oss-sec mailing list archives
Re: Malicious commits to Linux kernel as part of university study
From: James Feister <openjaf () gmail com>
Date: Fri, 23 Apr 2021 09:40:45 -0400
"Someone else might be even more unethical later" is a horrible reason to refrain from calling out unethical research methods. This community needs to make it absolutely clear that nonconsensual adversarial "research" is completely unacceptable, or next year you'll see five hundred grant applications intending to throw government-sponsored wrenches into every piece of collaboratively-written software on Earth.
It is naive to think this adversarial behavior is not already taking place. The overall response I have seen to this should be encouraging to all of us that live in these open-source and free software communities. It shows how our system works. In this case, the actors were identified, attributed to a publicly known group, and weeded out. The key part is the information was freely shared, everyone knows about it and can take what they feel are appropriate actions. Just like the submissions to this very mailing list help facilitate and the discussions that follow. As much as we can blame the University or group for the efficacy of their intent, we should assume this behavior has and is already happening. There is no other reason not to. It is a wake-up call to those who think otherwise, in public, private, and government sectors. In this case, the project's maturity ensured the proper people were able to identify the actor and take appropriate actions. My suggestion to part of the solution would not be any single technical process. It would be to ask that more commercial and government agencies ensure some of their budgeted resources (aka people) are used to help maintain the free software and open-source software they leverage. Yes, it will bring a whole new set of challenges, but it may tip the scale to favor those who are there to help. - Jim
Current thread:
- Re: Malicious commits to Linux kernel as part of university study, (continued)
- Re: Malicious commits to Linux kernel as part of university study David A. Wheeler (Apr 22)
- Re: Malicious commits to Linux kernel as part of university study Santiago Torres (Apr 22)
- Re: Malicious commits to Linux kernel as part of university study Ariadne Conill (Apr 22)
- Re: Malicious commits to Linux kernel as part of university study r00t4dm (Apr 22)
- Re: Malicious commits to Linux kernel as part of university study Mark Steward (Apr 22)
- Re: Malicious commits to Linux kernel as part of university study Michael Orlitzky (Apr 22)
- Re: Malicious commits to Linux kernel as part of university study Francis Booth (Apr 22)
- Re: Malicious commits to Linux kernel as part of university study Eric Biggers (Apr 22)
- Re: Malicious commits to Linux kernel as part of university study Jan Engelhardt (Apr 23)
- Re: Malicious commits to Linux kernel as part of university study Kurt H Maier (Apr 23)
- Re: Malicious commits to Linux kernel as part of university study James Feister (Apr 23)
- Re: Malicious commits to Linux kernel as part of university study Greg KH (Apr 23)
- Re: Malicious commits to Linux kernel as part of university study Marcus Meissner (Apr 22)
- Re: Malicious commits to Linux kernel as part of university study Marcus Meissner (Apr 22)
- Re: Malicious commits to Linux kernel as part of university study Silas (Apr 24)
- Re: Malicious commits to Linux kernel as part of university study Thomas Ward (Apr 24)