Live data from Hacker News

Open letter from researchers involved in the “hypocrite commit” debacle

lore.kernel.org

91–100 of 384 posts

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#91
This apology fails from the 5th word:

"We sincerely apologize for any harm..."

While there are other requirements, a sincere apology cannot in any way entertain doubt about the fact that there WAS harm.

Truly acknowledging the harm done is foundational to a real apology, and most of us (myself included) end up sneaking in weasel words or phrases like this.

Psychologically, its nice for the apologizer, since it allows one to think "i'm being good by apologizing, but maybe I didn't do anything bad after all?".

But from the apologizee standpoint, these phrases are often devastating and can make it clear that the apologizer has no real recognition or care of what happened.

Personally I've worked pretty hard to try to remove these sorts of phrases from my apologies. It's not easy. It makes you feel much more vulnerable and you really have to let whatever you did sit with you in a very uncomfortable way. But it's worth it.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#92

Does the response of the Linux community seem like the response of some corporations when security vulnerabilities are disclosed? In each case, a vulnerability was disclosed. With Linux being used everywhere you can be sure intelligence services etc are likely sending in bad patches. If the Linux kernel requires only patchers with good intentions, and doesn’t have other means of catching this stuff, we are screwed.

However, when a vulnerability is found, you would expect that the path by which that vulnerability was introduced would be shut off, right? In this case, what they’ve done is to revert all patches from this group, pending further review, just in case something else slipped through.

They’re not sweeping issues under the carpet. They are actively addressing those issues.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#93

I really appreciate the apology and as they stated, its unconditional nature. Good. However, I find something very problematic. This quote shows it: "We have learned some important lessons about research with the open source community from this incident." This is something I don't like. This is not something about "research with the open source community". If anything, they should have learned something about treatin…

"If anything, they should have learned something about not treating human beings as persons and not as involuntary guinea pigs."

Perhaps the entire "tech" industry needs to learn that lesson. Non-technical end users should be entitled to that same level of trust as nerds. I can download free open source code, extract a tarball and build the software without worrying too much about scanning through all the files first for phone home/telemetry/OriginTrials nonsense.^1 However non-technical end users who use programs compiled for them by "tech" companies with ads and surveillance as their "business model" are not entitled to the same trust. I cannot think of any justification for the difference.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#95
post #8

Earlier quoted context omitted.

Just curious, and I'm genuinely asking as someone who thought the letter seemed well-intentioned: what should they have put in the apology letter?

> We are sorry for the harm we've caused by our unethical experimentation involving members of the Linux community. In accordance with community standards and a desire to avoid benefiting from our ethical failure, we have requested the immediate retraction of the papers and other published work resulting from this unethical experimentation. We are also working together with our institutional leadership to address the…

Good suggestion, especially getting the IRB involved. The board failed to recognize that the target of the research was not inanimate software but human beings.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#96

Does the response of the Linux community seem like the response of some corporations when security vulnerabilities are disclosed? In each case, a vulnerability was disclosed. With Linux being used everywhere you can be sure intelligence services etc are likely sending in bad patches. If the Linux kernel requires only patchers with good intentions, and doesn’t have other means of catching this stuff, we are screwed.

> the response of some corporations when security vulnerabilities are disclosed There's a big ethical difference between trying to exploit a piece of commercially produced software, and trying to exploit the time and actions of humans who are producing software which is given away for free.

Also, this wasn’t a vulnerability found in existing code that was disclosed. This was an attempt to introduce several of them in the form of innocent looking commits.

I don’t think the free vs commercial aspect is the main issue here; lots of kernel devs are paid for their work after all...

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#97
post #90
post #70

Earlier quoted context omitted.

Several parts read strangely to me > we are very sorry that the method used in the “hypocrite commits” paper was inappropriate This reads more as "sorry you were offended" than "It was inappropriate and we are sorry". > As many observers have pointed out to us, we made a mistake by not finding a way to consult with the community and obtain permission before running this study; we did that because we knew we could not…

> Bringing up why you did something in an apology is very shaky. Like in this case, it can sound more like justifying / excusing. Why is that a problem?

Answering myself: the apology feels more like a justification as to why they did, not an understanding of why they shouldn’t have.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#98
post #80

Earlier quoted context omitted.

That only tells me, that there's more garbage than just one individual. If they lack knowledge of why it was bad, what will prevent them from doing another garbage study next time.

This incident, time, and reflection.

But their self-relfection, and I say basic ethics is severely lacking.

This study could have been done with consent, with limited bias, but they chose to go the idiot route.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#99

> we did that because we knew we could not ask the maintainers of Linux for permission, or they would be on the lookout for the hypocrite patches. For you security people out there, how do red teams handle this issue?

A red teamer answered above: https://news.ycombinator.com/item?id=26929797

Basically, warn in that you’re going to do it at some point in the future. Then do it in a time-frame of maybe 6 months or so from another ID. Maybe get some of the higher-ups to sign off (say Linus or Greg in this case) beforehand. At the very least, engage with the community...

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#100

Does the response of the Linux community seem like the response of some corporations when security vulnerabilities are disclosed? In each case, a vulnerability was disclosed. With Linux being used everywhere you can be sure intelligence services etc are likely sending in bad patches. If the Linux kernel requires only patchers with good intentions, and doesn’t have other means of catching this stuff, we are screwed.

No, not really. For starters, notice how (some) corporations threaten legal action when evidence of a bug is disclosed? And how, here, there was simply a public ban on account of no longer being a good faith participant?
Post reply on HN