Live data from Hacker News

UMN CS&E Statement on Linux Kernel Research

cse.umn.edu

161–170 of 332 posts

Re: UMN CS&E Statement on Linux Kernel Research

#161

To me reverting those hundreds of patches sounds like an overreaction, which might cause actual damage. It's not clear (at least from what I have read in the thread) that this code, which may be wrong or at least useless, is part of any "let's check their patch process" experiment (or did I just miss that?) That they did that in the past is clearly unethical and was generally a shitty thing to do, but this group also…

[deleted]

Re: UMN CS&E Statement on Linux Kernel Research

#162
post #2

This is a great statement, they confirm they're aware of the issue, they acknowledge the concerns and they set out their intention to gather the full facts whilst suspending the operation of the research in the meantime. They also acknowledge the systematic way the need to deal with this. I hope their follow up is as thorough but I want to applaud this, it's a good approach.

I agree, and given that they have only just started to look into it, I think it shows an appropriate amount of concern and urgency. They'll at least want to talk to the researchers and get their point of view, before committing any further. This is about the best you could expect at this point, they'll want to proceed methodically.

Re: UMN CS&E Statement on Linux Kernel Research

#163
post #57
post #26

Earlier quoted context omitted.

Which department should do it?

Sociology or anthropology. Possibly, though less so, political science, economics, or even a B school. These are all disciplines that study the social behavior of groups. As as study of a group activity it seems inapplicable to a psychology department, though that could be a bias on my part.

How would sociologists and anthropologists know how to write kernel code ..?

Re: UMN CS&E Statement on Linux Kernel Research

#165
post #2

This is a great statement, they confirm they're aware of the issue, they acknowledge the concerns and they set out their intention to gather the full facts whilst suspending the operation of the research in the meantime. They also acknowledge the systematic way the need to deal with this. I hope their follow up is as thorough but I want to applaud this, it's a good approach.

It doesn't take much to write a single paragraph, though. I think the quality of their response will become much more clear later.

Re: UMN CS&E Statement on Linux Kernel Research

#167
post #118
post #80

Earlier quoted context omitted.

i think the discussion should not be around banning them as known bad actors, but instead should be around how to detect bad actors or better introduce safety and security into the project. i'll tell you one thing, it has shaken my trust in the oss kernel development model as it operates today, and honestly that seems like maybe a good thing? how many companies are literally printing money with the linux kernel? can'…

No development model is protected from malicious actors, and this is not unique to OSS. Could the Ministry of State Security sponsor a student to study at the US, and then after graduate, that student gets a job at Microsoft, and then introduces vulnerabilities in Windows? In theory all patches should get code reviews, but could someone get a bug past code reivew? Sure! You can try to detect it before it happens, but…

so if satya nadella hires security firms to try this on the nt kernel (do they still call it that) and they succeed, then they learn from it, tighten security and process, and then move forward...

but if a set of academic researchers try it on the linux kernel, nothing changes and then there's a bunch of internet drama with people calling for them to be fired because why?

honestly, i've believed in oss since i encountered it in the early 90s. but this is making me start to reconsider proprietary software again.

Re: UMN CS&E Statement on Linux Kernel Research

#168
post #24
post #14

Earlier quoted context omitted.

There was one thing that I found to be lacking from their statement. They never said that what they had done was wrong. The university already knows what the researchers did and are aware of the paper that was written about the subject by those same researchers. [1] [1] On the Feasibility of Stealthily Introducing Vulnerabilities in Open-Source Software via Hypocrite Commits -- https://github.com/QiushiWu/QiushiWu.gi…

They shouldn't have. This appears to be a pretty clear cut case, but made up outrage-bait has made it to the top of HN before. Investigating claims is the correct thing to do.

Exactly. If someone apologizes to me, and I know that they have no way of knowing if they're guilty or not, what's that apology worth?

Re: UMN CS&E Statement on Linux Kernel Research

#169

"We discovered some folks have been urinating into the campus coffee urns, in order research whether people will object to the flavor. We have told them to stop."

A potent analogy, perhaps it will sway those that don't consider consent an important part of social research. I expect the department and university to perform a thorough investigation, and respond with decisive action afterwards . Not the other way around.

> respond with decisive action afterwards. Not the other way around.

... absolutely. Perhaps people liked the flavor.

Re: UMN CS&E Statement on Linux Kernel Research

#170
post #150

Earlier quoted context omitted.

What on earth has that got to with any of this?

It's an example of an organization making a promise to take action to respond to feedback from the community, not providing a time frame, and then just never doing it.

For the sake of discussion, I'll grant the example, but the fact that org A acts in bad faith has no bearing on whether org B acts in bad faith.

If Mozilla had ties to UMN CS&E you might have had a (tenuous) point, but...

Plus, this has come out in the last 48hrs or so? And you're somehow saying that's comparable to 3 years? Sure, if they haven't issued a further statement in 1 month, 3 months, etc. then you might be justified.

Post reply on HN