"Full disclosure" from the University of Minnesota
"Full disclosure" from the University of Minnesota
Posted Apr 29, 2021 22:28 UTC (Thu) by mpg (subscriber, #70797)In reply to: "Full disclosure" from the University of Minnesota by nedu
Parent article: "Full disclosure" from the University of Minnesota
*I'll note that if we scroll down a bit on [3] they already tried to clarify that the malicious commits never got into the kernel, and in [4] the commenter already notes the contradiction.
Still, considering the full set of data we have today, I don't think it's justified to state that "they were deliberately trying to put bugs into production code", as the recent comment I was replying to did.
They did several things they shouldn't have done, such as experimenting on human subjects without their consent, making a paper with IMO weak methodology and relatively poor execution (I think we can hardly draw useful conclusions from their experiment) and communicating poorly about it (which again, would have been less of a problem if they had sought informed consent beforehand), but I don't think "deliberately trying to put bugs into production code" was one of them.
Posted Apr 30, 2021 21:56 UTC (Fri)
by rgmoore (✭ supporter ✭, #75)
[Link]
Not exactly. They say they never intended for their bugs to make it into a released kernel, but they said that only after the whole thing blew up and they were in damage control mode. We don't know what their true intent was. Maybe they intended to stop the bugs from ever being released. Maybe they thought it would be good to get one into a released version and then stealthily patch it in the next version, and that would be safe because it would be fixed by the time they told the world what they had done. We simply can't know what they would have done in the hypothetical world in which one of their patches had made it into the mainline kernel. We have only their word for it, and honestly their word isn't very good with a lot of people right now.
"Full disclosure" from the University of Minnesota
I quickly learned that they tried to make sure the commits didn't get into the kernel.