OpenSSH Ships on Every Mac, Linux Server and Windows PC. Its Creator Trusts No One.

· 36 min read

OpenSSH creator Theo de Raadt was pushed out of NetBSD, lost a DARPA grant and fought half of open source. Now his paranoid code guards the world's servers.

Dunnottar Castle on its sea cliff under a grey sky


I. Half a Second

Until the last days of March 2024, almost nobody outside a small circle of programmers had heard of liblzma. It was a compression library, a piece of plumbing buried deep in Linux, and for two years someone had been preparing to use it to walk through the front door of the internet.

He called himself Jia Tan. He was patient. He wrote helpful patches. He was polite to an exhausted volunteer maintainer, and useful, and always there, and in time he was given the keys. Then he began to build. The payload went into the release tarballs in pieces, obfuscated and disguised as test files. It was aimed at OpenSSH, the program that guards remote access to nearly every server on Earth. Once the code shipped in the stable releases of the major Linux distributions, whoever held the private key could let himself into a large share of the world's machines.

It nearly worked. What stopped it was half a second.

Andres Freund, an engineer at Microsoft, noticed that SSH logins on his Debian test machine were burning about five hundred milliseconds more CPU than they should. Most people would have let it go. Freund didn't. He followed the delay down through the SSH daemon, through systemd, and into liblzma, and at the bottom he found the backdoor.

He posted the disclosure to the oss-security list on March 29. Within hours the Linux world was doing triage. Red Hat issued an urgent advisory. Debian rolled back. At banks, cloud providers and hospital networks, engineers were pulled out of bed to tear open their build pipelines. They were all asking the same question: are we exposed?

The city of Calgary sits on the high plains of southern Alberta, where the prairie runs flat to the east and the Rockies stand to the west like a wall. In winter the cold comes down hard and stays. Sometimes a wind called the Chinook pours off the mountains, warm and dry, and lifts the temperature twenty degrees in an afternoon. Snowbanks rot to slush by dark. Locals say the Chinook brings migraines and short tempers, and that dogs won't settle while it blows. It arrives without warning, and nobody asks for it.

An empty Calgary road in a night blizzard

Here, one operating system was not asking.

OpenBSD had never been in the blast radius. The attack depended on a chain. Linux distributions had patched their SSH daemons to talk to systemd, systemd pulled in liblzma, and liblzma carried the poison into the daemon's memory. OpenBSD had never let systemd in. It had never tied that dependency to its most sensitive process. For nearly a decade it had wrapped its programs in restraints called pledge and unveil. Under those rules, a program that reached for anything it hadn't declared in advance was killed by the kernel.

Nine years earlier, at a conference in Quebec, the man who built that system had stood before a room and named the danger. He didn't speak of compressors in general. He named this one. "Especially with compressors like XZ," he said, "which had 2 memory system vulnerabilities in the last year…"

Nobody had taken much notice at the time.

His name is Theo de Raadt. He has called Richard Stallman "a lying cheating hypocrite" and called Linux "garbage." The first project he helped found threw him out. A single sentence to a newspaper cost him a million dollars of Pentagon money. And his code is almost certainly running on the machines that hold your bank balance, your medical records and the servers that delivered this page. He lives far from the centers of the technology industry, in a city known for cattle and oil. He trusts almost no one. That is why so many others can afford to trust.

Theo de Raadt


II. The Boy Who Left Before the Army Came

It begins with a departure.

Pretoria, South Africa, 1977. Soweto burned the year before. The apartheid state is at war with its own people and its neighbors, and every white boy in the country has a date waiting in his future: two years of compulsory service in that army. Theo de Raadt was born on May 19, 1968. He is the eldest of four children of a Dutch father and a South African mother. He is nine, so the draft is still a decade away. The family doesn't wait.

In November 1977 they leave for Calgary. It is the boy's first lesson in security, and the oldest one. When the system is rotten, you don't negotiate with it. You leave.

A boy from the Highveld steps off a plane into a prairie November, into a cold that hurts your teeth under a white, enormous sky. He learns it. In 1983 the ground moves again. Canada falls into its worst recession since the Depression, the Alberta oil economy collapses, and the family relocates for a time to the Yukon, where caribou outnumber people and the winter light lasts only a few hours.

The Yukon

By then he has a computer. It is a Commodore VIC-20, a wedge of beige plastic with five kilobytes of memory that plugs into a television. It speaks BASIC and, for the serious, 6502 machine code. It forgives nothing. There is no internet to ask and no one to call. There is the manual and the cursor. If you get one byte wrong the machine locks up, and you start again.

Commodore VIC-20

An Amiga comes later. But the VIC-20 is the one that counts. The family has been uprooted twice. The country is still foreign, and the land outside is as hard and clean as a sheet of ice. Economies collapse and people fail you, but the machine is exact. Understand it down to the last register and it will never betray you.

For a boy teaching himself to program alone in the northern dark, correctness isn't a matter of taste. It is shelter.

He returns to Calgary and finishes a Bachelor of Science in Computer Science at the University of Calgary in 1992. He is twenty-four and brilliant. He hasn't yet learned that most people don't care about correctness the way he does.


III. Exile

In 1993 the free Unix world is a frontier town. AT&T and Berkeley are fighting in court over who owns the code. Linus Torvalds is a Finnish student with a hobby kernel. A few hackers scattered across the continent are trying to turn 386BSD, a free Unix for the cheap Intel PC, into something that actually works. It isn't working well enough, and it's run too loosely. Four of them break away: Chris Demetriou, Adam Glass, Charles Hannum and Theo de Raadt. They call their project NetBSD.

De Raadt pours himself into it. With Chuck Cranor he builds the Sun SPARC port, and he writes code in quantities that are hard to account for. When NetBSD 1.0 ships in October 1994, it is the project's first multi-platform release. Much of that portability has his fingerprints on it.

Sun SPARCstation

Then there are the mailing lists.

On a mailing list, de Raadt is a blowtorch. A user asks a naïve question and gets flayed. A developer sends a patch he considers sloppy, and it comes back stripped to the bone. He is usually right, which makes it worse. He is right in a way that leaves people bleeding, and he doesn't seem to see the blood. Or he sees it and doesn't think it matters next to whether the code is correct.

The hacker culture of 1994 will forgive almost anything if the code is good. Almost. De Raadt finds the limit and goes past it.

On December 20, 1994, five days before Christmas, the rest of the NetBSD core team revokes his access to the source repository. The project has locked out one of its own founders.

Three days later Adam Glass writes to the netbsd-users list:

"This was a very difficult decision to make, and resulted from Theo's long history of rudeness towards and abuse of users and developers of NetBSD. We believe that there is no place for that type of behaviour from representatives of the NetBSD Project, and that, overall, it has been damaging to the project."

Glass concedes that de Raadt was the "principal caretaker of NetBSD's SPARC support, and has written too much code to mention." That changes nothing. He is out.

Years later Charles Hannum looks back on it. "It's widely claimed that I'm 'the one' who ejected Theo from the NetBSD community. That is false," he says. "At that time in NetBSD's history, Chris G. Demetriou was playing the role of alpha male, and I wasn't even given a choice. I was certain it was going to bite us in the ass. I think the question for historians is not whether it did bite us in the ass, but how many times and how hard."

The writer Peter Wayner, in Free for All, puts it mildly: de Raadt's "excessive directness" rubbed people the wrong way. From the inside it must have looked different. He had already lost one country before it could conscript him and lost his footing in another when its economy collapsed. Now the one place he had built with his own hands had voted him out, in writing, in public. They let him build it, and then they took it away.

Another man might have gone quiet after that.

De Raadt made a rule instead. He would never again build anything whose keys another person could take from him.


IV. Year Zero

October 1995, in Calgary. De Raadt takes the NetBSD source, the same code he'd been locked out of, and forks it. The license permits it, so no one can stop him. He calls the new project OpenBSD.

This time there is no core team with the power to remove him. There is one leader. Releases come every six months, on schedule, and each is supported for a year and then retired. The code is audited constantly, line by line across the whole tree. When one bug is found, the team hunts down every other instance of that kind of mistake. Features come second. So do performance, hardware support and feelings. Only one question matters: can this be broken?

Puffy, the OpenBSD mascot

The mascot is a pufferfish called Puffy. It looks cute enough for a T-shirt, but a pufferfish survives by swelling into a ball of spines and being poisonous. No software project has chosen a more honest emblem.

Early on, a Calgary security firm called Secure Networks, later absorbed by McAfee, gets in touch. It is building a network auditing tool called Ballista. The collaboration gives OpenBSD a doctrine, proactive security. You don't wait for the burglar to break the window. You assume he is already in the yard with his hand on the glass.

OpenBSD turns paranoia into an engineering method. All code is assumed guilty. All networks are hostile. Every programmer will make mistakes, the project's own included, so the system has to survive them. When something looks wrong, the program dies at once and loudly, because a crash can be recovered from and a compromise may not be. The default install turns almost nothing on, so that newcomers, in the project's words, need not "become security experts overnight."

Then de Raadt puts a boast on the front page of the website, where every attacker on Earth can read it:

"Five years without a remote hole in the default install!"

It holds for years. Across the industry, patches for commercial systems arrive every month like clockwork. In Alberta, a volunteer project goes on daring anyone to break in.

In June 2002, Mark Dowd of Internet Security Systems finds a flaw in OpenSSH's challenge-response authentication. De Raadt changes the slogan in public: "One remote hole in the default install, in nearly 6 years!" In 2007, Alfredo Ortega finds a second hole, in the network stack. The slogan changes again:

"Only two remote holes in the default install, in a heck of a long time!"

That is two remote holes in more than a decade. The people who called him paranoid have their answer.


V. The Padlock

Until the mid-1990s, the internet ran unencrypted.

System administrators logged into remote machines with Telnet or rlogin. Every keystroke crossed the wire in cleartext, including usernames, passwords and root passwords. Anyone on the network with a card in promiscuous mode could read them. In February 1994, CERT advisory CA-94:01 described intruders who had quietly collected login credentials for tens of thousands of systems.

DEC VT100 terminal

In 1995, Tatu Ylönen, a researcher at the Helsinki University of Technology, wrote the Secure Shell. It encrypted the session and verified the server with cryptographic keys. He released it free, and by the end of the year it had twenty thousand users in fifty countries. Then he founded a company, SSH Communications Security, and the license began to tighten. By 1999 new versions carried commercial restrictions, and companies were being directed to a firm called Datafellows to buy one.

For de Raadt, this was intolerable. The internet's most important security tool was being walled off, and a company would hold the keys to everyone's front door.

The OpenBSD developers found an old version of Ylönen's code, 1.2.12, that was still under a free license. A Swedish programmer named Björn Grönvall had been maintaining it under the name OSSH. It spoke only the old 1.3 protocol, but they could take it. OpenBSD 2.6 was due to ship in less than two months. De Raadt decided it would ship with an SSH that was entirely free.

The work went fast. From Calgary, de Raadt cut out convoluted and non-portable code so that nothing could hide in it. Niels Provos, a German living in the United States, drove up to Canada again and again to work at his side, stripping out restricted cryptography and GPL-licensed code and replacing it with freely reusable libraries such as OpenSSL. In Germany, Markus Friedl rewrote the protocol support, first for SSH 1.5 and later for SSH 2.0 and SFTP. Dug Song, Aaron Campbell and Bob Beck filled the gaps. They had no office and no investors, only a deadline they had set themselves and would not move.

On December 1, 1999, OpenBSD 2.6 shipped with OpenSSH 1.2.2.

OpenSSH

What happened next was never part of de Raadt's plan. Damien Miller and Philip Hands ported the code to Linux and other Unix systems, creating the "portable" version and leaving OpenBSD's core untouched. The code was free. The paranoid team had audited it. The RSA patent would expire in the United States in September 2000. So everyone took it. It went into Linux, Solaris, AIX and macOS, and into millions of routers, firewalls and appliances. By 2008 a survey found it on more than 80 percent of SSH servers. Estimates today run higher.

A man who had been thrown out of his own project had built a fortress for himself and a few like-minded paranoiacs. He had ended up making the lock the whole world uses. Bank transfers pass through it. An administrator patching a hospital database at three in the morning logs in with it. Cloud platforms are run through it. He built it to keep the world out, and the world moved in.

The industry built fortunes on it. In 2004, accepting an award from the Free Software Foundation, de Raadt gave an accounting of the thanks: the hardware vendors who used OpenSSH in all their products had given the project "a total of one laptop" in five years. "And asking them for that laptop took a year. That was IBM."


VI. Half a Cruise Missile

At the University of Pennsylvania, Jonathan Smith of the Distributed Systems Laboratory ran a project called POSSE, Portable Open Source Security Elements. It had won a $2.125 million grant from DARPA, the Pentagon's research agency and the builder of the original ARPANET. The government wanted hardened, open security software for its own computers, and it chose OpenBSD, calling it "the computing world's most secure forum for the development of open-source software." About $1 million of the grant went to de Raadt's project.

The project had lived on donations and on sales of CD-ROMs and T-shirts, so the money meant survival. It could pay for hardware and hackathons and let developers work full-time.

In March 2003 the United States invaded Iraq. Tomahawk missiles rose off warships in the Persian Gulf and the Red Sea, trailing white fire across the night, and the images went around the world.

Tomahawk cruise missile launch, 2003

In April a reporter from the Globe and Mail called de Raadt and asked how he felt about taking military money.

With a million dollars at stake, the expected answer was gratitude, something about the work benefiting everyone, and then silence.

De Raadt said this:

"I actually am fairly uncomfortable about it, even if our firm stipulation was that they cannot tell us what to do. We are simply doing what we do anyways — securing software — and they have no say in the matter. I try to convince myself that our grant means a half of a cruise missile doesn't get built."

Within days DARPA cut off the funding. Smith said military officials had been uncomfortable with the OpenBSD leader's anti-war remarks. The million dollars was gone.

A more practical man would have called the Pentagon the next morning to apologize and say he had been quoted out of context. De Raadt did not retract anything. He would not put a closed, unaudited binary in his kernel, and he would not put an unaudited opinion in his mouth either. His independence was part of the security model. If someone else's money could decide what he said, it could decide what he shipped.

The project scrambled and survived, poorer than before.


VII. Nasty Things

If he would do that to the Pentagon, his peers could expect no better.

He saw Linux, the corporate-backed system that had taken over the server market, as everything wrong with software. It put features, hardware support and market share first and treated security as an afterthought. In 2005, Forbes ran an interview headlined "Is Linux For Losers?" and de Raadt said:

"It's terrible, everyone is using it, and they don't realize how bad it is. And the Linux people will just stick with it and add to it rather than stepping back and saying, 'This is garbage and we should fix it.'"

Linus Torvalds answered in kind. On the Linux kernel mailing list in 2008 he called the OpenBSD crowd "a bunch of masturbating monkeys," because they made such a big deal of security that they "pretty much admit that nothing else matters to them." He meant it as an insult. In Calgary it read as a fair description.

Linus Torvalds

Then there were the blobs. Modern Wi-Fi chips, GPUs and network cards often work only with secret firmware, called a "binary blob," which is loaded into the device and given high privileges without anyone outside the vendor seeing what it does. Linux mostly accepts these blobs so that laptops can connect to the coffee-shop Wi-Fi.

De Raadt refused. To him a blob was a stranger handed the key to the vault with no identification. It might contain a bug or a backdoor, and there was no way to tell, because no one was allowed to look. So he went after the hardware vendors in public, by name, demanding documentation.

At a conference in Melbourne, an HP executive warned him: "If you say nasty things like that to vendors you're not going to get anything."

De Raadt replied:

"No, in eight years of saying nothing, we've got nothing, and I'm going to start saying nasty things, in the hope that some of these vendors will start giving me money so I'll shut up."

The shaming worked. Several major Taiwanese wireless chipmakers opened their documentation. Free drivers followed, for OpenBSD and for every other open system, Linux included. The man everyone called impossible got what polite people had been requesting for years. Almost nobody thanked him.

Then there was Richard Stallman, founder of the Free Software Foundation and author of the GPL. Its copyleft terms require anyone who builds on the code to keep their own work free as well. De Raadt considered that a leash dressed up as freedom. OpenBSD used permissive licenses, ISC and BSD, which let anyone, corporations included, use the code for anything. That is how OpenSSH ended up everywhere. To de Raadt, that was freedom. The GPL was somebody else's rules.

Richard Stallman

In December 2007, on the openbsd-misc mailing list, Stallman accused OpenBSD of steering users toward non-free software through its ports tree. De Raadt explained, with rising heat, that the ports tree contained only Makefiles and URLs and none of the non-free software itself. Stallman didn't back down. De Raadt wrote:

"…you are being the usual slimy hypocritical asshole… You may have had value ten years ago, but people will see that you don't anymore… Richard, you are a lying cheating hypocrite."

Hardly anyone speaks to Stallman that way, in public or otherwise. De Raadt does, because nothing stands between what he believes and what he types. It is the same trait that kept him from lying to the Globe and Mail and keeps him from shipping a blob. His honesty isn't aimed at anyone in particular. It points in every direction, like the spines on a pufferfish.


VIII. The Letter

In December 2010 an email arrived without warning.

It came from Gregory Perry, former chief technology officer of NETSEC, a now-defunct government contractor, and once a technical consultant to the FBI. His non-disclosure agreement had expired, he wrote. Ten years earlier, he said, the FBI had paid NETSEC developers to plant backdoors and "side channel key leaking mechanisms" in the OpenBSD Cryptographic Framework and the IPsec stack, the code that secures VPNs. The aim was to monitor encrypted site-to-site traffic. He named two people, Jason Wright and Angelos Keromytis, as having been connected to NETSEC while the IPsec code was written.

For fifteen years the project had told the world it could be trusted because it trusted no one. Now it was accused of carrying a government backdoor.

An ordinary organization would have hired lawyers, opened a quiet internal review, drafted a holding statement and hoped the story never got out.

On December 14, 2010, de Raadt forwarded Perry's email, complete, to the public openbsd-tech mailing list.

"I refuse," he wrote, "to become part of such a conspiracy."

The accusation was aimed at the fortress, so he opened every gate and invited every cryptographer in the world to come and search it.

Wright and Keromytis denied it. "I will state clearly that I did not add backdoors to the OpenBSD operating system," Wright wrote, and demanded an apology. The audit found real bugs from that period, including a "CBC oracle problem" in the software crypto stack, but no confirmed backdoor. De Raadt stayed suspicious. "I believe that NetSec was probably contracted to write backdoors as alleged," he said. "If those were written, I don't believe they made it into our tree. They might have been deployed as their own product."

The allegation may have been true, a grudge, or a ghost story from the paranoid decade after 9/11. What mattered was the response. When the fortress was accused, it opened wider. It was safe not because anyone promised it was, but because anyone could read every line and check.


IX. Valhalla

In April 2014 the internet began to bleed.

Heartbleed

Heartbleed, CVE-2014-0160, was a flaw in OpenSSL, the library behind the padlock icon on most encrypted web traffic. An attacker anywhere could send a malformed "heartbeat" message and read back pieces of a server's memory, which might contain passwords, session cookies or the server's private keys. The flaw had been in the code for two years, and a large share of the web was exposed.

Open source had long reassured itself with Eric S. Raymond's line that "given enough eyeballs, all bugs are shallow." De Raadt had always thought that was sentimental. "My favorite part of the 'many eyes' argument," he had said, "is how few bugs were found by the two eyes of Eric."

Then the facts came out. The library protecting the world's credit card numbers was maintained by a small, exhausted team living on roughly $2,000 a year in donations. The code was a swamp. It was full of support for dead operating systems, and its custom memory wrappers defeated the very tools that might have caught the bug.

De Raadt didn't file a bug report. The OpenBSD team forked OpenSSL and called the fork LibreSSL.

What followed was a purge. The developers logged it on a blog called the "OpenSSL Valhalla Rampage." In the first week they cut more than 90,000 lines of C and some 150,000 lines of content in all. Support for Classic Mac OS, NetWare, OS/2, 16-bit Windows and VMS went. The custom memory wrappers were torn out and replaced with standard library calls.

LibreSSL

"Some of that is indentation, because we are trying to make the code more comprehensible," de Raadt said. "99.99% of the community does not care for VMS support, and 98% do not care for Windows support… Code must be simple."

When more OpenSSL bugs were disclosed that June, he accused the OpenSSL team of deliberately leaving LibreSSL out of the advance warning. The break was complete. It was the same pattern as OpenBSD after NetBSD and OpenSSH after SSH Communications. When he was handed something rotten, he didn't negotiate. He forked it, gutted it and built a new wall.


X. The Walls Within the Walls

Server racks in a data center

Most people never see OpenBSD itself. What reaches them are its ideas, which tend to leave Calgary and turn up years later, often uncredited, in other operating systems.

In 2011, with Mac OS X Lion, Apple began retiring its old firewall in favor of PF, OpenBSD's packet filter, which reached it by way of FreeBSD. PF has shipped on every Mac since. In 2018 Microsoft, whose monthly security patches had long made OpenBSD's boast look good, built OpenSSH into Windows 10. With Windows Server 2025 it comes installed by default. The lock made in Calgary now ships with Windows itself.

The principle behind these ideas is simple: complexity is the enemy of security. Programmers will make mistakes, especially in C. So you build walls inside the walls, to keep a mistake in one room from burning down the house.

  • strlcpy and strlcat (1999). C's standard string-copying functions produced buffer overflows constantly. Todd C. Miller and de Raadt presented safer replacements at USENIX that always terminate the string and always know how big the destination is. Ulrich Drepper, the maintainer of glibc, kept them out of Linux's C library for years. FreeBSD, macOS and Solaris adopted them. In July 2023, twenty-four years after the USENIX paper, glibc 2.38 added them without ceremony. In 2024 POSIX made them part of the standard.
  • Privilege separation. Niels Provos built it into OpenSSH. The daemon splits in two. A small privileged monitor holds the keys, and a larger unprivileged process handles the network. An attacker who breaks into the network side finds himself locked in a cell without root.
  • W^X (Write XOR Execute). A page of memory can be writable or executable, never both. Code injected into a data buffer cannot run.
  • pledge(2), 2015. A program declares to the kernel in advance which groups of system calls it will use, such as "stdio" and "rpath," and nothing else. If it is hijacked and tries anything outside that list, the kernel kills it.
  • unveil(2), 2018. A program declares which parts of the filesystem it is allowed to see, and the rest disappears. An attacker who gets control and goes looking for password hashes finds nothing.

The security researcher Thomas Ptacek, surveying modern sandboxing, said OpenBSD "got this right with 'pledge' and 'unveil', which allow programs to gradually ratchet down the access they get to the kernel." He compared it favorably with Linux's intricate seccomp profiles.

The principle is simple. Don't trust anyone's code, including your own. Make every program declare what it will do, and have the kernel kill it if it does anything else.


XI. The Scrape in the Floor

The OpenBSD Foundation, a Canadian non-profit founded by developer Bob Beck in July 2007, keeps the project running. It pays for servers, bandwidth and hardware on a budget that would be a rounding error at any company that runs OpenSSH. Above all, it pays for the hackathons.

The first was held in Calgary in June 1999. A handful of developers moved into a house, with no keynotes, sponsors or slides. They had laptops, cables, coffee and sleeping bags on the floor, and they worked around the clock for a week. The result was an industry first, IPv6 and IPsec stacks fully integrated into an operating system. They also left a scrape in the hardwood floor of the house, which the project still remembers.

OpenBSD developers at the c2k1 hackathon, MIT, 2001

OpenBSD developers at the c2k1 hackathon, MIT, June 2001.

Later hackathons took place in rented houses, university dorms, and any cheap place that would take a few dozen people who barely slept. They are invitation-only and exhausting. People who spend the rest of the year on different continents, exchanging terse emails, sit side by side and commit major architectural changes directly to the tree.

De Raadt sits at the center, the gatekeeper with the final word. He demands perfection and does not tolerate mediocrity. He will make the system harder to use before he makes it one degree weaker. Michael Lucas gave his book on the system the subtitle UNIX for the Practical Paranoid. It could serve as a caption for its founder.

The stories about his flame wars leave something out. People stay. Markus Friedl, Damien Miller and Bob Beck appear across twenty-five years of the project's history. Fear alone doesn't keep people that long. Belonging does: to a small, hard group that agrees the work comes first and that getting it right, once, is worth any amount of unpleasantness.

The fortress has people inside it, and they chose to be there.

Jon "maddog" Hall hands Theo de Raadt a pair of devil horns, FISL 2007

At FISL in Porto Alegre, 2007, Jon "maddog" Hall presents Theo de Raadt with a pair of red devil horns.


XII. Half a Second, Again

Back to Calgary at the end of March 2024.

The Linux world is still cleaning up, pulling packages and rebuilding from clean sources. Commentators are writing long threads about the maintainer burnout that let Jia Tan in. Somewhere, the people who built the backdoor, whether a government, a criminal group or one gifted individual, have watched more than two years of work undone over half a second.

The fortress on the prairie is untouched.

Luck has nothing to do with it. Decades ago a boy who had already been uprooted twice decided that nothing could be trusted unless he understood it all the way down. A young man was locked out of the project he helped build and resolved that no one would ever hold his keys again. He refused systemd, blobs, the GPL, and the Pentagon's money once he felt its strings. And in Quebec in 2015 he said the letters XZ aloud, as an example of the kind of code that frightened him.

The traits cannot be separated. The paranoia that got him expelled from NetBSD built OpenBSD. The contempt that made vendors flinch in Melbourne produced free Wi-Fi drivers for everyone. The lack of any filter between his conscience and his mouth cost him the DARPA money and also brought the FBI allegation into the open. The arrogance that wrote "lying cheating hypocrite" looked at Heartbleed and decided to rewrite OpenSSL.

By most accounts he is not a nice man, and he would probably not want to be called one. Nice men take the DARPA money and say nothing, ship the blobs, keep the old code, and leave the FBI letter in a drawer. Nice men have written most of the world's software, and that software is in poor shape.

The internet is leaking and patched and held together by commercial compromises, tired volunteers, and code nobody has read in twenty years. Near its center, where the most sensitive traffic passes, is a lock made in Calgary by a man who trusts no one. It holds while systems worth billions fail around it. It holds because its maker assumed, every working day, that someone was coming to break it.

He was right more often than not.


A note on method: this piece uses reconstructed scenes, free indirect interior voice, and dramatic compression. The events, dates, figures, and quotations come from the sources listed below. The interior thoughts attributed to Theo de Raadt and the atmospheric detail of individual scenes are the author's imaginative reconstruction, not reported fact.


References

  1. CUUG Meetings: 2017–2018, http://www.cuug.ab.ca/past-meetings/meetings.17-18.html
  2. OpenSSH/Overview — Wikibooks, https://en.wikibooks.org/wiki/OpenSSH/Overview
  3. Open Source Software vs Proprietary Software, https://uomustansiriyah.edu.iq/media/lectures/6/6_2019_03_12!12_11_28_AM.pdf
  4. Calgary programmer Theo de Raadt: biography and projects, https://calgary-future.com/en/eternal-calgary-programmer-theo-de-raadt-biography-and-projects
  5. Theo de Raadt — Wikipedia, https://en.wikipedia.org/wiki/Theo_de_Raadt
  6. Hackathons — OpenBSD, https://www.openbsd.org/hackathons.html
  7. OpenBSD — Wikipedia, https://en.wikipedia.org/wiki/OpenBSD
  8. Theo de Raadt — Wikiquote, https://en.wikiquote.org/wiki/Theo_de_Raadt
  9. Раадт, Тэо де — Цитаты известных личностей, https://ru.citaty.net/avtory/raadt-teo-de/
  10. Is Linux For Losers? — OSnews, https://www.osnews.com/story/10889/is-linux-for-losers/comment-page-2/
  11. netbsd-users: Theo De Raadt, https://mail-index.netbsd.org/netbsd-users/1994/12/23/0000.html
  12. POSSE project — Wikipedia, https://en.wikipedia.org/wiki/POSSE_project
  13. Famous Male Programmers — Ranker, https://www.ranker.com/list/famous-male-programmers/reference?page=2
  14. Theo de Raadt — Alchetron, https://alchetron.com/Theo-de-Raadt
  15. OpenBSD Handbook, https://www.openbsdhandbook.com/
  16. What is OpenBSD? Overview & Latest Features — Liquid Web, https://www.liquidweb.com/blog/what-is-openbsd/
  17. strlcpy and strlcat — Consistent, Safe, String Copy and Concatenation (USENIX 1999), https://www.usenix.org/event/usenix99/full_papers/millert/millert.pdf
  18. Introduction — OpenBSD Handbook, https://www.openbsdhandbook.com/introduction/
  19. OpenSSH — Proceedings of the 12th USENIX Security Symposium, https://www.usenix.org/event/sec03/tech/full_papers/provos_et_al/provos_et_al.pdf
  20. CarolinaCon 15: Writing Exploit-Resistant Code With OpenBSD, https://lteo.net/blog/2019/04/27/carolinacon-15-writing-exploit-resistant-code-with-openbsd/
  21. Writing Exploit-Resistant Code with OpenBSD — Lawrence Teo, https://lteo.net/assets/pdf/lteo-openbsd-carolinacon15-20190427.pdf
  22. The history of SSH, from telnet to OpenSSH — SSD Nodes, https://www.ssdnodes.com/learn/history-of-ssh-telnet-to-openssh
  23. Project History — OpenSSH, https://www.openssh.org/history.html
  24. Open Source Doesn't Make Money Because It Isn't Designed to — Reddit, https://www.reddit.com/r/programming/comments/b30m3s/open_source_doesnt_make_money_because_it_isnt/
  25. "Blob-free OpenBSD kernel needed" — Hacker News, https://news.ycombinator.com/item?id=9671025
  26. We need more people like linus — Reddit, https://www.reddit.com/r/degoogle/comments/1vp1unn/we_need_more_people_like_linus/
  27. Theo de Raadt Zitate, https://beruhmte-zitate.de/autoren/theo-de-raadt/
  28. HACK — IT ARTICLES, https://cancoute-666.blogspot.com/2010/05/hack.html
  29. OpenBSD Cryptographic Framework — Wikipedia, https://en.wikipedia.org/wiki/OpenBSD_Cryptographic_Framework
  30. OpenBSD Founder Believes FBI Built IPsec Backdoor — Dark Reading, https://www.darkreading.com/vulnerabilities-threats/openbsd-founder-believes-fbi-built-ipsec-backdoor
  31. The FBI Planted Backdoors to Easily Spy on the Internet, Claims — Gizmodo, https://gizmodo.com/the-fbi-planted-backdoors-to-easily-spy-on-the-internet-5713735
  32. Did the FBI Plant Backdoors in OpenBSD? — Intego, https://www.intego.com/mac-security-blog/did-the-fbi-plant-backdoors-in-openbsd/
  33. More Details Emerge Regarding OpenBSD FBI Backdoors — OSnews, https://www.osnews.com/story/24142/more-details-emerge-regarding-openbsd-fbi-backdoors/
  34. Allegations of OpenBSD Backdoors May be True, Updated — Linux Journal, https://www.linuxjournal.com/content/allegations-openbsd-backdoors-may-be-true
  35. How to Prevent the next Heartbleed — David A. Wheeler, https://dwheeler.com/essays/heartbleed.html
  36. Heartbleed — Wikipedia, https://en.wikipedia.org/wiki/Heartbleed
  37. OpenBSD forks, prunes, fixes OpenSSL — ZDNET, https://www.zdnet.com/article/openbsd-forks-prunes-fixes-openssl/
  38. Does the Heartbleed bug refute Linus's Law? — Armed and Dangerous, http://esr.ibiblio.org/?p=5665
  39. True Crypt, Heartbleed, and Lessons Learned — zwilnik, https://www.zwilnik.com/security-and-privacy/true-crypt-heartbleed-and-lessons-learned/
  40. LibreSSL — Wikipedia, https://en.wikipedia.org/wiki/LibreSSL
  41. LibreSSL: why OpenSSL has no solution — Desde Linux, https://blog.desdelinux.net/en/libressl-because-openssl-is-irreparable-according-to-openbsd/
  42. C programming/C reference/nonstandard/strlcpy — Wikibooks, https://en.wikibooks.org/wiki/C_programming/C_reference/nonstandard/strlcpy
  43. Enhancing XFree86 Security — OpenBSD, http://www.openbsd.org/papers/xf86-sec.pdf
  44. Privilege drop, privilege separation, and restricted-service operating, https://sha256.net/privsep.html
  45. OpenBSD security features — Wikipedia, https://en.wikipedia.org/wiki/OpenBSD_security_features
  46. An early warning of the XZ Compromise? — synhack.org, https://synhack.org/blog/pledge/
  47. Sandboxing Adoption in Open Source Ecosystems — arXiv, https://arxiv.org/pdf/2405.06447
  48. Sandboxing and Workload Isolation — Fly.io, https://fly.io/blog/sandboxing-and-workload-isolation/
  49. Backdoor in upstream xz/liblzma leading to SSH server compromise — LowEndTalk, https://lowendtalk.com/discussion/193769/backdoor-in-upstream-xz-liblzma-leading-to-ssh-server-compromise-openwall-com-via-hacker-news
  50. Blog — Vivian Voss, https://vivianvoss.net/blog
  51. Did (or would) the XZ Utils backdoor affect the BSD ecosystem at all? — Reddit, https://www.reddit.com/r/freebsd/comments/1btxreq/did_or_would_the_xz_utils_backdoor_affect_the_bsd/
  52. OpenBSD is a cozy operating system — Hacker News, https://news.ycombinator.com/item?id=40024393
  53. Activities — OpenBSD Foundation, https://www.openbsdfoundation.org/activities.html
  54. www/hackathons.html at master · openbsd/www — GitHub, https://github.com/openbsd/www/blob/master/hackathons.html
  55. OpenBSD in Canada — undeadly.org, https://undeadly.org/cgi?action=article;sid=20230226065006
  56. Absolute OpenBSD: UNIX for the Practical Paranoid — Michael W. Lucas
  57. Linus Torvalds on OpenBSD ("masturbating monkeys"), LKML, July 2008 — https://lkml.org/lkml/2008/7/15/296
  58. The GNU C Library version 2.38 is now available — GNU info-gnu, July 2023, https://lists.gnu.org/archive/html/info-gnu/2023-07/msg00010.html
  59. OpenSSH for Windows overview — Microsoft Learn, https://learn.microsoft.com/en-us/windows-server/administration/openssh/openssh-overview
  60. Installing OpenSSH on Windows 10 (1803 and higher) and Server 2019 — 4sysops, https://4sysops.com/archives/installing-openssh-on-windows-10-1803-and-higher-and-server-2019/
  61. PF (firewall) — Wikipedia, https://en.wikipedia.org/wiki/PF_(firewall)
  62. Ipfirewall — Wikipedia, https://en.wikipedia.org/wiki/Ipfirewall
  63. Get started with OpenSSH Server for Windows — Microsoft Learn, https://learn.microsoft.com/en-us/windows-server/administration/openssh/openssh_install_firstuse
  64. strlcat — POSIX.1-2024, The Open Group, https://pubs.opengroup.org/onlinepubs/9799919799/functions/strlcat.html

Image Credits

  1. dunnottar-graded.jpg — Dunnottar Castle, Aberdeenshire, Scotland (converted to black and white; adaptation shared under the same license). Stratos Filalithis / Wikimedia Commons, CC BY-SA 4.0, https://commons.wikimedia.org/wiki/File:Dunnotar_Castle_with_clouds.jpg
  2. calgary-blizzard.jpg — Empty snow-swept road under streetlights during a night blizzard, NE Calgary (converted to black and white). Colby Stopa / Flickr, CC BY 2.0, https://www.flickr.com/photos/93057803@N06/11189129403
  3. theo-de-raadt-bw.jpg — Theo de Raadt speaking at ruBSD 2013, Moscow (cropped and converted to black and white). FAndrey / Wikimedia Commons, CC BY 2.0, https://commons.wikimedia.org/wiki/File:Theo_de_Raadt_2013.jpg
  4. yukon.jpg — Tombstone Range in winter from North Fork Pass, Yukon (converted to black and white). Dlogic / Wikimedia Commons, CC BY 3.0, https://commons.wikimedia.org/wiki/File:Tombstone_mountain_range_winter.jpg
  5. vic-20.jpg — Commodore VIC-20 (converted to black and white). Evan-Amos / Wikimedia Commons, Public domain, https://commons.wikimedia.org/wiki/File:Commodore-VIC-20-FL.jpg
  6. sparcstation.jpg — Sun SPARCstation IPX (converted to black and white; adaptation shared under the same license). htomari / Wikimedia Commons, CC BY-SA 2.0, https://commons.wikimedia.org/wiki/File:Sun_SPARCstation_IPX.jpg
  7. puffy.png — Puffy, the OpenBSD mascot (3D render) (converted to black and white). art.gnux.info / Wikimedia Commons, CC BY 1.0, https://commons.wikimedia.org/wiki/File:Puffy.png
  8. vt100.jpg — DEC VT100 terminal, Living Computer Museum (converted to black and white). Jason Scott / Wikimedia Commons, CC BY 2.0, https://commons.wikimedia.org/wiki/File:DEC_VT100_terminal.jpg
  9. openssh-logo.png — OpenSSH logo (converted to black and white). OpenSSH / OpenBSD project, used for identification, https://www.openssh.com/
  10. tomahawk-2003.jpg — USS Donald Cook (DDG 75) launches a Tomahawk toward Iraq, 21 March 2003 (converted to black and white). U.S. Navy photo by Chief Journalist Alan J. Baribeau / Wikimedia Commons, Public domain, https://commons.wikimedia.org/wiki/File:US_Navy_030321-N-6141B-012_The_guided_missile_destroyer_USS_Donald_Cook_(DDG_75)_launches_a_Tomahawk_Land_Attack_Missile_(TLAM)_toward_Iraq_during_the_initial_stages_of_Operation_Iraqi_Freedom.jpg
  11. torvalds.jpg — Linus Torvalds at LinuxCon Europe 2014, Düsseldorf (converted to black and white; adaptation shared under the same license). Krd (photo), Von Sprat (crop) / Wikimedia Commons, CC BY-SA 4.0, https://commons.wikimedia.org/wiki/File:LinuxCon_Europe_Linus_Torvalds_03_(cropped).jpg
  12. stallman.jpg — Richard Stallman at LibrePlanet 2019 (converted to black and white). Ruben Rodriguez / Wikimedia Commons, CC BY 4.0, https://commons.wikimedia.org/wiki/File:Richard_Stallman_at_LibrePlanet_2019.jpg
  13. heartbleed.png — Heartbleed logo (converted to black and white). Leena Kurjenniska / Codenomicon / Wikimedia Commons, CC0, https://commons.wikimedia.org/wiki/File:Heartbleed.svg
  14. libressl.png — LibreSSL logo (converted to black and white). LibreSSL / OpenBSD project, used for identification, https://www.libressl.org/
  15. datacenter.jpg — Server racks, BalticServers data centre (converted to black and white; adaptation shared under the same license). BalticServers.com / Wikimedia Commons, CC BY-SA 3.0, https://commons.wikimedia.org/wiki/File:BalticServers_data_center.jpg
  16. hackathon.jpg — OpenBSD developers at the c2k1 hackathon, MIT, June 2001 (converted to black and white). Dug Song / Wikimedia Commons, Public domain, https://commons.wikimedia.org/wiki/File:OpenBSD_hackers_at_c2k%2B%2B_at_MIT.jpg
  17. theo-de-raadt-2.jpg — Jon "maddog" Hall gives Theo de Raadt a set of red plastic horns, FISL 8, Porto Alegre, 2007 (converted to black and white; adaptation shared under the same license). Randal Schwartz / Wikimedia Commons, CC BY-SA 2.0, https://commons.wikimedia.org/wiki/File:Jon_%22maddog%22_Hall_gives_Theo_de_Raadt_a_set_of_red_plastic_horns.jpg