Live data from Hacker News

Open letter from researchers involved in the “hypocrite commit” debacle

lore.kernel.org

361–370 of 384 posts

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#361
post #213
post #187

Earlier quoted context omitted.

> Says who? Me and common sense. I don't believe consent is relevant when there is no risk of harm to the subject. IRBs and the GDPR are overly aggressive on this point, probably as a reaction to real and important violations of privacy. But the idea that A/B testing the color of your CTA button on a landing page requires informed consent is absurd.

> But the idea that A/B testing the color of your CTA button on a landing page requires informed consent is absurd. A/B testing on major platforms is much more sophisticated than that[1]. It's a crucial practice for advertisers and marketing teams that dives deep into researching the psychological response towards images, text and dozens of other variables. Human subjects are acting as lab rats in order to extract so…

> A/B testing on major platforms is much more sophisticated than that[1].

On some it is, and some it isn't.

> It's a crucial practice for advertisers and marketing teams that dives deep into researching the psychological response towards images, text and dozens of other variables. Human subjects are acting as lab rats in order to extract some data points to drive the next test and campaign.

This is just a long and emotionally laden way of saying "changing images and text to see which works best".

> So, yes, it should definitely require informed consent and opting in.

Guess we're just going to have to agree to disagree then. I don't see any reason whatsoever to think that this practice is harmful to the subjects being experimented on.

At worst, it's harmful to society in general because it incentivizes consumerism and potentially self destructive behavior. But that is completely orthogonal to the issue of informed consent. If you got perfectly informed consent from 10,000 people to tease out the perfect pitch text, and then deployed it against the rest of the population, the effect would be exactly the same, whether or not you got consent.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#362
post #160

Earlier quoted context omitted.

This is probably because they don't mean the apology, they were forced to write it by their administrators. And to be honest, I kind of agree with them. I don't really see what they did here as particularly bad. They demonstrated a very serious vulnerability in the linux kernel development process. I guess the harm they caused was wasting maintainers time, a bit? But what we all got out of it is the knowledge that re…

The purpose of the research was to publicly announce that that the research subjects (who did not consent to being studied) messed up. The research consisted of submitting patches specially crafted to make sure the (non-consenting) subjects did indeed mess up.

Ya, I get that. But the point was to demonstrate that the project was vulnerable to this kind of attack - which it was. That's an extremely important finding.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#363
post #352

Earlier quoted context omitted.

I don’t really buy the idea that other people’s feelings are entirely within their own control and not at all within my control. If we really had complete agency over our feelings then I guess we’d all just choose to feel great all the time. Doesn’t seem to work that way.

Suppose my sibling and I call each other 'ugly' as a greeting and we normally enjoy this behavior. If one day I feel hurt, is my sibling responsible for that feeling? If yes, is my sibling responsible for the depth of that feeling? Even if, on this particular day, I feel more hurt by the comment because I had just broken up with a partner? Is my sibling responsible for the duration of the feeling? Even if my response…

I think your sibling should apologize for hurting your feelings by calling you ugly.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#364
post #216
post #212

Earlier quoted context omitted.

This paint on canvas got sold and therefore it is Art.

What is that supposed to mean? Conference publications are for research. I pulled this from the website of Oakland 2021 Since 1980 in Oakland, the IEEE Symposium on Security and Privacy has been the premier forum for computer security research, presenting the latest developments and bringing together researchers and practitioners. We solicit previously unpublished papers offering novel research contributions in any a…

You’re defining whether something is “research” not based upon what it is or what it contains, but just based upon whether or not it’s been published.

I was pointing out that this is like defining whether or not something is “art” not based upon the work itself, but instead based solely upon whether somebody bought it.

Incidentally, my recipe for apple pie was printed in a newspaper, and so therefore my recipe is “news”.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#365
post #290
post #222

Earlier quoted context omitted.

Non-academics get fired for doing unethical things entirely unrelated to their jobs all the time, just to avoid bad publicity. Determining how to conduct your research ethically is a core part of being a researcher. Basic research into pen testing and security research would have revealed how unethical this study was. I see firing as completely justifiable given that was a failure in a core part of thier job, that no…

> Non-academics get fired for doing unethical things entirely unrelated to their jobs all the time, just to avoid bad publicity. Yes, only if it's unrelated to their jobs. People get hired, not fired, to do unethical research in industry labs. Ethics is breached all the time in industry - rarely even considered. Google tried to make amends, but decided caring too much about ethics was a roadblock to their goals. Tesl…

I wasn't comparing morality of academia and industry, I was making an argument about what are considered a reasonable grounds to calling for someone's firing.

If you are trying to argue that publicly funded research institutions don't think ethics are a core part of research, that seems like something that needs to be addressed.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#366
post #211

Earlier quoted context omitted.

The researchers already lied when they conducted the study. What you are proposing is that we now should trust them to tell us the extent of their previous duplicitousness. The most recent patch, which triggered the bad, has not been explained in good faith and it seems likely there were mistruths involved in that exchange as well. So while it is absolutely a waste of time to have to go back through those 190 commits…

Why shouldn’t we trust them on the extent of their lies? Except three research commits, everything they have said has been true. Given how few of the 190 have turned out wrong, given the timeline of the research relative, given the existing static analysis paper. Did Aditya Pakki write two entire papers about static analysis as cover for continuing this hypocrite commit research? Or did Aditya Pakki submit a bad patc…

Let's flip this on it's head and posit a counterfactual. Let's say that Greg does nothing and re-extend trust. Then vulnerabilities are exploited that exist due to additional bad patches submitted by this researcher. Greg would be rightly held to account for failing to his due diligence when he had clear evidence of malicious commits.

So even if all the the commits are good and even if Greg believes that, he has still been forced into these actions by the violations of trust committed by the researchers.

You are correct that the line as to what patches is a bit arbitrary, but it was always going to be. The research was conducted by the University so it seem the most reasonable place to draw the line to me.

I have still yet to see any explanation from the researchers as to why that "bad patch" happened, didn't include a reference to the automated tool as required, or what tool it even was.

I do think Greg is angry, but I don't think your insistence asscribing Greg's anger as his primary motivation is fair to him or consistent with HN guidelines on comments. I think you could make points about reverting commits without what seem to me like unnecessary personal attacks.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#367

Earlier quoted context omitted.

> I've run such phishing campaigns To test if employees are easy to pish, or was it for real (black hat)?

The former _only_. I'm usually not testing only whether employees are easy to phish (the answer is pretty much 100% yes). I'm testing end-to-end: can you as a company prevent me from phishing through email protections? Can you detect when I'm phishing your employees? Will your employees report potential phishing emails? Can you figure out (without me telling you) which employees were targeted and which attacks were s…

This job seems like fun :-)

Even more fun if you were allowed to social engineer your way into the office and steal someone's powered on not-screenlocked laptop :-)

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#368
post #352

Earlier quoted context omitted.

I don’t really buy the idea that other people’s feelings are entirely within their own control and not at all within my control. If we really had complete agency over our feelings then I guess we’d all just choose to feel great all the time. Doesn’t seem to work that way.

Suppose my sibling and I call each other 'ugly' as a greeting and we normally enjoy this behavior. If one day I feel hurt, is my sibling responsible for that feeling? If yes, is my sibling responsible for the depth of that feeling? Even if, on this particular day, I feel more hurt by the comment because I had just broken up with a partner? Is my sibling responsible for the duration of the feeling? Even if my response…

This highlights the importance of apologizing for the impact something has, vs. just apologizing for the act itself.

There is no universal rule that can be applied to determine when one vs. the other is appropriate, but seemingly innocuous actions can have negative impact, and apologizing for the innocuous thing may not always make sense.

To be clear, this is not universally true. There are situations where apologizing for the action makes sense, and situations where the action that led to a negative outcome are either inconsequential on their own, or there might be a myriad of factors leading to the need for an apology.

Apologizing for the action can also come across as disingenuous or passive aggressive in the wrong context. This is especially true when the action is well-intentioned, but has the wrong effect. Taken to an extreme, this sounds like "I'm sorry I tried helping".

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#370
post #331
post #235

Earlier quoted context omitted.

I agree with the approach you’ve outlined. I also empathize with the plight of the researchers — Linux is a bit different than normal Red Team engagements, in that a normal organization has a hunch of administrative / management layers who typically do not participate in the operations of the system being tested. A VP of engineering at a medium to large company is unlikely to be committing code, much less maintaining…

Why do you think there will be any change in behavior ? It is not like community members are not for look out for bad commits on every new commit from most committers any way, since at least 2003, I think substantially earlier.

[deleted]
Post reply on HN