I believe even the old Folger's commercials where they secretly replaced people's coffee with Folger's Crystals would not pass muster with respect to informed consent.
I believe even the old Folger's commercials where they secretly replaced people's coffee with Folger's Crystals would not pass muster with respect to informed consent.
> The writing of a paper on this research [PDF] was not the immediate cause of the recent events; instead, it was the posting of a buggy patch originating from an experimental static-analysis tool run by another developer at UMN. That led developers in the kernel community to suspect that the effort to submit intentionally malicious patches was still ongoing. Since then, it has become apparent that this is not the case, but by the time the full story became clear, the discussion was already running at full speed.
and
> The LF Technical Advisory Board is taking a look at the history of UMN's contributions and their associated research projects. At present, it seems the vast majority of patches have been in good faith, but we're continuing to review the work. Several public conversations have already started around our expectations of contributors.
The recent shit storm was not caused by a malicious act on the part of anybody at UMN. The "overworked" maintainers made a mistake and ascribed malice to the actions of a good-faith contributor who also happened to be from UMN.
I still see people in this thread assuming that UMN has some history of submitting malicious patches and the wholesale ban is a justifiable response. That response might be justified if some internal ethical system at UMN is broken, but that is not the case, at least here. This history is clean save the one incident regarding the research paper, which has been withdrawn.
This is not true and is explained in the article:
> That said, there are multiple definitions of "malice". To some of the developers involved, posting unverified patches from an experimental static-analysis tool without disclosing their nature is a malicious act. It is another form of experiment involving non-consenting humans.
This is the “recent shit storm” and can in no way be described as “good-faith” particularly after the disgusting response from the researcher after being called out on their shit.
> particularly after the disgusting response from the researcher after being called out on their shit.
The researcher was slandered publicly by Greg. Greg repeatedly accuses the maintainer of purposefully submitting malicious patches, which he NEVER did. Greg also does so in an extraordinarily insulting way, diminishing the student's skillset, somewhat ironically as the student's research did in fact find bugs in the kernel.
The researcher very rightfully responded the way he did - by calling out the slanderous remarks and removing himself from the Linux Kernel, a project that will no longer benefit from his contributions (which, if you bothered to look into, are far better than Greg gave credit for).
Greg is very much in the wrong here. He is the one who made repeated false accusations.
Please do not continue the very unfortunate attacks against a student who was only trying to submit good-faith patches to the kernel.
Greg overreacted. Linus agrees, other kernel maintainers agree. The only person who won't come out and admit it is Greg himself, and his overreaction has cost the kernel a valuable asset as well as the reputation of an innocent researcher, who now gets comments like "they're disgusting" from people who took Greg's accusations at face value.
https://www.kernel.org/doc/html/latest/process/code-of-condu...
That type of reality is not natural and it's not human and it's not the one I live in.
Be pissed at the stupid research paper all you want. It doesn't justify treating some tertiary human like utter shit.
And for the record nobody is trying to "cancel" Greg or the kernel here. The project is great and Greg is probably a super chill dude on most occasions. But people aren't perfect and fuck up. You can act rashly under stress and later be wrong. That's understandable and that is human. The whole point is how you respond in light of new information. That's the test of character.
We don't need to sit here and sweep Greg's BS under the rug because he's a kernel celebrity. I honestly think some form of apology would go a long way to rectifying the slander, and cool down the whole thing and most importantly, might be enough to make Aditya feel welcome again in the community. Greg was wrong, his behavior rash, and the example should not be emulated by others in our community. Period.
Recommended reading: All Hallows Eve by Charles Williams, a meditation on where stupidity and selfishness lead.
And for the record I don’t think there is even level headed consensus formed yet on the whole paper thing. It’s arguably unethical, but it is also arguably simply inconsiderate. And it has certainly provided some degree of utility, although it’s unclear how much. I think most of the impressions have been molded by Greg’s response during the “kernel peeps are pissed” phase of the whole affair.
The paper has been withdrawn because consensus is clear: for experiments on human subjects informed consent is required in advance. The institution recognizes that much: "We acknowledge our responsibility to do this to prevent situations like this incident in the future."
> for experiments on human subjects informed consent is required in advance
By such simple logic A/B testing is unethical. And that may be the case. Still, it's not exactly clear in this case where to draw the line and who/what the subject is.
There's a comment elsewhere in this thread that sums the situation up better than I can: https://news.ycombinator.com/item?id=26985631. I've read the paper and honestly I have a mixed impression. It certainly is respectful and doesn't come off as "we're going to be super malicious and mega waste everyone's time and fuck with the kernel maintainers for fun and science". It does not aim to experiment with humans in order to study how humans socially react to a breach of trust in a high trust collaboration. That was not their goal at all. Arguably, as laid out pretty explicitly in the paper, the experiment is not on human subjects but rather on a system of collaboration used primarily by open source projects. It happens that the system is operated by humans. Are you testing the humans, or stressing the system?
Is making crafted investments in the market for the sole purpose of studying the validity of a hypothetical model unethical? Is it research on humans because the market is a human endeavor operated by humans? These are genuine questions.
There are also different ethical frameworks. No harm was caused by this research. In fact, the only real harm to humans has been Greg berating a person (because of their proximity to past research and perceived sloppy patches) who offered legitimate patches some of which actually fixed bugs in the kernel. Clearly Greg didn't even take the time to understand the patches he just categorically dismissed them all because he had a bone to pick. Now the kernel is down a contributor who's contributions clearly have utility.
Back to the paper, even if it presents the obvious for people working on open source projects, it, like is the status quo in security research, is the working example of the exploit. In my experience people don't give a shit about perceived vulnerabilities until they become real vulnerabilities. As a kernel user, I actually value this research more than the alleged waste of time it may have caused for maintainers. I'm not the only one who feels this way. Sometimes to effect change you need to light a fire under somebody's ass.
So the paper is valuable to some subset of people. It provides utility. It did no harm to computer system or humans. You see what I'm getting at.. there are ethical frameworks under which this paper is clearly ethical (even if you concede it directly and explicitly aimed to experiment on humans, which I debate). Ideally the researchers would have asked Linus and Greg if they could perform the research on their project so they wouldn't feel out of the loop and attacked/culpable when the research was published. I do hope everyone's learned their lesson in that regard.
Anyway back to Greg, you're really moving the goal posts. We can agree 100% that the paper is unethical. The fact is simply irrelevant when considering whether it's right to piss on some student at UMN who presented valid albeit sloppy patches to the kernel in a gesture of good faith in order to try and improve the state of security. It's a breach of the kernel's own community guidelines, at the very least!
> and that there was some agreement in place with the University which must have stipulated "no more bogus patches"
This is baseless.
> Then Aditya went and posted another bogus patch
Not bogus. Aditya's analyzer did in fact find plenty of bugs - do your research, this is confirmed by many other maintainers.
> to further his career, even though he should have known how that would be received
Why should he have known that? I would never expect to receive the kind of feedback given by Greg, followed by a total university ban, over a student submitting subpar commits. It's an insane overreaction.
There was behind-the-scenes talk that the student chose to ignore, it's impossible to interpret in any other way.
Greg was assuming these were patches coming from some new "hypocrite patch" project at UMN and "AGAIN" refers to the previous incident in Aug2020 regarding the paper. I don't think the student was ignoring anything. Greg categorically dismissed legitimate contributions to the kernel because of his rash perception that UMN was up to no good AGAIN. So that's why he referenced the previous event and said AGAIN.
In reality, this isn't some conspiracy where UMN was attempting to add hypocrite patches for a 2nd time. Greg was dead wrong in that regard. You need to read: https://www-users.cs.umn.edu/%7Ekjlu/papers/full-disclosure.....
So - no more free research support for the University of Minnesota. That's fair because the reviewers did not choose to spend time on the University of Minnesota's research output.
But the commit in question was bogus, and it looks like Aditya did not properly check the output of his tool. Maybe he did not send bogus patches on purpose, but the fact that he used the Linux kernel as a playground for testing his experimental static analysis tool (without disclosing it in the commits) is still problematic and he should be called out for that.
Are you saying that Aditya was not involved in the hypocrite commits research? He’s not cited in the paper but his name is on the open letter [1].
If this is the case, would you please provide a citation? I feel like I’m missing something or being misled.
[1] https://lwn.net/ml/linux-kernel/CAK8KejpUVLxmqp026JY7x5GzHU2...
But here you go if you want to read more about the research. You'll notice that the messages/ patches are all attributed to those cited in the paper.
https://www-users.cs.umn.edu/~kjlu/papers/full-disclosure.pd...
And yes, you are being misled. That's why Greg needs to publicly retract his accusation and apologize. That's why it's so frustrating that LWN did not clearly explain that Greg was flat out wrong.
Edit: To clarify, I don’t think you’ve made enough of a case to prove Aditya’s innocence or justified your attack on Greg.
I didn't tell you what to say, I'm pleading with you and everyone else to stop spreading misinformation that is costing an innocent man his reputation.
> As for attacking people, you’re doing a whole lot more than me, which unlike you, wasn’t my intent.
You called Aditya's response "disgusting".
I see this repeated, but arguments like "You don't get to secretly do things to your subjects." are not sufficient nor is "it's arguably the most important software on the planet". These viewpoints are not agreed upon or codified anywhere that would affect an IRB decision.
"human subjects" qualification -> https://www.fda.gov/about-fda/center-drug-evaluation-and-res... (et al sources)
The notable history of outrage in some communities (did this make the evening news anywhere?) that has been created, may influence future decisions, at best.
But even so, defining human subjects so as to exclude humans who are subject to your experimentation is absurd on the face of it. Who cares what is codified by whom? Experimenting on unwitting subjects is unethical. I had hoped that by now that would be something that didn't need stating and restating.
Why you decided that was a claim is your own bias talking. I was pointing out the relevant section. You've tried to raise something that isn't the issue, nor is it a sensible question as you undoubtedly realized (But even so).
Every human in an experiment is a human subject. Glad we got that out of the way.
The issue is what an IRB is looking for in evaluating the ethical feasibility of an experiment.
> Experimenting on unwitting subjects is unethical
> I had hoped that by now that would be something that didn't need stating and restating.
That's because it's your opinion. Seriously, go tell your local Target or College Bookstore to stop playing with the wall colors because there is no disclosure AND they make money off of it.
> An IRB evaluates “Human Subjects Research”, which has a precise technical definition according to US federal regulations (see 45 CFR 46.102), and this technical definition may not accord with intuitive understanding of concepts like “experiments” or even “experiments on people”.
[0]: https://drive.google.com/file/d/1z3Nm2bfR4tH1nOGBpuOmLyoJVEi...