 Some members of our security auditing team worked for Secure Networks,
 the company that made the industry's premier network security scanning
 software package Ballista (Secure Networks got purchased by Network
+Associates, Ballista got renamed to Cybercop Scanner, and well...).
 That company did a lot of security research, and thus fit in well
 with the OpenBSD stance.  OpenBSD passed Ballista's tests with flying
 colours since day 1.<p>
 and only months later discovered that the problems were in fact
 exploitable.  (Or, more likely someone on
 <a href="";>BUGTRAQ</a>
+would report that other operating systems were vulnerable to a "newly
+discovered problem", and then it would be discovered that OpenBSD had
 been fixed in a previous release).  In other cases we have been saved
 from full exploitability of complex step-by-step attacks because we
 had fixed one of the intermediate steps.  An example of where we
 <li><h3><font color="#e00000">The Reward</font></h3><p>
 Our proactive auditing process has really paid off.  Statements like
+"This problem was fixed in OpenBSD about 6 months ago" have become
 commonplace in security forums like
 <a href="";>BUGTRAQ</a>.<p>

