This apology fails from the 5th word: "We sincerely apologize for any harm..." While there are other requirements, a sincere apology cannot in any way entertain doubt about the fact that there WAS harm. Truly acknowledging the harm done is foundational to a real apology, and most of us (myself included) end up sneaking in weasel words or phrases like this. Psychologically, its nice for the apologizer, since it allows…
This is probably because they don't mean the apology, they were forced to write it by their administrators. And to be honest, I kind of agree with them. I don't really see what they did here as particularly bad. They demonstrated a very serious vulnerability in the linux kernel development process. I guess the harm they caused was wasting maintainers time, a bit? But what we all got out of it is the knowledge that re…
Open letter from researchers involved in the “hypocrite commit” debacle
201–210 of 384 posts
Re: Open letter from researchers involved in the “hypocrite commit” debacle
#202Re: Open letter from researchers involved in the “hypocrite commit” debacle
#203Earlier quoted context omitted.
This is probably because they don't mean the apology, they were forced to write it by their administrators. And to be honest, I kind of agree with them. I don't really see what they did here as particularly bad. They demonstrated a very serious vulnerability in the linux kernel development process. I guess the harm they caused was wasting maintainers time, a bit? But what we all got out of it is the knowledge that re…
What is the serious vulnerability? That sometimes bugs slip through?
Re: Open letter from researchers involved in the “hypocrite commit” debacle
#204Uhh.. but that was the exact intent of the paper. And they did it successfully. So.. mission failed successfully?
What a bizarre attempt to save-face. This is academic misconduct and they're trying to save their asses. finding and fixing security vulnerabilities.
Re: Open letter from researchers involved in the “hypocrite commit” debacle
#205Earlier quoted context omitted.
I don't think they had malice, but the breach of elemental ethics is just appalling. They show no remorse for being trusted and abusing that trust and good faith. They show no remorse for using human beings as involuntary guinea pigs. In sum, they show not remorse for doing wrong.
For me, it's not learning the lesson the first time around. I completely agree their experiment is unethical. However, it's not actually clear cut to most researchers the ethical bounds of their work, especially for study papers that's never really been explored before. Ethics in of itself is largely a active subtopic for many areas in CS, not only security research. AI is one area where qualifying potential harm to…
The ethics around research that involves deception have been pretty well established and are are several good comments here explaining them.
Every scientist is personally respsible for the ethics of the research they conducts. Full Stop, no caveats allowed.
If your research is in an area where the ethics are controversial or grey, that means your need to spend MORE time considering the ethics of your research, not that you get a free pass from being responsible.
If a any scientist espouses the opinion that determining the ethics of their projects is not their responsibility, they should be permanently barred from recieving grant money.
Re: Open letter from researchers involved in the “hypocrite commit” debacle
#206This apology fails from the 5th word: "We sincerely apologize for any harm..." While there are other requirements, a sincere apology cannot in any way entertain doubt about the fact that there WAS harm. Truly acknowledging the harm done is foundational to a real apology, and most of us (myself included) end up sneaking in weasel words or phrases like this. Psychologically, its nice for the apologizer, since it allows…
This is probably because they don't mean the apology, they were forced to write it by their administrators. And to be honest, I kind of agree with them. I don't really see what they did here as particularly bad. They demonstrated a very serious vulnerability in the linux kernel development process. I guess the harm they caused was wasting maintainers time, a bit? But what we all got out of it is the knowledge that re…
Re: Open letter from researchers involved in the “hypocrite commit” debacle
#207Earlier quoted context omitted.
> Says who? Me and common sense. I don't believe consent is relevant when there is no risk of harm to the subject. IRBs and the GDPR are overly aggressive on this point, probably as a reaction to real and important violations of privacy. But the idea that A/B testing the color of your CTA button on a landing page requires informed consent is absurd.
There's lots of systemically horrible things that can happen if you're not careful about what you allow. If you're interested why these ethical principles exist in the United States, I suggest you at least skim the Belmont Report https://en.wikipedia.org/wiki/Belmont_Report
Of course there are. But what specifically are the harms that are going to be caused by either this research or a landing page A/B test without a click through pop up? The existence of theoretical harms for broad categories of potential research does not have a whole lot of bearing on these specific lines of research.
> If you're interested why these ethical principles exist in the United States, I suggest you at least skim the Belmont Report
I read it. It was interesting, but I don't think it's particularly relevant here. The only prong of its test that would be relevant to this experiment is "respect for persons". The idea that somehow not revealing the bug or the experiment was intrinsically harmful as a violation of a person's moral autonomy.
I don't buy that line of reasoning, and I can't really think of any valid consequentialist justification for it, and the report itself does not attempt to justify it either, as far as I can tell.
Re: Open letter from researchers involved in the “hypocrite commit” debacle
#208Earlier quoted context omitted.
What are your thoughts about this article[0], my reading or article is that; author fails in similar way (to some extent) as researchers and there's IRB in regards to ethics of such research. [0] https://dave-dittrich.medium.com/security-research-ethics-re...
IANAL, but the claim that this research was exempt under 45 CFR 46.104(d)(2) seems suspect to me. (i) doesn't seem to apply because Linux kernel developers are required to go by their real names for licensing reasons (cf. the rules regarding Signed-off-by). (ii) seems dubious given that the authors themselves argue that they need reviewer consent to release information about the authors' malicious patches. Note in pa…
Re: Open letter from researchers involved in the “hypocrite commit” debacle
#209Earlier quoted context omitted.
It seems like a nitpick to me, since the rest of the apology uses the proper choices of words, though. "The method used was inappropriate", "we made a mistake", etc. The apology is also specific about what they did wrong despite their intentions. It really is a good apology after reading past the first six words.
ESL here. How correct is it to use ’any harm’ to mean ‘all harm’.
2) "We apologize for any harm that we caused"
3) "We apologize for all the harm that we caused"
(1) is the least apologetic. This could be interpreted as saying "we might or might not have caused harm, and we think we didn't but you think we did, so we're going to apologize for your sake, but we're not really sorry because we didn't do anything wrong from our perspective".
(3) is the most apologetic. You acknowledge that you did something wrong, and that you're apologizing for it. This might be followed up with a specific list of the things that you did wrong, and that you are apologizing for. That would make for the most sincere apology. This could be interpreted as "we caused harm and we're sorry, whatever harm you think that we did, we agree that you are right, and we are sorry for all of it".
(2) is partway between (1) and (3). You acknowledge you caused harm, but you won't enumerate the things that you did wrong. So, you leave yourself a little bit of wiggle room. This could be interpreted as "we caused harm and we're sorry, but we didn't cause that much harm, we think it was actually quite little, you think it was a lot, but we're saying sorry, so let us go with this apology".
Re: Open letter from researchers involved in the “hypocrite commit” debacle
#210I really appreciate the apology and as they stated, its unconditional nature. Good. However, I find something very problematic. This quote shows it: "We have learned some important lessons about research with the open source community from this incident." This is something I don't like. This is not something about "research with the open source community". If anything, they should have learned something about treatin…