Live data from Hacker News

Open letter from researchers involved in the “hypocrite commit” debacle

lore.kernel.org

241–250 of 384 posts

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#241

Earlier quoted context omitted.

Indeed. This letter is an attempt to justify and rationalise their actions. Essentially, it amounts to saying "we're sorry you were offended and felt hurt by our legitimate work but we had no choice but to lie to you and unethically experiment on you without your consent or we wouldn't have been able to do it". Their statement is not an actual apology, even if it is phrased in the language of apology, and it is an ex…

People love to analyze apologies after the fact, but it seems totally unfair to me. Once someone has said an apology you can take the text of it and turn it into anything you want and say it proves they were lying.

The researchers can no longer be trusted at all. The apology should have come from the University ethics board.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#242

Earlier quoted context omitted.

We are talking about deliberate security vulnerabilities in the Linux kernel, a piece of critical infrastructure. Frankly, this is not the place to assume good faith.

But they did not introduce security vulnerabilities as there prevented the bad patches from being merged

Those measures were insufficient, as according to the developers, a number of the bogus patches were merged and had to be reverted.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#243
If we don't somehow make it socially acceptable to let any security researchers conduct the required social engineering to test supply chain attack susceptibility of OSS maintainers without tipping them off in advance, dangerous state actors -will- continue to do it and -not- tell anyone when they are successful.

Punishing these researchers this harshly about bad manners is creating a chilling effect that will scare researchers away from evaluating potentially one of the single biggest vulnerabilities in our industry.

To be honest if anyone went around anonymously trying to merge security exploits all across well used open source supply chains and always told everyone when they were successful immediately after and helped everyone become more vigilant in code review, I would call them a public servant even if they were almost universally hated for it.

I don't think most people realize just how easy supply chain attacks are and how widely they are being exploited by very dangerous organizations.

If something does not change fast to dramatically increase the level of scrutiny we give to code contributions, it is going to get much worse.

I have gone very far in pentests. Planting malicious USB cables, modifying keyboard firmware, straight up taking unlocked laptops and walking off, sniping recently expired domains to do XSS attacks, obtaining password reset links for the email accounts of maintainers of highly depended on third party dependencies.

Even with consent from high levels at orgs it still upsets unknowing people that are tricked at lower levels in the org. I don't apologize for this because it is my job.

I have seen real and successful social engineering attacks by state actors up close and you would way prefer a security researcher with bad manners to break you of your your survivors bias over being hit by the real thing.

The reality is big companies can afford to pay people like me. Open source projects by random solo maintainers that the security of almost everyone on the internet relies on... can't.

We should be very thankful for people that risk public rebuke to do research like this in open source at minimal cost to the receiving organization.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#244
post #10
post #7

Earlier quoted context omitted.

I was just about to post: "This is a great apology." Context is everything, of course. I think you're right that it's tainted by the fact that they absolutely did not have a choice, and coming from people who've deceived the same tribes they're now trying to apologize to.

And what of the merits? If the previous 190 patches were indeed legitimate it strikes me as overly vengeful to pull them in a "punish the son for the sins of the father and the father for the sins of the son" kind of way.

Problem is, hardly anyone is spending money on lawyers to defend Free Software. So the cheapest way to defend Free Software is to ban submissions from people who have a record of submitting crap.

Blocking an entire University seems extreme; but just think of it as a sanction on the University's ethics board. I think a (short, and very explicit) apology from the ethics board ought to suffice, to get the Uni off the hook.

And I think those researchers should not be allowed near Free Software again, unless their pushes are going to be rigourously scrutinised.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#245
post #187

Earlier quoted context omitted.

> Consent is only relevant when there is some risk to the subject Says who? I don't think that's true according to IRB standards in the US. Nor is it true for websites who A/B test according to the GDPR

> Says who? Me and common sense. I don't believe consent is relevant when there is no risk of harm to the subject. IRBs and the GDPR are overly aggressive on this point, probably as a reaction to real and important violations of privacy. But the idea that A/B testing the color of your CTA button on a landing page requires informed consent is absurd.

If anything they wasted time and energy of project maintainers. This alone should be enough to see the behavior is inexcusable.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#246
post #236

Earlier quoted context omitted.

Imagine if instead they did this research with the closed source community. You know, get hired under false pretenses, sneak some vulns into some commercial product, write a paper about how easy it was. Pretty sure if they tried that they would be in jail right now.

There are literally companies you can hire that will go this far pentesting your company and the employees involved are not in on it. How else do you prove your process can stop real infiltrators by state actors?

So? The difference is consent (in your case of the owners of the company).

There are many crimes in the world that are only crimes if you do it without consent.

> How else do you prove your process can stop real infiltrators by state actors?

One of the common security controls against infiltration by foreign nation states is espionage being a capital offense. Well obviously not appropriate, i think that its pretty obvious that these researchers would have not succeded if they faced the electric chair like a spy would. So i don't think the comparison is apt.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#247
post #236

Earlier quoted context omitted.

Imagine if instead they did this research with the closed source community. You know, get hired under false pretenses, sneak some vulns into some commercial product, write a paper about how easy it was. Pretty sure if they tried that they would be in jail right now.

There are literally companies you can hire that will go this far pentesting your company and the employees involved are not in on it. How else do you prove your process can stop real infiltrators by state actors?

> you can hire

there lies the difference, duh.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#248

People here don’t seem to be convinced. There’s a good amount of defense in this letter, so I get it, and it could have been framed better, but ultimately it seems like they learned a valuable lesson and have value to add, so why not let people learn from mistakes and move on? They’ve already been publicly shamed…

Reading this thread I am saddened to see hn apparently conform to the law of maximum offence. We see the least charitable explanation for everything said in the apology because outrage gets upvotes.

I agree. This is what I would expect from twitter. I would have hoped HN could manage to be better.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#249
post #2

I'd like to give them the benefit of the doubt, but this is written like an apology they know they must write . It does not come across as apologetic. It comes across as rationalization veiled as an apology, and it doesn't sit well with me. I hope I'm just being overly sensitive here.

Indeed. This letter is an attempt to justify and rationalise their actions. Essentially, it amounts to saying "we're sorry you were offended and felt hurt by our legitimate work but we had no choice but to lie to you and unethically experiment on you without your consent or we wouldn't have been able to do it". Their statement is not an actual apology, even if it is phrased in the language of apology, and it is an ex…

Agreed. This is like a psychologist apologizing for traumatizing children by testing a hypothesis that telling them scary stories before bedtime would give them bad dreams. "Oh, but it's important to learn what scares kids, for the greater good" just doesn't cut it.

Software is complex. Wasting maintainer's time is harmful to the maintainers and to those who use the software. If the goal is to explain what sort of exploits to be on the look-out for, just write the paper without doing the exploits.

As for the letter, their goal is to recover their reputations, not to apologize. I suppose a lawyer helped them in spots, but there is still a certain truth that shines through: they want to continue on doing this sort of thing, because they are oh-so-clever and their work is oh-so-valuable. Nice try, but the academic community may be better off without these folks doing this sort of research and influencing students to follow their methods.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#250
post #2

I'd like to give them the benefit of the doubt, but this is written like an apology they know they must write . It does not come across as apologetic. It comes across as rationalization veiled as an apology, and it doesn't sit well with me. I hope I'm just being overly sensitive here.

> It does not come across as apologetic. The words are there. It's not up to us to decide if they're "genuine". No one's a mindreader. The tendency to view apologies as fake seems more often to reflect how harshly we view the one making it.

Apologies are really difficult to do.

You have to acknowledge (in full) what it is that you are apologising for. That's the most important thing. Promises are meaningless.

It's not possible to "be genuine"; especially in a public post, nothing is genuine, everything is PR and smoke. Both the researchers and their ethics board need to grovel. If they did that, this tornado-in-a-teacup could be over in a month or two.

But keep those researchers banned.

Post reply on HN