I found these statements by the associate department head interesting: https://twitter.com/lorenterveen/status/1384955467051454466 > I do work in Social Computing, and this situation is directly analogous to a number of incidents on Wikipedia quite awhile ago that led to that community and researchers reaching an understanding on research methods that are and are not acceptable. and https://twitter.com/lorenterveen/s…
UMN CS&E Statement on Linux Kernel Research
51–60 of 332 posts
Re: UMN CS&E Statement on Linux Kernel Research
#52This is a great statement, they confirm they're aware of the issue, they acknowledge the concerns and they set out their intention to gather the full facts whilst suspending the operation of the research in the meantime. They also acknowledge the systematic way the need to deal with this. I hope their follow up is as thorough but I want to applaud this, it's a good approach.
There was one thing that I found to be lacking from their statement. They never said that what they had done was wrong. The university already knows what the researchers did and are aware of the paper that was written about the subject by those same researchers. [1] [1] On the Feasibility of Stealthily Introducing Vulnerabilities in Open-Source Software via Hypocrite Commits -- https://github.com/QiushiWu/QiushiWu.gi…
Re: UMN CS&E Statement on Linux Kernel Research
#53Earlier quoted context omitted.
I would argue that first requires investigation. They probably just have a bunch of angry emails to go on at this point and haven’t looked in detail at anything else.
> I would argue that first requires investigation. Why do you think that enough of an investigation hasn't been performed in order to understand culpability? Thay already know what happened and want to learn why it was approved. That was what their comment said. Take a look at the actual PDF from the researchers , "On the Feasibility of Stealthily Introducing Vulnerabilities in Open-Source Software via Hypocrite Comm…
0: https://www-users.cs.umn.edu/~kjlu/papers/clarifications-hc....
Re: UMN CS&E Statement on Linux Kernel Research
#54First time they initially skipped IRB review for sending malicious patches to the mailing list, which people do install. (So IRB exemption should not apply.) A top security conference allowed a paper with a broken IRB process, and UMN IRB, when a later IRB exempt request was filed, explicitly allowed this. Bad, bad, and bad.
The latest Linux incident seems like a repeat by the same CS dept, advisor, student, & presumably, UMN IRB. No naivete excuse anymore, this is now business as usual.
The bigger fail to me is the UMN dept head + IRB, and the security conference review process around IRB norms. Especially damning that it's a repeat of the same IRB mess. IRB exemption matters a lot for practicing scientists, and leadership tolerating this stuff is what will get it taken away for everyone else.
Fool me once..
Re: UMN CS&E Statement on Linux Kernel Research
#55It was a good idea to ban the uni entirely, cause that way they had to respond.
Anyone saying that it was a bad idea to ban the entire University isn't looking at the big picture. I look at it from a very philosophical standpoint: The entire idea of an academic (research) institution can be summarized as "an entity representing a group of trusted people who act in good faith of that institution". The moment one of your researchers acts in bad faith, or shows that they cannot be trusted, it's cle…
Although it isn't the medical profession, the same directive should apply to research:
"First, do no harm."
This deliberate poisoning of OS projects without prior permission to 'test the security' violated that big time.
I'm astonished it got past any ethics review, indicating to me that there likely was none.
Re: UMN CS&E Statement on Linux Kernel Research
#56Eh, I work at a uni. This came from a dept head. The university is taking it seriously?? Doubt it. Now, when a Dean puts up a webpage... things just got serious.
Re: UMN CS&E Statement on Linux Kernel Research
#57This kind of research is interesting and important but should not be done by a computer science department, any more than the social science department should try to develop a process control system.
Which department should do it?
As as study of a group activity it seems inapplicable to a psychology department, though that could be a bias on my part.
Re: UMN CS&E Statement on Linux Kernel Research
#58Earlier quoted context omitted.
It's still #3 on the front page: https://news.ycombinator.com/item?id=26887670 (and other iterations on the same story earlier today).
Ah thanks. How moronic, whomever thought this was in any way a good idea is pretty out of touch with reality.
Re: UMN CS&E Statement on Linux Kernel Research
#59I guess the question I have is "Did any *previous* research done by UMN successfully introduce bugs into the Linux Kernel git commit log?" There are weasel words in this statement that make it unclear and the researchers have been really dishonest already. But! If it's true that their research has never made it out of email chains then it does seem like the reaction is a bit disproportionate to the damages here.
Re: UMN CS&E Statement on Linux Kernel Research
#60Earlier quoted context omitted.
Ah thanks. How moronic, whomever thought this was in any way a good idea is pretty out of touch with reality.
isn't it just a form of red teaming? has red teaming fallen out of fashion?