Live data from Hacker News

“I Want to Know What Code Is Running Inside My Body”

backchannel.com

201–210 of 217 posts

Re: “I Want to Know What Code Is Running Inside My Body”

#201
post #191

Earlier quoted context omitted.

Maybe it's just that the rebels these days are quieter and more establishmentarian, because they have /become/ the establishment. TBF, I quite like this state of affairs and don't miss the rebellion-for-the-sake-of-rebellion attitudes of yesteryear.

Yeah. If you don't hurry up to change the world, then the world changes you. http://www.sylvialiuland.com/2012/01/mafalda-classic-cartoon...

Even if you do change the world, the world changes you. It's not a zero sum game.

Re: “I Want to Know What Code Is Running Inside My Body”

#202

Earlier quoted context omitted.

The pacemaker or ICD generator is replaced when the battery is exhausted, typically 8–10 years. The procedure is not a big deal, it is commonly outpatient and done under local. Outside of some durable orthopedic implants, few implants will survive in the body for 50 years: it is a very hostile environment.

Useful to know. Of course, batteries get better and electronics gets lower powered - I can imagine in the near future implanted devices being effectively passive (such as RFID)... but your point about the body being a hostile environment is definitely something I hadn't considered before.

To expand on one aspect of hostile, some white blood cells greet foreign bodies with micromolar concentrations of a variety of oxidants and radicals: hypohalous acids (not just the familiar household bleach, hypochlorous acid, but also the nastier hypobromous acid), peroxides, superoxide, nitroxides, maybe even hydroxyl radical.

Realizing that, it's easy to see why autoimmune diseases are so devastating.

Re: “I Want to Know What Code Is Running Inside My Body”

#203
post #74

Earlier quoted context omitted.

> Medical device software is subject to a level of rigor in development process that little else is. How do you know this?

Spent 15+ years developing code for medical devices. I doubt very much that opening the source would have much impact on quality. For starters, without access to the hardware and understanding what it's supposed to be doing, how do you know if the code is right or not? Let me clarify that I'm not opposed to open sourcing the code, once issues around Trade Secrets are handle. But I don't think it would have even remot…

I don't need to know much about what it's supposed to be doing to critique a data channel that transmits plaintext over a radio, or accepts commands without cryptographically authenticating the sender.

I also don't need to know much about the intended function of the device to find coding styles that cause problems in an embedded environments.

Re: “I Want to Know What Code Is Running Inside My Body”

#204

Earlier quoted context omitted.

What happened to us? My theory is this is HN-specific - and what you saw on slashdot was slashdot-specific. Because HN started as part of YC its culture really likes VC-backed startups. And we think VCs want the kind of huge returns that are seen more often by closed source companies - they want to back the next Microsoft or Apple or Google or Facebook or Paypal or Amazon, not the next Red Hat or Canonical or MySQL.…

I see a similar lack of enthusiasm for free software everywhere, not just in HN (maybe confirmation bias), in Lobsters, Reddit, IRC. I really think that Unix in Apple and Android has given us what Steinbeck calls "a bored and slothful cynicism, in which rebellion against the world as it is, and myself as I am, are submerged in listless self-satisfaction." It's good enough for most people, we have some Unix under the…

> free software has mostly won.

The impression I get is that it's mostly the opposite: people have mostly given up on the notion of having all (or majority of) software being Free, and see that more and more as a pipe dream. Hence they don't want to "waste" their enthusiasm on something that feels like a (literal) utopia now.

There's a lot of reasons combined to get people there:

* seeing corporate behemoths everywhere that want to keep critical software proprietary

* many more people wanting to monetise their own software, and seeing that GPL-ing software offers only a few (and not-universally-applicable) monetisation strategies

* seeing that the "all bugs are shallow" and "everybody pitching in will make Free software the best there is" turn out not really true in practice

* seeing that in practical terms, having access to read and modify source code means nothing in 99% of cases because of software overload and others' code being so hard to get into that it's often practically impenetrable.

Not to say that I agree with all or any of these completely, but it's easy to see such a multi-pronged attack pushing back hard against the FSF's message. Further reducing FSF's ability to spread the message is the widespread character assassination of RMS as an "insane, overly idealistic, and rude slob" that has been going on for at least a decade.

As someone that read the Halloween documents non-stop overnight, it makes me a bit sad too.

Re: “I Want to Know What Code Is Running Inside My Body”

#205
post #190

Earlier quoted context omitted.

that would be an interesting study... but one that is impractical I think.

Well until there's evidence of it's effectiveness I'm going to avoid using obscurity. I know how to achieve an acceptably low break-in rate using mathematically valid encryption etc.. Defense in depth shouldn't be an excuse for using practices you haven't evaluated the effectiveness of at all.

You're missing the point.

An acceptably low break in rare using mathematically valid encryption.... Yes, fine... Given a perfect implementation.

You haven't got one of those.

Re: “I Want to Know What Code Is Running Inside My Body”

#206

Earlier quoted context omitted.

The pacemaker or ICD generator is replaced when the battery is exhausted, typically 8–10 years. The procedure is not a big deal, it is commonly outpatient and done under local. Outside of some durable orthopedic implants, few implants will survive in the body for 50 years: it is a very hostile environment.

>it is a very hostile environment. I've never thought of it this way, and you are right from both a technological and biological perspective. Biologically we are wonderful containers of nutrients, but we have an army only the very sneaky or militant can overcome. Once that army stands down we are rapidly colonized - which is why we must be so careful with food/meat storage.

You just made me realize why bacteria and other things want to kill us so badly... we are precisely that, really extremely-high concentration stores of nutrients.

Re: “I Want to Know What Code Is Running Inside My Body”

#207

I saw a talk about medical device security (or lack thereof) at the Eleventh Hope a few weekends ago. Very scary. They started off with a story about patients in a hospital who became horribly addicted to morphine because they were able to hack the machine from resources found online ( http://www.massdevice.com/hospital-patient-hacks-his-own-mor... ). Go on Shodan and search for medical devices and terminology (e.g.…

Not just open sourcing, because if they just open source and ignore the vulnerabilities, that's more trouble. Device should be allowed to be uploaded with code by the user or by the community, and the original people should just write good code in the first place.

Re: “I Want to Know What Code Is Running Inside My Body”

#208
post #190

Earlier quoted context omitted.

Well until there's evidence of it's effectiveness I'm going to avoid using obscurity. I know how to achieve an acceptably low break-in rate using mathematically valid encryption etc.. Defense in depth shouldn't be an excuse for using practices you haven't evaluated the effectiveness of at all.

You're missing the point. An acceptably low break in rare using mathematically valid encryption.... Yes, fine... Given a perfect implementation. You haven't got one of those.

No, you're missing the point. I'm talking about the real-world implementation that I have.

I don't think it's too much to ask before adopting a given security policy that it provide some evidence that it increases security. Or should I also be gathering a collection of rocks that keep hackers away?

Re: “I Want to Know What Code Is Running Inside My Body”

#209

Earlier quoted context omitted.

Even if we assume that these arguments are sound (which they aren't), they do not appear to provide a proper justification for letting a human being die . Put another way: If you had to explain Marie Moe's death to one of her relatives, which of your three points would make the relative understand your position?

Your argument that opening up the source code might have prevented her death is facetious.

Facetious?

You're attempting to justify the release of a (potentially fatally) flawed product on the grounds of lost "competitive advantage".

If you lost a family member to a faulty (yet certified!) medical device, would you feel that their death is justified by a marginal improvement to some company's bottom line? What if it wasn't a medical device with closed code, but a miracle pill whose manufacturer refused to release the formula to the government for analysis?

The argument I made in my original comment does not rely on the (un)soundness of your original claims - it is a moral argument about the value we place on human life. I'd be willing to bet that, even if you think that closed source is superior in every fashion, you would never be satisfied by your own justifications in the case of a personal tragedy. This contradiction suggests that, at the very least, we must draw a distinction between justifiably and unjustifiably closed source code.

Re: “I Want to Know What Code Is Running Inside My Body”

#210

I want to inspect the blueprints of every building I walk into and know the sourcing and composition of all the structural components as well. For my life depends on these things to be true and properly constructed.

I'd like to read commments here without total strawmen derailing the conversation to nonsense. Do you have anything constructive to add?

Do you?
Post reply on HN