Skip to content
quotesby

42 Theo de Raadt Quotes

Theo de Raadt shares sharp, cynical commentary on code quality, fork paranoia, and freedom.

Theo de Raadt quotes

  1. I actually am fairly uncomfortable about it, even if our firm stipulation was that they cannot tell us what to do. We are simply doing what we do anyways - securing software - and they have no say in the matter. I try to convince myself that our grant means a half of a cruise missile doesn't get built.

    Permalink to quote #1
  2. Low code quality keeps haunting our entire industry. That, and sloppy programmers who don't understand the frameworks they work within. They're like plumbers high on glue.

    Permalink to quote #2
  3. Hardware donations do not come from vendors who use OpenSSH on parts of their stuff. They come from individuals. The hardware vendors who use OpenSSH on all of their products have given us a total of one laptop since we developed OpenSSH five years ago. And asking them for that laptop took a year. That was IBM.

    Permalink to quote #3
  4. So the HP guy comes up to me (at the Melbourne conference) and he says, 'If you say nasty things like that to vendors you're not going to get anything'. I said 'no, in eight years of saying nothing, we've got nothing, and I'm going to start saying nasty things, in the hope that some of these vendors will start giving me money so I'll shut up'.

    Permalink to quote #4
  5. This is a software monopoly but at least it was written by people who care about security, so it's not like Microsoft's monopoly.

    Permalink to quote #5
  6. It's terrible, everyone is using it, and they don't realize how bad it is. And the Linux people will just stick with it and add to it rather than stepping back and saying, 'This is garbage and we should fix it.

    Permalink to quote #6
  7. Linux people do what they do because they hate Microsoft. We do what we do because we love Unix.

    Permalink to quote #7
  8. I think it is astounding that people could argue for 'you just must trust someone else to fix it' instead of 'you could fix it yourself, or hire someone to fix it.' There is a contractor base out there that can solve these problems as well as or better than the major vendors could. But I think the major vendors are still having more luck at getting the ear of the press.

    Permalink to quote #8
  9. Well, we do not do this so that other players can make profit. We've actually been doing this for a long time and I do not know of anyone who specifically makes money off OpenBSD. They may, at best, save some money by not having to re-engineer the same software that we have already written. It is not exactly that we are letting them make a profit, but that we are doing a proper job and saving someone else from having to do the same job in a corporate setting. In our eyes, that is perhaps a waste of planet-wide engineer talents, rewriting the same thing over and over. Why can't we just get it right once?

    Permalink to quote #9
  10. What's so exciting is to be able to just take something and polish it so much that hopefully in the future people will start borrowing things from it.

    Permalink to quote #10
  11. ...you are being the usual slimy hypocritical asshole... You may have had value ten years ago, but people will see that you don't anymore.

    Permalink to quote #11
  12. Buttons are for idiots.

    Permalink to quote #12
  13. A solid systems's approach should not be based on 'but it works'. Yet, time and time again, we see that for most people this is the case. They don't care about good software, only about 'good enough' software. So the programmers can continue to make such mistakes.

    Permalink to quote #13
  14. Why are you guys so fork paranoid? Do you want everyone to vote for the same political party, too?

    Permalink to quote #14
  15. I think your computer science teachers are still teaching you from books written in the 80's, when the word 'micro-kernel' was associated with a future utopia.

    Permalink to quote #15
  16. But software which OpenBSD uses and redistributes must be free to all (be they people or companies), for any purpose they wish to use it, including modification, use, peeing on, or even integration into baby mulching machines or atomic bombs to be dropped on Australia.

    Permalink to quote #16
  17. Do you trust glibc? OK, perhaps that snide remark is overstating things a bit, but secure software only happens when all the pieces have 100% correct behavior.

    Permalink to quote #17
  18. I say things as they are. Slackers are called slackers, people who can't read manual pages are called losers, and in general, calling things what they are results in developers wasting less time.

    Permalink to quote #18
  19. You did not create these mailing lists, so you can take your opinions about why these lists were created and shove them up your ass.

    Permalink to quote #19
  20. We don't normally recommend that you use it over another operating system. Or even under, or beside, or even near. 'Instead of ' -- that describes how we use it ;)

    Permalink to quote #20
  21. It's the little things that make Freedom become Not Freedom.

    Permalink to quote #21
  22. I am simply astounded at some of the things people keep repeating. I don't mean this applies to everyone, but is there a high quantity of attention deficit disorder in our user community? Or retards? Or is it just the same old trolling? OpenBSD does not incorporate non-free software.

    Permalink to quote #22
  23. They may want to use some GPL'd build tools but if they start putting GPL parts directly into X, then that is going to cause another X split. I promise.

    Permalink to quote #23
  24. Scaling isn't really our concern; I barely know what the word means. There is one group of people who we do know scales. Whiners. They scale really well.

    Permalink to quote #24
  25. I am very easy to get along with, but I don't have time to waste being nice to people who are being stupid.

    Permalink to quote #25
  26. In the Unix system view, anything which needs to talk to raw devices INSTEAD OF THE KERNEL DOING SO is broken. There are no apologies to be made. Period. If you want X to talk to IO devices, what next? ls?

    Permalink to quote #26
  27. Hardly surprising. Apple. They build crap and make you pay extra.

    Permalink to quote #27
  28. Complexity does not avert risk. Ever. Period.

    Permalink to quote #28
  29. You are absolutely deluded, if not stupid, if you think that a worldwide collection of software engineers who can't write operating systems or applications without security holes, can then turn around and suddenly write virtualization layers without security holes.

    Permalink to quote #29
  30. Admittedly, I was apprehensive about interviewing Theo de Raadt.

    Permalink to quote #30
  31. Difficult.

    Permalink to quote #31
  32. What I do know is Theo is the kind of security genius that various state secret-service organizations would love to have on their side. If he were to waltz into the Department of Defense and promise to be a good boy, I think Director of Central Intelligence George Tenet would probably jizz all over himself.

    Permalink to quote #32
  33. It's widely claimed that I'm 'the one' who ejected Theo from the NetBSD community. That is false. At that time in NetBSD's history, Chris G. Demetriou was playing the role of alpha male, and I wasn't even given a choice. I was certain it was going to bite us in the ass. I think the question for historians is not whether it did bite us in the ass, but how many times and how hard.

    Permalink to quote #33

Also attributed

  1. I don't know if there's enough vision. Industry wide, the apathy regarding this recent problem is already setting in - shiny things are happening elsewhere, people are forgetting.

  2. Linux has never been about quality. There are so many parts of the system that are just these cheap little hacks, and it happens to run.

  3. Only failure makes us experts.

  4. [...] beer results in ideas, which results in new code.

  5. I started working on OpenBSD, and many earlier projects, because I have always felt that vendor systems were not designed for quality.

  6. The primary goal of a vendor is to make money.

  7. In some industry markets, high quality can be tied to making more money, but I am sure by now all of us know the computer industry is not like that.

  8. I work on OpenBSD fulltime, as the project leader. I set some directions, increase communication between the developers, and try to be involved in nearly every aspect of the base system.

  9. C++ is a pile of crap.