Live data from Hacker News

UMN CS&E Statement on Linux Kernel Research

cse.umn.edu

201–210 of 332 posts

Re: UMN CS&E Statement on Linux Kernel Research

#201

I think everybody is missing the point. If one grad student was able to do this, imagine what a team of dozens of well-paid, well-equipped, and highly experienced security experts could do. In other news, we just learned that any half-decent security agency has already injected their own vulnerabilities and back-doors in OSS.

It's a matter of trust. UMN was given a fair amount of trust before, as academics were entrusted to do goods in research in ethical ways.

Trust is an important social contract since it lowers the cost of social transactions. But trust takes a long time to earn and can be lost in a flash.

Re: UMN CS&E Statement on Linux Kernel Research

#202
It seems concerning that the investigation is being conducted by the CS&E department itself, rather than an independent third party. There's a risk that the results of the investigation won't be seen as impartial, since the CS&E faculty obviously have an interest in protecting the department's reputation.

Re: UMN CS&E Statement on Linux Kernel Research

#203
Can someone explain why engineering of bugs into products is bad but hacking to find software defects is good. I think trying to do this sort of research is good because obviously it presents a vector for malicious actors we should all be aware of. It’s good that the Linux team found these issues but I don’t see the intention as being any different than any other kind of hacking, just like some organisations will send you phishing emails once or twice a year to see if you’re susceptible.

Re: UMN CS&E Statement on Linux Kernel Research

#204
The university's ethics committee approved the research, and it was guided by a number of their professors. I see no acknowledgement of this in the statement; instead, I see the groundwork laid for hanging the students out to dry.

> The research method used raised serious concerns in the Linux Kernel community and, as of today, this has resulted in the University being banned from contributing to the Linux Kernel.

The research method _approved by the University's internal authorities_.

Re: UMN CS&E Statement on Linux Kernel Research

#205
post #2

This is a great statement, they confirm they're aware of the issue, they acknowledge the concerns and they set out their intention to gather the full facts whilst suspending the operation of the research in the meantime. They also acknowledge the systematic way the need to deal with this. I hope their follow up is as thorough but I want to applaud this, it's a good approach.

This statement rings true because it is the wordsmith'd version of exactly what the department head probably said when he first heard, which probably went something like "what the f*k did you do, who the f*k thought this was a good idea, and who the f*k told you you could do this?"

Yeah, i thought the same thing. This is basically someone yelling in an office put through a diplomacy filter, which is what you would expect happened.

Re: UMN CS&E Statement on Linux Kernel Research

#206
you should notice that the professor involved is listed as being on the Program Committee for IEEE S&P 2022 already, meaning he must be well-connected with various higher ups at the conference. This is probably why they are reluctant to remove the paper. There were similar issues with the ISCA'19 peer review fraud case. IEEE/ACM are having some major issues these days.

Re: UMN CS&E Statement on Linux Kernel Research

#207

The university's ethics committee approved the research, and it was guided by a number of their professors. I see no acknowledgement of this in the statement; instead, I see the groundwork laid for hanging the students out to dry. > The research method used raised serious concerns in the Linux Kernel community and, as of today, this has resulted in the University being banned from contributing to the Linux Kernel. Th…

> We will investigate [...] the process by which this research method was approved, determine appropriate remedial action, and safeguard against future issues,

And the associate department head labelling it a failure of the review process: https://twitter.com/lorenterveen/status/1384966202301337603

Re: UMN CS&E Statement on Linux Kernel Research

#208

Can someone explain why engineering of bugs into products is bad but hacking to find software defects is good. I think trying to do this sort of research is good because obviously it presents a vector for malicious actors we should all be aware of. It’s good that the Linux team found these issues but I don’t see the intention as being any different than any other kind of hacking, just like some organisations will sen…

Society works because of trust. Activities like these erode trust. It's like "let's try and pour a bottle of acid into the freshwater storage facility".

Re: UMN CS&E Statement on Linux Kernel Research

#209

The title here should probably be "UMN CSE Department Statement..." rather than merely "UMN Statement ..." since it's coming from the department head and associate department head, not from the university as a whole. cc/ dang

Sorry for getting sidetracked, but does cc has any special function here or you are hoping that dang would read all the comments and see your cc?

"@dang" is a no-op.

fhars helpfully changed the title.

Re: UMN CS&E Statement on Linux Kernel Research

#210
post #155
post #138

Earlier quoted context omitted.

> Not once do they talk about getting the ban removed, instead they talk about figuring out why it happened and how to be better at having research done being ethical. I feel as if we’re discussing two different statements. > The research method used raised serious concerns in the Linux Kernel community and, as of today, this has resulted in the University being banned from contributing to the Linux Kernel. Here the…

Yes that's called the trigger. You have a trigger, that leads you to focus on and review what caused said trigger, and reach conclusions. The ban is the trigger. The review is about to happen, so they really can't talk about its result yet. For all you and me know, said review will say their processes are just fine which I would personally disagree with but it could happen. Then, if there was an issue, they will upda…

I think we’re mostly in agreement. The ban is clearly the trigger, and it’s pretty transparent.

> For all you and me know, said review will say their processes are just fine which I would personally disagree with but it could happen.

Agreed. For what it’s worth, I don’t actually think there’s much they can really do besides acknowledge it and make sure their ethics board is competent and consulted.

> the ban is the focus – not what led to the ban

I was talking about the ban being the focus of the statement, as it’s the point at which there’s a clear shift from the situation to the fix. This is unfortunate, because to me it is placing the emphasis on the trigger, rather than the cause.

I believe it could have been written in a way that mentioned the ban, left room to investigate, but made it crystal clear that the community concerns and the ban were not the problem. It makes it feel to me as though their primary motivation to investigate is to get unbanned – which, to be fair, it probably is – rather than to be committed to root out alleged unethical practices. Even if the short-term consequences are the same, it’s a subtle but important distinction.

I suppose it’s a form of honesty, and I could instead embrace its transparency.

Post reply on HN