4 ms·
> All are highly secure and Not really, those systems get much less attention from sec folk than the Linux kernel (apps aside). Finding a priv escalation in th
by jagger11 10y ago
> All are highly secure and
Not really, those systems get much less attention from sec folk than the Linux kernel (apps aside). Finding a priv escalation in the Linux kernel takes time (most of low hanging fruits have been already found by fuzzing or by code review), while finding it in *BSD kernels requires writing a simple syscall fuzzer and running it for a couple of minutes. I've seen it done live.
- mijoharas 10y agoI also was under the impression that the BSD's had a strong focus on security, was I misunderstanding something?
- yeukhon 10y agoI say it depends on from which perspective. If the number of changes going into one of the BDS OS is much less than the Linux's, it is possible there are fewer security vulnerabilities. But if you look at this from the other spectrum, it could mean fewer people are looking at it. Seriously, I don't think there is any fair comparison. Even if you compare the number of CVE, is there an absolute correlation between number of commits and number of security patches released? Perhaps, perhaps not. But many of the tools we are familiar with (e.g. OpenSSH itself being the classic one) did come from OpenBSD after forking from the original implementation, and perhaps is quite strong from the code quality. I never study the code, but from what I hear people generally praise the code quality as well as the attention to the overall architecture of OpenSSH. Someone from OS security should chime in. [1]: https://www.openssh.com/security.html https://www.openssh.com/security.html
- delinka 10y agoI suspect you're thinking about OpenBSD, upon which none of the other BSDs are based.
- evgen 10y agoOpenBSD is more secure than Linux will ever be, FreeBSD is more secure than Linux current is now; while Linux has more eyeballs looking at it there is also a significantly larger amount of kernel bloat in which weird bugs and future priv escalations can hide. What is probably less secure on the *BSD side is userspace, where there is less attention paid to security review and automated fuzzing than there is in many Linux distributions.