I’ll never forget the day when I got the call from Tim Berners-Lee, asking me if I would co-chair the W3C Technical Architecture Group, along with Peter Linss. I had previously been an elected member of the TAG, which I already counted as a great honor. And now, I was being asked to help lead this group during a time of great change. A “new guard” had been elected to the TAG, bringing with them a new vision for change – change in what TAG should focus on and how it should operate. Tim needed Peter and myself, who had some W3C and TAG experience, to help facilitate that change. Together, as a group, we built new TAG processes, such as the mechanism of design review; we instigated developer meet-ups to make the TAG (and web standards in general) more transparent to the developer community; we moved much of our work to GitHub and Slack, and away from Email and IRC. Later, we moved to a “breakout” process to parallelize our work, both during in-person meetings and through our weekly calls. Importantly, we continued to evolve our process, most recently launching the TAG Associates to widen our community of practice. We also reimagined what Technical Architecture should mean for the W3C – by building TAG into a technical design authority, and by codifying core principles such as the Priority of Constituencies and the Ethical Web Principes. I’m immensely proud of the work that we’ve done in the TAG in the last decade+ and the role I’ve …

Why am I running for W3C Advisory Board? Read more »

Lots happened in 2024. Here are some personal highlights. A Return to Samsung and Sticking with Open Source Security At the end of 2023, I was job hunting, after having been laid off from my job at the cybersecurity company Snyk. I learned a lot at Snyk, and had the opportunity to work some amazing people . Snyk also gave me the opportunity to get involved with the Open Source Security Foundation, where I’ve been working to help improve the security of the open source ecosystem. I made the decision at the end of 2023 to remain connected to the OpenSSF and to re-run as an independent for the Technical Advisory Council (TAC) election, which I won. I subsequently was hired by Samsung Open Source Group, where I’ve been working for the past year, focusing on open source security as well as authenticity and provenance. I’ve also started working more on the tech policy side of things, where I’ve been tracking the EU Cybersecurity Resilience Act, among other things.  I’m glad to report I’ll be continuing that work in 2025. You Win Some, You Lose Some I am really proud of what I’ve accomplished in the TAC this year, but unfortunately I was not selected in the current election cycle so I won’t be part of this body in 2025. One of the things I appreciate about OpenSSF is the open nature of its community. TAC calls are public and anyone can dial into them, a feature I definitely took advantage of when I first became …

2024 Year in Review & Looking Ahead Read more »

Today, the World Wide Web Consortium (W3C) published the Ethical Web Principles as a “Statement.” This has been a labor of love for me over the past few years. It started off with a blog post in 2019 and, thanks to the support and encouragement and contributions of many people, it grew into a movement and gained a surprising amount of support across the web developer ecosystem. I’m glad that it’s already been influencing the direction of web architecture and the design of new technologies, both directly and through other more “actionable” guidelines documents such as the Web Platform Design Principles and the Privacy Principles. Getting this published as a Statement means it’s now “endorsed” by the W3C – and we can be on even firmer ground when we use it as a way to guide the ongoing development and evolution of the web. You can read the full post on W3C’s blog.

I’m running for OpenSSF TAC, as an independent, in an election that any OpenSSF participants are eligible to vote in. If you’ve been active in OpenSSF, I’d appreciate your vote. The election is open until 30 December. If you’d like to know more background, read on. In Summer 2022, I joined Snyk and became involved with the Open Source Security Foundation – the OpenSSF. The OpenSSF is a Linux Foundation off-shoot which focuses on … well … Open Source Security – and specifically on “software supply chain” security. My philosophy when it comes to open source foundations and governance bodies like this is that if you want to be involved then it’s best to do so proactively – to jump in with both feet. That is one reason why, in late 2022, I put myself forward as a candidate for OpenSSF’s Technical Advisory Council.  Given the fact that I’ve been impacted in a recent round of lay-offs at Snyk, you might wonder why am I still involved in this organization and why have I once again put myself forward for OpenSSF TAC election this year? Since becoming involved with this community, with this part of the open source ecosystem, I’ve become convinced of the importance of this way of thinking about open source software. I still believe what I wrote in 2022: “This web of software that we all rely on so much is under constant attack.” The more developers are empowered and supported to mitigate against software security issues during the development process, the stronger the defence against this …

Why Am I Running for OpenSSF TAC? Read more »

In navigating the landscape of technology and digital innovation, we often find ourselves having to deal with complex concepts that cross between the technical, policy and legal domains. We hear words like “open source”, “open data”, and “open standards” thrown around, each with its attached notions of transparency, accessibility, and collaboration. However, these concepts aren’t as interchangeable as they might seem, and it’s crucial to understand the different rules that govern each. Bear in mind too that the term “IP” or “intellectual property” is really a catch-all term for a bag full of different types of rights, including copyright (which can apply to software, as a so-called literary work), database rights, patents, trade marks, and more. As someone who has served as an Open Source & Open Standards Strategy Director, worked for the Open Data Institute, and sat on the Open Standards Board for the UK Government, I’ve seen first-hand the nuances that define and differentiate these domains. This understanding is crucial as we cannot simply transfer licenses or IP guidelines from one sphere to another, owing to their unique features and scopes. This post was prompted by a few examples I’ve seen this year where people are either misunderstanding the differences between these domains, or conflating them. Having said all that: I am not a lawyer. This is not legal advice. I did not say this. I am not here. Open Source licenses: Code Reuse The term “open source” generally refers to a type of software whose source code is accessible to the public, allowing …

What’s the deal with Open Source, Open Data, and Open Standards licenses? Read more »

What’s an influencer, anyway? This is the question that rings out in my mind as I attempt to internalize the fact that I have been named one of the Top 100 UK Open Source Influencers for 2022 as part of their 2023 honours list #OpenUKHonours23. It’s definitely an “honour” to be recognized by OpenUK for my work in this way. But when we think of internet “influencers,” open source usually doesn’t come to mind. What I think and hope it means to be an open source influencer is that people are listening to what I have to say, be it on social media, in blog posts, videos, or whatever channel. But with great power comes great responsibility, right? So what can I use this currency, this influential authority, for?  I hope that I’ve influenced people to pay attention to ethical technology development, to the importance of privacy and personal dignity, and to the importance of building diverse and inclusive communities as we build tools, services, and applications for people. I also hope I’ve influenced people to understand the importance of community efforts, open source, and open standards in helping to build a technology ecosystem on the internet that is sustainable and exists to build people up and support society, starting from supporting marginalized groups. Halfway through 2022, I changed jobs, joining Snyk as Open Source & Open Standards Strategy Director. One thing that attracted me to Snyk was its stance on workplace flexibility. I hope to influence in 2023 by banging the drum a little about the importance of flexibility in the …

Influence Read more »

Today, as reported in the Guardian and elsewhere, Twitter suspended accounts of several journalists who had reported on Elon Musk and have also suspended accounts related to Mastodon as well as banning or “shadow-banning” people who talk about or link to their Mastodon profiles. Everyone should now be “reconsidering” their engagement with Twitter at this point. Personally I’ve stopped Tweeting. I’ve been removing links to my Twitter from across my other identities on the web. I’ve also been encouraging the organisations I’m involved with to move their social media engagement to the #Fediverse / Mastodon / ActivityPub and away from being Twitter-centric. By the way, I’ve been on Twitter since 2006. For context the iPhone debuted in 2007. I’ve spend a significant portion of my social media energy on Twitter. So it’s painful for me to say this, but Twitter is now dead – dead to me, at least. I’ve been on Mastodon since 2016. After witnessing the migration of people to Mastodon and other open federated platforms over the past months and how well the federated approach has been working, I’m more convinced than ever that this is the way forward. I think closed services like LinkedIn can also continue to play a role in the social media landscape but when it comes to filling the hole Twitter leaves, the #Fediverse is the way forward.

Consensus. It shouldn’t be a dirty word, but in some circles it seems to have become one. I was on an industry working group call the other week where someone presented a series of governance models and “consensus” was presented as the worst model for decision-making – something to be avoided at all costs. The speaker was promoting a more “consent”/voting-based approach where the majority rules. It’s not the first time I’ve heard the consensus-based approach to decision-making dragged through the mud. I have to say, I take a different view. Decision-making in groups is hard, especially when those groups are made up of people who do not have formal working relationships such as “boss/employee.” Industry working groups (such as groups at World Wide Web Consortium) are often peopled by software professionals, peers, from industry competitors. Nobody can tell anyone else what to do. I’ve been the chair of a few such groups and I can tell you unequivocally that the chair cannot tell people in a working group what to do. If the chair of such a group were acting as if they did have authority I would see that as a sign of dysfunction. In absence of this kind of formal authority, industry working groups must function using some kind of collective decision-making process. In my experience, consensus-driven decision-making achieves the best outcomes in these kinds of situations. So what is consensus? First of all, consensus does not mean “everyone must agree.” It means making decisions based on general agreement. In practice, it usually means …

Let’s Talk About the C Word Read more »

This blog is now a part of the #fediverse. I was inspired by the recent migration user growth on Mastodon and other federated social web sites to get the ActivityPub WordPress plugin installed here and start federating out any posts I write here. For more info on how to get this working on your own WordPress site, see The Fediverse beyond Mastodon | Fedi.Tips – An Unofficial Guide to Mastodon and the Fediverse. I also had to muck around with my .htaccess file and this post was very helpful.

Apparently there’s been some confusion about my choice of hair color. Some people seem to have been under the impression that I chose purple to match the color scheme of Samsung Internet. So I want to set the record straight. Purple is my favoirite color, and I exclusively choose employers with purple logos. I hope that clears things up. So now – after six years with Samsung, building and leading the Samsung Internet developer advocacy group, I’m moving on to a new role and a new set of challenges. I want to be clear about one thing: Samsung Internet is a great browser and it’s been a privilege to have worked as part of the team there. I also think, under the leadership of the awesome Heejin Chung, Samsung Internet is on exactly the right path — particularly in putting an emphasis on greater user privacy. During my time there I feel I’ve helped to achieve the goal we set out of putting Samsung Internet on the map and establishing it, rightly, as one of the big web browsers. If you’ve been following my journey (and there’s no particular reason you should have been, but just on the off chance) then you’ll know that one constant theme has been the web. I got my start building web sites and web applications for scientific publishers and later for dot-coms during the go-go 90s when the web was just taking off. After moving to London, and subsequently becoming out of work in London, I landed at Vodafone where I took my passion for the …

All Change, Still Purple. Read more »