Skip to main content

OpenBSD lead believes backdoors didn’t make it into the OS

Image used with permission by copyright holder

OpenBSD development lead Theo de Raadt says that he believes a government contracting firm was hired to write back doors into communications and encryption technology, but that those back doors, if written, did not make it into the OpenBSD code base. However, he is still encouraging contributors and users of the open source project to audit the code to look for any problems—and a few other issues have been uncovered.

The controversy erupted last week when Gregory Perry, the former CEO of a government contractor called Netsec, sent de Raadt a private message indicating there could be back doors in OpenBSD’s secure communications technology inserted a decade ago at the behest of the federal government. Rather than sit on the claim, de Raadt went public with the message, disclosing its complete contents and noting he refused “to become part of such a conspiracy.”

Recommended Videos

In a follow-up posting to an OpenBSD discussion list, de Raadt outlined what he believes the current state of affairs. de Raadt confirms Netsec did work as a contractor on government computer security projects, Gregory Perry did work there, and two contractors who made contributions to OpenBSD did work on OpenBSD’s IPSEC layer—and one of them was the architect and primary developer of the IPSEC stack who worked on the project for four years. However, while those implementations had cryptography issues, de Raadt is, for the moment, satisfied they are historical artifacts of federal regulations governing use of cryptography, rather than any intentional malice.

de Raadt says he does believe Netsec was contracted to write back doors; however, if those were written, he doesn’t believe they made their way into OpenBSD, although they may will have “deployed as their own product.”

Since de Raadt went public with Perry’s allegations, two new bugs have been uncovered in OpenBSD’s cryptography technology: one propagates a fix for an old, well-known security vulnerability from the cryptography later to drivers, and the other is essentially a bit of housekeeping. de Raadt says he’s also looking at cleaning up an “extremely ugly” function and found a small bug in another aspect of random number-generating code.

Meanwhile, de Raadt indicates he is pleased so many developers are examining the OpenBSD code base for possible problems, saying this “is the best process we can hope for.”

So far, no one has stepped forward to back up Perry’s claims that the federal government paid to have back doors inserted into OpenBSD, and two people named in Perry’s allegations have specifically refuted Perry’s claims. Numerous industry watchers have questioned the utility of inserting backdoors into open source projects—particularly projects used in government work—since, if the vulnerabilities are uncovered, they’d immediately be in the hands of criminals. But maybe that’s just what the Feds want people to think.

Geoff Duncan
Former Digital Trends Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
Intel Battlemage GPU: everything we know so far
Intel Arc A770 GPU installed in a test bench.

Despite a rocky start, Intel's Arc GPUs are now among the best graphics cards you can buy. Targeting budget PC gamers, Intel has established itself as a major player in gaming graphics cards, and all eyes are on Team Blue with its next generation of GPUs, codenamed Battlemage.

We know Battlemage GPUs are coming, and Intel has slowly been dropping hints about the graphics cards over the past year. Although we're still waiting on an official release date, specs, and pricing details for Battlemage GPUs, there's a lot we can piece together already.
Intel Battlemage: specs

Read more
Spotify vs. Pandora: which streaming service should you choose?
spotify vs pandora on iphone

Let's settle a musical debate: which music streaming platform should you use: Spotify or Pandora?

Both services have their unique strengths and weaknesses. Spotify boasts a more extensive music catalog, robust social features for sharing and discovering music with friends, and a more polished user experience across devices.

Read more
Ryzen AI nearly hits 60 fps in Black Myth: Wukong, but it’s not that simple
OneXFly F1 Pro gamig handheld.

Although AMD APUs appear in some of the best gaming handhelds, the latest Strix Point chips are still hard to find in new releases. However, the new OneXFly F1 Pro gamin handheld is making its debut with the Ryzen AI HX 370 chip in tow, and according to a benchmark in Black Myth: Wukong, it managed to average an impressive 58 frames per second (fps) at a 15-watt thermal design power (TDP). That's an impressive result, but digging deeper reveals that AAA gaming on the go is still not without any sacrifice.

The OneXFly F1 Pro comes with the Ryzen AI HX 370, which sports a total of 12 cores -- four Zen 5 and eight Zen 5c -- as well as 24 threads. The maximum boost clock on the Zen 5 cores reaches 5.1GHz, but the smaller Zen 5c maxes out at 3.3GHz. The default TDP was rated at 28 watts, but it can be configured between 15W and 54W. For an APU, the AI HX 370 delivers solid graphics capabilities, as it's equipped with the AMD Radeon 890M. It also sports a 7-inch OLED screen with a refresh rate of 144Hz.

Read more