Skip to main content
  1. Home
  2. Computing
  3. Legacy Archives

OpenBSD lead believes backdoors didn’t make it into the OS

Add as a preferred source on Google
Image used with permission by copyright holder

OpenBSD development lead Theo de Raadt says that he believes a government contracting firm was hired to write back doors into communications and encryption technology, but that those back doors, if written, did not make it into the OpenBSD code base. However, he is still encouraging contributors and users of the open source project to audit the code to look for any problems—and a few other issues have been uncovered.

The controversy erupted last week when Gregory Perry, the former CEO of a government contractor called Netsec, sent de Raadt a private message indicating there could be back doors in OpenBSD’s secure communications technology inserted a decade ago at the behest of the federal government. Rather than sit on the claim, de Raadt went public with the message, disclosing its complete contents and noting he refused “to become part of such a conspiracy.”

Recommended Videos

In a follow-up posting to an OpenBSD discussion list, de Raadt outlined what he believes the current state of affairs. de Raadt confirms Netsec did work as a contractor on government computer security projects, Gregory Perry did work there, and two contractors who made contributions to OpenBSD did work on OpenBSD’s IPSEC layer—and one of them was the architect and primary developer of the IPSEC stack who worked on the project for four years. However, while those implementations had cryptography issues, de Raadt is, for the moment, satisfied they are historical artifacts of federal regulations governing use of cryptography, rather than any intentional malice.

de Raadt says he does believe Netsec was contracted to write back doors; however, if those were written, he doesn’t believe they made their way into OpenBSD, although they may will have “deployed as their own product.”

Since de Raadt went public with Perry’s allegations, two new bugs have been uncovered in OpenBSD’s cryptography technology: one propagates a fix for an old, well-known security vulnerability from the cryptography later to drivers, and the other is essentially a bit of housekeeping. de Raadt says he’s also looking at cleaning up an “extremely ugly” function and found a small bug in another aspect of random number-generating code.

Meanwhile, de Raadt indicates he is pleased so many developers are examining the OpenBSD code base for possible problems, saying this “is the best process we can hope for.”

So far, no one has stepped forward to back up Perry’s claims that the federal government paid to have back doors inserted into OpenBSD, and two people named in Perry’s allegations have specifically refuted Perry’s claims. Numerous industry watchers have questioned the utility of inserting backdoors into open source projects—particularly projects used in government work—since, if the vulnerabilities are uncovered, they’d immediately be in the hands of criminals. But maybe that’s just what the Feds want people to think.

Geoff Duncan
Former Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
Google Earth’s AI misadventure lasted only a day. It was a tale of dangerous ignorance.
Nuclear reactors, tanks, and historical destruction on a life-like satellite map? Yeah, that's bad.
Nano Banana AI image generator representation.

Technology behemoths are clearly not reading the room, or they are just moving faster than they should when it comes to AI deployment. Google has already stuffed its Gemini AI in every corner of its software stack, from Android to daily productivity tools like Gmail that are used by hundreds of millions of users every day. AI is everywhere. Not all of it is bad, mind you. But in a few places, it just feels forced.

In its latest AI-fication experiment, the company targeted Google Earth. The idea was to let the audience use its Nano Banana 2 AI image generator and make images that can be placed on the map view. On paper, it's a cool idea. What would the Colosseum of Rome look like in your urban neighborhood? Yeah, fun stuff like that.

Read more
AMD is apparently gearing up to raise GPU prices right after Nvidia’s steep hike
AMD has reportedly told AIB partners about a price hike that goes into effect in. August.
AMD RX 7800

AMD is next in line to raise the asking price of its Radeon GPUs, merely days after the news of a similar hike coming for Nvidia graphics cards started making waves. As per ChannelGate on Weibo (h/t VideoCardz), AMD has informed its board partners that the price of GPU and memory bundles will go up by at least 10% in August.

Is a similar price hike coming for standalone graphics cards? I won't be surprised if that happens. The situation is so bad that AMD is planning to bring back graphics cards with 4GB of onboard memory. AMD just introduced the RX 9050 GPU, which costs $279. Notably, it's just $20 less than the RX 9060 XT that offers double the graphics memory.

Read more
Microsoft will make Windows work well with just 8GB RAM. We desperately need it
The dream of a reliable and affordable Windows laptop hinges on the next milestone at Microsoft.
Surface laptop on wooden table

The year 2026 has marked a huge course correction for Microsoft after years of frustrating users with plenty of confusing processes, unoptimized UI elements, and just the generous bloatware that can bring any Windows system to a crawl. Microsoft has finally shifted into a new phase. From fixing the right-click behavior to speeding up the Search system, the company has fixed plenty of papercuts.

The next major milestone is making Windows 11 run smoothly on Windows PCs with just 8GB of RAM. That directly means entry-level and budget laptops will at least get the basics right, even if that means sacrificing the on-device AI bells and whistles. Let's face it. The increasingly AI-first approach to computing on a Windows 11 machine is a little too taxing on the hardware at hand.

Read more