frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

A university got itself banned from the Linux kernel (2021)

https://www.theverge.com/2021/4/30/22410164/linux-kernel-university-of-minnesota-banned-open-source
35•italophil•1h ago

Comments

gnabgib•1h ago
(2021) Discussion at the time (3025 points, 1954 comments) https://news.ycombinator.com/item?id=26887670
jovial_cavalier•33m ago
The authors were 100% in the right, and GKH was 100% in the wrong. It's very amusing to go back and read all of the commenters calling for the paper authors to face criminal prosecution. The fact is that they provided a valuable service and exposed a genuine issue with kernel development policies. Their work reflected poorly on kernel maintainers, and so those maintainers threw a hissy fit and brigaded the community against them.

Also, banning umn.edu email addresses didn't even make sense since the hypocrite commits were all from gmail addresses.

yjftsjthsd-h•15m ago
> Also, banning umn.edu email addresses didn't even make sense since the hypocrite commits were all from gmail addresses.

The blanket ban was kicked off by another incident after the hypocrite commit incident.

letmetweakit•53m ago
Imo, the experiment was worthwhile, it exposed a risk, hopefully the kernel is better armed against similar attacks now.
arjie•36m ago
The ultimate problem is that it's easy to fake stuff so you have to use heuristics to see who you can trust. You sort of sum up your threat score and then decide how much attention to apply. Without doing something like that, the transaction costs dominate and certain valuable things can't be done. It's true that Western universities are generally a positive component to that score and students under a professor there are another positive component to the score.

It's like if my wife said "I'm taking the car to get it washed" and then she actually takes the car to the junkyard and sells it. "Ha, you got fooled!". I mean, yes, obviously. She's on the inside of my trust boundary and I don't want to live a life where I'm actually operating in a way immune to this 'exploit'.

I get that others object to the human experimentation part of things and so on, but for me that could be justified with a sufficiently high bar of utility. The problem is that this research is useless.

jovial_cavalier•31m ago
No, random anonymous contributors with cheng3920845823@gmail.com as their email address are not as trustworthy as your wife, and blindly merging PRs from them into some of the most security-critical and widely used code in the entire world without so much as running a static analyzer is not reasonable.
arjie•14m ago
Oh I misunderstood the sections in the article about the umn.edu email stuff. My mistake. The actual course of events:

1. Prof and students make fake identities

2. They submit these secret vulns to Greg KH and friends

3. Some of these patches are accepted

4. They intervene at this point and reveal that the patches are malicious

5. The patches are then not merged

6. This news comes out and Greg KH applies big negative trust score to umn.edu

7. Some other student submits a buggy patch to Greg KH

8. Greg KH assumes that it is more research like this

9. Student calls it slander

10. Greg KH institutes policy for his tree that all umn.edu patches should be auto-rejected and begins reverts for all patches submitted in the past by such emails

To be honest, I can't imagine any other such outcome could have occurred. No one likes being cheated out of work that they did, especially when a lot of it is volunteer work. But I was wrong to say the research was useless. It does demonstrate that identities without provenance can get malicious code into the kernel.

Perhaps what we really need is a Social Credit Score for OSS ;)

yjftsjthsd-h•7m ago
> 3. Some of these patches are accepted

> 4. They intervene at this point and reveal that the patches are malicious

> 5. The patches are then not merged

It's not clear to me that they revealed anything, just that they did fix the problems:

> In their paper, Lu and Wu claimed that none of their bugs had actually made it to the Linux kernel — in all of their test cases, they’d eventually pulled their bad patches and provided real ones. Kroah-Hartman, of the Linux Foundation, contests this — he told The Verge that one patch from the study did make it into repositories, though he notes it didn’t end up causing any harm.

(I'm only working from this article, though, so feel free to correct me)

paultopia•30m ago
Woah, the thing that leapt out at me, as a professor, is that they somehow got an exemption from the UMN institutional review board. Uh, how?? It's clearly human subjects research under the conventional federal definition[1] and obviously posed a meaningful risk of harm, in addition to being conducted deceptively. Someone has to have massively been asleep at the wheel at that IRB.

[1] https://grants.nih.gov/policy-and-compliance/policy-topics/h...

tptacek•17m ago
The whole story is a good example of why there are IRBs in the first place --- in any story not about this Linux kernel fiasco people generally cast them as the bad guys.
advisedwang•11m ago
A reteroactive exception!
jmclnx•11m ago
Did they ever get un-banned ? IIRC, that Univ has/had great Computer Science Dept.

But there is always the BSDs.

Apple Says 'Pixelmator' App on iOS Will No Longer Receive Updates

https://www.macrumors.com/2026/01/13/pixelmator-no-longer-being-updated/
1•tosh•1m ago•0 comments

EditYourDocuments

https://edityourdocuments.com/
1•Radhan•1m ago•0 comments

Netflix Weighs Amending Warner Bros. Bid to Make It All Cash

https://www.bloomberg.com/news/articles/2026-01-13/netflix-weighs-amending-warner-bros-bid-to-mak...
1•mfiguiere•2m ago•0 comments

Tangled: Decentralized Git hosting and collaboration platform

https://tangled.org/
2•maxloh•3m ago•0 comments

Tuicr – Terminal UI for Code Review

https://tuicr.dev/
1•agavra•4m ago•0 comments

A lightweight comment convention for better human–AI collaboration

https://github.com/ovidiuiliescu/AiComments
1•ovvyblabla•6m ago•0 comments

Tell HN: The insane price hike of internal SSDs

1•malshe•6m ago•0 comments

Humanoid Robots Are Here… and Embarrassingly Bad at Being Our Servants

https://gizmodo.com/humanoid-robots-are-here-and-embarrassingly-bad-at-being-our-servants-ces-202...
1•voxadam•6m ago•0 comments

Games Workshop bans staff from using AI, management not excited about the tech

https://www.ign.com/articles/warhammer-maker-games-workshop-bans-its-staff-from-using-ai-in-its-c...
2•jsheard•7m ago•0 comments

Shopify, Walmart Endorse Google's New Open Commerce Protocol

https://thenewstack.io/shopify-walmart-endorse-googles-new-open-commerce-protocol/
1•CrankyBear•8m ago•0 comments

Recursive structural pattern matching – mathspp

https://mathspp.com/blog/recursive-structural-pattern-matching
2•rbanffy•8m ago•0 comments

Unit testing your code's performance, part 1: Big-O scaling

https://pythonspeed.com/articles/big-o-tests/
1•rbanffy•9m ago•0 comments

TigerBeetle: Financial transactions database designed for safety and performance

https://tigerbeetle.com/
1•maxloh•9m ago•0 comments

Making hypermadia-driven applications feel faster

https://postomator.com/updates/
1•postshakeman•9m ago•0 comments

No one is evaluating AI coding agents in the way they are used

https://marginlab.ai/blog/the-problem-with-coding-benchmarks/
1•qwesr123•11m ago•0 comments

CSS Grid Native Masonry Layout

https://developer.mozilla.org/en-US/docs/Web/CSS/Guides/Grid_layout/Masonry_layout
1•doodlesdev•13m ago•0 comments

Chrome DevTools (MCP) for your AI agent

https://developer.chrome.com/blog/chrome-devtools-mcp
1•lobo_tuerto•14m ago•0 comments

Can Apple read your iMessages? (2013)

https://blog.cryptographyengineering.com/2013/06/26/can-apple-read-your-imessages/
1•chistev•18m ago•0 comments

Intel could blow up the Console Wars (if it had the guts)

1•noumenon1111•19m ago•0 comments

Poll: Do you use RSS in 2026?

1•Darkstryder•20m ago•1 comments

'Molecular microscope' reveals greener path to ammonia

https://phys.org/news/2025-12-molecular-microscope-reveals-greener-path.html
1•PaulHoule•20m ago•0 comments

Organizing My Stuff

https://bezoar.org/posts/2020/0203/organizing-my-stuff/
1•thunderbong•21m ago•0 comments

Show HN: Print Your Anki Decks to Paper

https://evan.widloski.com/ankiprint/
1•Evidlo•21m ago•0 comments

AI layoffs are looking more and more like corporate fiction that's masking dark

https://fortune.com/2026/01/07/ai-layoffs-convenient-corporate-fiction-true-false-oxford-economic...
2•xbmcuser•22m ago•0 comments

OCR Isn't Good Enough: From Medical Faxes to Structured Data

https://robert-mcdermott.medium.com/ocr-isnt-good-enough-from-faxes-to-structured-data-1302d60344c6
1•mcdermott•25m ago•0 comments

Podcast interview with one of the maintainers of StyleX

https://engineering.fb.com/2026/01/12/web/css-at-scale-with-stylex/
1•mostdefinite1•26m ago•0 comments

RFK Jr.'s new food pyramid could be a disaster for the environment

https://www.theverge.com/report/861326/meat-food-pyramid-protein-nutrition-guideline-climate-beef...
1•ebbi•27m ago•1 comments

30 Years

https://www.charlespetzold.com/blog/2026/01/30-Years.html
1•strmcrw•27m ago•0 comments

Ask HN: Does anyone else think that humanoid robots is a bubble?

2•NewUser76312•28m ago•4 comments

Whistleblower leaks personal details of thousands of Border Patrol/ICE Agents

https://www.rawstory.com/ice-agents-data-leak/
8•ck2•31m ago•6 comments