Live data from Hacker News

“They introduce kernel bugs on purpose”

lore.kernel.org

341–350 of 1001 posts

Re: “They introduce kernel bugs on purpose”

#343
post #286

How is such a ban going to be effective? The "researchers" could easily continue their experiments using different credentials, right?

Arbitrary anonymous submissions don't go into the kernel in general. The point[1] behind the Signed-off-by line is to associate a physical human being with real contact information with the change.

One of the reason this worked is likely that submissions from large US research universities get a "presumptive good faith" pass. A small company in the PRC, for an example, might see more intensive review. But given the history of open source, we trust graduate students maybe more than we should.

[1] Originally legal/copyright driven and not a security feature, though it has value in both domains.

Re: “They introduce kernel bugs on purpose”

#344

Linux maintainers should log a complaint with the University's ethics board. You can't just experiment on people without consent.

I agree. They are attempting to put security vulnerabilities into a security-critical piece of software that is used by billions of people. This is clearly unethical and unacceptable.

Re: “They introduce kernel bugs on purpose”

#346

Very embarrassed to see my alma mater in the news today. I was hoping these were just some grad students going rogue but it even looks like the IRB allowed this 'research' to happen.

It's very likely the IRB was mislead. Don't feel too bad. I saw in one of the comments that the IRB was told that the researchers would be "sending emails," which seems to be an intentionally obtuse phrasing for them submitting malformed kernel patches.

Re: “They introduce kernel bugs on purpose”

#347

They should be reported to the authorities for attempting to introduce security vulnerabilities into software intentionally. This is not ok.

Maybe it was those very authorities who wanted them there. Lot's of things have gotten patched and the backdoors don't work as well as they used to... gotta get clever.

Re: “They introduce kernel bugs on purpose”

#349
@gregkh

These patches look like bombs under bridges to me.

Do you believe that some open source projects should have legal protection against such actors? The Linux Kernel is pretty much a piece of infrastructure that keeps the internet going.

Re: “They introduce kernel bugs on purpose”

#350

This isn't friendly pen-testing in a community, this is an attack on critical infrastructure using a university as cover. The foundation should sue the responsible profs personally and seek criminal prosecution. I remember a bunch of U.S. contractors said they did the same thing to one of the openbsd vpn library projects about 15 years ago as well. What this professor is proving out is that open source and (likely, o…

I am not knowledgeable enough to know if this intent is provable, but if someone can frame the issue appropriately, it feels like it could be good to report this to the FBI tip line so it is at least on their radar.
Post reply on HN