http://cypherpunk-handbook.i2p/articles/openbsd.html
We are not so much looking for security holes, as we are
looking for basic software bugs, and if years later someone discovers
the problem used to be a security issue, and we fixed it because it
was just a bug, well, all the better. Flaws have been found in just
about every area of the system. Entire new classes of security
problems have been found during our audit, and often source code
which had been audited earlier needs...