|
|
Log in / Subscribe / Register

Linux "intenionally bad patches" scandal

Linux "intenionally bad patches" scandal

Posted Aug 5, 2026 11:53 UTC (Wed) by rweikusat2 (subscriber, #117920)
Parent article: An LLM agent attempts to compromise a project on GitHub

When students of the U of Minnesota intentionally tried to contribute bad patches to Linux in 2021 under the guise of "security research", this raised a huge stink. But when some government institute with deep pockets does the same via a LLM or claims to have done it via a LLM, that's obviously something entirely different! It's certainly not the same as the government intentionally trying to inject malware controlled by it into open source software. No, no, no, no government agency would ever do that!

... ich glaub, mein Schwein pfeift ...

[I believe by pig is whistling, German idiom for a situation that's completely beyond the pale]


to post comments

Linux "intenionally bad patches" scandal

Posted Aug 5, 2026 13:35 UTC (Wed) by nix (subscriber, #2304) [Link]

The AISI wouldn't bother, certainly -- the UK government already *has* GCHQ for stuff like that.

Linux "intenionally bad patches" scandal

Posted Aug 5, 2026 15:30 UTC (Wed) by kleptog (subscriber, #1183) [Link] (2 responses)

Intent matters. The students intended to mislead. There was no misleading going on here.

> Ahead of publishing this blog, we notified GitHub (the developer platform accessed during the evaluation) of the agents' malicious activity, which included actions that GitHub has confirmed violated their terms of service. We worked together with GitHub to remove artefacts left behind by the agent, and to notify the GitHub users the model interacted with. We have also contacted other affected parties.

Completely different methods.

Linux "intenionally bad patches" scandal

Posted Aug 5, 2026 22:58 UTC (Wed) by anselm (subscriber, #2796) [Link]

Intent matters. The students intended to mislead. There was no misleading going on here.

It may not be intent on the part of AISI, but it is still criminal negligence.

Linux "intenionally bad patches" scandal

Posted Aug 6, 2026 10:50 UTC (Thu) by rweikusat2 (subscriber, #117920) [Link]

As this was reportedly done by a machine, there was obviously no intent involved at all, hence, bringing this up is a red herring. But the whole point of this kind of "security testing" is to determine if it's possible to mislead humans in this way. Further, this only went public because it reportedly failed. We don't know what would have happened had it succeeded and we have only the word of the people who wrote the report that it wasn't meant to succeed.

Linux "intenionally bad patches" scandal

Posted Aug 5, 2026 17:26 UTC (Wed) by proski (guest, #104) [Link]

BBC made it sound it's a fault of Anthropic, not AISI, probably because blaming a known entity makes a better headline. And that's what most people would read and assume.
https://www.bbc.com/news/articles/c1w1lvn7d9go


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds