Live data from Hacker News

UMN CS&E Statement on Linux Kernel Research

cse.umn.edu

141–150 of 332 posts

Re: UMN CS&E Statement on Linux Kernel Research

#141
post #128
post #93

Earlier quoted context omitted.

If you wanted to know if the kernel review process is able to reliably catch malicious attempts you literally could have just asked the kernel maintainers and they'd told you that no, review can't go that deep. Or looked at non-malicious bugs and observed that no, review does not catch all bugs with security implications. You'd very likely would have been able to get code past them even if you told them that there ar…

the project is 30 something odd years old now, and is no longer a hobby, it is now critical infrastructure that powers virtually everything. it's unfortunate that something happened in the project that cost the maintainers a lot of hours, that comes with the territory of working on important software, i'd argue. i don't want an espionagetastic fundamentally untrustable and inescapable computing hellscape, airplanes f…

> So you are saying that because a non-controversial method to show the same issue wouldn't cause the publicity connected purely to their way of operating, it was right to ignore the concerns?

what's the non-controversial alternative? alerting the organization before they do it? that doesn't work. that's why scientists do blinding and double blinding.

if you mean something else, then i'm missing parts of this (really complicated) debate.

Re: UMN CS&E Statement on Linux Kernel Research

#142
post #129
post #99

Earlier quoted context omitted.

It is a good statement, and I believe they'll follow through, but it's missing something important that is often missing from otherwise professional communication. The last line is "We will report our findings back to the community as soon as practical." It should be followed by "and we will provide an update in no more than 30 days". Without any explicit time frame, holding them publicly accountable becomes trickier…

Kind of like how Mozilla will open-source Pocket any day now, just like they promised in 2017...

What on earth has that got to with any of this?

Re: UMN CS&E Statement on Linux Kernel Research

#143

Earlier quoted context omitted.

Anyone saying that it was a bad idea to ban the entire University isn't looking at the big picture. I look at it from a very philosophical standpoint: The entire idea of an academic (research) institution can be summarized as "an entity representing a group of trusted people who act in good faith of that institution". The moment one of your researchers acts in bad faith, or shows that they cannot be trusted, it's cle…

Banning the university is fine to send a message, but reverting all patches from umn emails seems very shortsighted to me. Especially blindly reverting patches years before this "research" was conducted that almost certainly have had context changes around them, likely introducing more harm than good.

I could easily see sending in a bad patch to see what happens and then waiting a few years to do more and write them up; there's no realistic way to guarantee when the bad-faith contributions started.

Re: UMN CS&E Statement on Linux Kernel Research

#144

I think everybody is missing the point. If one grad student was able to do this, imagine what a team of dozens of well-paid, well-equipped, and highly experienced security experts could do. In other news, we just learned that any half-decent security agency has already injected their own vulnerabilities and back-doors in OSS.

He didn’t succeed in injecting anything, right?

It would be interesting if someone found bad stuff in the kernel, but pet of the org structure makes this hard.

Re: UMN CS&E Statement on Linux Kernel Research

#145

I don't know why, but somehow I am not too bothered by the research itself. Sure, in retrospect, it does not sounds like it was the right thing to do (or the right way to do). But, you know, stuff happens. Instead, what bothered me immensely is the way the PhD student handled that interaction: immediately claiming "bias", "slander", playing "victim", etc... I don't know if he learned such a way to communicate from hi…

Maybe that was in line with the "research"? I think this can be an interesting topic in itself, how those trigger words and victim playing can get you through code reviews faster. It's certainly true in my company...

It looks like Linux kernel has passed the test!

Re: UMN CS&E Statement on Linux Kernel Research

#146

I think everybody is missing the point. If one grad student was able to do this, imagine what a team of dozens of well-paid, well-equipped, and highly experienced security experts could do. In other news, we just learned that any half-decent security agency has already injected their own vulnerabilities and back-doors in OSS.

> do this They got caught and had all their contributions reverted.

[deleted]

Re: UMN CS&E Statement on Linux Kernel Research

#147

Earlier quoted context omitted.

Anyone saying that it was a bad idea to ban the entire University isn't looking at the big picture. I look at it from a very philosophical standpoint: The entire idea of an academic (research) institution can be summarized as "an entity representing a group of trusted people who act in good faith of that institution". The moment one of your researchers acts in bad faith, or shows that they cannot be trusted, it's cle…

Banning the university is fine to send a message, but reverting all patches from umn emails seems very shortsighted to me. Especially blindly reverting patches years before this "research" was conducted that almost certainly have had context changes around them, likely introducing more harm than good.

they are re-reviewing the patches and will be accepting them back if they look fine, it is not really blindly rejecting them all

Re: UMN CS&E Statement on Linux Kernel Research

#148

I think everybody is missing the point. If one grad student was able to do this, imagine what a team of dozens of well-paid, well-equipped, and highly experienced security experts could do. In other news, we just learned that any half-decent security agency has already injected their own vulnerabilities and back-doors in OSS.

He didn’t succeed in injecting anything, right? It would be interesting if someone found bad stuff in the kernel, but pet of the org structure makes this hard.

He landed code that nobody seems to understand the purpose of. That looks like success to me.

Re: UMN CS&E Statement on Linux Kernel Research

#149

Earlier quoted context omitted.

>We basically at this point assuming bad faith for all UMN patches This seems like a gross overreaction to three commits that didn't even make it into mainline. Especially when done for commits years before the "research" was done. But I suppose nobody can miss a chance to let loose a little outrage

There were more than three buggy commits, at least one of which is from this month

Other than the three in question no others were intentionally buggy. https://lore.kernel.org/lkml/YIBMKSovJumS79SR@pendragon.idea...

Best to spend time auditing every commit in the kernel for bugs rather than grandstanding over the commits from one university's members.

Re: UMN CS&E Statement on Linux Kernel Research

#150
post #129

Earlier quoted context omitted.

Kind of like how Mozilla will open-source Pocket any day now, just like they promised in 2017...

What on earth has that got to with any of this?

It's an example of an organization making a promise to take action to respond to feedback from the community, not providing a time frame, and then just never doing it.
Post reply on HN