Theo de Raadt: "You've been smoking something mind altering" (2007)

In October 2007, Theo de Raadt, the founder and lead developer of the OpenBSD operating system, delivered a scathing critique of the security practices within the financial industry. His remarks, delivered at a BSDCan conference, were blunt: he accused financial institutions of knowingly deploying deeply insecure systems and being utterly unprepared for real-world attacks. The now-famous quote, “You’ve been smoking something mind altering,” encapsulated his disbelief at the industry’s apparent complacency. More than 15 years later, his warning remains remarkably relevant, even prophetic. This article will dissect de Raadt’s original claims, examine the current state of financial security, and highlight why OpenBSD's proactive security approach continues to be a powerful, if often overlooked, solution.
The 2007 Critique: A Systemic Failure of Security
De Raadt’s criticism wasn’t a general complaint about occasional vulnerabilities. He argued the entire approach to security within the financial sector was fundamentally flawed. He specifically targeted the reliance on proprietary operating systems (like Windows) and the lack of proactive auditing and secure coding practices. He argued that the industry prioritized features and speed of deployment over actual security, relying on reactive patching rather than preventative measures.
Here’s a breakdown of his core concerns, as expressed in his presentation and subsequent discussions:
- Reliance on Untrusted Code: He pointed to the vast amounts of third-party code – particularly within Point of Sale (POS) systems – that were rarely, if ever, thoroughly vetted for security vulnerabilities. This included operating system components, database software, and application-level code.
- Lack of Proactive Auditing: Financial institutions, he claimed, almost universally lacked a robust program of proactive security auditing and penetration testing. They waited for vulnerabilities to be discovered by external researchers (or exploited by attackers) before taking action.
- Ignoring Known Vulnerabilities: Even when vulnerabilities were identified, the response was often slow and inadequate. Patching was often delayed due to compatibility concerns or bureaucratic inertia.
- Complacency & Denial: De Raadt accused the industry of a widespread attitude of denial, believing themselves to be too large or too important to be targeted by attackers. They assumed security through obscurity.
- EMV as a False Sense of Security: He was also critical of the early rollout of EMV (chip and PIN) technology, suggesting it created a false sense of security while neglecting underlying software vulnerabilities on POS systems. He correctly predicted that attackers would shift their focus to exploiting these software weaknesses.
Has Anything Changed? The Current Landscape of Financial Security
Unfortunately, many of de Raadt’s concerns remain strikingly relevant today. While the financial industry has invested significantly in security, the underlying problems persist.
- Ransomware Attacks are Rampant: Financial institutions are consistently targeted by ransomware groups. These attacks don't just disrupt services; they often involve the theft of sensitive customer data. The Colonial Pipeline attack in 2021, while not a direct attack on a bank, demonstrated the fragility of critical infrastructure and the potential for cascading financial consequences.
- POS System Breaches Continue: Point-of-Sale (POS) systems remain a major point of vulnerability. Data breaches affecting retailers are common, leading to the compromise of millions of credit and debit card numbers. The ongoing evolution of malware targeting POS systems demonstrates the continued exploitation of software vulnerabilities.
- Sophisticated Phishing Campaigns: Phishing remains a highly effective attack vector. Attackers are becoming increasingly sophisticated in their ability to mimic legitimate financial institutions, tricking customers into revealing their credentials.
- Supply Chain Attacks: The rise of supply chain attacks highlights the vulnerability of relying on third-party software and services. Compromises in a vendor's software can have a cascading effect, impacting numerous financial institutions.
- Internal Threats: Insider threats, whether malicious or accidental, remain a significant concern. Employees with access to sensitive data can pose a risk.
While EMV chip cards have reduced card-present fraud, attackers have adapted. Card not present fraud (online transactions) has surged, as has account takeover fraud. Furthermore, the migration to cloud-based financial services introduces new security challenges related to data residency, access control, and vendor management.
The industry has responded with increased adoption of multi-factor authentication (MFA), fraud detection systems, and threat intelligence sharing. However, these are largely reactive measures. They address the symptoms of the problem, not the root causes.
OpenBSD: A Proactive Approach to Financial Security
Theo de Raadt's critique wasn’t merely a doomsday prediction; it was a call to action, implicitly advocating for a different approach to security. OpenBSD, the operating system he founded, embodies that approach.
OpenBSD is renowned for its uncompromising commitment to code correctness and security. Here’s how it differs from mainstream operating systems:
- Proactive Auditing: OpenBSD undergoes rigorous, continuous code auditing. Developers actively search for vulnerabilities before they can be exploited. This isn’t a one-time event; it’s an ongoing process.
- Default Security: OpenBSD is designed with security in mind from the ground up. Unnecessary services are disabled by default, and the system is configured to minimize the attack surface.
- Secure by Design: OpenBSD developers prioritize code simplicity and clarity. This makes it easier to identify and fix vulnerabilities. They actively remove features that increase complexity and potential attack vectors.
- Constant Code Review: Every line of code is reviewed by multiple developers. This peer review process helps to catch errors and security flaws.
- Opportunistic Encryption: OpenBSD features built-in support for opportunistic encryption, automatically securing network traffic whenever possible.
- Focus on Correctness: OpenBSD prioritizes correctness and portability of code. This reduces the likelihood of subtle bugs that can be exploited.
Why OpenBSD Matters for Finance:
While widespread adoption of OpenBSD in large financial institutions is challenging (due to existing infrastructure and legacy systems), its principles are highly applicable:
- POS Systems: OpenBSD can be deployed on dedicated POS terminals, providing a highly secure environment for processing transactions. A dedicated, hardened POS system minimizes the risk of malware infection and data theft. https://example.com/ (a suitable small form factor computer that could run OpenBSD).
- Firewalls and Routers: OpenBSD is widely used as a firewall and router, protecting networks from external attacks. Its robust security features make it an ideal choice for securing critical financial infrastructure.
- Security Appliances: OpenBSD can be used to build custom security appliances, providing specialized security functions such as intrusion detection and prevention.
- Auditing existing infrastructure: Even if replacing core systems isn't feasible, OpenBSD tools can be used to audit existing systems for vulnerabilities and weaknesses.
Challenges to Adoption:
It’s important to acknowledge the challenges of adopting OpenBSD in a large financial institution:
- Software Compatibility: Some commercial applications may not be compatible with OpenBSD.
- Skills Gap: Finding personnel with OpenBSD expertise can be challenging.
- Integration Complexity: Integrating OpenBSD into existing infrastructure can be complex and time-consuming.
- Perception & Inertia: Overcoming the perception that OpenBSD is “too niche” or too difficult to use can be a significant hurdle.
The Future of Financial Security: Learning from the Past
Theo de Raadt’s 2007 warning wasn’t just about OpenBSD. It was about a fundamental shift in mindset. The financial industry needs to move beyond reactive security measures and embrace a proactive, security-first approach. This requires:
- Prioritizing Security from the Outset: Security must be a primary consideration in all stages of software development and deployment.
- Investing in Proactive Auditing: Regular, independent security audits are essential.
- Embracing Open Source: Open source software, when properly vetted, can offer greater transparency and security.
- Reducing Reliance on Proprietary Systems: Minimize the use of closed-source software where possible.
- Investing in Security Training: Educate employees about security threats and best practices.
- Adopting Zero Trust Principles: Assume that all users and devices are potentially compromised and implement strict access controls.
De Raadt’s “You’ve been smoking something mind altering” remains a stark reminder that complacency is the enemy of security. While the threat landscape has evolved since 2007, the core principles of proactive security, code correctness, and rigorous auditing remain as relevant as ever. OpenBSD, while not a silver bullet, offers a powerful example of how to build truly secure systems.
Disclaimer: This article contains affiliate links to Amazon. If you purchase a product through one of these links, we may receive a small commission. This does not affect the price you pay. We only recommend products we believe are valuable and relevant to our readers.