Comment by brabel

4 years ago

There are two separate issues with this story.

One is that what the researchers did is beyond reckless. Some of the bugs they've introduced could be affecting real world critical systems.

The other issue is that the research is actually good in proving by practical means that pretty much anyone can introduce vulnerabilities into software as important and sensitive as the Linux kernel. This hurts the industry confidence that we can have secure systems even more than it already is.

While some praise may be appropriate for the latter, they absolutely deserve the heat they're getting for the former. There may be many better ways to prove a point.