First of all, when somebody reports a bug, they do not try to argue that it is not really a bug or something like that, they fix it. And then, they look through their entire code base to see if that kind of bug shows up somewhere else. It is a little sad, but even today, this attitude is not the norm. And it does not matter if that bug is remote code execution in the IP stack or a typo in one of the man pages. They fix it.
Furthermore, I like the approach to security the OpenBSD people take. As Theo de Raadt one explained in a talk, if a security feature needs to be configured before it works, people won't, and if it can be disabled, people will. So most security features on OpenBSD Just Work(tm), out of the box. Some stuff (like pf, their packet filter) obviously needs to be configured and can be disabled, but for the most part, you do not need to do anything special to enjoy the security OpenBSD offers.
Often, the OpenBSD people will do something akin to reinventing the wheel. As one comment on German IT news site once said, with any other project, you would accuse the developers of Not-Invented-Here-syndrome. But the OpenBSD people get it right.
But just to be clear, I have nothing bad to say about Mister Dillon. I hope my comment did not give you the impression I did.
I have no interest in openbsd any more. Debian is significantly better in every way except for "code correctness" and philosophical license issues which are frankly irrelevant to the end user.
I gave up and bought a mac which is a certified unix and apple pays people to actually work on the non-glamorous bits. My laptop lasts nearly all day and everything works. The UX for a laptop user is orders of magnitude better in every single way.
OpenBSD is a great idea but it's a terrible laptop OS.