Should we all contact UMN to complain?
Edit: please explain why I’m being downvoted for asking sincere questions.
Should we all contact UMN to complain?
Edit: please explain why I’m being downvoted for asking sincere questions.
For what purpose other than to harass UMN staff? It's obvious they're well aware of the issue and that the community isn't happy with their actions. They've got staff and students that read HN and twitter.
Calling them at this point doesn't accomplish much other than being a DDoS attack and shooting the messenger (there's no way you're going to get in contact with the people who actually conducted the study).
In terms of sheer muscle power, most public officials can't compare to the behemoth that is a university. They are even outclassed on agility.
It may be your local official's job to do something, but the reality of budget anemia is stiffer than their obligations to you.
I understand that what they did was, and is bad and shouldn't be done. However how many other people do not also purposely submit buggy patches? In the end of the day, this happening just show vulnerabilities of the merging system itself.
The issue is that U of Minnesota, and universities in general, had a good standing reputation with the Linux kernel group. Students at the University can still submit patches, but not currently with the strength of institutional credibility standing behind them.
Knowing who to trust and updating your trust when you’re wrong is part of healthy security.
These grad students wanted to make a splash and went after one of the most important code bases on the planet. It stopped being an ethical problem when the kernel maintainers had to manually search for vulnerabilities. They are using hours that could be used elsewhere. The Linux Foundation is paying Greg Kroah-Hartman to solve this problem, so they have a financial loss due to the actions of these grad students. There's your civil liability. They "knowingly cause(d) the transmission of a program, information, code, or command, and as a result of such conduct, intentionally causes damage without authorization, to a protected computer" so there's your criminal liability from the Computer Fraud and Abuse Act. There's probably criminal liability in the state where they live as well.
However, if this were in a more traditional scientific field, this sort of error would be treated as a serious lapse of experimental oversight protocols and the school or the participants would be sanctioned according to their professional discipline (in this case, that would probably be the IEEE).
Unethical experiments are a huge deal. If this had been an experiment on people face to face in e.g. a sociology context, then these students would likely have been expelled (and probably deported) and would likely be leaving the field.
Since it was in an IT area, the U's oversight rules probably weren't even applied.
Isn't that like saying an MIT Media Lab degree has reduced in value due to their relationship with Jeffrey Epstein, Nicky Negroponte and other deplorables.
Yes, and this is also true.
This is more a pride / trust issue than it is actual damages
Isn't there such a thing as people being charged with conspiracy to commit XYZ?
There's also no general "Conspiracy" modifier to crimes. Rather, "Conspiracy to X" is a separate law for only a handful of X.
Whether or not there could be 'large damage' in the future (your "once I or someone else takes advantage") is irrelevant, immaterial, and only barely actionable. You could seek an injunction to attempt to prevent further potentially-damaging conduct. But you would not be able to claim any actual damages and would generally not be entitled to any form of compensation, not even for the attorney's fees generated in seeking the injunction.
As a sibling points out, conspiracy is question of criminal law, not civil law. Furthermore, in almost all jurisdictions within the United States, conspiracy requires at least one of the members of the conspiracy to have actually committed some overt act in furtherance of the crime. It should be impossible to find these researchers guilty of a conspiracy -- even if you claim that introducing hypocrite commits was the overt act, it is already clear that their intention is to academically investigate (and improve, if you're feeling charitable) the state of open-source security. Their actions (introducing hypocrite commits) are not in and of themselves violations of criminal law, so you'd still have to prove that they actually conspired to do something actually criminally illegal as well, e.g. intent to actually damage in some specific way, facilitated by these commits, some specific entity Foo which uses the linux kernel. It's perfectly clear that no such intent existed.
Trust is very hard to make an actual damages claim for, it can be done but outside of the Linux Foundation I am not sure what companies would have an actual damages claim
I suspect many volunteer kernel developers do contract development to pay the bills -- it should not be hard for them to just create a billing code for UMN clean-up. The Linux foundation can aggregate them all and dump that on UMN.
(Also, I have a MSEE from UMN, and I can tell you that the next attempt at fund raising from me is not going to go well for them.)
How far does it extend? The patches would have been reviewed and approved by someone at the linux foundation. Are they complicit and liable? Same goes for the person that merged the code. I don't think that's a door I want to open.