Live data from Hacker News

Open letter from researchers involved in the “hypocrite commit” debacle

lore.kernel.org

171–180 of 384 posts

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#171
post #139

Earlier quoted context omitted.

If someone, or in this case a set of affiliated someones, have proven to do malicious or ethically questionable things, trust has to be earned. The risk of letting things stay without extensive verification is not worth it and I definitely don't consider this a kneejerk reaction given the potential perception risks.

Hypocrite patches came from Gmail. Banned umn mail. Because that’s going to reduce risk?

It’s not so much that they banned umn email, as it is they banned the university of Minnesota.

This particular act is about avoiding the risk of researchers wasting kernel developers time.

As evinced by the response, it seems really unlikely that other institutions would think it’s a good idea to perform experiments on the kernel devs in the future.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#172
post #155
post #135

Earlier quoted context omitted.

This interpretation looks flawed. You discredit the entire message based on a single word--a very general word whose meaning you pinned to a definition which results in the most negative interpretation--and you also ignore the fact that they explicitly state the damage it caused in the same paragraph. To clarify: I'm not arguing this is a good or bad apology; just that the justification provided here looks flawed. Hu…

I would argue at this point in collective awareness of public communications, using a form of "sorry if I did any harm" regardless of specific words used is an explicit decision by the writer to not accept full culpability. I agree with original comment, when you see a weasel apology introduction, reading the rest is of little value.

> I would argue at this point in collective awareness of public communications, using a form of "sorry if I did any harm" regardless of specific words used is an explicit decision by the writer to not accept full culpability.

Based on my experience with the general public, with academics, and with industry folks, the criteria for what constitutes a sincere apology is not known by the majority. Furthermore, many of those who have heard the criteria do not accept it as a gold standard, and disagree with it (even those who are not being looked to for an apology).

The recipient can always choose to accept or not an apology. However, I find it quite distasteful to attribute intentions to someone simply because they did not follow a recipe (even if the choice not to was intentional).

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#173
post #160

Earlier quoted context omitted.

This is probably because they don't mean the apology, they were forced to write it by their administrators. And to be honest, I kind of agree with them. I don't really see what they did here as particularly bad. They demonstrated a very serious vulnerability in the linux kernel development process. I guess the harm they caused was wasting maintainers time, a bit? But what we all got out of it is the knowledge that re…

They performed an experiment on human subjects without informed consent.

This is the part I'm personally most interested in. Research generally has pretty strict ethical regulations about consent. I'm wondering if this would qualify as a violation of any of their university's or the conference's rules.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#174
post #168

Earlier quoted context omitted.

"Please respond to the strongest plausible interpretation of what someone says, not a weaker one that's easier to criticize. Assume good faith." https://news.ycombinator.com/newsguidelines.html I think it's both unfair and non-constructive to pick apart a apology letter based on one word like that. Let's assume good faith, especially when the writer's English might not be their first language (based on their name).

I think this response misses the point. The purpose of an apology is to make the recipient feel that you're sorry. That means thinking about how word choice is received is critical in crafting a good one. Your parent isn't saying the author's choice of words is in "bad faith", they're saying the author's word choice falls short of an effective apology due to a mistake that's common and easy to make. I agree, and I ha…

It seems like a nitpick to me, since the rest of the apology uses the proper choices of words, though. "The method used was inappropriate", "we made a mistake", etc.

The apology is also specific about what they did wrong despite their intentions. It really is a good apology after reading past the first six words.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#175
post #160

Earlier quoted context omitted.

This is probably because they don't mean the apology, they were forced to write it by their administrators. And to be honest, I kind of agree with them. I don't really see what they did here as particularly bad. They demonstrated a very serious vulnerability in the linux kernel development process. I guess the harm they caused was wasting maintainers time, a bit? But what we all got out of it is the knowledge that re…

They performed an experiment on human subjects without informed consent.

That's how security is tested. TSA undergoes undercover testing.

https://abcnews.go.com/US/tsa-fails-tests-latest-undercover-...

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#176

This apology fails from the 5th word: "We sincerely apologize for any harm..." While there are other requirements, a sincere apology cannot in any way entertain doubt about the fact that there WAS harm. Truly acknowledging the harm done is foundational to a real apology, and most of us (myself included) end up sneaking in weasel words or phrases like this. Psychologically, its nice for the apologizer, since it allows…

"Please respond to the strongest plausible interpretation of what someone says, not a weaker one that's easier to criticize. Assume good faith." https://news.ycombinator.com/newsguidelines.html I think it's both unfair and non-constructive to pick apart a apology letter based on one word like that. Let's assume good faith, especially when the writer's English might not be their first language (based on their name).

That’s responding to comments on HN. This apology wasn’t on HN.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#177
post #132

There are some relatively minor issues with this apology that appear to already have ample discussion here, and I'll not repeat it. I want something more: I want to hear from the sponsoring faculty, research ethics board, and editors of the journal that published the article. There appear to be some systemic issues in addition to the investigators' ill-considered project. How was it that this research, which is clear…

What are your thoughts about this article[0], my reading or article is that; author fails in similar way (to some extent) as researchers and there's IRB in regards to ethics of such research. [0] https://dave-dittrich.medium.com/security-research-ethics-re...

IANAL, but the claim that this research was exempt under 45 CFR 46.104(d)(2) seems suspect to me. (i) doesn't seem to apply because Linux kernel developers are required to go by their real names for licensing reasons (cf. the rules regarding Signed-off-by). (ii) seems dubious given that the authors themselves argue that they need reviewer consent to release information about the authors' malicious patches. Note in particular that both exemption categories are concerned with what information the researchers have ("information ... recorded" in (i), "any disclosure ... would not" in (ii)), not what they publish, so the idea that they need consent to publish this information seems to imply that they needed consent to collect it.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#178

Huge "I'm sorry I got caught" vibe. And it still refers to this malicious annoying behavior as "work" or "research", lmao

I mean, there’s all kinds of terrible unethical research.

What makes you think this isn’t research?

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#179
post #55

Earlier quoted context omitted.

To be fair, you wouldn’t expect these individual researchers to address the governance question. That should come from the University or the department in question.

Indeed, I agree -- the University of Minnesota should shoulder a degree of responsibility. That is even more so the case given that the researchers do not seem to understand (or clearly acknowledge that they understand) the importance of informed consent in both research and security operations, how much reputational damage (for them and the university) can result from unethical research, and the potential for actual…

The university should shoulder a huge degree of responsibility. They hired these "researchers". The apology should be coming from those who sponsored and funded the effort. Who cares about any "apology" these "researchers" cobbled together?

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#180

Do not entertain these people's pony show. Do not give them attention. The only way for UMN to be redeemed is for them to expel all the researchers responsible and to fire all the staff tangentially responsible for letting it happen.

Really? I unequivocally think it was unethical research, and thus a mistake.

But what’s the appropriate proportional response?

I honestly have a hard time thinking firing a bunch of people over this would be a good outcome for anyone.

What’s the end goal? I feel like already there’s been enough action to deter this kind of sneaky research in the future.

But at some point you’re just going to scare away the ethical researchers too.

Post reply on HN