[OpenBSD]

OpenBSD Security Views

OpenBSD believes in strong security. Our aspiration is to be NUMBER ONE in the industry for security. Due to our open software development model, we are able to take a more uncompromising view towards increasing security than Sun, SGI, IBM, HP, or other vendors are able to.

Like most members of the BUGTRAQ mailing list (which rarely sees OpenBSD security reports these days :-), we believe in full disclosure of security problems. We have found that the coding of proper fixes to security problems typically only requires about 4-5 minutes of coding. Thus we typically have fixes available extremely quickly.

Our security auditing team typically has between six and twelve members, and most of us continually search for and fix new security holes. We have been auditing since the summer of 1997. The process we followed to increase security was simply a comprehensive file-by-file analysis of every critical software component. Flaws were found in just about every area of the system. Entire new classes of security problems were found while we were doing the audit, and in many cases source code which had been audited earlier had to be re-audited with these new flaws in mind.

Another facet of our security auditing process is it's proactiveness. In almost all cases we have found that the determination of exploitability is not an issue. During our auditing process we find many bugs, and endeavor to simply fix them even though exploitability is not proven. We have fixed many simple and obvious careless programming errors in code and then only months later discovered that the problems were in fact exploitable. This proactive auditing process has really paid off. Statements like ``This problem was fixed in OpenBSD about 6 months ago'' have become commonplace in security forums like BUGTRAQ.

The auditing process is not over yet, and as you can see we continue to find and fix new security flaws.

OpenBSD 2.1 Security Advisories

These are the OpenBSD 2.1 advisories. All these problems are solved in OpenBSD 2.2. Some of these problems still exist in other operating systems.

OpenBSD 2.2 Security Advisories

These are the OpenBSD 2.2 advisories. All these problems are solved in OpenBSD current. Some of these problems still exist in other operating systems.

Other Resources

Other security advisories that have (in the past) affected OpenBSD can be found at the Secure Networks archive.

If you find a new security problem, you can mail it to deraadt@openbsd.org.
If you wish to PGP encode it (but please only do so if privacy is very urgent, since it is inconvenient) use this pgp key.


This site Copyright © 1996, 1997 OpenBSD.
$OpenBSD: security.html,v 1.16 1998/02/19 22:41:42 deraadt Exp $