Earlier quoted context omitted.
> I would argue that first requires investigation. Why do you think that enough of an investigation hasn't been performed in order to understand culpability? Thay already know what happened and want to learn why it was approved. That was what their comment said. Take a look at the actual PDF from the researchers , "On the Feasibility of Stealthily Introducing Vulnerabilities in Open-Source Software via Hypocrite Comm…
The prof overseeing the paper clarified that they initially did not seek IRB approval, and then received an IRB exemption [0]. I'd want to ask the IRB why they approved that, for starters. Maybe because they'd already done the research and hoped it would blow over, vs. the controversy of rejecting it when they'd already done the work? 0: https://www-users.cs.umn.edu/~kjlu/papers/clarifications-hc....
UMN CS&E Statement on Linux Kernel Research
91–100 of 332 posts
Re: UMN CS&E Statement on Linux Kernel Research
#92Earlier quoted context omitted.
There was one thing that I found to be lacking from their statement. They never said that what they had done was wrong. The university already knows what the researchers did and are aware of the paper that was written about the subject by those same researchers. [1] [1] On the Feasibility of Stealthily Introducing Vulnerabilities in Open-Source Software via Hypocrite Commits -- https://github.com/QiushiWu/QiushiWu.gi…
The department heads just learn of what is happening. They cannot say "we didn't do anything wrong!!!" without investigation because it will make the university in a very negative light (it is a serious ramifications). They need to get all the facts and knowing how it happens and who is responsible for this. So this way they can make a concise action and they will make a proper statement. They are taking "investigati…
Re: UMN CS&E Statement on Linux Kernel Research
#93Earlier quoted context omitted.
red teaming without approval of the target org is out of fashion, yes.
that helps a bit with regards to understanding why people are so upset about this. but honestly, it seems like valuable research to me. it's unfortunate that it took some time away from busy kernel developers, and it's unfortunate that it ultimately makes the project look worse... ...but isn't that supposed to be part of the promise behind open source? it wouldn't surprise me if i learned that management of private o…
You'd very likely would have been able to get code past them even if you told them that there are attempts coming and got their approval.
Given that, you need a good justification why that wasn't enough for you, and what value you truly added over what already was the common view on the issue. But at least we got valuable recommendations from their paper, like "there should be a code of conduct forbidding malicious submissions" and "you could try vetting peoples real identities". (I guess they added to the last bit, giving additional data points that "works at a respected institution in a related field" is not sufficient to establish trust)
Re: UMN CS&E Statement on Linux Kernel Research
#94Earlier quoted context omitted.
If they really care about being banned, they'll have no choice but to follow thorough
I’ve read and re-read that statement, and it seems like the ban is the focus – not what led to the ban. I get that they may not know anything, but there are other ways to word that without admitting liability, making it seem less like the focus is on the ban and more on the allegedly shady stuff.
This seems like an entirely appropriate balance of text and emphasis for a statement that is short and to the point. Which is also appropriate and laudable. Typically when an organization says any more, it's to try and do some spin doctoring.
Re: UMN CS&E Statement on Linux Kernel Research
#95Re: UMN CS&E Statement on Linux Kernel Research
#96Earlier quoted context omitted.
The prof overseeing the paper clarified that they initially did not seek IRB approval, and then received an IRB exemption [0]. I'd want to ask the IRB why they approved that, for starters. Maybe because they'd already done the research and hoped it would blow over, vs. the controversy of rejecting it when they'd already done the work? 0: https://www-users.cs.umn.edu/~kjlu/papers/clarifications-hc....
Yes, but that doesn't have bearing on my comment that was being referenced, that they didn't say what had happened was wrong. Here is Ken Thompson's apropos paper from 1984. [0] [0] https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_Ref...
> Why do you think that enough of an investigation hasn't been performed in order to understand culpability?
Re: UMN CS&E Statement on Linux Kernel Research
#97This is purely a damage mitigation strategy. If we give them more credit than they really deserve, the department and IRB were severely negligent.
Re: UMN CS&E Statement on Linux Kernel Research
#98Earlier quoted context omitted.
If they really care about being banned, they'll have no choice but to follow thorough
I’ve read and re-read that statement, and it seems like the ban is the focus – not what led to the ban. I get that they may not know anything, but there are other ways to word that without admitting liability, making it seem less like the focus is on the ban and more on the allegedly shady stuff.
Not once do they talk about getting the ban removed, instead they talk about figuring out why it happened and how to be better at having research done being ethical.
Was the ban the trigger to them (the heads) looking into it ? Of course since they do already have safeguards and review processes in place, this happened despite those, so they're saying they will investigate them to figure out how this project was validated and make sure to strengthen these processes as needed.
The end goal they give themselves in that message is not a ban removal but "safeguard against future [such] issues".
Re: UMN CS&E Statement on Linux Kernel Research
#99This is a great statement, they confirm they're aware of the issue, they acknowledge the concerns and they set out their intention to gather the full facts whilst suspending the operation of the research in the meantime. They also acknowledge the systematic way the need to deal with this. I hope their follow up is as thorough but I want to applaud this, it's a good approach.
The last line is "We will report our findings back to the community as soon as practical." It should be followed by "and we will provide an update in no more than 30 days".
Without any explicit time frame, holding them publicly accountable becomes trickier. At any point they can just say "we're still investigating" until enough time has passed people aren't paying attention any more.
Note that the companies that do ongoing incident updates on status sites best all do this -- "We will provide an update by 10:30pm PST".
Re: UMN CS&E Statement on Linux Kernel Research
#100Earlier quoted context omitted.
If they really care about being banned, they'll have no choice but to follow thorough
I’ve read and re-read that statement, and it seems like the ban is the focus – not what led to the ban. I get that they may not know anything, but there are other ways to word that without admitting liability, making it seem less like the focus is on the ban and more on the allegedly shady stuff.