Live data from Hacker News

UMN CS&E Statement on Linux Kernel Research

cse.umn.edu

301–310 of 332 posts

Re: UMN CS&E Statement on Linux Kernel Research

#301

Earlier quoted context omitted.

they are re-reviewing the patches and will be accepting them back if they look fine, it is not really blindly rejecting them all

And in the meantime allowing patched permissions vulnerabilities to reappear in mainline? Seems to be a bit of an overreaction no? https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/lin...

I don't think the removal of those patches means the changes will be immediately pushed to public. If they are breaking anything it is develop branch and surely they will review all those patches and will merge the good ones back before releasing anything public

edit: actually not even the develop I think https://lore.kernel.org/lkml/20210421130105.1226686-1-gregkh... It is just another branch? I am not familiar with the jargon

Re: UMN CS&E Statement on Linux Kernel Research

#302

background for those unfamiliar with this: https://news.itsfoss.com/hypocrite-commits/ and Kangjie Lu's response: https://www-users.cs.umn.edu/~kjlu/papers/clarifications-hc....

The sheer entitlement of this: > Does this project waste certain efforts of maintainers? > Unfortunately, yes. We would like to sincerely apologize to the maintainers involved in the corresponding patch review process; this work indeed wasted their precious time. We had carefully considered this issue, but could not figure out a better solution in this study. Here’s a better solution: don’t do it. You do not have a d…

Regarding:

> Does this project waste certain efforts of maintainers?

> Unfortunately, yes. We would like to sincerely apologize to the maintainers involved in the corresponding patch review process; this work indeed wasted their precious time. We had carefully considered this issue, but could not figure out a better solution in this study.

Have they ever heard about carbon offsets? How about finding/performing work that offsets the abuse of time of the maintainers involved? (Hint: it's not too late to do this to show you really are sorry. You won't be trusted at first but it's the right thing to do.)

Re: UMN CS&E Statement on Linux Kernel Research

#303
post #276

Earlier quoted context omitted.

>They'll lose good students if this is not fixed. "Ability to commit to the Linux kernel with my school email" isn't likely to be a major issue for many. It's a non-issue for undergrad work, and even most grad students are unlikely to be affected. Other than this research, only one other person associated with UMN has committed code to the kernel. This impacts any direct school-sponsored research work, but if some ra…

I think you underestimate the shade this puts on the UMN name. I've never even heard of UMN before, but I doubt I'll ever forget hearing about this university fraudulently trying to sabotage the Linux project, and will probably treat anything and anyone with an UMN background with great suspicion in the future.

You will treat anyone educated at the same university with `great suspicion`? Really? That is hardly rational or appropriate.

Re: UMN CS&E Statement on Linux Kernel Research

#304

Earlier quoted context omitted.

There were more than three buggy commits, at least one of which is from this month

Other than the three in question no others were intentionally buggy. https://lore.kernel.org/lkml/YIBMKSovJumS79SR@pendragon.idea... Best to spend time auditing every commit in the kernel for bugs rather than grandstanding over the commits from one university's members.

How do you know? These people already attempted to manipulate the kernel maintainers repeatedly, even after being caught. Nothing they claim about their own work can be trusted.

Re: UMN CS&E Statement on Linux Kernel Research

#305
post #121
post #18

That sounds like someone's academic career has just landed in the toilet ...

Apparently the researchers in question don't have tenure. If that is so, RIP to their achedemic careers right now.

That seems optimistic. Scientific fraud is caught all the time and basically never results in anything happening. The university here repeatedly signed off on this so it's institutionally culpable. Normally when bad stuff happens in research academics just all blatantly deny anything is wrong and dare you to do anything about it.

Re: UMN CS&E Statement on Linux Kernel Research

#306

Earlier quoted context omitted.

Maybe that was in line with the "research"? I think this can be an interesting topic in itself, how those trigger words and victim playing can get you through code reviews faster. It's certainly true in my company...

It looks like Linux kernel has passed the test!

I think many of the responses from Linus over the years shows that Linux never needed that test ;)

Re: UMN CS&E Statement on Linux Kernel Research

#307

Earlier quoted context omitted.

Except that patch is clearly BS! You can't patch a double-read vulnerability by checking for a capability; that's not a thing that works. So either the description is wrong, or the patch is wrong, or both. And the point of the reverts is that the kernel maintainers don't have the unlimited time that would be necessary to re-review all of these questionable patches for probable malicious underhanded C, so they are rev…

You don't think reverting a patch from someone whose only relation is working(worked?) at the same university as the advisor initially responsible for the security "research" is overkill? If the goal is to prevent security bugs in mainline then maybe haphazardly reverting everything that doesn't conflict and fixing it later isn't the best approach. I'm disappointed at seeing hackernews jump on this mindless mob justi…

> I'm disappointed at seeing hackernews jump on this mindless mob justice like other sites would.

Having your patch reverted pending review is hardly punishment. Calling this mob justice is an insult to both mobs and justice.

Re: UMN CS&E Statement on Linux Kernel Research

#308

Earlier quoted context omitted.

> At any point they can just say "we're still investigating" until enough time has passed people aren't paying attention any more. They need to act to get the ban rescinded, they can't just ignore this issue away.

> They need to act to get the ban rescinded, they can't just ignore this issue away. I doubt that - in the other thread, someone noted that the last non-hostile kernel contribution from @umn.edu was in 2014. I don't think they are champing at the bit to get legit kernel contributions merged - or at least haven't in the past 7 years. At this point, it is purely a reputation/PR problem with little urgency - the ban is…

The real urgency is they need to protect their reputation. So long as they do a proper investigation and take proper action they can spin this as a rouge professor and be forgiven. We as a community should give them time to investigate and figure out how to handle and prevent this, and then if done correctly forgive them. If they make this statement and then there is no action within a year, then we should assume this is a token attempt to sweep things under the rug and continue with more bans.

For now I'll accept their apology, but if there is no action in the future I'll retract that.

Re: UMN CS&E Statement on Linux Kernel Research

#309
post #190

Earlier quoted context omitted.

I have also seen many times a university happy to throw a student or even a faculty member under the bus, and in this case it seems extremely clear that they were running an unethical sociological experiment that was probably not reviewed by the IRB there. That's grounds for the university very rapidly turning on you. Violating IRB ethics is a very serious issue, and has timelines in place once a complaint is filed.…

They’ve explicitly said before that this was reviewed by the IRB and cleared by them as not being an experiment with human subjects

Which means either they mislead the IRB, or the IRB also needs reform. That investigation should take a while either way to figure out how that is possible.

Re: UMN CS&E Statement on Linux Kernel Research

#310
post #303
post #276

Earlier quoted context omitted.

I think you underestimate the shade this puts on the UMN name. I've never even heard of UMN before, but I doubt I'll ever forget hearing about this university fraudulently trying to sabotage the Linux project, and will probably treat anything and anyone with an UMN background with great suspicion in the future.

You will treat anyone educated at the same university with `great suspicion`? Really? That is hardly rational or appropriate.

Very appropriate. Until yesterday I was happy to have a CS degree from the UMN. Now that is tainted and I want to hide who gave me the degree. I have to wonder if they taught me some things that were unethical that I'm not doing without knowing better. I wouldn't hire a UMN grad because of their reputation.

For now I'm assuming that my degree was more than 20 years ago, and things change in that time (most of the professors I remember best are dead...). However this is doubt in my mind.

Post reply on HN