Go Back   Professional Soldiers ® > Technical FAQ Forum > Technology News and Reviews

Reply
 
Thread Tools Display Modes
Old 12-14-2010, 18:00   #1
perdurabo
Guerrilla
 
perdurabo's Avatar
 
Join Date: Nov 2008
Location: Pacific Northwest
Posts: 356
Allegations regarding OpenBSD IPSec

http://marc.info/?l=openbsd-tech&m=129236621626462&w=2

Summary: Former OpenBSD engineer claims the FBI paid some engineers to backdoor their IPSec implementation.

It could be some crazy ramblings, or it may have some truth to it.

IPSec is used to secure network links across IP-based networks. It's my understanding that OpenBSD's implementation is widely-used in other products, similar to OpenSSH.

http://en.wikipedia.org/wiki/Openbsd
http://en.wikipedia.org/wiki/Ipsec
perdurabo is offline   Reply With Quote
Old 12-15-2010, 09:36   #2
Slantwire
Quiet Professional
 
Slantwire's Avatar
 
Join Date: Mar 2006
Posts: 407
Quote:
Originally Posted by perdurabo View Post
Summary: Former OpenBSD engineer claims the FBI paid some engineers to backdoor their IPSec implementation.

It could be some crazy ramblings, or it may have some truth to it.
First impression I'm going with is "crazy ramblings."

OpenBSD is "Open" because it's "open source." As in, anyone can (and is encouraged to) download the raw source code and read it. Spot flaws and report them, even submit code fixes. But submitted changes are audited heavily before being accepted. That's partly to prevent "cure is worse than the disease" situations with badly-written fixes, and also to prevent someone trying to sabotage the code. It's possible someone slipped something in, but a security-minded open source project seems like the most difficult target to do so.

Secondly, the guy who supposedly started this states that his "NDA with the FBI recently expired." I can't speak for others, but I've never signed an NDA that had an expiration date.

The alleged original email has Perry specifically complaining about Bureau types pushing OpenBSD for virtual machine use.... and his signature references VMware, which is probably the biggest seller of virtual machine software. So there are potentially some business competition motives as well.

Also.... the FBI supposedly implemented this secret flaw, leaked it to DARPA, and it still stayed secret until now? Call me skeptical.

I'd say either Perry, de Raadt, or an impostor is making things up.
__________________
..-. .. -. .- .-.. .-.. -.-- | .- -. | . -.-. .... --- | .-.-.

Last edited by Slantwire; 12-15-2010 at 09:46.
Slantwire is offline   Reply With Quote
Old 12-15-2010, 13:10   #3
perdurabo
Guerrilla
 
perdurabo's Avatar
 
Join Date: Nov 2008
Location: Pacific Northwest
Posts: 356
Quote:
Originally Posted by Slantwire View Post
First impression I'm going with is "crazy ramblings."

OpenBSD is "Open" because it's "open source." As in, anyone can (and is encouraged to) download the raw source code and read it. Spot flaws and report them, even submit code fixes. But submitted changes are audited heavily before being accepted. That's partly to prevent "cure is worse than the disease" situations with badly-written fixes, and also to prevent someone trying to sabotage the code. It's possible someone slipped something in, but a security-minded open source project seems like the most difficult target to do so.

Secondly, the guy who supposedly started this states that his "NDA with the FBI recently expired." I can't speak for others, but I've never signed an NDA that had an expiration date.

The alleged original email has Perry specifically complaining about Bureau types pushing OpenBSD for virtual machine use.... and his signature references VMware, which is probably the biggest seller of virtual machine software. So there are potentially some business competition motives as well.

Also.... the FBI supposedly implemented this secret flaw, leaked it to DARPA, and it still stayed secret until now? Call me skeptical.

I'd say either Perry, de Raadt, or an impostor is making things up.
Great points, and it should be verifiable in short order by examining the diffs from the committer logs for the people in question.

I'm not buying it.
perdurabo is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump



All times are GMT -6. The time now is 12:45.



Copyright 2004-2022 by Professional Soldiers ®
Site Designed, Maintained, & Hosted by Hilliker Technologies