*BSD News Article 89658


Return to BSD News archive

Path: euryale.cc.adfa.oz.au!newshost.carno.net.au!harbinger.cc.monash.edu.au!news.cs.su.oz.au!metro!metro!munnari.OZ.AU!uunet!in1.uu.net!199.94.215.18!cam-news-hub1.bbnplanet.com!news.bbnplanet.com!news.maxwell.syr.edu!news.bc.net!info.ucla.edu!nnrp.info.ucla.edu!psgrain!news.rain.net!pacifier!downsj
From: downsj@threadway.teeny.org (Jason Downs)
Newsgroups: comp.unix.bsd.netbsd.misc,comp.security.unix
Subject: Re: OpenBSD hides security fixes (and blindly integrates code)
Date: 17 Feb 1997 15:24:18 GMT
Organization: OpenBSD
Lines: 43
Message-ID: <5e9t72$2t6@news.pacifier.com>
References: <none-ya023480001912962244220001@news.infi.net> <5e69v0$1u4@news.bayarea.net> <slrn5gdgk7.cne.tqbf@char-star.rdist.org> <5e9e8r$ak4@cynic.portal.ca>
NNTP-Posting-Host: teenyrtr.pacifier.com
Xref: euryale.cc.adfa.oz.au comp.unix.bsd.netbsd.misc:5494 comp.security.unix:31959

In article <5e9e8r$ak4@cynic.portal.ca>,
Curt Sampson <cjs@cynic.portal.ca> wrote:
>In article <slrn5gdgk7.cne.tqbf@char-star.rdist.org>,
>Thomas H. Ptacek <tqbf@enteract.com> wrote:
>
>>Nor is it ethical of them to intentionally complicate the integration.
>
>No, you're quite right. It was childish to put that #ifdef into
>the NetBSD source code. And it's been taken out.
>
>>If Theo de Raadt inserted preprocessor directives to intentionally turn
>>off security fixes #ifdef __NetBSD__, the community would be up in arms.
>
>No, probably not. It's already the general feeling in the NetBSD
>community that Theo has an interest in making it difficult for us
>to move things from OpenBSD back into NetBSD. (I'm not going to
>argue about whether that perception is actually true or not,
>however.)

You obviously don't know Theo very well, then.  How many discussions with
Theo have you had about security issues?

The truth is that Theo-- and OpenBSD in general-- does not have "an interest
in making it difficult" for anyone to integrate changes.  You can attempt
to obfuscate it all you want, but you can't avoid the fact that what you're
saying is simply not true.

I would suggest that if anyone in NetBSD has problems with integrating code,
it's by their own choice.  I certainly *do* see them integrating code (and
only once in a while giving any credit).

OpenBSD would be quite pleased if every other operating system in the world,
be it free or proprietary, were as secure as OpenBSD.

And kindly cease associating OpenBSD purely with Theo.  Theo may have the
source repository in his house, but OpenBSD is made up of a rather large
group of people.

-- 
Jason Downs
downsj@teeny.org  --> teeny.org: Free Software for a Free Internet <--
			     http://www.teeny.org/
	       Little.  Yellow.  Secure.  http://www.openbsd.org/