Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I presume you are attempting to imply that this one of the 'leet' FBI backdoors that the Perry email discussed. It would help if you actually said why you thought this patch was interesting when submitting it to HN.

I hope we are not going to get a rash of inarticulate HN submissions for every minor patch to openbsd which may have security implications.

I doubt this is in anyway related to the recent drama.

The initial bad patch which broke things looks like v1.63 of the file. This was committed in 2001 by angelos.

Note: - angelos has a greek email address (for what it is worth) - 1.63 was committed in 2001; the allegations of backdoors seem to be from 2000 and 1999 - it appears to break things for all non-ipsec aware nics. This seems to broad an error for an intentional backdoor

It also looks like the code didn't make it to a release branch before being fixed - so if it was an attempted backdoor, it was not successful.

Disclaimer: I have no experience with BSD kernel code nor with IPSEC.

Edit: I initially thought that angelos also commited the fix as well. I think I need to get my eyes tested



I figured that v1.61 had the initial line in it; 1.63 added the comment explaining its purpose. (the diffs are ugly, though, and hard to tell what lines went where sometimes)

The fix was in 1.75, though, over a year later. In the middle is v1.69, tagged as the release version for OpenBSD 3.0 (and the branch point for 3.1)

1.75 looks like the release version for 3.1 (and branch point for 3.2), so the bug would have been present in the released 3.0 version.


blargh.

You are quite correct - I don't know how I missed that.

I hope the conspiracy theorists don't turn on me for participating in the cover up.


  > I hope we are not going to get a rash of inarticulate
  > HN submissions for every minor patch to openbsd which
  > may have security implications.
I do. Submissions are cheap and skippable. Plus, now I get to look at all these small bugs and not make the same mistakes in my own code, which is both a huge win in my book and something that one can't learn from a textbook.


This submission prior to tptacek's (rather good) analysis was of little value. The original submitter gave absolutely no context to the diff.

I don't think we can depend on tptacek always being on hand.

This bug itself is not novel and something any programmer (if they are being honest) will admit to doing themselves.

The really interesting part of this story is not technical at all (and not evident from the posted patch) - why did the openbsd team not feel it necessary to release a security advisory for this bug. That decision may tarnish their reputation more than any wild conspiracy claims.


The submitter works about 15 away from me, for what it's worth.


"Submissions are cheap and skippable."

By that logic, you will not mind if I spam your mailbox since emails are cheap and skippable.


Angelos has (had?) an email address from the University of Crete (now uoc.gr, formerly uch.gr), of which he's a graduate.

Nothing weird there.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: