Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The paper file listing [1] from the PC in question shows predictable [conference][year]-paper[incrementing-number] file name pattern. Rather than "insider help" [2], could this be explained via a "leaky endpoint/api" that got scraped?

I hope I'm missing something.

[1] https://miro.medium.com/max/1400/1*sNC6SuC1v8peYmw6KEcz3g.pn...

[2] Quote: "HotCRP does not show you your own submission even if you are a PC member, so how did the de-anonymized reviews and PC comments for Huixiang’s paper end up in his laptop? An insider help seems likely."



It's possible, but there are only a few reviewing systems that are commonly used and their permission systems are robust as far as I know. I think a simpler explanation is that someone in the fraud group has a "higher permission role" than a first-line reviewer, so has access to these. This could be someone who is a general chair, program committee chair, track chair or area chair if the conference is big enough, and often even senior PC members (the metareviewers). All they have to do is perform an export and put it on Dropbox or Google Drive.


It has been confirmed that the reviewing system in question is HotCRP, which is a very battle-tested system that is unlikely to have these issues.

There is a comment from Eddie Kohler on Twitter which implies this was not a leaky endpoint problem. You can see this thread for more details: https://twitter.com/xexd/status/1222659612857401344?s=20




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: