Live data from Hacker News

Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

phoronix.com

111–120 of 121 posts

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#111
post #26

Earlier quoted context omitted.

Can you provide specifics what do you mean exactly by unfounded accusations ? Really curious who makes unfunded accusations ...

https://lore.kernel.org/linux-nfs/YH5%2Fi7OvsjSmqADv@kroah.c... And the resulting conversations between Aditya Pakki and Greg. Aditya was never part of the hypocrite commit research, accusing them for this is just bad.

That's easy to say now.

At the time, UMC had not "debriefed" the kernel maintainers they lied to in the "hypocrite commits".

And then Pakki didn't mention that these new patches were generated by a tool, and submitted a bunch of "nonsense" patches with no explanation.

What reason did GKH have to trust anyone associated with the "hypocrite commits" at that point?

(ps. don't think you deserve all the downvotes here...)

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#112
post #111

Earlier quoted context omitted.

https://lore.kernel.org/linux-nfs/YH5%2Fi7OvsjSmqADv@kroah.c... And the resulting conversations between Aditya Pakki and Greg. Aditya was never part of the hypocrite commit research, accusing them for this is just bad.

That's easy to say now. At the time, UMC had not "debriefed" the kernel maintainers they lied to in the "hypocrite commits". And then Pakki didn't mention that these new patches were generated by a tool, and submitted a bunch of "nonsense" patches with no explanation. What reason did GKH have to trust anyone associated with the "hypocrite commits" at that point? (ps. don't think you deserve all the downvotes here...)

I said the same thing then. The pre-print was public at that point and I had been following it since December, sharing thesis adviser doesn't make you associated with research conducted months prior.

Yes, they are bad patches and the research is also questionable. But this is not bad faith nor malicious.

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#113
post #72

Earlier quoted context omitted.

They lied in their abstract [0], they lied to their IRB, and Kangjie Lu's aspirations have been wasting a lot of Linux maintainer time. The real disgrace was the experiment. The response was fairly natural for humans with imperfect information being experimented on. Please be more specific. How do you think the Linux kernel maintainers should improve their procedures to prevent clownshows like this in the future? No…

I just don't understand why open source software can continue with the assumption that every single contributor is honest. Imagine if this philosophy was applied to, say, cryptography or network security. What would be the state of encryption algorithms and key exchange protocols and so on, if their developers had a meltdown at the mere suggestion of there existing a liar? Since the Linux kernel is installed on many…

> I just don't understand why open source software can continue with the assumption that every single contributor is honest

It's not a bare assumption of honestly, it's an established relationship of trust. If you have zero trust then you cannot have any collaboration with other humans; it would be definition take as much or more effort than any creation to verify that the creation is fully safe in an current and future potential contexts.

That trust with the university was broken, and in doing so their work has been reviewed and oft rejected.

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#114
post #78

So what are we doing about all the maintainers that initially approved these commits that were later found to be incorrect?

the same thing we do to a carpenter whose door get broken into in a robbery: nothing unless they were inexcusably incompetent or complicit.

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#115

Earlier quoted context omitted.

> I smashed windows on 20 buildings and took cash out of their registers. More like they posted on your facebook pro- messages. There's some value in grounding the analogy in reality.

I think the cash theft is analogous to the dev time the researchers wasted.

What exactly is the value? How did you come to it? The pay rate of people who would be working on the software regardless of the MNU boondoggle, is not wasted anymore than any other day is wasted. This is part of development. Dead ends, circling back, accounting, maintenance, et al.

> I think the cash theft is analogous to the dev time the researchers wasted.

That's a fantasy that developers would like to believe because they put an inappropriate valuation on the the time spent on software. The inability to face this, has been disturbing from the start.

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#116
post #77

Earlier quoted context omitted.

Yeah. I'm not trying to come down hard on you or anything, I just feel like a common reaction to this research is, "ethics aside, didn't they point out a real vulnerability?" And I want to make it crystal clear that, no, they didn't. Their research was entirely without value.

If you put ethics aside, then yes there was value. Failed research is most valuable, while successful research is usually quite worthless due to the bias toward finding whatever researchers already believe. I do wonder if they would have published if they didn't expect disclosure by angry Linux maintainers, i.e. if they really believe they were weakly successful. Generally, I think this is the type of finding that no…

> If you put ethics aside, then yes there was value. Failed research is most valuable, while successful research is usually quite worthless due to the bias toward finding whatever researchers already believe.

True as far as it goes, but the most valuable failing research is that which fails to produce an expected positive result.

Next most valuable is failing to corroborate a novel hypothesis (which is probably what you meant).

When you get an expected result, you haven't learned much, regardless of whether you were (or should have been) expecting success OR failure (with the exception being getting more, or more accurate, data that narrows error bars).

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#117

Earlier quoted context omitted.

Institutional Review Board dropped the ball and failed at their job. Which reflects on the institution. It's not just about individuals.

Eh, maybe, but at the same time, I kind of got the feeling that the researchers were treating the IRB as one more layer of security to get around. The IRB is a gatekeeper, yes, but it is also a resource. You should be working with the IRB to make sure everything you are doing is above the board, because ultimately, if you do something unethical or harmful to individuals or society, that's still on you, even if you go…

> Eh, maybe, but at the same time, I kind of got the feeling that the researchers were treating the IRB as one more layer of security to get around.

Which suggests an entirely new line of inquiry: testing IRB procedures to see whether unethical proposals will be approved if described in misleading terms.

While we're at it, we should check to see whether proposals ostensibly from people who are not faculty or students, or who perhaps don't even exist, are ever approved.

Regardless of the results, we can conclude that having to sign a statement promising to never do unethical research before submitting a proposal, and insisting on identity verification before proposals are reviewed, will lower the chances of unethical research proposals slipping through.

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#118
post #11

Earlier quoted context omitted.

Not trying to badmouth the university here, but having to trust the statement of those who broke your trust in the first place doesn't meet my definition of "knowing" something. Maybe "believe" would be better used here? Knowing would mean to know precisely what each of these changes does and whether they open up new vulnerabilities and then having confidence that all is well. Gaining this confidence requires work. A…

80 developers reviewing for a month isn't enough work for you? They just put more man-hours into reviewing these commits than the contributors put into writing them.

if 80 devs all read the same part same way, it won't make much of a difference.

maybe the issue is we aren't using static analysis enough / don't have enough static analysis tools?

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#119
post #4

Earlier quoted context omitted.

"ALL the proposals that were intentionally vulnerable and were really vulnerabilities were not accepted" The thing is there is no way you can actually know that. So this is not some kind of revenge. This is rather a valid precaution.

>The thing is there is no way you can actually know that. We do know since the researchers have told the linux community, the university and IEEE what those patches where. Please do not spread further misinformation about the case. Please read the IEEE statement and the full Linux TAB review. https://www.ieee-security.org/TC/SP2021/downloads/2021_PC_St... https://lkml.org/lkml/2021/5/5/1244

I can only suggest that you stop spreading your misbeliefs about the case. And also stop using the buzzwords the meaning of which you apparently do not understand.

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#120

Earlier quoted context omitted.

If you put ethics aside, then yes there was value. Failed research is most valuable, while successful research is usually quite worthless due to the bias toward finding whatever researchers already believe. I do wonder if they would have published if they didn't expect disclosure by angry Linux maintainers, i.e. if they really believe they were weakly successful. Generally, I think this is the type of finding that no…

The ideas in the paper were novel, perhaps (didn't check) but there was far more to learn from looking at reviews where bugs did slip by than doing their experiment. You could probably calculate the bug acceptance rate by category of bug, making a few random data points does not help science here

I think the prevailing belief, and belief they must have had to try their research was the belief that a good percentage of attempts would slip through initial review to be caught at a later stage. I fail to see what your alternative research would do to that apparently false belief other than reinforce it.
Post reply on HN