Live data from Hacker News

“They introduce kernel bugs on purpose”

lore.kernel.org

301–310 of 1001 posts

Re: “They introduce kernel bugs on purpose”

#301

I just want you to know that this is extremely unethical to create a paper where you attempt to discredit others by just using your university's reputation to try to create vulnerabilities on purpose. I back your decision and fuck these people. I will additionally be sending a strongly worded email to this person, their advisor and their whoever's in charge of this joke of a computer science school. Sometimes I wish…

I completely disagree with this framing.

A real malicious actor is going to be planted in some reputable institution, creating errors that look like honest mistakes.

How do you test if the process catches such vulnerabilities? You do it the just the way that these researchers did.

Yes, it creates extra homework for some people with certain responsibilities, that doesn't mean it's unethical. Don't shoot the messenger.

Re: “They introduce kernel bugs on purpose”

#302

I just want you to know that this is extremely unethical to create a paper where you attempt to discredit others by just using your university's reputation to try to create vulnerabilities on purpose. I back your decision and fuck these people. I will additionally be sending a strongly worded email to this person, their advisor and their whoever's in charge of this joke of a computer science school. Sometimes I wish…

[deleted]

Re: “They introduce kernel bugs on purpose”

#303

Yes, and robbing a bank to show that the security is lax is totally fine because the real criminals don't notify you before they rob a bank. Do you understand how dumb that sounds?

> Do you understand how dumb that sounds?

If you make a dumb analogy, that's on you.

Re: “They introduce kernel bugs on purpose”

#305

I just want you to know that this is extremely unethical to create a paper where you attempt to discredit others by just using your university's reputation to try to create vulnerabilities on purpose. I back your decision and fuck these people. I will additionally be sending a strongly worded email to this person, their advisor and their whoever's in charge of this joke of a computer science school. Sometimes I wish…

I completely disagree with this framing. A real malicious actor is going to be planted in some reputable institution, creating errors that look like honest mistakes. How do you test if the process catches such vulnerabilities? You do it the just the way that these researchers did. Yes, it creates extra homework for some people with certain responsibilities, that doesn't mean it's unethical. Don't shoot the messenger.

These are real malicious actors.

Re: “They introduce kernel bugs on purpose”

#306
post #171
post #22

Later down thread from Greg K-H: > Because of this, I will now have to ban all future contributions from your University. Understandable from gkh, but I feel sorry for any unrelated research happening at University of Minnesota. EDIT: Searching through the source code[1] reveals contributions to the kernel from umn.edu emails in the form of an AppleTalk driver and support for the kernel on PowerPC architectures. In t…

Seems like a bit of a strong response. Universities are large places with lots of professors and people with different ideas, opinions, views, and they don't work in concert, quite the opposite. They're not some corporation with some unified goal or incentives. I like that. That's what makes universities interesting to me. I don't like the standard here of of penalizing or lumping everyone there together, regardless…

I'd concur: the university is the wrong unit-of-ban.

For example: what happens when the students graduate- does the ban follow them to any potential employers? Or if the professor leaves for another university to continue this research?

Does the ban stay with UMN, even after everyone involved left? Or does it follow the researcher(s) to a new university, even if the new employer had no responsibility for them?

Re: “They introduce kernel bugs on purpose”

#307

Yes, and robbing a bank to show that the security is lax is totally fine because the real criminals don't notify you before they rob a bank. Do you understand how dumb that sounds?

> Do you understand how dumb that sounds? If you make a dumb analogy, that's on you.

Same analogy... there's a vulnerability and you want to test it? Go set up a test, and notify the people.

You really think the Linux kernel guys would change their process if you did this? They'd still do the same things they do.

Re: “They introduce kernel bugs on purpose”

#308
post #286

How is such a ban going to be effective? The "researchers" could easily continue their experiments using different credentials, right?

I believe this is so that the university treats the reports seriously. It's basically a "shit's broken, fix it". The researchers are probably under a lot of pressure from the rest of the university right now.

Re: “They introduce kernel bugs on purpose”

#309

Earlier quoted context omitted.

> The thread then gets down to business and starts coordinating revert patches for everything committed by University of Minnesota email addresses. What's preventing those bad actors from not using a UMN email address?

If they submit them from personal or anonymous email the patches may have come under more sucutiny. They gain some trust comming from university email addresses

Exactly. Users contributing from the University addresses were borrowing against the reputation of the institution. That reputation is now destroyed and each individual contributor must build their own reputation to earn trust.
Post reply on HN