TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Linux 5.13 Reverts and Fixes the Problematic University of Minnesota Patches

262 pointsby varbhatalmost 4 years ago

11 comments

dec0dedab0dealmost 4 years ago
What is really sad, is that this could be a good pen-test for the kernel. Especially the idea of introducing bugs that are only vulnerabilities when they all come in together.<p>If only they had contacted the Linux Foundation ahead of time to get permission, and set up terms, like a real pen-test. Then work could be done on detecting, and preventing these sorts of attacks, maybe resulting in a system that could help everyone. At the very least a database for security researchers that are registered, but unknown to maintainers, where they could store hashes of bad commits. Then a check if any of those commits made it through. I know the kernel makes use of rebasing, so that might not be the best approach technically, but something like that. To ease the pain of wasting developers time, sponsors could put up money that the maintainer gets if they catch it, and maybe a smaller amount if they have to revert it.<p>EDIT: if the Linux Foundation said no, they could have tried another large open source project with a governing body, Apache, Python, Postgres, Firefox, etc. It wouldn&#x27;t have been as flashy and high profile, but it would have still been the same research, and odds are you would find at least one project willing to participate.
评论 #27235666 未加载
评论 #27236651 未加载
评论 #27239190 未加载
评论 #27235628 未加载
dwheeleralmost 4 years ago
Just to clarify, all the proposals that were intentionally vulnerable and were really vulnerabilities were not accepted in the first place. However, that event triggered review of all University of Minnesota proposals, and that&#x27;s what&#x27;s being discussed here.
评论 #27233802 未加载
wrsalmost 4 years ago
Just from a code quality process standpoint, that’s an interesting result. Now I’m wondering what would happen if you picked a set of 150 random kernel patches and told 80 reviewers to re-review them assuming they could be malicious. I bet you’d find quite a few fixes.
评论 #27235126 未加载
评论 #27235988 未加载
评论 #27235039 未加载
评论 #27237740 未加载
google234123almost 4 years ago
Isn&#x27;t the moral of the story here that it&#x27;s probably trival for organizations like the FSB&#x2F;NSA&#x2F;Chinese equivalent to get malicious patches accepted into Linux.
评论 #27239090 未加载
评论 #27237344 未加载
评论 #27237370 未加载
评论 #27240704 未加载
foldralmost 4 years ago
As usual, The Onion anticipated this: <a href="https:&#x2F;&#x2F;youtu.be&#x2F;FpN_RjIaVw8" rel="nofollow">https:&#x2F;&#x2F;youtu.be&#x2F;FpN_RjIaVw8</a>
AtNightWeCodealmost 4 years ago
Maybe the people reviewing the changes should be unaware of who made them. I am biased and for sure look more closely at some developers pull requests than others.
评论 #27238968 未加载
teknopaulalmost 4 years ago
honestly fsck these &quot;pen testers&quot;, spend some time trying to make things better rather than trying to break shit and finger pointing.<p>Starting to feel like pen testing is a broken profession.
评论 #27236742 未加载
devitalmost 4 years ago
So what are we doing about all the maintainers that initially approved these commits that were later found to be incorrect?
评论 #27242509 未加载
balozialmost 4 years ago
The moral of this story is this: whatever you do, don&#x27;t be the dweeb that gets their code closely reviewed by the kernel maintainers. (You are actually better off having it reviewed tho)
floor_almost 4 years ago
Anyone else notice the site linked has the most crazy racist wigged out psychos on the comments&#x2F;forums? Yikes.
greenwich26almost 4 years ago
The guilt by association here is now approaching Biblical scales. Like the guy in the comments who wants to close down the entire Computer Science and Electrical Engineering departments at UMN, which probably employ&#x2F;educate the best part of a thousand people. Ha!<p>In general, the fury and seethe which this experiment inspired is amazing. IMO the real disgrace is not the experiment itself, but the response. The kernel developers need to stop being martyrs and playing blame games. They need to be rational and take responsibility for improving their own procedures. Because, if they didn&#x27;t already have them, governments now have entire departments studying how to use deliberate vulnerabilities in open source projects, for military intelligence and other purposes. And they will not be deterred by the continued public flogging of the University of Minnesota.
评论 #27236426 未加载
评论 #27235739 未加载
评论 #27236405 未加载