Live data from Hacker News

“They introduce kernel bugs on purpose”

lore.kernel.org

141–150 of 1001 posts

Re: “They introduce kernel bugs on purpose”

#141
post #16

The problem here is really that they’re wasting time of the maintainers without their approval. Any ethics board would require prior consent to this. It wouldn’t even be hard to do.

> The problem here is really that they’re wasting time of the maintainers without their approval.

Not only that, but they are also doing experiments on a community of people which is against their interest and also could be harmful by creating mistrust. Trust is a big issue, without it it is almost impossible for people to work meaningfully together.

Re: “They introduce kernel bugs on purpose”

#142

Researcher(s) shows that it's relatively not hard to introduce bugs in kernel HN: let's hate researcher(s) instead of process Wow. Assume good faith, I guess?

With that logic you can conduct research on how easy it is to rob elderly people in the street, inject poison in supermarket yogurts, etc.

Re: “They introduce kernel bugs on purpose”

#144

From https://lore.kernel.org/linux-nfs/CADVatmNgU7t-Co84tSS6VW=3N... , > A lot of these have already reached the stable trees. If the researchers were trying to prove that it is possible to get malicious patches into the kernel, it seems like they succeeded -- at least for an (insignificant?) period of time.

It may be unethical from an academic perspective, but I like that they did this. It shows there is a problem with the review process if it is not catching 100% of this garbage. Actual malicious actors are certainly already doing worse and maybe succeeding. In a roundabout way, this researcher has achieved their goal, and I hope they publish their results. Certainly more meaningful than most of the drivel in the acade…

I'm not sure what we learned. Were we under the impression that it's impossible to introduce new (security) bugs in Linux?

Re: “They introduce kernel bugs on purpose”

#145
post #98

So many comments here refrain, “They should have asked for consent first”. But would not that be detrimental to the research subject? Specifically, stealthily introducing security vulnerabilities. How should a consent request look to preserve the surprise factor? A university approaches you and says, “Would it be okay for us to submit some patches with vulnerabilities for review, and you try and guess which ones are…

Ethics in research matters. You don't see vaccine researchers shooting up random unconsenting people from the street with latest vaccine prototypes. Researchers have to come up with a reasonable research protocol. Just because the ethical way to do what UMN folks intended to do isn't immediately obvious to you - doesn't mean that it doesn't exist.

Re: “They introduce kernel bugs on purpose”

#146

I guess someone had to do this unethical experiment, but otoh, what is the value here? There's a high chance someone would later find these "intentional bugs" , it's how open source works anyway. They just proved that OSS is not military-grade , but nobody thought so anyway

> They just proved that OSS is not military-grade , but nobody thought so anyway

...and yet FOSS and especially Linux is very widely used in military devices including weapons.

Because it's known to be less insecure than most alternatives.

Re: “They introduce kernel bugs on purpose”

#147
post #22

Later down thread from Greg K-H: > Because of this, I will now have to ban all future contributions from your University. Understandable from gkh, but I feel sorry for any unrelated research happening at University of Minnesota. EDIT: Searching through the source code[1] reveals contributions to the kernel from umn.edu emails in the form of an AppleTalk driver and support for the kernel on PowerPC architectures. In t…

> I think all patches have come from people currently being advised by Kangjie Liu[3] or Liu himself dating back to Dec 2018

New plan: Show up at Liu's house with a lock picking kit while he's away at work, pick the front door and open it, but don't enter. Send him a photo, "hey, just testing, bro! Legitimate security research!"

Re: “They introduce kernel bugs on purpose”

#148
post #79

Is there a more readable version of this available somewhere? I really struggle to follow the unformatted mailing list format.

Just keep hitting the "next" link to follow the thread.

The next link is one hyperlink buried in the middle of the wall of text, and simply appends the new message to the existing one. It also differentiates between prev and parent?

It's super unclear.

Re: “They introduce kernel bugs on purpose”

#149

I guess someone had to do this unethical experiment, but otoh, what is the value here? There's a high chance someone would later find these "intentional bugs" , it's how open source works anyway. They just proved that OSS is not military-grade , but nobody thought so anyway

> but nobody thought so anyway A lot of people claim that there's a lot of eyes on the code and thus introducing vulnerabilities is unlikely. This research clearly has bruised some egos bad.

> A lot of people claim that there's a lot of eyes on the code.

Eric Raymond claimed so, and a lot of people repeated his claim, but I don't think this is the same thing as "a lot of people claim" -- and even if a lot of people claim something that is obviously stupid, it doesn't make the thing less obviously stupid, it just means it's less obvious to some people for some reasons.

Post reply on HN