5 ms·
The response by Patio11 regarding how this was acceptable penetration testing was beyond stupid. Just because you are univesity researcher does not means you c
by AMEDICALRe 11y ago
The response by Patio11 regarding how this was acceptable penetration testing was beyond stupid.
Just because you are univesity researcher does not means you can take money and then attack some random company and say LOL JK just doing "Research". Universities have enormous computing power / resources available via various means to do research. Just because I have access to a thousand node cluster does not means I can randomly launch DDOS attack against some company and then claim "Research". This is equivalent to those youtube videos where at the end they justify assault and other egregious behaviour claiming "Social experiment" or "Prank".
- maxerickson 11y agoThe problem is that people are outraged that they attacked Tor when they should be outraged that they attacked Tor users. Given what the Tor project thinks to be, it needs smart people to poke it.
- vox_mollis 11y agoSome of us are more outraged by the fact that they kowtowed to authority on the BlackHat presentation, and had a disclosure policy that favored the Feds over both the Tor project and the entire security community. The CMU researchers are basically Sabu. Subhuman traitors to the hacker ethos.
- deleted 11y ago[deleted]
- maxerickson 11y agoI doubt they ever particularly cared about the mantle of 'hacker' and whatever ethos is supposed to go with it. That makes it hard for them to betray it.
- derefr 11y agoRight; the ethical experiment here would be to set up one's own private Tor network and then attack that. (Think that requires a lot of effort? Well, yeah; that's why you do it as part of a university with grant funding!) This would also have the bonus effect of being able to instrument all the nodes, so you could see the effects of your attack flowing through the system in a white-box manner.
- hawkice 11y agoThis is perhaps the most unnecessarily rude comment to be at the top of a hacker news thread in some time. Let's all remember that disagreeing with someone doesn't mean being glib or mean.
- deleted 11y ago[deleted]
- deleted 11y ago[deleted]
- deleted 11y ago[deleted]
- deleted 11y ago[deleted]
- deleted 11y ago[deleted]
- deleted 11y ago[deleted]
- deleted 11y ago[deleted]
- AMEDICALRe 11y agoAs a serious academic researcher with a research group has access to amount of data/computing power that we can make NYTIMES headline effortlessly if we were to throw our ethics out of the window, Let me tell you this isn't a fucking joke. Patio11 who seems to be darling of this forum, has no clue what he is talking about. He seems to have never participated in any kind of academic research. Unlike some stupid bingo card creator or bubble driven recruiting startup. Academic research is a serious business, there is a reason why it is looked in positive light and a lot of things which otherwise are not allowed, are acceptable when done as research. And for it to stay that way scrutiny of research conduct is essential.
- deleted 11y ago[deleted]
- tptacek 11y agoIf you had cut the ridiculous and mean first sentence out of this comment it would have been fine, but then, as you know, nobody would have cared about it, because you'd have been saying nothing everyone else hadn't already been saying.
- pahael 11y agoWhy do you copyright your comments?
- deleted 11y ago[deleted]
- nightpool 11y agoflippant answer—tptacek doesn't "copyright" anything. in territories that recognize the Berne convetion of 1989, everything created that meats the standards for copyright is protected by copyright. you can't "copyright" something—something either is, or isn't protected by copyright. IANAL, but as tptacek's comments are tangible forms of creative works, they are trivially protected by copyright less flippant answer—because he's probably had problems with people stealing his answers and posting them on other forums or similar issues.
- wglb 11y agoA minor nit, from his profile at https://news.ycombinator.com/user?id=tptacek https://news.ycombinator.com/user?id=tptacek All comments Copyright © 2009, 2010, 2011, 2012, 2013, 2015, 2018, 2023 Thomas H. Ptacek, All Rights Reserved.
- deleted 11y ago[deleted]
- fweespeech 11y ago> The response by Patio11 regarding how this was acceptable penetration testing was beyond stupid. Actually, from a security perspective, its quite understandable. If you provide a tool that claims to be safe from state actors, they can use that kind of power to attack it. That said, if it didn't pass the usual protocols at the university for ethical standards they can and should be fired regardless of the client or reason.
- fweespeech 11y ago> The response by Patio11 regarding how this was acceptable penetration testing was beyond stupid. Actually, from a security perspective, its quite understandable. If you provide a tool that claims to be safe from state actors, they can use that kind of power to attack it. That said, if it didn't pass the usual protocols at the university for ethical standards they can and should be fired regardless of the client or reason.
- kajecounterhack 11y agoWhat was the patio11 comment? It seems to have been deleted, making this thread a bit harder to follow.
- firebones 11y agoI believe it was a tweet https://twitter.com/patio11/status/664551822120476672 https://twitter.com/patio11/status/664551822120476672 which was interpreted as chiding the victims for being thin-skinned in the attack upon them. (Secure systems thrive and survive only if they can take on all stressors and remain robust.) While Patrick seemed to be focusing on the abstract notion of security mechanisms needing to welcome malicious scrutiny, the strong reaction against his tweet was based on the observation that Patrick failed to take into account the real, human cost of such an attack. This was further compounded by the fact that often, research requires IRB approval to determine whether the research is ethical, and the evidence is that CMU's actions weren't ethical. Yet Patrick felt it necessary to opine without understanding the ethical component of such an attack.
- wisty 11y agoHis actual statement: > Tor is having a fit of institutional pique that researchers are compromising the network's privacy guarantees by, well, looking at it. > If you write security software, and you're not praying that loyal opposition hits you with everything they've got, you're not doing security > Tor is intended to be, and is marketed as, robust against nation state adversaries. It cannot possibly be so if it worries about academics. Two interpretations: 1. It's OK to go after Tor. This is dead wrong - attacking a network without permission is very bad form. Maybe it's OK to do the equivalent of checking to see if someone's front door is locked (this is a grey area), but only if you intend to warn them that their door's unlocked. Going through their stuff is obviously unethical (and probably illegal). 2. Tor should be more permissive, encouraging more attacks from researchers. Obviously, the researchers crossed the line when they started gathering user data. But Tor should only be upset that the attack went too far, not that the attack succeeded. I'm not sure of the context - was the Tor community pissed off that researchers found a weakness, or pissed off that the weakness was exploited? Twitter is a pretty poor platform if you want nuance, so it's probably best to be charitable in your interpretations of what people say there.