Live data from Hacker News

I was part of a human subject research study without my consent

christine.website

321–330 of 382 posts

Re: I was part of a human subject research study without my consent

#321
post #249
post #66

Earlier quoted context omitted.

Yep I posted this hoping to raise awareness, but the reaction was not what I expected. In the US even a meritless legal threat will require hiring a lawyer to ensure you are in the clear which requires significant amount of money, in addition to the stress. Researchers should never be putting anyone in that position.

> In the US even a meritless legal threat will require hiring a lawyer to ensure you are in the clear which requires significant amount of money, in addition to the stress. So what happens when a site receives a CCPA inquiry from an actual person concerned about privacy instead of a researcher under a fake identity? The site still needs to determine if the law applies to them and if so what they must do to satisfy th…

> So what happens when a site receives a CCPA inquiry from an actual person concerned about privacy instead of a researcher under a fake identity?

They conclude that it's a Princeton research study and throw it in the trash.

This is part of the harm this study has done; because the researchers were not upfront about who they were and what they were doing, they have introduced uncertainty about the CCPA process.

> Should such laws instead require users to go through some state agency as an intermediary which would then only contact the site on behalf of the person if the agency determines that the user's data at the site is covered?

That could be a good idea. It would depend, of course, on that agency being well-staffed and well-trained (both of which are separate from being well-funded, which can help). There's a giant pile of messy problems that can crop up due to negative influences from, say, corporations that want to sell more data.

That said, it would be nice to have an org that can do the minimum legal work necessary to figure out if the claimant has a leg to stand on. That would not only minimize the harm of this sort of ill-advised study, but also make it harder to use threats of legal force to coerce smaller site owners.

Re: I was part of a human subject research study without my consent

#322

Earlier quoted context omitted.

This is just FUD. I've yet to meet a lawyer who won't do a cursory evaluation of your case for free. It's in their interest to know if you're bringing them an easy win.

> I've yet to meet a lawyer who won't do a cursory evaluation of your case for free. You don't get out much, do you? I've known tons of lawyers that won't look at their watch and tell you the time, unless they get a tenner from it. To be fair, they are used to folks trying to extract highly valuable services from them, for free, so it's sort of a defense mechanism. I have (and have had) many friends that are lawyers.…

It's also worth noting that under US law, a lawyer who gives you legal advice can be held liable if that advice causes trouble down the line.

This creates even more incentives to have a paywall--one, it keeps people from bugging you for free legal advice that can bite them and you in the ass later, and two, it ensures that the people who do get advice from you have followed your procedures for setting up an account with you.

Re: I was part of a human subject research study without my consent

#323
post #258

Earlier quoted context omitted.

As the author of that article, I bet I meet that bar as soon as one of my posts gets on the front page of Hacker News, very easily if I post multiple articles which ended up getting popular like I have this month.

Why are you collecting personal information (IPs) of your readers though?

It's kind of hard not to log IPs when running a service over the internet. You kind of have to have their IP address in order to know where to send the info they want.

Further, logging an IP address has also been necessary for security--to detect DoS and DDoS attacks, for instance, as both involve many repeated connections from the same IP (though you can offload that to a service now).

Re: I was part of a human subject research study without my consent

#324

Earlier quoted context omitted.

Yeah, but the idea of “informed consent” is misunderstood broadly. There is no constitutional right to informed consent. Not all human subjects research requires informed consent — or even consent. There are other institutional ethical lapses that are much more dangerous — and there are also ethical attitudes that rest on the researcher, not the institution. Righteous indignation over something like this is dangerous…

> Not all human subjects research requires informed consent — or even consent. There have been multiple examples of this going horribly, horribly wrong. (Naturally, the worst examples were government-funded and ran during the Cold War.) As a society, we have since concluded that at bare minimum, people should know they are being experimented on--and even that isn't enough to stop things from going badly. This is why…

I'd recommend reading up on why not all human subjects research requires informed consent. For instance, there are exceptions for human subjects research that takes place on normal educational practices. This carve out was made because of the difficulty of getting unanimous consent from all parents during normal classroom education. With greater oversight and full informed consent, a lot of educational research simply wouldn't happen.

So, to reframe this: "can you think of scenarios where institutional oversight could cause negative harms on society?" There are tradeoffs in ethical domains —and usually a lot of work has been done to find a middle ground.

Re: I was part of a human subject research study without my consent

#325

A lot of people mocking the author or others for being scared and worried are basically blaming the victim here, and I would like them to stop. The nature of legal practices in the USA is such that the answers to "Are you totally in the clear legally?" and "Will you lose significant amounts of money proving in random courts that you are in the clear legally?" are often both yes. As a result, any researchers who send…

Would it not need something written (paper) in the US to start anything? In most european countries you just ignore mails with stuff like this and wont be scared in anyway, just as you are not to be scammed by our beloved nigerian prince.

Not a lawyer, but: Not really. You do have to present the case to the judge in a certain format to start it, but as I understand it, there's no requirement for you to send notice to the guy you're suing in a specific format. Once the suit starts, contacting the other party is taken care of either by the court or by your lawyer.

Re: I was part of a human subject research study without my consent

#326

Earlier quoted context omitted.

> very slightly worrisome Recommend you don’t spend “ thousands of dollars to hire a lawyer and file a response” on something that you find very slightly worrisome. Again, I think you, too, are being suckered into spam. Plenty of people fall for spam scams. It is nothing to be ashamed of. Think of all the people who fall for the fake IRS phone calls. But learn from it: keep your guard up when you get emails, phone ca…

> Recommend you don’t spend “ thousands of dollars to hire a lawyer and file a response” on something that you find very slightly worrisome. I call a lawyer any time I have a legal question for which I am not confident about the answer. If it’s not a real problem, a lawyer will be able to answer it a fraction of an hour’s worth of billable time.

> a lawyer will be able to answer it a fraction of an hour

Except that they will probably won't know the answer immediately an need more time than that: https://twitter.com/DanielleVEsq/status/1472105731474137094

Re: I was part of a human subject research study without my consent

#327
post #160
post #92

Earlier quoted context omitted.

They weren't just asking questions. From the email: >My questions are about your process for when I do submit a request. It's really easy to read this as "I am going to be submitting a request." >I look forward to your reply without undue delay and at most within 45 days of this email, as required by Section 1798.130 of the California Civil Code. So I'd say there is some legal threat here.

That code talks about businesses, and not just any businesses, but ones with revenue over $25M: https://oag.ca.gov/privacy/ccpa#sectiona Random blogger who's not a business does not have any connection to this. It's more like if I tell you I'll sue you for murder, high treason and collusion with the Martian invasion, is it really a legal threat? There's literally no legal way for me to sue anybody like that.

As someone in another comment thread pointed out, the requirements also put you on the spot if 50,000 Cali citizens have personal data that you've got access to.

And, as someone also pointed out in that thread, being on Hackernews and having IP logging may be enough to trigger that requirement.

Further, with the absolute shitshow that is the US court system, if someone brings a frivolous suit you're looking at thousands of dollars in legal fees, because you're going to need a lawyer (or previous experience in law) to properly explain to the judge why this suit is utterly ridiculous. And there's no guarantee if you'll get compensated for that, even if you file counter-suit--and even if you do get compensation, it's likely going to happen several years later, after the guy who tried to sue you does everything in his power to avoid paying up, because he knows you're eventually going to run out of money.

Re: I was part of a human subject research study without my consent

#328

Earlier quoted context omitted.

>thinly veiled legal threats How is asking someone questions a legal threat?

> How is asking someone questions a legal threat? It isn't. Being paranoid about lawsuits against some personal blog shows a lack of legal sophistication and this type of sensationalism promotes an irrational fear of being somehow financially vulnerable to almost any legal predation. That's simply not how the US system works. There have to be actual damages for a court case to go forward to the worst-case expensive e…

Following those questions by citing a statute of the law, however, IS a legal threat. Implicit in citing specific parts of the law is the threat that those parts of the law apply to this situation.

Re: I was part of a human subject research study without my consent

#329
post #161

Earlier quoted context omitted.

It really depends on your ethical framework doesn't it? People lie all the time for good reasons. Are those actions unethical? Further, I am struggling to see who was harmed here or how there was any ill intent. On top of that, the results of this study seem like they would be enlightening. It seems like society should want this experiment to be able to take place. Certainly a western liberal understanding of ethics…

"People lie all the time for good reasons. Are those actions unethical?" is whataboutism of the worst kind. We're not talking about any other hypothetical case where a person might lie for good reasons. We're talking about this case, and the lie/misrepresentation was at the heart of why it was unethical. Secondly, you say you don't see who was harmed - the person who posted the original blog post was clearly harmed.…

OP of the blog article. I didn't have a panic attack. If you want access to my private medical information and are not my doctor, you will not get it. Do not assume anything further.

Re: I was part of a human subject research study without my consent

#330

Earlier quoted context omitted.

Deception is allowed, but should be scrutinized carefully to determine if it is necessary. In this case, it was not necessary. The researcher could have easily just said "we want to know if you are compliant with CCPA for the purpose of doing this research, could you tell us your policy please" https://research.oregonstate.edu/irb/research-involving-dece... quotes: a) Psychologists do not conduct a study involving de…

Are you sure that this is applicable to OP's situation? It appears to be a set of guidelines, not a requirement. And in fact, I'm skeptical that there are requirements, except on a university-by-university basis -- which is to say, the process seems much less formal than people are saying. For example, I would feel comfortable with this study if at the bottom it said "Just kidding, we're actually researchers. Can you…

> I'm a former pentester, and deceptions like this were run all day, every day, by a dedicated team. It's often phase one of phishing, since you end up assuming you're talking to a trustworthy source. So I'm wondering why we seem comfortable with that, but not this.

Because pentesters get permission up-front. What the hell kind of pentesting operation are you running where trying to penetrate a site that isn't already one of your clients? You'd be in hot water, legally, if you did that--because the sites affected would have every reason to assume that you're malicious.

This is exactly the thing that was gone over last time, in the U of M case where researchers knowingly submitted exploitable code to see how the Linux kernel team would react. They were also compared to pentesters--but pentesters get permission first, and the U of M people didn't, which is why they were treated as malicious by the kernel team.

If you do not have rules of engagement that were agreed upon by the pentesting team and the client, you are not pentesting, you are committing some form of crime. Stop claiming that pentesters are allowed to phish/exploit things without permission, it makes everyone in that community look bad.

Post reply on HN