Earlier quoted context omitted.
Indeed. This letter is an attempt to justify and rationalise their actions. Essentially, it amounts to saying "we're sorry you were offended and felt hurt by our legitimate work but we had no choice but to lie to you and unethically experiment on you without your consent or we wouldn't have been able to do it". Their statement is not an actual apology, even if it is phrased in the language of apology, and it is an ex…
People love to analyze apologies after the fact, but it seems totally unfair to me. Once someone has said an apology you can take the text of it and turn it into anything you want and say it proves they were lying.
Open letter from researchers involved in the “hypocrite commit” debacle
241–250 of 384 posts
Re: Open letter from researchers involved in the “hypocrite commit” debacle
#242Earlier quoted context omitted.
We are talking about deliberate security vulnerabilities in the Linux kernel, a piece of critical infrastructure. Frankly, this is not the place to assume good faith.
But they did not introduce security vulnerabilities as there prevented the bad patches from being merged
Re: Open letter from researchers involved in the “hypocrite commit” debacle
#243Punishing these researchers this harshly about bad manners is creating a chilling effect that will scare researchers away from evaluating potentially one of the single biggest vulnerabilities in our industry.
To be honest if anyone went around anonymously trying to merge security exploits all across well used open source supply chains and always told everyone when they were successful immediately after and helped everyone become more vigilant in code review, I would call them a public servant even if they were almost universally hated for it.
I don't think most people realize just how easy supply chain attacks are and how widely they are being exploited by very dangerous organizations.
If something does not change fast to dramatically increase the level of scrutiny we give to code contributions, it is going to get much worse.
I have gone very far in pentests. Planting malicious USB cables, modifying keyboard firmware, straight up taking unlocked laptops and walking off, sniping recently expired domains to do XSS attacks, obtaining password reset links for the email accounts of maintainers of highly depended on third party dependencies.
Even with consent from high levels at orgs it still upsets unknowing people that are tricked at lower levels in the org. I don't apologize for this because it is my job.
I have seen real and successful social engineering attacks by state actors up close and you would way prefer a security researcher with bad manners to break you of your your survivors bias over being hit by the real thing.
The reality is big companies can afford to pay people like me. Open source projects by random solo maintainers that the security of almost everyone on the internet relies on... can't.
We should be very thankful for people that risk public rebuke to do research like this in open source at minimal cost to the receiving organization.
Re: Open letter from researchers involved in the “hypocrite commit” debacle
#244Earlier quoted context omitted.
I was just about to post: "This is a great apology." Context is everything, of course. I think you're right that it's tainted by the fact that they absolutely did not have a choice, and coming from people who've deceived the same tribes they're now trying to apologize to.
And what of the merits? If the previous 190 patches were indeed legitimate it strikes me as overly vengeful to pull them in a "punish the son for the sins of the father and the father for the sins of the son" kind of way.
Blocking an entire University seems extreme; but just think of it as a sanction on the University's ethics board. I think a (short, and very explicit) apology from the ethics board ought to suffice, to get the Uni off the hook.
And I think those researchers should not be allowed near Free Software again, unless their pushes are going to be rigourously scrutinised.
Re: Open letter from researchers involved in the “hypocrite commit” debacle
#245Earlier quoted context omitted.
> Consent is only relevant when there is some risk to the subject Says who? I don't think that's true according to IRB standards in the US. Nor is it true for websites who A/B test according to the GDPR
> Says who? Me and common sense. I don't believe consent is relevant when there is no risk of harm to the subject. IRBs and the GDPR are overly aggressive on this point, probably as a reaction to real and important violations of privacy. But the idea that A/B testing the color of your CTA button on a landing page requires informed consent is absurd.
Re: Open letter from researchers involved in the “hypocrite commit” debacle
#246Earlier quoted context omitted.
Imagine if instead they did this research with the closed source community. You know, get hired under false pretenses, sneak some vulns into some commercial product, write a paper about how easy it was. Pretty sure if they tried that they would be in jail right now.
There are literally companies you can hire that will go this far pentesting your company and the employees involved are not in on it. How else do you prove your process can stop real infiltrators by state actors?
There are many crimes in the world that are only crimes if you do it without consent.
> How else do you prove your process can stop real infiltrators by state actors?
One of the common security controls against infiltration by foreign nation states is espionage being a capital offense. Well obviously not appropriate, i think that its pretty obvious that these researchers would have not succeded if they faced the electric chair like a spy would. So i don't think the comparison is apt.
Re: Open letter from researchers involved in the “hypocrite commit” debacle
#247Earlier quoted context omitted.
Imagine if instead they did this research with the closed source community. You know, get hired under false pretenses, sneak some vulns into some commercial product, write a paper about how easy it was. Pretty sure if they tried that they would be in jail right now.
There are literally companies you can hire that will go this far pentesting your company and the employees involved are not in on it. How else do you prove your process can stop real infiltrators by state actors?
there lies the difference, duh.
Re: Open letter from researchers involved in the “hypocrite commit” debacle
#248People here don’t seem to be convinced. There’s a good amount of defense in this letter, so I get it, and it could have been framed better, but ultimately it seems like they learned a valuable lesson and have value to add, so why not let people learn from mistakes and move on? They’ve already been publicly shamed…
Reading this thread I am saddened to see hn apparently conform to the law of maximum offence. We see the least charitable explanation for everything said in the apology because outrage gets upvotes.
Re: Open letter from researchers involved in the “hypocrite commit” debacle
#249I'd like to give them the benefit of the doubt, but this is written like an apology they know they must write . It does not come across as apologetic. It comes across as rationalization veiled as an apology, and it doesn't sit well with me. I hope I'm just being overly sensitive here.
Indeed. This letter is an attempt to justify and rationalise their actions. Essentially, it amounts to saying "we're sorry you were offended and felt hurt by our legitimate work but we had no choice but to lie to you and unethically experiment on you without your consent or we wouldn't have been able to do it". Their statement is not an actual apology, even if it is phrased in the language of apology, and it is an ex…
Software is complex. Wasting maintainer's time is harmful to the maintainers and to those who use the software. If the goal is to explain what sort of exploits to be on the look-out for, just write the paper without doing the exploits.
As for the letter, their goal is to recover their reputations, not to apologize. I suppose a lawyer helped them in spots, but there is still a certain truth that shines through: they want to continue on doing this sort of thing, because they are oh-so-clever and their work is oh-so-valuable. Nice try, but the academic community may be better off without these folks doing this sort of research and influencing students to follow their methods.
Re: Open letter from researchers involved in the “hypocrite commit” debacle
#250I'd like to give them the benefit of the doubt, but this is written like an apology they know they must write . It does not come across as apologetic. It comes across as rationalization veiled as an apology, and it doesn't sit well with me. I hope I'm just being overly sensitive here.
> It does not come across as apologetic. The words are there. It's not up to us to decide if they're "genuine". No one's a mindreader. The tendency to view apologies as fake seems more often to reflect how harshly we view the one making it.
You have to acknowledge (in full) what it is that you are apologising for. That's the most important thing. Promises are meaningless.
It's not possible to "be genuine"; especially in a public post, nothing is genuine, everything is PR and smoke. Both the researchers and their ethics board need to grovel. If they did that, this tornado-in-a-teacup could be over in a month or two.
But keep those researchers banned.