Thursday, December 23, 2010

OpenBSD code audit uncovers bugs, but no evidence of backdoor

OpenBSD project leader Theo de Raadt disclosed an e-mail earlier this month in which former NETSEC CTO Gregory Perry claimed that his company was paid by the FBI to plant a "backdoor" in the OpenBSD IPSEC stack. The allegations led to a thorough code review and historical analysis of the relevant code.

In a follow-up e-mail published this week, de Raadt outlined his current perspective on the controversy and his interpretation of the findings that have emerged from the ongoing code audit. Reviews are being conducted on the history and provenance of code in the IPSEC stack as well as the current implementation. Reviewers have uncovered several bugs that could have security implications, but the nature of the bugs suggests that they were not intentional, nor were they intended to facilitate a backdoor.

Read the rest of this article...

Read the comments on this post


FIRST SOLAR FINISAR FEI COMPANY FAIRCHILD SEMICONDUCTOR INTERNATIONAL FAIR ISAAC

No comments:

Post a Comment