Based on the news that has been coming out from Uber, I think it's time for our industry to re-focus on the ethics of what we do. Being technologically cool, doesn't make something good.
Based on the news that has been coming out from Uber, I think it's time for our industry to re-focus on the ethics of what we do. Being technologically cool, doesn't make something good.
The responses I got were mostly variants of "not until they make us," which is exactly the kind of attitude that results in our present state of affairs (thinking of the BMW emissions controversy, Uber, &c). I don't want another major teachable scandal to come out of the tech world, but that may be what it takes.
Then take that to the authority. I believe it's the dean or provost of the CS department who would have the authority to make changes to the program -- and it is usually on a review cycle (so they might tell you to wait).
I think it's great what you've started, and so if all else fails -- put it on Coursera or open source it.
The professors I talked to referred me to the department chair, who I think has final say over new courses here. Either way, open sourcing it would be fantastic (an entire section is devoted to ethical questions in IP/open source development).
first article found of 641000 http://www.bbc.com/news/business-34324772
BMW is actually doing it right http://www.bmwblog.com/2016/02/16/top-five-current-diesel-bm...
sheesh
(edit: add BMW story link)
The BMW story is on a bmw blog...
Here you can see other emissions, in a Guardian article, where it's clearly to be seen that BMW does not comply to the EURO 6 norms.
https://www.theguardian.com/business/2016/apr/21/all-top-sel...
In the actual context of the comment, which is the the USA "emissions controversy" with the massively fraudulent code, it was VOLKSWAGEN that was the main player, BMW was not involved.
(also IMO, Diesels are a pretty bad way to burn fuel in any case; I don't think BMW should pursue it at all, and although I like my petrol-powered model, I wouldn't buy one of their diesels)
Ethical class won't solve that.
That's how it works for doctors and lawyers.
IMO, its one of the reasons this field is such a feast and famine shitshow. Unlike accountants, attorneys, and engineers, we have no professional associations or standards to help protect our professional interests.
It's possible Uber's devs were misled about the nature of the software they were writing - for example I read their other secret system, "Greyball", was written under the guise of protecting Uber drivers from being physically assaulted by militant Taxi drivers - a common sight in certain parts of the world - nothing to do with the dual-use of shadow-banning public officials and journalists.
Though I feel that's not so much about ethics as it was appropriate safeguards/testing given the problem space.
"What are the ethical implications in the field of software engineering?"
"Therac-25."
I don't think we've gotten any better, either. I'm surprised there aren't thousands of Therac-25s killing people every day, actually. I guess the hardware engineers got better at turning off software, because I don't think software engineers got better at software engineering.
Years ago (like 25 years) I read an author discussing safety critical system. He flat out said, safety must be a primary system level design goal. Attempts to band aid it in will fail. Properly designed systems have safeties, interlocks, and monitoring subsystems to prevent software bugs from propagating to the point where people are harmed. People designing safety critical systems tend to completely distrust software.
We also covered other ethics-related case-studies that covered project-mismanagement leading to massive cost-overruns, especially of public-service projects - particularly when those overruns are caused by malfeasance instead of incompetence or ever-changing client requirements (e.g. embezzlement, fraudulent conduct, etc). Another one was the ethics of personal data collection.
Summary: https://en.wikipedia.org/wiki/Therac-25#Problem_description
Full Reading from Berkeley course: https://www-inst.cs.berkeley.edu/~cs61a/reader/Therac-25.pdf
Its a pretty infamous case.
It is rightfully broadly criticized, and that shouldn't change because Uber are the perpetrators here
Yep and that shouldn't be a federal offense with ~20 year jail term with a lifetime criminal record
It's private companies defining federal law and dictating enforcement for their own purposes. You wouldn't let Wal-Mart define what it's own tax laws are, or have McDonalds define what RICO is - having companies define what theft or trespass are is just as absurd.
edit: the list of notable CFAA cases reads like a tragic comedy[0]
There is a case in there where someone was charged for encouraging his union members to email complaints to a company and when it crashed their mail server he was charged under the CFAA.
https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act#N...
Also, it obviously has to be a federal offense, since wires cross state lines.
With 97% of federal cases ending in plea agreements sentencing is overwealmingly in the hands of prosecutors.
In the Swartz case she wanted him to plead guilty to every single charge and serve up to 6 years. Hence the suicide.
As leverage in negotiations they told him at trial he was facing up to 35.
It was 6 months, not 6 years. http://archive.boston.com/metrodesk/2013/01/14/mit-hacking-c...
>As leverage in negotiations they told him at trial he was facing up to 35.
Again, this is a nonsense figure. Can you give an example of someone who has been sentenced to 35 years in jail for similar crimes?
Same thing happen to Aaron, they hung a 7 year sentence around his neck if he didn't please guilty to all charges and accept the deal they offered him.
Even the innocent would please guilty in those circumstances, it's the only rational thing to do.
But you contradict this in your own post. They threatened him with a 7 year jail term, not a 35 year jail term.
The plight of the innocent in the US system is very real, but irrelevant to the case of AS, as he was very clearly and unambiguously guilty.
The original DOJ press release[0] when Schwartz was charged:
> If convicted on these charges, SWARTZ faces up to 35 years in prison
That maximum sentence is not uncommon in CFAA cases as most charges carry 10 or 5 years and layering charges together is very common (ex Mathew Keys faced 25 years on 3 charges for sharing a password)
Facing 35 years Swartz enters plea talks and is offered 6 months recommended, up to 6 years but guilty to all charges
The prosecutors tell him if he doesnt take that deal and goes to trial then they'll be seeking a 7 year minimum 35 year max
A lot has been written about the problems with not just federal sentencing and plea agreements (internationally it is a unique system) but also specific problems with CFAA and sentencing guidelines:
https://www.eff.org/deeplinks/2013/03/41-months-weev-underst...
[0] https://web-beta.archive.org/web/20110724043722/https://www....
The problems with plea agreements relate largely to innocent people being pressured into taking them because a trial is too risky. Swartz had clearly violated the law, so he would have had nothing to gain from going to trial in any jurisdiction.
See e.g. here for further analysis:
http://volokh.com/2013/01/16/the-criminal-charges-against-aa...
>... realistically, Swartz was facing anything from probation to a few years in jail if he went to trial — depending largely on how you value the loss he caused — and either a 4 months in jail or 0-6 months in jail if he pled guilty.
The case was far from clear cut, weev had his case overturned and the Lori Drew case was overturned specifically because the judge said terms of use violations don't apply under CFAA
I read Orin Kerr a lot, abd agree with almost all of what he says in the series he wrote on the Swartz case - I only didn't buy his justification that overprosecution is ok because all the other prosecutors also do it
Swartz's main concern was a lifetime criminal record and not being able to work, and second pleading guilty to charges that he (and many others) don't agree he was guilty to
I def agree with Kerr that the unauthorized access statutes need to be reformed tho, that would have the Swartz case irrelevant and placed it back where it belonged - in a civil court
It's arithmetic. The maximum sentences are what they are, and their sum is what it is. Justification doesn't come into it. But a 35 year sentence was never "hanging over him". He had good legal advice. He knew that he would not go to jail for 35 years.
>The case was far from clear cut,
He physically broke into one of their network closets while attempting to disguise his identity. If that doesn't count as unauthorized access, nothing does.
>Swartz's main concern was a lifetime criminal record and not being able to work
Which, as Kerr points out, makes it absolutely baffling that he did this in the first place. It's often glossed over, but it really was an enormously stupid thing to do. It's sad that he got himself into so much trouble by doing it, but I can't see how anyone else is to blame for that. Especially when he'd already had fair warning after the PACER incident.
>MIT is aware of the controls they could put in place to prevent what they consider abuse, such as downloading too many PDFs from one website or utilizing too much bandwidth, but they choose not to.
MIT did impose controls on the network to prevent Aaron from downloading PDFs, and he kept deliberately circumventing them (e.g. by spoofing his MAC address). So the idea that MIT was totally cool with what he was doing is obviously false, and AS knew that at the time.
If someone doesn't lock their front door and you enter their building, you're still trespassing. Especially if it's your competitor's front door and you're repeatedly entering the building to scout the place out for financial gain.
"You wouldn't open an unlocked door" is the "you wouldn't download a car" of infosec. The later redefined theft as not requiring anybody to be deprived of a good while the former has the same flaw, you arent deprived of any good, you aren't harmed, you haven't been coerced or forced - i.e. It meets none of the common law definitions of trespass[0]
[0] but it does explain why ddos attacks, spam and stealing user data are trespass because they do meet those definitions
There's a difference between "opening an unlocked door" and opening it, walking through it, making notes of everything behind it and repeating this room for all the other unlocked doors and then doing that pretty much continuously for days, weeks, months or however long Uber did it.
I would totally open an unmarked unlocked door in a public space that has locked doors clearly marked "restricted access", especially if the layout of the place I'm visiting suggests that there would be something interesting there.
That's pretty much what it boils down to, no? Just because you didn't document an endpoint doesn't necessarily mean it's restricted access. In fact, if the end point is accessible, and you have other sections of your service that require authentication, then it's very much the exception that proves the rule — the fact that you specifically forbid access to some routes reasonably means that, in general, I'm allowed access to unauthenticated endpoints.
> collected and analyzed the data Lyft provides
they did it without permission
The Information article suggests that driver IDs were available in the clear to anyone who'd bother looking at API payloads.
Why? Sweeping privacy concerns. In a world where most people have an Uber or a Lyft app installed security issues like this become spy machines. So it isn't just drivers that lose their privacy, in the long run it touches on everyone's privacy, because location data is notoriously hard to anonymize and machine learning is only getting better. So there is the first ethical argument against this behavior that pops to mind.
> Hell originated after Uber created fake rider accounts on Lyft and used software to trick Lyft’s system into thinking those riders were in certain locations. This allowed Uber to see the eight closest available Lyft drivers to each fake rider.
You literally just typed the equivalent of "what's wrong with using an ad unit to deliver a zero day exploit? It's not much different from advertising."
Simplifying it even more: If you had people on the street, looking for cars with a Lyft sticker and reporting back every one you see - would you say that is illegal?
Yes, because trying to "hack" the legal system by finding things that you can argue are "technically legal" is not something that impresses me.
I get that beating someone up and throwing a paying customer off a plane, or using a firehose on civil rights marchers, is "legal" if some judge can be persuaded ($$$) to agree, but I'm not going to play that game: I don't want to live someplace where we do what is legal and don't do what is illegal; I want my neighbors to know right from wrong.
A Reasonable Person would think that Uber was doing this to wrong Lyft and indeed it turns out, was doing this to wrong Lyft.
Also, discussing what changes on Lyft's side would make it definitely illegal is interesting if you ever have some personal data in your own service.
IANAL, but I read the DPA a few times and I think it's an edge case. If someone has better idea, I'd love to hear it.
"* “personal data” means data which relate to a living individual who can be identified (a) from those data, or (b) from those data and other information which is in the possession of, or is likely to come into the possession of, the data controller"
Sorry, but they already thought of that one.