The outrage, and the core ethical violation, centers around intentionally wasting the time of others for selfish benefit without appropriate review and consent.
The outrage, and the core ethical violation, centers around intentionally wasting the time of others for selfish benefit without appropriate review and consent.
No, informed consent must be with all participants and maintainers reviewing the patches. Why does Linus/Greg get to decide that for others?
California emissions testing for vehicles includes licensed smog test stations and a process where undercover inspectors bring cars that are in violation to those stations. If the smog test station is incompetent, they will be cited and perhaps stripped of their operating license.
If another state decided that they’d like to start performing random tests upon their network of smog test stations, without any retaliation to those stations, then it would not be a violation of ethics for that state to send undercover cars through the stations.
It would be unethical to punish those who fail undercover tests, unless the state had announced that random undercover testing was beginning and that punishments would be applied for failures.
The researchers were not attempting to modify the behavior of the participants, nor did they seem to be interested in naming and shaming specific maintainers, so it’s not as simple as “anyone who comes into contact with the experiment must be fully informed”.
Do you see how that differs from an academic randomly experimenting on an open source project with no notice or warning?
Retail store owners/managers contract out “mystery shoppers” to test compliance with retail store policy and procedure. This example is also nothing like the UMN experimenting on Linux, since there’s a contract and both parties are aware.
A similar example to the UMN/Linux situation would be an academic doctor deciding to randomly test blood donor screening by sending in HIV positive people to lie about their status in order to donate tainted blood and only telling the Red Cross or whoever after the blood has been donated.
I'm not sure that I agree that sociology experiments have 'informed consent' the way you appear to be thinking of it. Yes, you know you're in an experiment, but if you know what the experiment actually is, then your reactions are not authentic and you skew the results (which always makes me wonder about clever people in experiments).
In white hat stories, it's not always the case that everyone knows ahead of time, but 'enough' people know. Those who do know bear part of the responsibility of ensuring that things don't 'go too far', and they give organizational consent but not personal consent. Although I confess that OSS might be a little fuzzy here because I didn't sign anything when I started. You can't tapdance around informing me by pointing to some employment agreement.
And fyi, not all white hat stories are clean in their approaches, that in itself remains a controversial topic for another discussion. Furthermore, employees in an organization are under a different set of contractual obligations, full of caveats, to their employers. In some ways, they've already "consented" to specific bare minimums(white-hat can be framed as security awareness training required in your job role).
Open source contributors and reviewers are individual third party actors. No one has established any tolerance limits. So "enough" people doesn't really apply here because no one was made the arbiter source to decide that.
[1] https://www.dhs.gov/sites/default/files/publications/CSD-Men...
I do not think that would help. This was done on public mailing list and deceptive behavior was also against third parties (other reviewers). I do not think Linus/Greg can give consent to that.
So, then, it is similar with a 'secret experiment upon unwitting people' and the Linux project. The owner/operators are Linus and Greg, and as the experiment cannot be pre-announced without tainting the outcomes, they are the ultimate "go or no-go" decision makers — just as the owner/operator of the footpaths would, too, have a right to refuse an experiment upon their participants. The individual Linux contributors who participate in the Linux project have no implicit authority whatsoever in any such consideration, and would not be offered opt-in or opt-out consent prior to it being performed. If the good of the project requires pentesting the processes that contributors operate, the project has every right to do so; it's for the good of the project, and contributors' time spent will have been net valuable even if the specific contributions are felt to have been "discarded" or if the contributors feel that their time was "wasted".
This lack of individual authority in many respects is not comfortable or appealing for open source contributors to consider, but it's critical for us to confront it and learn lessons from it. We do not perfect authority over how open source projects use our contributions, whether in time, money, or code. Some percentage of our contributions will always end up being discarded or wasted, and sometimes that will be upsetting to contributors. These are real aspects of project participation regardless of whether secret experiments are approved by the project owners/operators or not. I hope that this event helps us develop better empathy for large projects, such as Linux or other operating systems, when they make decisions that benefit the project rather than contributors.
I think the thing I'm objecting to is that this is a valid or meaningful 'experiment'. Placing there, to me, is already inaccurate framing.
Get consent from the project leaders and announce publicly their intentions and a time window of a few months. Then randomly submit the patches as originally outlined.
Although this would not prove as strong of a result, it is far more ethical and similarly effective. Companies use this kind of method all the time.
It's also questionable whether the IRB should have considered this human subjects research and not given them an exemption. It's also questionable whether, if the IRB had done that, the IRB would have stopped the study or asked for revisions to the study design (they would if they were paying close enough attention).
Professors at universities are typically given large amounts of freedom to conduct studies without heavy prior approval, it's a tradeoff.
It sort of like asking “What if we volunteered for the parks department and slipped a load of salt into the fertilizer?” - of course bad actors can find new ways to circumvent security.