One of the things that surprised me was that she was identifying manipulated and duplicated images using her own eyes.
This could be done via software, and might catch more papers than the ~6k out of 100k that she did.
In the software world, there are tools for this, "software composition analysis". I worked at a company that got busted for violating GPL, and as part of settling the suit, all software had to be run through BlackDuck and all warning/issues found by the tool had to be resolved before the software could be released.
(NOTE: the software that violated GPL was from an acquisition)
For these scientific papers, at a minimum truth==reproducibility.
For humanities and social sciences, it could mean consensus, but in hard science it is different. You are doing experiments that produce data. If someone else repeats the experiment, they should get the same data.
In this case, no one could reproduce the results of the papers in question.
I wonder how widespread this has become. How many scientists, driven to publish, know that it is too expensive to reproduce their experiment?
I had a Professor in college who refused to meet with me behind a a close door, and we were both male. He kindly explained that he picked this up from a former professor of his. He wanted zero possibility of a student accusing him of sexual misconduct. At the time I thought it was a bit strange, but I agreed and left the door open. 20 years later, it doesn't sound so strange anymore.
How you treat the "other" is the measure of a low trust society. Murder is wrong and not tolerated within the clan, but violence towards the "other" is ignored and in some cases encouraged.
Yes, there are hate crimes in America but they make the news and promoted to the FBI. This helps build trust.
In my limited experience, Germans are more sensitive to personal privacy than other Europeans, even the rest of the world. To non-Germans they might seem paranoid. Maybe we can all learn from their historical mistake.
The problem I see with the DIY-attitude is that security is easy to get wrong and is moving target. The other opinion here is "keep it in the country". If someone really wants your data, the locale won't save you. And yet, if there is a breach, I could see an foreign company like AWS trying to hush it, where a German company would make a bigger fuss (diplomatic issue).
Does anyone have info on GDPR's success in getting data removed or fining companies? I am not following closely, but last I saw was GDPR is a law whose enforcement is untested.
If I understood correctly, the database was on a publicly accessible network. Wouldn't the problem be averted by putting the database in a separate VLAN, where only specific IP's from the public VLAN could access it, and not IP's from WWW??
I would add that you don't need to understand the implementation details to understand privacy of citizens, tracking of users, and accountability. It doesn't take years of programming experience to understand that the big data companies wield incredible power and are also vulnerable to security breaches. (Maybe you shouldn't collect data that you can't protect.)
If there is a medium to high drop out rate, and teachers are constantly looking for new student to fill their schedule (even 30% of their schedule), it could well be worth it.
But reproducing studies could be live-streamed without a problem.