3 ms·
Because they feel bipolar on security sometimes. On one hand they go to the extremes with auditing and being early adopters of various security technologies but
by RaleyField 11y ago
Because they feel bipolar on security sometimes. On one hand they go to the extremes with auditing and being early adopters of various security technologies but on the other hand they lack in other areas. Until recently they didn't sign binaries because the blessed method was to acquire patches via CVS which were signed. Iso files and their signatures are distributed via http because the blessed method of acquiring the signing key is to acquire and verify it over multiple networks, because PKI can't be trusted even though some of us check that https isn't being signed by a weird CA and companies like Verisign aren't likely to burn their CA business for anyone - so I'm forced to use Tor just to download an iso file complete with updating virtual machines hooked to Tor because who knows which exploits are being pushed from exit nodes... Then there is limited choice of packages and for everything else you are left to community ports and I don't trust randomers maintaining them. In practice OpenBSD is good only for servers where you are willing to put some effort in maintaining them, but it isn't prepackaged solution like Ubuntu is.
- bmir-alum-007 11y agoSo true. We would consider OpenBSD if it ran on AWS and stably supported ZFS. (We use FreeBSD with PF and ZFS.) "NIH syndrome" resulted in signify rather than using normal, proven tools like GPG which Debian-base distros use for package management.
- yellowapple 11y ago> We would consider OpenBSD if it ran on AWS It probably could if Amazon wanted to support it. It does already run on Xen (which is what AWS is built on, IIRC). > "NIH syndrome" resulted in signify rather than using normal, proven tools like GPG Whoa there, pardner! Let's not be so quick to label every attempt at improving the selection of software in a given category as "NIH syndrome", eh? By that logic, "NIH syndrome" resulted in GnuPG rather than using normal, proven tools like the original PGP :) GnuPG is great. Don't get me wrong. I use it all the time, even on OpenBSD. GnuPG is also a big program. It has a lot of features, and tends to be very complex. In the context of package signing, most of those features - like encryption, webs of trust, all that jazz - are way overkill; the OpenBSD folks just needed a tool that can apply a digital signature and verify that signature, and signify does that job pretty darn well. There's also the fact that GnuPG is GPL-licensed, and OpenBSD has a pretty strict policy against including copyleft software. The implications of copyleft might not be important to you or me or the dog next door, but they're very important for the OpenBSD folks.
- yellowapple 11y agoRe: ISO file signatures: the actual "blessed method" involving getting install media is actually to order a CD-ROM set. IIRC, the ISOs don't actually include the SHA256.sig file necessary to verify the installation tarballs; this is only present on the official CD-ROMs. Re: package signing: yes, this was a strange oversight, and I'm glad they sign their packages now. > Then there is limited choice of packages It's not that limited, at least on i386 and AMD64 (other platforms are a bit more limited). Are there particular packages that are missing that you'd prefer to be available? > and I don't trust randomers maintaining them. So compile them yourself, with or without ports. OpenBSD ships with GCC, binutils, etc. Besides, I'm pretty sure this is the same situation as with Gentoo, Arch, etc. (and know for a fact that it's the same situation as Slackware's SlackBuilds.org). > In practice OpenBSD is good only for servers where you are willing to put some effort in maintaining them I run multiple OpenBSD servers. I can personally attest that the effort required to maintain them is minimal. The only situation where OpenBSD maintenance is less than dead simple is when it comes to upgrading a machine where you don't have console access (such as a server in a remote datacenter), since now you have to do the installer's job yourself. When you do have console access, however, OpenBSD's installer makes it dead-simple to upgrade. Plus, it does so safely; no more total breakages like you'd get in, say, Ubuntu. I will say, however, that it would be very nice to be able to track the stable branch without having to pretty much build OpenBSD from source. I think there are some folks that maintain stable-following ISOs, but this is really something that could and should be supported as a first-party feature. > but it isn't prepackaged solution like Ubuntu is. I'm pretty sure Ubuntu uses AppArmor - not grsecurity - so I'm not really sure how that's relevant in this particular discussion. Unless, of course, you happen to install grsecurity on Ubuntu, at which point I highly doubt OpenBSD not being an Ubuntu-like "prepackaged solution" is really as much of a problem as you make it out to be :) Regardless, OpenBSD has as of late been progressing toward such a prepackaged solution. Boot the CD-ROM, mash the Enter key a few times (interrupted by entering some usernames and passwords), and you have a complete server operating system ready-to-go; a webserver or mailserver or fileserver or DNS server or timeserver or what have you is just an edit of /etc/rc.conf.local away. Maybe not a prepackaged desktop solution, there are plenty of other operating systems for that. With that said, I'm not sure if the OpenBSD folks want to be comparable to Ubuntu. Canonical's demonstrated a willingness to compromise security and privacy for the sake of convenience (see: shopping lens), that's (hopefully) not something de Raadt and friends would want to emulate. > companies like Verisign aren't likely to burn their CA business for anyone Not voluntarily. You're inherently trusting some random company to be up to snuff on their security.