4 ms·
>Biology researchers aren't reverse engineering the binary outputs of qPCR machines While this is beside your point, outputs from qPCR machines are often reaso
by cge 2y ago
>Biology researchers aren't reverse engineering the binary outputs of qPCR machines
While this is beside your point, outputs from qPCR machines are often reasonably interpretable. I've seen one model that's XML, and one that's JSON, both as files in an overall data file that's just a ZIP, and I have seen intermediate files that are just plain text. In both cases, these are processed on the machine from raw images, which are a standard TIFFs, though they are usually not stored.
I am similarly left confused about the motivation of this project, however. If I recall correctly, commercial offerings of cryptographic signatures for qPCR machines already exist, running on the machines. Also, while they immediately dismiss the idea of modifying the machine, or even using different software, those are both important considerations. Many modern qPCR machines have computers running full operating systems in them (the QuantStudio machines run Android, for example, and have their core control running internally in Python); these can extremely insecure. All the work they have done would do nothing to protect against a modified machine, and contrary to what they suggest, I have found that modifying machines, and writing interface software as an alternative to the manufacturer's, can be quite easy. qPCR machines are not actually very complicated instruments, especially from a firmware perspective. In putting tamper-evident seals on the machines they perhaps don't realize how open lab equipment can be: I've seen almost intentional unauthenticated privileged remote code execution, for example.
And, as you note: it's very unclear what type of behavior this is even trying to defend against. Research malpractice is both rare, and can take place at very many points in the process. This seems like it is defending against a particularly unlikely point. I think fraud would more likely take place either in setup, or in data processing.
And finally: this locks down machines to be only usable in very specific ways. That is reasonable in diagnostic and clinical settings. But research is often not about doing the exact same thing that has already been done. It often involves new uses for equipment, and new experimental methods. Most of my use of qPCR machines, for examplee, would be impossible in their setup, as I'm using them in ways the manufacturer's software doesn't support, and the data coming out has nothing to do with qPCR, and so can't be processed in a normal way. At some level, research equipment cannot be heavily constrained, as that is contrary to the very point of research.
(For context: I maintain an open source package to control QuantStudio machines, primarily intended for using them for non-qPCR purposes.)