Live data from Hacker News

Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

phoronix.com

11–20 of 121 posts

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#11
post #4

Earlier quoted context omitted.

"ALL the proposals that were intentionally vulnerable and were really vulnerabilities were not accepted" The thing is there is no way you can actually know that. So this is not some kind of revenge. This is rather a valid precaution.

>The thing is there is no way you can actually know that. We do know since the researchers have told the linux community, the university and IEEE what those patches where. Please do not spread further misinformation about the case. Please read the IEEE statement and the full Linux TAB review. https://www.ieee-security.org/TC/SP2021/downloads/2021_PC_St... https://lkml.org/lkml/2021/5/5/1244

Not trying to badmouth the university here, but having to trust the statement of those who broke your trust in the first place doesn't meet my definition of "knowing" something.

Maybe "believe" would be better used here? Knowing would mean to know precisely what each of these changes does and whether they open up new vulnerabilities and then having confidence that all is well. Gaining this confidence requires work. And unless you put that work in, you are left to trusting/believing.

(Edit: what I mean here is that the researchers could be totally nice and ethical people, but the Linux devs would still have to either take a risk by trusting them OR put in the work to check it all OR decide not to put in that work)

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#12
post #8
post #4

Earlier quoted context omitted.

>The thing is there is no way you can actually know that. We do know since the researchers have told the linux community, the university and IEEE what those patches where. Please do not spread further misinformation about the case. Please read the IEEE statement and the full Linux TAB review. https://www.ieee-security.org/TC/SP2021/downloads/2021_PC_St... https://lkml.org/lkml/2021/5/5/1244

Well, apparently they needed the bad publicity and "overreaction" to actually do that. The fact that they didn't communicate _clearly_ with the kernel about exactly which patches this was about at the time when they announced their paper is extremely icky, and makes my sympathy for later misunderstandings/misinformation very limited.

The entire incident has been disappointing.

The researchers conducting the research thinking this was a good idea, the IRB review process at the UMN, IEEE accepting the IRB exception after ethical concerns where raised, and the overreaction from gregkh on the LKML.

Hopefully there is a silver lining and we see better research collaboration between the kernel devs and researchers going forward. IEEE has a job to do around all of this going forward.

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#13
post #5
post #4

Earlier quoted context omitted.

>The thing is there is no way you can actually know that. We do know since the researchers have told the linux community, the university and IEEE what those patches where. Please do not spread further misinformation about the case. Please read the IEEE statement and the full Linux TAB review. https://www.ieee-security.org/TC/SP2021/downloads/2021_PC_St... https://lkml.org/lkml/2021/5/5/1244

Ah, so we're just supposed to trust the same people who tried introducing the vulnerabilities in the first place...

That's exactly the opposite of what the initial comment of this thread suggests.

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#14
post #6
post #4

Earlier quoted context omitted.

>The thing is there is no way you can actually know that. We do know since the researchers have told the linux community, the university and IEEE what those patches where. Please do not spread further misinformation about the case. Please read the IEEE statement and the full Linux TAB review. https://www.ieee-security.org/TC/SP2021/downloads/2021_PC_St... https://lkml.org/lkml/2021/5/5/1244

"Please do not spread further misinformation about the case." Let's assume that most people are giving their opinions to their best knowledge. We shall be careful when telling someone to stop spreading misinformation as this is how fascism starts. "I am right, you are wrong, stop talking!"

[deleted]

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#15
post #8

Earlier quoted context omitted.

Well, apparently they needed the bad publicity and "overreaction" to actually do that. The fact that they didn't communicate _clearly_ with the kernel about exactly which patches this was about at the time when they announced their paper is extremely icky, and makes my sympathy for later misunderstandings/misinformation very limited.

The entire incident has been disappointing. The researchers conducting the research thinking this was a good idea, the IRB review process at the UMN, IEEE accepting the IRB exception after ethical concerns where raised, and the overreaction from gregkh on the LKML. Hopefully there is a silver lining and we see better research collaboration between the kernel devs and researchers going forward. IEEE has a job to do ar…

> the overreaction from gregkh on the LKML

I don't think it was an overreaction. I think it was a very valid reaction.

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#16
post #4

Earlier quoted context omitted.

"ALL the proposals that were intentionally vulnerable and were really vulnerabilities were not accepted" The thing is there is no way you can actually know that. So this is not some kind of revenge. This is rather a valid precaution.

>The thing is there is no way you can actually know that. We do know since the researchers have told the linux community, the university and IEEE what those patches where. Please do not spread further misinformation about the case. Please read the IEEE statement and the full Linux TAB review. https://www.ieee-security.org/TC/SP2021/downloads/2021_PC_St... https://lkml.org/lkml/2021/5/5/1244

I just read that IEEE statement, I'm glad someone else has started noticing the paper was bullshit in addition to unethical:

> Investigation of these patches revealed that the description provided by the authors in the paper is ambiguous and in some cases misleading. The experiments do not provide convincing evidence to substantiate the main claims in the paper and the technical contributions of the work need to be revisited.

Interesting that they list ethical considerations added to the review process, but are not adding content quality considerations to the review process. I think that's at least as embarrassing to PC. You can say that they erred in assuming the uni covered the ethics review, but what are they doing if they're accepting papers without checking that the papers support their own claims?

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#18

Earlier quoted context omitted.

The entire incident has been disappointing. The researchers conducting the research thinking this was a good idea, the IRB review process at the UMN, IEEE accepting the IRB exception after ethical concerns where raised, and the overreaction from gregkh on the LKML. Hopefully there is a silver lining and we see better research collaboration between the kernel devs and researchers going forward. IEEE has a job to do ar…

> the overreaction from gregkh on the LKML I don't think it was an overreaction. I think it was a very valid reaction.

There are a few issues with blaming someone for sending known malicious patches which just causes confusion and is outright wrong. Brad Spengler is a... character, but I do agree with him that greg started out on this wrong. (He also goes a bit further with his criticism that I don't agree with).

However yes, review of the patches was proper but all this could have been done with less unfounded accusations from gregs side.

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#19
post #4

Earlier quoted context omitted.

"ALL the proposals that were intentionally vulnerable and were really vulnerabilities were not accepted" The thing is there is no way you can actually know that. So this is not some kind of revenge. This is rather a valid precaution.

>The thing is there is no way you can actually know that. We do know since the researchers have told the linux community, the university and IEEE what those patches where. Please do not spread further misinformation about the case. Please read the IEEE statement and the full Linux TAB review. https://www.ieee-security.org/TC/SP2021/downloads/2021_PC_St... https://lkml.org/lkml/2021/5/5/1244

> We do know since the researchers have told the linux community

Replace researchers with hackers, CIA, North Korea, China, etc. Do you still have the warm fuzzies?

The fact of the matter is they broke the trust and your expectation is that since they've been exposed they can be trusted again?

No, if anything the event has shown that additional vetting and layers of scrutiny might be needed to protect against bad actors in the future should they be malicious.

* I type good.

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#20
post #11
post #4

Earlier quoted context omitted.

>The thing is there is no way you can actually know that. We do know since the researchers have told the linux community, the university and IEEE what those patches where. Please do not spread further misinformation about the case. Please read the IEEE statement and the full Linux TAB review. https://www.ieee-security.org/TC/SP2021/downloads/2021_PC_St... https://lkml.org/lkml/2021/5/5/1244

Not trying to badmouth the university here, but having to trust the statement of those who broke your trust in the first place doesn't meet my definition of "knowing" something. Maybe "believe" would be better used here? Knowing would mean to know precisely what each of these changes does and whether they open up new vulnerabilities and then having confidence that all is well. Gaining this confidence requires work. A…

[deleted]
Post reply on HN