3 ms·
If you look at some of the comments, sources, and just the attitude of the guy that put this together it seems he does have an axe to grind. It kinda says so in
by beachhead 6y ago
If you look at some of the comments, sources, and just the attitude of the guy that put this together it seems he does have an axe to grind. It kinda says so in the about section. I think if you dive into the mitigations section without looking at that it seems less like that because he ends up having to admit some of them are decent ideas... try as he might to come up with ways in which they're not. There are plenty of OpenBSD users going around talking nonsense but this "systematic evaluation" is not an actual systematic evaluation.
I especially like the part where it lists people who helped but it's all redacted. All of this "research" came from google and twitter. I'd like to see some bypasses to OpenBSD's mitigations and perhaps some ideas and/or code to help improve them or implement ones that these folks say work better. If they're all so bad then it shouldn't be hard for someone like the author or so called security experts he quoted to do these things. Yeah, maybe no one is going to pay for that work to be done... that seems to always be the response when someone asks for proof, code, etc. No one has the time. They sure spend enough time making websites, blog posts, and tweeting about it though.
- Accacin 6y agoThe guy who wrote this did a talk about it, this website was to list sources etc. I’m an OpenBSD user and I did not personally feel like he had an axe to grind, and overall thought he was fair and had well made points. I’ll be the first to admit a lot of what he said was rather too technical for me, but if I’m remembering correctly I never saw many counter points to his claims. I personally feel that OpenBSD is more secure for my use case, but I’m happy that people bring up points like this as humans make mistakes and not even OpenBSD is perfect.
- beachhead 6y agoI watched the talk. The guy was wearing a t-shirt with the OpenBSD mascot with "got hacked" under it. Again if you read the about section it seems pretty clear. You're parroting the same language from the talk. Why should there be counter points to some random internet person's claims? Where are those bypasses at? Where are the patches to incorporate these better mitigations or to improve existing ones? I don't think OpenBSD has perfect security and I'm not sure why that needs to be said. I don't see anyone involved in the project making that claim either. What I'm saying is this talk/website is just as dubious as some of y'all think OpenBSD mitigations are and if that's not obvious from looking at the sources I'm not sure what else to say here.