Skip to main content

OpenBSD lead believes backdoors didn’t make it into the OS

Image used with permission by copyright holder

OpenBSD development lead Theo de Raadt says that he believes a government contracting firm was hired to write back doors into communications and encryption technology, but that those back doors, if written, did not make it into the OpenBSD code base. However, he is still encouraging contributors and users of the open source project to audit the code to look for any problems—and a few other issues have been uncovered.

The controversy erupted last week when Gregory Perry, the former CEO of a government contractor called Netsec, sent de Raadt a private message indicating there could be back doors in OpenBSD’s secure communications technology inserted a decade ago at the behest of the federal government. Rather than sit on the claim, de Raadt went public with the message, disclosing its complete contents and noting he refused “to become part of such a conspiracy.”

Recommended Videos

In a follow-up posting to an OpenBSD discussion list, de Raadt outlined what he believes the current state of affairs. de Raadt confirms Netsec did work as a contractor on government computer security projects, Gregory Perry did work there, and two contractors who made contributions to OpenBSD did work on OpenBSD’s IPSEC layer—and one of them was the architect and primary developer of the IPSEC stack who worked on the project for four years. However, while those implementations had cryptography issues, de Raadt is, for the moment, satisfied they are historical artifacts of federal regulations governing use of cryptography, rather than any intentional malice.

de Raadt says he does believe Netsec was contracted to write back doors; however, if those were written, he doesn’t believe they made their way into OpenBSD, although they may will have “deployed as their own product.”

Since de Raadt went public with Perry’s allegations, two new bugs have been uncovered in OpenBSD’s cryptography technology: one propagates a fix for an old, well-known security vulnerability from the cryptography later to drivers, and the other is essentially a bit of housekeeping. de Raadt says he’s also looking at cleaning up an “extremely ugly” function and found a small bug in another aspect of random number-generating code.

Meanwhile, de Raadt indicates he is pleased so many developers are examining the OpenBSD code base for possible problems, saying this “is the best process we can hope for.”

So far, no one has stepped forward to back up Perry’s claims that the federal government paid to have back doors inserted into OpenBSD, and two people named in Perry’s allegations have specifically refuted Perry’s claims. Numerous industry watchers have questioned the utility of inserting backdoors into open source projects—particularly projects used in government work—since, if the vulnerabilities are uncovered, they’d immediately be in the hands of criminals. But maybe that’s just what the Feds want people to think.

Geoff Duncan
Former Digital Trends Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
Google Street View camera captures highly suspicious act, leading to arrests
The Google Street View image showing someone loading a large bundle into the trunk of a car.

Imagery from Googleā€™s Street View has reportedly helped to solve a murder case in northern Spain.

Street View is the online tool that lets you view 360-degree imagery captured by cameras mounted on Googleā€™s Street View cars that travel the world.

Read more
AMD’s RDNA 4 may surprise us in more ways than one
AMD RX 7800 XT and RX 7700 XT graphics cards.

Thanks to all the leaks, I thought I knew what to expect with AMD's upcoming RDNA 4. It turns out I may have been wrong on more than one account.

The latest leaks reveal that AMD's upcoming best graphics card may not be called the RX 8800 XT, as most leakers predicted, but will instead be referred to as theĀ  RX 9070 XT. In addition, the first leaked benchmark of the GPU gives us a glimpse into the kind of performance we can expect, which could turn out to be a bit of a letdown.

Read more
This futuristic mechanical keyboard will set you back an eye-watering $1,600
Hands typing on The Icebreaker keyboard.

I've complained plenty about how some of the best gaming keyboards are too expensive, from the Razer Black Widow V4 75% to the Wooting 80HE, but nothing comes remotely close to The Icebreaker. Announced nearly a year ago by Serene Industries, The Icebreaker is unlike any keyboard I've ever seen -- and it's priced accordingly at $1,600. Plus shipping, of course.

What could justify such an extravagant price? Aluminum, it turns out. The keyboard is constructed of one single block of 6061 aluminum in what Serene Industries calls an "unorthodox wedge form." As if that wasn't enough metal, the keycaps are also made of aluminum, and Serene says they include "about 800" micro-perforations that allow the LED backlight of the keyboard to shine through.

Read more