4 ms·
For many years, I was a devoted FreeBSD user. The lack of basic security hardening found on FreeBSD as compared to other systems vexed me somewhat. When the H
by ninefathom 4y ago
For many years, I was a devoted FreeBSD user. The lack of basic security hardening found on FreeBSD as compared to other systems vexed me somewhat. When the HardenedBSD project got going, I was thrilled. "Ah-ha!" I thought. "Now I can keep using my favorite OS without feeling like security is taking a back seat."
Then I found a bug (in the base FreeBSD, not Hardened-specific) that had prevented ipfw from being used on big-endian systems for several years. Years, mind you- ipfw went for years without working on big-endian systems and nobody had noticed. That was too much, and I ran for the hills.
Now, on OpenBSD, I very much miss ZFS... but that's a small price to pay in my book.
- pdimitar 4y agoWait what? Only FreeBSD gives you ZFS on your boot/OS drive? What about OpenBSD / NetBSD / DragonflyBSD etc.? EDIT: I love it that I get downvoted for asking a question. Seriously people, get a grip.
- 1500100900 4y agoHave you tried auditing ZFS? That's way too much code to be secure, it's best for OpenBSD to never import it.
- mrweasel 4y agoI figured OpenBSDs argument against ZFS was the licens. It makes sense that they would want to audit the code before importing it into base, and it can’t be a kernel module, given that OpenBSD yanked that feature years ago.
- nix23 4y agoJust NetBSD, FreeBSD and HardenedBSD. But DragonflyBSD has Hammer2.
- philkrylov 4y agoNetBSD has a root-on-ZFS recipe only for amd64.
- nix23 4y ago> The lack of basic security hardening found Page 6 especially: https://freebsdfoundation.org/wp-content/uploads/2021/07/Seven-Ways-to-Increase-Security-in-a-New-FreeBSD-Installation.pdf https://freebsdfoundation.org/wp-content/uploads/2021/07/Sev... Full on "hardened" ;) https://hardenedbsd.org/content/easy-feature-comparison https://hardenedbsd.org/content/easy-feature-comparison
- ninefathom 4y agoFor reference, this was several years ago- 2015 or thereabouts. The FreeBSD project has since added or improved various security features (or made them more accessible) directly as a result of the work from and/or the pressure exerted by HardenedBSD. This was not the case early on, and to my memory, in the early days of HardenedBSD, the relationship between the two groups could have generously been described as acrimonious. For an example, see the ASLR-on-FreeBSD debate.
- 0x457 4y ago> For an example, see the ASLR-on-FreeBSD debate. Not much of a debate? You either take contribution feedback or you don't contribute. When I open a PR to some open-source project, and maintainers/contributors give me feedback, I incorporate it and don't throw a tantrum. Everything aside, ASLR is present since 13.0 and default in 14.0. Different implementation. Usefulness of ASLR in general is another debate.
- acoppora 4y agoTo clarify, FreeBSD 14.0 is not out and probably won't be out for quite some time. All users of the current release are still without even basic ASLR.
- emaste 4y agoThat's not true - it is in all supported releases, but not enabled by default. It will be enabled by default in the upcoming 131.1