Live data from Hacker News

A university got itself banned from the Linux kernel (2021)

theverge.com

61–70 of 74 posts

Re: A university got itself banned from the Linux kernel (2021)

#61

The stupid thing about the experiment was that it's never been a secret that the kernel is vulnerable to malicious patches. The kernel community understood this long before these academics wasted kernel maintainer time with a silly experiment.

Well I didn’t know and thanks to them now I know.

I believe most people believe that the Linux kernel couldn’t be compromised because there is multiple approval process and highly professional people vetoing.

It seems like a big vulnerability, if a teacher assistant could do that, there is no doubt that government agencies can too.

Re: A university got itself banned from the Linux kernel (2021)

#63
Pretty ridiculous. If I send them an email with a stupid question wasting their time on purpose just to see if they'll reply is that "human experimentation"? What a loose definition.

More to the point; are they salty because the author has possibly proved that it's most certainly possible to get critical flaws into the Linux kernel with social engineering? How else is something like that meant to be tested?

If you give them a heads-up they'll pay more attention for a short duration of time.

Re: A university got itself banned from the Linux kernel (2021)

#64

Imo, the experiment was worthwhile, it exposed a risk, hopefully the kernel is better armed against similar attacks now.

They retaliated against the entire university. I don't think they learned anything.

[flagged]

Re: A university got itself banned from the Linux kernel (2021)

#65

Earlier quoted context omitted.

Since this IRB approved the study, what good were they?

That person died in a car accident and they were wearing a seatbelt! Why would anyone wear a seatbelt? They are clearly useless.

> That person died in a car accident and they were wearing a seatbelt! But in any story not about this car accident people generally cast them as the useless.

This story isn't evidence that IRBs are always useless, but also it's not an example of them being useful. The thing this story shows is they are sometimes useless.

Re: A university got itself banned from the Linux kernel (2021)

#66

Woah, the thing that leapt out at me, as a professor, is that they somehow got an exemption from the UMN institutional review board. Uh, how?? It's clearly human subjects research under the conventional federal definition[1] and obviously posed a meaningful risk of harm, in addition to being conducted deceptively. Someone has to have massively been asleep at the wheel at that IRB. [1] https://grants.nih.gov/policy-an…

> Woah, the thing that leapt out at me, as a professor, is that they somehow got an exemption from the UMN institutional review board. .... in addition to being conducted deceptively There are cases where deception (as they call it) can be approved (even by ethics boards). Based on the Verge's article, this research setup should not have been approved even by then. But the topic itself seems as relevant as ever with…

Right, that's something to discuss at the IRB review. But they didn't even do an IRB review before conducting the experiment. After the outcry, they went back to the IRB and said "was this OK?"

Re: A university got itself banned from the Linux kernel (2021)

#67

Earlier quoted context omitted.

That person died in a car accident and they were wearing a seatbelt! Why would anyone wear a seatbelt? They are clearly useless.

> That person died in a car accident and they were wearing a seatbelt! But in any story not about this car accident people generally cast them as the useless. This story isn't evidence that IRBs are always useless, but also it's not an example of them being useful. The thing this story shows is they are sometimes useless.

Yeah, that's reasonable.

Re: A university got itself banned from the Linux kernel (2021)

#68
post #56
post #12

Did they ever get un-banned ? IIRC, that Univ has/had great Computer Science Dept. But there is always the BSDs.

The Gopher protocol was made there!

Yes, and I use Gopher as a B/U of my Gemini Capsule. A couple of years ago I moved my site to Gemini with Gopher as a mirror.

I found doing that makes maintenance far easier that what I had to do with html.

Re: A university got itself banned from the Linux kernel (2021)

#69

Earlier quoted context omitted.

1) once hypocrite commits were accepted, the authors would immediately retract them 2) I don't think it's unethical to send someone an email that has bad code in it. You shouldn't need an IRB to send emails.

1) How did they hit stable then? [0] 2) Yes, emails absolutely need IRB sign-off too. If you email a bunch of people asking for their health info or doing a survey, the IRB would smack you for unapproved human research without consent. Consent was obviously not given here. [0] https://lore.kernel.org/linux-nfs/CADVatmNgU7t-Co84tSS6VW=3N...

1) They did not hit stable. GKH is referring, in this email, to a legitimate attempt to contribute from a student at UMN. Whether or not this student was part of the hypocrite commits study, I don't know. But it's not a hypocrite commit, just a normal buggy commit. You can tell, because it's from a umn.edu email address, which they did not use for hypocrite commits.

2) I don't actually care about the internal policies of UMN's IRB. Whether or not the study's approval was proper and whether they would get into trouble with their boss is not my problem. The point is that what they did is obviously not immoral or unethical.

Re: A university got itself banned from the Linux kernel (2021)

#70
post #22

Earlier quoted context omitted.

1) once hypocrite commits were accepted, the authors would immediately retract them 2) I don't think it's unethical to send someone an email that has bad code in it. You shouldn't need an IRB to send emails.

> I don't think it's unethical to send someone an email that has bad code in it. It's unethical because of the bits you left out: sending code you know is bad, and doing so under false pretenses. Whether or not you think this rises to the level of requiring IRB approval, surely you must be able to understand that wasting people's time like this is going to be viewed negatively by almost anyone. Some people might be w…

See another comment I made in this thread about GKH's response - the UMN group submitted a handful of small patches as part of this study, and "wasted" probably a handful of man hours or at worst a few man days of maintainer time. I don't really consider it a waste because evidence that critical open source infrastructure doesn't bother to run static analysis before merging code from randos is actually useful information that the public deserves to have.

GKH's response was to waste man weeks or man months of maintainer time persecuting every last commit that happened to come from umn.edu, despite having zero reason to believe these commits were more suspect than any other institution's commits.

Post reply on HN