← Back to context

Comment by wtallis

14 hours ago

> evidence that critical open source infrastructure doesn't bother to run static analysis before merging code from randos is actually useful information that the public deserves to have.

It's totally possible to obtain evidence of that without being an asshole to kernel maintainers. Which is the kind of thing that an ethics review conducted before the experiment could have pointed out. If the goal of the experiment was merely to demonstrate the lack of routine static analysis capable of catching such vulnerabilities, then the experiment's design was not justified and the experiment was needlessly harmful to non-consenting participants.