Live data from Hacker News

UMN CS&E Statement on Linux Kernel Research

cse.umn.edu

321–330 of 332 posts

Re: UMN CS&E Statement on Linux Kernel Research

#321

Earlier quoted context omitted.

> They need to act to get the ban rescinded, they can't just ignore this issue away. I doubt that - in the other thread, someone noted that the last non-hostile kernel contribution from @umn.edu was in 2014. I don't think they are champing at the bit to get legit kernel contributions merged - or at least haven't in the past 7 years. At this point, it is purely a reputation/PR problem with little urgency - the ban is…

The real urgency is they need to protect their reputation. So long as they do a proper investigation and take proper action they can spin this as a rouge professor and be forgiven. We as a community should give them time to investigate and figure out how to handle and prevent this, and then if done correctly forgive them. If they make this statement and then there is no action within a year, then we should assume thi…

bluGill says: "...rouge professor? "

Re: UMN CS&E Statement on Linux Kernel Research

#322
post #182

Earlier quoted context omitted.

I don't think that's the case (due to how fame works) and I don't even think it's particularly productive to bring up that point. Their actions should be rectified since they did wrong - not out of fear of a punishment. When we bring only a specific punishment in as a consequence then the question of how to respond can be shifted over to a "which is worse" proposition which means that the punishment needs to be prope…

There are enough of us here that have heard about this as to make a UMN degree worth less because we will trash a resume with that name on it.

I certainly wouldn't do so - this looks like it was a research topic by one professor and one grad student... So nearly no one with a degree from UMN was involved with this. Even the specific grad student was college aged at the time and we all did stupid stuff when we were young. I think this only really rubs off on the professor since they clearly should've known better. Honestly I think the biggest blow to the university will be when it comes to hiring CS professors - those are the only folks likely to do the due diligence on this topic or be passively aware of it.

Re: UMN CS&E Statement on Linux Kernel Research

#323

Earlier quoted context omitted.

The real urgency is they need to protect their reputation. So long as they do a proper investigation and take proper action they can spin this as a rouge professor and be forgiven. We as a community should give them time to investigate and figure out how to handle and prevent this, and then if done correctly forgive them. If they make this statement and then there is no action within a year, then we should assume thi…

bluGill says: "...rouge professor? "

It's a common misspelling, and I find it particularly grating (that, and "tounge" *shivers*). However, I've been getting better at reflexively requesting corrections as I also have some words I constantly misspell.

Re: UMN CS&E Statement on Linux Kernel Research

#324
> Leadership in the University of Minnesota Department of Computer Science & Engineering learned today about the details of research being conducted by one of its faculty members

Uhh... they didn't know what their own employees were doing?

Don't most universities have review/approval procedures before people can do experiments or studies?

Re: UMN CS&E Statement on Linux Kernel Research

#325

I think everybody is missing the point. If one grad student was able to do this, imagine what a team of dozens of well-paid, well-equipped, and highly experienced security experts could do. In other news, we just learned that any half-decent security agency has already injected their own vulnerabilities and back-doors in OSS.

> do this They got caught and had all their contributions reverted.

Sure, but are there others who did not get caught? Others who might be better at obscuring their changes? And who might first develop a history of good, secure work, and then slip something sketchy into one -- and only one -- patch?

Seems like the UMN "researcher" was doing this over and over; the more times you do it, the more likely you are to get caught.

Re: UMN CS&E Statement on Linux Kernel Research

#326
post #199
post #176

Earlier quoted context omitted.

To quote my comment above: > If you wanted to know if the kernel review process is able to reliably catch malicious attempts you literally could have just asked the kernel maintainers and they'd told you that no, review can't go that deep. Or looked at non-malicious bugs and observed that no, review does not catch all bugs with security implications. > You'd very likely would have been able to get code past them even…

> But you don't get splashy outrage, and thus less success at "raising awareness" with people that didn't care before, which is what your comment seemed to argue for. the reason for doing it, is basic quality science. it's proper blinding. the result is raising awareness, which if it leads to more scrutiny and a better and more secure linux kernel, seems to be a good thing... in the long run. i mean, i get it. a lot…

Here's a practitioner with a better elaborated variant of what I'm trying to argue, so I'll defer to this: https://davisjam.medium.com/ethical-conduct-in-cybersecurity... IMHO worth a read

Re: UMN CS&E Statement on Linux Kernel Research

#327
post #320

Earlier quoted context omitted.

I disagree. The associate department head named in the statement linked it on Twitter, immediately following up his comments with > I very much welcome feedback from the participants who brought this to our attention: that's why I tagged @gregkh . Obviously, we would appreciate any guidance as to how we can get the Univ. of Minnesota contribution ban lifted. This is pretty clearly one of their main interests in movin…

What's your interest in "fast" here?

I don't understand the question. By fast I mean that they had a statement up on the website within 24 hours and the associate head of the department is already pinging members of the kernel team on Twitter to ask how they can get unbanned. That's moving very quickly by academic standards.

Re: UMN CS&E Statement on Linux Kernel Research

#328
post #225

Earlier quoted context omitted.

> So, as long as you ignore the formatting they presented it with and decide to read it without it, you can come to a different conclusion? No. It reads that way with the formatting they provided. You can’t take that paragraph break out without putting one back exactly there. It’s refreshingly transparent, and perfect if you expect them not to care about the underlying cause as much as they care about the ban. > I do…

> You can’t take that paragraph break out without putting one back exactly there. Exactly. And paragraphs are used to separate concepts and statements into conceptual units. That you're letting a concept and interpretation from one apply to and influence the reading of another as if there is no break is the problem. > It’s not a contortion, it’s just how it reads to me. I think you have some interesting ideas of how…

> Exactly. And paragraphs are used to separate concepts and statements into conceptual units. That you're letting a concept and interpretation from one apply to and influence the reading of another as if there is no break is the problem.

Their second paragraph says they "take the situation very seriously".

What "situation", exactly?

Re: UMN CS&E Statement on Linux Kernel Research

#329

Earlier quoted context omitted.

I don't want to defend the researcher, but that's not a solution. The way it was done was at least blinded (even if ethically wrong).

What would be wrong with that? It seems like it would have handled the issue of consent pretty straight forwardly.

It would handle the issue of consent, but not answer the question they were researching: "Would this bug get into the kernel?" Because if the maintainers knew that this was research, not an actual ordinary patch, they'd be answering a hypothetical: "Would I accept this, if it were an actual ordinary patch?" I don't think people are wired to answer that exactly the same if they know it's a hypothetical as if they were answering it non-hypothetically, "Should we accept this patch into the kernel?" So the only way to really find out what would happen in reality is to really do it for real... So that's what they did.

What's weird is of course that they didn't tell anyone. In the fairly analogous situation of "white-hat hacker" penetration testing, the penetrators have authorization from either someone (fairly high up in) the security department of the organisation to be tested, or if that whole department is being evaluated someone even higher than that; without that authorization it's not white-hat testing but just black-hat cracking. They should have privately contacted mr Kroah-Hartman, and/or Linus himself, beforehand and asked if they were amenable to this. Then they could have had the option to accept and be in on it, not comment on but silently monitor the patches in question, and at the end of the experiment reveal the results to their fellow maintainers and revert any specific patches -- which they would have been continuously kept informed about out-of-band -- that had made it through review.

Provided of course that they, Greg K-H or Linus or whoever, would have been comfortable with temporarily deceiving -- or letting be deceived -- their fellow maintainers, of course. Or, well, even if they weren't exactly "comfortable" with it, seems to me there's a chance they might have gone for it because of the valuable knowledge it would have gained the community. The "reveal" afterwards, coming first from one of these trusted people, would probably go down a lot better in the maintainer community than it did as this secret external attack.

Re: UMN CS&E Statement on Linux Kernel Research

#330
post #265

Earlier quoted context omitted.

Ah, but you're missing the directive that medicine doesn't have: "If a doctor commits malpractice, immediately disregard all medical advice given to you by any other doctors at their hospital"

If one doctor at a hospital does very bad things - then yes, I would avoid that hospital completely. Because in a working environment, bad actors would be detected by colleagues, etc. And since this not happened, one can only assume the whole hospital to be deeply flawed.

Indeed! If I heard that a doctor was deliberately and repeatedly poisoning his patients, I'd absolutely avoid the place because proper oversight is clearly lacking.

Perhaps the hospital actually has excellent oversight and it is just that the evil doctor is exceptionally clever at avoiding it. But, Occam's Razor says that is a poor bet.

Post reply on HN