5 ms·
Pretty much this. Having worked in biopreparedness...the instructions aren't the hard part. Both creating and deploying a biological threat are wildly more diff
by Fomite 3y ago
Pretty much this. Having worked in biopreparedness...the instructions aren't the hard part. Both creating and deploying a biological threat are wildly more difficult.
- nextos 3y agoI don't fully agree. Things are becoming quite simple, which is scary. There's a well-intentioned lobby in the UK advocating for some minimal control, i.e. checking DNA / RNA / protein sequences. For instance, cheap mRNA synthesis as a service has lowered the barrier of entry for any malicious actor. It's frankly ridiculous there are no checks in place right now.
- jdewerd 3y ago> minimal control, i.e. checking DNA / RNA / protein sequences They were already doing this 15 years ago. > It's frankly ridiculous there are no checks in place right now. It's frankly ridiculous that you think this.
- nextos 3y agoThat's your opinion, but I've seen firsthand that there's a lack of controls in this area.
- jdewerd 3y agoMy experience, not my opinion. I personally tripped over the checks many times, back before they got institutional authentication smoothed out. I regularly hear bio researchers claim firtshand experience that there are no checks, but then it turns out they were using institutional names, credit cards, and shipping addresses the whole time, so what they actually experienced was a lack of false positives rather than an absence of checking.
- jefftk 3y ago>> minimal control, i.e. checking DNA / RNA / protein sequences > They were already doing this 15 years ago. I work in this area. Some synthesis providers check, others don't. And the checking isn't great. (Some of my coworkers work on https://securedna.org https://securedna.org which is trying to make this screening more robust.)
- pushfoo 3y agoTL;DR: I don't understand how adding homomorphic encryption makes a cloud virus scanner for physical pathogens a better idea > Only authorized researchers should be able to obtain DNA permitting them to assemble pandemic-capable agents. Imagine this becomes legally mandatory. What happens when they get breached? For example: * Does it enable denial-of-service attacks by returning false positives hospitals legally can't ignore? * Does it return false negatives as part of another attack? Example: printing known or novel virii which will be introduced in a specific lab? * Does the attacker selectively perform these behaviors as part of an action against a specific person or area? Metadata seems like it would enough to target the physical parts of an attack usefully, even without plaintext. The best security & privacy approach I've seen in hospitals is keeping critical services on-prem, or at least strictly intranet-only. The latter ends up being forced by physical scale once a medical complex grows large enough to span multiple buildings. The firmware embedding mentioned on their site seems better than cloud, yet still seems misguided. How will you debug problems, especially if you never have access to the plaintext? Formal methods and verified programs? Provably equivalent encrypted and plain operations?
- deleted 3y ago[deleted]
- jefftk 3y ago> I don't understand how adding homomorphic encryption makes a cloud virus scanner for physical pathogens a better idea The reason to use a cloud service is that you can check whether someone is trying to synthesize something hazardous without distributing a list of the hazards. There are a lot of subtle ways to cause harm with biology, and you don't want to tell people where to look. Then the reason to use homomorphic encryption is that otherwise the cloud service learns which sequences people are trying to synthesize. Biotech companies care a lot about keeping their in-progress work private, so they'd reject a cloud system without this. > Does it enable denial-of-service attacks by returning false positives hospitals legally can't ignore? Aside: I'm confused why you're saying "hospitals" -- medical providers don't synthesize things, it's researchers at universities and biotech companies. Maybe you're using "hospitals" as in "research hospitals" which is fine, but maybe you're using it because you're under the impression that synthesis is part of medical treatment? To answer your question, though, if an attacker managed to add something normal and harmless to the DB then yes, a benchtop synthesizer would refuse to synthesize the sequence. The lab would escalate, it would be sorted out, there'd be a postmortem etc. > Does it return false negatives as part of another attack? Example: printing known or novel virii which will be introduced in a specific lab? Yes, if an attacker managed to remove a harmful sequence from the database then it wouldn't raise any flags if they or a confederate tried to synthesize that sequence. Both of these cases come down to "it's important that you have good controls around what's in the DB, and a secure process for making changes." > Metadata seems like it would enough to target the physical parts of an attack usefully, even without plaintext. I'm not sure what you're saying here.
- deleted 3y ago[deleted]
- XorNot 3y ago...what do you think a vial of mRNA actually does? I'll give you a hint: if you touched it to your finger, it would be completely destroyed.
- Vecr 3y agoYou don't want RNA anyway, you want to turn the virus's RNA sequence into a DNA sequence (reverse transcription), then do whatever editing you want once that's in your computer, then synthesize the DNA, and grow up the virus in culture by introducing the DNA. The cells in the cell culture will turn the DNA into RNA for you and then assemble the viruses.
- XorNot 3y agoAlso the whole "testing" part. Unless you're just culturing an already known virus (in which case, why do you need to synthesize anything? You have it in a test tube or something) then there is not in fact any real way to know whether or not some particular genetic modification translates to any type of favorable property. Even gene-linked desirable traits in one species may not correspond to that trait in another, particularly when your metrics are things like "transmissivity" and "lethality" and not "I need slightly more peas per pod".