Earlier quoted context omitted.
1) How did they hit stable then? [0] 2) Yes, emails absolutely need IRB sign-off too. If you email a bunch of people asking for their health info or doing a survey, the IRB would smack you for unapproved human research without consent. Consent was obviously not given here. [0] https://lore.kernel.org/linux-nfs/CADVatmNgU7t-Co84tSS6VW=3N...
1) They did not hit stable. GKH is referring, in this email, to a legitimate attempt to contribute from a student at UMN. Whether or not this student was part of the hypocrite commits study, I don't know. But it's not a hypocrite commit, just a normal buggy commit. You can tell, because it's from a umn.edu email address, which they did not use for hypocrite commits. 2) I don't actually care about the internal policie…
A university got itself banned from the Linux kernel (2021)
71–74 of 74 posts
Re: A university got itself banned from the Linux kernel (2021)
#72Earlier quoted context omitted.
> I don't think it's unethical to send someone an email that has bad code in it. It's unethical because of the bits you left out: sending code you know is bad, and doing so under false pretenses. Whether or not you think this rises to the level of requiring IRB approval, surely you must be able to understand that wasting people's time like this is going to be viewed negatively by almost anyone. Some people might be w…
See another comment I made in this thread about GKH's response - the UMN group submitted a handful of small patches as part of this study, and "wasted" probably a handful of man hours or at worst a few man days of maintainer time. I don't really consider it a waste because evidence that critical open source infrastructure doesn't bother to run static analysis before merging code from randos is actually useful informa…
It's totally possible to obtain evidence of that without being an asshole to kernel maintainers. Which is the kind of thing that an ethics review conducted before the experiment could have pointed out. If the goal of the experiment was merely to demonstrate the lack of routine static analysis capable of catching such vulnerabilities, then the experiment's design was not justified and the experiment was needlessly harmful to non-consenting participants.
Re: A university got itself banned from the Linux kernel (2021)
#73> If a sufficiently motivated, unscrupulous person can put themselves into a trusted position of updating critical software, there’s honestly little that can be done to stop them,” says White, the security researcher. That says a lot about Linux kernel safety.
Re: A university got itself banned from the Linux kernel (2021)
#74Earlier quoted context omitted.
1) They did not hit stable. GKH is referring, in this email, to a legitimate attempt to contribute from a student at UMN. Whether or not this student was part of the hypocrite commits study, I don't know. But it's not a hypocrite commit, just a normal buggy commit. You can tell, because it's from a umn.edu email address, which they did not use for hypocrite commits. 2) I don't actually care about the internal policie…
The point of an IRB is to act as an outside reviewer of _ethics_. IRBs aren't some checklist thing admin put in to protect the University's reputation, they exist as a direct reaction to huge amounts of unethical human experimentation occurring last century.
The "ethical" issues with this study do not rise to the level that I care, so the only objection is that they didn't get the IRB to rubber stamp it beforehand, which I also don't care about.