Remix.run Logo
gnabgib 14 hours ago

(2021) Discussion at the time (3025 points, 1954 comments) https://news.ycombinator.com/item?id=26887670

alphager 12 hours ago | parent | next [-]

Fun fact: one of the researchers removed any reference to this from their publications page: https://www-users.cse.umn.edu/~kjlu/

gweinberg 11 hours ago | parent | prev | next [-]

Yeah, given that it's been 5 years I would think there would be some followup.

jovial_cavalier 13 hours ago | parent | prev [-]

The authors were 100% in the right, and GKH was 100% in the wrong. It's very amusing to go back and read all of the commenters calling for the paper authors to face criminal prosecution. The fact is that they provided a valuable service and exposed a genuine issue with kernel development policies. Their work reflected poorly on kernel maintainers, and so those maintainers threw a hissy fit and brigaded the community against them.

Also, banning umn.edu email addresses didn't even make sense since the hypocrite commits were all from gmail addresses.

yjftsjthsd-h 12 hours ago | parent | next [-]

> Also, banning umn.edu email addresses didn't even make sense since the hypocrite commits were all from gmail addresses.

The blanket ban was kicked off by another incident after the hypocrite commit incident.

caycep 12 hours ago | parent | prev [-]

I mean...there is a whole discussion about the questionable ethics of the research methods in the verge article. And human subjects and issues-of-consent questions aside, they are also messing with a mission critical system (linux kernel), and apparently left crappy code in there for all the maintainers to go back and weed out.

jovial_cavalier 12 hours ago | parent [-]

1) once hypocrite commits were accepted, the authors would immediately retract them

2) I don't think it's unethical to send someone an email that has bad code in it. You shouldn't need an IRB to send emails.

wtallis 12 hours ago | parent | next [-]

> I don't think it's unethical to send someone an email that has bad code in it.

It's unethical because of the bits you left out: sending code you know is bad, and doing so under false pretenses.

Whether or not you think this rises to the level of requiring IRB approval, surely you must be able to understand that wasting people's time like this is going to be viewed negatively by almost anyone. Some people might be willing to accept that doing this harm is worth it for the greater cause of the research, but that doesn't erase the harm done.

mmooss 3 hours ago | parent [-]

Bad code is wasting time; investigating the security of Linux code approval is a good use of time.

AlotOfReading 12 hours ago | parent | prev [-]

1) How did they hit stable then? [0]

2) Yes, emails absolutely need IRB sign-off too. If you email a bunch of people asking for their health info or doing a survey, the IRB would smack you for unapproved human research without consent. Consent was obviously not given here.

[0] https://lore.kernel.org/linux-nfs/CADVatmNgU7t-Co84tSS6VW=3N...