Live data from Hacker News

UMN CS&E Statement on Linux Kernel Research

cse.umn.edu

191–200 of 332 posts

Re: UMN CS&E Statement on Linux Kernel Research

#191
post #2

This is a great statement, they confirm they're aware of the issue, they acknowledge the concerns and they set out their intention to gather the full facts whilst suspending the operation of the research in the meantime. They also acknowledge the systematic way the need to deal with this. I hope their follow up is as thorough but I want to applaud this, it's a good approach.

It doesn't take much to write a single paragraph, though. I think the quality of their response will become much more clear later.

Have you ever drafted a public response for an issue receiving a lot of attention on social media when you don’t know the whole story but, from what little you do know, things aren’t looking great for the entity you represent?

You vastly underestimate how much effort and attention was put into writing that “single paragraph” because I promise you it sure does take much.

Re: UMN CS&E Statement on Linux Kernel Research

#193

The researchers, the researcher's bosses and pretty much every person in command at UMN had to sign off on this being an acceptable method of conducting research. This shows such an extreme lack of good faith or judgement on their part that I do not believe UMN could, or should ever be forgiven. Their actions show nothing but criminally bad faith taking place, all the way up to the top. The only rational response fro…

> The researchers, the researcher's bosses and pretty much every person in command at UMN had to sign off on this being an acceptable method of conducting research.

That is nothing like how research operates at a university like UMN. At a research university, typically the only person that actually must sign off on a computer science experiment is the grad student / professor actually doing the work. Graduate students frequently clear their work with their advisors first, but even that isn't strictly required. A small amount of work technically requires IRB approval, but unless what you're doing is very obviously human subject research, it is unlikely anyone would even notice if you went rogue and ignored it.

Re: UMN CS&E Statement on Linux Kernel Research

#194
post #99
post #2

This is a great statement, they confirm they're aware of the issue, they acknowledge the concerns and they set out their intention to gather the full facts whilst suspending the operation of the research in the meantime. They also acknowledge the systematic way the need to deal with this. I hope their follow up is as thorough but I want to applaud this, it's a good approach.

It is a good statement, and I believe they'll follow through, but it's missing something important that is often missing from otherwise professional communication. The last line is "We will report our findings back to the community as soon as practical." It should be followed by "and we will provide an update in no more than 30 days". Without any explicit time frame, holding them publicly accountable becomes trickier…

It is a good PR statement, but it doesn't touch on any of the Linux Kernel community's concerns. It makes no committment to working with the community or, like you said provide any kind of explicit time frame.

Instead, the statement is there to prevent journalists from putting "UWN puts the entire internet at risk" on their front page. Instead, it frames the incident into a boring "Students offended the Linux Kernel community while trying to help out by doing security research, we will investigate" story.

Re: UMN CS&E Statement on Linux Kernel Research

#195

Earlier quoted context omitted.

Yeah and that's some heavy shade on a university. They'll lose good students if this is not fixed.

>They'll lose good students if this is not fixed. "Ability to commit to the Linux kernel with my school email" isn't likely to be a major issue for many. It's a non-issue for undergrad work, and even most grad students are unlikely to be affected. Other than this research, only one other person associated with UMN has committed code to the kernel. This impacts any direct school-sponsored research work, but if some ra…

Maybe practically this doesn’t prevent most students or faculty from doing anything, but it is a huge reputation problem. How many universities (or organizations in general) are banned from contributing to the Linux kernel? When people search for why, they’ll find a research group basically screwing over their collaborators and anyone else who uses Linux. That that exists at UMN could be viewed as a serious cultural problem at the university and dissuade prospective students and collaborators from contact with UMN. That in real terms costs the university prestige and money.

Re: UMN CS&E Statement on Linux Kernel Research

#196
post #2

This is a great statement, they confirm they're aware of the issue, they acknowledge the concerns and they set out their intention to gather the full facts whilst suspending the operation of the research in the meantime. They also acknowledge the systematic way the need to deal with this. I hope their follow up is as thorough but I want to applaud this, it's a good approach.

I disagree. There's not a single word of apology in it.

They don't have to, it's the ,,redearcher'' who has to apologize.

The University has to do exactly what they have done and follow up, to keep their reputation.

Re: UMN CS&E Statement on Linux Kernel Research

#197
post #2

This is a great statement, they confirm they're aware of the issue, they acknowledge the concerns and they set out their intention to gather the full facts whilst suspending the operation of the research in the meantime. They also acknowledge the systematic way the need to deal with this. I hope their follow up is as thorough but I want to applaud this, it's a good approach.

Is it?

Their ethics committee approved the research, and yet I see no acknowledgement of their responsibility.

Re: UMN CS&E Statement on Linux Kernel Research

#198
post #99
post #2

This is a great statement, they confirm they're aware of the issue, they acknowledge the concerns and they set out their intention to gather the full facts whilst suspending the operation of the research in the meantime. They also acknowledge the systematic way the need to deal with this. I hope their follow up is as thorough but I want to applaud this, it's a good approach.

It is a good statement, and I believe they'll follow through, but it's missing something important that is often missing from otherwise professional communication. The last line is "We will report our findings back to the community as soon as practical." It should be followed by "and we will provide an update in no more than 30 days". Without any explicit time frame, holding them publicly accountable becomes trickier…

> The last line is "We will report our findings back to the community as soon as practical." It should be followed by "and we will provide an update in no more than 30 days".

I don't really think this is a worthwhile distinction. Personally, it comes off as trying to nanny a process that involves the Linux kernel maintainers and UMN Admins. There's a ban on UMN, probably until they show they can head off ethical issues. The public doesn't need to be sitting around demanding an update in 30 days or less. They'll act when they have confidence in their facts and the outcome, and the Linux community will undoubtedly act in kind.

Re: UMN CS&E Statement on Linux Kernel Research

#199
post #176
post #141

Earlier quoted context omitted.

> So you are saying that because a non-controversial method to show the same issue wouldn't cause the publicity connected purely to their way of operating, it was right to ignore the concerns? what's the non-controversial alternative? alerting the organization before they do it? that doesn't work. that's why scientists do blinding and double blinding. if you mean something else, then i'm missing parts of this (really…

To quote my comment above: > If you wanted to know if the kernel review process is able to reliably catch malicious attempts you literally could have just asked the kernel maintainers and they'd told you that no, review can't go that deep. Or looked at non-malicious bugs and observed that no, review does not catch all bugs with security implications. > You'd very likely would have been able to get code past them even…

> But you don't get splashy outrage, and thus less success at "raising awareness" with people that didn't care before, which is what your comment seemed to argue for.

the reason for doing it, is basic quality science. it's proper blinding.

the result is raising awareness, which if it leads to more scrutiny and a better and more secure linux kernel, seems to be a good thing... in the long run.

i mean, i get it. a lot of this security stuff feels a lot like gotcha qa, with people looking to make names for themselves at the expense of others. and yeah, in science, making a name for yourself is the primary currency...

but honestly, they ran their experiment and it worked, uncovered an actual, not theoretical, vulnerability in an irrefutable way, in a massive chunk of computing infrastructure that powers massive chunks of society.

papers like this one can have a lot of potential in terms of raising funds. this is the sort of thing that can be taken to governments, private foundations and public corporations to ask for quite a lot of money to help with the situation.

Post reply on HN