Live data from Hacker News

Open letter from researchers involved in the “hypocrite commit” debacle

lore.kernel.org

181–190 of 384 posts

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#181

This apology fails from the 5th word: "We sincerely apologize for any harm..." While there are other requirements, a sincere apology cannot in any way entertain doubt about the fact that there WAS harm. Truly acknowledging the harm done is foundational to a real apology, and most of us (myself included) end up sneaking in weasel words or phrases like this. Psychologically, its nice for the apologizer, since it allows…

"Please respond to the strongest plausible interpretation of what someone says, not a weaker one that's easier to criticize. Assume good faith." https://news.ycombinator.com/newsguidelines.html I think it's both unfair and non-constructive to pick apart a apology letter based on one word like that. Let's assume good faith, especially when the writer's English might not be their first language (based on their name).

> English might not be their first language (based on their name)

This is a pretty weak assumption. Someone's name (and physical appearance) don't give you an accurate information about anything.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#182
post #168

Earlier quoted context omitted.

I think this response misses the point. The purpose of an apology is to make the recipient feel that you're sorry. That means thinking about how word choice is received is critical in crafting a good one. Your parent isn't saying the author's choice of words is in "bad faith", they're saying the author's word choice falls short of an effective apology due to a mistake that's common and easy to make. I agree, and I ha…

It seems like a nitpick to me, since the rest of the apology uses the proper choices of words, though. "The method used was inappropriate", "we made a mistake", etc. The apology is also specific about what they did wrong despite their intentions. It really is a good apology after reading past the first six words.

ESL here. How correct is it to use ’any harm’ to mean ‘all harm’.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#183
post #167

Earlier quoted context omitted.

They performed an experiment on human subjects without informed consent.

Sure, but so does every website that AB tests a landing page. Consent is only relevant when there is some risk to the subject (or something they value, like privacy, etc).

What about the risk to the reputation of anyone who approves these patches? Or of intentinally buggy patches making it into the wild and being exploited?

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#184
post #167

Earlier quoted context omitted.

They performed an experiment on human subjects without informed consent.

Sure, but so does every website that AB tests a landing page. Consent is only relevant when there is some risk to the subject (or something they value, like privacy, etc).

> Consent is only relevant when there is some risk to the subject

Says who? I don't think that's true according to IRB standards in the US. Nor is it true for websites who A/B test according to the GDPR

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#185

Earlier quoted context omitted.

They performed an experiment on human subjects without informed consent.

That's how security is tested. TSA undergoes undercover testing. https://abcnews.go.com/US/tsa-fails-tests-latest-undercover-...

TSA agents are informed that there are tests as part of their job. See this comment for another example of informed consent in security testing

https://news.ycombinator.com/item?id=26929797

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#186
post #183
post #167

Earlier quoted context omitted.

Sure, but so does every website that AB tests a landing page. Consent is only relevant when there is some risk to the subject (or something they value, like privacy, etc).

What about the risk to the reputation of anyone who approves these patches? Or of intentinally buggy patches making it into the wild and being exploited?

> What about the risk to the reputation of anyone who approves these patches?

This is a risk, but it's exposing vulnerabilities is always preferable to leaving them in place.

> Or of intentinally buggy patches making it into the wild and being exploited?

There was no real risk of this. They specifically did not allow it to make its way into real releases.

If they had allowed it into actual releases, I would have a serious problem with that.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#187
post #167

Earlier quoted context omitted.

Sure, but so does every website that AB tests a landing page. Consent is only relevant when there is some risk to the subject (or something they value, like privacy, etc).

> Consent is only relevant when there is some risk to the subject Says who? I don't think that's true according to IRB standards in the US. Nor is it true for websites who A/B test according to the GDPR

> Says who?

Me and common sense. I don't believe consent is relevant when there is no risk of harm to the subject. IRBs and the GDPR are overly aggressive on this point, probably as a reaction to real and important violations of privacy. But the idea that A/B testing the color of your CTA button on a landing page requires informed consent is absurd.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#188

Earlier quoted context omitted.

It seems like a nitpick to me, since the rest of the apology uses the proper choices of words, though. "The method used was inappropriate", "we made a mistake", etc. The apology is also specific about what they did wrong despite their intentions. It really is a good apology after reading past the first six words.

ESL here. How correct is it to use ’any harm’ to mean ‘all harm’.

There isn’t much difference and both are really correct. The problem with ‘any’ as raised here is the ambiguity. It could be taken to mean ‘any harm, if it occurred’ or ‘any single bit of harm that did occur’. So in this sense ‘all harm’ would be safer and less ambiguous.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#189
post #43

A BS non-apology is not enough. These assholes should at the very least be reprimanded by the University of Minnesota for unethical research practises (psychological experiments on humans without their consent) and bringing the whole institution in disrepute.

The reputational damage to the department is staggering.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#190

Earlier quoted context omitted.

It seems like a nitpick to me, since the rest of the apology uses the proper choices of words, though. "The method used was inappropriate", "we made a mistake", etc. The apology is also specific about what they did wrong despite their intentions. It really is a good apology after reading past the first six words.

ESL here. How correct is it to use ’any harm’ to mean ‘all harm’.

Not correct, at least in this context. "Any harm" means there could be no harm, or some harm, but "all harm" admits there was harm. I.e. "any" is not an admission of doing harm, or an acceptance that it happened.

If you want to apologise, "all harm" admits you caused harm, which seems necessary for an apology. "Any" is a bit like those "I'm sorry if you were offended" non-apologies, though in this case the rest of the message does better than that.

Post reply on HN