Live data from Hacker News

UMN CS&E Statement on Linux Kernel Research

cse.umn.edu

81–90 of 332 posts

Re: UMN CS&E Statement on Linux Kernel Research

#81
post #2

This is a great statement, they confirm they're aware of the issue, they acknowledge the concerns and they set out their intention to gather the full facts whilst suspending the operation of the research in the meantime. They also acknowledge the systematic way the need to deal with this. I hope their follow up is as thorough but I want to applaud this, it's a good approach.

If they really care about being banned, they'll have no choice but to follow thorough

I’ve read and re-read that statement, and it seems like the ban is the focus – not what led to the ban.

I get that they may not know anything, but there are other ways to word that without admitting liability, making it seem less like the focus is on the ban and more on the allegedly shady stuff.

Re: UMN CS&E Statement on Linux Kernel Research

#82

The title here should probably be "UMN CSE Department Statement..." rather than merely "UMN Statement ..." since it's coming from the department head and associate department head, not from the university as a whole. cc/ dang

Sorry for getting sidetracked, but does cc has any special function here or you are hoping that dang would read all the comments and see your cc?

I think dang might have something in place which alerts him when he is mentioned. Certainly he tends to show up quickly when people "page" him like this.

Re: UMN CS&E Statement on Linux Kernel Research

#83
post #15
post #9

I found these statements by the associate department head interesting: https://twitter.com/lorenterveen/status/1384955467051454466 > I do work in Social Computing, and this situation is directly analogous to a number of incidents on Wikipedia quite awhile ago that led to that community and researchers reaching an understanding on research methods that are and are not acceptable. and https://twitter.com/lorenterveen/s…

That whole twitter thread is really interesting, starting from https://twitter.com/lorenterveen/status/1384954220705722369

Yeah, it gets even worse:

https://twitter.com/SarahJamieLewis/status/13848713855379087...

Re: UMN CS&E Statement on Linux Kernel Research

#84
post #2

This is a great statement, they confirm they're aware of the issue, they acknowledge the concerns and they set out their intention to gather the full facts whilst suspending the operation of the research in the meantime. They also acknowledge the systematic way the need to deal with this. I hope their follow up is as thorough but I want to applaud this, it's a good approach.

They also didn't just throw the group under the bus and try and wash their hands clean - good move.

Re: UMN CS&E Statement on Linux Kernel Research

#85
post #78

I do some maintenance work for the linux kernel dvb and infrared subsystems. I reviewed and accepted some patches from umn.edu addresses. They looked fine to me, however they're all around error handling, which can get pretty tricky with long error paths. What else can I do than revert the lot?

gregkh sent a 190 patch series to revert all of the "easy" UMN reverts, pending review. People are now looking at the patches and saying things like, "that's one OK, don't revert". There are another 68 commits which did not revert cleanly, in some cases because they were later fixed up, already reverted, or some other patch has touched those lines of code. This will require further manual work. We basically at this p…

What a mess, that could be hundreds of hours of work …

Re: UMN CS&E Statement on Linux Kernel Research

#87
post #70
post #52

Earlier quoted context omitted.

This is what innocent until proven guilty looks like. I, for one, agree with the approach. I don't want to live in a world where people are fired and projects shutdown on the basis of allegations alone.

Don't jump to conclusions, and say I am guilty of something that I didn't write. I never said to fire people and shutdown projects based upon allegations alone. You may not have read the article for this comment page, but they admit that the action took place. The researchers, themselves, elsewhere admitted it took place.

Pardon me. I did not mean to imply you were calling for anything. And I agree, the facts look pretty damning. Nevertheless, I fully support a slow, deliberate, and comprehensive evaluation by any authority when evaluating serious accusations. Further, I strongly believe in presumptive innocence, regardless of initial impressions.

Btw, I'm not suggesting you don't believe in any of the above.

Re: UMN CS&E Statement on Linux Kernel Research

#88
The other reason this is a hotbutton issue is because it is related to the general problem of abusing the universities as a protected platform for general subversion for its own sake.

It's not innovation or research, or even progress, it's actively destabilizing and subverting a targetted community that a huge part (even majority) of the economy depends on the integrity of. This is a hawkish view, but in a challenging cultural moment, their activities are very difficult to be charitable about.

Re: UMN CS&E Statement on Linux Kernel Research

#89
post #30

I guess the question I have is "Did any *previous* research done by UMN successfully introduce bugs into the Linux Kernel git commit log?" There are weasel words in this statement that make it unclear and the researchers have been really dishonest already. But! If it's true that their research has never made it out of email chains then it does seem like the reaction is a bit disproportionate to the damages here.

Lu has posted to LKML today, weasel wording around when asked point blank for a list of everything malicious sent to the kernel.

https://lore.kernel.org/lkml/YIBMKSovJumS79SR@pendragon.idea...

e: Not getting pulled into a maintainer tree isn't enough to be safe about what was posted to a kernel mailing list. People can (and testing scripts blindly do) grab and apply patches on the mailing list.

Re: UMN CS&E Statement on Linux Kernel Research

#90

Interesting, looks like the 2nd time they're doing the same thing, and 2nd time they're in hot water for it. They even apologized the first time by pleading naivete: https://www-users.cs.umn.edu/~kjlu/papers/clarifications-hc.... . First time they initially skipped IRB review for sending malicious patches to the mailing list, which people do install. (So IRB exemption should not apply.) A top security conference allo…

> looks like the 2nd time they're doing the same thing

It's not clear that they're doing the same thing--we don't know that these recent patches are deliberately bogus. See this comment with clarifications from the other post: https://news.ycombinator.com/item?id=26890583

Post reply on HN