OpenSSH Ships on Every Mac, Linux Server and Windows. Its Creator Trusts No One
zbruceli.org
zbruceli.org
FWIW, this issue did not affect Slackware. Slackware tries to use unpatched software plus it does not use systemd.
I framed it around the XZ backdoor in March 2024 because it's the cleanest illustration of the thesis: OpenSSH was the target, and OpenBSD wasn't exposed. The backdoor reached sshd on Linux through a distro patch that linked in libsystemd (and with it liblzma), not through upstream OpenSSH. That gap between "the code he controls" and "everything bolted on around it" runs through his whole career, from NetBSD in 1994 to the DARPA money in 2003 to LibreSSL after Heartbleed and pledge/unveil.
My argument in the piece is that the personality and the security model are the same thing: the traits that made him hard to work with are why the code holds. I'm sure people here who've used OpenBSD in production or dealt with the project directly will have corrections or nuance, and I'd like to hear them.