5 ms·
> minimal control, i.e. checking DNA / RNA / protein sequences They were already doing this 15 years ago. > It's frankly ridiculous there are no checks in pla
by jdewerd 3y ago
> minimal control, i.e. checking DNA / RNA / protein sequences
They were already doing this 15 years ago.
> It's frankly ridiculous there are no checks in place right now.
It's frankly ridiculous that you think this.
- nextos 3y agoThat's your opinion, but I've seen firsthand that there's a lack of controls in this area.
- jdewerd 3y agoMy experience, not my opinion. I personally tripped over the checks many times, back before they got institutional authentication smoothed out. I regularly hear bio researchers claim firtshand experience that there are no checks, but then it turns out they were using institutional names, credit cards, and shipping addresses the whole time, so what they actually experienced was a lack of false positives rather than an absence of checking.
- jefftk 3y ago>> minimal control, i.e. checking DNA / RNA / protein sequences > They were already doing this 15 years ago. I work in this area. Some synthesis providers check, others don't. And the checking isn't great. (Some of my coworkers work on https://securedna.org https://securedna.org which is trying to make this screening more robust.)
- pushfoo 3y agoTL;DR: I don't understand how adding homomorphic encryption makes a cloud virus scanner for physical pathogens a better idea > Only authorized researchers should be able to obtain DNA permitting them to assemble pandemic-capable agents. Imagine this becomes legally mandatory. What happens when they get breached? For example: * Does it enable denial-of-service attacks by returning false positives hospitals legally can't ignore? * Does it return false negatives as part of another attack? Example: printing known or novel virii which will be introduced in a specific lab? * Does the attacker selectively perform these behaviors as part of an action against a specific person or area? Metadata seems like it would enough to target the physical parts of an attack usefully, even without plaintext. The best security & privacy approach I've seen in hospitals is keeping critical services on-prem, or at least strictly intranet-only. The latter ends up being forced by physical scale once a medical complex grows large enough to span multiple buildings. The firmware embedding mentioned on their site seems better than cloud, yet still seems misguided. How will you debug problems, especially if you never have access to the plaintext? Formal methods and verified programs? Provably equivalent encrypted and plain operations?
- deleted 3y ago[deleted]
- jefftk 3y ago> I don't understand how adding homomorphic encryption makes a cloud virus scanner for physical pathogens a better idea The reason to use a cloud service is that you can check whether someone is trying to synthesize something hazardous without distributing a list of the hazards. There are a lot of subtle ways to cause harm with biology, and you don't want to tell people where to look. Then the reason to use homomorphic encryption is that otherwise the cloud service learns which sequences people are trying to synthesize. Biotech companies care a lot about keeping their in-progress work private, so they'd reject a cloud system without this. > Does it enable denial-of-service attacks by returning false positives hospitals legally can't ignore? Aside: I'm confused why you're saying "hospitals" -- medical providers don't synthesize things, it's researchers at universities and biotech companies. Maybe you're using "hospitals" as in "research hospitals" which is fine, but maybe you're using it because you're under the impression that synthesis is part of medical treatment? To answer your question, though, if an attacker managed to add something normal and harmless to the DB then yes, a benchtop synthesizer would refuse to synthesize the sequence. The lab would escalate, it would be sorted out, there'd be a postmortem etc. > Does it return false negatives as part of another attack? Example: printing known or novel virii which will be introduced in a specific lab? Yes, if an attacker managed to remove a harmful sequence from the database then it wouldn't raise any flags if they or a confederate tried to synthesize that sequence. Both of these cases come down to "it's important that you have good controls around what's in the DB, and a secure process for making changes." > Metadata seems like it would enough to target the physical parts of an attack usefully, even without plaintext. I'm not sure what you're saying here.
- Fomite 3y ago"Aside: I'm confused why you're saying "hospitals" -- medical providers don't synthesize things, it's researchers at universities and biotech companies" During at least two pandemics I've worked on, I've known hospital labs synthesizing their own PCR primers for diagnostic tests.
- anonymouskimmer 3y agoIf someone really, really wants to do it they'll buy a second hand oligonucleotide synthesizer and the reagents, and do the larger scale assembly the old fashioned way. Still, it's worth keeping the barrier of entry higher than just being able to order it. As per the homomorphic encryption discussed earlier, you can easily avoid the 'need' for this by having federal governments operate the screening tools.
- jefftk 3y ago> it's worth keeping the barrier of entry higher than just being able to order it. Exactly! Keeping groups with lots of resources from synthesizing harmful things isn't a battle we can win (and in a decade or so biological design tools will make scanning synthesis orders a very weak precaution) but raising the bar means fewer people are in a position to cause large-scale damage. (Long term we also need to make society more robust to biological attacks, with better monitoring, better PPE, and faster countermeasures.)
- deleted 3y ago[deleted]