Live data from Hacker News

Open letter from researchers involved in the “hypocrite commit” debacle

lore.kernel.org

301–310 of 384 posts

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#301

Earlier quoted context omitted.

You don’t. You work with the leadership & security team. Any employee that clicks your phishing email gets an extra dose of security training. Those that forward the email to abuse@corp.com get a nice compliment

Just clicking the link is enough to fail? No need to enter private info or execute downloaded files? Either your phising emails are badly crafted or you expect employees to see the future.

Megacorp I work at does this. I think I've had around 1 phishing mail per month for the last year or so, and yes, just clicking the link is enough to fail.

It's particularly annoying where I work, as the company itself sends out a completely unreasonable amount of internal spam every.single.day - often with bad spelling/grammar, and very often with the contents being a single image with rendered text (why?!?!).

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#302

Earlier quoted context omitted.

It’s not so much that they banned umn email, as it is they banned the university of Minnesota. This particular act is about avoiding the risk of researchers wasting kernel developers time. As evinced by the response, it seems really unlikely that other institutions would think it’s a good idea to perform experiments on the kernel devs in the future.

Most of the reverted commits are fine by inspection and the researched insist there were 3 hypocrite submissions that didn’t get merged. So the idea is to collectively punish the mostly innocent people who wrote the 190 good commits, spending a huge amount of developer time checking them or losing the fixes to prevent other institutions from doing this? Does reverting nearly 200 good patches seem out of proportion re…

That’s a fair question about proportionality.

I don’t have any special insight into the kernel team, but I think the response is as much about making an example of the university as it is about removing any plausibly contaminated commits, in which case it makes sense to be somewhat extreme.

Others are saying the entire research team should be fired.

It’s interesting that the former (reverting the commits) is something the kernel devs can do to publish the university, while the latter (firing researchers) is something the university can do to punish the researchers.

Who messed up? The researchers or the university who approved their research?

Probably enough blame to go around.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#304
post #96

Earlier quoted context omitted.

> the response of some corporations when security vulnerabilities are disclosed There's a big ethical difference between trying to exploit a piece of commercially produced software, and trying to exploit the time and actions of humans who are producing software which is given away for free.

Also, this wasn’t a vulnerability found in existing code that was disclosed. This was an attempt to introduce several of them in the form of innocent looking commits. I don’t think the free vs commercial aspect is the main issue here; lots of kernel devs are paid for their work after all...

> Also, this wasn’t a vulnerability found in existing code that was disclosed.

You're right that the OP's analogy breaks down if the researchers were unsuccessful in getting their malicious patches accepted, because then there is arguably no vulnerability to report, and OP said "when security vulnerabilities are disclosed".

Steelmanning that analogy, though, what the researchers were doing was "probing for possible vulnerabilities", which some vendors also complain about, especially if the target is an online service rather than software running locally on the researcher's machine.

In that case, the main flaw in the analogy is still the difference between exploiting software and exploiting humans, so I probably should have focused on that. Nevertheless, there is a small ethical difference in some circumstances between software that is bought and software which is freely downloadable (regardless of the licences involved), since if you paid for something which is defective then you might deserve a refund.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#305

Earlier quoted context omitted.

You don’t. You work with the leadership & security team. Any employee that clicks your phishing email gets an extra dose of security training. Those that forward the email to abuse@corp.com get a nice compliment

Just clicking the link is enough to fail? No need to enter private info or execute downloaded files? Either your phising emails are badly crafted or you expect employees to see the future.

> Just clicking the link is enough to fail?

Yes, clicking on links is dangerous[0].

0. https://www.bleepingcomputer.com/news/security/google-fixes-...

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#306

There is a major error made by the research group. It starts and ends here: "we did that because we knew we could not ask the maintainers of Linux for permission, or they would be on the lookout for the hypocrite patches." I am a Red Teamer and work with companies to understand how their detective/preventative/recovery controls and processes are working. Here's how you resolve this: You work with maintainers to get t…

Great plan. Agree with all. Thanks.

In your experience, do you create a "fail safe"?

So for this study, some way for the researchers to prevent any of their patches from ever being released.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#307

Earlier quoted context omitted.

Most of the reverted commits are fine by inspection and the researched insist there were 3 hypocrite submissions that didn’t get merged. So the idea is to collectively punish the mostly innocent people who wrote the 190 good commits, spending a huge amount of developer time checking them or losing the fixes to prevent other institutions from doing this? Does reverting nearly 200 good patches seem out of proportion re…

That’s a fair question about proportionality. I don’t have any special insight into the kernel team, but I think the response is as much about making an example of the university as it is about removing any plausibly contaminated commits, in which case it makes sense to be somewhat extreme. Others are saying the entire research team should be fired. It’s interesting that the former (reverting the commits) is somethin…

Proportionality is one aspect.

Punishing the right people is another.

If you’re an UMN patch submitter who has just seen your work thrown away because of the actions of some researchers you don’t know and some kernel maintainer you don’t know, you’d be rightly upset.

Punishing the entire university for the actions of a few. I think it’s a bad idea: https://en.m.wikipedia.org/wiki/Collective_punishment

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#309

Earlier quoted context omitted.

How extremely easy it is for a nation state or other malicious actor to intentionally introduce bugs.

Was there ever any doubt?

Perhaps not, but was it on people's radar as much as it is as a consequence of this event?

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#310

There are some relatively minor issues with this apology that appear to already have ample discussion here, and I'll not repeat it. I want something more: I want to hear from the sponsoring faculty, research ethics board, and editors of the journal that published the article. There appear to be some systemic issues in addition to the investigators' ill-considered project. How was it that this research, which is clear…

Another query about IRB and human subjects: In the case of software which is not only written/maintained by a community of humans, but used by a (vast) community of humans, do the latter also become "human subjects" as well in such an experiment?
Post reply on HN