4 ms·
Can you detail how the views presented provided are 'slanted' and 'don't matter'?
by uponcoffee 7y ago
Can you detail how the views presented provided are 'slanted' and 'don't matter'?
- kev009 7y agoSure, say you configure a Linux, OpenBSD, and FreeBSD machine to provide some useful service. A "stack" as they call it these days. None of these OSes are going to have a large attack surface outside that "stack", and that is the primary liability in running an internet service. There are relatively rare occurrences like the TCP SACK bug that affected Linux and Netflix' non-default FreeBSD RACK TCP stack. Every UNIX-like written in C without formal verification is subject to incidents like that from time to time. Every other security concern is addressed in an OS-agnostic fashion with failure domains, limits of scope/networking, access controls, monitoring, and operations procedures. Now what Linux, and to a lesser degree FreeBSD, can do is survive real world usage at scale. OpenBSD cannot. It would fall over or require magnitude more machine count to do the same workloads that people use Linux and FreeBSD to run. So all the exploit mitigation diatribe and "great defaults" and pet projects are cute but funny when you try and throw shade onto others with them. As I said, there are some kernels of truth that pertain less about security and more about overall health in FreeBSD this doc accidentally hits on, but running some hobby software like opensmtpd on openbsd isn't going to save the world from real cybersecurity issues.
- Cyberdog 7y agoAmong those "cute pet projects" are OpenSSH, LibreSSL, OpenNTPD, and PF. The internet at large, and even FreeBSD itself, would be all the poorer for not having these projects available. As someone who has run web servers with both FreeBSD and OpenBSD, I think some of your criticism in this thread is valid, but you really crossed the line into blatant fanboyism with that one at the least.
- pushpop 7y agoOnly really OpenSSH from your list applies though. LibreSSL isn’t really in widespread usage outside of OpenBSD and has still been vulnerable to some of recent the OpenSSL exploits. OpenNTPD is more widely used but lots of people still go for other alternatives and frankly I’m not convinced OpenNTPD offers anything significant over the competition anyway. pf is barely used outside of OpenBSD and frankly why should it be when Linux has iptables (which does the job well) and FreeBSD has ipfw (which also does the job well). pf is also a decent firewall but it’s also a crowded market with lots of really decent alternatives written by their respective platform hosts. I do actually quite like OpenBSD though. But outside of OpenSSH, OpenBSD is slowly becoming less relevant to the wider industry as other platforms catch up on security and even over take in terms of enterprise features.
- aquabeagle 7y agopf is shipped on macOS and iOS as well.