8 ms·
Does it seem a little embarrassing to anyone else that this is necessary? OpenBSD is supposedly the most secure nix platform available, and yet users have to re
by can09 10y ago
Does it seem a little embarrassing to anyone else that this is necessary? OpenBSD is supposedly the most secure nix platform available, and yet users have to resort to third-parties to get functionality that is available on nearly every other nix system by default.
- OrpheanBeholder 10y agoThe OpenBSD project doesn't have the resources to provide this so m:tier employs a couple of OpenBSD developers to provide this option for people who want it. Not sure what is embarrassing about this.
- can09 10y agoThe fact that virtually every other nix system, large and small, can provide this standard functionality, and the OpenBSD project cannot. Having to rely on third parties for convenient updates is an obvious potential security issue. Firstly because it discourages updates in the first place, but secondly because I now have to trust m:tier as well as the OpenBSD devs. That is why I say embarrassing - they are one of very few projects to lack this feature, and this feature is an important part of a secure system. OpenBSD is all about being "hands off" and "sane by default" and yet paradoxically their update process is much more involved and hands-on!
- saean 10y agoIf openbsd developers do it, why don't they make it official and provide it from openbsd.org? They could still plaster "this is thanks to funding from mtier" on the site prominently.
- sdkmvx 10y agoThe OpenBSD developers are unwilling to do anything that makes some architectures better than others, and M:Tier is unwilling to build stable updates for everything. Perhaps this will change one day as hardware continues to consolidate, but that's the way it is for now. http://www.openbsd.org/plat.html http://www.openbsd.org/plat.html
- the_trapper 10y agoAs far as I know, the patches are submitted to the -stable ports tree. mtier just provides a very convenient way to perform binary updates. I fail to see any downsides to this arrangement.
- notaplumber 10y agoYou can always stick with the release binaries, which are unchanged.. or follow -current development by periodically upgrading to snapshots, where you can find more up-to-date binary packages. This is what developers run on their laptops, and often in production. It's sort of a "rolling release". There aren't enough resources or interested developers willing to handle -stable package builds, but the ports tree is tagged each release and receives select backported security updates, which you can build yourself.
- RaleyField 10y agoIt's what's blocking me from trying it. I don't want to spend time to micro manage my desktop system and applying security patches involves lots of time. They should bless certain architectures (amd64) and certain packages (chrome, firefox, one DE) and keep binary patches available for those, everything else can stay the same (i.e. binaries on release). I also don't want to try third party services for updates because I'm not sure if I can trust them. I know core OpenBSD team can run a tight ship but other OS teams have shown that's not always the case. Irc the excuse is that openbsd is now a research operating system, but lack of funding probably plays into this as well. So everything is broken as per usual. </rant>
- jlgaddis 10y ago> ... I'm not sure if I can trust them. Might I suggest looking into who it is at M-Tier that's producing these packages? It's not just some random third-party. FWIW, the openup tool makes things extremely easy and it certainly doesn't "involves lots of time". Run "openup -c" from a cronjob and, when you get an e-mail saying there are updates available, log in and run "openup". Kick off a reboot if the kernel/base was updated and you're good. I run several OpenBSD boxes in production. Don't let this be what stops you.
- saean 10y agoThe idea that we outsiders have to research mtier to decide that it's not very much of a third party after all is just odd. I don't want to seem adversarial, and I want to like openbsd, but it's hard.
- toyg 10y agoI said it before: if the people running mtier and openbsd are basically the same, the fact that they are different organizations invites speculation as to why that might be the case. In the spirit of trust and full-disclosure, it would be good if this situation were made transparent. At the moment there's a lot of "these packages are not blessed but they're from the same people wink-wink-nudge-nudge". Nobody else does this, not even small distributions, and tbh the excuses are really thin - especially for a project so committed to security and transparency.
- technofiend 10y agoWhy would anyone find it embarrassing that OpenBSD is not RedHat? They don't have the staff or the funding to curate an operating system and all the ports. Rather than do a poor job maintaining a large code base they prefer to do the best job they can on the core OS. What's embarrassing about that?
- can09 10y agoWe are not talking about the same thing. I am not arguing they should be more responsible for third-party codebases, this is not an issue of ports vs base. This is far more an issue of infrastructure, of source vs binary. Simply offering binpatches for their core OS would still be a huge step forward.
- montyedwards 10y agoNobody is suggesting OpenBSD not being RedHat should be embarrassing. However, it is not ideal to have a security-focused OS not directly provide binpatches for the base system and core libraries like libressl. Trusting OpenBSD.org is one thing, but trusting additional entities like mtier, etc. just to get security updates without having to compile is another. FWIW, I think we should feel embarrassed about not giving more funding & time to OpenBSD given everything they already do for us. http://www.openbsdfoundation.org/campaign2016.html http://www.openbsdfoundation.org/campaign2016.html Maybe someone at OpenBSD Foundation should get itself listed at smile.amazon.com and make it even easier for people to contribute.
- the_trapper 10y agoThe traditional means of patching is recompiling from source. That is the ONLY officially supported method. This is just another convenient option. I fail to see the problem here. If you want supported first-party binary security patches you should be using a project that provides that, such as FreeBSD, or just about any Linux distro that is not Gentoo.
- toyg 10y agoI think there would be no problem with OpenBSD supporting an automated build-and-recompile tool, that would be perfectly fine and would stop people like me bitching about updates. Yeah yeah "it's trivial for you to write etc etc" but that's not the point: it's like saying that developing a text editor is simple so we shouldn't provide vi. This sort of thing is better designed and implemented by people who know the OS inside out, not by users.