Live data from Hacker News

“They introduce kernel bugs on purpose”

lore.kernel.org

731–740 of 1001 posts

Re: “They introduce kernel bugs on purpose”

#731
Reading this email exchange, I worry about the state of our education system, including computer science departments. Instead of making coherent arguments, this PhD student speaks about "preconceived biases". I loved Greg's response. The spirit of Linus lives within the Kernel! These UMN people should be nowhere near the kernel. I guess they got the answer to their research on what would happen if you keep submitting stealth malicious patches to the kernel: you will get found out and banned. Made my day.

Re: “They introduce kernel bugs on purpose”

#732
What I dont get... why not ask the board of the Linux foundation if they could attempt social engineering attacks and get authorization. If Linux foundation sees value they'd approve it and who knows maybe such tests (hiring pentesters to do social engineering) are done anyway by the Linux foundation.

Re: “They introduce kernel bugs on purpose”

#733

This seems like a pretty scummy way to do "research". I mean I understand that people in academia are becoming increasingly disconnected from the real world, but wow this is low. It's not that they're doing this, I'm sure they're not the first to think of this (for research or malicious reasons), but having the gall to brag about it is a new low.

This observation may very well get downvoted to oblivion: what UMN pulled is the Linux kernel development version of the Sokal Hoax. Both are unethical, disruptive, and prove nothing about the integrity of the organizations they target.

Except for Linux actively running on 99% of all servers on the planet. Vulnerabilities in Linux can literally kill people, open holes for hackers, spies, etc.

Submitting a fake paper to a journal read by a few dozen academics is a threat to someones ego. It is not in the same ballpark as a threat to IT infrastructure everywhere.

Re: “They introduce kernel bugs on purpose”

#735

This seems like a pretty scummy way to do "research". I mean I understand that people in academia are becoming increasingly disconnected from the real world, but wow this is low. It's not that they're doing this, I'm sure they're not the first to think of this (for research or malicious reasons), but having the gall to brag about it is a new low.

Devil's advocate, but why? How is this different from any other white/gray-hat pentest? They tried to submit buggy patches, once approved they immediately let the maintainers know not to merge them. Then they published a paper with their findings and which weak parts in the process they thing are responsible, and which steps they recommend be taken to mitigate this.

You can read the (relatively short) email chains for yourself, but to try and answer your question, as I understood it the problem wasn't entirely the problems submitted in the paper it was followup bad patches and ridiculous defense. Essentially they sent patches that were purportedly the result of static analysis but did nothing, broke social convention by failing to signal that the patch was the result of a tool, and it was deemed indistinguishable from more attempts to send bad code and perform tests on the linux maintainers.

Re: “They introduce kernel bugs on purpose”

#737

This seems like a pretty scummy way to do "research". I mean I understand that people in academia are becoming increasingly disconnected from the real world, but wow this is low. It's not that they're doing this, I'm sure they're not the first to think of this (for research or malicious reasons), but having the gall to brag about it is a new low.

>I mean I understand that people in academia are becoming increasingly disconnected from the real world, but wow this is low. I don't have data to back this up, but I've been around a while and I can tell you papers are rejected from conferences for ethics violations. My personal observation is that infosec/cybersecurity academia has been steadily moving to higher ethical standards in research. That doesn't mean that…

[deleted]

Re: “They introduce kernel bugs on purpose”

#738

I just want you to know that this is extremely unethical to create a paper where you attempt to discredit others by just using your university's reputation to try to create vulnerabilities on purpose. I back your decision and fuck these people. I will additionally be sending a strongly worded email to this person, their advisor and their whoever's in charge of this joke of a computer science school. Sometimes I wish…

Please don't fulminate on HN (see https://news.ycombinator.com/newsguidelines.html). It's not what this site is for, because it leads to considerably worse conversation.

Even if you're justifiably steaming about something, please wait to cool down before posting here.

We detached this subthread from https://news.ycombinator.com/item?id=26889743.

Re: “They introduce kernel bugs on purpose”

#740

Yes, and robbing a bank to show that the security is lax is totally fine because the real criminals don't notify you before they rob a bank. Do you understand how dumb that sounds?

Please review https://news.ycombinator.com/newsguidelines.html and omit name-calling and swipes from your comments here. See also https://news.ycombinator.com/item?id=26893776.

We detached this subthread from https://news.ycombinator.com/item?id=26890035.

Post reply on HN