V tomhle pripade se diskutovalo o tom, ze mozna pouzity generator nahodnych cisel neni z kryptografickeho hlediska uplne bezpecny. Tzn. neni tam kod "if(backdoor) then ...", ale mozna je tam chyba v necem cemu rozumi tak stovka lidi na svete. A i kdybyste vedel v cem je chyba tak asi nebude snadne tu chybu vyuzit.
Kdyz v Debianu "vylepsili" generator nahodnych cisel pro OpenSSL tak to trvalo nekolik let nez nekomu doslo, ze PIDu v Unixu vlastne hrozne malo.
Jasne, generator nahodnych cisel:
So, it appears the original allegations that developers working on OpenBSD networking code could have worked on backdoors but there is no proof and had opportunity to add them to OpenBSD but they probably didn't. And if they did, it was probably pulled out long ago anyway. The bugs previously mentioned were not found to backdoor code.
Audits and overall basic cleanup of code continues.
Vid prvy link z guglu: http://www.linuxjournal.com/content/allegations-openbsd-backdoors-may-be-true
Podla mna sa jasne diskutovalo o zabudovanom backdoore.