Live data from Hacker News

Open letter from researchers involved in the “hypocrite commit” debacle

lore.kernel.org

131–140 of 384 posts

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#131
post #113

This apology fails from the 5th word: "We sincerely apologize for any harm..." While there are other requirements, a sincere apology cannot in any way entertain doubt about the fact that there WAS harm. Truly acknowledging the harm done is foundational to a real apology, and most of us (myself included) end up sneaking in weasel words or phrases like this. Psychologically, its nice for the apologizer, since it allows…

> a sincere apology cannot in any way entertain doubt about the fact that there WAS harm Someone will always be apologizing wrong for some. Some interpretation of what harm there was, is not necessarily the same as my interpretation. There are too many ways to construe what harm there was or may have been according to others to satisfy everyone addressed. This is an efficient wording that doesn't explicitly satisfy y…

"If you give me six lines written by the hand of the most honest of men, I will find something in them which will hang him."

I understand doubting the sincerity of the authors, but this argument hinges here on them saying "any" instead of "all" and they are often used interchangeably in casual conversation.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#132

There are some relatively minor issues with this apology that appear to already have ample discussion here, and I'll not repeat it. I want something more: I want to hear from the sponsoring faculty, research ethics board, and editors of the journal that published the article. There appear to be some systemic issues in addition to the investigators' ill-considered project. How was it that this research, which is clear…

What are your thoughts about this article[0], my reading or article is that; author fails in similar way (to some extent) as researchers and there's IRB in regards to ethics of such research.

[0] https://dave-dittrich.medium.com/security-research-ethics-re...

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#133
post #97
post #90

Earlier quoted context omitted.

> Bringing up why you did something in an apology is very shaky. Like in this case, it can sound more like justifying / excusing. Why is that a problem?

Answering myself: the apology feels more like a justification as to why they did, not an understanding of why they shouldn’t have.

> the apology feels more like a justification

Which I'm guessing is why they made it an open letter. This isn't about acknowledging their misdeeds and trying to fix their relationship with the OS community, this is them trying to sneak in spin and justifications to a public announcement to cover their collective asses, to put forth a false narrative that shows their actions in a better light than they acted in.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#134
The overwhelming majority of the HN comments seem critical of a party who... wrote and shipped code intended specifically to exploit the trust/naivete of others, to the others' detriment, for the offending party's career gain.

And which party then -- to add insult to injury -- didn't seem to appreciate the offense, when called on it.

IMHO, to examine this incident very seriously is appropriate and beneficial. If we ease up on the casting stones, and look at the problem a bit more generally, some of the lessons learned might hit close to home.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#135

This apology fails from the 5th word: "We sincerely apologize for any harm..." While there are other requirements, a sincere apology cannot in any way entertain doubt about the fact that there WAS harm. Truly acknowledging the harm done is foundational to a real apology, and most of us (myself included) end up sneaking in weasel words or phrases like this. Psychologically, its nice for the apologizer, since it allows…

This interpretation looks flawed. You discredit the entire message based on a single word--a very general word whose meaning you pinned to a definition which results in the most negative interpretation--and you also ignore the fact that they explicitly state the damage it caused in the same paragraph.

To clarify: I'm not arguing this is a good or bad apology; just that the justification provided here looks flawed. Human speech isn't a programming language; it's not well defined and it's more than the sum of its parts. One can't derive conclusions about a text by analyzing a tiny subset out of context.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#136

There is a major error made by the research group. It starts and ends here: "we did that because we knew we could not ask the maintainers of Linux for permission, or they would be on the lookout for the hypocrite patches." I am a Red Teamer and work with companies to understand how their detective/preventative/recovery controls and processes are working. Here's how you resolve this: You work with maintainers to get t…

This is how it should've been done. Like a war game (at least,as depicted in movies like Periscope Down), the organizers of the study and the project maintainers need to agree on (and be aware of!) bounds of the study, without necessarily knowing all of the details.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#138
post #57
post #17

Earlier quoted context omitted.

I think they could have really helped themselves by being humble and truly apologetic. Simple things like: - "We are sorry for the harm we caused" instead of "We're sorry for any harm we caused" - Not trying to explain their actions in the first paragraph of the apology! I think most folks are aware of their intent by now, and leading with yet another explanation just makes the whole thing feel disingenuous - Avoid s…

> hallmarks of a non-apology Is that a thing? Like there's some non-apology Bingo card you can fill out? I don't see a connection between the criteria you listed and genuine-vs-false contrition. You may perceive these things one way, but ultimately you can't know the minds of others well enough to tell if they are sincere or not about anything. You don't get to just declare yourself the arbiter of their feelings beca…

There literally are bingo cards, yes!

https://www.google.com/search?q=non+apology+bingo

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#139

I agree with this post > Unless the researchers are lying (which I've not seen a clear indication of), the 190 patches you have selected here are nothing more than collateral damage while you are completely missing the supposed patch submission addresses from which the malicious patches were sent! This all really sounds like a knee-jerk reaction to thier posting. I have to say, I think it's the wrong reaction to have…

If someone, or in this case a set of affiliated someones, have proven to do malicious or ethically questionable things, trust has to be earned. The risk of letting things stay without extensive verification is not worth it and I definitely don't consider this a kneejerk reaction given the potential perception risks.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#140
post #12
post #2

I'd like to give them the benefit of the doubt, but this is written like an apology they know they must write . It does not come across as apologetic. It comes across as rationalization veiled as an apology, and it doesn't sit well with me. I hope I'm just being overly sensitive here.

They didn’t have to write it. The first two sentences seem sincere. This reads as a real apology.

They didn't have to write it if they wanted the whole university to stay banned.
Post reply on HN