Live data from Hacker News

Open letter from researchers involved in the “hypocrite commit” debacle

lore.kernel.org

51–60 of 384 posts

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#51
post #2

I'd like to give them the benefit of the doubt, but this is written like an apology they know they must write . It does not come across as apologetic. It comes across as rationalization veiled as an apology, and it doesn't sit well with me. I hope I'm just being overly sensitive here.

Social media insanity has greatly reduced our capacity to accept public apologies at face value. There is always a seething mob that is ready to question the sincerity of the apology once there are no more demands left to be made.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#52
post #16

Earlier quoted context omitted.

Indeed. This letter is an attempt to justify and rationalise their actions. Essentially, it amounts to saying "we're sorry you were offended and felt hurt by our legitimate work but we had no choice but to lie to you and unethically experiment on you without your consent or we wouldn't have been able to do it". Their statement is not an actual apology, even if it is phrased in the language of apology, and it is an ex…

maybe i am being very naive here but that letter read like a sincere apology to me as well.

I think if it were a sincere apology, they would have apologized for what they did, not just that there were undesirable side effects of their research. The letter is a typical "I'm sorry you got mad" apology that people make when they're forced to, but don't think they did anything wrong.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#53
The thing I’m still missing is a detailed explanation of what the heck was going on with the recent bogus commit that triggered the banning. Supposedly the “hypocrite commit” research was all done in 2020 and is now in the past. So what was going on with this latest bad commit? The student who submitted it claimed it was generated by a static analysis tool, which kernel maintainers have plausibly called bullshit on. Was that student lying? If so, what were they actually doing? If not, it seems absolutely necessary at this point to prove that they were telling the truth by publishing how that commit was produced, including the tool’s source code and how it was invoked. Even if the campaign to intentionally introduce security flaws was over in 2020, the more recent issue is that the same research group submitted an apparently intentionally incorrect patch and then seems to have lied about its provenance and why it was submitted. Until that’s cleared up any kind of apology feels premature and impossible to evaluate. How can anyone decide if an apology is sincere without understanding what was done?

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#54
post #8

Earlier quoted context omitted.

Just curious, and I'm genuinely asking as someone who thought the letter seemed well-intentioned: what should they have put in the apology letter?

> we did that because we knew we could not ask the maintainers of Linux for permission, or they would be on the lookout for the hypocrite patches. This bit just reads like "sorry you're upset". I would have expected something along the lines of "sorry, we should have asked the maintainers and we understand why it was wrong not to", instead of "sorry, we didn't ask the maintainers, but this is why we didn't".

"It's just a prank dude!"

Legitimately these folks have some kind of personality defect. They observed something that everyone already knew and then decided to act on it and pretend they were doing something interesting and new rather than just being twats. They should be treated exactly as should be based on their actions, regardless of their claims of being researchers. This would be a perfect cover for being on the take from a government agency. They should be investigated to ensure they aren't actual malicious actors.

It takes almost no imagination to think of hundreds of "security vulnerabilities" in the world, yet the vast majority of people realize that it's dumb to act on those observations.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#55

Whether it is appropriate or not, the Linux kernel is used in many mission critical and essential services. One could very convincingly argue that the open source Linux kernel is a vital part of mission critical infrastructure found all around the world. An apology, likely written under duress, for an inappropriate research method or for consuming the time of maintainers (either volunteer or paid) does not address th…

To be fair, you wouldn’t expect these individual researchers to address the governance question. That should come from the University or the department in question.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#56

Earlier quoted context omitted.

People love to analyze apologies after the fact, but it seems totally unfair to me. Once someone has said an apology you can take the text of it and turn it into anything you want and say it proves they were lying.

Yep, it's called accountability. Would you prefer people acted without regard for others knowing that magic words can be spoken after the damage is done?

I would prefer you not go around saying someone is "apologizing wrong" because you've found the magic formula to turn all apology text into "I'm sorry you feel bad". There's no point in making a statement like that the original person can't respond to, anyway.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#57
post #17
post #7

Earlier quoted context omitted.

I was just about to post: "This is a great apology." Context is everything, of course. I think you're right that it's tainted by the fact that they absolutely did not have a choice, and coming from people who've deceived the same tribes they're now trying to apologize to.

I think they could have really helped themselves by being humble and truly apologetic. Simple things like: - "We are sorry for the harm we caused" instead of "We're sorry for any harm we caused" - Not trying to explain their actions in the first paragraph of the apology! I think most folks are aware of their intent by now, and leading with yet another explanation just makes the whole thing feel disingenuous - Avoid s…

> hallmarks of a non-apology

Is that a thing? Like there's some non-apology Bingo card you can fill out? I don't see a connection between the criteria you listed and genuine-vs-false contrition.

You may perceive these things one way, but ultimately you can't know the minds of others well enough to tell if they are sincere or not about anything. You don't get to just declare yourself the arbiter of their feelings because they used "any" instead of "the".

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#58
Supply chain attacks are the security buzzthreat of day, at least since Solarwinds. Mucking about with the Linux kernel would be a really juicy target for nation-state actors. If you wanted to study this risk, how would you go about doing it?

I haven't done kernel work since BSD4.3 so my opinion isn't particularly interesting. With that said, I would agree that the researchers were naive and their approach has caused collateral damage. However, I'd also argue that the (apparent) topic of research is quite valid. There are a lot of extremely well funded adversaries who are quite talented at obfuscation. "Be careful out there."

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#59
post #8

Earlier quoted context omitted.

Indeed. This letter is an attempt to justify and rationalise their actions. Essentially, it amounts to saying "we're sorry you were offended and felt hurt by our legitimate work but we had no choice but to lie to you and unethically experiment on you without your consent or we wouldn't have been able to do it". Their statement is not an actual apology, even if it is phrased in the language of apology, and it is an ex…

Just curious, and I'm genuinely asking as someone who thought the letter seemed well-intentioned: what should they have put in the apology letter?

I am not a stakeholder in this, and my comment is about apologies, even though as a lifelong linux user and technologist responsible for deploying it, I still think there should be a real investigation.

While I had a bunch of notes about what makes the sentiment behing an apology meaningful, it's really separate from the issue that this should have been done privately. A public apology is just another thing about them and their message. They're performing and trying to draw in sympathetic members of an imaginary audience. There is no humility in public displays. I would be surprised if anybody asked for it, and doing it without asking is just more of the same type of behavior. There is no such thing as a public apology.

That said, I have no doubt they have suffered personally over this, and have some compassion for that suffering itself, but not sympathy for this performance. There is no gesture that restores trust. When their contributions and acomplishments become more remarkable than this issue, they will have restored it, but like most things, there is no "back" to go to. Maybe that static analyzer will be the ultimate bug finder, as succeeding at that is probably their only out.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#60
post #19

Earlier quoted context omitted.

Yeah, it's not a great apology. I would say as far as justifications go, I think it's a certain level of depth expected from academics, you shouldn't overthink it. As far as giving benefit of the doubt, it's likely not done out of malice in the first place. Just a combination of poor reasoning and doesn't exactly clear up if they even considered alternatives to control their variables. Unfortunately, it seems like th…

I don't think they had malice, but the breach of elemental ethics is just appalling. They show no remorse for being trusted and abusing that trust and good faith. They show no remorse for using human beings as involuntary guinea pigs. In sum, they show not remorse for doing wrong.

For me, it's not learning the lesson the first time around.

I completely agree their experiment is unethical. However, it's not actually clear cut to most researchers the ethical bounds of their work, especially for study papers that's never really been explored before. Ethics in of itself is largely a active subtopic for many areas in CS, not only security research. AI is one area where qualifying potential harm to human beings remains largely controversial. Ask any ML scientist, and they'll tell you that determining the ethics of a project is not their responsibility.

Post reply on HN