Live data from Hacker News

“They introduce kernel bugs on purpose”

lore.kernel.org

51–60 of 1001 posts

Re: “They introduce kernel bugs on purpose”

#51
post #16

The problem here is really that they’re wasting time of the maintainers without their approval. Any ethics board would require prior consent to this. It wouldn’t even be hard to do.

1) They identified vulnerabilities with a process 2) They contributed the correct code after showing the maintainer the security vulnerability they missed. 3) Getting the consent of the people behind the process would invalidate the results.

Getting specific consent from the project leads is entirely doable, and would have avoided most of the concerns.

Re: “They introduce kernel bugs on purpose”

#53
post #22

Later down thread from Greg K-H: > Because of this, I will now have to ban all future contributions from your University. Understandable from gkh, but I feel sorry for any unrelated research happening at University of Minnesota. EDIT: Searching through the source code[1] reveals contributions to the kernel from umn.edu emails in the form of an AppleTalk driver and support for the kernel on PowerPC architectures. In t…

seems extreme. one unethical researcher blocks work for others just because they happen to work at the same employer? they might not even know the author of the paper...

Re: “They introduce kernel bugs on purpose”

#54
post #17
post #2

I don't think there have been any recent comments from anyone at U.Mn. So, back when the original research (happened last year) the following clarification was offered by Qiushi Wu and Kangjie Lu which atleast paints their research in somewhat better light: https://www-users.cs.umn.edu/~kjlu/papers/clarifications-hc.... That said the current incident seems to have gone beyond the limits of that one and is a new incid…

Their first suggestion to the process is pure gold:"OSS projects would be suggested to update the code of conduct, something like “By submitting the patch, I agree to not intend to introduce bugs”" Like somebody picking your locks, and suggesting, 'to stop this one approach would be to post a sign "do not pick"'

The sign is to remind honest people that the lock is important, and we do not appreciate game playing here.

Re: “They introduce kernel bugs on purpose”

#55

From https://lore.kernel.org/linux-nfs/CADVatmNgU7t-Co84tSS6VW=3N... , > A lot of these have already reached the stable trees. If the researchers were trying to prove that it is possible to get malicious patches into the kernel, it seems like they succeeded -- at least for an (insignificant?) period of time.

I wonder whether they broke any laws intentionally putting bugs in software that is critical to national security.

Re: “They introduce kernel bugs on purpose”

#57
post #40

[flagged]

This is unjustified xenophobia. And besides, if they were really trying to get bugs into the Linux kernel to further some nefarious goal, why would they publish a paper on it?

Simplest explanation is that they just wanted the publication, not to blame it on CCP or the researchers' nationality.

Re: “They introduce kernel bugs on purpose”

#58

From https://lore.kernel.org/linux-nfs/CADVatmNgU7t-Co84tSS6VW=3N... , > A lot of these have already reached the stable trees. If the researchers were trying to prove that it is possible to get malicious patches into the kernel, it seems like they succeeded -- at least for an (insignificant?) period of time.

It may be unethical from an academic perspective, but I like that they did this. It shows there is a problem with the review process if it is not catching 100% of this garbage. Actual malicious actors are certainly already doing worse and maybe succeeding.

In a roundabout way, this researcher has achieved their goal, and I hope they publish their results. Certainly more meaningful than most of the drivel in the academic paper mill.

Re: “They introduce kernel bugs on purpose”

#59
post #22

Later down thread from Greg K-H: > Because of this, I will now have to ban all future contributions from your University. Understandable from gkh, but I feel sorry for any unrelated research happening at University of Minnesota. EDIT: Searching through the source code[1] reveals contributions to the kernel from umn.edu emails in the form of an AppleTalk driver and support for the kernel on PowerPC architectures. In t…

[deleted]

Re: “They introduce kernel bugs on purpose”

#60
post #22

Later down thread from Greg K-H: > Because of this, I will now have to ban all future contributions from your University. Understandable from gkh, but I feel sorry for any unrelated research happening at University of Minnesota. EDIT: Searching through the source code[1] reveals contributions to the kernel from umn.edu emails in the form of an AppleTalk driver and support for the kernel on PowerPC architectures. In t…

seems extreme. one unethical researcher blocks work for others just because they happen to work at the same employer? they might not even know the author of the paper...

[deleted]
Post reply on HN