Hacker News new | ask | show | jobs
by temprature 3081 days ago
They don't like embargoes but they don't go out of their way to break them. The only embargo I know of that OpenBSD broke was for OpenSSL, and that was an honest mistake, as explained here: https://www.tedunangst.com/flak/post/regarding-embargoes

There was another "incident" with the KRAK embargo, where OpenBSD got permission to silently patch it early and then the researcher who found it regretted giving them permission.

I think people put these two incidents together, combine it with the developers' attitudes towards embargoes and come out with: OpenBSD doesn't honour embargoes!

1 comments

I guess if they made an explicit statement that they will comply with embargoes going forward, they'll be able to correct the record. But I don't see that that has happened. Lots of egos have to get out of the way, maybe?