Maybe the people reviewing the changes should be unaware of who made them. I am biased and for sure look more closely at some developers pull requests than others.
Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches
101–110 of 121 posts
Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches
#102What is really sad, is that this could be a good pen-test for the kernel. Especially the idea of introducing bugs that are only vulnerabilities when they all come in together. If only they had contacted the Linux Foundation ahead of time to get permission, and set up terms, like a real pen-test. Then work could be done on detecting, and preventing these sorts of attacks, maybe resulting in a system that could help ev…
The stated motivations of the researchers make it seem like they are not interested in advancing the security of open source software, but rather undermining it.
Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches
#103Isn't the moral of the story here that it's probably trival for organizations like the FSB/NSA/Chinese equivalent to get malicious patches accepted into Linux.
Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches
#104Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches
#105What is really sad, is that this could be a good pen-test for the kernel. Especially the idea of introducing bugs that are only vulnerabilities when they all come in together. If only they had contacted the Linux Foundation ahead of time to get permission, and set up terms, like a real pen-test. Then work could be done on detecting, and preventing these sorts of attacks, maybe resulting in a system that could help ev…
Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches
#106Earlier quoted context omitted.
Most maintainers are volunteer, meaning that they spend their evenings, weekends and holidays developing the kernel because they like it, it gives them a sense of worth and fulfillment that can be hard to come across. I don't know if you've ever talked to one, but they take a real pride in their work, most make a pitiful salary in comparison to FAANG levels but they still do it because it is full of interesting chall…
I don't dispute that the researchers were dishonest and broke the trust of the kernel maintainers. So they can be a bit peeved off at UMN. But is this sort of thing not the reality of their operation? That liars exist in the world? I don't really see what the volunteer part has to do with it. If anything it means they have less to complain about. I mean...most soldiers are volunteers, which would make it even more ab…
Here the "contributors" had done multiple commits and were coming from a university that had previously upstreamed several commits. There was and should be an expectation of trust because you can't scrutinize every commit for several hours (they just don't have them enough maintainers for it).
Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches
#107Earlier quoted context omitted.
Why would the Linux Foundation get to decide on if those researchers are allowed to experiment on and waste the time of volunteer developers?
Why would the Linux Foundation get to decide on if those researchers are allowed to experiment on and waste the time of volunteer developers? Granted, In the case of linux, it might make more sense if it were the combination of the Linux Foundation & Linus. It's their project, they can subject their volunteers to any tests they want. It may drive away some volunteers, but wether to take that risk or not, is up to the…
Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches
#108Earlier quoted context omitted.
To be clear, I 100% understand the harsh reaction. If anything I think they were lucky no criminal charges were pressed.
Yeah. I'm not trying to come down hard on you or anything, I just feel like a common reaction to this research is, "ethics aside, didn't they point out a real vulnerability?" And I want to make it crystal clear that, no, they didn't. Their research was entirely without value.
I do wonder if they would have published if they didn't expect disclosure by angry Linux maintainers, i.e. if they really believe they were weakly successful. Generally, I think this is the type of finding that normally gets lost if there's no pre-disclosure.
Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches
#109Isn't the moral of the story here that it's probably trival for organizations like the FSB/NSA/Chinese equivalent to get malicious patches accepted into Linux.
Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches
#110Earlier quoted context omitted.
Yeah. I'm not trying to come down hard on you or anything, I just feel like a common reaction to this research is, "ethics aside, didn't they point out a real vulnerability?" And I want to make it crystal clear that, no, they didn't. Their research was entirely without value.
If you put ethics aside, then yes there was value. Failed research is most valuable, while successful research is usually quite worthless due to the bias toward finding whatever researchers already believe. I do wonder if they would have published if they didn't expect disclosure by angry Linux maintainers, i.e. if they really believe they were weakly successful. Generally, I think this is the type of finding that no…