Live data from Hacker News

“They introduce kernel bugs on purpose”

lore.kernel.org

321–330 of 1001 posts

Re: “They introduce kernel bugs on purpose”

#321
This is supremely fucked up and I’d say is borderline criminal. It’s really lucky asshole researchers like this haven’t caused a bug that cost billions of dollars, or killed someone, because eventually shit like this will... and holy shit will “it was just research” do nothing to save them.

Re: “They introduce kernel bugs on purpose”

#323

I just want you to know that this is extremely unethical to create a paper where you attempt to discredit others by just using your university's reputation to try to create vulnerabilities on purpose. I back your decision and fuck these people. I will additionally be sending a strongly worded email to this person, their advisor and their whoever's in charge of this joke of a computer science school. Sometimes I wish…

I completely disagree with this framing. A real malicious actor is going to be planted in some reputable institution, creating errors that look like honest mistakes. How do you test if the process catches such vulnerabilities? You do it the just the way that these researchers did. Yes, it creates extra homework for some people with certain responsibilities, that doesn't mean it's unethical. Don't shoot the messenger.

This would absolutely be true if this were an authorised penetration test, however it was unauthorised and therefore unethical.

Re: “They introduce kernel bugs on purpose”

#324
post #286

How is such a ban going to be effective? The "researchers" could easily continue their experiments using different credentials, right?

If you're a young hacker that wants to get into kernel development as a career, are you going to consider going to a university that has been banned from officially participating in development for arguably the most prolific kernel?

The next batch of "researchers" won't be attending the University of Minnesota, and other universities scared of the same fate (missing out on tuition money) will preemptively ban such research themselves.

"Effective" isn't binary, and this is a move in the right direction.

Re: “They introduce kernel bugs on purpose”

#325

Linux maintainers should log a complaint with the University's ethics board. You can't just experiment on people without consent.

I'm not sure it is experimenting people without consent. Though it's certainly shitty and opportunitstic of UoM to do this.

Linux Bug fixes are open to the public. The experiment isn't on people but on bugs. I would be like filing different customer support complaints to change the behavior of a company -- you're not experimenting on people but the process of how that company interfaces with the public.

I see no wrong here including the Linux maintainers banning submissions from UoM which is completely justified as time wasting.

Re: “They introduce kernel bugs on purpose”

#326
post #286

How is such a ban going to be effective? The "researchers" could easily continue their experiments using different credentials, right?

> How is such a ban going to be effective? It trashes University of Minnesota in the press. What is going to happen is that the president of the university now is going to hear about it, so will the provost and so will people in charge of doling money. That will rapidly fix the professor problem. While people may think that tenure professors get to do what they want, they never win in a war with a president and a pro…

The professor's site says that he is an assistant professor, i.e., he doesn't actually have tenure yet.

Re: “They introduce kernel bugs on purpose”

#329
post #280

I wish the title were clearer. Linux bans University of Minnesota for sending buggy patches on purpose .

The term of art for an intentional bug that deliberately introduces a security flaw is a "trojan" (from "Trojan Horse", of course). UMN trojaned the kernel. This is indeed just wildly irresponsible.

Re: “They introduce kernel bugs on purpose”

#330
post #325

Linux maintainers should log a complaint with the University's ethics board. You can't just experiment on people without consent.

I'm not sure it is experimenting people without consent. Though it's certainly shitty and opportunitstic of UoM to do this. Linux Bug fixes are open to the public. The experiment isn't on people but on bugs. I would be like filing different customer support complaints to change the behavior of a company -- you're not experimenting on people but the process of how that company interfaces with the public. I see no wron…

It's experimenting with how specific people manage bugs.
Post reply on HN