Live data from Hacker News

Open letter from researchers involved in the “hypocrite commit” debacle

lore.kernel.org

291–300 of 384 posts

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#291
post #286

Earlier quoted context omitted.

> Do any security researchers ask permission before finding other vulnerabilities in random open source code? I have never observed this. That's not what happened. Nobody is asking (or is expected to ask) when they look for vulnerabilities. The researchers were trying to introduce vulnerabilities. Had they only looked at the tools that maintainers use and given those a good shake to see whether an attack vector is lu…

Trying to submit a vulnerability they had no intention of actually allowing to ship to the public is not that different from finding serious vulnerabilities with no intention of using them. There also might be middle ground where people submit benign code that clearly demonstrates highly risky behavior the reviewer should have noticed. Maybe I introduce code that covertly exfiltrates memory from a non sensitive addre…

> Trying to submit a vulnerability they had no intention of actually allowing to ship to the public is not that different from finding serious vulnerabilities with no intention of using them.

It is different in that looking for vulnerabilities in code only costs you time, trying to introduce vulnerabilities costs the other person's time as well, and often producing vulnerabilities scales much better, e.g. you could write some tool that mails them patches, while they'd have to individually judge the merits.

> There also might be middle ground where people submit benign code that clearly demonstrates highly risky behavior the reviewer should have noticed.

I don't think so. The issue isn't so much with trying to get code reviewed, it's with wasting people's time. That they did so by trying to introduce bugs is just the icing on the cake.

If you get consent, you can have all your tests and strengthen the infrastructure, without eventually breaking the system because every other "researcher" submits bogus code every day in hopes to have one slip through and write a paper on how they proved that project x is exploitable.

I've noticed the same with general bounties. When you have a security.txt or are on hackerone etc, you'll get lots of useless automated submissions that are wasting your time. Once that happens, you'll either shut down the program, or start rejecting reports automatically which includes the possibility of a false positive.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#292
post #72
post #67

Contrarian thought: Linux Kernel Community, forever above board, pure, pristine and virtuous, is perhaps eager to cast the first stone against these researcher / activists in order to clean their own clothes by dirtying others, or deflect attention from their own failings? Quick search through the Lore for "problematic" phrases: - site:lkml.org intext:moronic ~ 46 results - site:lkml.org intext:idiotic ~ 278 results…

But you have a choice to interact with community or not to interact with an community, difference is that researcher's of “hypocrite commit” did not give such choice to community members, as of today there is overwhelming indication that this researcher's violated basic and fundamental principles of scientific ethical research.

But if I choose to interact with the community, does my choice to present myself, justify any and all abusive actions they may volley at me? Oof coarse not.

The point would ordinarily be a good one, but I think you've misused it.

The Linux kernel community, by your logic, chose to interact with and be open to patches which were not properly vetted.

This framing seems secondary to a seemingly more important point, which is, nobody is fucking perfect.

In LKLM or in UMinn. The light now shines on UMinn, but to me, the feigned horror of LKML at UMinn's transgressions, and the lack of commensurate outrage at the many abusive, toxic and hostile transgressions of the LKML community, presupposes a terrifying "normalization" of abusive behavior within the LKLM community.

By sooch notion, it's safer to interact with the UMinn transgressors, than it is with LKML, who here fail to even once question their own guilt, introspect upon their own created violations of trust and ethics, but heartily condemn the egregious breaches of trust of others.

I'd rather hang with the contrite, or at least hangdog, scallywag, than the quicktongued accusers blind to their own abuses. I'd feel safer there anyhoow.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#293
post #283
post #275

Earlier quoted context omitted.

> even though in reality I will do tests like this to a tiiiiny percentage of repos over the next decade So...contrary to what you suggest in your first paragraph, all you need to do is send out a handful of warning emails at the appropriate juncture. What’s the problem? For sure you shouldn’t be submitting malicious code to a project without forewarning. That's just a basic ethical no-no. Even if you were right that…

Well that basic ethical no-no is going to make it impractical for anyone to do open source supply chain integrity evaluation at scale because getting permission from thousands of people to do sweeping tests is impractical and warns everyone for a short period making it an inauthentic scenario. It will make it hard for things to improve, so millions will continue to get hacked due to supply chain attacks that almost n…

>Well that basic ethical no-no is going to make it impractical for anyone to do [x]

There's tons of potentially useful research that's impractical because of ethical considerations. Just think of all the incredibly useful medical research that could be done in the absence of ethical constraints!

In the end that's just tough cookies. If you can't do your research ethically then you can't do it. Period.

If you really want to help the Linux kernel, offer your time as a patch reviewer. That would achieve far more than any attempt to deceive and embarrass others with pointless "research". (I say that it's pointless because the results are antecedently obvious – of course you can deceive reviewers if you spend enough time and effort on it.)

In your ethical world, it seems that people who offer their spare time to review kernel patches are "negligent", while people who do nothing but carp from the sidelines are heroes. In my view, the situation is exactly the opposite.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#294

Earlier quoted context omitted.

Hypocrite patches came from Gmail. Banned umn mail. Because that’s going to reduce risk?

It’s not so much that they banned umn email, as it is they banned the university of Minnesota. This particular act is about avoiding the risk of researchers wasting kernel developers time. As evinced by the response, it seems really unlikely that other institutions would think it’s a good idea to perform experiments on the kernel devs in the future.

Most of the reverted commits are fine by inspection and the researched insist there were 3 hypocrite submissions that didn’t get merged.

So the idea is to collectively punish the mostly innocent people who wrote the 190 good commits, spending a huge amount of developer time checking them or losing the fixes to prevent other institutions from doing this?

Does reverting nearly 200 good patches seem out of proportion relative to 3 unmerged hypocrite commits?

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#295

Earlier quoted context omitted.

What is the serious vulnerability? That sometimes bugs slip through?

How extremely easy it is for a nation state or other malicious actor to intentionally introduce bugs.

Was there ever any doubt?

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#296
post #211

I agree with this post > Unless the researchers are lying (which I've not seen a clear indication of), the 190 patches you have selected here are nothing more than collateral damage while you are completely missing the supposed patch submission addresses from which the malicious patches were sent! This all really sounds like a knee-jerk reaction to thier posting. I have to say, I think it's the wrong reaction to have…

The researchers already lied when they conducted the study. What you are proposing is that we now should trust them to tell us the extent of their previous duplicitousness. The most recent patch, which triggered the bad, has not been explained in good faith and it seems likely there were mistruths involved in that exchange as well. So while it is absolutely a waste of time to have to go back through those 190 commits…

Why shouldn’t we trust them on the extent of their lies? Except three research commits, everything they have said has been true.

Given how few of the 190 have turned out wrong, given the timeline of the research relative, given the existing static analysis paper. Did Aditya Pakki write two entire papers about static analysis as cover for continuing this hypocrite commit research? Or did Aditya Pakki submit a bad patch in good faith and Greg Kroah-Hartman misunderstood and then overreacted with this mass revert? I think the latter is more plausible.

Otherwise, why stop at 190? The hypocrite commits came from Gmail. Logically, we can’t trust the researchers so we need to revert all Gmail commits. Wait they could Be infiltrating other universities, we should ban university commits everywhere. That would be a lot of work. So Greg picked a medium set of patches that expressed his power and outrage but had no real effect. The point is the particular set of commits he chose aren’t risky (by inspection we know they are good) and aren’t related to the hypocrite commits. So many innocent people are having their work thrown away because Greg is angry.

Note that we have only seen the simple to revert patches. There are 68 complex umn patches that have not been reverted. I expect they won’t because this is mainly theater. The commits are good but Greg wants to be show how angry he is.

My impression is we are just living through some kernel maintainer lashing out because he was embarrassed by the failed review process and mixed up the buggy static commits with the hypocrite research. Admitting you’re wrong is hard, so I don’t expect Greg to do that.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#297
post #207

Earlier quoted context omitted.

There's lots of systemically horrible things that can happen if you're not careful about what you allow. If you're interested why these ethical principles exist in the United States, I suggest you at least skim the Belmont Report https://en.wikipedia.org/wiki/Belmont_Report

> There's lots of systemically horrible things that can happen if you're not careful about what you allow. Of course there are. But what specifically are the harms that are going to be caused by either this research or a landing page A/B test without a click through pop up? The existence of theoretical harms for broad categories of potential research does not have a whole lot of bearing on these specific lines of res…

If I sit across the street from your house in a van and observe your life, noting down the times you come and go, and logging what I can see through your window, and then using that data to market things to you, would you agree that you'd rather be able to provide and withdraw consent for this activity? No harm done to you.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#299

Earlier quoted context omitted.

ESL here. How correct is it to use ’any harm’ to mean ‘all harm’.

1) "We apologize for any harm we might have caused" 2) "We apologize for any harm that we caused" 3) "We apologize for all the harm that we caused" (1) is the least apologetic. This could be interpreted as saying "we might or might not have caused harm, and we think we didn't but you think we did, so we're going to apologize for your sake, but we're not really sorry because we didn't do anything wrong from our perspe…

A sincere written apology should be 3. You needn’t misrepresent your own intentions to do this, but it does require thinking about the specific harms you have caused (perhaps unintentionally) and enumerating them in a way that doesn’t minimize their import. That is the anatomy of a true apology. It requires taking the other perspective as fact.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#300
post #193

Earlier quoted context omitted.

It’s not so much that they banned umn email, as it is they banned the university of Minnesota. This particular act is about avoiding the risk of researchers wasting kernel developers time. As evinced by the response, it seems really unlikely that other institutions would think it’s a good idea to perform experiments on the kernel devs in the future.

You do know that one can contribute without having to use their institution email address ?

Yes, I do know that.

The policy is not about them being physically prevented from emailing from not-a-umn-researcher@yahoo.com.

It’s a symbolic policy, but I would be extremely surprised if a university flouted a clear and explicit ban on their participation.

Post reply on HN