Live data from Hacker News

“They introduce kernel bugs on purpose”

lore.kernel.org

601–610 of 1001 posts

Re: “They introduce kernel bugs on purpose”

#601

I used to sit on a research ethics board. This absolutely would not have passed such a review. Not a 'revise and resubmit' but a hard pass accompanied with 'what the eff were you thinking?. And, yes, this should have had a REB review: testing the vulnerabilities of a system that includes people is experimenting on human subjects. Doing so without their knowledge absolutely requires a strict human subject review and t…

This is my understanding as well, but then, how such paper was accepted by IEEE ?

Re: “They introduce kernel bugs on purpose”

#602

The tone of Aditya Pakki's message makes me think they would be very well served by reading 'How to Win Friends & Influence People' by Dale Carnegie. This is obviously the complete opposite of how you should be communicating with someone in most situations let alone when you want something from them. I have sure been there though so if anything, take this as a book recommendation for 'How to Win Friends & Influence P…

His email reminds me the way politicians behaves in my country (India): play victim and start dunking.

Re: “They introduce kernel bugs on purpose”

#603

Here's a clarification from the Researchers over at UMN[1]. They claim that none of the Bogus patches were merged to the Stable code line : >Once any maintainer of the community responds to the email,indicating “looks good”,we immediately point out the introduced bug and request them to not go ahead to apply the patch. At the same time, we point out the correct fixing of the bug and provide our proper patch. In all t…

The response makes the researchers seem clueless, arrogant, or both - are they really surprised that kernel maintainers would get pissed off at someone deliberately wasting their time? From the post: * Does this project waste certain efforts of maintainers? Unfortunately, yes. We would like to sincerely apologize to the maintainers involved in the corresponding patch review process; this work indeed wasted their prec…

Indeed! "we could not figure out a better solution in this study".

There IS a better solution: not to proceed with that "study" at all.

Re: “They introduce kernel bugs on purpose”

#604

Here's a clarification from the Researchers over at UMN[1]. They claim that none of the Bogus patches were merged to the Stable code line : >Once any maintainer of the community responds to the email,indicating “looks good”,we immediately point out the introduced bug and request them to not go ahead to apply the patch. At the same time, we point out the correct fixing of the bug and provide our proper patch. In all t…

In the end, the damage has been done and the Linux developers are now going back and removing all patches from any user with a @umn.edu email. Not sure how the researchers didn't see how this would backfire, but it's a hopeless misuse of their time. I feel really bad for the developers who now have to spend their time fixing shit that shouldn't even be there, just because someone wanted to write a paper and their pee…

I feel the same way. People don't understand how it is difficult to be a maintainer. This is very selfish behaviour. Appreciate Greg's strong stance against it.

Re: “They introduce kernel bugs on purpose”

#606

This seems like a pretty scummy way to do "research". I mean I understand that people in academia are becoming increasingly disconnected from the real world, but wow this is low. It's not that they're doing this, I'm sure they're not the first to think of this (for research or malicious reasons), but having the gall to brag about it is a new low.

[deleted]

Re: “They introduce kernel bugs on purpose”

#607
post #435
post #342

> I will not be sending any more patches due to the attitude that is not only unwelcome but also intimidating to newbies and non experts. Maybe not being nice is part of the immune system of open source.

Honestly WTF would a "newbie and non-expert" have to do with sending KERNEL PATCHES.

Personally I don't think you can become an expert in Linux kernel programming without sending patches. So over the long term, if you don't let non-experts submit patches then no new experts will ever be created, the existing ones will die or move on, and there won't be any experts at all. At that point the project will die.

Re: “They introduce kernel bugs on purpose”

#609
Here’s a (perhaps naively) optimistic take: by publishing this research and showing it to lawmakers and industry leaders, it will sound alarms on a serious vulnerability in what is critical infrastructure for much of the tech industry and public sector. This could then lead to investment in mitigations for the vulnerability, e.g. directly funding work to proactively improve security issues in the kernel.

Re: “They introduce kernel bugs on purpose”

#610

Research without ethics is research without value. Unbelievable that this could have passed ethics review, so I'd bet it was never reviewed. Big black eye for University of Minnesota. Imagine if you are another doctoral student is CS/EE and this tool has ruined your ability to participate in Linux.

Some CS labs at UMN take ethics very seriously. Their UXR lab for example.

Other CS labs at UMN, well... apparently not so much.

Post reply on HN