peter hessler @openbsd is a user on bsd.network. You can follow them or interact with them if you have an account anywhere in the fediverse. If you don't, you can sign up here.

"Speculating about Intel" by Theo de Raadt. A lunchtime BoF at

Yes, it will be livestreamed.

bsdcan.org/2018/schedule/event

"Speculating about " by Theo de Raadt of will be livestreamed at bsdnow.tv/bsdcan_dms1140 Starts in around 2 hours, at 12:30 Canada/Eastern.

Or come to room DMS1140 if you are at .

To be very clear: OpenBSD has not agreed to an embargo or NDA.

peter hessler @openbsd @phessler

New things from . was not invited. OpenBSD asked Intel to be involved. OpenBSD has not received a reply to multiple-emails.

Theo de Raadt "Speculations about Intel"

· Web · 17 · 13

has *never* intentionally violated an Embargo.

There were two incidents with OpenSSL, where they said "wait for the commits", we saw N-1/N commits, and committed all of them. Unintentional mistake.

Other was Krack Attacks, where we had written permission to commit.

@phessler When I learn so much FreeBSD the next OS I am going to install is OpenBSD!

The FreeBSD Foundation has signed an NDA on the behalf of several (I believe they said 4) developers.

The FreeBSD project has not signed them.

Theo asked FreeBSD to commit the fixes for the FPU state leak issue we have already publicly fixed (marc.info/?l=openbsd-cvs&m=152).

Shouting happened.

@phessler I'd be interested in forming some sort of BSD working group for collaborating on various microarchitectural security vulnerability issues and fixes.

I discussed this statement with a Director of the FreeBSD Foundation, and they said this was basically correct.

@phessler The fact that we honored the #KRACK embargo by keeping silent about the actual impact of the bug beyond #OpenBSD is part of the reason why #FreeBSD acted all surprised on the October 16 2017 disclosure date and patched their users one day too late:

lists.freebsd.org/pipermail/fr

lists.freebsd.org/pipermail/fr

So my guess is that nobody told them during the entire embargo window of July to October 2017.
Is there a better explanation?

In my opinion, they should have been told.

#embargosarestupid