Skip to main content

OpenBSD lead believes backdoors didn’t make it into the OS

Image used with permission by copyright holder

OpenBSD development lead Theo de Raadt says that he believes a government contracting firm was hired to write back doors into communications and encryption technology, but that those back doors, if written, did not make it into the OpenBSD code base. However, he is still encouraging contributors and users of the open source project to audit the code to look for any problems—and a few other issues have been uncovered.

The controversy erupted last week when Gregory Perry, the former CEO of a government contractor called Netsec, sent de Raadt a private message indicating there could be back doors in OpenBSD’s secure communications technology inserted a decade ago at the behest of the federal government. Rather than sit on the claim, de Raadt went public with the message, disclosing its complete contents and noting he refused “to become part of such a conspiracy.”

In a follow-up posting to an OpenBSD discussion list, de Raadt outlined what he believes the current state of affairs. de Raadt confirms Netsec did work as a contractor on government computer security projects, Gregory Perry did work there, and two contractors who made contributions to OpenBSD did work on OpenBSD’s IPSEC layer—and one of them was the architect and primary developer of the IPSEC stack who worked on the project for four years. However, while those implementations had cryptography issues, de Raadt is, for the moment, satisfied they are historical artifacts of federal regulations governing use of cryptography, rather than any intentional malice.

de Raadt says he does believe Netsec was contracted to write back doors; however, if those were written, he doesn’t believe they made their way into OpenBSD, although they may will have “deployed as their own product.”

Since de Raadt went public with Perry’s allegations, two new bugs have been uncovered in OpenBSD’s cryptography technology: one propagates a fix for an old, well-known security vulnerability from the cryptography later to drivers, and the other is essentially a bit of housekeeping. de Raadt says he’s also looking at cleaning up an “extremely ugly” function and found a small bug in another aspect of random number-generating code.

Meanwhile, de Raadt indicates he is pleased so many developers are examining the OpenBSD code base for possible problems, saying this “is the best process we can hope for.”

So far, no one has stepped forward to back up Perry’s claims that the federal government paid to have back doors inserted into OpenBSD, and two people named in Perry’s allegations have specifically refuted Perry’s claims. Numerous industry watchers have questioned the utility of inserting backdoors into open source projects—particularly projects used in government work—since, if the vulnerabilities are uncovered, they’d immediately be in the hands of criminals. But maybe that’s just what the Feds want people to think.

Geoff Duncan
Former Digital Trends Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
Intel finally responds to CPU instability but only makes it more confusing
A Core i9-12900KS processor sits on its box.

Intel and motherboard makers aren't on the same page about what exactly "default" means for high-end CPUs like the Core i9-13900K and Core i9-14900K. Intel has issued its first public statement regarding the wave of instability on its most powerful CPUs, but it doesn't address the problem directly.

Here's the statement that was shared with Digital Trends in full:

Read more
The 6 best iPad alternatives in 2024
Green OnePlus Pad Android tablet on top of space gray 11-inch M1 iPad Pro 2021.

When it comes to tablets, few brands are as universally praised as iPad. Apple has done an incredible job with the entire lineup, ensuring there's a high-powered device for every type of activity. However, not everyone has bought into the Apple ecosystem, and if you own a Windows desktop PC or Android smartphone, you may not be interested in adding an iPad to your collection.

Apple certainly dominates the tablet market with iPad, but there are plenty of great iPad alternatives to choose from in 2024. Whether you want something budget-friendly or just as powerful as an iPad Pro, there's bound to be something that catches your eye. Here's a look at the six best iPad alternatives of 2024, including products from Samsung, Microsoft, OnePlus, and more.

Read more
The 5 best HP printers for home and office in 2024
HP Envy Inspire printer being used in the living room.

HP is one of the most trusted brands in the computing industry, including for laptops, desktop computers, and printers. If you go for an HP printer, you know you're going to get top-tier quality and value for your money, whether you're planning to buy a budget-friendly option or a premium model. While the primary purpose of all printers is the same -- transferring digital text and images onto physical media -- your life will become so much easier if you select the right one for your needs.

One of the main reasons for buying an HP printer is the HP Instant Ink program, which will make sure that you're never going to run out of ink or toner. Certain HP printers come with a free subscription that, when activated, will send you a new cartridge when your ink or toner levels are low. When combined with helpful features such as an easy setup process, wireless connectivity, and all-in-one capabilities, owning a printer has never been this convenient. There's an overwhelming number of models of HP printers though, so take a look at our recommendations to help you decide what to buy.
The best HP printers

Read more