diff --git a/src/content/posts/criminal-thinking.md b/src/content/posts/criminal-thinking.md index 5bd0bc7..b089368 100644 --- a/src/content/posts/criminal-thinking.md +++ b/src/content/posts/criminal-thinking.md @@ -99,7 +99,7 @@ The case of the Lukaskrankenhaus in Neuss, Germany, is a prime example. A virus The attackers realized that public infrastructure was a goldmine. By 2019, the target list expanded to city governments. New Orleans had to declare a state of emergency following a cyberattack that crippled the police department, courts, and emergency medical services. -The human cost of this is not theoretical. In 2020, a patient in Germany died after being diverted to a different hospital because the nearest facility was in the midst of a ransomware lockout. The delay in treatment proved fatal. This tragedy underscores the danger of viewing IT security as a cost center rather than a safety requirement. When organizations like Sony (in 2007) or local hospitals decide that "hardening the database costs $10 million, but the breach only costs $1 million," they are making a business calculation that ignores the catastrophic reputational and human damage that modern black hats can inflict. +The human cost of this is not theoretical. In 2020, a patient in Germany died after being diverted to a different hospital because the nearest facility was in the midst of a ransomware lockout. The delay in treatment proved fatal. This tragedy underscores the danger of viewing IT security as a cost center rather than a safety requirement. When organizations like Sony (in 2007) or local hospitals decide that "hardening the database costs \$10 million, but the breach only costs \$1 million," they are making a business calculation that ignores the catastrophic reputational and human damage that modern black hats can inflict. --- @@ -117,7 +117,7 @@ When Heartbleed was announced, the fix was released simultaneously. In a perfect ### The Myth of Calculated Risk -Historically, organizations have rationalized this sluggishness through cold financial calculus. A notorious example from 2007 involves a security executive at Sony, who essentially argued that if hardening a legacy database costs $10 million, but the cost of notifying customers after a breach is only $1 million, the valid business decision is to accept the risk of the hack. This "calculated negligence" was the industry standard for a long time. +Historically, organizations have rationalized this sluggishness through cold financial calculus. A notorious example from 2007 involves a security executive at Sony, who essentially argued that if hardening a legacy database costs \$10 million, but the cost of notifying customers after a breach is only \$1 million, the valid business decision is to accept the risk of the hack. This "calculated negligence" was the industry standard for a long time. That logic has now collapsed. The cost of a breach is no longer just the immediate cleanup bill. Today, we have regulatory hammers like the GDPR (General Data Protection Regulation) in Europe, which mandate that personal data must be protected according to the "state of the art." The penalties for negligence are now astronomical. For instance, the Greek mobile operator COSMOTE was fined €6 million after a hack exposed customer data. Beyond the fines, there is the devastating loss of reputation. In the modern tech economy, trust is a currency. When companies lose customer data, they lose that trust, and the market punishes them far more severely than the cost of a firewall upgrade. diff --git a/src/content/posts/critical-thinking.md b/src/content/posts/critical-thinking.md index c756caa..2479577 100644 --- a/src/content/posts/critical-thinking.md +++ b/src/content/posts/critical-thinking.md @@ -44,7 +44,7 @@ This is where many technical arguments fail. A statement can meet all the previo **Networking (Breadth)** An argument can check every box above and still only represent a slice of the truth. For example, "Reducing three lanes to two on the Getreidemarkt will cause massive traffic jams." That might be true from a traffic flow perspective. But we must view it from other angles. Do we need to consider other standpoints (urban planning, environmental impact, pedestrian safety)? Do we need a new approach to the problem entirely? -**Logik** +**Logic** Does the whole thing make sense? Do the beginning and the end fit together seamlessly? The constituent parts must align without contradiction. **Focus** @@ -118,7 +118,7 @@ A classic example here is the availability heuristic. We judge the frequency or This filtering mechanism also leads to the confirmation bias, perhaps the most dangerous of them all. Once we adopt an opinion, we act like a filter that only lets in supporting evidence. We accept confirming data as high-quality facts and dismiss contradictory data as noise or exceptions. Francis Bacon identified this back in 1620, noting that human understanding forces everything else to add support and agreement to its adopted opinions. This is the engine behind modern "filter bubbles." We are not just passively receiving information; we are actively constructing a reality that reinforces what we already believe. -We also see this in how we perceive value and choices. The anchoring effect describes how we use the first piece of information we see as a reference point for everything that follows. If you see a price tag of $2000 crossed out next to a price of $1000, the TV seems cheap. If you just saw $1000, it might seem expensive. Similarly, the framing effect changes our decision based on how the data is presented. We prefer a product labeled "95% fat-free" over one labeled "5% fat," even though they are identical. We are also subject to inattentional blindness. When we focus hard on one thing — like counting passes in a basketball game — we can completely miss massive, obvious anomalies, like a person in a gorilla suit walking through the frame. This is known as the Monkey Business Illusion. +We also see this in how we perceive value and choices. The anchoring effect describes how we use the first piece of information we see as a reference point for everything that follows. If you see a price tag of \$2000 crossed out next to a price of \$1000, the TV seems cheap. If you just saw \$1000, it might seem expensive. Similarly, the framing effect changes our decision based on how the data is presented. We prefer a product labeled "95% fat-free" over one labeled "5% fat," even though they are identical. We are also subject to inattentional blindness. When we focus hard on one thing — like counting passes in a basketball game — we can completely miss massive, obvious anomalies, like a person in a gorilla suit walking through the frame. This is known as the Monkey Business Illusion. ### Problem 2: Not Enough Meaning @@ -178,7 +178,7 @@ _In the next part, we will explore how these human cognitive flaws are translate We have spent a lot of time dissecting the human brain. We know it is a cognitive miser, we know it filters information to save energy, and we know it constructs a version of reality that is often factually incorrect but easy to process. Now, we need to look at what happens when we take those flawed human brains and ask them to write code. -The counterpart to _cognitive bias_ in humans is **Algorithmic Bias** in computers. If we defined cognitive bias as "faulty tendencies in perceiving, remembering, thinking, and judging," we can map that definition 1:1 onto software. We tend to think of algorithms as neutral mathematical arbiters of truth, but they are often just codified opinions. These errors usually don't happen in isolation; they are a stack. You have inappropriate data structures forming the foundation for partial decisions, Machine Learning (ML) systems fed with unbalanced data, and models that are inherently distorted. +The counterpart to _cognitive bias_ in humans is **Algorithmic Bias** in computers. If we defined cognitive bias as "faulty tendencies in perceiving, remembering, thinking, and judging," we can map that definition 1\:1 onto software. We tend to think of algorithms as neutral mathematical arbiters of truth, but they are often just codified opinions. These errors usually don't happen in isolation; they are a stack. You have inappropriate data structures forming the foundation for partial decisions, Machine Learning (ML) systems fed with unbalanced data, and models that are inherently distorted. For the purpose of this section, we are going to treat the algorithm as a "Black Box." We can observe the Input and the Output, but the internal churning of the machine remains opaque. diff --git a/src/content/posts/design-thinking.md b/src/content/posts/design-thinking.md index b69f55f..ffe0347 100644 --- a/src/content/posts/design-thinking.md +++ b/src/content/posts/design-thinking.md @@ -17,7 +17,7 @@ Then we have the issue of error messages. Straight up, error messages are a fail ### High Stakes and "Dangerous" Design -Bad design isn't just about annoyance; it has a body count. In 2017, the USS John S. McCain collided with the Alnic MC, resulting in the deaths of ten sailors and over $230 million in damages. That is roughly the total budget of a mid-sized European university. The subsequent investigation didn't just find human error; it found a systemic failure in the User Interface. The ship used a complex touch-screen navigation system that confused the operators. +Bad design isn't just about annoyance; it has a body count. In 2017, the USS John S. McCain collided with the Alnic MC, resulting in the deaths of ten sailors and over \$230 million in damages. That is roughly the total budget of a mid-sized European university. The subsequent investigation didn't just find human error; it found a systemic failure in the User Interface. The ship used a complex touch-screen navigation system that confused the operators. This tragedy highlights a critical paradox in automation. We build systems to automate complex tasks, but when those systems malfunction or reach their limits, we hand control back to a human operator. The problem is that the operator, now out of the loop and relying on a confusing interface, is the least equipped person to handle that sudden spike in complexity. We cannot simply blame "user error" when the system itself is designed to provoke confusion. @@ -153,7 +153,7 @@ This ties directly into the concept of **Affordance**, a term borrowed from indu We must also respect the limits of **Human Perception**. Humans are excellent at Recognition — seeing an icon and knowing what it is — but terrible at Recall — remembering a specific command name from memory. Good design relies on recognition, minimizing the cognitive load required to use the tool. This extends to readability, ensuring font sizes, contrast ratios, and color choices accommodate human biology. -Efficiency is governed by the **80:20 Rule**. You should identify the 20% of features that users engage with 80% of the time and make those immediate, one-click actions. The remaining 80% of features, which are rarely used, should be tucked away in menus or secondary screens. The goal is to provide accelerators for power users while maintaining clear, uncluttered paths for beginners. +Efficiency is governed by the **80\:20 Rule**. You should identify the 20% of features that users engage with 80% of the time and make those immediate, one-click actions. The remaining 80% of features, which are rarely used, should be tucked away in menus or secondary screens. The goal is to provide accelerators for power users while maintaining clear, uncluttered paths for beginners. Finally, we must prioritize **Clarity and Control**. Every action needs a defined beginning and a clear confirmation of completion. But more importantly, we must prioritize "Undo" over error messages. An error message effectively tells the user, "You are stupid, stop." An Undo function tells the user, "Don't worry, explore, I have your back." By allowing users to reverse their actions, you give them the confidence to explore the system without fear of breaking it. If you must show an error, speak human language, not error codes. But the ultimate goal is to design a system where the error is impossible to commit in the first place. diff --git a/src/content/posts/responsible-thinking.md b/src/content/posts/responsible-thinking.md index 956ae9c..80940e5 100644 --- a/src/content/posts/responsible-thinking.md +++ b/src/content/posts/responsible-thinking.md @@ -83,7 +83,7 @@ Beyond the legalities, there are the softer, yet equally critical, principles of Consider medical trials involving a placebo. If you are testing a life-saving drug for a virus, and you infect 100 people, giving 50 the drug and 50 a placebo, you have a justice problem. If the "non-treatment" of the placebo group exposes them to significant harm or death, the study is unethical. You cannot sacrifice the health of one group just to prove a point about the other. Justice demands that the benefits and burdens of research are distributed fairly. -Finally, we have to talk about **Compensation**. It is good practice to thank participants, whether that is a small cash payment, a gift card, a badge, or just coffee and cake. However, money changes the voluntariness equation. We have to tread carefully regarding "undue inducement." For a wealthy person, $50 is a nice thank you. For a person in a desperate financial situation, $50 might be the difference between eating and starving. If the compensation is too high, it becomes coercive; the participant effectively _cannot_ say no, and they certainly cannot exercise their right to withdraw if they feel uncomfortable. We must ensure that compensation is an appreciation of time, not a bribe that exploits vulnerability. +Finally, we have to talk about **Compensation**. It is good practice to thank participants, whether that is a small cash payment, a gift card, a badge, or just coffee and cake. However, money changes the voluntariness equation. We have to tread carefully regarding "undue inducement." For a wealthy person, \$50 is a nice thank you. For a person in a desperate financial situation, \$50 might be the difference between eating and starving. If the compensation is too high, it becomes coercive; the participant effectively _cannot_ say no, and they certainly cannot exercise their right to withdraw if they feel uncomfortable. We must ensure that compensation is an appreciation of time, not a bribe that exploits vulnerability. ### In-Action Ethics diff --git a/src/content/posts/scientific-thinking.md b/src/content/posts/scientific-thinking.md index bb5b679..fbce602 100644 --- a/src/content/posts/scientific-thinking.md +++ b/src/content/posts/scientific-thinking.md @@ -263,7 +263,7 @@ Between the ideal of the Scientific Method and the reality of a career in resear But sometimes the fraud is designed to expose the system, not exploit it. In 1994, Austrian researchers Werner Purgathofer, Eduard Gröller, and Martin Feda suspected that the _VIDEA '95_ conference had zero quality control. To prove it, they submitted four completely absurd abstracts filled with subversive humor and technical nonsense. All four were accepted. They went public with the "Beware of VIDEA!" manifesto to shame the organizers. -This tradition of "sting operations" continued. In 2005, three MIT students built _SCIgen_, a software that automatically generates grammatically correct but meaningless computer science papers. They submitted a paper titled "Rooter: A Methodology for the Typical Unification of Access Points and Redundancy" to a conference, and it was accepted. In 2009, Philip Davis from Cornell used similar software to submit a paper to _The Open Information Science Journal_. The journal accepted it, asking only for an $800 publication fee. They didn't care about the science; they cared about the check. +This tradition of "sting operations" continued. In 2005, three MIT students built _SCIgen_, a software that automatically generates grammatically correct but meaningless computer science papers. They submitted a paper titled "Rooter: A Methodology for the Typical Unification of Access Points and Redundancy" to a conference, and it was accepted. In 2009, Philip Davis from Cornell used similar software to submit a paper to _The Open Information Science Journal_. The journal accepted it, asking only for an \$800 publication fee. They didn't care about the science; they cared about the check. The most recent and grotesque example dropped in 2024, when the journal _Frontiers in Cell Development and Biology_ — supposedly a peer-reviewed publication — published a paper containing AI-generated diagrams. One diagram featured a rat with a biologically impossible, gargantuan reproductive organ, labeled with gibberish text like "dck." The image went viral on social media, the paper was retracted, and the reviewers claimed it "wasn't their job" to check the images. These aren't just funny anecdotes; they are structural failures showing that the "critical collective review" we rely on is often asleep at the wheel.