Live data from Hacker News

“They introduce kernel bugs on purpose”

lore.kernel.org

281–290 of 1001 posts

Re: “They introduce kernel bugs on purpose”

#281
post #16

The problem here is really that they’re wasting time of the maintainers without their approval. Any ethics board would require prior consent to this. It wouldn’t even be hard to do.

1) They identified vulnerabilities with a process 2) They contributed the correct code after showing the maintainer the security vulnerability they missed. 3) Getting the consent of the people behind the process would invalidate the results.

You're right, and it is depressing how negative the reaction has been here. This work is the technical equivalent of "Sokalling", and it is a good and necessary thing.

The thing that people should be upset about is that such an important open source project so easily accepts patches which introduce security vulnerabilities. Forget the researchers for a moment - if it is this easy, you can be certain that malicious actors are also doing it. The only difference is that they are not then disclosing that they have done so!

The Linux maintainers should be grateful that researchers are doing this, and researchers should be doing it to every significant open source project.

Re: “They introduce kernel bugs on purpose”

#282

From https://lore.kernel.org/linux-nfs/CADVatmNgU7t-Co84tSS6VW=3N... , > A lot of these have already reached the stable trees. If the researchers were trying to prove that it is possible to get malicious patches into the kernel, it seems like they succeeded -- at least for an (insignificant?) period of time.

I tangentially followed the debacle unfold for a while and this particular thread now has lead to heated debates on some IRC channels I'm on. While it is maybe "scientifically interesting", intentionally introducing bugs into Linux that could potentially make it into production systems while work on this paper is going on, could IMO be described as utterly reckless at best . Two messages down in the same thread, it m…

I assume that having these go into production could make the authors "hackers" according to law, no?

Haven't whitehat hackers doing unsolicited pen-testing been prosecuted in the past?

Re: “They introduce kernel bugs on purpose”

#283

The professor gets exactly what they want here, no? "We experimented on the linux kernel team to see what would happen. Our non-double-blind test of 1 FOSS maintenance group has produced the following result: We get banned and our entire university gets dragged through the muck 100% of the time". That'll be a fun paper to write, no doubt. Additional context: * One of the committers of these faulty patches, Aditya Pak…

Isn't this reaction a bit like the emperor banishing anyone who tells him that his new clothes are fake? Are the maintainers upset that someone showed how easy it is to subvert kernel security?

More like the emperor banishing anyone who tries to sell him fake clothes to prove that the emperor will buy fake clothes.

Re: “They introduce kernel bugs on purpose”

#285
post #118

Does the University of Minnesota have an ethical review board or research ethics board? They need to be contacted ASAP.

Apparently, they were and did not care.

It's possible that they didn't knew what they were doing ( approving of this project) -- not sure if this is better or worse.
Post reply on HN