Just from a code quality process standpoint, that’s an interesting result. Now I’m wondering what would happen if you picked a set of 150 random kernel patches and told 80 reviewers to re-review them assuming they could be malicious. I bet you’d find quite a few fixes.
Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches
91–100 of 121 posts
Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches
#92Earlier quoted context omitted.
I just read that IEEE statement, I'm glad someone else has started noticing the paper was bullshit in addition to unethical: > Investigation of these patches revealed that the description provided by the authors in the paper is ambiguous and in some cases misleading. The experiments do not provide convincing evidence to substantiate the main claims in the paper and the technical contributions of the work need to be r…
Err the PC is already supposed to vet for quality. That they failed to do so adequately is not because the policies omitted that requirement, but probably more because Oakland receives many many submissions
Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches
#93Earlier quoted context omitted.
The sort of reaction an emperor has upon finding their shiny new clothes don't actually exist. It's bad the tailors sold fake clothes, but it's also bad the emperor and co. didn't notice sooner. Here we saw the emperor go on a full war path against the entire place of origin of a couple of misguided individuals. Not a proportionate response.
Institutional Review Board dropped the ball and failed at their job. Which reflects on the institution. It's not just about individuals.
The IRB is a gatekeeper, yes, but it is also a resource. You should be working with the IRB to make sure everything you are doing is above the board, because ultimately, if you do something unethical or harmful to individuals or society, that's still on you, even if you got your plan stamped by the IRB. You shouldn't have an antagonistic relationship where you use the vague and technically accurate but misleading descriptions of your research an an attempt to get a "get out of consequences free" card.
Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches
#94The guilt by association here is now approaching Biblical scales. Like the guy in the comments who wants to close down the entire Computer Science and Electrical Engineering departments at UMN, which probably employ/educate the best part of a thousand people. Ha! In general, the fury and seethe which this experiment inspired is amazing. IMO the real disgrace is not the experiment itself, but the response. The kernel…
They lied in their abstract [0], they lied to their IRB, and Kangjie Lu's aspirations have been wasting a lot of Linux maintainer time. The real disgrace was the experiment. The response was fairly natural for humans with imperfect information being experimented on. Please be more specific. How do you think the Linux kernel maintainers should improve their procedures to prevent clownshows like this in the future? No…
Since the Linux kernel is installed on many millions of computers, it is obviously pretty important that it doesn't have bugs in it. Certainly not malicious bugs. And if all it takes is a couple grad students and an assistant prof to get them in...well, that reflects very poorly on the state of kernel maintenance, to me. Which seems far more important and deserving of attention, than endlessly arraigning three clueless guys at some university.
I'm not in a position to be more specific about what should be fixed. But, what would your answer be to your query? Apparently, do nothing, and assume that everyone in the world is honest, while writing self-indulgent "public letters" about it? How is that going to help when the CCP tries to insert surveillance into the kernel? Or when Russian hackers try to get exploits and ransomware in there?
Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches
#95Earlier quoted context omitted.
Is it forbidden to do mistakes? In such cases is it a good idea to respond to your colleagues with "Please stop doing mistakes!" as the parent did?
No, but it may be reasonable to ask 'please do not repeat this particular mistake'
Throwing around accusations of spreading misinformation to further your opinion in an argument makes it harder to call out real misinformation.
Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches
#96The guilt by association here is now approaching Biblical scales. Like the guy in the comments who wants to close down the entire Computer Science and Electrical Engineering departments at UMN, which probably employ/educate the best part of a thousand people. Ha! In general, the fury and seethe which this experiment inspired is amazing. IMO the real disgrace is not the experiment itself, but the response. The kernel…
Most maintainers are volunteer, meaning that they spend their evenings, weekends and holidays developing the kernel because they like it, it gives them a sense of worth and fulfillment that can be hard to come across. I don't know if you've ever talked to one, but they take a real pride in their work, most make a pitiful salary in comparison to FAANG levels but they still do it because it is full of interesting chall…
Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches
#97Earlier quoted context omitted.
They lied in their abstract [0], they lied to their IRB, and Kangjie Lu's aspirations have been wasting a lot of Linux maintainer time. The real disgrace was the experiment. The response was fairly natural for humans with imperfect information being experimented on. Please be more specific. How do you think the Linux kernel maintainers should improve their procedures to prevent clownshows like this in the future? No…
I just don't understand why open source software can continue with the assumption that every single contributor is honest. Imagine if this philosophy was applied to, say, cryptography or network security. What would be the state of encryption algorithms and key exchange protocols and so on, if their developers had a meltdown at the mere suggestion of there existing a liar? Since the Linux kernel is installed on many…
There is no such assumption and it has been well known for a long time that such an assumption would be harmful.
> if all it takes is a couple grad students and an assistant prof to get them in
There were 0 malicious commits that made it through the review process (since the paper was incompetent as well as unethical.)
You seem to be missing some basic facts here. Filling in those gap would help you partipate more productively in the conversation.
Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches
#98Earlier quoted context omitted.
They lied in their abstract [0], they lied to their IRB, and Kangjie Lu's aspirations have been wasting a lot of Linux maintainer time. The real disgrace was the experiment. The response was fairly natural for humans with imperfect information being experimented on. Please be more specific. How do you think the Linux kernel maintainers should improve their procedures to prevent clownshows like this in the future? No…
I just don't understand why open source software can continue with the assumption that every single contributor is honest. Imagine if this philosophy was applied to, say, cryptography or network security. What would be the state of encryption algorithms and key exchange protocols and so on, if their developers had a meltdown at the mere suggestion of there existing a liar? Since the Linux kernel is installed on many…
It doesn't. They've been on the lookout since before 2003: https://lwn.net/Articles/57135/ (there are other examples, this is just the earliest I know of)
> Apparently, do nothing, and assume that everyone in the world is honest, while writing self-indulgent "public letters" about it?
This sounds overly dramatic which makes discussion difficult. My answer would be that the kernel maintainers have known about this threat vector for a very long time and seem to be doing a reasonable job of repelling it.
Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches
#99Earlier quoted context omitted.
Is it forbidden to do mistakes? In such cases is it a good idea to respond to your colleagues with "Please stop doing mistakes!" as the parent did?
No, but it may be reasonable to ask 'please do not repeat this particular mistake'
Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches
#100Earlier quoted context omitted.
Most maintainers are volunteer, meaning that they spend their evenings, weekends and holidays developing the kernel because they like it, it gives them a sense of worth and fulfillment that can be hard to come across. I don't know if you've ever talked to one, but they take a real pride in their work, most make a pitiful salary in comparison to FAANG levels but they still do it because it is full of interesting chall…
I don't dispute that the researchers were dishonest and broke the trust of the kernel maintainers. So they can be a bit peeved off at UMN. But is this sort of thing not the reality of their operation? That liars exist in the world? I don't really see what the volunteer part has to do with it. If anything it means they have less to complain about. I mean...most soldiers are volunteers, which would make it even more ab…
You must trust contributors to your project to some extent. If you don't extend some trust, you can't have contributors. That level of trust is then adjusted off that base level based on experience.
It is perfectly reasonable to drop someone below your base level of trust if they lie to you. This doesn't necessarily mean that the base level of trust needs to be adjusted.
In this case, the review process caught all the known harmful commits (which were from anonymous emails so recieved base level trust) and thus the base line level of trust seems to be working.