Live data from Hacker News

UMN CS&E Statement on Linux Kernel Research

cse.umn.edu

181–190 of 332 posts

Re: UMN CS&E Statement on Linux Kernel Research

#181
The research approach is distasteful and dangerous. Any one should not introduce bugs or malicious code intentionally, even for research purpose. The results are also a bit trivial. It is easy to imagine that this type of code injection would be possible. So let this be an example of what is the consequence of intentional malicious code injection, even in the name of research.

I wish I could be on the researchers' side, as I am both Chinese and an alum from UMN. But No - wrong is wrong.

Re: UMN CS&E Statement on Linux Kernel Research

#182

Earlier quoted context omitted.

If they really care about being banned, they'll have no choice but to follow thorough

Yeah and that's some heavy shade on a university. They'll lose good students if this is not fixed.

I don't think that's the case (due to how fame works) and I don't even think it's particularly productive to bring up that point.

Their actions should be rectified since they did wrong - not out of fear of a punishment. When we bring only a specific punishment in as a consequence then the question of how to respond can be shifted over to a "which is worse" proposition which means that the punishment needs to be properly proportioned.

At any rate - I doubt admissions would be appreciably impacted even if they handled this incident extremely poorly - some potential grad students might look elsewhere while most would likely be ignorant of the whole incident.

Re: UMN CS&E Statement on Linux Kernel Research

#183
The research approach is distasteful and dangerous. Any one should not introduce bugs or malicious code intentionally, even for research purpose. The results are also a bit trivial. It is easy to imagine that this type of code injection would be possible. So let this be an example of what would be the consequence of intentional malicious code injection, even in the name of research.

I wish I could be on the researchers' side, as I am both Chinese and an alum of UMN. But No - wrong is wrong.

Re: UMN CS&E Statement on Linux Kernel Research

#184

Earlier quoted context omitted.

If they really care about being banned, they'll have no choice but to follow thorough

Yeah and that's some heavy shade on a university. They'll lose good students if this is not fixed.

>They'll lose good students if this is not fixed.

"Ability to commit to the Linux kernel with my school email" isn't likely to be a major issue for many. It's a non-issue for undergrad work, and even most grad students are unlikely to be affected. Other than this research, only one other person associated with UMN has committed code to the kernel.

This impacts any direct school-sponsored research work, but if some random student wants to write a patch, they'll just do it from a personal address - no kernel committer is going to go do social media stalking of every contributor.

Re: UMN CS&E Statement on Linux Kernel Research

#185

I don't know why, but somehow I am not too bothered by the research itself. Sure, in retrospect, it does not sounds like it was the right thing to do (or the right way to do). But, you know, stuff happens. Instead, what bothered me immensely is the way the PhD student handled that interaction: immediately claiming "bias", "slander", playing "victim", etc... I don't know if he learned such a way to communicate from hi…

It's entirely possible that Aditya is actually just working on a static analysis tool, it is buggy, and he wasn't aware of the other research his advisor does. If that is the case, I can kind of understand his response. I would be pretty upset if I knew I was just trying to submit some honest(if buggy) patches, but was accused of being a scoundrel because of something that didn't even involve me.

Of course, it's also possible that he is just gaslighting Greg and actually was doing the same kind of "research" as other people did before.

I think that UMN will get to the bottom of it - it will be pretty clear to them what kind of research he was doing, and whether he represented himself honestly.

Re: UMN CS&E Statement on Linux Kernel Research

#186

I think everybody is missing the point. If one grad student was able to do this, imagine what a team of dozens of well-paid, well-equipped, and highly experienced security experts could do. In other news, we just learned that any half-decent security agency has already injected their own vulnerabilities and back-doors in OSS.

> do this They got caught and had all their contributions reverted.

After the code was accepted and in mainline… the horse was well out of the barn.

Re: UMN CS&E Statement on Linux Kernel Research

#187
post #2

This is a great statement, they confirm they're aware of the issue, they acknowledge the concerns and they set out their intention to gather the full facts whilst suspending the operation of the research in the meantime. They also acknowledge the systematic way the need to deal with this. I hope their follow up is as thorough but I want to applaud this, it's a good approach.

This statement rings true because it is the wordsmith'd version of exactly what the department head probably said when he first heard, which probably went something like "what the f*k did you do, who the f*k thought this was a good idea, and who the f*k told you you could do this?"

Re: UMN CS&E Statement on Linux Kernel Research

#188

Earlier quoted context omitted.

Sorry for getting sidetracked, but does cc has any special function here or you are hoping that dang would read all the comments and see your cc?

I think dang might have something in place which alerts him when he is mentioned. Certainly he tends to show up quickly when people "page" him like this.

It's a bit like saying Voldemort, somehow he always knows.

But opposite because dang is helpful and nice.

Re: UMN CS&E Statement on Linux Kernel Research

#189
post #157
post #99

Earlier quoted context omitted.

It is a good statement, and I believe they'll follow through, but it's missing something important that is often missing from otherwise professional communication. The last line is "We will report our findings back to the community as soon as practical." It should be followed by "and we will provide an update in no more than 30 days". Without any explicit time frame, holding them publicly accountable becomes trickier…

> explicit time frame This seems incompatible with the pace of academia, as I have experienced it.

Academics tend to be able to find their calendars when money or prestige is involved.

This is the second one.

Re: UMN CS&E Statement on Linux Kernel Research

#190
post #175

Earlier quoted context omitted.

They need not promise to have results in a particular time frame, but they should commit to giving an update by a particular date, even if that update is just, "We've made progress investigating this incident, but we are not yet ready to report our findings. We will give our next update no later than $DATE."

I have also seen many times a university happy to throw a student or even a faculty member under the bus, and in this case it seems extremely clear that they were running an unethical sociological experiment that was probably not reviewed by the IRB there. That's grounds for the university very rapidly turning on you. Violating IRB ethics is a very serious issue, and has timelines in place once a complaint is filed.…

They’ve explicitly said before that this was reviewed by the IRB and cleared by them as not being an experiment with human subjects
Post reply on HN