3 ms·
I would love to see how they managed to justify this to the IRB, and how the IRB failed at its only job, inasmuch as the only possible purpose for turning over
by cba9 11y ago
I would love to see how they managed to justify this to the IRB, and how the IRB failed at its only job, inasmuch as the only possible purpose for turning over the IPs to the FBI is to inflict harm on people, harm which happened. Given how IRBs worry about the most exotic potentials for harm...
- nullc 11y agoThey likely didn't speak to an IRB. I've complained a number of times about sketchy behavior from researchers in the space of "Bitcoin transaction deanonymization" which were likely to cause harm to people and have reliably gotten a response from CS departments that sounds like "anyone could do this, so there are no ethical considerations". E.g. for an example in print from CMU, see section 6.2 of http://arxiv.org/abs/1207.7139 http://arxiv.org/abs/1207.7139 I don't consider the argument persuasive: First, if we look to physical law there is no experiment that couldn't just be conducted by 'anyone'-- That nothing prevents me from stabbing you in the chest just to see what happens doesn't make it ethical. Much research in this space ends up actually breaking the law-- at least pedantically. For example, in the above citation they talk about the efforts they had to go through to avoid being blocked ("We spent some additional effort making our measurements as difficult to detect as possible", "Perhaps, bypassing the authentication mechanism and associated CAPTCHA by reusing an authentication cookie could be construed as a “hack.” However, we argue this is nothing more than using a convenient feature that the site operators have willingly offered their visitors.") which demonstrates that their access was beyond their authority, a violation of the CFAA (at least by the standard Weev, who incremented a counter in a URL, was prosecuted under!). Even outside of criminal law, the foreseeable harm you cause to another by investigating them opens you up to a tort even when 'anyone' could have performed the investigation. Researchers have access to institutional, governmental, and structural support (cheap students) which heighten the potential risk of their work (as well as their potential liability). But even ignoring that, research that causes harm to people is harmful regardless of who does it. Owing to the heightened risk and liability public institutions have infrastructure for harm mitigation which appears to be being bypassed. It sounds like over a million dollars of public funding went into these recent attacks, and efforts the tor project spent defending those attacks were diverted from being spent on protecting against other ones. But I don't think any of this is a problem limited to CMU or even University research. I think Computing professionals are simply falling down on their ordinary professional and ethical obligations to the users of their systems on a regular basis, in part because we're making a mistake of confusing the appropriate adversarial model we use for security analysis for an ethical maxim... and CMU acting as paid outsourced law enforcement due process violation mill is just a symptom of a greater dysfunction along with things like the Facebook emotional manipulation experiment. Edit: This is speculation on my part based on responses I've seen when asking researchers about their; but I am told that at least on other projects CMU CS does at times seek IRB approval, so my impression that they never do is probably sampling error.
- unethical_ban 11y agoI don't think that bitcoin deanonymization research is a bad thing. Perhaps it should be done in a way that tests the anonymity of transactions and accounts created for the purpose of the research, but to research the topic itself is easily classified as legitimate security research. The issue starts when you publicly "out" organizations or people in your research findings, or take money from authorities with the understanding that you'll report back data on people and organizations.
- yeukhon 11y ago> The issue starts when you publicly "out" organizations or people in your research findings, or take money from authorities with the understanding that you'll report back data on people and organizations. But that's probably in the contract.
- nullc 11y ago> I don't think that bitcoin deanonymization research is a bad thing. I never said it was; but care should be taken to avoid harming people. It's unlikely that someone will take that care to mitigate harm if they are of the view that they have no obligation to mitigate to begin with.
- jackgavigan 11y agoI think there's also an issue around keeping the results of the research secret.
- deleted 11y ago[deleted]
- doktrin 11y agoThis work was done by the SEI - an FFRDC - not campus researchers.