After HeartBleedGate and the rivers of text written about the case, that bunch of stubborn OpenBSD developers, led by Theo de Raadt, said, "Let's make our own OpenSSL with gambling and hookers." But since their funding doesn't stretch to gambling and hookers, they settled on just a fork of OpenSSL, which they'll call LibreSSL , and which will initially be available for OpenBSD 5.6 and, if all goes well, for other POSIX systems, including Linux, of course.
Ted Unangst, an OpenBSD developer, actually mentions that Heartbleed was just one of several catastrophic OpenSSL bugs each year , and that this bug wasn't a reason to create a fork. The bug Ted focuses on (the one that would eventually cause the fork) has to do with OpenSSL's internal freelists and the fact that Nginx doesn't work without them . But the most serious issue was OpenSSL's lack of response, since a patch for this bug has already been proposed, and they haven't implemented it yet. That patch has been missing for a year ; OpenSSL, OpenBSD, and Debian have patched it themselves. If the OpenSSL developers weren't going to implement the patch, they were even less likely to be convinced to drop support for Visual C++ 5.0 (C programmers can have a good laugh at these examples ).
So they got rid of about 150 thousand lines of code and counting, especially after removing support for VMS, an abominable closed operating system for servers that Hewlett Packard maintains. It is as if X is compared to Wayland.
Meanwhile, I'll leave you with the OpenSSL Valhalla Rampage site , featuring the gallery of horrors that the OpenBSD team is trying to fix.