Live data from Hacker News

Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

phoronix.com

31–40 of 121 posts

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#31
post #10
post #4

Earlier quoted context omitted.

>The thing is there is no way you can actually know that. We do know since the researchers have told the linux community, the university and IEEE what those patches where. Please do not spread further misinformation about the case. Please read the IEEE statement and the full Linux TAB review. https://www.ieee-security.org/TC/SP2021/downloads/2021_PC_St... https://lkml.org/lkml/2021/5/5/1244

This is awful: > Based on the overall positive reviews and the recommendation of all reviewers to accept the work, the PC did not discuss this paper during the online PC meeting; [...] When, after acceptance, the authors tweeted the abstract of the work in November 2020, several people expressed concerns about human-subject research featured in this work. At that time, the PC chairs discussed these concerns [...]. As…

What really happened (to the best of my understanding):

- Researchers submitted paper to IEEE.

- Researcher twitter about it.

- Tweet was deleted, because people pointed out it was bad humans subject researcher. (consent and deception)

- Other researchers not from UNM, filled complaints to IEEE.

- Researcher mislead (so far seems like) IRB, arguably IRB failed to do a job and just rubber stamped human subject research exemption, after research was conducted ...

- Paper got accepted to IEEE.

- Researchers push more patches to Linux kernel.

- Plonk email from Greg.

- UNM response latter indirectly blaming only researchers but not IRB.

- Paper get retracted from IEEE

- IEEE Response letter.

- We are here.

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#32

Earlier quoted context omitted.

> the overreaction from gregkh on the LKML I don't think it was an overreaction. I think it was a very valid reaction.

There are a few issues with blaming someone for sending known malicious patches which just causes confusion and is outright wrong. Brad Spengler is a... character, but I do agree with him that greg started out on this wrong. (He also goes a bit further with his criticism that I don't agree with). However yes, review of the patches was proper but all this could have been done with less unfounded accusations from gregs…

Are you Aditya? You write quite a bit like them.

Do you want to take a moment and explain how your broken static anylizer isn't involved?

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#33
post #4

Earlier quoted context omitted.

"ALL the proposals that were intentionally vulnerable and were really vulnerabilities were not accepted" The thing is there is no way you can actually know that. So this is not some kind of revenge. This is rather a valid precaution.

>The thing is there is no way you can actually know that. We do know since the researchers have told the linux community, the university and IEEE what those patches where. Please do not spread further misinformation about the case. Please read the IEEE statement and the full Linux TAB review. https://www.ieee-security.org/TC/SP2021/downloads/2021_PC_St... https://lkml.org/lkml/2021/5/5/1244

Sorry, why would you believe the words of bad actors who are known to lie? Can you be absolutely certain this isn't simply a continuation of their twisted "experiment"?

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#34

Earlier quoted context omitted.

There are a few issues with blaming someone for sending known malicious patches which just causes confusion and is outright wrong. Brad Spengler is a... character, but I do agree with him that greg started out on this wrong. (He also goes a bit further with his criticism that I don't agree with). However yes, review of the patches was proper but all this could have been done with less unfounded accusations from gregs…

Are you Aditya? You write quite a bit like them. Do you want to take a moment and explain how your broken static anylizer isn't involved?

Please google me. You'll quickly learn I'm a 26 year old Norwegian FOSS maintainer named "Morten Linderud".

Or, y'know. Click on the profile.

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#35

Earlier quoted context omitted.

Are you Aditya? You write quite a bit like them. Do you want to take a moment and explain how your broken static anylizer isn't involved?

Please google me. You'll quickly learn I'm a 26 year old Norwegian FOSS maintainer named "Morten Linderud". Or, y'know. Click on the profile.

Passionate! I like it, Morten. It's rare.

I did click your profile, but this is a post about deception. Trust no one.

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#36
What is really sad, is that this could be a good pen-test for the kernel. Especially the idea of introducing bugs that are only vulnerabilities when they all come in together.

If only they had contacted the Linux Foundation ahead of time to get permission, and set up terms, like a real pen-test. Then work could be done on detecting, and preventing these sorts of attacks, maybe resulting in a system that could help everyone. At the very least a database for security researchers that are registered, but unknown to maintainers, where they could store hashes of bad commits. Then a check if any of those commits made it through. I know the kernel makes use of rebasing, so that might not be the best approach technically, but something like that. To ease the pain of wasting developers time, sponsors could put up money that the maintainer gets if they catch it, and maybe a smaller amount if they have to revert it.

EDIT: if the Linux Foundation said no, they could have tried another large open source project with a governing body, Apache, Python, Postgres, Firefox, etc. It wouldn't have been as flashy and high profile, but it would have still been the same research, and odds are you would find at least one project willing to participate.

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#37
post #26

Earlier quoted context omitted.

Can you provide specifics what do you mean exactly by unfounded accusations ? Really curious who makes unfunded accusations ...

https://lore.kernel.org/linux-nfs/YH5%2Fi7OvsjSmqADv@kroah.c... And the resulting conversations between Aditya Pakki and Greg. Aditya was never part of the hypocrite commit research, accusing them for this is just bad.

That's the problem with bad-faith action by an institution... It casts a shadow on the actions of all the other agents of the institution.

Greg's concerns proved to be overblown, but at the time they were raised he had reason to believe them valid.

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#38
post #23

Just from a code quality process standpoint, that’s an interesting result. Now I’m wondering what would happen if you picked a set of 150 random kernel patches and told 80 reviewers to re-review them assuming they could be malicious. I bet you’d find quite a few fixes.

I was wondering the same thing, and it appears it would be worth the effort, but getting enough high quality reviewers would be a problem.

Maybe the NCAA could organize competitive code reviewing leagues? I bet you would get e.g. a highly motivated Caltech team reviewing USC contributed patches, and vice versa.

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#39
post #11
post #4

Earlier quoted context omitted.

>The thing is there is no way you can actually know that. We do know since the researchers have told the linux community, the university and IEEE what those patches where. Please do not spread further misinformation about the case. Please read the IEEE statement and the full Linux TAB review. https://www.ieee-security.org/TC/SP2021/downloads/2021_PC_St... https://lkml.org/lkml/2021/5/5/1244

Not trying to badmouth the university here, but having to trust the statement of those who broke your trust in the first place doesn't meet my definition of "knowing" something. Maybe "believe" would be better used here? Knowing would mean to know precisely what each of these changes does and whether they open up new vulnerabilities and then having confidence that all is well. Gaining this confidence requires work. A…

What the uni guys did was correct. The Linux devs only able to review their codes because they are alerted. I am very sure there are plenty of bad faith commits that were accepted by Linux devs. For one, any governments with interest for backdoors with resources beyond the combine all Linux devs would have done it. Instead of appreciating what the uni did, they go beserk because their ego bruised. I am not surprised if within the next 5 years we going to hear more about this issue just that this time the parties involved are not that university.

Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

#40
post #23

Just from a code quality process standpoint, that’s an interesting result. Now I’m wondering what would happen if you picked a set of 150 random kernel patches and told 80 reviewers to re-review them assuming they could be malicious. I bet you’d find quite a few fixes.

Probably, but the fact that maintainers are stretched thin when it comes to time for code review is not really news.
Post reply on HN