"Using case studies involving machine learning and other hastily-executed figments of Silicon Valley's imagination, I will explain why computer security (and larger notions of ethical computing) are difficult to achieve if developers insist on literally not questioning anything that they do since even brief introspection would reduce the frequency of git commits." For anyone who hasn't heard a James Mickens talk, do…
He's the guy who wrote the Slow Winter. He's hilarious. https://www.usenix.org/system/files/1309_14-17_mickens.pdf
Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?
31–40 of 184 posts
Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?
#32Sidestepping comedy for a bit, there are a lot of inscrutable systems that we connect to 'things that matter' all the time. The financial systems themselves are pretty damn inscrutable. Corporations are very often inscrutable.
The word Mickens uses is "interpretable", which financial infrastructure is, and ML models are not.
Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?
#33Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?
#34Regarding the "we don't know how this stuff works" point, doesn't the FDA approve a ton of drugs where we don't know the exact mechanism of how it works? Do we need to know exactly and precisely how something works to know _that_ it works?
The overwhelming majority of medical treatments don't have inteligent humans actively trying to maliciously sabatoge them. Many drugs can be made horrendously lethal or otherwise dangerous with little effort (often just by significantly increasing the dosage) but we don't need to care very much because it's not possible to silently untracably apply that effort from arbitrarily far away, and there usually isn't anythi…
Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?
#35Regarding the "we don't know how this stuff works" point, doesn't the FDA approve a ton of drugs where we don't know the exact mechanism of how it works? Do we need to know exactly and precisely how something works to know _that_ it works?
No, but drugs spend literal years in testing through various models and animal subjects before even being considered for years more of human trials. Then the benefits are weighed up against the known side-effects and if they stack up the drug is approved. Even after that sometimes the analysis is wrong and the drug turns out to be ineffective or even harmful. Technology companies churn out things with barely a few we…
Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?
#36James Mickens is pure gold https://mickens.seas.harvard.edu/wisdom-james-mickens
> This World Of Ours: Wherein it is revealed that 1024-bit keys cannot prevent people from sending their credit card numbers to Nigerian princes. (I think that 1025-bit keys might solve the problem, but nobody listens to my common-sense advice.)
Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?
#37Fixing security is quite possible. Install a backdoor, go to jail for "exceeding authorized access". Fail to fix an security bug, get sued for negligence. Make it public policy that license contracts cannot override those responsibilities.
>Make it public policy that license contracts cannot override those responsibilities. This would be a disaster for open source. Who wants to write software for free if you can get sued for a bug?
Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?
#38Start with the Internet of Things example. He chalks up the abysmal security record of IoT devices to two factors: it keeps IoT devices cheap, and IoT vendors don't understand history. And there's a lot of truth in both these assertions! But they are both just expressing facets of a deeper, more fundamental reason: IoT devices aren't secure because their customers don't demand security.
This deeper problem completely explains why the two higher-level problems he observes exist. Making your product secure makes it more expensive and slower to come to market than just leaving it wide open, and the IoT vendors know their customers care about cost and availability and don't care about security. So they do the rational (in the homo economicus sense of the term) thing and optimize for things their customers are actually willing to pay for.
The same causality can be observed in the ML world. Mickens asks why people are hooking ML systems whose operation isn't fully understood to important things like financial decisionmaking and criminal justice systems. The answer is that the customers demand it. ML is trendy and buzzworthy, so if you're a vendor of (say) financial systems, and you can find some way to incorporate ML into your offerings with a straight face, now you have an attractive new checkbox on the feature list your salespeople dangle in front of potential customers. And once the effectiveness of having that box checked becomes clear, you kind of have to do it, even if you know it'll be ineffective or even worse, or risk losing business to a competitor with fewer scruples.
All of which is to say that what we see playing out in both these scenarios isn't really the vendors' fault. They are instead classic examples of market failure. People end up buying shoddy products because spotting their shoddiness requires technical expertise they don't have; responsible vendors who try not to make shoddy products lose sales to irresponsible vendors who don't; eventually all the responsible vendors are out of business and the only products available to buy are shoddy ones. There are lessons to learn from this, but they're economic rather than technological.
Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?
#39Re: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible?
#40Earlier quoted context omitted.
The overwhelming majority of medical treatments don't have inteligent humans actively trying to maliciously sabatoge them. Many drugs can be made horrendously lethal or otherwise dangerous with little effort (often just by significantly increasing the dosage) but we don't need to care very much because it's not possible to silently untracably apply that effort from arbitrarily far away, and there usually isn't anythi…
Is there any kind of sabotage other than malicious sabotage?
Stupidity is probably the biggest threat. Dietrich Bonhoeffer:
https://religiousgrounds.wordpress.com/2016/05/11/bonhoeffer...