> We just want you to know that we would never intentionally hurt the Linux kernel community and never introduce security vulnerabilities. Our work was conducted with the best of intentions and is all about Uhh.. but that was the exact intent of the paper. And they did it successfully. So.. mission failed successfully? What a bizarre attempt to save-face. This is academic misconduct and they're trying to save their a…
Obviously the intent was never to introduce security vulnerabilities, no matter how naive and badly thought-out their methodology was. The intent was to show it could be done. None of the proposed vulnerabilities ever got in the kernel, whenever they were at risk of being accepted, the maintainer was warned and the process was aborted.
Open letter from researchers involved in the “hypocrite commit” debacle
341–350 of 384 posts
Re: Open letter from researchers involved in the “hypocrite commit” debacle
#342Earlier quoted context omitted.
So? The difference is consent (in your case of the owners of the company). There are many crimes in the world that are only crimes if you do it without consent. > How else do you prove your process can stop real infiltrators by state actors? One of the common security controls against infiltration by foreign nation states is espionage being a capital offense. Well obviously not appropriate, i think that its pretty ob…
So if we get consent from a C-level at a company, we don't need consent from every other lower level person we trick? If you have approval from one person in an org of 100,000 is this still okay? It has to be, because getting explicit consent from every person in the org at that size would be untenable, and make them artificially extra vigilant during a potential audit window. Well now scale this to open source. The…
You have to get consent from someone who has legal authority to give it to you.
> If every white hat has to get permission from exponentially large dependency chains
They don't. They just have to get permission from someone in authority. Different open source projects have different governance structures. Sometimes that is a single person.
> The blackhats set the rules of engagement, for better or worse. White hats should be free to go for it just like with any other vulnerability they evaluate.
If you are hacking someone elses system without their consent (not to mention for your own personal gain), you are a blackhat. By definition. Pretending to be a researcher doesn't change that.
Re: Open letter from researchers involved in the “hypocrite commit” debacle
#343Earlier quoted context omitted.
An apology should be for actions taken, not for how the other party felt about it. Acknowledging those feelings is important, but taking credit for those feelings takes agency away from the other person.
I don’t think that really makes sense. Often in a personal relationship the “action taken” will be innocuous considered in itself. But you may have done it knowing full well that it would hurt the other person’s feelings. In a case where the person’s feelings are totally irrational and you had a strong independent justification for taking the action, it does get more complicated. In general, though, I think it’s a hu…
Regardless, you can't genuinely apologize for things that aren't in your control. (You can and should empathize and sympathize with their feelings about it.) It may be a convenient fiction at times, but there are many downsides to this type of boundary blurring. I think you do the recipient a disservice by implying they have no agency—especially if they believe you. You also face the danger that your apology seems insincere or you misjudged their feelings, which could actually make matters worse.
Re: Open letter from researchers involved in the “hypocrite commit” debacle
#344Earlier quoted context omitted.
> It does not come across as apologetic. The words are there. It's not up to us to decide if they're "genuine". No one's a mindreader. The tendency to view apologies as fake seems more often to reflect how harshly we view the one making it.
Their opening statement has the most classic of all non-apology tactics: "We're sorry for any harm we caused". Maybe this wasn't their intent, but this is one of the oldest "say the words without having to mean anything" tactics in the book. It's like telling your partner "I'm sorry if I hurt you". No, you hurt them. Apologize for hurting them.
The phrasing is such that it acknowledges harm was done. It's an apology, full-stop.
Re: Open letter from researchers involved in the “hypocrite commit” debacle
#345Earlier quoted context omitted.
> It does not come across as apologetic. The words are there. It's not up to us to decide if they're "genuine". No one's a mindreader. The tendency to view apologies as fake seems more often to reflect how harshly we view the one making it.
You don't have to be a mind reader to see that this apology isn't an apology. They spend as much time justifying their actions as they do apologizing for the unintended outcomes, and they close by complaining that they've also been hurt.
Re: Open letter from researchers involved in the “hypocrite commit” debacle
#346Earlier quoted context omitted.
> It does not come across as apologetic. The words are there. It's not up to us to decide if they're "genuine". No one's a mindreader. The tendency to view apologies as fake seems more often to reflect how harshly we view the one making it.
Apologies are really difficult to do. You have to acknowledge (in full) what it is that you are apologising for. That's the most important thing. Promises are meaningless. It's not possible to "be genuine"; especially in a public post, nothing is genuine, everything is PR and smoke. Both the researchers and their ethics board need to grovel. If they did that, this tornado-in-a-teacup could be over in a month or two.…
Re: Open letter from researchers involved in the “hypocrite commit” debacle
#347Will they review incoming patches more carefully going forward?
Re: Open letter from researchers involved in the “hypocrite commit” debacle
#348Earlier quoted context omitted.
It’s a good observation. So for example we have a 2019 commit by Wenwen Wang being reverted. Wenwen is now at UGA. The commit is “ALSA: usx2y fix a double free bug” review by Takashi Iwai confirms it’s a good fix. I don’t agree with Greg K-H threatening to trash Wenwen’s work, his reputation, and add bugs to the Linux kernel out of spite toward researchers than Wenwen hasn’t worked with in years. Note that Aditya Pak…
The complaints, depending on who you were listening to, were that the patches were superfluous (cf. [1], where Aditya apparently later claimed "The patch is garbage") or contained security flaws (cf. [2] for one such allegation) , whether deliberate or accidental, and that too many of them had been accepted without enough review by dint of being "trivial fixes". (One claim, for example, was "I took a look on 4 accept…
In the end, we largely agree.
It is exactly the accusation of malice when what occurred was normal error that deserves an apology. You teased that out well.
As you note, we don’t have certainty. But we observe:
Aditya is not an author on the hypocrite commits paper.
Aditya withdrew his “garbage” commit when made aware it was not correct.
Aditya is author of other papers on static analysis.
Aditya’s other commits have generally survived this bulk review. Leon Romanovksy has offered no follow up for his claim of security holes nor explained his claim that the commits are part of the hypocrite commits research.
Aditya maintains his claims even as other members of UMN have explained their role in the hypocrite commits.
Aditya’s commits come from a UMN address where as hypocrite commits came from gmail.
These observations make it overwhelmingly likely that Aditya’s commits are from a good faith somewhat buggy static analysis effort.
This poor guy has worked for years on the Linux kernel and Greg Kroah-Hartman’s thoughtless rush to judgement threatened all that effort. Greg should apologize. Leon Romanovksy should too.
They mixed up and couple things and got carried away by their emotions. It happens. They should work to undo the damage.
Re: Open letter from researchers involved in the “hypocrite commit” debacle
#349Earlier quoted context omitted.
The complaints, depending on who you were listening to, were that the patches were superfluous (cf. [1], where Aditya apparently later claimed "The patch is garbage") or contained security flaws (cf. [2] for one such allegation) , whether deliberate or accidental, and that too many of them had been accepted without enough review by dint of being "trivial fixes". (One claim, for example, was "I took a look on 4 accept…
Great detailed specific reply. In the end, we largely agree. It is exactly the accusation of malice when what occurred was normal error that deserves an apology. You teased that out well. As you note, we don’t have certainty. But we observe: Aditya is not an author on the hypocrite commits paper. Aditya withdrew his “garbage” commit when made aware it was not correct. Aditya is author of other papers on static analys…
It seems like he withdrew it in response to stumbling over [2], wherein Al Viro points out that the correct thing to do with buggy commits is to request they be reverted. (Based on, among other things, the fact that said LWN post is cited in the revert.)
> Leon Romanovksy has offered no follow up for his claim of security holes nor explained his claim that the commits are part of the hypocrite commits research.
He did offer the patch I cited as "[2]" in my prior reply, as well as pointing out [1] the commit where they reworked the buggy logic from it.
One commit does not a sinner make, but it's not correct to say he offered no data.
> They mixed up and couple things and got carried away by their emotions.
I'm not the biggest fan of GregKH for other reasons [3], but other than maybe explicitly requiring and verifying a list of broken commits beforehand, I'm not sure what I would have wanted him to do differently. If you have prior reason to suspect a group of behaving maliciously, and someone you trust attests that they appear to have behaved maliciously, what do you do differently? "I promise I'm not part of that research" doesn't work if you think the group might lie, and as I've pointed out other times, the only ones caught in the temporary patch removal were members of the relevant lab, and I further claim that "patches temporarily removed for re-examining" is not that severe a punishment.
[1] - https://lore.kernel.org/linux-nfs/YIMDCNx4q6esHTYt@unreal/
Re: Open letter from researchers involved in the “hypocrite commit” debacle
#350Earlier quoted context omitted.
Great detailed specific reply. In the end, we largely agree. It is exactly the accusation of malice when what occurred was normal error that deserves an apology. You teased that out well. As you note, we don’t have certainty. But we observe: Aditya is not an author on the hypocrite commits paper. Aditya withdrew his “garbage” commit when made aware it was not correct. Aditya is author of other papers on static analys…
> Aditya withdrew his “garbage” commit when made aware it was not correct. It seems like he withdrew it in response to stumbling over [2], wherein Al Viro points out that the correct thing to do with buggy commits is to request they be reverted. (Based on, among other things, the fact that said LWN post is cited in the revert.) > Leon Romanovksy has offered no follow up for his claim of security holes nor explained h…
Fair point. Not sure what became of the other alleged security holes.
> "I promise I'm not part of that research"
This is a gross oversimplification of the evidence that Aditya is not malicious.
I offered a lot of evidence above that Aditya is likely not malicious just clumsy.
The lwn post you pointed to reaches the same conclusion “ I am quite certain by now that patches had been crap in good faith; the odds of that being the penetration testing, take 2, are IMO very low.”
So possible that Greg wrongly judged Aditya based on trusting Leon or other bad reasoning. Fine.
Now it’s abundantly clear the Aditya was not making malicious commits and Greg should apologize to him for the false accusation.