5 ms·
> We decided that it is unfair to _our sponsors_ that the above mentioned unlawful players can get away with their activity. How is that unfair to them specifi
by RaleyField 11y ago
> We decided that it is unfair to _our sponsors_ that the above mentioned unlawful players can get away with their activity.
How is that unfair to them specifically? The purpose of this is to protect them by raising a paywall for anyone that isn't their 'sponsor'? (tangentially, that's why I prefer BSD/MIT, because people aren't as obsessed with other people doing dirty, nasty things with their free code.)
It's bad enough that these patches aren't integrated into the kernel like they ought to be or that they aren't included into mainline distros and are only ever present on custom built machines, now they are behind paywall as well. Damit, I don't want to move to OpenBSD.
- yellowapple 11y ago> Damit, I don't want to move to OpenBSD. Why not? OpenBSD's awesome.
- na85 11y agoMaybe for servers. It's completely unusable due to performance problems on my i7-powered thinkpad.
- lnufnu 11y ago"The test series, unfit in our view for production use, will however continue to be available to the public to avoid impact to the Gentoo Hardened and Arch Linux communities." Why would you have to migrate to OpenBSD? Is the test series unstable?
- mfukar 11y agoWell, it's not called "stable".
- bmir-alum-007 11y agoOne risk of using OpenBSD is a lot, but not quite enough, people use it on enough on random hardware and give actionable feedback to make it battle-tested, "Just Work" (TM).
- yellowapple 11y agoReally? I run it on a PowerBook G4, and while it's sluggish, it's not entirely "unsuable". If a 10-year-old single-core machine can handle OpenBSD, I'd be amazed by even the slightest performance issue on a quad-core, hyperthreaded, modern PC. What's additionally surprising is that this is the case on a Thinkpad, of all things; IIRC, the OpenBSD devs dogfood OpenBSD pretty heavily on Thinkpads due to their FOSS-friendliness. Does your laptop have an Nvidia GPU, by chance? In my experience, those do tend to have very bad performance on OpenBSD. Intel and AMD/ATI GPUs should work better. Also, it's worth mentioning that OpenBSD's kernel has a whole slew of debugging and error checking features compiled in by default; compiling a custom kernel without such features can be done, but the docs don't really recommend it, since it becomes excruciatingly difficult to troubleshoot any problems with it.
- na85 11y agoMy laptop has an Intel card, and everything is nominally supported. You are free to be surprised all you wish: I went back to linux because I was sick of dealing with the system locking up for 5-10 seconds every time I opened, closed, or switched to a new browser tab. Couple that with 1-2 fewer hours' worth of battery life and I found myself very quickly asking what the point of "code correctness" was if the system just doesn't work. A thoroughly frustrating experience from top to bottom.
- yellowapple 11y agoJust saying. If you haven't already, I'd definitely send them a bug report and dmesg; that all seems very abnormal.
- RaleyField 11y agoBecause they feel bipolar on security sometimes. On one hand they go to the extremes with auditing and being early adopters of various security technologies but on the other hand they lack in other areas. Until recently they didn't sign binaries because the blessed method was to acquire patches via CVS which were signed. Iso files and their signatures are distributed via http because the blessed method of acquiring the signing key is to acquire and verify it over multiple networks, because PKI can't be trusted even though some of us check that https isn't being signed by a weird CA and companies like Verisign aren't likely to burn their CA business for anyone - so I'm forced to use Tor just to download an iso file complete with updating virtual machines hooked to Tor because who knows which exploits are being pushed from exit nodes... Then there is limited choice of packages and for everything else you are left to community ports and I don't trust randomers maintaining them. In practice OpenBSD is good only for servers where you are willing to put some effort in maintaining them, but it isn't prepackaged solution like Ubuntu is.
- bmir-alum-007 11y agoSo true. We would consider OpenBSD if it ran on AWS and stably supported ZFS. (We use FreeBSD with PF and ZFS.) "NIH syndrome" resulted in signify rather than using normal, proven tools like GPG which Debian-base distros use for package management.
- yellowapple 11y ago> We would consider OpenBSD if it ran on AWS It probably could if Amazon wanted to support it. It does already run on Xen (which is what AWS is built on, IIRC). > "NIH syndrome" resulted in signify rather than using normal, proven tools like GPG Whoa there, pardner! Let's not be so quick to label every attempt at improving the selection of software in a given category as "NIH syndrome", eh? By that logic, "NIH syndrome" resulted in GnuPG rather than using normal, proven tools like the original PGP :) GnuPG is great. Don't get me wrong. I use it all the time, even on OpenBSD. GnuPG is also a big program. It has a lot of features, and tends to be very complex. In the context of package signing, most of those features - like encryption, webs of trust, all that jazz - are way overkill; the OpenBSD folks just needed a tool that can apply a digital signature and verify that signature, and signify does that job pretty darn well. There's also the fact that GnuPG is GPL-licensed, and OpenBSD has a pretty strict policy against including copyleft software. The implications of copyleft might not be important to you or me or the dog next door, but they're very important for the OpenBSD folks.
- cortesoft 11y agoI think he means that it is unfair because the abusive companies are releasing an insecure and untested version of grsecurity, while using the grsecurity brand name in their advertising. This means that any vulnerabilities discovered will hurt the grsecurity brand, making customers trust it less, and hurting the actual legit sponsors using a real secure version of grsecurity. It is similar to how any knock-off of a brand could hurt the brand; a crappier version of something that people will now associate with the real brand.
- RaleyField 11y agoGrsecurity has been here for a while and I don't think common people know of it at all, they hardly know of what Linux is and half of them run it on their phones. Those who know of it will also understand that running outdated versions on outdated kernels isn't a fault of Grsecurity. Grsecurity isn't really a brand or needs to be defended.
- throwaway000002 11y agoThat defence of the "meaning" of the trademark is not up to you to decide, that's for the owners of Grsecurity. Similarly, Google presents its derivative work as Android, and it exercises its rights vigorously to defend the perception of its marque.
- RaleyField 11y ago> not up to you to decide Obviously, I'm just pointing out the fact that there are different groups of users for both products and one group isn't likely to be influenced by how others use the trademarked goods. Android has common people for its clientele, Grsecurity has security professionals that will judge it based on its intrinsic merit and not on what some subsidiary of Intel once did with it. Grsecurity de facto doesn't need to be defended, even if de jure they are entitled to the protection. That's why this is nothing but a money grab, what bothers me though is that they try to package it into something that it is not.