5 ms·
Do you have a source? Google got me only KRACK, which doesn't mesh with your comment. They did participate in that embargo, for six weeks, then refused to exten
by twhb 8y ago
Do you have a source? Google got me only KRACK, which doesn't mesh with your comment. They did participate in that embargo, for six weeks, then refused to extend it to three months because the information was widespread at that point, including to US government agencies, so they felt it likely to be exploited. They communicated this beforehand, got the OK, then patched it silently, which while potentially revealing is no announcement. Their actions seem consistent with a goal of minimizing exploitation across the industry, not some quixotic dedication to non-secrecy. Even the least charitable interpretation of their behavior would lead one to notify them weeks beforehand, not hours.
- LukeShu 8y agoColin Percival was the FreeBSD Security Officer 2005-2012. In that role, he interacted personally with members of the OpenBSD team (and Theo de Raadt in particular) in discussing vulnerabilities with them; this is not necessarily public communication. Elsewhere in this HN thread, he discussed OpenBSD's/Theo's handling of an unspecified vulnerability in 2005, and the "Lazy FPU" vulnerability in 2018. Perhaps one of the more salient bits is when he wrote "I'm not saying that he [Theo] has agreed to embargoes and then broken them. I'm saying that he has made it clear that he isn't interested in acting as a productive member of the community." As a member of the broader security community, and of the BSD security community in particular, Colin is somewhat uniquely qualified to make that statement on his own credibility. Replying to him in the thread is Ted Unangst, a high-profile OpenBSD developer.
- bjpbakker 8y ago> the "Lazy FPU" vulnerability in 2018 You mean that OpenBSD discovered this issue by themselves when they were left out of an ongoing embargo? Please explain to me how one can break an embargo they are not a part of in the first place?
- cperciva 8y agoThey didn't discover it themselves. If they had, how would they have known who was part of the embargo and when it was scheduled to end? Someone leaked it to them.
- ryacko 8y agoPeople make inferences all the time. In order to discover security vulnerabilities in the first place, you have to make inferences about how permissions or memory accesses are mishandled.
- bjpbakker 8y ago“discovered by themselves” was intended to read “discovered outside of the embargo”. Since you didn’t answer my question, let me try again. How can someone break an embargo they’re not a part of? To me the mess back then was a very convenient distraction from the real issue, for Intel and their embargo.
- cperciva 8y agoOpenBSD didn't break the embargo. Whoever leaked it to them broke the embargo (and is very very lucky that nobody is saying who it was).
- busterarm 8y agoVulnerability disclosure is a hotly contested topic in the industry and Colin's comments can also be interpreted as saying Theo has no intention of falling in line with an opinion he clearly disagrees with. Given that Theo maintains OpenBSD and what has come out of the project (https://www.openbsd.org/innovations.html https://www.openbsd.org/innovations.html), I think it's pretty clear that Theo is an extremely productive member of the community.
- majewsky 8y agoNote the way it was said. > [Theo] isn't interested in acting as a productive member of the community. That's not saying he is not an extremely productive member of the community. It's saying that he is not acting in a way appropriate for that role. It's like when people say that Trump is not presidential, they don't deny that he is president.