Live data from Hacker News

Open letter from researchers involved in the “hypocrite commit” debacle

lore.kernel.org

211–220 of 384 posts

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#211

I agree with this post > Unless the researchers are lying (which I've not seen a clear indication of), the 190 patches you have selected here are nothing more than collateral damage while you are completely missing the supposed patch submission addresses from which the malicious patches were sent! This all really sounds like a knee-jerk reaction to thier posting. I have to say, I think it's the wrong reaction to have…

The researchers already lied when they conducted the study. What you are proposing is that we now should trust them to tell us the extent of their previous duplicitousness.

The most recent patch, which triggered the bad, has not been explained in good faith and it seems likely there were mistruths involved in that exchange as well.

So while it is absolutely a waste of time to have to go back through those 190 commits, the responsibility for that falls squarely on the researchers who broke that trust, not on the Greg fro refusing to re-extend that trust in the face of continued sketchy behaviors.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#212
post #197

Earlier quoted context omitted.

I mean, there’s all kinds of terrible unethical research. What makes you think this isn’t research?

Their paper got accepted to S&P 2021. That is the top conference in computer security in case one is not aware. Not justifying what they did but this apparently is still research.

This paint on canvas got sold and therefore it is Art.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#213
post #187

Earlier quoted context omitted.

> Consent is only relevant when there is some risk to the subject Says who? I don't think that's true according to IRB standards in the US. Nor is it true for websites who A/B test according to the GDPR

> Says who? Me and common sense. I don't believe consent is relevant when there is no risk of harm to the subject. IRBs and the GDPR are overly aggressive on this point, probably as a reaction to real and important violations of privacy. But the idea that A/B testing the color of your CTA button on a landing page requires informed consent is absurd.

> But the idea that A/B testing the color of your CTA button on a landing page requires informed consent is absurd.

A/B testing on major platforms is much more sophisticated than that[1].

It's a crucial practice for advertisers and marketing teams that dives deep into researching the psychological response towards images, text and dozens of other variables. Human subjects are acting as lab rats in order to extract some data points to drive the next test and campaign.

So, yes, it should definitely require informed consent and opting in.

[1]: https://www.bbc.com/news/technology-28051930

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#214
post #195

Unpopular opinion: People here seem to be overreacting when Linus Torvalds thinks this is not a big deal. https://itwire.com/open-source/torvalds-says-submitting-know...

Linus doesn't say it isn't a big deal, he says the technical impact of the incident is not high. The reason this is a big deal is the violations of ethics and the breach of trust, not the technical damge to the source code, all of which Linus acknowledges.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#215

Earlier quoted context omitted.

It seems like a nitpick to me, since the rest of the apology uses the proper choices of words, though. "The method used was inappropriate", "we made a mistake", etc. The apology is also specific about what they did wrong despite their intentions. It really is a good apology after reading past the first six words.

ESL here. How correct is it to use ’any harm’ to mean ‘all harm’.

I would go with "We apologize for the harm [that] we caused" which seems the most natural choice while explicitly acknowledging that some harm was caused. "All the harm" does indeed come across as a bit inflated, as other commenters have mentioned.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#216
post #212
post #197

Earlier quoted context omitted.

Their paper got accepted to S&P 2021. That is the top conference in computer security in case one is not aware. Not justifying what they did but this apparently is still research.

This paint on canvas got sold and therefore it is Art.

What is that supposed to mean? Conference publications are for research.

I pulled this from the website of Oakland 2021

Since 1980 in Oakland, the IEEE Symposium on Security and Privacy has been the premier forum for computer security research, presenting the latest developments and bringing together researchers and practitioners. We solicit previously unpublished papers offering novel research contributions in any aspect of security or privacy. Papers may present advances in the theory, design, implementation, analysis, verification, or empirical evaluation and measurement of secure systems.

https://www.ieee-security.org/TC/SP2021/cfpapers.html

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#217

This apology fails from the 5th word: "We sincerely apologize for any harm..." While there are other requirements, a sincere apology cannot in any way entertain doubt about the fact that there WAS harm. Truly acknowledging the harm done is foundational to a real apology, and most of us (myself included) end up sneaking in weasel words or phrases like this. Psychologically, its nice for the apologizer, since it allows…

Exactly my feeling too when I read this apology.

For me, it reads like this "With the best intentions, we were helping you. Unfortunately, you are too stupid to not realise this. We are sorry that we hurt your feelings, but please let us continue in helping you."

When you get such an apology, best thing is to avoid such people. Because it's clear they do not understand where they went wrong.

They should have either apologized with "we made a very big mistake that had a negative impact, it did more harm than good". Or they should have argued with real evidence on how they improve the Linux kernel, like refer to real exploits that they fixed.

This is just a "we're sorry that you don't realize we are helping you"

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#218
post #58

Supply chain attacks are the security buzzthreat of day, at least since Solarwinds. Mucking about with the Linux kernel would be a really juicy target for nation-state actors. If you wanted to study this risk, how would you go about doing it? I haven't done kernel work since BSD4.3 so my opinion isn't particularly interesting. With that said, I would agree that the researchers were naive and their approach has caused…

> If you wanted to study this risk, how would you go about doing it?

The main factor in doing this ethically is obtaining consent from your research subjects. I believe that some Red Teams test precisely these sorts of security mechanisms in commercial software projects and there are solid comments else discussing procedures they use.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#219
post #10

Earlier quoted context omitted.

And what of the merits? If the previous 190 patches were indeed legitimate it strikes me as overly vengeful to pull them in a "punish the son for the sins of the father and the father for the sins of the son" kind of way.

Or it's not in vengeance, but caution after the researchers have demonstrated that they put their needs above the community's. When the presumption of innocence is lost, it's appropriate to revert the patches until they are known to be good. ETA: GKH on reverting the patches[1] > This patchset has the "easy" reverts, there are 68 remaining ones that need to be manually reviewed. Some of them are not able to be revert…

counterpoint: The LF Technical Advisory Board is taking a look at the history of UMN's contributions and their associated research projects. At present, it seems the vast majority of patches have been in good faith, but we're continuing to review the work. Several public conversations have already started around our expectations of contributors.

https://lwn.net/Articles/854064/

What the authors did is wrong, so did GKH actions. Let's be honest in calling BS out.

Post reply on HN