Live data from Hacker News

Open letter from researchers involved in the “hypocrite commit” debacle

lore.kernel.org

41–50 of 384 posts

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#41

Looking forward to the follow-up paper, "Open Source Insecurity: Concealing Vulnerabilities via Hypocrite Apologies"

The apology reads sincere to me even if it could be better, but this is for me why it might be very difficult for the Linux community to recover trust in these guys.

This, and the previous mail that I found pretty insulting too and seemingly written in bad faith but I'd give the benefit of the doubt, one can react badly to a difficult situation.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#42
post #12
post #2

I'd like to give them the benefit of the doubt, but this is written like an apology they know they must write . It does not come across as apologetic. It comes across as rationalization veiled as an apology, and it doesn't sit well with me. I hope I'm just being overly sensitive here.

They didn’t have to write it. The first two sentences seem sincere. This reads as a real apology.

Exculpatory apology

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#43
A BS non-apology is not enough. These assholes should at the very least be reprimanded by the University of Minnesota for unethical research practises (psychological experiments on humans without their consent) and bringing the whole institution in disrepute.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#44
Whether it is appropriate or not, the Linux kernel is used in many mission critical and essential services. One could very convincingly argue that the open source Linux kernel is a vital part of mission critical infrastructure found all around the world. An apology, likely written under duress, for an inappropriate research method or for consuming the time of maintainers (either volunteer or paid) does not address the most egregious transgression:

One does not conduct security research or experimentation on mission critical infrastructure without the informed consent of the persons maintaining or responsible for said infrastructure.

The stark difference between white (or even gray) hat and black hack security operations is whether those operations are done with the informed consent of the owners of the system(s) being manipulated. To knowingly and deliberately attempt to manipulate critical infrastructure without the informed consent of the persons responsible for that infrastructure is, in my eyes, clearly unethical black hat hacking. It does not matter how many resources were expended nor does it matter if there was no personal injury or destruction of property. A quiet, relatively uneventful outcome of a black hat operation is nothing more than a dose of good luck.

There are many other circumstances in which this sort of clandestine operation would be obviously unacceptable. Consider if a researcher wished to surreptitiously tamper with vaccine supply chains, automotive or aircraft supply chains, fuel distribution supply chains, chemical manufacturing supply chains, etc. Even if the researcher claimed to have the best of intentions, and had a written plan to carefully back-out or otherwise reverse (or prevent from going to production) the intentionally flawed manipulations or modifications of critical supply chain components, I think very few people would consider the research ethical. There are an enormous number of issues, defects, and mishaps that occur even when a group of people tries their best to implement and maintain critical systems. When a clandestine operator decides to interfere, using whatever justification, then reliability of the system can be expected to suffer.

I do not believe the written apology addresses the underlying problem, which seems to be that the University of Minnesota does not exercise sufficient governance over the researchers in its employ.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#46
post #5
post #2

I'd like to give them the benefit of the doubt, but this is written like an apology they know they must write . It does not come across as apologetic. It comes across as rationalization veiled as an apology, and it doesn't sit well with me. I hope I'm just being overly sensitive here.

I agree, but let's give them a little extra benefit of the doubt. I thought as I was reading it that it seemed stilted and forced, then I wondered if the author(s) don't speak / write English as a primary language. I'll be interested to see how they react to feedback / responses.

The wording is definitely stilted and forced, but the content is also wrong for an apology. They spend a lot of time justifying their actions, and close with "this has been painful for us too". This may also be cultural, but it's overly self-centered for an apology.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#47

Earlier quoted context omitted.

Indeed. This letter is an attempt to justify and rationalise their actions. Essentially, it amounts to saying "we're sorry you were offended and felt hurt by our legitimate work but we had no choice but to lie to you and unethically experiment on you without your consent or we wouldn't have been able to do it". Their statement is not an actual apology, even if it is phrased in the language of apology, and it is an ex…

People love to analyze apologies after the fact, but it seems totally unfair to me. Once someone has said an apology you can take the text of it and turn it into anything you want and say it proves they were lying.

Yep, it's called accountability. Would you prefer people acted without regard for others knowing that magic words can be spoken after the damage is done?

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#48
post #2

I'd like to give them the benefit of the doubt, but this is written like an apology they know they must write . It does not come across as apologetic. It comes across as rationalization veiled as an apology, and it doesn't sit well with me. I hope I'm just being overly sensitive here.

> It does not come across as apologetic. The words are there. It's not up to us to decide if they're "genuine". No one's a mindreader. The tendency to view apologies as fake seems more often to reflect how harshly we view the one making it.

You don't have to be a mind reader to see that this apology isn't an apology. They spend as much time justifying their actions as they do apologizing for the unintended outcomes, and they close by complaining that they've also been hurt.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#49
There is a major error made by the research group. It starts and ends here: "we did that because we knew we could not ask the maintainers of Linux for permission, or they would be on the lookout for the hypocrite patches."

I am a Red Teamer and work with companies to understand how their detective/preventative/recovery controls and processes are working. Here's how you resolve this:

You work with maintainers to get their coordination on the research. You work out a mechanism to prevent submitted patches from being merged (e.g. maintainers are notified before bad patches accepted by code review processes are merged).

You do not tell them when the patches are coming. You do not tell them which identities are going to be used for the patches (e.g. from which email addresses). You do not tell them which area of code will be targeted. You set rules and time bounds for the study.

You wait some amount of time before submitting such patches (weeks to months). Realistically this is all that's needed. If hypersensitive, set this up earlier and let it bake longer.

At this point, you submit patches from a variety of addresses (probably not associated with your university - it is easy to create many such identities). You also can coordinate with other researchers, universities, and companies to submit patches under identities as needed. You also study submitting from yandex, gmail, .cn and other email addresses (because isn't that interesting to know?).

The premise that there's some ultimatum between working with the community and performing the research is on its face incorrect. This is either ignorance or laziness on behalf of the researchers. Clearly, they hadn't taken the time to work with the community to work out an approach that could be mutually acceptable.

Re: Open letter from researchers involved in the “hypocrite commit” debacle

#50
Wouldn't it be better if the kernel had a governance committee and such so that innocent mistakes like this could be smoothed over and the personalities over-reacting on the basis of nothing but years of expertise gained at efforts that benefit the public at large could be dismissed because of their personality problems?

Maybe we can find or make up something unrelated but unsavory about these characters objecting to those pissing in the font of Linux... That's the normal way these things are handled now, right?

(scorching sarcasm intended)

Post reply on HN