What is really sad, is that this could be a good pen-test for the kernel. Especially the idea of introducing bugs that are only vulnerabilities when they all come in together. If only they had contacted the Linux Foundation ahead of time to get permission, and set up terms, like a real pen-test. Then work could be done on detecting, and preventing these sorts of attacks, maybe resulting in a system that could help ev…
> that this could be a good pen-test for the kernel Not really. Everyone knows this flaw exists, the interesting part is how to fix it. Did you read the "suggestions" the researchers made in their paper[1]? They're clueless. It's like pointing out that buildings can be robbed by breaking their windows. No shit. What do you want to do about it? [1] https://twitter.com/SarahJamieLewis/status/13848800341465743...
Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches
51–60 of 121 posts
Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches
#52Earlier quoted context omitted.
Can you provide specifics what do you mean exactly by unfounded accusations ? Really curious who makes unfunded accusations ...
https://lore.kernel.org/linux-nfs/YH5%2Fi7OvsjSmqADv@kroah.c... And the resulting conversations between Aditya Pakki and Greg. Aditya was never part of the hypocrite commit research, accusing them for this is just bad.
Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches
#53Earlier quoted context omitted.
> that this could be a good pen-test for the kernel Not really. Everyone knows this flaw exists, the interesting part is how to fix it. Did you read the "suggestions" the researchers made in their paper[1]? They're clueless. It's like pointing out that buildings can be robbed by breaking their windows. No shit. What do you want to do about it? [1] https://twitter.com/SarahJamieLewis/status/13848800341465743...
Agreed. As I mentioned in an earlier thread on this scandal, [0] we already know that security bugs can make their way into the kernel. [0] https://news.ycombinator.com/item?id=26888129
Signed, UMN Researchers.
Edit: Wait, the cops are here. We sincerely apologize for any harm our research group did to your business. Our goal was to identify issues with the windows on your buildings and we are very sorry that the method used in the “smashing windows to take cash” paper was inappropriate.
Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches
#54Just from a code quality process standpoint, that’s an interesting result. Now I’m wondering what would happen if you picked a set of 150 random kernel patches and told 80 reviewers to re-review them assuming they could be malicious. I bet you’d find quite a few fixes.
Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches
#55Earlier quoted context omitted.
Agreed. As I mentioned in an earlier thread on this scandal, [0] we already know that security bugs can make their way into the kernel. [0] https://news.ycombinator.com/item?id=26888129
Check out my groundbreaking research. I smashed windows on 20 buildings and took cash out of their registers. In order to fix this vulnerability, I suggest you make everyone who passes by your building sign this piece of paper saying they won't smash your windows and take your money. I will happily receive your nearest Nobel prize now, thank you. Signed, UMN Researchers. Edit: Wait, the cops are here. We sincerely ap…
More like they posted on your facebook pro- messages. There's some value in grounding the analogy in reality.
Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches
#56What is really sad, is that this could be a good pen-test for the kernel. Especially the idea of introducing bugs that are only vulnerabilities when they all come in together. If only they had contacted the Linux Foundation ahead of time to get permission, and set up terms, like a real pen-test. Then work could be done on detecting, and preventing these sorts of attacks, maybe resulting in a system that could help ev…
Why would the Linux Foundation get to decide on if those researchers are allowed to experiment on and waste the time of volunteer developers?
Granted, In the case of linux, it might make more sense if it were the combination of the Linux Foundation & Linus. It's their project, they can subject their volunteers to any tests they want. It may drive away some volunteers, but wether to take that risk or not, is up to the project to decide. For something as big as the kernel they may decide to get permission from the individual maintainers, maybe even limit the research to only the subsystems that agree to participate.
In any case, the point I'm trying to make, is that this kind of testing may be beneficial, if the project is aware of it, and agrees to it. Who gets to decide on behalf of the project, would depend on the hierarchy of each project.
Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches
#57Earlier quoted context omitted.
These are not independent malicious actors. These are researchers and students at a University. FUD does not serve any purpose here. And for full disclosure, I'm one of the four authors of the original complaint to IEEE back in December about the research. I fully believe all the facts have been put forth and there is no reason to spread misinformation about the incident.
>These are not independent malicious actors. These are researchers and students at a University. They wanted to prove that others are too trusting, they got exactly what they wanted: heightened suspicion to things that are normally expected to be done in good faith. I understand that inside the academic world the status imparted by "researchers and students at a University" is significant and important. For those of…
But season this old recipe heavily with some “fuck around and find out” and things get pretty spicy.
Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches
#58What is really sad, is that this could be a good pen-test for the kernel. Especially the idea of introducing bugs that are only vulnerabilities when they all come in together. If only they had contacted the Linux Foundation ahead of time to get permission, and set up terms, like a real pen-test. Then work could be done on detecting, and preventing these sorts of attacks, maybe resulting in a system that could help ev…
Why would the Linux Foundation get to decide on if those researchers are allowed to experiment on and waste the time of volunteer developers?
Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches
#59Earlier quoted context omitted.
"ALL the proposals that were intentionally vulnerable and were really vulnerabilities were not accepted" The thing is there is no way you can actually know that. So this is not some kind of revenge. This is rather a valid precaution.
>The thing is there is no way you can actually know that. We do know since the researchers have told the linux community, the university and IEEE what those patches where. Please do not spread further misinformation about the case. Please read the IEEE statement and the full Linux TAB review. https://www.ieee-security.org/TC/SP2021/downloads/2021_PC_St... https://lkml.org/lkml/2021/5/5/1244
They lied to their IRB.
What evidence do you have that they're telling the truth now?
Re: Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches
#60Earlier quoted context omitted.
Check out my groundbreaking research. I smashed windows on 20 buildings and took cash out of their registers. In order to fix this vulnerability, I suggest you make everyone who passes by your building sign this piece of paper saying they won't smash your windows and take your money. I will happily receive your nearest Nobel prize now, thank you. Signed, UMN Researchers. Edit: Wait, the cops are here. We sincerely ap…
> I smashed windows on 20 buildings and took cash out of their registers. More like they posted on your facebook pro- messages. There's some value in grounding the analogy in reality.