Live data from Hacker News

UMN CS&E Statement on Linux Kernel Research

cse.umn.edu

281–290 of 332 posts

Re: UMN CS&E Statement on Linux Kernel Research

#281
post #198
post #99

Earlier quoted context omitted.

It is a good statement, and I believe they'll follow through, but it's missing something important that is often missing from otherwise professional communication. The last line is "We will report our findings back to the community as soon as practical." It should be followed by "and we will provide an update in no more than 30 days". Without any explicit time frame, holding them publicly accountable becomes trickier…

> The last line is "We will report our findings back to the community as soon as practical." It should be followed by "and we will provide an update in no more than 30 days". I don't really think this is a worthwhile distinction. Personally, it comes off as trying to nanny a process that involves the Linux kernel maintainers and UMN Admins. There's a ban on UMN, probably until they show they can head off ethical issu…

I disagree. The associate department head named in the statement linked it on Twitter, immediately following up his comments with

> I very much welcome feedback from the participants who brought this to our attention: that's why I tagged @gregkh . Obviously, we would appreciate any guidance as to how we can get the Univ. of Minnesota contribution ban lifted.

This is pretty clearly one of their main interests in moving fast here. https://twitter.com/lorenterveen/status/1384954220705722369

Re: UMN CS&E Statement on Linux Kernel Research

#282
post #273

Earlier quoted context omitted.

I think it’s more accurate to say that “we know that they approved something . Whether or not that something turns out to be exactly that this professor and his student did here is I gather a different question.

The "hypocrite commit" preprint/abstract was a controversy which broke late last year. Prof. Lu at that point published an FAQ stating that he didn't think it was Human Subject Research (HSR) and got a post hoc review from the UMN IRB giving him a free pass, agreeing that attempting to con humans is apparently not HSR by their lights. This is three month old news at this point, and is quite well established. What tri…

Thanks, I didn't know that background (shame on me for not reading through all the history I guess). Odd decisions appear to have been made here by all parties. Though I was born in Iowa, I grew up in Minnesota and have a lot of friends who went there (Twin Cities campus, mostly).

Definitely not "Minnesota Nice".

Re: UMN CS&E Statement on Linux Kernel Research

#283
CS department security research is near universally not held to be in the scope of IRBs. This isn't entirely bad: the IRB process that projects are subjected to is so broken that it would be a sin to bring that mess on any other things.

But it means the regularly 'security' research does ethically questionable stuff.

IRBs exist because of legal risk. If parties harmed by unethical computer science research do not litigate (or bring criminal complaints, as applicable) the university practices will not substantially change.

Re: UMN CS&E Statement on Linux Kernel Research

#284

"We discovered some folks have been urinating into the campus coffee urns, in order research whether people will object to the flavor. We have told them to stop."

More likely: "We have concluded that since this is research on the coffee urn handling process it is not subject to review for compliance with our policies on research on human subjects."

Re: UMN CS&E Statement on Linux Kernel Research

#285
post #2

This is a great statement, they confirm they're aware of the issue, they acknowledge the concerns and they set out their intention to gather the full facts whilst suspending the operation of the research in the meantime. They also acknowledge the systematic way the need to deal with this. I hope their follow up is as thorough but I want to applaud this, it's a good approach.

This statement rings true because it is the wordsmith'd version of exactly what the department head probably said when he first heard, which probably went something like "what the f*k did you do, who the f*k thought this was a good idea, and who the f*k told you you could do this?"

I'm pretty sure the biggest program at UMN is Social Sciences. Conducting research experiments on unwitting subjects (the kernel maintainers) is a huge ethics violation.

I can only imagine the other department heads screaming at the head of the, relatively speaking, small CS department.

Re: UMN CS&E Statement on Linux Kernel Research

#286
post #223
post #195

Earlier quoted context omitted.

Maybe practically this doesn’t prevent most students or faculty from doing anything, but it is a huge reputation problem. How many universities (or organizations in general) are banned from contributing to the Linux kernel? When people search for why, they’ll find a research group basically screwing over their collaborators and anyone else who uses Linux. That that exists at UMN could be viewed as a serious cultural…

I feel you're overvaluing the ability to contribute to the linux kernel - this is definitely a bad thing and the university should work to correct the situation. But when I was looking at colleges and universties (for undergrad - I didn't pursue a grad degree) I didn't ever ask if the university was blacklisted by any open source organizations. I don't think anyone would notice this ban - it'd just be an odd curiosit…

The question isn't whether they need to be able to commit to the Linux kernel. Probably they don't. But the question is, what reputation does a CS department (and consequently a university) have, that has been banned from submitting patches to one of the most prolific open source projects around?

Re: UMN CS&E Statement on Linux Kernel Research

#287
post #267

Earlier quoted context omitted.

The department leadership never approved the research. Why does no one seem to understand that universities don't work like corporations? You never have to get your research ideas approved up the chain of command. You just start working on them (after running them by an IRB if you think that's necessary).

They have, in fact. The UMn IRB gave approval post hoc; they claimed no human subjects were involved.

The IRB is not "leadership", and the IRB process is usually not very adversial, i.e. primarily based on how the researchers represent their own work. (which is a flaw, but one thats common to how this works, not necessarily some special failure of UMN - which is why more investigation is needed)

Re: UMN CS&E Statement on Linux Kernel Research

#288

The research approach is distasteful and dangerous. Any one should not introduce bugs or malicious code intentionally, even for research purpose. The results are also a bit trivial. It is easy to imagine that this type of code injection would be possible. So let this be an example of what is the consequence of intentional malicious code injection, even in the name of research. I wish I could be on the researchers' si…

Being Chinese has nothing to do with this discussion.

Re: UMN CS&E Statement on Linux Kernel Research

#289

background for those unfamiliar with this: https://news.itsfoss.com/hypocrite-commits/ and Kangjie Lu's response: https://www-users.cs.umn.edu/~kjlu/papers/clarifications-hc....

The sheer entitlement of this: > Does this project waste certain efforts of maintainers? > Unfortunately, yes. We would like to sincerely apologize to the maintainers involved in the corresponding patch review process; this work indeed wasted their precious time. We had carefully considered this issue, but could not figure out a better solution in this study. Here’s a better solution: don’t do it. You do not have a d…

Beyond any other damage they did, they are wasting the life time and energy of the kernel developers currently sorting out this mess. To me, that is on the same level as locking them up in a room against their will. This could be considered a felony. In any case, they should make up for the economical part of the damage they caused, that is be billed for the hours the kernel developers spend in resolving the matter at hand at a high market rate (and probably above for punitive damages).

Re: UMN CS&E Statement on Linux Kernel Research

#290

Earlier quoted context omitted.

The entire statement has only 2 paragraphs, and says absolutely nothing at all about rescinding the ban.

Why else would they take the ban extremely seriously and take the actions mentioned? I guess it's possible they're worried about the ban spreading, but rescinding the ban seems more likely.

Or, maybe they don't want to be in a position where they are getting banned just in general? Like, maybe you don't mind getting banned from a specific bar, but you do mind being the kind of person that is getting banned from bars.
Post reply on HN