I bet if the embargo were for 5 days they would reconsider. But good luck with that with members like Microsoft, Cisco, Oracle, which a terrible reputation of postponing things the maximum possible.
Here's a page describing the list in question:
http://oss-security.openwall.org/wiki/mailing-lists/distros
Here's the embargo policy:
> Please note that the maximum acceptable embargo period for issues disclosed to these lists is 14 to 19 days .... In fact, embargo periods shorter than 7 days are preferable.
At least it would minimize the risk of zero-daying LibreSSL users.
... but I guess, this isn't where the problem is?
OpenBSD is making the gamble that either a) they can pressure the adults doing coordinated disclosure to stop doing that via their excellent people skills, or b) that they are so awesome that they can find the problems before everyone else.
NB: I love OpenBSD from a security POV, but that doesn't mean what the leaders of the project do is always correct for security.
Didn't people find traces of hearthbleed attacks that happened months before it was published?
There are good arguments for very short embargo periods, especially if you mostly care about the security of your users. (of course, in a perfect world every vendor would be willing/able to release patches after 24 h or so, and it wouldn't matter, but we don't have one of those...)
> Why? Well, they just don't. That's the whole story.
Could have been
> Why? Well, we'd have liked to but they don't embargo reported bugs and we do.
Clearer for everyone.
Assuming it's true.