Live data from Hacker News

UMN CS&E Statement on Linux Kernel Research

cse.umn.edu

51–60 of 332 posts

Re: UMN CS&E Statement on Linux Kernel Research

#51
post #9

I found these statements by the associate department head interesting: https://twitter.com/lorenterveen/status/1384955467051454466 > I do work in Social Computing, and this situation is directly analogous to a number of incidents on Wikipedia quite awhile ago that led to that community and researchers reaching an understanding on research methods that are and are not acceptable. and https://twitter.com/lorenterveen/s…

Terveen was always honest about what works and what doesn't work. Its good to see them acknowledge that this is something they need to dive into and fix.

Re: UMN CS&E Statement on Linux Kernel Research

#52
post #14
post #2

This is a great statement, they confirm they're aware of the issue, they acknowledge the concerns and they set out their intention to gather the full facts whilst suspending the operation of the research in the meantime. They also acknowledge the systematic way the need to deal with this. I hope their follow up is as thorough but I want to applaud this, it's a good approach.

There was one thing that I found to be lacking from their statement. They never said that what they had done was wrong. The university already knows what the researchers did and are aware of the paper that was written about the subject by those same researchers. [1] [1] On the Feasibility of Stealthily Introducing Vulnerabilities in Open-Source Software via Hypocrite Commits -- https://github.com/QiushiWu/QiushiWu.gi…

This is what innocent until proven guilty looks like. I, for one, agree with the approach. I don't want to live in a world where people are fired and projects shutdown on the basis of allegations alone.

Re: UMN CS&E Statement on Linux Kernel Research

#53
post #42

Earlier quoted context omitted.

I would argue that first requires investigation. They probably just have a bunch of angry emails to go on at this point and haven’t looked in detail at anything else.

> I would argue that first requires investigation. Why do you think that enough of an investigation hasn't been performed in order to understand culpability? Thay already know what happened and want to learn why it was approved. That was what their comment said. Take a look at the actual PDF from the researchers , "On the Feasibility of Stealthily Introducing Vulnerabilities in Open-Source Software via Hypocrite Comm…

The prof overseeing the paper clarified that they initially did not seek IRB approval, and then received an IRB exemption [0]. I'd want to ask the IRB why they approved that, for starters. Maybe because they'd already done the research and hoped it would blow over, vs. the controversy of rejecting it when they'd already done the work?

0: https://www-users.cs.umn.edu/~kjlu/papers/clarifications-hc....

Re: UMN CS&E Statement on Linux Kernel Research

#54
Interesting, looks like the 2nd time they're doing the same thing, and 2nd time they're in hot water for it. They even apologized the first time by pleading naivete: https://www-users.cs.umn.edu/~kjlu/papers/clarifications-hc.... .

First time they initially skipped IRB review for sending malicious patches to the mailing list, which people do install. (So IRB exemption should not apply.) A top security conference allowed a paper with a broken IRB process, and UMN IRB, when a later IRB exempt request was filed, explicitly allowed this. Bad, bad, and bad.

The latest Linux incident seems like a repeat by the same CS dept, advisor, student, & presumably, UMN IRB. No naivete excuse anymore, this is now business as usual.

The bigger fail to me is the UMN dept head + IRB, and the security conference review process around IRB norms. Especially damning that it's a repeat of the same IRB mess. IRB exemption matters a lot for practicing scientists, and leadership tolerating this stuff is what will get it taken away for everyone else.

Fool me once..

Re: UMN CS&E Statement on Linux Kernel Research

#55
post #4

It was a good idea to ban the uni entirely, cause that way they had to respond.

Anyone saying that it was a bad idea to ban the entire University isn't looking at the big picture. I look at it from a very philosophical standpoint: The entire idea of an academic (research) institution can be summarized as "an entity representing a group of trusted people who act in good faith of that institution". The moment one of your researchers acts in bad faith, or shows that they cannot be trusted, it's cle…

Yup, it had to be dealt with on an org level, not only the offending person/group.

Although it isn't the medical profession, the same directive should apply to research:

"First, do no harm."

This deliberate poisoning of OS projects without prior permission to 'test the security' violated that big time.

I'm astonished it got past any ethics review, indicating to me that there likely was none.

Re: UMN CS&E Statement on Linux Kernel Research

#56

Eh, I work at a uni. This came from a dept head. The university is taking it seriously?? Doubt it. Now, when a Dean puts up a webpage... things just got serious.

I wonder if there’s anyone higher up in the administration even aware this is happening.

Re: UMN CS&E Statement on Linux Kernel Research

#57
post #26
post #13

This kind of research is interesting and important but should not be done by a computer science department, any more than the social science department should try to develop a process control system.

Which department should do it?

Sociology or anthropology. Possibly, though less so, political science, economics, or even a B school. These are all disciplines that study the social behavior of groups.

As as study of a group activity it seems inapplicable to a psychology department, though that could be a bias on my part.

Re: UMN CS&E Statement on Linux Kernel Research

#58
post #38

Earlier quoted context omitted.

It's still #3 on the front page: https://news.ycombinator.com/item?id=26887670 (and other iterations on the same story earlier today).

Ah thanks. How moronic, whomever thought this was in any way a good idea is pretty out of touch with reality.

isn't it just a form of red teaming? has red teaming fallen out of fashion?

Re: UMN CS&E Statement on Linux Kernel Research

#59
post #30

I guess the question I have is "Did any *previous* research done by UMN successfully introduce bugs into the Linux Kernel git commit log?" There are weasel words in this statement that make it unclear and the researchers have been really dishonest already. But! If it's true that their research has never made it out of email chains then it does seem like the reaction is a bit disproportionate to the damages here.

Much focus is on the 3 patches from the paper last year, but others have been submitted before and since by the same group, and some that have been found to be malicious did make it into the Stable branch: https://lore.kernel.org/lkml/78ac6ee8-8e7c-bd4c-a3a7-5a90c7c...

Re: UMN CS&E Statement on Linux Kernel Research

#60
post #58

Earlier quoted context omitted.

Ah thanks. How moronic, whomever thought this was in any way a good idea is pretty out of touch with reality.

isn't it just a form of red teaming? has red teaming fallen out of fashion?

red teaming without approval of the target org is out of fashion, yes.
Post reply on HN