oss-sec mailing list archives
Re: Malicious commits to Linux kernel as part of university study
From: Santiago Torres <torresariass () gmail com>
Date: Thu, 22 Apr 2021 12:41:54 -0400
*ALL* OSS projects should review proposed changes for potential security issues, and harden their software & supply chain against attacks. I also welcome research to make that better! But we don’t need researchers who perform attacks on production systems without authorization, or perform attacks on developers without their consent.
Agreed, when I first heard about the paper in November I was very excited to read about it, as I sometimes face skepticism about SC attacks (less so, now that they appear more in the news). Research in the space is important, but this is akin to cutting the brakes on a bus to see when the drivers or the passengers find out... To add to things, I don't think the researchers themselves are aware on how the lkml actually works. They wouldn't be able to assess the result of their experiment, or prepare a meaningful explanation for the IRB with such a flawed model. I'm not trying to point fingers at anybody here, but us academics need to do some soul-seeking in terms of how we engage with the rest of the software-world. Thanks, -Santiago
Attachment:
signature.asc
Description:
Current thread:
- Malicious commits to Linux kernel as part of university study Peter Bex (Apr 22)
- Re: Malicious commits to Linux kernel as part of university study Albert Veli (Apr 22)
- Re: Malicious commits to Linux kernel as part of university study Peter Bex (Apr 22)
- Re: Malicious commits to Linux kernel as part of university study David A. Wheeler (Apr 22)
- Re: Malicious commits to Linux kernel as part of university study Santiago Torres (Apr 22)
- Re: Malicious commits to Linux kernel as part of university study Ariadne Conill (Apr 22)
- Re: Malicious commits to Linux kernel as part of university study r00t4dm (Apr 22)
- Re: Malicious commits to Linux kernel as part of university study Mark Steward (Apr 22)
- Re: Malicious commits to Linux kernel as part of university study Michael Orlitzky (Apr 22)
- Re: Malicious commits to Linux kernel as part of university study Francis Booth (Apr 22)
- Re: Malicious commits to Linux kernel as part of university study Eric Biggers (Apr 22)
- Re: Malicious commits to Linux kernel as part of university study Peter Bex (Apr 22)
- Re: Malicious commits to Linux kernel as part of university study Jan Engelhardt (Apr 23)
- Re: Malicious commits to Linux kernel as part of university study Kurt H Maier (Apr 23)
- Re: Malicious commits to Linux kernel as part of university study James Feister (Apr 23)
- Re: Malicious commits to Linux kernel as part of university study Albert Veli (Apr 22)
- Re: Malicious commits to Linux kernel as part of university study Greg KH (Apr 23)