Live data from Hacker News

People’s freedom jeopardised by new software adopted by California’s courts

bbc.co.uk

111–120 of 131 posts

Re: People’s freedom jeopardised by new software adopted by California’s courts

#111
post #99

Earlier quoted context omitted.

>Cars are designed with an assumption that they will be sometimes mishandled But not maliciously. If you run your car at another, the other car will break. I would compare it to lock-making. Despite thousands of years of lock-making, they _still_ get broken, and there's nothing to be done about it. >Deeply defensive programming methodologies also exist, from using safer languages and formally proven algorithms to pen…

Maliciously, too: see all these little things from door locks to built-in speed limiters. Formal certification may be paperwork. But things like using e.g. Haskell instead of Ruby, or Rust instead of C, generating exhaustive tests where possible, making sure that tests touch every line of the code base, writing short pure functions for the most part, and isolating effectful and unsafe code are not about paperwork, to…

>Formal certification may be paperwork. But things like using e.g. Haskell instead of Ruby, or Rust instead of C, generating exhaustive tests where possible, making sure that tests touch every line of the code base, writing short pure functions for the most part, and isolating effectful and unsafe code are not about paperwork, to my mind.

But you can't legislate languages (C is banned). You'd legislate something along the lines of three hundred pages of legalese requirements which read like Patent applications (there's a reason they look that way) which _would_ require use of a memory safe language but would require that the compiler be signed off by a bunch of lawyers, closed source and costing about $10,000 a license.

We had a government language. It was called Ada. There's a reason it never took off.

Re: People’s freedom jeopardised by new software adopted by California’s courts

#112

Software is currently in a strange place legislatively, in the 18th century Civil Engineering exploded (sometimes literally) and the number of disasters went up in radically (for an interesting case https://en.wikipedia.org/wiki/Tay_Bridge_disaster ), over time professional standards bodies grew alongside the maturing industry to both ensure that people working in the industry where adequately trained and adequately…

We already have a taste of these rules and regulations, for example HIPAA, PCI, and FIPS-140. I'm not saying I disagree with you, but keep in mind that those are all considered quite burdensome, and it's hard to see how that could be different. Also FIPS-140 is a good example of a standard that names specific technologies and so is doomed to lag behind the state of the art. Just be careful what you wish for! But as y…

I find it weird that all the standards in the privacy space (that I know about) seem to me to be much more about checkbox-checking compliance (ie. following their letter doesn't help much or at all) as opposed to standards in reliability space.

Re: People’s freedom jeopardised by new software adopted by California’s courts

#113

Earlier quoted context omitted.

>Cars are designed with an assumption that they will be sometimes mishandled But not maliciously. If you run your car at another, the other car will break. I would compare it to lock-making. Despite thousands of years of lock-making, they _still_ get broken, and there's nothing to be done about it. >Deeply defensive programming methodologies also exist, from using safer languages and formally proven algorithms to pen…

> It's not just money. It's paperwork, bureaucracy, and ultimately not effective. Practically, the only way to ensure safety is to take down the internet. https://logfall.wordpress.com/all-or-nothing-fallacy/ We can and should be making incremental improvements to technology. Continuing to use methods that are known to be faulty is gross negligence in the legal sense: https://en.wikipedia.org/wiki/Gross_negligence We…

The problem is that there are only two ways to have a safe internet:

1. Remove pacemakers and cars from the internet.

2. Make a government bureaucracy, lock down computers to running "approved code only", requiring certification before being allowed to touch a compiler, require all code (including macros, one of the most popular sources of viruses) and websites be "formally verified" (a very expensive project) and written without bugs.

I'd prefer #1.

Re: People’s freedom jeopardised by new software adopted by California’s courts

#114

Software is currently in a strange place legislatively, in the 18th century Civil Engineering exploded (sometimes literally) and the number of disasters went up in radically (for an interesting case https://en.wikipedia.org/wiki/Tay_Bridge_disaster ), over time professional standards bodies grew alongside the maturing industry to both ensure that people working in the industry where adequately trained and adequately…

We already have a taste of these rules and regulations, for example HIPAA, PCI, and FIPS-140. I'm not saying I disagree with you, but keep in mind that those are all considered quite burdensome, and it's hard to see how that could be different. Also FIPS-140 is a good example of a standard that names specific technologies and so is doomed to lag behind the state of the art. Just be careful what you wish for! But as y…

> those are all considered quite burdensome

Not to mention ambiguous. I've never found two people who can agree on the proper interpretation of even one of the guidelines in HIPAA or PCI. My experience with both has been managers who would rather spend a week trying to get out of having to be compliant than spend a day just complying.

Re: People’s freedom jeopardised by new software adopted by California’s courts

#115
post #106
post #17

Similar problems have been reported in Tennessee and also in Indiana - where prosecutors have had a perhaps more troubling issue of inmates being mistakenly released early. It seems backwards to describe this as more troubling.

Keep in mind this is a UK site. People are guilty until proven innocent, so from that perspective guilty people going free may indeed seem more troubling.

The UK is "Innocent until proven Guilty" except for specific exemptions (mostly related to not handing over encryption passwords, which is an offence itself..a lovely little logical trap they snuck in on that one didn't they).

Re: People’s freedom jeopardised by new software adopted by California’s courts

#116
post #69

Earlier quoted context omitted.

Not at all. Do you want a rapist getting out of jail earlier? That would be troubling.

But a person with a traffic ticket getting jailed and registered as a sex offender is better? Both are equally troubling. In my mind, the latter moreso.

Hm - I take your point. I was coming at it from a public safety point of view first and foremost. But I can see the other side, sure.

Re: People’s freedom jeopardised by new software adopted by California’s courts

#117
post #49

Oh, no, people's freedom is being jeopardised? That's terrible, BBC. http://www.theregister.co.uk/2016/11/30/investigatory_powers...

What does one have to do with the other?

Does the UK passing the investigatory powers act in any way have any bearing on abuses by the legal system in other countries or are we just playing "whataboutism bingo" today?

Re: People’s freedom jeopardised by new software adopted by California’s courts

#118
post #12

Although I don't have any direct evidence regarding this instance, I wouldn't be surprised if the old system was greenscreen & form-based, while the new one is some kind of shiny Java-backed web app. It wouldn't surprise me at all if the old system was faster to use and less error-prone: those old greenscreen apps tended to be optimised for long-term use, rather than for showing off in a board-room demo.

That's exactly the difference. Mr Woods (the defender I quote in the story) described the old system as something a computer hacker would use in a Hollywood movie... but it worked and was stable.

Re: People’s freedom jeopardised by new software adopted by California’s courts

#119

Earlier quoted context omitted.

It definitely seems like more of the blame here should be shouldered by the police and the courts, who, knowing that the system has problems (and hopefully assured that those problems will be resolved in the future) should put less faith in them, and double-check (against filed papers, for example) potentially dubious results. This is more expensive in terms of people's times, but it's just part of the cost of adopti…

Indeed. The "Computer says no" or "Computer says catch him" attitude should change: particularly if you know it's a new system, check twice before making drastic actions based on data it gives.

I think it's more complex than checking twice. You can't check twice for something that doesn't exist on a record but should, for example. How would you know what to look for?

Re: People’s freedom jeopardised by new software adopted by California’s courts

#120
post #90

I'm so glad I don't have to only rely on a journalism source across the globe and can count on my local paper to warn me about such things. https://duckduckgo.com/?q=site%3Alatimes.com+tyler+technolog... /s

To be fair - it's been covered by the East Bay Times, SF Chron and KQED in some depth. That's how I heard about it.
Post reply on HN