7 ms·
OpenBSD 5.0 Released
- gatlin 15y agoMad props for the Alfred E Neumann pic.
- copper 15y agoMy favourite bit from the (as always, impressive) changelog: For additional security, security(8) was rewritten in Perl.
- petsos 15y agoWhat was the language of the previous version?
- there 15y agoshell script
- thomasknowles 15y agohttp://www.openbsd.org/plus50.html http://www.openbsd.org/plus50.html > Switched from the old shell script /etc/security to the new Perl script security(8).
- ez77 15y agoThat reason seems pretty shallow coming from the OBSD team... How can changing the language make it more secure by itself? Is a rewrite in C the next planned enhancement?
- tedunangst 15y agoperl has better support for symbolic file name and directory traversal.
- KaeseEs 15y agoIs security(8) setuid? perl does a number of things to make setuid Perl scripts more secure than either setuid schell scripts or C programs (cf. taint mode).
- there 15y agono, security is run from /etc/daily, which is run by root's crontab every day at 0130.
- ez77 15y agoAt the risk of dumping yet more karma, let me rephrase more constructively. OpenBSD has focused on security from the beginning. Precisely for that reason, and considering all the audits they run, it feels like, if OpenBSD has used (up to 4.9) shell scripts for security(8), there mustn't be any compelling reason against using the shell. Surely they must not have them. I realize this was a changelog and not an article, and probably due reasons were found and discussed by the team. I still feel, nonetheless, that "For additional security, security(8) was rewritten in Perl" is either too short (provide a brief reason such tedunangst's) or too long (omit half-baked reasons and simply provide the fact that "security(8) was rewritten in Perl").
- priteau 15y agoFrom the CVS log 7 months ago: Work in progress to replace /etc/security, not yet linked to the build. Main design goals: 1. Safely handle untrusted file names and file content. 2. Output compatibility with current security(8) to please people parsing the output with scripts (except when improving functionality right away saves considerable implementation effort). Substantial functional enhancements are for later. Prodding to do this in Perl by deraadt@. Using some feedback from espie@. http://www.openbsd.org/cgi-bin/cvsweb/src/libexec/security/security http://www.openbsd.org/cgi-bin/cvsweb/src/libexec/security/s...
- 16s 15y agoCD sales support OpenSSH and PF development as well. PF is part of Mac OS X since 10.7.
- there 15y agotoo bad apple doesn't support OpenSSH and PF development. http://www.callfortesting.org/macpf/ http://www.callfortesting.org/macpf/
- sgt 15y agoSong is amusing. http://www.openbsd.org/songs/song50.mp3 http://www.openbsd.org/songs/song50.mp3
- dfc 15y agoI didn't like the song as much as some of the original(older) songs
- ImCEOBitch 15y agoI used to love OpenBSD but I've had to abandon it: - no sendfile implementation to accelerate web servers - ancient userland pthread implementation - worst SMP implementation of any mainstream OS - no unified buffer cache - no working TRIM support - no 802.11n support - video card drivers aging, ~3 years behind mainstream - no adobe flash support / hackarounds The only thing I really miss is PF.
- hackermom 15y agoOpenBSD was never meant to be a desktop BSD. You should take a look at FreeBSD instead.
- ImCEOBitch 15y agoI was just throwing out some desktop-specific things at the end and have no interest in running any BSD as a desktop anymore. They all suffer from the good enough but not mainstream enough problem, i.e. official Nvidia drivers that are not officially supported.
- SageRaven 15y agoThe Radeon stuff is improving rapidly. You can't buy a diesel truck for the power and then complain that it won't take gasoline. ;-) To hell w/ NVidia. If they won't play ball, I'll spend my money on an arguably slightly lesser performing product that is more open. Though, currently the linux emulation layer in CURRENT has a change that broke the linux Flash binary. I've been flash-free for about 2 weeks now. I can't decide if that's a curse or liberation. Otherwise, I personally think FreeBSD is a mighty fine desktop OS. ZFS is really nice.
- sliverstorm 15y agoI never really saw BSD as a desktop operating system, regardless what OSX achieved with Darwin. It made for an amazing mailserver last I tried it though. I used 3.4 on an ancient P4 with maybe 256MB of RAM an 8GB hard drive. Turns out that was way more computer than it needs, and it was so stable I began to think of it the same way I think of my router.
- rmgraham 15y agoMy favourite part is that NULL is now (void *)