The accusation came at a really strange time. I'm inclined to think more people jumped on the government conspiracy bandwagon because of the recent release of the diplomatic cables via wikileaks.
Incidentally, I thought I had seen Mr. Perry someplace on TV, and then I remembered he was on an episode of Penn and Tellers "Bullsh*t" a while back. Link for the interested: http://www.youtube.com/watch?v=DT2YET6sg5I
Many of the commenters in the last thread admitted to this, which made it all the more irrational. There was even a debate about whether, in general, 'conspiracy theories' were more or less common than the public perception. As if that had any bearing on these specific allegations.
With the strange claims made in the email (outsourcing, expired NDAs, DARPA knew), I wish Theo would've thought twice before publicizing this guy's name. At least the extra eyes on IPSEC might catch something else.
Third question: "Did you find anything?" Option 1: "Yes" => panic. Option 2: "No" => "Liar!".
You have to release all the details sometime, but the longer you wait, the more people suspect they aren't getting all the details (even if they are) and the larger the drama whirlpool becomes. Did "Kaminsky found a DNS bug, details will be forthcoming" accomplish anything? No, it was a giant clusterfuck.
As a side note, I think it's weird that in a "post-wikileaks" era people are arguing that an open source project named openbsd be less transparent.
You'll have a hard time gathering a small circle of people willing to state, for the record, "We reviewed the code and the invisible bug doesn't exist." Personally, I would want no part in an audit like that.
For a concrete threat, yeah, you fix it first. But the thing about scandals is that delay only incubates a bigger scandal.
I think Theo de Raadt is right to make the accusation open, because it is quite a serious thing.
On the other hand, I know that such an accusation can have a devastating effect on the live of the accused developer. So the principle of _in dubio pro reo_ should be applied faithfully.
This should be the instinctive reaction of a democratic society. It does seem to be quite hard to have this collective routine work reliably nowadays, which is sad.
Incidentally, I thought I had seen Mr. Perry someplace on TV, and then I remembered he was on an episode of Penn and Tellers "Bullsh*t" a while back. Link for the interested: http://www.youtube.com/watch?v=DT2YET6sg5I