This is more a pride / trust issue than it is actual damages
This is more a pride / trust issue than it is actual damages
Trust is very hard to make an actual damages claim for, it can be done but outside of the Linux Foundation I am not sure what companies would have an actual damages claim
I suspect many volunteer kernel developers do contract development to pay the bills -- it should not be hard for them to just create a billing code for UMN clean-up. The Linux foundation can aggregate them all and dump that on UMN.
(Also, I have a MSEE from UMN, and I can tell you that the next attempt at fund raising from me is not going to go well for them.)
How far does it extend? The patches would have been reviewed and approved by someone at the linux foundation. Are they complicit and liable? Same goes for the person that merged the code. I don't think that's a door I want to open.
Isn't there such a thing as people being charged with conspiracy to commit XYZ?
There's also no general "Conspiracy" modifier to crimes. Rather, "Conspiracy to X" is a separate law for only a handful of X.
Whether or not there could be 'large damage' in the future (your "once I or someone else takes advantage") is irrelevant, immaterial, and only barely actionable. You could seek an injunction to attempt to prevent further potentially-damaging conduct. But you would not be able to claim any actual damages and would generally not be entitled to any form of compensation, not even for the attorney's fees generated in seeking the injunction.
As a sibling points out, conspiracy is question of criminal law, not civil law. Furthermore, in almost all jurisdictions within the United States, conspiracy requires at least one of the members of the conspiracy to have actually committed some overt act in furtherance of the crime. It should be impossible to find these researchers guilty of a conspiracy -- even if you claim that introducing hypocrite commits was the overt act, it is already clear that their intention is to academically investigate (and improve, if you're feeling charitable) the state of open-source security. Their actions (introducing hypocrite commits) are not in and of themselves violations of criminal law, so you'd still have to prove that they actually conspired to do something actually criminally illegal as well, e.g. intent to actually damage in some specific way, facilitated by these commits, some specific entity Foo which uses the linux kernel. It's perfectly clear that no such intent existed.