Live data from Hacker News

Open letter from researchers involved in the “hypocrite commit” debacle

lore.kernel.org

351–360 of 384 posts

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#351

Earlier quoted context omitted.

> Aditya withdrew his “garbage” commit when made aware it was not correct. It seems like he withdrew it in response to stumbling over [2], wherein Al Viro points out that the correct thing to do with buggy commits is to request they be reverted. (Based on, among other things, the fact that said LWN post is cited in the revert.) > Leon Romanovksy has offered no follow up for his claim of security holes nor explained h…

> He did offer the patch I cited Fair point. Not sure what became of the other alleged security holes. > "I promise I'm not part of that research" This is a gross oversimplification of the evidence that Aditya is not malicious. I offered a lot of evidence above that Aditya is likely not malicious just clumsy. The lwn post you pointed to reaches the same conclusion “ I am quite certain by now that patches had been cra…

I think we're agreeing loudly.

I agree with you that Aditya is probably not malicious, just clumsy, to be clear. But I feel like it's probably reasonable for someone in GregKH's position to have a higher threshold to clear than "probably" once the question is posed.

I also wasn't trying to claim that "I promise I'm not part of that research" encompassed all the evidence, just remark that personal attestation of innocence would not have been a useful input at that juncture.

I'm not sure, however, at what point an apology is merited now - anything significantly less than 100% of someone's patches seems like a poor choice given the small absolute number of bad patches that were used in that paper, but we're choosing by pseudorandom sample, but that's biased by how active/familiar the maintainers are with different parts of the code...etc.

So I don't know what the right confidence level should be for concluding a prior judgment of "you might be malicious" was wrong. (Maybe enumerating+examining all the "malicious" commits remarked upon by Leon, since that's what sparked the fire?)

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#352
post #274

Earlier quoted context omitted.

I don’t think that really makes sense. Often in a personal relationship the “action taken” will be innocuous considered in itself. But you may have done it knowing full well that it would hurt the other person’s feelings. In a case where the person’s feelings are totally irrational and you had a strong independent justification for taking the action, it does get more complicated. In general, though, I think it’s a hu…

I don't think you can take the action outside of the context in which it is performed. If you take action knowing another person is likely to feel hurt, are you... not sorry you took that action? Regardless, you can't genuinely apologize for things that aren't in your control. (You can and should empathize and sympathize with their feelings about it.) It may be a convenient fiction at times, but there are many downsi…

I don’t really buy the idea that other people’s feelings are entirely within their own control and not at all within my control.

If we really had complete agency over our feelings then I guess we’d all just choose to feel great all the time. Doesn’t seem to work that way.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#353
post #352

Earlier quoted context omitted.

I don't think you can take the action outside of the context in which it is performed. If you take action knowing another person is likely to feel hurt, are you... not sorry you took that action? Regardless, you can't genuinely apologize for things that aren't in your control. (You can and should empathize and sympathize with their feelings about it.) It may be a convenient fiction at times, but there are many downsi…

I don’t really buy the idea that other people’s feelings are entirely within their own control and not at all within my control. If we really had complete agency over our feelings then I guess we’d all just choose to feel great all the time. Doesn’t seem to work that way.

Suppose my sibling and I call each other 'ugly' as a greeting and we normally enjoy this behavior. If one day I feel hurt, is my sibling responsible for that feeling? If yes, is my sibling responsible for the depth of that feeling? Even if, on this particular day, I feel more hurt by the comment because I had just broken up with a partner? Is my sibling responsible for the duration of the feeling? Even if my response to the experience is to repeat the comment over and over in my head even after my sibling apologizes? Is my sibling responsible for all the decisions in my life (including encouraging that behavior) that have lead me to be sensitive to the comment in that moment? Am I powerless to change (whether in the near term or long term) how I respond to that comment, whether through meditation, therapy, confidence training or whatever? Am I also powerless to remove my sibling from my life?

In my view, the extent to which we can influence the emotions of another is the extent to which the recipient themselves has given implicit permission to do so; which is to say, they have agency. I don't think that simplifies into being able to choose to feel great any old time we like. I also don't think it at all excuses bad behavior or justifies a lack of empathy. But I will say that I feel a lot more good moments and less frequent and intense bad moments since I adopted this view and took responsibility for my own emotions.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#354

Earlier quoted context omitted.

That depends on the sentence context.[1] As used here it is fully correct; "we sincerely apologize for all harm our research group did" would be highly anomalous, whereas the phrasing they actually used is conventional. "We sincerely apologize for all the harm our research group did" would be a little less unnatural than "...for all harm...", but it's still an unusual choice of wording that ends up sounding like you…

How about "we apologize for the harm"?

You want my opinion? It's possible, it's less standard than the "for any harm" form, but it means roughly the same thing.

It wouldn't have occurred to me to discuss it above, because I thought I was contrasting any with all, and neither is present in that example. But I'd rate it above most of the alternatives discussed (while still below "for any harm").

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#355

Earlier quoted context omitted.

Apologies are really difficult to do. You have to acknowledge (in full) what it is that you are apologising for. That's the most important thing. Promises are meaningless. It's not possible to "be genuine"; especially in a public post, nothing is genuine, everything is PR and smoke. Both the researchers and their ethics board need to grovel. If they did that, this tornado-in-a-teacup could be over in a month or two.…

No one should have to "grovel" for an apology to be effective.

The ethics board were asleep on the job. Grovelling is probably less painful than falling on your sword.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#356
post #322
post #292

Earlier quoted context omitted.

But if I choose to interact with the community, does my choice to present myself, justify any and all abusive actions they may volley at me? Oof coarse not. The point would ordinarily be a good one, but I think you've misused it. The Linux kernel community, by your logic, chose to interact with and be open to patches which were not properly vetted. This framing seems secondary to a seemingly more important point, whi…

Context who does what actions is important, you seem to equate university "professionals" research actions to volunteer community actions, it is false to large degree, like comparing apples to orangeries, additionally, consent to be deceived is critical factor. No one in Linux community promises you to be nice[0], and Linux has stepped aside due to his past behavior[1]. To me main point who initiates actions eg. did…

So it's bad for the researchers to deliberately deceive the community because a rule says patches must be good faith but it's not bad for the community to be abusive because there's no rule that says it shouldn't?

so the community can be abusive but no one may abuse the community?

If so, I think that sounds like the basis for bullying culture which perhaps unsurprisingly is what is observed.

I think it's naive for them to assume that all submissions are done in good faith, just as it's naive for participants to assume that all interactions will be nice. It's not the community's fault they were deceived nor is it the participants fault they were abused.

My point is there is an equality. That personal responsibility, ethics and integrity should apply to everyone not just to some labeled group.

What it sounds to me like you're saying is, it's the researchers fault that they deceived us and we have a right to be outraged but it's not our fault that we're abusive to participants and they have no right to be surprised at that. Am i hearing you wrong?

my point i think is to draw attention to the apparently unequal application of these principles of ethics responsibility and integrity. Additionally I'm a little worried that your reluctance to compare your different groups is an attempt to conceal, and justify, a continued unequal application of responsibility ethics and integrity.

That sounds pretty harsh towards you and so I doubt that's actually what you're saying because I don't think you're someone who lacks a moral character like that. I think probably you and I are just misunderstanding what each other is saying. Perhaps.

For instance I don't think either of us believe that bad behavior on either side whether the deception of the researchers or the abusiveness of the community is okay.

I suppose what I'm doing is addressing, or trying to, to contrast the reactions of either side to those things and expose what I see as an unfairness or a double standard or an unequal application. hope that helps you understand what I'm saying. Anyway have a good doi

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#357
post #356
post #322

Earlier quoted context omitted.

Context who does what actions is important, you seem to equate university "professionals" research actions to volunteer community actions, it is false to large degree, like comparing apples to orangeries, additionally, consent to be deceived is critical factor. No one in Linux community promises you to be nice[0], and Linux has stepped aside due to his past behavior[1]. To me main point who initiates actions eg. did…

So it's bad for the researchers to deliberately deceive the community because a rule says patches must be good faith but it's not bad for the community to be abusive because there's no rule that says it shouldn't? so the community can be abusive but no one may abuse the community? If so, I think that sounds like the basis for bullying culture which perhaps unsurprisingly is what is observed. I think it's naive for th…

It is not just bad researchers behavior, it not just unprofessional, it is unacceptable in scientific community, this is an fact, this is where most of outrage is coming from, but at same time similar unethical behavior is legal to a degree[0] in business organization.

No one is arguing that any online community perfect, no organization is perfect, but organization imperfections is not a justification for unethical behavior toward given imperfect organization, to a large degree, there rare case where it is justified, but this not the case here, at all what so ever.

> I think it's naive for them to assume that all submissions are done in good faith.

This is false, there where numerous attempts to submit backdoor to linux kernel, and most in the community are aware that such attempts will never stop, this why also some people criticize that there's study is just another scientific garbage paper.

What is unacceptable in name of science submitting commits in bad faith without informed consent.

What is unacceptable in name of science or otherwise ATTEMPTING an unauthorized penetration testing, this is illegal.

[0] https://www.theatlantic.com/technology/archive/2014/06/every...

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#358
post #357
post #356

Earlier quoted context omitted.

So it's bad for the researchers to deliberately deceive the community because a rule says patches must be good faith but it's not bad for the community to be abusive because there's no rule that says it shouldn't? so the community can be abusive but no one may abuse the community? If so, I think that sounds like the basis for bullying culture which perhaps unsurprisingly is what is observed. I think it's naive for th…

It is not just bad researchers behavior, it not just unprofessional, it is unacceptable in scientific community, this is an fact, this is where most of outrage is coming from, but at same time similar unethical behavior is legal to a degree[0] in business organization. No one is arguing that any online community perfect, no organization is perfect, but organization imperfections is not a justification for unethical b…

Thanks for repluing. I'll trie to make sense of what you're saying and maybe reply you loiter. Have good doi :)

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#359
post #207

Earlier quoted context omitted.

> There's lots of systemically horrible things that can happen if you're not careful about what you allow. Of course there are. But what specifically are the harms that are going to be caused by either this research or a landing page A/B test without a click through pop up? The existence of theoretical harms for broad categories of potential research does not have a whole lot of bearing on these specific lines of res…

If I sit across the street from your house in a van and observe your life, noting down the times you come and go, and logging what I can see through your window, and then using that data to market things to you, would you agree that you'd rather be able to provide and withdraw consent for this activity? No harm done to you.

I think it's reasonable to consider invasion of privacy a harm on its own. There was no invasion of privacy in this example.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#360
post #187

Earlier quoted context omitted.

> Says who? Me and common sense. I don't believe consent is relevant when there is no risk of harm to the subject. IRBs and the GDPR are overly aggressive on this point, probably as a reaction to real and important violations of privacy. But the idea that A/B testing the color of your CTA button on a landing page requires informed consent is absurd.

If anything they wasted time and energy of project maintainers. This alone should be enough to see the behavior is inexcusable.

Ya, they wasted a bit of their time. That wasn't very nice. But it's hardly the great crime it's being made out to be, and what they did was a huge public service. It's impossible to over-state the importance of linux kernel security.
Post reply on HN