6 ms·
See page 9 of the already published paper: https://raw.githubusercontent.com/QiushiWu/qiushiwu.github.io/main/papers/OpenSourceInsecurity.pdf https://raw.githu
by duncaen 5y ago
See page 9 of the already published paper:
https://raw.githubusercontent.com/QiushiWu/qiushiwu.github.io/main/papers/OpenSourceInsecurity.pdf https://raw.githubusercontent.com/QiushiWu/qiushiwu.github.i...
> We send the emails to the Linux communityand seek their feedback. The experiment is not to blame any maintainers but to reveal issues in the process. The IRB of University of Minnesota reviewed the procedures of the experiment and determined that this is not human research. We obtained a formal IRB-exempt letter. The experiment will not collect any personal data, individual behaviors, or personal opinions. It is limited to studying the patching process OSS communities follow, instead of individuals.
- karlmdavis 5y agoCommunities aren’t people? What in the actual fuck is going on with this university’s IRB?!
- DetroitThrow 5y agoIn my experience in university research, the correct portrayal of the ethical impact is the burden of the researchers unfortunately, and the most plausible explanation in my view given their lack of documentation of the request for IRB exemption would be that they misconstrued the impact of the research. It seems very possible to me that an IRB wouldn't have accepted their proposed methodology if they hadn't received an exemption.
- tikiman163 5y agoThey weren't studying the community, they were studying the patching process used by that community, which a normal IRB would and should consider to be research on a process and therefore not human Research. That's how they presented it to the IRB so it got passed even if what they were claiming was clearly bullshit. This research had the potential to cause harm to people despite not being human research and was therefore ethically questionable at best. Because they presented the research as not posing potential harm to real people that means they lied to the IRB, which is grounds for dismissal and potential discreditation of all participants (their post-graduate degrees could be revoked by their original school or simply treated as invalid by the educational community at large). Discreditation is unlikely, but loss of tenure for something like this is not out of the question, which would effectively end the professor's career anyway.
- d110af5ccf 5y ago> This research had the potential to cause harm to people I don't buy it, and you fail to back that claim up at all.
- liamwire 5y agoAt a minimum, is needlessly increasing the workload of an unwitting third party considered a harm? I ask, because I’d be pretty fucking mad if someone came along and added potentially hundreds of man-hours of work in the form of code review to my life.
- ShamblingMound 5y agoIt certainly is considered harm. Ethical research with human subjects makes every effort to do no harm. Taking someone's time without compensating them can be harmful. That's why researchers often give gift cards or small amounts of money for filling out surveys. It's not always as straightforward as paying participants, but compensating participants for their time should be a consideration in ethical research with human subjects. I don't know how much time the kernel maintainers spent on these patches or what their time is worth, but I'm certain that the time they spent on this is worth way more than the nothing they got in return. The uncompensated time that maintainers spent on this is harm. And that anger that you imagine you would feel is harm. Ethical research with human subjects tries to avoid causing this kind of harm, and there seems to have been no such effort in this research design. This was not ethical research.
- d110af5ccf 5y agoConsidering that the number of patches submitted was quite limited I don't think the original research paper would qualify as a DoS attack. The workload imposed by the original research appears to have been negligible compared to the kernel effort as a whole, no more than any drive by patch submission might result in. So no, I wouldn't personally view that as harmful. As to the backdated review now being undertaken, as far as I'm concerned that decision is squarely on the maintainers. (Honestly it comes across as an emotional outburst to me.)
- volta83 5y ago> We send the emails to the Linux communityand seek their feedback. That's not really what they did. They sent the patches, the patches where either merged or rejected. And they never let anybody knew that they had introduced security vulnerabilities on the kernel on purpose until they got caught and people started reverting all the patches from their university and banned the whole university.
- duncaen 5y agoThis is not what happened according to them: https://www-users.cs.umn.edu/~kjlu/papers/clarifications-hc.pdf https://www-users.cs.umn.edu/~kjlu/papers/clarifications-hc.... > (4). Once any maintainer of the community responds to the email, indicating “looks good”, we immediately point out the introduced bug and request them to not go ahead to apply the patch. At the same time, we point out the correct fixing of the bug and provide our proper patch. In all the three cases, maintainers explicitly acknowledged and confirmed to not move forward with the incorrect patches. This way, we ensure that the incorrect patches will not be adopted or committed into the Git tree of Linux.
- tecleandor 5y agoIt'd be great if they pointed to those "please don't merge" messages on the mailing list or anywhere. Seems like there are some patches already on stable trees [1], so they're either lying, or they didn't care if those "don't merge" messages made anybody react to them. 1 - https://lore.kernel.org/linux-nfs/CADVatmNgU7t-Co84tSS6VW=3NcPu=17qyVyEEtVMVR_g51Ma6Q@mail.gmail.com/ https://lore.kernel.org/linux-nfs/CADVatmNgU7t-Co84tSS6VW=3N...
- treesknees 5y agoThe paper doesn't cite specific commits used. It's possible that any of the commits in stable are actually good commits and not part of the experiment. I support the ban/revert, I'm just pointing out there's a 3rd option you didn't touch on.
- dekhn 5y agoThis is exactly what I would have said: this sort of research isn't 'human subjects research' and therefore is not covered by an IRB (whose job it is to prevent the university from legal risk, not to identify ethically dubious studies). It is likely the professor involved here will be fired if they are pre-tenure, or sanctioned if post-tensure.
- dfranke 5y agoHow in the world is conducting behavioral research on kernel maintainers to see how they respond to subtly-malicious patches not "human subject research"?
- alxlaz 5y agoIn the restricted sense of Title 45, Part 46, it's probably not quite human subject research (see https://www.hhs.gov/ohrp/regulations-and-policy/regulations/45-cfr-46/revised-common-rule-regulatory-text/index.html https://www.hhs.gov/ohrp/regulations-and-policy/regulations/... ). Of course, there are other ethical and legal requirements that you're bound to, not just this one. I'm not sure which requirements IRBs in the US look into though, it's a pretty murky situation.
- dfranke 5y agoIf there's some deeply legalistic answer explaining how the IRB correctly interpreted their rules to arrive at the exemption decision, I believe it. It'll just go to show the rules are broken. IRBs are like the TSA. Imposing annoyance and red tape on the honest vast-majority while failing to actually filter the 0.0001% of things they ostensibly exist to filter.
- dlgeek 5y agoHow so? It seems to qualify per §46.102(e)(1)(i) ("Human subject means a living individual about whom an investigator [..] conducting research: (i) Obtains information [...] through [...] interaction with the individual, and uses, studies, or analyzes the information [...]") I don't think it'd qualify for any of the exemptions in 46.104(d): 1 requires an educational setting, 2 requires standard tests, 3 requires pre-consent and interactions must be "benign", 4 is only about the use of PII with no interactions, 5 is only about public programs, 6 is only about food, 7 is about storing PII and not applicable and 8 requires "broad" pre-consent and documentation of a waiver.
- protomyth 5y agoThe IRB of University of Minnesota reviewed the procedures of the experiment and determined that this is not human research. How is this not human research? They experimented on the reactions of people in a non-controlled environment.
- temp8964 5y agoFor IRB human research means humans as subject in the research study. The subject of the study is the kernel patch review process. Yes, the review process does involve humans, but the humans (reviewers) are not the research subject. Not defending the study in anyway.
- dragonwriter 5y ago> Yes, the review process does involve humans It doesn’t just “involve humans” it is first and foremost the behavior of specific humans. > but the humans (reviewers) are not the research subject. The study is exactly studying their behavior in a particular context. They are absolutely the subjects.
- temp8964 5y agoNot sure why you are so obsessed with this. Yes this process does involve humans, but the process has aspects can be examined as independent of humans. This study does not care about the reviewers, it cares about the process. For example, you can certainly improve the process without replacing any reviewers. It is just blatantly false to claim the process is all about humans. Another example, the review process can even be totally conducted by AIs. See? The process is not all about humans, or human behavior. To make this even more understandable, considering the process of building a LEGO, you need human to build a LEGO, but you can examine the process of building the LEGO without examine the humans who build the LEGO.
- fishycrackers 5y agoPeople are obsessed because you're trying to excuse the researchers behavior as ethical. "Process" in this case is just another word for people because ultimately, the process being evaluated here is the human interaction with the malicious code being submitted. Put another way, let's just take out the human reviewer, pretend the maintainers didn't exist. Does the patch get reviewed? No. Does the patch get merged into a stable branch? No. Does the patch get evaluated at all? No. The whole research paper breaks down and becomes worthless if you remove the human factor. The human reviewer is _necessary_ for this research, so this research should be deemed as having human participants.
- nkurz 5y ago> The IRB of University of Minnesota reviewed the procedures of the experiment and determined that this is not human research. I'm not sure how it affects things, but I think it's important to clarify that they did not obtain the IRB-exempt letter in advance of doing the research, but after the ethically questionable actions had already been taken: The IRB of UMN reviewed the study and determined that this is not human research (a formal IRB exempt letter was obtained). Throughout the study, we honestly did not think this is human research, so we did not apply for an IRB approval in the beginning. ... We would like to thank the people who suggested us to talk to IRB after seeing the paper abstract. https://www-users.cs.umn.edu/~kjlu/papers/clarifications-hc.pdf https://www-users.cs.umn.edu/~kjlu/papers/clarifications-hc....
- catgary 5y agoI'm a bit shocked that the IRB gave an exemption letter - are they hoping that the kernel maintainers won't take the (very reasonable) step towards legal action?
- emeraldd 5y ago> The IRB of University of Minnesota reviewed the procedures of the experiment and determined that this is not human research. We obtained a formal IRB-exempt letter. Is there anyone on hand who could explain how what looks very much like a social engineering attack is not "human research"?