“They introduce kernel bugs on purpose”
731–740 of 1001 posts
Re: “They introduce kernel bugs on purpose”
#732Re: “They introduce kernel bugs on purpose”
#733This seems like a pretty scummy way to do "research". I mean I understand that people in academia are becoming increasingly disconnected from the real world, but wow this is low. It's not that they're doing this, I'm sure they're not the first to think of this (for research or malicious reasons), but having the gall to brag about it is a new low.
This observation may very well get downvoted to oblivion: what UMN pulled is the Linux kernel development version of the Sokal Hoax. Both are unethical, disruptive, and prove nothing about the integrity of the organizations they target.
Submitting a fake paper to a journal read by a few dozen academics is a threat to someones ego. It is not in the same ballpark as a threat to IT infrastructure everywhere.
Re: “They introduce kernel bugs on purpose”
#734Re: “They introduce kernel bugs on purpose”
#735This seems like a pretty scummy way to do "research". I mean I understand that people in academia are becoming increasingly disconnected from the real world, but wow this is low. It's not that they're doing this, I'm sure they're not the first to think of this (for research or malicious reasons), but having the gall to brag about it is a new low.
Devil's advocate, but why? How is this different from any other white/gray-hat pentest? They tried to submit buggy patches, once approved they immediately let the maintainers know not to merge them. Then they published a paper with their findings and which weak parts in the process they thing are responsible, and which steps they recommend be taken to mitigate this.
Re: “They introduce kernel bugs on purpose”
#736Re: “They introduce kernel bugs on purpose”
#737This seems like a pretty scummy way to do "research". I mean I understand that people in academia are becoming increasingly disconnected from the real world, but wow this is low. It's not that they're doing this, I'm sure they're not the first to think of this (for research or malicious reasons), but having the gall to brag about it is a new low.
>I mean I understand that people in academia are becoming increasingly disconnected from the real world, but wow this is low. I don't have data to back this up, but I've been around a while and I can tell you papers are rejected from conferences for ethics violations. My personal observation is that infosec/cybersecurity academia has been steadily moving to higher ethical standards in research. That doesn't mean that…
Re: “They introduce kernel bugs on purpose”
#738I just want you to know that this is extremely unethical to create a paper where you attempt to discredit others by just using your university's reputation to try to create vulnerabilities on purpose. I back your decision and fuck these people. I will additionally be sending a strongly worded email to this person, their advisor and their whoever's in charge of this joke of a computer science school. Sometimes I wish…
Even if you're justifiably steaming about something, please wait to cool down before posting here.
We detached this subthread from https://news.ycombinator.com/item?id=26889743.
Re: “They introduce kernel bugs on purpose”
#739Re: “They introduce kernel bugs on purpose”
#740Yes, and robbing a bank to show that the security is lax is totally fine because the real criminals don't notify you before they rob a bank. Do you understand how dumb that sounds?
We detached this subthread from https://news.ycombinator.com/item?id=26890035.