Pith. sign in

REVIEW

Ethical Considerations Towards Protestware

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2306.10019 v2 pith:H6CY2KDV submitted 2023-05-27 cs.CY cs.CRcs.SE

classification cs.CYcs.CRcs.SE
keywords librariesprotestwaredifferentlibrarymaintainersmaliciousopensoftware
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

A key drawback to using a Open Source third-party library is the risk of introducing malicious attacks. In recently times, these threats have taken a new form, when maintainers turn their Open Source libraries into protestware. This is defined as software containing political messages delivered through these libraries, which can either be malicious or benign. Since developers are willing to freely open-up their software to these libraries, much trust and responsibility are placed on the maintainers to ensure that the library does what it promises to do. Using different frameworks commonly used in AI ethics, we illustrate how an open-source maintainer's decision to protest is influenced by different stakeholders (viz., their membership in the OSS community, their personal views, financial motivations, social status, and moral viewpoints), making protestware a multifaceted and intricate matter.

Discussion (0). Continue with ORCID to comment.

Pith tools