6 ms·
Isn't the exactly what secure by default means?
by blhack 6y ago
Isn't the exactly what secure by default means?
- joshspankit 6y agoIt also must imply that the base install has no insecurities, including when you enable a built-in service. Adding 3rd party packages sure: you’ve left “default” behind, but ones installed by the OS? They count imho
- spijdar 6y agoIt is "secure by default" but I find that phrase disingenuous when the "default" doesn't really do anything. Sure, it's secure, but that doesn't help me much if I have to immediately make changes that could instantly make it insecure. "Secure by default" would be most meaningful IMO when describing a "fat" OS with services and such already enabled, and configured securely. OpenBSD's "secure by default" is nice and useful so far as you can trust it's extremely unlikely someone will be able to nail you with a 0-day when you're doing your OS install and early setup, but that's the biggest part of that. Not to say OpenBSD doesn't do other secure things. I'm just not impressed by their claim of "secure by default".
- blhack 6y ago>"default" doesn't really do anything. This is an unbelievably absurd statement. What do you mean it doesn't """do""" anything? I can boot up my openBSD desktop machine and write computer software, edit graphics, play media files, etc. Basically anything that you would want a computer to do. Before that computer starts interacting with other computers over the network however, I generally have to ask it to. That's GOOD.
- spijdar 6y ago> Basically anything that you would want a computer to do. Some people will be okay playing uncompressed WAV and Sun AU files cat'ed to the audio device. Other people are going to want to play other audio formats. This kind of reasoning is a bit reductionist. Sure, as long as my computer has a compiler and basic interfaces, I can "do anything that you would want a computer to do", given <x> amount of work on my part to re-implement the functionality I want. Unless I want to write my own MP3 decoder, though, I'll need to install 3rd party software from ports. > Before that computer starts interacting with other computers over the network however, I generally have to ask it to. That's GOOD. Right, it is -- but most linux distributions also don't start a lot of network services. Linux has had a few more TCP/IP stack vulnerabilities than OpenBSD, but not many. And of course (mostly) Linux distros uses OpenBSD's SSH package. Your empty Linux install and empty OpenBSD install will, from the network, appear mostly identical. And the bug in Firefox that pops a shell on your system likely won't be either Linux or OpenBSD's fault, but Firefox's.
- dagw 6y agobut most linux distributions also don't start a lot of network services. While that is mostly true today, it certainly didn't used to be. Back when OpenBSD was really earning its security reputation, a default install of Red Hat would be rooted almost as soon as you connected it to the internet.
- arp242 6y ago> I can boot up my openBSD desktop machine and write computer software, edit graphics, play media files, etc. Basically anything that you would want a computer to do. But if mg has a bug allowing malicious files to run code, then this won't increment the"remote holes in the default install"-claim, just to name an example. If I go to the CVE database and search for "Windows 10" or "FreeBSD" then I might find 200 security holes of varying severity, and people will say "Windows 10 has had 200 security problems" Not all those problems will affect everyone, but this is the common-sense way most people would understand it. But OpenBSD has a subtly different definition, and I think this subtly distinction is lost on many. I have nothing against OpenBSD and generally like it, but I always found this claim to be a bit misleading (even though it's technically correct). It's not a meaningless metric though; I remember installing Windows 2000 back in the day and it had malware before I could install the updates. But it is a very incomplete one.
- flomo 6y agoOpenBSD's "secure by default" slogan dates back to the days when you could install Windows NT/2000 or RedHat Linux or whatever UNIX from the CD-ROM, and end up with several very optional "exploitable by default" services running in the background. It might not seem like a huge claim now, but it was actually extremely influential and operating systems now ship with inessential services turned off.
- deleted 6y ago[deleted]
- pjmlp 6y agoPlatforms like Tru64 did it first.
- Shish2k 6y agoBy that logic all software is 100% "secure by default" - if I don’t choose to add my own electricity into the equation, then there are no bugs in the running software at all, because no software is running :D It’s technically correct, but a meaningless metric :P
- blhack 6y agoIt is not even a remotely meaningless metric. OpenBSD doing NOTHING by default is exactly what I want. Somebody said that sshd starts by default, but actually it doesn't unless you specify that you want it to during installation. When you finish an openBSD installation, you are presented with a fully functioning system that will boot up to a shell, which has a networking stack available, and will allow you to then install the things you want. That's what I want a computer to do. I don't want it to start up the kitchen sink unless I ask it to.
- diffeomorphism 6y ago> OpenBSD doing NOTHING by default is exactly what I want. True, but that does not have anything to do with the metric. For example, see https://xkcd.com/641/ https://xkcd.com/641/ . Cereal being asbestos-free is definitely a good thing and "exactly what I want". Yet, people will complain about that advertisement. Or "No vulnerabilities in the webservers turned on by default^1. Also, all default-enabled webservers are giraffes." 1: There are none, so this is true.
- jjav 6y agoYes, that is "secure by default". It's a very reasonable claim to make. This was a contrast to a fresh install of Windows which would get infected within minutes of being connected to the network (I'm assuming this is no longer true, but have never used windows).
- peteretep 6y agoAny OS that shipped OpenSSH earlier than June 2002 could get infected within minutes of being connected to the network, which is basically a set of all Linuxes or their parents.
- chungus_khan 6y ago(and OpenBSD as well)