5 ms·
It would be great if CMU alumni, faculty, and students petitioned the university's IRB to investigate and its administration to return the funding. CMU Researc
by justcommenting 11y ago
It would be great if CMU alumni, faculty, and students petitioned the university's IRB to investigate and its administration to return the funding.
CMU Research Ethics Reporting: https://www.cmu.edu/research-compliance/report-problem/index.html https://www.cmu.edu/research-compliance/report-problem/index...
CMU Research Misconduct hotline: https://www.cmu.edu/research-compliance/research-misconduct/ https://www.cmu.edu/research-compliance/research-misconduct/ or call 877-700-7050 for 'anonymous' reporting
CMU IRB contacts: https://www.cmu.edu/research-compliance/human-subject-research/contact.html https://www.cmu.edu/research-compliance/human-subject-resear...
CMU Office of the President contact page: https://www.cmu.edu/leadership/president-suresh/contact/index.html https://www.cmu.edu/leadership/president-suresh/contact/inde...
Also of note - Ethical Tor Research Guidelines: https://blog.torproject.org/blog/ethical-tor-research-guidelines https://blog.torproject.org/blog/ethical-tor-research-guidel...
- minimaxir 11y agoCMU alum here. Let's just say there are quite a few rants happening in my network on Facebook.
- dopamean 11y agoIt'd be great if it was more than rants on facebook.
- TeMPOraL 11y agoThat's how it starts, usually.
- dev1n 11y agoand ends, unfortuantely.
- TeMPOraL 11y agoDepends. First of all, before people go out to the streets they need to coordinate somehow, and Facebook seems to be a good way of doing that recently. Second of all, the rants that are done publicly have a chance of creating a huge PR shitstorm for CMU when some journalist gets a wind of it. Sadly, in this age media pressure is the only thing that actually works (usually for worse).
- akshatpradhan 11y agoWell that's that folks. Like all topics in Security, Tomorrow, we won't even remember this convo. How's the weather in PA?
- DyslexicAtheist 11y agohttps://twitter.com/ValbonneConsult/status/664732936466468865 https://twitter.com/ValbonneConsult/status/66473293646646886...
- danielrm26 11y agoand repeats, sadly
- idlewords 11y agoMySpace will be hearing about this, let me assure you.
- scott_karana 11y agoMere "rants on Facebook" caused a higher Canadian youth voter turnout than in decades to oust the long-standing Conservative party. Let's not be too cynical. :-)
- cba9 11y agoI would love to see how they managed to justify this to the IRB, and how the IRB failed at its only job, inasmuch as the only possible purpose for turning over the IPs to the FBI is to inflict harm on people, harm which happened. Given how IRBs worry about the most exotic potentials for harm...
- nullc 11y agoThey likely didn't speak to an IRB. I've complained a number of times about sketchy behavior from researchers in the space of "Bitcoin transaction deanonymization" which were likely to cause harm to people and have reliably gotten a response from CS departments that sounds like "anyone could do this, so there are no ethical considerations". E.g. for an example in print from CMU, see section 6.2 of http://arxiv.org/abs/1207.7139 http://arxiv.org/abs/1207.7139 I don't consider the argument persuasive: First, if we look to physical law there is no experiment that couldn't just be conducted by 'anyone'-- That nothing prevents me from stabbing you in the chest just to see what happens doesn't make it ethical. Much research in this space ends up actually breaking the law-- at least pedantically. For example, in the above citation they talk about the efforts they had to go through to avoid being blocked ("We spent some additional effort making our measurements as difficult to detect as possible", "Perhaps, bypassing the authentication mechanism and associated CAPTCHA by reusing an authentication cookie could be construed as a “hack.” However, we argue this is nothing more than using a convenient feature that the site operators have willingly offered their visitors.") which demonstrates that their access was beyond their authority, a violation of the CFAA (at least by the standard Weev, who incremented a counter in a URL, was prosecuted under!). Even outside of criminal law, the foreseeable harm you cause to another by investigating them opens you up to a tort even when 'anyone' could have performed the investigation. Researchers have access to institutional, governmental, and structural support (cheap students) which heighten the potential risk of their work (as well as their potential liability). But even ignoring that, research that causes harm to people is harmful regardless of who does it. Owing to the heightened risk and liability public institutions have infrastructure for harm mitigation which appears to be being bypassed. It sounds like over a million dollars of public funding went into these recent attacks, and efforts the tor project spent defending those attacks were diverted from being spent on protecting against other ones. But I don't think any of this is a problem limited to CMU or even University research. I think Computing professionals are simply falling down on their ordinary professional and ethical obligations to the users of their systems on a regular basis, in part because we're making a mistake of confusing the appropriate adversarial model we use for security analysis for an ethical maxim... and CMU acting as paid outsourced law enforcement due process violation mill is just a symptom of a greater dysfunction along with things like the Facebook emotional manipulation experiment. Edit: This is speculation on my part based on responses I've seen when asking researchers about their; but I am told that at least on other projects CMU CS does at times seek IRB approval, so my impression that they never do is probably sampling error.
- cmuuuuuu 11y agocurrent cs student here: my friends are sorta like "lol"