Live data from Hacker News

Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

phoronix.com

101–110 of 121 posts

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#101

Maybe the people reviewing the changes should be unaware of who made them. I am biased and for sure look more closely at some developers pull requests than others.

For the sake of spotting malicious actors, wouldn't it make more sense for reviewers to be aware, so they can focus their attention on patches from untrusted sources?

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#102

What is really sad, is that this could be a good pen-test for the kernel. Especially the idea of introducing bugs that are only vulnerabilities when they all come in together. If only they had contacted the Linux Foundation ahead of time to get permission, and set up terms, like a real pen-test. Then work could be done on detecting, and preventing these sorts of attacks, maybe resulting in a system that could help ev…

The stated motivations of the researchers make it seem like they are not interested in advancing the security of open source software, but rather undermining it.

Then "on behalf of whom" should be the next question.

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#103

Isn't the moral of the story here that it's probably trival for organizations like the FSB/NSA/Chinese equivalent to get malicious patches accepted into Linux.

Not after Linux banned University of Minnesota from submitting patches. We're safe now.

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#105

What is really sad, is that this could be a good pen-test for the kernel. Especially the idea of introducing bugs that are only vulnerabilities when they all come in together. If only they had contacted the Linux Foundation ahead of time to get permission, and set up terms, like a real pen-test. Then work could be done on detecting, and preventing these sorts of attacks, maybe resulting in a system that could help ev…

Maybe it is more productive to just do the opposite. When vulnerabilities are found investigate the committer(s) for possible links, and quality of previous work

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#106
post #47

Earlier quoted context omitted.

Most maintainers are volunteer, meaning that they spend their evenings, weekends and holidays developing the kernel because they like it, it gives them a sense of worth and fulfillment that can be hard to come across. I don't know if you've ever talked to one, but they take a real pride in their work, most make a pitiful salary in comparison to FAANG levels but they still do it because it is full of interesting chall…

I don't dispute that the researchers were dishonest and broke the trust of the kernel maintainers. So they can be a bit peeved off at UMN. But is this sort of thing not the reality of their operation? That liars exist in the world? I don't really see what the volunteer part has to do with it. If anything it means they have less to complain about. I mean...most soldiers are volunteers, which would make it even more ab…

I don't have internal info so this is just an hypothesis, but I think they absolutely do expect adversarial commits and if you tried to get something accepted today with no affiliation or anything you would need to talk to multiple maintainers and your commits would be under scrutiny.

Here the "contributors" had done multiple commits and were coming from a university that had previously upstreamed several commits. There was and should be an expectation of trust because you can't scrutinize every commit for several hours (they just don't have them enough maintainers for it).

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#107

Earlier quoted context omitted.

Why would the Linux Foundation get to decide on if those researchers are allowed to experiment on and waste the time of volunteer developers?

Why would the Linux Foundation get to decide on if those researchers are allowed to experiment on and waste the time of volunteer developers? Granted, In the case of linux, it might make more sense if it were the combination of the Linux Foundation & Linus. It's their project, they can subject their volunteers to any tests they want. It may drive away some volunteers, but wether to take that risk or not, is up to the…

There are relatively few volunteers working on Linux. They mostly do it for their day jobs. Though the same criticism applies with respect to wasting time at their various companies. But, yes, there may have been some way of conducting a useful test after receiving permission--probably on a limited subsystem or set of subsystems.

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#108
post #77

Earlier quoted context omitted.

To be clear, I 100% understand the harsh reaction. If anything I think they were lucky no criminal charges were pressed.

Yeah. I'm not trying to come down hard on you or anything, I just feel like a common reaction to this research is, "ethics aside, didn't they point out a real vulnerability?" And I want to make it crystal clear that, no, they didn't. Their research was entirely without value.

If you put ethics aside, then yes there was value. Failed research is most valuable, while successful research is usually quite worthless due to the bias toward finding whatever researchers already believe.

I do wonder if they would have published if they didn't expect disclosure by angry Linux maintainers, i.e. if they really believe they were weakly successful. Generally, I think this is the type of finding that normally gets lost if there's no pre-disclosure.

https://pubmed.ncbi.nlm.nih.gov/16060722/

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#110
post #77

Earlier quoted context omitted.

Yeah. I'm not trying to come down hard on you or anything, I just feel like a common reaction to this research is, "ethics aside, didn't they point out a real vulnerability?" And I want to make it crystal clear that, no, they didn't. Their research was entirely without value.

If you put ethics aside, then yes there was value. Failed research is most valuable, while successful research is usually quite worthless due to the bias toward finding whatever researchers already believe. I do wonder if they would have published if they didn't expect disclosure by angry Linux maintainers, i.e. if they really believe they were weakly successful. Generally, I think this is the type of finding that no…

The ideas in the paper were novel, perhaps (didn't check) but there was far more to learn from looking at reviews where bugs did slip by than doing their experiment. You could probably calculate the bug acceptance rate by category of bug, making a few random data points does not help science here
Post reply on HN