sure, that would be relevant info that websites need to keep. But there’s no reason why they should keep the material itself anymore than a person stumbling over CSEM – or being sent it – and then having it in their cache should then preserve that on their PC.

      • azarias commented:

        “Does it really count as retaliation/defamation” Yes. “”Probably it was from regular porn” to quote you.” You have successfully identified what I told myself so I could sleep at night. I had no training or tools with which to make this determination. That is the substance of my complaint in this specific example. There are correct ways to approach these situations, and then there’s what I was stuck doing.

        • K commented:

          The problem, as you described it, wasn’t the gif though, it was it being in the Underage tag. Big dicks and hairless pussies are abundant in porn, and I doubt there’s training to age-date genitals by sight. If you wouldn’t have thought that was a child sans tag, the *gif* itself isn’t actionable as CSEM until a victim comes forward. It was Your job to identify that (whether that’s a child or not). The question was: Is the gif an illustration for the *fanfiction* (to whom the tag refers), or does the tag go for the gif seperately as a descriptor of what’s shown in the gif? In that second case, it wouldn’t matter how old the performers looked or if you tag it Fiction, cause the Underage (or non-con) tag would trump that if they were seen as describing non-fiction (the live-action sex gif). Which is not how tags should work. There’s enough people thinking they are endorsements or porn genres already.

          • Nonny commented:

            “Big dicks and hairless pussies” is truly charming language to use in the context of child sexual abuse.

          • K commented:

            Pardon the crassness. I was using the same words as the above commenter was using in another forum when describing the material they were evaluating, and I was coming from a place of someone who had seen far too many people claim that smooth genitals or size differences in adults are, and I quote, “catering to pedophiles” or that porn featuring those are “basically cp”. My point was that a content tag should not matter when you are tasked to evaluate potential CSEM gifs *by sight* (well, unless a sexual gif is tagged Underage and Non-Fiction).

      • azarias commented:

        “Unpaid volunteers not getting mental health care provided from their fellow unpaid volunteers?” Unpaid volunteers who are exposed to traumatic attacks as a consequence of, but outside the expected scope of, their unpaid work do in fact deserve appropriate healthcare. That the org chose not to provide any such care is a massive ethical failure at the least. Doing so as a one-time emergency response would not constitute providing employee benefits or reclassifying volunteers or whatever excuse OTW leadership used not to do it, and would not be overstrain the org’s financial resources. A voucher for 2-3 online counseling sessions in order to debrief, or bringing in a contractor to offer group seminars on over Zoom, would not be treating volunteers as employees. There are actual rules and tests you can apply to volunteer classification; you don’t just have to go on vibes.

        • K commented:

          That’s not their job. That’s none of the volunteers’ job. Which doesn’t mean it couldn’t have been done, but unless anyone had piped up at the time to say “Hey, I’m gonna start a donation drive for us to pay for therapists” and the Board forbade it, I’m not sure why you think they are responsible for it not getting done.You could have done it. Any of the other traumatised volunteers could have done it. Any outsider could have done it. Preemtively, or after the first time or that second time ir right now. But the Board isn’t responsible for budgeting for terrorist attacks. (And I might be wrong, but I’m pretty sure them paying for therapy vouchers would mean that the volunteers were being PAID. Out of donations not meant for that purpose. Which strikes me as illegal.)

          • I see commented:

            “That’s not their job. That’s none of the volunteers’ job. […] I’m not sure why you think they [=the Board] are responsible for it not getting done. […] But the Board isn’t responsible for budgeting for terrorist attacks.” Hum, I thought it would be too obvious to miss, but this (among other things) is EXACTLY WHAT PEOPLE ARE CRITICISING on this topic? Now, I admit I’m pretty new to the internal OTW structure, but from what I picked up there is a hierarchical structure that’s something like People in Committees answer to -> Committee Chairs answer to -> the Board (or Legal?) (And Fanlore also states “The OTW is run by an elected board”). All of them volunteers, but still at different points in the hierarchy. So when a “terrorist attack”, as you called it, against a massive part of the volunteer workforce happens, shouldn’t the Board as the highest up in the hierarchy (who, again, run the OTW) take care of the mental health of the people working under them? Maybe it is the case that the people on the Board don’t or can’t, not having the rights to make executive functions like that? Well, that would speak to the organizational dysfunction people are complaining about. Or maybe there is someone who could make such decisions but they said, “Nah, mental health care for the volunteers after this event is not necessary”? Well, that would speak to the organizational dysfunction people are complaining about. I don’t know anything about legality of paying for therapy vouchers that you bring up, so I can’t comment on that, but the ethical failure mentioned above is right there.

      • azarias commented:

        PAC’s work is complex, but there are tools that PAC could be given access to to make these decisions easier.

        • azarias commented:

          Legal are not experts on all applicable laws affecting AO3 and the OTW. I apologize for the disjointedness of these replies; the commenting software is giving me fits.

      • azarias commented:

        “What big secrets did you leak that I have missed that they are supposedly so mad at you about that they’d retaliate” Everything I’ve said is in public. Please let me know if you have any further questions.

  3. Azarias commented:

    The first such attack on OTW volunteers was actually in October 2021! PAC as a whole and I personally warned the Org that further attacks and escalations were expected. Can you explain why the Org took zero steps to protect volunteers the FIRST time this happened, and instead waited until the attacker gained greater access and was able to threaten more volunteers more severely?

  4. turtle commented:

    So you’re not going to address her claim that she *did* contact AO3 directly through a website contact form, and that Rebecca Tushnet *did* set up a phonecall with her and, instead of listening to her recommendations, pressured her to delete her twitter thread and said AO3 would not advise your volunteers of the steps to take against further threats because somehow the danger of marginalized people contacting the police for their anti-SWATting procedures was somehow more dangerous than what would happen if those exact same marginalized people got SWATtted?
    Is that what counts as protecting volunteers?
    (Among other things you haven’t addressed! Azarias has already brought up her issue above, and I’m sure there are others)

    For anyone who wants the full account, Rahaeli/Denise wrote up the whole thing at synecdochic at dreamwidth dot org.
    Note: I don’t know her personally and have never interacted with her so far as I know.

    • turtle commented:

      My mistake, it’s synecdochic.dreamwidth.org, not “at”

  5. tremontaine commented:

    had she contacted us directly, we could have addressed her questions and concerns. We did not ignore her advice in 2022 and would not do so now.

    According to rahaeli, not only did you in fact ignore her advice but a longstanding member of the OTW’s Legal Committee rang her up to demand she retract it/remove public posts intended to provide volunteers with advice and resources which the OTW was not giving them. Will that allegation be addressed at any point?

  6. gloss commented:

    Couple questions!

    So did Rebecca Tushnet ask Denise to remove her thread of advice in the wake of the attack or not?

    The Legal Committee has always worked closely and cooperatively with the Policy & Abuse Committee, and continues to do so.>/i>
    That’s part of the problem, though! Why does Legal feel emboldened to hamstring PAC decision-making to the extent that it does?

    This work includes organization-wide policy and technological measures to reduce stress and strain on our Policy & Abuse volunteers, and these measures are ongoing and continuing.
    In what possible way are legal academics who specialize in IP at all equipped to do such work? Why do you on the committee feel entitled and qualified to do so?

    • gloss commented:

      Argh, apologies for the mess of formatting.

    • Hex commented:

      (I’d say it’s shocking that the OTW comment section doesn’t have basic input validation to close tags, but…)

      And if Tushnet did contact Rahaeli and attempt to pressure her into removing the Twitter thread (which I have no reason to disbelieve), who else has been asked to delete discussion, comments or criticism of OTW and/or AO3? It this standard Legal procedure?

  7. surskitty commented:

    Aren’t Legal IP lawyers? Why are they working with PAC in the first place? That sounds far outside of their specialties.

    • tacky_tramp commented:

      +1

    • aimmyarrowshigh commented:

      +1 (re: PAC being outside the specialization of IP lawyers in the first place)

  8. Azarias commented:

    Closing tag.

    • gloss commented:

      Thank you. I made a mess, but I had no idea it would propagate past my comment.

      • Muccamukk commented:

        What the hell is this code!? I’m laughing so hard right now. What a gong show.

  9. moljn commented:

    I think it would be useful for people to be able to read the claims you’re addressing. I’m confident Rahaeli does not mind being linked to: https://twitter.com/rahaeli/status/1669350441971494914

  10. EchoEkhi commented:

    I have to say that releasing this statement is not the correct thing to do, nor is it the right time to do it. “It is an axiom of practical politics never to believe anything until it has been officially denied.” By swiftly and immediately denying these accusations, you’re actually showing that you’re worried about the effects of the accusations, leading people to think they might actually be true. The Org should have waited until a question about this comes up on the public meeting on 2nd of July, then the statement will be less abrupt. So I have to ask you this: was there a particular reason Comms decided that this was urgent enough to release an immediate statement, provided that the accusations are false?

    • tacky_tramp commented:

      Strongly disagree. I’m glad they at least addressed the legal-compliance issue immediately.

      • EchoEkhi commented:

        There was never any question about OTW’s legal compliance. Systems made it clear that database backups were stored for a year.

        • tacky_tramp commented:

          Where did they make that clear?

          • PrettyOdd commented:

            Systems did a driveby post on the AO3 mirror(previous post) in response to a thread where we were talking about it. Again I cannot stress enough that this is pretty easily hidden and shoved on the end of the 3rd page of pretty heated responses. I wholeheartedly don’t even think that Systems wanted to respond since it seemed like a panicked off-the-cuff reaction from the person who was sending it (No offense to them, they seemed to be trying their best with what they were given).

            I frankly don’t like the fact that the OTW purposefully hides and tries and cower from genuine discussions like this. This is also the only post that isn’t mirrored on AO3 publically. And it’s to save face for the donors 1000%. They don’t want the majority of AO3 users who would run from this if they heard about it to know about these allegations. It’s also why (IMO) they didn’t name the EndOTWRacism protest in their last post nor title the anti-racism post on AO3 and here anything relevant. Because let’s be honest… OTW knows that if the majority of the userbase heard of this instability, they wouldn’t donate.

          • EchoEkhi commented:

            It is mirrored on AO3 publically. https://archiveofourown.org/comments/661154842 I appreciate Systems’ transparency.

          • Impertinence commented:

            It also very much should not be System’s random configuration that decides how long this data is stored. I know they are doing their best, but they’re inadvertently exposing that what we suspect is true: there are people in the org making decisions about mission critical legal compliance issues that absolutely shouldn’t be, because their only legal advice is coming from people who are unqualified to advise in this domain and unethical enough to advise anyway, and there is no policy from the Board that prevents this status quo from continuing.

          • EchoEkhi commented:

            Sorry, here’s the source: https://archiveofourown.org/comments/661154842

          • rahaeli commented:

            Server backups are not a reasonable solution for legal retention and preservation requirements in the slightest. Server backups are for data loss or machine failure, not for the legal requirement to preserve and retain records about a single specific account: from that setup James describes, for the organization to meet its legal obligations in the event of “a report of CSAM was sent to NCMEC and we have now gotten the subpoena from law enforcement for the information about the account we were legally required to preserve as of the instant we hit ‘submit’ on the report” would take James, conservatively, probably a minimum of 100 hours and the use of a spare very large machine (that the OTW probably doesn’t just have lying around) that could be entirely bypassed by either a) making a code change to make all content by a suspended user invisible and prevent them from editing, changing, or deleting anything in their account or b) maintaining a subpoena compliance snapshot script that dumps a snapshot of the individual account’s contents and its metadata at the instant the “submit” button was pushed on the NCMEC report and created the affirmative obligation to preserve those contents.

          • EchoEkhi commented:

            > “would take James, conservatively, probably a minimum of 100 hours and the use of a spare very large machine (that the OTW probably doesn’t just have lying around)” I don’t know where you got the idea that it takes 100 hours to restore a backup. By your estimate, the restore rate would be 1.67 MB/s. They could use their staging machine to restore the data.

  11. TuttleDuttle commented:

    Thank you for the clarification. Denise’s statement has created a rather large shit show

  12. Silverfish commented:

    Why has PAC not been using industry-standard best practices to reduce the exposure of volunteers to potential CSEM up through now? Has it now researched these best practices, and is it planning to implement them in a reasonable time frame to prevent further trauma and distress to volunteers? Does OTW have a response to Denise/Rahaeli’s allegations that she has, in fact, directly contacted the OTW multiple times, and the only response she has received was a phone call from Rebecca Tushnet strongly pressuring her to remove advice for volunteers who were victims of the CSEM attack? Will the OTW retract its defamatory internal letter implying that the volunteer Azarias was behind the CSEM attacks (despite the fact that they reinstated her)? Will any Legal members who authored or approved that letter be removed for their unethical behavior towards a volunteer? Given the internal letter by the Board, is it addressing the concerning fact that Legal unilaterally decided to suspend a volunteer without even notifying the Board?

  13. Kutti commented:

    Hi Legal,
    I am a current volunteer with the OTW and I am posting this here because I have been waiting more than 3 weeks for Board to answer my questions regarding the May 2022 situation and its aftermath, and have received no response.

    My questions (asked on 28th May 2023) were:
    1) Who is in charge (board or legal or volcom) of creating the documentation for defining what an emergency is and what is authorised in it
    2) What timeframe can we expect for this documentation to be drafted

    I would also like to let you know that I received only 2 all-org emails after the May CSEM attacks, and the advice in them was limited to:

    “If someone outside the U.S. received CSEM, they may also want to also report to NCMEC, since what they received came via U.S. servers. They should use their own judgment about reporting it to their own local, national, or regional authorities. Anyone who receives CSEM should delete it from their e-mail and hard drive. If you think you may have been a target of this malicious activity, do NOT open any unknown e-mail to investigate or find out what it contains.” (dated 5 May 2022)

    “We strongly recommend not opening any messages from unknown senders claiming to be from the OTW, particularly if they contain attachments. Delete them immediately. […] We encourage you to choose a password that you haven’t used before and cannot be easily guessed, and we strongly recommend that you enable 2-factor authentication. […]
    “there is a possibility that any personal information you included in your Slack profile may have been compromised.
    We recommend that you take steps to protect yourself in the event this does occur. You may want to make changes such as:
    reviewing and removing information on your Slack profile, such as social media accounts;
    if your Slack profile has links to social media, removing location information and other identifying data from those accounts;
    changing your login data from those social media accounts, changing their protection level, or deleting them entirely.”

    You did not share any information about what to do if we were SWATTED, what to do if we were doxxed, or how to deal with the trauma if we were exposed to CSEM material. You did not offer any psychological assistance, and over a year later, according to the latest information, there are still no resources available for volunteers should we be attacked again.

    You did not even, as rahaeli’s thread did, provide us the peer-reviewed citation to play Tetris.

    • Impertinence commented:

      Thank you for continuing to press them on this.

    • msilverstar commented:

      Thank you for presenting your experience — that’s significantly alarming.

    • tacky_tramp commented:

      Thank you for confirming that Rahaeli’s thread of advice was indeed stuff OTW hadn’t discussed with volunteers.

    • Former Volunteer & Victim of the 2022 Attack commented:

      As one of the volunteers who was sent CSEM in the attack last year, thank you for speaking up about this. I am no longer a volunteer due to this incident, and likely will not attempt to resume volunteering if there is another opportunity to do so, especially since it seems that nothing has changed in a full year.

      While I did receive support, I remember it coming primarily from other volunteers higher up the chain than I was. Most of the immediate aftermath is a blur now, but here’s what I remember:
      – I can’t say for sure whether legal directly posted anything concerning this incident in the channel(s) I was part of, but regardless, a LOT of the heavy lifting was done by volunteers higher up the chain than I was. There was a lot of language like, “This was the advice given to us by legal and/or the board.”
      – I’m not going to go too deeply into detail about the email I was sent in the attack, but in addition to the CSEM, there was an angry rant that made references and included specific details about conversations that had taken place in Slack (some of them in channels I was part of), as well as threats of violence and/or extortion against the volunteers (each of them named in the diatribe). The sender had also left several email addresses (presumably of other volunteers) in the recipient list, which I provided to the volunteer who helped me through the immediate aftermath.
      – I don’t remember there being much confirmation one way or another which platforms had been compromised. The platforms I used for my volunteering work were locked down immediately, but I was afraid to post anything in Slack. This was a concern I saw echoed by other volunteers, but eventually conversation picked back up without any confirmation provided one way or the other that it would be safe to do so.
      – I don’t remember who it was that helped me through the immediate aftermath, but I remember their advice lining up almost word-for-word with what azarias has posted recently, about the support she personally provided to volunteers that had been sent CSEM (specifically the really practical stuff about how to lock your stuff down, clean your hard drive, etc). In fact, it was so close that that post had me wondering if maybe it WAS azarias that helped me back then (and if it was, and you happen to be reading this, thank you so much!)

      The thing is, even if there HAD been more support provided for mental health purposes, I’m not sure I would have taken it at the time. Not from any OTW volunteer, no matter where they were in the hierarchy. I remember feeling terrified to even check my email or open Slack, because I had no idea what had been compromised and I didn’t want to take any chances. I sure as hell didn’t want to tie any part of my irl identity to my fandom identity, which I was worried would happen if I asked for any more support than what I received.

      I really don’t know what kind of support I would have been most receptive to back then, but to the volunteers who helped me in the immediate aftermath, I can’t thank you enough. Thank you so much for being so kind and patient with me during such a scary and tumultuous period, and walking me through that crisis. Thank you for continued work in addressing this and protecting volunteers from such incidents in the future, even at risk of retaliation.

  14. InsanityPrelude commented:

    Can you address Denise’s statement that Rebecca Tushnet contacted her to demand she take down her thread about the 2022 attack? Because wow that is not a good look for the OTW.

  15. Muccamukk commented:

    Your post here is being refuted by multiple volunteers in this thread! Saying “we were using best practices!” does not make it true.

    You also have not addressed libeling one of your former volunteers to all of your current volunteers. Whoever is responsible for that needs to resign. Now.

  16. fioment commented:

    This is such blatant ass-covering in lieu of actually doing something to fix the problem. Legal’s overreach is obvious and poisonous. You need to clean house badly before you hurt even more of your volunteers.

  17. Airspaniel commented:

    Stating that you have no legal liability in this situation is a cop out of the highest order. Yes, you may technically not be violating any laws, but that doesn’t mean you’re doing the right thing or behaving responsibly towards your volunteers and people raising reasonable concerns which this statement completely fails to address.

    • uh oh commented:

      Except they DO have legal liability because they’re still hosting CSEM through embedded images AND not preserving relevant evidence for the legally required 90-day period when reporting CSAM. Jesus.

  18. Madame Hardy commented:

    I admit that I’m feeling cranky, but I’d like a clarification here.
    We respect and have often listened to her expertise in the past; had she contacted us directly, we could have addressed her questions and concerns.

    Does this imply that you don’t intend to address her questions and concerns now? Her points about the protection of volunteers, and about supporting volunteers emotionally, and not just legally, still stand. For instance, the use of the program that inverts and blurs possible CSAM when a volunteer may be confronted with it.

  19. Morncrown commented:

    All I can do is laugh. If you are not going to engage in good faith with the allegations, you’d be better off saying nothing on the org’s behalf at all.

    I also question OTW’s motives in choosing not to comment until only Rahaeli specifically made public comments about the ongoing discussion, rather than responding to the multiple serious, specific detailed allegations already put forth by multiple other people. Frankly, this smacks of “someone with a fandom-related grudge against Rahaeli just couldn’t let her have the last word.”

  20. fall commented:

    I’m a bit baffled by the clarification that images aren’t hosted on the AO3 servers – we all know this, but you have to realize that allowing links to CSEM, even if not hosted, still counts as distribution, right? I understand that this clarification may be for legal purposes, but without addressing the way CSEM could still be distributed without requiring server hosting via AO3, it reads like a very poor excuse to not acknowledge other ways the OTW can be complicit in allowing access to CSEM. This is an oddly defensive post that makes me even more wary of the org.

    • tacky_tramp commented:

      That bit concerned me, too. Either the person writing this doesn’t understand that hosting is irrelevant here, or they understand that but wanted to muddy the waters.

      • Impertinence commented:

        It’s also quite literally not true. They create & distribute work downloads with images embedded. The implication that distribution doesn’t count is wrong but their statement around hosting is also flat-out provably false.

        • fall commented:

          I didn’t even think about this, but you’re right. That makes their entire argument that images can’t be hosted on AO3 – however technical we want to get – entirely moot. Yikes.

          • Impertinence commented:

            It really does not inspire confidence that they are in fact compliant or telling the truth!