7 ms·
A university got itself banned from the Linux kernel (2021)
https://archive.md/cBIzm https://archive.md/cBIzm
- gnabgib 8mo ago(2021) Discussion at the time (3025 points, 1954 comments) https://news.ycombinator.com/item?id=26887670 https://news.ycombinator.com/item?id=26887670
- jovial_cavalier 8mo agoThe authors were 100% in the right, and GKH was 100% in the wrong. It's very amusing to go back and read all of the commenters calling for the paper authors to face criminal prosecution. The fact is that they provided a valuable service and exposed a genuine issue with kernel development policies. Their work reflected poorly on kernel maintainers, and so those maintainers threw a hissy fit and brigaded the community against them. Also, banning umn.edu email addresses didn't even make sense since the hypocrite commits were all from gmail addresses.
- yjftsjthsd-h 8mo ago> Also, banning umn.edu email addresses didn't even make sense since the hypocrite commits were all from gmail addresses. The blanket ban was kicked off by another incident after the hypocrite commit incident.
- caycep 8mo agoI mean...there is a whole discussion about the questionable ethics of the research methods in the verge article. And human subjects and issues-of-consent questions aside, they are also messing with a mission critical system (linux kernel), and apparently left crappy code in there for all the maintainers to go back and weed out.
- jovial_cavalier 8mo ago1) once hypocrite commits were accepted, the authors would immediately retract them 2) I don't think it's unethical to send someone an email that has bad code in it. You shouldn't need an IRB to send emails.
- wtallis 8mo ago> I don't think it's unethical to send someone an email that has bad code in it. It's unethical because of the bits you left out: sending code you know is bad, and doing so under false pretenses. Whether or not you think this rises to the level of requiring IRB approval, surely you must be able to understand that wasting people's time like this is going to be viewed negatively by almost anyone. Some people might be willing to accept that doing this harm is worth it for the greater cause of the research, but that doesn't erase the harm done.
- mmooss 8mo agoBad code is wasting time; investigating the security of Linux code approval is a good use of time.
- jovial_cavalier 8mo agoSee another comment I made in this thread about GKH's response - the UMN group submitted a handful of small patches as part of this study, and "wasted" probably a handful of man hours or at worst a few man days of maintainer time. I don't really consider it a waste because evidence that critical open source infrastructure doesn't bother to run static analysis before merging code from randos is actually useful information that the public deserves to have. GKH's response was to waste man weeks or man months of maintainer time persecuting every last commit that happened to come from umn.edu, despite having zero reason to believe these commits were more suspect than any other institution's commits.
- wtallis 8mo ago> evidence that critical open source infrastructure doesn't bother to run static analysis before merging code from randos is actually useful information that the public deserves to have. It's totally possible to obtain evidence of that without being an asshole to kernel maintainers. Which is the kind of thing that an ethics review conducted before the experiment could have pointed out. If the goal of the experiment was merely to demonstrate the lack of routine static analysis capable of catching such vulnerabilities, then the experiment's design was not justified and the experiment was needlessly harmful to non-consenting participants.
- alphager 8mo agoFun fact: one of the researchers removed any reference to this from their publications page: https://www-users.cse.umn.edu/~kjlu/ https://www-users.cse.umn.edu/~kjlu/
- gweinberg 8mo agoYeah, given that it's been 5 years I would think there would be some followup.
- deleted 8mo ago[deleted]
- letmetweakit 8mo agoImo, the experiment was worthwhile, it exposed a risk, hopefully the kernel is better armed against similar attacks now.
- knowitnone3 8mo agoThey retaliated against the entire university. I don't think they learned anything.
- imtringued 8mo agoWhat's the alternative to banning bad actors? Making Linux maintainers take every spam commit 100% seriously as if it was legitimate? All that would bring about is that the second "research project" would be about spamming commits to the Linux kernel to DDOS the maintainers.
- kahrl 8mo ago[flagged]
- arjie 8mo agoThe ultimate problem is that it's easy to fake stuff so you have to use heuristics to see who you can trust. You sort of sum up your threat score and then decide how much attention to apply. Without doing something like that, the transaction costs dominate and certain valuable things can't be done. It's true that Western universities are generally a positive component to that score and students under a professor there are another positive component to the score. It's like if my wife said "I'm taking the car to get it washed" and then she actually takes the car to the junkyard and sells it. "Ha, you got fooled!". I mean, yes, obviously. She's on the inside of my trust boundary and I don't want to live a life where I'm actually operating in a way immune to this 'exploit'. I get that others object to the human experimentation part of things and so on, but for me that could be justified with a sufficiently high bar of utility. The problem is that this research is useless.
- jovial_cavalier 8mo agoNo, random anonymous contributors with cheng3920845823@gmail.com as their email address are not as trustworthy as your wife, and blindly merging PRs from them into some of the most security-critical and widely used code in the entire world without so much as running a static analyzer is not reasonable.
- arjie 8mo agoOh I misunderstood the sections in the article about the umn.edu email stuff. My mistake. The actual course of events: 1. Prof and students make fake identities 2. They submit these secret vulns to Greg KH and friends 3. Some of these patches are accepted 4. They intervene at this point and reveal that the patches are malicious 5. The patches are then not merged 6. This news comes out and Greg KH applies big negative trust score to umn.edu 7. Some other student submits a buggy patch to Greg KH 8. Greg KH assumes that it is more research like this 9. Student calls it slander 10. Greg KH institutes policy for his tree that all umn.edu patches should be auto-rejected and begins reverts for all patches submitted in the past by such emails To be honest, I can't imagine any other such outcome could have occurred. No one likes being cheated out of work that they did, especially when a lot of it is volunteer work. But I was wrong to say the research was useless. It does demonstrate that identities without provenance can get malicious code into the kernel. Perhaps what we really need is a Social Credit Score for OSS ;)
- paultopia 8mo agoWoah, the thing that leapt out at me, as a professor, is that they somehow got an exemption from the UMN institutional review board. Uh, how?? It's clearly human subjects research under the conventional federal definition[1] and obviously posed a meaningful risk of harm, in addition to being conducted deceptively. Someone has to have massively been asleep at the wheel at that IRB. [1] https://grants.nih.gov/policy-and-compliance/policy-topics/human-subjects/research https://grants.nih.gov/policy-and-compliance/policy-topics/h...
- tptacek 8mo agoThe whole story is a good example of why there are IRBs in the first place --- in any story not about this Linux kernel fiasco people generally cast them as the bad guys.
- NetMageSCW 8mo agoSince this IRB approved the study, what good were they?
- margalabargala 8mo agoThat person died in a car accident and they were wearing a seatbelt! Why would anyone wear a seatbelt? They are clearly useless.
- Consultant32452 8mo agoIf a lot of money is involved, it's only a matter of time before all oversight is corrupt. Similarly, you can safely assume all data that is on an important (big money) topic is fake.
- jujube3 8mo agoBut a lot of money was not involved here.
- 8mo ago
- jmclnx 8mo agoDid they ever get un-banned ? IIRC, that Univ has/had great Computer Science Dept. But there is always the BSDs.
- 9cb14c1ec0 8mo agoThe stupid thing about the experiment was that it's never been a secret that the kernel is vulnerable to malicious patches. The kernel community understood this long before these academics wasted kernel maintainer time with a silly experiment.
- hamstergene 8mo agoAgree, to me this "research" is like proving grocery stores are vulnerable to theft by sending students to shoplift. If review process guaranteed that vulnerabilities can't pass, wouldn't that mean that the current kernel should be pristinely devoid of them?
- aucisson_masque 8mo agoWell I didn’t know and thanks to them now I know. I believe most people believe that the Linux kernel couldn’t be compromised because there is multiple approval process and highly professional people vetoing. It seems like a big vulnerability, if a teacher assistant could do that, there is no doubt that government agencies can too.
- something765478 8mo agoWhile I did see some problems with their approach (i.e. doing the IRB reviews retroactively instead of doing them ahead of time, and not properly disclosing the experiments afterwards), I think this research is valuable, and I don't think the authors were too unethical. The event that this most reminds me of the Sokal Squared scandal, where researchers sent bogus papers to journals in order to test those journal's peer review standards.
- firefax 8mo ago>Then, there’s the dicier issue of whether an experiment like this amounts to human experimentation. It doesn’t, according to the University of Minnesota’s Institutional Review Board. Lu and Wu applied for approval in response to the outcry, and they were granted a formal letter of exemption. I had to apply for exemptions often in grad school. You must do so before performing the research -- it is not ethical to wait for outcry then apply after the fact. Any well run CS department trains it's incoming students on IRB procedures during orientation, and Minnesota risks all federal funding if they continue to allow researchers to operate in this manner. (Also "exempt" usually refers to exempt from the more rigorous level of review used for medical experiments -- you still need to articulate why your experiment is exempt to avoid people just doing whatever they want then asking for forgiveness after the fact)
- samgranieri 8mo agoI was honestly surprised the University of Minnesota didn’t part ways with the teacher and students who performed this bullshit research. This level of malfeasance strikes me as something akin to plagiarism for a professional writer.
- cmxch 8mo agoa/b testing the insertion of vulnerable code is not a good idea.
- aetherspawn 8mo agoThe uni should just donate to the Linux maintainers for damages - however much time was wasted - and just move on its merry way. Money is money and buys time, no harm done, useful research conducted, and a whole lot of publicity gained.
- aucisson_masque 8mo ago> If a sufficiently motivated, unscrupulous person can put themselves into a trusted position of updating critical software, there’s honestly little that can be done to stop them,” says White, the security researcher. That says a lot about Linux kernel safety.
- mastermage 8mo agothats literally like 90% of anything. This is open source, code maintained in large swaths by volunteers. Obviously there is not extensive background checks that are being done, the amount of resources that would require is not something the Linux Foundation probably has.
- agent013 8mo agoWasting time — it’s just burning trust, and the reaction was entirely predictable.
- fennecfoxy 8mo agoPretty ridiculous. If I send them an email with a stupid question wasting their time on purpose just to see if they'll reply is that "human experimentation"? What a loose definition. More to the point; are they salty because the author has possibly proved that it's most certainly possible to get critical flaws into the Linux kernel with social engineering? How else is something like that meant to be tested? If you give them a heads-up they'll pay more attention for a short duration of time.