8 ms·
Neat and quite impressive, given how exotic OpenBSD seems to most people. One thing that bothers me though: why? I mean, why wouldn't they do it with any linux
by arespredator 15y ago
Neat and quite impressive, given how exotic OpenBSD seems to most people. One thing that bothers me though: why? I mean, why wouldn't they do it with any linux distribution? It would probably require less work, less custom tools (like these apps for automatic network configuration or scripts for automounting usb drives they mention), and with some security patches/kernel configurations it should give a similar security level OpenBSD does.
Or am I missing something?
- shin_lao 15y agoOpenBSD security is more than few security patches and kernel configuration. Check out their web site for more information. Most Linux distributions I've played with (CentOS, Redhat, Ubuntu Server, Debian) are pretty mediocre when it comes to security. I've actually stopped using Debian since this incident : http://www.debian.org/security/2008/dsa-1571 http://www.debian.org/security/2008/dsa-1571 In addition, my own experience would point out that OpenBSD is more reliable than Linux, but I'm just a single data point. For development however, we use FreeBSD for a wide range of reasons including ports freshness.
- danieldk 15y agoIt's funny that you mention Red Hat (and CentOS), since they invest very heavily in attack mitigation and sandboxing through virtual machines: http://www.awe.com/mark/blog/20101130.html http://www.awe.com/mark/blog/20101130.html And as much as people dislike SELinux, it does help a lot in confining applications. OpenBSD does not provide comparable techniques.
- 16s 15y agoThey have clearly stated why they do not support those technologies multiple times, but it continually comes up. OpenBSD always goes with simple, easy to understand solutions that "just work out of the box" and can be easily configured and maintained. They build those simple solutions into the OS, they do not (and will not) bolt on complexity.
- danieldk 15y agoOpenBSD always goes with simple, easy to understand solutions that "just work out of the box" and can be easily configured and maintained. Yes, we hear this every time. But this is the same project that advocated systrace, which provided access control with respect to syscalls. I do not see much of a difference between systrace and a mandatory access control framework, except that the implementation of systrace was flawed, it didn't support file labels, and SELinux has a more sophisticated policy language. The OpenBSD Project has a very narrow view of security, and do little to improve attack mitigation for software that is not in the base system (ports).
- tedunangst 15y agoMost of OpenBSD's attack mitigation is at the kernel or libc level. It applies equally to the base system and third party software.
- runjake 15y agoThis doesn't articulate your point at all. What simple solutions are you referring to? systrace? "Don't install ports"?
- dj_axl 15y agoI don't know about now, but ~4 years ago installing from scratch I tried SELinux and after hours of configuring it still wasn't recognizing some hardware. Then I tried OpenBSD or FreeBSD, and it was up and running with minimal configuration. YMMV.
- tedunangst 15y agoYou discovered the difference between "works" and "can be made to work". There are many people who still believe they are synonymous.
- evangineer 15y agoI've worked with SELinux in the past, it works but it can be a real pain to get up and running and there's a bit of a learning curve associated with it.
- jcr 15y agoBIAS: I drank the OpenBSD kool-aid a dozen years ago and have no regrets. I run OpenBSD everywhere and I try to help out as time and health allow, including on undeadly, but I'm not a commiter, major contributor or anyone special. OpenBSD is a bit like Jazz music. When someone asked Louis Armstrong, "What is jazz?" his reply was, "If ya gots to ask, ya'll never know." Though it will most definitely seem elitist, there's some subtle wisdom there; You need to experience it for yourself to learn the what's and why's. Similar is true for all of the BSD's. If you're just looking for a fast bullet point list and "executive overview" (a.k.a. "buzzword bingo decision support"), you'll never find a reason to run any of the BSD's, and worse, you'll never learn on your own why zealots like me exist. The thing you're missing is the experience of learning it for yourself. You might come to a different conclusion than me, and that's fine, but you would still benefit from the experience.
- arespredator 15y agoThanks, I guess I'll just have to try it:)
- apl 15y agoWell, I'm sure that from your perspective the subtleties can't possibly be boiled down without missing the essence of OpenBSD. But there's got to be a way of summarizing its appeal. We are talking about an operating system, and not Kafka short stories or Haydn string quartets, after all. Otherwise I'll have to go with elitism as the most likely explanation. A common sentiment among jazz enthusiasts, by the way.
- vacri 15y agoRemember that with jazz, if you make a mistake, just play it again a couple of times and then it looks like you meant it :)
- ghshephard 15y agoI'm a huge fan of OpenBSD, having tried freebsd and most of the major Linux distress before settling on it. If I had to identify the why, i'd have to agree with the jazz reference. I seriously started comparing the various distros around 2003, and OpenBSD just gave a more consistent, well documented and clean experience. It is a very conservative distro, and has a pristine configuration and network stack. It's reliable, and trustworthy. On the downside, it's not particularly performant, nor is it well supported by enterprise Applications - you won't be running oracle 10g on OpenBSD. Its upgrades are rolled out like clockwork, and are always evolutionary improvements on the previous version.