If you have a history of breaking embargoes, you're going to stop getting included in them.
Edit: Changed to reflect the explicit nature, as it seems the answer is not all BSDs ;)
I think (but not really sure someone please correct me) that openbsd has a policy of not signing NDAs but I think freebsd devs are willing. Why they, netbs, or illumos (although I have no information on how they handle these kinds of disclosures) wasn't alerted is beyond me.
It's not that OpenBSD did not want to cooperate, it's that there was some miscommunication that ended up not fitting in the coordinated disclosure.
Why dont you reach to the source?
>Note that I wrote and included a suggested diff for OpenBSD already, and that at the time the tentative disclosure deadline was around the end of August. As a compromise, I allowed them to silently patch the vulnerability.
I can't speak for other BSDs, but I'm not aware of any time in the past 15 years when FreeBSD has failed to respect an embargo.
Even with 6 months lead time, they were startlingly unprepared in all but their works-as-designed press release.
https://news.ycombinator.com/item?id=11820078
Their handling of recent events has really cemented this view in my mind.
You have to remember that IBM's PR is stuff like "Watson is sitting here curing cancer right now while his best friend Deep Blue beats people at chess!!11!" Intel doesn't do any of that.
CEPH comes close, but cannot completely replace it.
When you connect a thousand nodes to a single storage pool with high throughput and low latency requirements, not everything can cut it.
While it's fair to criticize them, sometimes it comes across as "those hardware bozos don't know what they're doing" and hardware design, at the speeds and features Intel does is hard (just look at the number of competitors)
Then there are other segments including Gamers and Casual users, who really believe in Intel's brand and could careless about what Intel did.
Basically we dont see any damages being done to Intel. And when their PR spin how good their 10nm is and Intel being the underdog with Qualcomm in Modem race, everyone would have forgotten about Meltdown and Spectre.
OpenBSD followed [0] the original embargo from the KRACK researcher, he gave OpenBSD the go-ahead to commit it.. only later we he got CERT involved did they want to delay it for more months. He changed his mind retroactively. It's even stated in the original FAQ for that particular security issue.
Enough already? This has nothing to do with Intel's very selective disclosure of Meltdown.
[0] https://lobste.rs/s/dwzplh/krack_attacks_breaking_wpa2#c_pbh...
It's also not limited to just KRACK. With the OpenSSL/LibreSSL stuff back in 2015, OpenBSD wasn't part of the disclosure because Theo said he wasn't going to deal with an email-list or embargoes prior to that. Marc Espie has said he thinks it's a good thing that the KRACK embargo was broken early.
In fact, your original link is quite explicit.
>Then he got CERT (and, thus, US gov agencies) involved and had to extend the embargo even further until today. At that point we already had the ball rolling and decided to stick to the original agreement with him, and he gave us an agreeing nod towards that as well.
So, stsp pretty specifically says "It got extended, we decided not to follow the new date, and he went 'well, okay'"
https://www.krackattacks.com/#openbsd
>To avoid this problem in the future, OpenBSD will now receive vulnerability notifications closer to the end of an embargo.
If OpenBSD did nothing wrong, it seems quite odd that the same person who you are saying was fully on board with it is now explicitly saying he is going to provide late notifications.
You should read the rest of what you linked, and check the dates carefully.
> As a compromise, I allowed them to silently patch the vulnerability.
It's pretty easy to argue that OpenBSD doesn't like embargoes, but it's pretty hard to argue that they ignore embargoes and patch whenever they want to. In this specific case, the project asked and received permission to patch early. The fact that the researcher regrets this in hindsight is beside the point.
He regrets coming to that compromise when they pushed back. They still pushed back and did not want to follow the extension.
Stop spreading this FUD. OpenBSD developers were allowed to make the patch silently, they contacted the KRACK researcher and he agreed to this. HE CHANGED HIS MIND LATER, after the patch went it and he started blaming OBSD and spreading bullshit.
>Note that I wrote and included a suggested diff for OpenBSD already, and that at the time the tentative disclosure deadline was around the end of August. As a compromise, I allowed them to silently patch the vulnerability.
He asked them to respect the extension. They pushed back against it. Rather than making a big fight about it, he shrugged and went "Well, fine, whatever"
It was obviously not an amenable thing to him, because he's specifically not even going to give them the same level of warning with the understanding they must respect the full embargo period, because right after the bit you quoted, he says:
>To avoid this problem in the future, OpenBSD will now receive vulnerability notifications closer to the end of an embargo.
If it was just him going "Yeah dudes go for it it's cool everyone else will have to wait out the extended embargo but you can just release the patch immediately!" he wouldn't be punishing OpenBSD for it.