31 ms·
Why OpenBSD Is Important to Me
- executesorder66 10y agoI'm curious why the author says Linux is "insecure, anti-secure, and anti-privacy software" Can anyone explain this? Also, why OpenBSD specifically, and not FreeBSD for example?
- atmosx 10y agoSince OpenBSD can be backdoored[1] with the same ease that the Linux kernel could be backdoored, I have no idea why all the fuss. Debian is pretty thorough in NOT including proprietary software if that's what we're talking about. As far as I'm concerned, it's good to have options and the OpenBSD developers have created software that I use daily (OpenSMTPd, SSH, PF, etc.) and for that, I'm thankful! ps. I know that developing IPSEC backdoors is not easy by any means. But the subsequent Theo De Raadt answer, was that he can't tell if there are backdoors or not. That was my point. [1] https://marc.info/?l=openbsd-tech&m=129236621626462&w=2 https://marc.info/?l=openbsd-tech&m=129236621626462&w=2
- aortega 10y ago>can be backdoored[1] with the same ease No, no with the same ease. Every OpenBSD commit is throughly reviewed, and there is only a bunch of commiters. Compared with linux, with thousands of commiters and tons of code added every day, OBSD is way more difficult to backdoor.
- notaplumber 10y agoNo loadable kernel modules for OpenBSD either.
- tptacek 10y agoNot having a formal kernel module system does not actually mean the kernel is secure. Exploits to create module loading systems out of kernel vulnerabilities are approximately as old as stack overflow exploits.
- notaplumber 10y agoNX enforced kernel W^X, SMEP/SMAP, always-on stack protector and a limited attack surface (..say, from pledge(2)), only serve to make such theoretical attacks impractical against OpenBSD.
- tptacek 10y agoNo. Those are useful countermeasures, but kernel exploits for OpenBSD are neither theoretical nor impractical.
- JoachimSchipper 10y agoEven as an OpenBSD fan, I'm not sure why tptacek was downvoted here. W^X etc. make it harder to write an exploit, but sufficiently-bad bugs can still yield arbitrary code execution. (Or confused-deputy problems allowing escalation to root, etc.; there's more than one way to pwn a box.) And - architecturally - OpenBSD's kernel isn't that different from Linux, both being UNIX-style kernels; to the extent that OpenBSD's kernel has better security than Linux, it's mostly because OpenBSD tends to have fewer (and, sometimes, better-considered) features. (There's an interesting argument to be had about Linux+grsecurity vs. OpenBSD - focusing on having some cutting-edge parts vs. solid engineering throughout - but that's not the argument we're having.)
- PhantomGremlin 10y agoI'm not sure why tptacek was downvoted here Maybe because his comment had the tone of: "For this, I have found a truly wonderful proof, but the margin is too small to contain it."
- gonzo 10y ago> Every OpenBSD commit is throughly reviewed, [...] You should observe that this didn't happen here. Sam Leffler found that bug, fixed it, and sent OpenBSD the patch while bringing the "fast IPSec"stack to FreeBSD. OpenBSD silently patched it. The whole thing only came to light years later, when the accusations were made.
- MustardTiger 10y ago>Since OpenBSD can be backdoored[1] And you link to that not happening? Seems a bit silly.
- mulander 10y agoFreeBSD is pretty anti-secure too. https://vez.mrsk.me/freebsd-defaults.txt https://vez.mrsk.me/freebsd-defaults.txt
- akerro 10y agoAlso this: http://networkfilter.blogspot.com/2014/12/security-openbsd-vs-freebsd.html http://networkfilter.blogspot.com/2014/12/security-openbsd-v...
- protomyth 10y agoBSD Now did a rebuttal in Episode 134 http://www.bsdnow.tv/episodes/2016_03_23-marking_up_the_ports_tree http://www.bsdnow.tv/episodes/2016_03_23-marking_up_the_port... IMHO, I found it unconvincing. It soured me on the rest of the episode and its not really my watch as soon as its out podcast anymore. I guess since every segment is basically a FreeBSD segment no matter what OS they are talking about, it had to go that way. YMMV
- quisquous 10y agoI'm lumping Linux in that group because my impression is that Linus is ambivalent about security--it seems to be just another feature to him (see http://www.washingtonpost.com/sf/business/2015/11/05/net-of-insecurity-the-kernel-of-the-argument/ http://www.washingtonpost.com/sf/business/2015/11/05/net-of-...). Additionally, with most of the popular distros, once I install the OS, I have to spend a bunch of time locking things down before I do anything else, whereas OpenBSD has pretty good defaults that I can build up from. Also, when Ubuntu, one of the most popular Linux distros, started capturing searches by default, that got me questioning their commitment to privacy. That's not to say there aren't distros and contributors to Linux that care deeply about security--clearly there are. I just don't find the overall ecosystem nor the most popular distros nearly as focused on or as trustworthy on security and privacy. And as the stakes get higher with more of our lives going digital and more companies, states, and criminals trying to take advantage of that trend, I worry. As for OpenBSD vs FreeBSD, I've had an easier time getting OpenBSD working on my hardware and OpenBSD seems to me more concerned with, focused on, and practically innovative on security--that is to say, they don't just introduce new security features that can be configured and used by someone smarter than me, the OpenBSD folks work hard to introduce new security tech that's on by default with no special knowledge required by the end user, i.e. pledge, W^X.
- nickpsecurity 10y agoThen modify the claim to say "some Linux kernels/distros" instead of Linux as a whole. Meanwhile, thanks to CompSci, there's Linux's (eg Criswell's SVA-OS) and FreeBSD's (eg CheriBSD on CHERI) that run with way more security than OpenBSD. They push the state of the art. So, it's a mixed bag. OpenBSD is actually no different. The developers care a lot about security and quality. Yet, the mere fact that I see OpenBSD desktops in Google images running shoddy applications shows many OpenBSD users make similar tradeoffs to what you described of Linux camp. It's just the kernel and select userland that gets their attention to quality due to limited staff (and their preferences).
- neerdowell 10y ago> Yet, the mere fact that I see OpenBSD desktops in Google images running shoddy applications shows many OpenBSD users make similar tradeoffs to what you described of Linux camp. Are these "shoddy applications" not more secure on OpenBSD due to the various mitigations applied to userland software?
- dijit 10y agoFreeBSD follows a similar pattern to linux, security at the expense of performance is a regression. the reason people say that Linux is insecure is probably because Linus' stances take a hard line, in that "you must understand what you're doing in order to make a patch". The problem is, QA and auditing is only so good and doesn't always catch the people who really don't know what they're doing.. So Linus is openly hostile to people who do stupid things consistently in some sort of attempt to fend off the others who are doing silly things although perhaps not realising it. That's my impression and it's based on nothing more than an outside perspective so I'm probably way off base, but Linus has certainly been quoted before as saying things like "anybody who pushes for security first is a masturbating monkey", avoiding integrating GRSec and PaX for aeons and it's usually left up to distro maintainers to cherry pick the bug fixes from the mainline kernel branch.
- peatmoss 10y agoI think this line was meant mainly to refer to his closed source iPhone, OS X, and Windows use. Perhaps he means his Linux usage is one of the more mainstream distributions that readily facilitates installation of binary kernel blobs (e.g. wifi, video), or 3rd party closed source software. He may also be calling Linux insecure due to it being less uncompromisingly about security. Same could be said about FreeBSD--they aren't necessarily insecure, but they are not as explicitly focussed on that. OpenBSD invests a great deal here. They have their own fork of Xorg (or was that XFree86?) that runs not as root. As far as I know that's unique amongst libre *nixen. EDIT: this is what I get for starting a response, getting coffee and resuming my reply. We don't have to speculate what the author of is post intended, and his response is better than mine ;-)
- creshal 10y ago> OpenBSD invests a great deal here. They have their own fork of Xorg (or was that XFree86?) that runs not as root. As far as I know that's unique amongst libre *nixen. It's a standard feature of Xorg nowadays, but it's only a feature of vanilla Xorg for a few years.
- Santosh83 10y agoI'm probably misunderstanding something but on my system (Ubuntu 14.04 LTS) the X server runs as root & not as my user.
- creshal 10y agoUbuntu does not enable it by default, as it mixes poorly with some drivers: https://wiki.ubuntu.com/X/Rootless https://wiki.ubuntu.com/X/Rootless AMD only added KMS to their proprietary driver last year, and Nvidia this year (and IIRC only in a beta driver so far); and systemd makes the permission handling a lot easier. So Ubuntu will transition to it eventually, but didn't have all puzzle pieces until too recently for even 16.04 LTS.
- symtos 10y agowhy not freebsd? the freebsd project seem to focus exclusively on post-attack with jails and trustedbsd mac. fbsd has not implemented any of the modern exploit mitigation techniques. i mean, even os x has had full aslr since 2012 lol. some years ago fbsd was forked to hardenedbsd which has aslr, mprotect restrictions, non-exec pages on cpus w/o NX, randomized lib loading order, etc. i guess the freebsd project is too busy fighting meritocracy cus none of it has been merged as far as i can tell. as for linux, plenty has been written on linus' stance on what he considers to be a "security circus"; and the mantra on lkml is still that "a bug is a bug". just watch oss-sec and see distro people wading through kernel commit logs (hyperbole) cus sec-related bugs usually aren't reported downstream
- corv 10y agoFreeBSD has ASLR. https://wiki.freebsd.org/AddressSpaceLayoutRandomization https://wiki.freebsd.org/AddressSpaceLayoutRandomization
- symtos 10y agono. did you read the first paragraph? > FreeBSD lacks basic low-level exploit mitigation, such as Address Space Layout Randomization (ASLR) the whitepaper you linked was published in 2014 by Shawn Webb, one of the people behind the hardenedbsd fork. that same year a submission for review was opened on phabricator[1] re. merging their aslr work in mainline fbsd. it was closed on 2015-10-19: > Closing this revision. FreeBSD is free to pull from HardenedBSD. another aslr review request was then created on 2016-03-10 by Konstantin Belousov[2]: > This revision needs review, but there are no reviewers specified. that same day he sent a call for testing to freebsd-arch[3]. there is also a bugzilla ticket[4] for the people waiting for freebsd to catch up with 2001. 1: https://reviews.freebsd.org/D473 https://reviews.freebsd.org/D473 2: https://reviews.freebsd.org/D5603 https://reviews.freebsd.org/D5603 3: https://lists.freebsd.org/pipermail/freebsd-arch/2016-March/017719.html https://lists.freebsd.org/pipermail/freebsd-arch/2016-March/... 4: https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=181497 https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=181497
- 4ad 10y agoFreeBSD lacks (or disables) most mitigations OpenBSD (and usually Windows, or some Linux distros) have, like ASLR, stack protector, W^X, PIE applications by default, libc.so symbol randomization, pledge()'d ports, etc. I love FreeBSD, and use it a lot, and I wish these were all implemented, but until then, it pains me that FreeBSD has less mitigations enabled than Windows and good Linux distros.
- lasermike026 10y agoCarry on. I'm with you.
- pyritschard 10y agoWe also owe the OpenBSD team OpenSSH, which greatly benefits from their attention to detail and commitment to small improvements towards better security. Of course software is never perfect, but it's nice to know the (small) subset of OpenBSD developers working on OpenSSH are still working on keeping the proverbial doors locked.
- peatmoss 10y agoYes, the OpenBSD team's willingness to roll up their sleeves for software that I consider core to a functional Internet is pretty remarkable. Even though the last OpenSSL vulnerability also affected LibreSSL, in the past others haven't. EDIT: Morning brain made context shift unclear. They do OpenSSH and now LibreSSL. Also pf and more too.
- ben_bai 10y agohttp://www.openbsd.org/innovations.html http://www.openbsd.org/innovations.html AnonCVS, OpenNTPd, OpenSMTPd, ...
- jayofdoom 10y agoProbably worth noting as well how many software products OpenBSD has contributed back to the overall free software world; things like OpenSSH, (edit: NOT OpenSSL), a more secure ntpd and inetd. Even if you don't run OpenBSD, you benefit from it.
- madars 10y ago> how many software products OpenBSD has contributed back to the overall free software world; things like OpenSSH, OpenSSL, a more secure ntpd and inetd One of them is not like the others -- OpenSSL is not an OpenBSD project and the code quality is markedly different :-)
- protomyth 10y agoperhaps jayofdoom meant LibreSSL. and yes, OpenSSL is a bit of a code quality difference than the OpenBSD norm.
- nickpsecurity 10y agoYall don't be too nice to them. The code quality is shit. My favorite quip of all came from Ted Unagnst noticing they did endian-checks in one code that ran very often during use of protocol. He said something along the lines that they hadn't applied any sense to (important issue) but they had you covered if your CPU's endianness changed in mid-operation. No words. :)
- protomyth 10y agoI meant my comment in the same spirit as a Southerner means "Bless your heart". I do believe Ted Unagnt's comment is included in the https://www.youtube.com/watch?v=GnBbhXBDmwU https://www.youtube.com/watch?v=GnBbhXBDmwU LibrSSL first 30 days along with quite a lot of other oddities.
- nickpsecurity 10y ago
- Spooky23 10y agoEnd of the day, OpenBSD is a great example of the value of competition, and the necessity to maintain market rules that encourage it. How awesome is it that we have dedicated operation system geared towards the niche of the market that cares deeply about security?
- zxcvcxz 10y agoJust fyi we actually have multiple operating systems dedicated to security.
- oarsinsync 10y agoCan you elaborate on what the alternatives are? The more we all know, the better!
- akerro 10y agoHardenedBSD!
- d_theorist 10y agoI ran across this the other day. Looks interesting. Does anybody know the general difference in approach between HBSD and OBSD? They both seem to be trying to achieve roughly the same thing (a security-focussed BSD).
- JoachimSchipper 10y agoFor any Linux distro, applying the grsecurity patchset will make your box more secure. RHEL (and thus, CentOS) does a pretty good job of configuring and enabling SELinux for packaged software. There is a Hardened Gentoo. All the fun of normal Gentoo, but with fewer companions to find the compiler bugs. ;-) Still, they've built quite a stack of security patches, including grsecurity. There is (used to be?) Hardened Linux From Scratch. Educational, but not practical. OpenWall Linux is dead-ish, but - as you'd expect from a Solar Designer product - introduced several interesting patches (some backported from OpenBSD). You may be interested in http://www.openwall.com/presentations/Owl/ http://www.openwall.com/presentations/Owl/. I recommend - and use - OpenBSD, but there are definitely people interested in security in the Linux world.
- zxcvcxz 10y agoI don't know how anyone can lump Linux in with Windows when it comes to security from NSA spying and then say OpenBSD is a good alternative. HN seems to love the anti-Linux FUD though. Anything that further fractures the OSS community is upvoted fast. I like the BSDs too, but there are a ton of reasons Linux is the most popular kernel in the world, it's not just because the NSA makes it so.
- dijit 10y agoit's not just that though, there's the push for systemd which was not welcomed and alienated a lot of sysadmin folk who frequent hackernews. personally I felt rather shafted by systemd, not because it's bad, but because my arguments were never even met, it was just a brushing off from some of the people who had already accepted it. So I tried the BSD's and they were significantly better than I imagined they would be, I would put money on this being the case for other people who are upvoting these topics.
- vox_mollis 10y agoIndeed. If systemd were just a parallelized init system with better unit management, far more would be okay with this shift. But that wasn't enough. They had to hijack bootloading, logging, device management, network, etc. For reasons that nobody seems to be able to actually explicate.
- cm3 10y agoThey want to control it all to give the best possible user experience but fail short and introduce bugs I've never had since the first day I've installed Linux in the 90s.
- PhantomGremlin 10y agoThey want to control it all to give the best possible user experience Or perhaps, since Poettering et al. are Red Hat employees: Red Hat want to control it all ... for reasons
- zymhan 10y agoI'm just getting started on setting up an OpenBSD router that I want to be the basis for making sure much of my data is secure. I figure I can start with the edge of my network and work in. And for such an important device as an internet gateway, I want to be able to trust it.
- dwc 10y ago> I'm just getting started on setting up an OpenBSD router that I want to be the basis for making sure much of my data is secure. A bit of warning... I've seen this go wrong when people who don't know OpenBSD do this. Adding an additional OS means learning and "supporting" it. * If learn your way around, get it set up well, keep your system updated the way you do for anything else, then you'll be in good shape. * If you learn just enough to get it working and then set it on the back burner for when you can find the time to learn more, don't update it, etc., then you're better off going with an OS that you know and can keep secure. I'm not trying to dissuade you, but I'd like you to evaluate if you will devote the time to using a new OS on a border device that it deserves. If you will then I think you'll be quite happy with your choice. :)
- niroze 10y agoIndeed! Spoken by someone that seems to have experience maintaining many machines. As secure as the machine is, its security slowly degrades the longer it is out-of-sync with updates (especially security ones) and/or admins administering the machines aren't good enough. System administration isn't a set-it-and-forget-it type of thing.
- leaveyou 10y agoI wanted multiple times to study the OpenBSD source code and I've downloaded it but I never managed to navigate through it, to find the "head and the tail" or to find a reasonable "map" of the source code. I would like for example to follow the execution path in the source code, from the boot up to the login prompt. Does any documentation like this exist or could anyone give me some hints ? Thanks
- deprave 10y agoThere are three parts in this sequence: 1. Boot up - this is very machine-dependent ("MD") so you'll find it in each architecture's source code. Look for files named "locore.s" or "locore.S" in places like src/sys/i386/i386. 2. Kernel - the machine-independent ("MI") part, or where the fun begins... this is in src/sys/kern/init_main.c, look for the function main(). You'll see the different subsystems initialized, from the lowest level (auto configuration of hardware devices and console initialization) through fundamental subsystems (virtual memory, disk, network, processes, etc.), all the way to the scheduler. The scheduler will only have one process to work with (PID 1) which is init (src/sbin/init), so that's what gets executed. 3. Userland - /sbin/init is the first process that runs, and it takes care of running everything else, like daemons and eventually your login prompt. Your points of interest in init.c are runetcrc(), read_ttys(), and multi_user().
- tomcam 10y agoWhat a relief! Thanks for scratching that itch. Also turns out to be good code organization, but I needed that post to boot me up.
- mbrock 10y agoSomeone should make a site for sharing little "guided tours" of open source code bases...
- Terribledactyl 10y agoWhile not a walk through the code base, there are these wonderful volumes: http://www.aosabook.org/en/index.html http://www.aosabook.org/en/index.html that have creators/maintainers/contributors walk through at a higher level how these amazing programs work.
- deleted 10y ago[deleted]
- cisstrd 10y agoI am an OpenBSD user, there is no OS I'd rather use currently (obviously) and I am sure there is no OS with a greater focus on security and clean code, the project as a whole deserves a great deal of respect and admiration for setting the bar when it comes to security, and for being the originator of great products that are used outside the boundaries of OpenBSD itself, however (with all due respect) what the author portrays here is paranoid philosophical mumbo-jumbo I'm normally used to from radical FSF-devotees. Yes, there are NSA scandals, yes, the US government has repeatedly overstepped boundaries, yes, caution and scepticism is a very healthy and good thing, but on the other hand there are GNU/Linux distributions taking security somewhat seriously, they have to, they too work with open source code, have a lot of users, and review said code, I doubt someone is interested in your specific data, I doubt using a GNU/Linux distribution or some other BSD OS is some risk one shouldn't take, I doubt we should all have to automatically strive for an "ethical" all Free Software life or otherwise we are in risk of somehow being under totalitarian control, I doubt Apple and Microsoft are totally out to get you and by definition filled with evil backdoors the NSA uses to spy on _everyone_... I doubt they only do malicious things,... and talking about security, it's not all in the Software, a lot is in users' behaviour... not talking about him specifically, but "We are all spied on by the NSA, please like me on Instagram and follow me on Facebook for hourly updates on my life so we can join in the fight against totalitarian control"... As you have guessed by now I am some kind of allergic to this... those idealistic over-simplifications... drawing everything in black and white... Some of the OS X users I know are incredible technology-orientated and privacy concerned people, should I draw the conclusion they are being overly naive by not using OpenBSD for everything? I don't think so, they are just not suffering from paranoia, are pragmatic and living in the real world...
- nickpsecurity 10y ago"As you have guessed by now I am some kind of allergic to this... those idealistic over-simplifications... drawing everything in black and white..." I avoid oversimplifications, too. Yet, most of what the author wrote was proven by precedent. Only grip I have is calling Linux anti-security and anti-privacy given how much good work in those used the platform. Gotta be a kernel by kernel and distro by distro judgment on that. Rest seems accurate. "Some of the OS X users I know are incredible technology-orientated and privacy concerned people, should I draw the conclusion they are being overly naive by not using OpenBSD for everything?" The conclusion is that they prefer to use OS X. That simple. Far as its security, it's made by a company that spent a long time lying to its users that they were immune to malware because Mac's were just inherently secure. They added lots of mitigations sometimes 10 years behind Windows and UNIX per one firm. I recall one vulnerability where an administrative service required a username and password for log-in but didn't check it against database. If you entered any password, you got in. Such a history of absolutely, terrible security plus deception of customers means Apple products shouldn't be trusted for security by default. Any "privacy concerned people" using it are making a foolish mistake or intentionally trading away privacy for some other benefit. Now, what you just saw me do was the evidence-based approach to these things. Helps cut through the noise nicely.
- deleted 10y ago[deleted]
- drblast 10y agoI just want to shake the hand of the person who made the OpenBSD installer the way it is. In case you haven't used it, it's dead-simple, command-line based, and it may take a few times to get it right if you don't know what you're doing. It's nearly featureless. But after you figure it out, you can automate installs, and roll your own distro by changing the contents of tar files, or add your own software and configuration the same way. It's quite possibly the most satisfyingly transparent OS install method I've ever used.
- morganvachon 10y agoIndeed, the only distros in the Linux world with installers that even come close are Alpine Linux (which is obviously heavily influenced by the OpenBSD installer) and Slackware Linux, coincidentally two of the better Linux distros for those who prefer a more BSD-style approach to managing the OS proper. Alpine needs a little work in the desktop OS department, and is painfully lacking in a few essential packages for daily computing, but it's come a long way in a short time. Meanwhile, Slackware is due to drop 14.2 on us any day now, and has seen vast improvements over the past few years. Both are worth a look if OpenBSD for some reason doesn't work on one's system. But having said that, OpenBSD is a cut above any other open source OS when it comes to stability, clean code, and well written, complete, thorough documentation.
- niroze 10y agoGreat opinion piece. I think this is mostly the opinion of anyone that really discovers OpenBSD and gets caught up in it. Security does matter, and the developers accept nothing less than what they want. My main problem with OpenBSD development is that all development is decided solely by the developers and there doesn't seem to be much care for what others want.. which is fine, they're doing all the work for peanuts. Sometimes you just have to do things that aren't well suited for OpenBSD (imagine updating and ensuring hundreds of OpenBSD machines are up-to-date, and running high performant threaded applications). Many things work, but that is all they do. Sure it may be much more secure than other unix or linux offerings, it may be all there is. Much of the ports are just "get this to compile and work". That isn't always good enough. Truly evaluate if it fits your needs. If there is something you want on the platform, it may be up to you to fix it. -- Unrelated, I find it interesting that NetBSD isn't mentioned once in this entire thread.
- 4ad 10y agoI've seen this type of comments many times, in many different context, about many different open source software projects, and I never understood them. > all (OpenBSD) development is decided solely by the developers and there doesn't seem to be much care for what others want This implies this is not the case for every other project. To pick on your SMP performance example, Linux doesn't have better SMP because "developer saw that people want SMP, and decided to implement it". Linux has better SMP because some people came and implemented it. Not at other's people request, that is never relevant. Different open source projects attract different (developer) audiences, and different project have different audience sizes, but don't make the fallacy that some projects chose what to work on (architecturally speaking) because user demanded it. That is never the case. Everything big happens because developers want it.
- niroze 10y agoIt isn't a "fight" or a "Linux vs OpenBSD" thing. It is just how they approach development. One could argue if it is "good" or "bad", but what matters is knowing it exists. Many projects have different approaches to development. Sure, many people work on bugs most of the time, but there are big decisions about where the limited resources are going to be spent on new features. Those are the ones that truly matter. There are examples of amazing things people have just done on a whim, but that isn't truly a standard and much of those things are generally huge.
- update 10y ago> I imagine the NSA has a bag full of OpenBSD exploits [...]. But OpenBSD has gifted to the world a fighting chance-- Doesn't the former sentence negate the latter? At this point, it seems just about all systems are hackable, given enough resources.
- quisquous 10y agoReading Bruce Schneier made me especially aware that security has a strong economic component--its not that you can make your server secure against all threats, but with the right tools you may be able to make it uneconomic for the threats you are most worried about. There's probably not much you can do to defend against an NSA-scale attacker that's targeting you individually. But if you're more concerned about NSA-style dragnets or their corporate equivalents, OpenBSD can help.
- update 10y ago> There's probably not much you can do to defend against an NSA-scale attacker that's targeting you individually. Hm. How is Phineas Fisher[1] is still on the loose then? [1] https://news.ycombinator.com/item?id=11512845 https://news.ycombinator.com/item?id=11512845
- stcredzero 10y agoTo paraphrase: Speaking freely is essential to democracy. The more restricted your conversations, the more careful you are about what you say. And being careful leads to less candor, less criticism, and less innovation. Thought and free speech are the breeding ground for new, sometimes controversial ideas. They are how we prototype, think new ideas through, refine them, and get them ready for wider distribution and discussion. The actions of many 21st century activists seem to be diametrically opposed to this ethos and designed create a social landscape of civic censorship and extra-legal punishment for "thoughtcrime." I think a society with laws supporting free speech on the books, but largely made of authoritarian and censorial organizations is no more democratic in spirit than the Jim Crow south was inclusive with its "technically" enfranchised non-white population. (It doesn't so much matter what laws are on the books, if society at large thinks something opposed.) For democracy to work, there needs to be freedom to dissent. I think many young people who grew up with web forums were exposed to so much draconian censorship, they've come to unconsciously feel that censorship is a key means of expressing power and "justice." I just hope that enough of them work out how intellectually bankrupt such a society would be.
- OneTwoFree 10y ago> Plenty of hardware in my life has backdoors (I'm looking at you Intel[1]) That same libreboot article[1] says that AMD is not any better. Is there any alternative I'm not aware of? An ARM Chromebook is unfortunately not fast enough for me. [1] https://libreboot.org/faq/#intel https://libreboot.org/faq/#intel
- 4ad 10y agoI hope this will be good: https://www.raptorengineering.com/TALOS/prerelease.php https://www.raptorengineering.com/TALOS/prerelease.php
- arjun1296 10y agoDoes OpenBSD have good SMP support yet?
- ben_bai 10y agoBe more specific with your question or give an example where it is too slow. In general: In userland yes, in kernel yes and no and working on whatever seems too slow.
- anthk 10y ago>Plenty of hardware in my life has backdoors (I'm looking at you Intel). But I'm slowly replacing the bad stuff with the good stuff, as I'm able to find OpenBSD (and open hardware) based solutions for my remaining use cases. Use a blobless OS like Trisquel, Guix and get libre hardware from the FSF.
- Sabon792 10y agoThe biggest reason people don't use BSD of any type is that you can't go into a store and buy a computer with BSD on it. At least not in any store an "average" computer user would know where to look. As for someone like me, I used to build computers (more than a couple hundred) back in the 80s and 90s with alternate OSs to Mac (classic) and Windows but never tried BSD. I did try BeOS and OS/2 and Corel and close to a dozen different Linux distributions (I have the Penguins to prove it). At the time I didn't know anyone else that used BeOS or OS/2 other than me. Personally I mean. So that isn't my excuse for not using BSD. Mostly I rarely heard about it. Now I'm old (laughing) at 55 and left BeOS and OS/2 behind years ago and moved to Mac Classic and then Mac OS X which runs on top of BSD. That's the closest I've gotten. If you want more people to use BSD you really need to promote it more. Not just in nerd magazines but put out flyers around companies (don't ask, just leave them) with an explanation of what OpenBSD is and why they should be using it instead of Mac or Windows. It needs to be brief and clear and you need to make VERY clear how they find and install OpenBSD and not just, "Go out and buy a computer and install it." That's like telling most people, "Go out and buy a nuclear reactor and install for the OS for it." It's not going to happen unless you are clear and you make it as easy for them as possible. People like easy and they want to feel like someone cares and that they will be taken care of if they have ANY questions. Personally I feel that one of the biggest bad jokes is that "Microsoft cares". Really? Would you like to buy the Brooklyn bridge? Because it's for sale for $1. If you get everyone you know to lay out flyers at businesses with what I describe above then you may get a few more people to use OpenBSD. But be prepared to support them in not nerd languages and without any attitude. If you have emotional problems (low self esteem, and I'm not saying that YOU do, well those people shouldn't be helping anyone else with anything) then I would suggest leaving support to other people.
- j_s 10y agoDo the downlable .ISOs boot these days? Back when I had time to check it out nearly a decade ago, it cost real cash money to buy a bootable CD-ROM from their store.
- Sabon792 10y agoThe biggest reason people don't use BSD of any type is that you can't go into a store and buy a computer with BSD on it. At least not in any store an "average" computer user would know where to look. As for someone like me, I used to build computers (more than a couple hundred) back in the 80s and 90s with alternate OSs to Mac (classic) and Windows but never tried BSD. I did try BeOS and OS/2 and Corel and close to a dozen different Linux distributions (I have the Penguins to prove it). At the time I didn't know anyone else that used BeOS or OS/2 other than me. Personally I mean. So that isn't my excuse for not using BSD. Mostly I rarely heard about it. Now I'm old (laughing) at 55 and left BeOS and OS/2 behind years ago and moved to Mac Classic and then Mac OS X which runs on top of BSD. That's the closest I've gotten. If you want more people to use BSD you really need to promote it more. Not just in nerd magazines but put out flyers around companies (don't ask, just leave them) with an explanation of what OpenBSD is and why they should be using it instead of Mac or Windows. It needs to be brief and clear and you need to make VERY clear how they find and install OpenBSD and not just, "Go out and buy a computer and install it." That's like telling most people, "Go out and buy a nuclear reactor and install for the OS for it." It's not going to happen unless you are clear and you make it as easy for them as possible. People like easy and they want to feel like someone cares and that they will be taken care of if they have ANY questions. Personally I feel that one of the biggest bad jokes is that "Microsoft cares". Really? Would you like to buy the Brooklyn bridge? Because it's for sale for $1. If you get everyone you know to lay out flyers at businesses with what I describe above then you may get a few more people to use OpenBSD. But be prepared to support them in not nerd languages and without any attitude. If you have emotional problems (low self esteem, and I'm not saying that YOU do, well those people shouldn't be helping anyone else with anything) then I would suggest leaving support to other people.