While there are other requirements, a sincere apology cannot in any way entertain doubt about the fact that there WAS harm.
Truly acknowledging the harm done is foundational to a real apology, and most of us (myself included) end up sneaking in weasel words or phrases like this.
Psychologically, its nice for the apologizer, since it allows one to think "i'm being good by apologizing, but maybe I didn't do anything bad after all?".
But from the apologizee standpoint, these phrases are often devastating and can make it clear that the apologizer has no real recognition or care of what happened.
Personally I've worked pretty hard to try to remove these sorts of phrases from my apologies. It's not easy. It makes you feel much more vulnerable and you really have to let whatever you did sit with you in a very uncomfortable way. But it's worth it.
For me, it reads like this "With the best intentions, we were helping you. Unfortunately, you are too stupid to not realise this. We are sorry that we hurt your feelings, but please let us continue in helping you."
When you get such an apology, best thing is to avoid such people. Because it's clear they do not understand where they went wrong.
They should have either apologized with "we made a very big mistake that had a negative impact, it did more harm than good". Or they should have argued with real evidence on how they improve the Linux kernel, like refer to real exploits that they fixed.
This is just a "we're sorry that you don't realize we are helping you"
The issue I have with the letter (not being involved at all and just following) is that it feels like an apology of the bully at school that took your lunch money, and the parents found out.
Honestly, for all we know this letter could be meaningless. A real good actor would also reveal the other commits in order to have a full disclosure.
Trust isn't based on promises, trust is based on past actions. Therefore they should be treated as such, as their actions are evidence for being a potentially malicious actor.
I'm still convinced Greg did the right thing here, as it's better to be safe than sorry in this case due to the sheer scale of an attack vector that the actors might have introduced.
Even if other commits of good actors at the same University are now treated with more attention to their code, I think they are a casualty that was predictable in the moment the ethics commitee signed off the paper's research procedure.
This interpretation looks flawed. You discredit the entire message based on a single word--a very general word whose meaning you pinned to a definition which results in the most negative interpretation--and you also ignore the fact that they explicitly state the damage it caused in the same paragraph.
To clarify: I'm not arguing this is a good or bad apology; just that the justification provided here looks flawed. Human speech isn't a programming language; it's not well defined and it's more than the sum of its parts. One can't derive conclusions about a text by analyzing a tiny subset out of context.
If this was a transcript of a spoken apology I might be of your train of thought, but this was a composed letter looked over by (ostensibly) multiple folks. The wording was a choice.
Strongly agree with your sentiment; any premeditated/composed message is held to a higher standard (and rightfully so). I'm not arguing that one shouldn't analyze the wording, but that the analysis here is flawed (for the reasons I stated).
I would argue at this point in collective awareness of public communications, using a form of "sorry if I did any harm" regardless of specific words used is an explicit decision by the writer to not accept full culpability. I agree with original comment, when you see a weasel apology introduction, reading the rest is of little value.
> I would argue at this point in collective awareness of public communications, using a form of "sorry if I did any harm" regardless of specific words used is an explicit decision by the writer to not accept full culpability.
Based on my experience with the general public, with academics, and with industry folks, the criteria for what constitutes a sincere apology is not known by the majority. Furthermore, many of those who have heard the criteria do not accept it as a gold standard, and disagree with it (even those who are not being looked to for an apology).
The recipient can always choose to accept or not an apology. However, I find it quite distasteful to attribute intentions to someone simply because they did not follow a recipe (even if the choice not to was intentional).
I find it nicely clear in German. If you wrong someone, you're loading guilt unto yourself ("mit Schuld beladen"). You'll then ask to be forgiven ("um Entschuldigung bitten" is "asking to be relieved of the guilt"), and the other party can lift the guilt ("entschuldigen"). You can also say "ich entschuldige mich", which skips that step and is essentially "I absolve myself".
While it's common in colloquial German to use the one-step-absolution and skip over the possibility of the other party not absolving you, it's also often considered rude when it matters and has a taste of "but not really". It's fine when you accidentally stepped on someone's foot, but not so much when you've stolen their car.
“I’m sorry if I hurt you,” is a very different statement from, “I am sorry I hurt you.” One makes responsibility conditional, and the other takes responsibility.
Strong disagree. You should always apologize for _what you did_ not the _effects_ of what you did. Lead with and more strongly emphasize your actions and how they were inappropriate.
I think it's both unfair and non-constructive to pick apart a apology letter based on one word like that. Let's assume good faith, especially when the writer's English might not be their first language (based on their name).
I think this response misses the point. The purpose of an apology is to make the recipient feel that you're sorry. That means thinking about how word choice is received is critical in crafting a good one. Your parent isn't saying the author's choice of words is in "bad faith", they're saying the author's word choice falls short of an effective apology due to a mistake that's common and easy to make. I agree, and I have done this myself in the past.
It seems like a nitpick to me, since the rest of the apology uses the proper choices of words, though. "The method used was inappropriate", "we made a mistake", etc.
The apology is also specific about what they did wrong despite their intentions. It really is a good apology after reading past the first six words.
1) "We apologize for any harm we might have caused"
2) "We apologize for any harm that we caused"
3) "We apologize for all the harm that we caused"
(1) is the least apologetic. This could be interpreted as saying "we might or might not have caused harm, and we think we didn't but you think we did, so we're going to apologize for your sake, but we're not really sorry because we didn't do anything wrong from our perspective".
(3) is the most apologetic. You acknowledge that you did something wrong, and that you're apologizing for it. This might be followed up with a specific list of the things that you did wrong, and that you are apologizing for. That would make for the most sincere apology. This could be interpreted as "we caused harm and we're sorry, whatever harm you think that we did, we agree that you are right, and we are sorry for all of it".
(2) is partway between (1) and (3). You acknowledge you caused harm, but you won't enumerate the things that you did wrong. So, you leave yourself a little bit of wiggle room. This could be interpreted as "we caused harm and we're sorry, but we didn't cause that much harm, we think it was actually quite little, you think it was a lot, but we're saying sorry, so let us go with this apology".
A sincere written apology should be 3. You needn’t misrepresent your own intentions to do this, but it does require thinking about the specific harms you have caused (perhaps unintentionally) and enumerating them in a way that doesn’t minimize their import. That is the anatomy of a true apology. It requires taking the other perspective as fact.
There isn’t much difference and both are really correct. The problem with ‘any’ as raised here is the ambiguity. It could be taken to mean ‘any harm, if it occurred’ or ‘any single bit of harm that did occur’. So in this sense ‘all harm’ would be safer and less ambiguous.
That depends on the sentence context.[1] As used here it is fully correct; "we sincerely apologize for all harm our research group did" would be highly anomalous, whereas the phrasing they actually used is conventional.
"We sincerely apologize for all the harm our research group did" would be a little less unnatural than "...for all harm...", but it's still an unusual choice of wording that ends up sounding like you want to emphasize that you did an unusually large amount of harm.
A more standard phrasing that includes the word all would be "We apologize for any and all harm...".
The standard form I know is actually "[I am deeply sorry] for any harm I may have caused..."; the letter here does not use a modalized verb. (Compare their "We sincerely apologize for any harm our research group did...".) In that sense it's more definite than usual. The criticism above is strange.
(The reason for the modality in the standard form isn't really to leave open the possibility that you didn't do any harm. It's to leave open the possibility that you did harm you don't even know about -- and therefore can't apologize for specifically.)
[1] In general, any occurs only in negative sentences, though in the details there are several types of sentences that are sort of "honorarily negative" for the purposes of allowing any and other words that obey the same restrictions.
You want my opinion? It's possible, it's less standard than the "for any harm" form, but it means roughly the same thing.
It wouldn't have occurred to me to discuss it above, because I thought I was contrasting any with all, and neither is present in that example. But I'd rate it above most of the alternatives discussed (while still below "for any harm").
Not correct, at least in this context. "Any harm" means there could be no harm, or some harm, but "all harm" admits there was harm. I.e. "any" is not an admission of doing harm, or an acceptance that it happened.
If you want to apologise, "all harm" admits you caused harm, which seems necessary for an apology. "Any" is a bit like those "I'm sorry if you were offended" non-apologies, though in this case the rest of the message does better than that.
I would go with "We apologize for the harm [that] we caused" which seems the most natural choice while explicitly acknowledging that some harm was caused. "All the harm" does indeed come across as a bit inflated, as other commenters have mentioned.
As others have said, 'any harm' implies that there might be none, while 'all harm' implies there is definitely some harm. So, 'all harm' is definitely the better choice of words for an apology (in this context.)
I am surprised to see people hung up on this, because the rest of the letter acknowledges specific harms done. To me, it really seems like a minor thing, and something that I might have written (as a native English speaker.)
We are talking about deliberate security vulnerabilities in the Linux kernel, a piece of critical infrastructure. Frankly, this is not the place to assume good faith.
The "hypocrite commits", according to the researchers' own paper, originated from "random Gmail addresses", and the researchers continue to claim none of those got merged (though since they haven't told us what they were, ...)
The additional claim is that some of the commits not covered by their "hypocrite commits" (and thus, submitted from their UMN addresses) contained security bugs, deliberate or not, and the loss of trust in the researchers is sufficient to justify reverting all of their commits until they can be reviewed.
I don't think it's that weak of an assumption. First, considering all the people with foreign names in relevant groups (multinational corporations, or in this case, a researcher/ student at a university), I would say the chances that their first language is not English is high enough to be a consideration. And even if it is, there are also regional variations regarding what are common and accepted ways of phrasing things. Second, similar to the rule used here at HN, giving the text a more charitable read should be the starting point.
those guidelines only apply to members of this community. Not an outside article. We should assume all users on hn honour the guidelines. We don't need to assume outside articles do.
I read it as a comment that was criticizing the language, not the intention of the apology. As such they are not inferring that the apology was insincere but pointing out language that in the apology that the posted has often added themselves that gives the appearance of insincerity of the recipient. To me that is the strongest possible interpretation of the comment you are replying to.
In researcher's shoes, I would retract paper from IEEE, only then send open latter. Because they did not do this, does not looks like there's open letter is sincere, I am sure researcher's aware that there where multiple complaints regarding there's paper before ban. The least they could have done is acknowledge such failures in open letter.
This is probably because they don't mean the apology, they were forced to write it by their administrators.
And to be honest, I kind of agree with them. I don't really see what they did here as particularly bad. They demonstrated a very serious vulnerability in the linux kernel development process. I guess the harm they caused was wasting maintainers time, a bit? But what we all got out of it is the knowledge that real bad actors could easily have done this too. It's odd to me that people are focusing on like, the etiquette here when such an important vulnerability was demonstrated.
The purpose of the research was to publicly announce that that the research subjects (who did not consent to being studied) messed up. The research consisted of submitting patches specially crafted to make sure the (non-consenting) subjects did indeed mess up.
Ya, I get that. But the point was to demonstrate that the project was vulnerable to this kind of attack - which it was. That's an extremely important finding.
Sure, but so does every website that AB tests a landing page. Consent is only relevant when there is some risk to the subject (or something they value, like privacy, etc).
What about the risk to the reputation of anyone who approves these patches? Or of intentinally buggy patches making it into the wild and being exploited?
There is also the risk that a third party sees the patch on a mailing list, and merges it to his internal branch because it looks like it is fixing one of his problem.
But I'd argue it is his own fault to use unsupported patches.
Me and common sense. I don't believe consent is relevant when there is no risk of harm to the subject. IRBs and the GDPR are overly aggressive on this point, probably as a reaction to real and important violations of privacy. But the idea that A/B testing the color of your CTA button on a landing page requires informed consent is absurd.
> But the idea that A/B testing the color of your CTA button on a landing page requires informed consent is absurd.
A/B testing on major platforms is much more sophisticated than that[1].
It's a crucial practice for advertisers and marketing teams that dives deep into researching the psychological response towards images, text and dozens of other variables. Human subjects are acting as lab rats in order to extract some data points to drive the next test and campaign.
So, yes, it should definitely require informed consent and opting in.
> A/B testing on major platforms is much more sophisticated than that[1].
On some it is, and some it isn't.
> It's a crucial practice for advertisers and marketing teams that dives deep into researching the psychological response towards images, text and dozens of other variables. Human subjects are acting as lab rats in order to extract some data points to drive the next test and campaign.
This is just a long and emotionally laden way of saying "changing images and text to see which works best".
> So, yes, it should definitely require informed consent and opting in.
Guess we're just going to have to agree to disagree then. I don't see any reason whatsoever to think that this practice is harmful to the subjects being experimented on.
At worst, it's harmful to society in general because it incentivizes consumerism and potentially self destructive behavior. But that is completely orthogonal to the issue of informed consent. If you got perfectly informed consent from 10,000 people to tease out the perfect pitch text, and then deployed it against the rest of the population, the effect would be exactly the same, whether or not you got consent.
There's lots of systemically horrible things that can happen if you're not careful about what you allow. If you're interested why these ethical principles exist in the United States, I suggest you at least skim the Belmont Report
> There's lots of systemically horrible things that can happen if you're not careful about what you allow.
Of course there are. But what specifically are the harms that are going to be caused by either this research or a landing page A/B test without a click through pop up? The existence of theoretical harms for broad categories of potential research does not have a whole lot of bearing on these specific lines of research.
> If you're interested why these ethical principles exist in the United States, I suggest you at least skim the Belmont Report
I read it. It was interesting, but I don't think it's particularly relevant here. The only prong of its test that would be relevant to this experiment is "respect for persons". The idea that somehow not revealing the bug or the experiment was intrinsically harmful as a violation of a person's moral autonomy.
I don't buy that line of reasoning, and I can't really think of any valid consequentialist justification for it, and the report itself does not attempt to justify it either, as far as I can tell.
If I sit across the street from your house in a van and observe your life, noting down the times you come and go, and logging what I can see through your window, and then using that data to market things to you, would you agree that you'd rather be able to provide and withdraw consent for this activity? No harm done to you.
Ya, they wasted a bit of their time. That wasn't very nice. But it's hardly the great crime it's being made out to be, and what they did was a huge public service. It's impossible to over-state the importance of linux kernel security.
You don't get to decide what you think is important and then burden others pushing it.
If you think testing security in random attack way is important tell the people who run the project. They are the ones qualified to make the calls.
It's just a scammy move at best. To me it's borderline criminal to sabotage a project like that.
This is the part I'm personally most interested in. Research generally has pretty strict ethical regulations about consent. I'm wondering if this would qualify as a violation of any of their university's or the conference's rules.
Their biggest crime seems to be they just aren't great developers. If you look at the patches they presented which to their knowledge were correct you'd see they couldn't have done anything useful. Because of their earlier work this was taken as intentional malice, but if they had been submitting great work it wouldn't be an issue.
> end up sneaking in weasel words or phrases like this.
Honestly, based on the way they handled their "research" in the first place, sneaking weasel words into an open apology letter is entirely par for the course...
Your critique seems more about waffle words in apologies and less about this specific apology. While they do waffle in that sentence, on the whole, their apology seems pretty sincere. They acknowledge their error and the harms they perceive they caused. As a linux user, I am inclined to accept.
> a sincere apology cannot in any way entertain doubt about the fact that there WAS harm
Someone will always be apologizing wrong for some. Some interpretation of what harm there was, is not necessarily the same as my interpretation. There are too many ways to construe what harm there was or may have been according to others to satisfy everyone addressed. This is an efficient wording that doesn't explicitly satisfy your (and many people's) specific issues out of "the community", which illustrates the point.
"If you give me six lines written by the hand of the most honest of men, I will find something in them which will hang him."
I understand doubting the sincerity of the authors, but this argument hinges here on them saying "any" instead of "all" and they are often used interchangeably in casual conversation.
"We sincerely apologize for any harm..."
While there are other requirements, a sincere apology cannot in any way entertain doubt about the fact that there WAS harm.
Truly acknowledging the harm done is foundational to a real apology, and most of us (myself included) end up sneaking in weasel words or phrases like this.
Psychologically, its nice for the apologizer, since it allows one to think "i'm being good by apologizing, but maybe I didn't do anything bad after all?".
But from the apologizee standpoint, these phrases are often devastating and can make it clear that the apologizer has no real recognition or care of what happened.
Personally I've worked pretty hard to try to remove these sorts of phrases from my apologies. It's not easy. It makes you feel much more vulnerable and you really have to let whatever you did sit with you in a very uncomfortable way. But it's worth it.