Live data from Hacker News

“They introduce kernel bugs on purpose”

lore.kernel.org

961–970 of 1001 posts

Re: “They introduce kernel bugs on purpose”

#961

I don't see the difference between these and other 'hackers', white-hat, black-hat etc. The difference I see is the institution tested, Linux, is beloved here. Usually people are admired here for finding vulnerabilities in all sorts of systems and processes. For example, when someone submits a false paper to a peer-reviewed journal, people around here root for them; I don't see complaints about wasting the time and v…

I don't think what has been done here is comparable to other forms of "finding vulnerabilities". Linux and everyone else would be happy if people find vulnerabilities in their code and report them back. And it is not like linux team is unaware of this "vulnerability"

This is more comparable to DDOS ing a web server to test their capabilities of handling DDOS. And they are aware of the issue. And they told you to not do it when you did it before. You just don't waste other people's time/money like that unless they give you the permission.

Re: “They introduce kernel bugs on purpose”

#964
post #548

The tone of Aditya Pakki's message makes me think they would be very well served by reading 'How to Win Friends & Influence People' by Dale Carnegie. This is obviously the complete opposite of how you should be communicating with someone in most situations let alone when you want something from them. I have sure been there though so if anything, take this as a book recommendation for 'How to Win Friends & Influence P…

I’ve seen this book mentioned a couple of times on HN now. I’m curious: did you learn about this book from the fourth season of the Fargo? This is where I encountered it first.

As others have stated it is everywhere. The title always scared me away from it a little, but then I saw it come by in the intro of Netflix’s “The Politician” and I thought I’d give it a chance. Especially after I found out how old it is.

Re: “They introduce kernel bugs on purpose”

#965

Earlier quoted context omitted.

Isn't this reaction a bit like the emperor banishing anyone who tells him that his new clothes are fake? Are the maintainers upset that someone showed how easy it is to subvert kernel security?

More like the emperor banishing anyone who tries to sell him fake clothes to prove that the emperor will buy fake clothes.

The middle ground would be if the Emperor jailed the tailors of the New Clothes after he had shown off the clothes at the Parade, in front of the whole city.

Re: “They introduce kernel bugs on purpose”

#966

From an outsider, the main question is: does this expose an actual weakness in the Linux development model? From what I understand, this answer seems to be a "yes". Of course, it is understandable that GKH is frustrated, and if his community do not like someone pointing out this issue, it is OK too. However, one researcher does not represent the whole university, so it seems immature to vent this to other unrelated p…

No, because there is already historic evidence that it's a weakness.

Re: “They introduce kernel bugs on purpose”

#967
post #267

The professor gets exactly what they want here, no? "We experimented on the linux kernel team to see what would happen. Our non-double-blind test of 1 FOSS maintenance group has produced the following result: We get banned and our entire university gets dragged through the muck 100% of the time". That'll be a fun paper to write, no doubt. Additional context: * One of the committers of these faulty patches, Aditya Pak…

Thanks for the support. I also now have submitted a patch series that reverts the majority of all of their contributions so that we can go and properly review them at a later point in time: https://lore.kernel.org/lkml/20210421130105.1226686-1-gregkh...

> Thanks for the support.

THANK YOU! After reading the email chain, I have a much greater appreciation for the work you do for the community!

Re: “They introduce kernel bugs on purpose”

#968

Linux maintainers should log a complaint with the University's ethics board. You can't just experiment on people without consent.

I have a theory that while the university's ethics board may have people on it who are familiar with the myriad of issues surrounding, for instance, biomedical research, they have nobody on it with even the most cursory knowledge of open source software development. And nobody who has even the faintest idea of how critically important the Linux kernel is to global infrastructure.

They should also have people on it who are familiar with psychology research. The issues with this research the types of things psychology research should find.

Re: “They introduce kernel bugs on purpose”

#969
I'm not surprised.

I'm repeating myself, but I'm pretty certain the NSA or other intel agencies (Israel, especially, considering their netsec expertise) have already done it in one way or another.

Do you remember the semicolon that caused a big wifi vuln? Hard to really know if it was just a mistake.

I'm going full paranoiac here, but anyway.

You can also imagine the NSA submitting patches to the windows source code, without the knowledge of microsoft, and so many other similar scenarios (android, apple, etc)

Re: “They introduce kernel bugs on purpose”

#970
post #749
post #267

Earlier quoted context omitted.

Thanks for the support. I also now have submitted a patch series that reverts the majority of all of their contributions so that we can go and properly review them at a later point in time: https://lore.kernel.org/lkml/20210421130105.1226686-1-gregkh...

Just wanted to say thanks for your work! As an OSS maintainer (Node.js and a bunch of popular JS libs with millions of weekly downloads) - I feel how _tempting_ it is to trust people and assume good faith. Often since people took the time to contribute you want to be "on their side" and help them "make it". Identifying and then standing up to bad-faith actors is extremely important and thankless work. Especially ones…

How could resilience be verified after asking for consent?
Post reply on HN