Live data from Hacker News

Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

phoronix.com

71–80 of 121 posts

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#71

Earlier quoted context omitted.

> the overreaction from gregkh on the LKML I don't think it was an overreaction. I think it was a very valid reaction.

The sort of reaction an emperor has upon finding their shiny new clothes don't actually exist. It's bad the tailors sold fake clothes, but it's also bad the emperor and co. didn't notice sooner. Here we saw the emperor go on a full war path against the entire place of origin of a couple of misguided individuals. Not a proportionate response.

Institutional Review Board dropped the ball and failed at their job. Which reflects on the institution. It's not just about individuals.

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#72

The guilt by association here is now approaching Biblical scales. Like the guy in the comments who wants to close down the entire Computer Science and Electrical Engineering departments at UMN, which probably employ/educate the best part of a thousand people. Ha! In general, the fury and seethe which this experiment inspired is amazing. IMO the real disgrace is not the experiment itself, but the response. The kernel…

They lied in their abstract [0], they lied to their IRB, and Kangjie Lu's aspirations have been wasting a lot of Linux maintainer time.

The real disgrace was the experiment. The response was fairly natural for humans with imperfect information being experimented on.

Please be more specific. How do you think the Linux kernel maintainers should improve their procedures to prevent clownshows like this in the future? No points for mentioning things that they already do or assuming infinite maintainer hours.

[0]: https://twitter.com/SarahJamieLewis/status/13848760502079406...

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#73
post #53

Earlier quoted context omitted.

Agreed. As I mentioned in an earlier thread on this scandal, [0] we already know that security bugs can make their way into the kernel. [0] https://news.ycombinator.com/item?id=26888129

Check out my groundbreaking research. I smashed windows on 20 buildings and took cash out of their registers. In order to fix this vulnerability, I suggest you make everyone who passes by your building sign this piece of paper saying they won't smash your windows and take your money. I will happily receive your nearest Nobel prize now, thank you. Signed, UMN Researchers. Edit: Wait, the cops are here. We sincerely ap…

Related: there's a reason the Certified Ethical Hacker course places such emphasis on getting written permission before doing anything.

If you're messing with someone's systems, or (as in this case) with someone's processes, you don't get to claim to be the good guy unless they agreed to it before the fact. It's not rocket science.

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#74
post #48
post #42

Earlier quoted context omitted.

Even when people are giving their opinions to their best knowledge they can be spreading misinformation.

Is it forbidden to do mistakes? In such cases is it a good idea to respond to your colleagues with "Please stop doing mistakes!" as the parent did?

No, but it may be reasonable to ask 'please do not repeat this particular mistake'

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#77
post #64

Earlier quoted context omitted.

> Maybe it's a pipe dream, but I have a feeling it could lead to discussions of "what could we have done to catch this automatically," which in turn would lead to better static analysis tools. It did do that, at least twenty years ago. Static analysis tooling is a huge, active area of research and the kernel is frequently a target of that research. Ditto for other areas like language development (see the recent work…

To be clear, I 100% understand the harsh reaction. If anything I think they were lucky no criminal charges were pressed.

Yeah. I'm not trying to come down hard on you or anything, I just feel like a common reaction to this research is, "ethics aside, didn't they point out a real vulnerability?" And I want to make it crystal clear that, no, they didn't. Their research was entirely without value.

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#79

What is really sad, is that this could be a good pen-test for the kernel. Especially the idea of introducing bugs that are only vulnerabilities when they all come in together. If only they had contacted the Linux Foundation ahead of time to get permission, and set up terms, like a real pen-test. Then work could be done on detecting, and preventing these sorts of attacks, maybe resulting in a system that could help ev…

The stated motivations of the researchers make it seem like they are not interested in advancing the security of open source software, but rather undermining it.

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#80

What is really sad, is that this could be a good pen-test for the kernel. Especially the idea of introducing bugs that are only vulnerabilities when they all come in together. If only they had contacted the Linux Foundation ahead of time to get permission, and set up terms, like a real pen-test. Then work could be done on detecting, and preventing these sorts of attacks, maybe resulting in a system that could help ev…

Why would the Linux Foundation get to decide on if those researchers are allowed to experiment on and waste the time of volunteer developers?

I think it depends on how you frame it. If the Linux Foundation thinks this kind of research would generate useful information for the kernel project, then the developers' time wouldn't be wasted, just used in a different, yet productive, way. I concede that this is not an easy question, because the developers may have different opinions about the usefulness of this exercise, but at the end of the day, maintainers can run their projects how they see fit.
Post reply on HN