Live data from Hacker News

A university got itself banned from the Linux kernel (2021)

theverge.com

51–60 of 74 posts

Re: A university got itself banned from the Linux kernel (2021)

#51

Earlier quoted context omitted.

That person died in a car accident and they were wearing a seatbelt! Why would anyone wear a seatbelt? They are clearly useless.

If a lot of money is involved, it's only a matter of time before all oversight is corrupt. Similarly, you can safely assume all data that is on an important (big money) topic is fake.

But a lot of money was not involved here.

Re: A university got itself banned from the Linux kernel (2021)

#52
post #28

Earlier quoted context omitted.

You know there's a lot of he-said she-said here. The truth is that I was repeating there what they claimed in the paper which is that they intervened prior to merge to mainline.

My point was that (the article claims that) they didn't "reveal that the patches are malicious" at that point. Revert yes, reveal no.

IIRC one of them actually introduced a memory corrupting problem. I don't know if it got accepted or not. I remember seeing the issue and rejecting the patch for rhel.

Re: A university got itself banned from the Linux kernel (2021)

#53
post #22

Earlier quoted context omitted.

1) once hypocrite commits were accepted, the authors would immediately retract them 2) I don't think it's unethical to send someone an email that has bad code in it. You shouldn't need an IRB to send emails.

> I don't think it's unethical to send someone an email that has bad code in it. It's unethical because of the bits you left out: sending code you know is bad, and doing so under false pretenses. Whether or not you think this rises to the level of requiring IRB approval, surely you must be able to understand that wasting people's time like this is going to be viewed negatively by almost anyone. Some people might be w…

Bad code is wasting time; investigating the security of Linux code approval is a good use of time.

Re: A university got itself banned from the Linux kernel (2021)

#54

The stupid thing about the experiment was that it's never been a secret that the kernel is vulnerable to malicious patches. The kernel community understood this long before these academics wasted kernel maintainer time with a silly experiment.

Agree, to me this "research" is like proving grocery stores are vulnerable to theft by sending students to shoplift. If review process guaranteed that vulnerabilities can't pass, wouldn't that mean that the current kernel should be pristinely devoid of them?

Re: A university got itself banned from the Linux kernel (2021)

#55
post #34

Woah, the thing that leapt out at me, as a professor, is that they somehow got an exemption from the UMN institutional review board. Uh, how?? It's clearly human subjects research under the conventional federal definition[1] and obviously posed a meaningful risk of harm, in addition to being conducted deceptively. Someone has to have massively been asleep at the wheel at that IRB. [1] https://grants.nih.gov/policy-an…

I've also had to deal with the IRB a lot as a professor. The retroactive application is extremely weird (although maybe better than nothing?). This seems like one of those situations that would usually require regular review to err on the side of caution if nothing else. It's worth pointing out there are exceptions though: https://grants.nih.gov/sites/default/files/exempt-human-subj... Generally those exceptions fall…

I can see the irb giving retroactive approval solely because of political pressure. Which is why legitimate studies seek approval in advance.

Re: A university got itself banned from the Linux kernel (2021)

#57

Woah, the thing that leapt out at me, as a professor, is that they somehow got an exemption from the UMN institutional review board. Uh, how?? It's clearly human subjects research under the conventional federal definition[1] and obviously posed a meaningful risk of harm, in addition to being conducted deceptively. Someone has to have massively been asleep at the wheel at that IRB. [1] https://grants.nih.gov/policy-an…

> Woah, the thing that leapt out at me, as a professor, is that they somehow got an exemption from the UMN institutional review board. .... in addition to being conducted deceptively

There are cases where deception (as they call it) can be approved (even by ethics boards). Based on the Verge's article, this research setup should not have been approved even by then. But the topic itself seems as relevant as ever with the xz case and all.

Re: A university got itself banned from the Linux kernel (2021)

#58
post #11

Earlier quoted context omitted.

Oh I misunderstood the sections in the article about the umn.edu email stuff. My mistake. The actual course of events: 1. Prof and students make fake identities 2. They submit these secret vulns to Greg KH and friends 3. Some of these patches are accepted 4. They intervene at this point and reveal that the patches are malicious 5. The patches are then not merged 6. This news comes out and Greg KH applies big negative…

>No one likes being cheated out of work that they did, especially when a lot of it is volunteer work. You know what would really be wasteful of volunteer hours? Instituting a policy whereby the community has to trawl through 20 years of commits from umn.edu addresses and manually review them for vulnerabilities even though you have no reasonable expectation that such commits are likely to contain malicious code and y…

That professor just destroyed the ability to trust public institutions like universities to not be malicious actors. You can't restore that trust unless you comb through everything. If you just let them go, you now have to distrust every single university by default, which is even more expensive.

Re: A university got itself banned from the Linux kernel (2021)

#59

Imo, the experiment was worthwhile, it exposed a risk, hopefully the kernel is better armed against similar attacks now.

They retaliated against the entire university. I don't think they learned anything.

What's the alternative to banning bad actors? Making Linux maintainers take every spam commit 100% seriously as if it was legitimate? All that would bring about is that the second "research project" would be about spamming commits to the Linux kernel to DDOS the maintainers.

Re: A university got itself banned from the Linux kernel (2021)

#60
> If a sufficiently motivated, unscrupulous person can put themselves into a trusted position of updating critical software, there’s honestly little that can be done to stop them,” says White, the security researcher.

That says a lot about Linux kernel safety.

Post reply on HN