(Replying to PARENT post)

Well, according to (also unsourced, so no clue what the "real" story is) comments on the sister submisson [1] it is because LibreSSL doesn't want to take part in the embargo on reported vulnerabilities.

[1] https://news.ycombinator.com/item?id=9216815

๐Ÿ‘คdetaro๐Ÿ•‘10y๐Ÿ”ผ0๐Ÿ—จ๏ธ0

(Replying to PARENT post)

That's because they patch within a couple of days and don't want their systems unpatched for long (30 to 60 days!) when there is a known issue out in the wild. The flaws tend to get leaked, the temptation is big because there are huge money incentives.

I bet if the embargo were for 5 days they would reconsider. But good luck with that with members like Microsoft, Cisco, Oracle, which a terrible reputation of postponing things the maximum possible.

๐Ÿ‘คalecco๐Ÿ•‘10y๐Ÿ”ผ0๐Ÿ—จ๏ธ0

(Replying to PARENT post)

That is true. OpenBSD/Theo refuses to take part in embargos, which means they don't get a heads up. Don't have a citation right now, but Theo said that publicly when Hardbleed or so happened.
๐Ÿ‘คBluerise๐Ÿ•‘10y๐Ÿ”ผ0๐Ÿ—จ๏ธ0

(Replying to PARENT post)

In which case and assuming that is accurate then

> Why? Well, they just don't. That's the whole story.

Could have been

> Why? Well, we'd have liked to but they don't embargo reported bugs and we do.

Clearer for everyone.

Assuming it's true.

๐Ÿ‘คnoir_lord๐Ÿ•‘10y๐Ÿ”ผ0๐Ÿ—จ๏ธ0