Live data from Hacker News

Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

phoronix.com

91–100 of 121 posts

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#91
post #23

Just from a code quality process standpoint, that’s an interesting result. Now I’m wondering what would happen if you picked a set of 150 random kernel patches and told 80 reviewers to re-review them assuming they could be malicious. I bet you’d find quite a few fixes.

This would be an interesting study.

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#92

Earlier quoted context omitted.

I just read that IEEE statement, I'm glad someone else has started noticing the paper was bullshit in addition to unethical: > Investigation of these patches revealed that the description provided by the authors in the paper is ambiguous and in some cases misleading. The experiments do not provide convincing evidence to substantiate the main claims in the paper and the technical contributions of the work need to be r…

Err the PC is already supposed to vet for quality. That they failed to do so adequately is not because the policies omitted that requirement, but probably more because Oakland receives many many submissions

[deleted]

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#93

Earlier quoted context omitted.

The sort of reaction an emperor has upon finding their shiny new clothes don't actually exist. It's bad the tailors sold fake clothes, but it's also bad the emperor and co. didn't notice sooner. Here we saw the emperor go on a full war path against the entire place of origin of a couple of misguided individuals. Not a proportionate response.

Institutional Review Board dropped the ball and failed at their job. Which reflects on the institution. It's not just about individuals.

Eh, maybe, but at the same time, I kind of got the feeling that the researchers were treating the IRB as one more layer of security to get around.

The IRB is a gatekeeper, yes, but it is also a resource. You should be working with the IRB to make sure everything you are doing is above the board, because ultimately, if you do something unethical or harmful to individuals or society, that's still on you, even if you got your plan stamped by the IRB. You shouldn't have an antagonistic relationship where you use the vague and technically accurate but misleading descriptions of your research an an attempt to get a "get out of consequences free" card.

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#94
post #72

The guilt by association here is now approaching Biblical scales. Like the guy in the comments who wants to close down the entire Computer Science and Electrical Engineering departments at UMN, which probably employ/educate the best part of a thousand people. Ha! In general, the fury and seethe which this experiment inspired is amazing. IMO the real disgrace is not the experiment itself, but the response. The kernel…

They lied in their abstract [0], they lied to their IRB, and Kangjie Lu's aspirations have been wasting a lot of Linux maintainer time. The real disgrace was the experiment. The response was fairly natural for humans with imperfect information being experimented on. Please be more specific. How do you think the Linux kernel maintainers should improve their procedures to prevent clownshows like this in the future? No…

I just don't understand why open source software can continue with the assumption that every single contributor is honest. Imagine if this philosophy was applied to, say, cryptography or network security. What would be the state of encryption algorithms and key exchange protocols and so on, if their developers had a meltdown at the mere suggestion of there existing a liar?

Since the Linux kernel is installed on many millions of computers, it is obviously pretty important that it doesn't have bugs in it. Certainly not malicious bugs. And if all it takes is a couple grad students and an assistant prof to get them in...well, that reflects very poorly on the state of kernel maintenance, to me. Which seems far more important and deserving of attention, than endlessly arraigning three clueless guys at some university.

I'm not in a position to be more specific about what should be fixed. But, what would your answer be to your query? Apparently, do nothing, and assume that everyone in the world is honest, while writing self-indulgent "public letters" about it? How is that going to help when the CCP tries to insert surveillance into the kernel? Or when Russian hackers try to get exploits and ransomware in there?

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#95
post #74
post #48

Earlier quoted context omitted.

Is it forbidden to do mistakes? In such cases is it a good idea to respond to your colleagues with "Please stop doing mistakes!" as the parent did?

No, but it may be reasonable to ask 'please do not repeat this particular mistake'

But in the particular case, the discussion centers around a matter of opinion on "should trust be extended to this particular set of statements from a known deciever".

Throwing around accusations of spreading misinformation to further your opinion in an argument makes it harder to call out real misinformation.

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#96
post #47

The guilt by association here is now approaching Biblical scales. Like the guy in the comments who wants to close down the entire Computer Science and Electrical Engineering departments at UMN, which probably employ/educate the best part of a thousand people. Ha! In general, the fury and seethe which this experiment inspired is amazing. IMO the real disgrace is not the experiment itself, but the response. The kernel…

Most maintainers are volunteer, meaning that they spend their evenings, weekends and holidays developing the kernel because they like it, it gives them a sense of worth and fulfillment that can be hard to come across. I don't know if you've ever talked to one, but they take a real pride in their work, most make a pitiful salary in comparison to FAANG levels but they still do it because it is full of interesting chall…

I don't dispute that the researchers were dishonest and broke the trust of the kernel maintainers. So they can be a bit peeved off at UMN. But is this sort of thing not the reality of their operation? That liars exist in the world? I don't really see what the volunteer part has to do with it. If anything it means they have less to complain about. I mean...most soldiers are volunteers, which would make it even more absurd, if someone signed up to be a soldier, and then whined and complained when enemy soldiers shot at him. It seems equally obvious to me, that an open network should be assumed to have malicious actors on it, as that a battlefield should be assumed to have enemies on it. Obviously you don't have to like the enemies.

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#97
post #72

Earlier quoted context omitted.

They lied in their abstract [0], they lied to their IRB, and Kangjie Lu's aspirations have been wasting a lot of Linux maintainer time. The real disgrace was the experiment. The response was fairly natural for humans with imperfect information being experimented on. Please be more specific. How do you think the Linux kernel maintainers should improve their procedures to prevent clownshows like this in the future? No…

I just don't understand why open source software can continue with the assumption that every single contributor is honest. Imagine if this philosophy was applied to, say, cryptography or network security. What would be the state of encryption algorithms and key exchange protocols and so on, if their developers had a meltdown at the mere suggestion of there existing a liar? Since the Linux kernel is installed on many…

> assumption that every single contributor is honest.

There is no such assumption and it has been well known for a long time that such an assumption would be harmful.

> if all it takes is a couple grad students and an assistant prof to get them in

There were 0 malicious commits that made it through the review process (since the paper was incompetent as well as unethical.)

You seem to be missing some basic facts here. Filling in those gap would help you partipate more productively in the conversation.

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#98
post #72

Earlier quoted context omitted.

They lied in their abstract [0], they lied to their IRB, and Kangjie Lu's aspirations have been wasting a lot of Linux maintainer time. The real disgrace was the experiment. The response was fairly natural for humans with imperfect information being experimented on. Please be more specific. How do you think the Linux kernel maintainers should improve their procedures to prevent clownshows like this in the future? No…

I just don't understand why open source software can continue with the assumption that every single contributor is honest. Imagine if this philosophy was applied to, say, cryptography or network security. What would be the state of encryption algorithms and key exchange protocols and so on, if their developers had a meltdown at the mere suggestion of there existing a liar? Since the Linux kernel is installed on many…

> I just don't understand why open source software can continue with the assumption that every single contributor is honest

It doesn't. They've been on the lookout since before 2003: https://lwn.net/Articles/57135/ (there are other examples, this is just the earliest I know of)

> Apparently, do nothing, and assume that everyone in the world is honest, while writing self-indulgent "public letters" about it?

This sounds overly dramatic which makes discussion difficult. My answer would be that the kernel maintainers have known about this threat vector for a very long time and seem to be doing a reasonable job of repelling it.

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#99
post #74
post #48

Earlier quoted context omitted.

Is it forbidden to do mistakes? In such cases is it a good idea to respond to your colleagues with "Please stop doing mistakes!" as the parent did?

No, but it may be reasonable to ask 'please do not repeat this particular mistake'

Did you ever say such thing to someone who committed an error? How would you feel if someone (your partner, your colleague, your boss) told you such thing?

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#100
post #47

Earlier quoted context omitted.

Most maintainers are volunteer, meaning that they spend their evenings, weekends and holidays developing the kernel because they like it, it gives them a sense of worth and fulfillment that can be hard to come across. I don't know if you've ever talked to one, but they take a real pride in their work, most make a pitiful salary in comparison to FAANG levels but they still do it because it is full of interesting chall…

I don't dispute that the researchers were dishonest and broke the trust of the kernel maintainers. So they can be a bit peeved off at UMN. But is this sort of thing not the reality of their operation? That liars exist in the world? I don't really see what the volunteer part has to do with it. If anything it means they have less to complain about. I mean...most soldiers are volunteers, which would make it even more ab…

Trust is not a binary.

You must trust contributors to your project to some extent. If you don't extend some trust, you can't have contributors. That level of trust is then adjusted off that base level based on experience.

It is perfectly reasonable to drop someone below your base level of trust if they lie to you. This doesn't necessarily mean that the base level of trust needs to be adjusted.

In this case, the review process caught all the known harmful commits (which were from anonymous emails so recieved base level trust) and thus the base line level of trust seems to be working.

Post reply on HN