4 ms·
Colin, which specific embago(es) has OpenBSD broken?
by djmdjm 8y ago
Colin, which specific embago(es) has OpenBSD broken?
- sytse 8y agoYou didn't ask me but I found https://www.reddit.com/r/linux/comments/76ybkv/openbsd_developer_responds_to_the_accusation_that/ https://www.reddit.com/r/linux/comments/76ybkv/openbsd_devel...
- ori_b 8y agoTo quote the KRACK site directly: https://www.krackattacks.com/#openbsd https://www.krackattacks.com/#openbsd > Why did OpenBSD silently release a patch before the embargo? OpenBSD announced an errata on 30 August 2017 that silently prevented our key reinstallation attacks. More specifically, patches were released for both OpenBSD 6.0 and OpenBSD 6.1. > We notified OpenBSD of the vulnerability on 15 July 2017, before CERT/CC was involved in the coordination. Quite quickly, Theo de Raadt replied and critiqued the tentative disclosure deadline: “In the open source world, if a person writes a diff and has to sit on it for a month, that is very discouraging”. Note that I wrote and included a suggested diff for OpenBSD already, and that at the time the tentative disclosure deadline was around the end of August. As a compromise, I allowed them to silently patch the vulnerability. In hindsight this was a bad decision, since others might rediscover the vulnerability by inspecting their silent patch. To avoid this problem in the future, OpenBSD will now receive vulnerability notifications closer to the end of an embargo. In other words: "We said they could make their users more secure by applying the patch, and they did."