My understanding is that they've gotten better. FreeBSD has had advance notice of some issues. Last I heard they offered to let OpenBSD in too, but hadn't found anyone willing to sign an NDA.
I'm reasonably certain that OpenBSD has never agreed to any NDA from anyone as a matter of principle. It's one of the things that makes me love the project so much.
I don't know if "never" is accurate, but certainly they are very NDA-averse. That's their right, but it means they're going to get left out of things like this; it's simply not possible to organize coordinated disclosure of issues if the participants don't agree to not blab ahead of the agreed disclosure date.
An NDA is a legal agreement. It's entirely possible to organise coordinated disclosures without a legal agreement. The folks pushing NDAs, however, don't seem to be interested in other sorts of agreements.
The alternative would be a "gentleman's agreement"? An NDA would seem to be much more transparent with everyone understanding what was agreed to rather than something agreed upon over cigars and cognac. Refusing to sign NDAs as a matter of principal doesn't seem like a very mature way to conduct business.
It doesn't have to be a handshake and a nod. Things can still be clearly written down. But formal contracts with consequences take it up a notch. And this isn't about how you "conduct business"; that's a very business-oriented view of what's going on.
To be clear, we do routinely operate on the basis of "gentlemen's agreements"... but Intel is a corporation full of lawyers, so I would be astonished if they were willing to work on that basis.
Why would anyone sign an NDA for vulnerabilities? The problem is on Intel's end, not the OS devs.
So that embargoes can be enforced, so that the OS dev doesn't jump the gun and publicly announce the vulnerability to the world before all the other devs have had a chance to ready their patches.