Imagine, saying we would like to test how fire department responds to fire, by setting buildings on fire in NYC.
“They introduce kernel bugs on purpose”
341–350 of 1001 posts
Re: “They introduce kernel bugs on purpose”
#342Maybe not being nice is part of the immune system of open source.
Re: “They introduce kernel bugs on purpose”
#343How is such a ban going to be effective? The "researchers" could easily continue their experiments using different credentials, right?
One of the reason this worked is likely that submissions from large US research universities get a "presumptive good faith" pass. A small company in the PRC, for an example, might see more intensive review. But given the history of open source, we trust graduate students maybe more than we should.
[1] Originally legal/copyright driven and not a security feature, though it has value in both domains.
Re: “They introduce kernel bugs on purpose”
#344Linux maintainers should log a complaint with the University's ethics board. You can't just experiment on people without consent.
Re: “They introduce kernel bugs on purpose”
#345Linux maintainers should log a complaint with the University's ethics board. You can't just experiment on people without consent.
Re: “They introduce kernel bugs on purpose”
#346Very embarrassed to see my alma mater in the news today. I was hoping these were just some grad students going rogue but it even looks like the IRB allowed this 'research' to happen.
Re: “They introduce kernel bugs on purpose”
#347They should be reported to the authorities for attempting to introduce security vulnerabilities into software intentionally. This is not ok.
Re: “They introduce kernel bugs on purpose”
#348Re: “They introduce kernel bugs on purpose”
#349These patches look like bombs under bridges to me.
Do you believe that some open source projects should have legal protection against such actors? The Linux Kernel is pretty much a piece of infrastructure that keeps the internet going.
Re: “They introduce kernel bugs on purpose”
#350This isn't friendly pen-testing in a community, this is an attack on critical infrastructure using a university as cover. The foundation should sue the responsible profs personally and seek criminal prosecution. I remember a bunch of U.S. contractors said they did the same thing to one of the openbsd vpn library projects about 15 years ago as well. What this professor is proving out is that open source and (likely, o…