3 ms·
Sort of depends on how you look at it. A shitty, misconfigured install of MySQL on an OpenBSD box won't automatically become secure. And the default install is
by cipher_314159 6y ago
Sort of depends on how you look at it. A shitty, misconfigured install of MySQL on an OpenBSD box won't automatically become secure. And the default install is pretty spartan-- you're not likely to use an OpenBSD machine without installing outside software, which is not going to be developed by the OpenBSD guys. So you're only as secure as your weakest public-facing program.
I tend to look at OpenBSD as a sort of "security incubator" program, where good security ideas and practices have the chance to grow. I think that the biggest impact of OpenBSD tends to be felt in OTHER operating systems and on the internet at large.
One of the big areas where OpenBSD has pushed things forward, in my opinion, is defense-in-depth for software. They put a lot of effort into maintaining high coding standards and an emphasis on correctness. They've been active in the area of exploit prevention and detection-- they were the first to really do W^X, they've been using ProPolice by default since forever, they randomize memory addresses, etc. But they're also very active in exploit mitigation-- that is, if we start by assuming that a program IS going to have a security bug, how do we limit the damage? OpenBSD has invented or popularized techniques like privilege separation, their "pledge" and "reveal" systems, and various other forms of sandboxing.
There's also the crypt side-- their work on cleaning up OpenSSL to create LibreSSL has been an incredible service. OpenSSH has been adopted EVERYWHERE. Their work has done a LOT to reduce the amount of unencrypted traffic going across the internet generally.
- ori_b 6y ago> Sort of depends on how you look at it. A shitty, misconfigured install of MySQL on an OpenBSD box won't automatically become secure. And the default install is pretty spartan-- you're not likely to use an OpenBSD machine without installing outside software, which is not going to be developed by the OpenBSD guys Depends on what you're doing with it -- but the base system ships with many things that you would want to use, and it's definitely concievable that you'd only run with OpenBSD software. Web servers? OpenHTTPd. Mail wervers? OpenSMTPd. Proxies? Relayd Firewalls? pf Routing? Depends on what you need, but there's probably a daemon for that.
- hedora 6y agoThe OpenBSD base image includes a web server, dhcp client/server, a dns server, X11, a compiler, a (basic, for now) hypervisor, and so on. You can get a lot done without relying on ports. (Also, the ports are somewhat vetted, as far as I can tell.)
- greggyb 6y agoLate reply, adding onto port vetting. They do try to incorporate their security mitigations into ports. E.g. they have `pledge`d chromium in ports.[0] [0] https://undeadly.org/cgi?action=article&sid=20160107075227 https://undeadly.org/cgi?action=article&sid=20160107075227