Hacker News new | ask | show | jobs
by jmclnx 671 days ago
I remember this, it was the FBI. OpenBSD people did a huge audit and nothing was found. That was also like 20 years ago.

Also, other articles stated that never happened.

Plus, the "backdoor" in OpenSSH was a Linux only thing possibly related to systemd. It never affected OpenBSD. That is because of Linux people patching OpenSSH with "dependency hell". I believe systemd people is doing something about these dependency chains.

2 comments

The "thing to do" about the dependencies is not to have them in the first place. Distributions where patching OpenSSH to add a libsystemd dependency instead of adding 15 lines of code.
So you’re saying more than 1 person was paid to put the back door in.
And at least one of them was intentionally whistleblown to create an OpenBSD witchhunt wasting both OpenBSD developers time and distraction all the other *BSD and Linux security/devs, while the _real_ target slid under the radar...