6 ms·
OpenBSD 7.4
- zdw 3y agoFrom a networking perspective, I'm looking most forward to route-based IPSec tunnels: https://man.openbsd.org/sec.4 https://man.openbsd.org/sec.4 On the Linux side these are called "vti" devices, and they're simpler to use than most other methods, and also the default when interacting with cloud service providers IPSec gateways.
- dcow 3y agoWhat’s up with this seeming resurgence in interest in IPSec? Did Jason politically/socially mess up? Or are people realizing IPSec solves some novel problem outside the scope of WG?
- t-3 3y agoI think VPNs for general use are just increasingly popular as many people have privacy concerns, many governments are interested in or actively regulating internet speech, getting around geoblocking and copyright restrictions, etc. (not to mention, very aggressive advertising by commercial VPN providers). Remote working has probably increased use as well.
- accrual 3y agoI think it's great there is new attention to OpenBSD's IPSec stack. IPSec is still widely used and is the defacto VPN tech for many large corporations, even if wg is simpler and easier to deploy. IPSec tends to be built-in to enterprise routers, but I'm not sure if wg is.
- throw0101b 3y ago> What’s up with this seeming resurgence in interest in IPSec? IPsec is implemented on many/most network routers/firewalls, and so can be plugged into existing infrastructure perhaps.
- anotherhue 3y agoI liked this one * Do not calculate IP, TCP, and UDP checksums on lo(4) interfaces.
- dark-star 3y agoso, a tcpdump/wireshark trace on lo will now show all packets as red/bad? That sounds annoying. But I get why they did it, it probably makes sense in most real-life scenarios
- petee 3y agoThis is the commit for those curious: https://github.com/openbsd/src/commit/c778c0d73570b51def4f061069af442165eb791e https://github.com/openbsd/src/commit/c778c0d73570b51def4f06... > Packets sent over loopback got their checksums calculated twice. In the output path they were filled in and during TCP/IP input all checksums were calculated again to be compared with the previous result. Avoid this by claiming that lo(4) supports hardware checksum offloading. For each packet convert the flag that the checksum should be calculated to the flag that it has been checked successfully. Keep the flag that it should be calculated for the case that it may be bridged or forwarded later. A drawback is that "tcpdump -ni lo0 -v" reports invalid checksum. But that is the same with physical interfaces and hardware offloading. OK dlg@
- mbakke 3y agoAww, I was most excited about the release song! Is it not happening anymore?
- codetrotter 3y agoOpenBSD 7.2 did not have a release song, but OpenBSD 7.3 did. https://www.openbsd.org/72.html https://www.openbsd.org/72.html https://www.openbsd.org/73.html https://www.openbsd.org/73.html Likewise there has been several other versions that did not have songs either in the past. https://www.openbsd.org/lyrics.html https://www.openbsd.org/lyrics.html So probably there will be more songs in the future too, even if not every release has a song.
- chunk_waffle 3y agoAlso looking forward to artwork merch but that's still for 7.3 on their shop, maybe it will be updated in a few days?
- accrual 3y agoI still miss buying CD sets. I understand why the project doesn't do it anymore (lots of effort and time, similar to why VAX was dropped), but it sure was fun getting them in the mail and using official discs to install.
- 0xDEF 3y agoOpenBSD has a reputation for being super secure but are there any big organizations that actually use it for security critical applications? A quick search shows outdated or non-related results.
- rs_rs_rs_rs_rs 3y agoThat reputation was and still is propagated by OpenBSD fanboys. When put to scrutiny OpenBSD fails the same way any other operating system does(https://isopenbsdsecu.re/about/ https://isopenbsdsecu.re/about/)
- bombcar 3y agoOpenBSD is secure in the default install; it's just that their default install has basically had everything turned off since forever. Mind you, that was a great improvement over things like Windows NT, but "this is super secure as long as you don't do anything with it" is not as incredibly useful as it sounds like at first.
- lcall 3y agoI like having to install the things I really want, which gives me a chance to consider the security implications of them, instead of having many things pre-installed and I don't know what the total risks are. And nothing else I know of has gone since ~1996 with only 2 of the worst kind of security holes (i.e., remote exploit of something I didn't even need, but was installed by default). In the base install are many useful things (including a web server IIRC, though the port is not exposed by default), and those are audited and have that excellent track record. Then when you install extra things, they are usually limited by what user they run as, and usually have pledge/unveil run (limiting access to predetermined/approved syscalls and parts of the file system) so they can't break other things if compromised.
- zvmaz 3y agoI have read that many security innovations [1] get implemented in OpenBSD soon, like W^X [2]. But I don't know enough about OpenBSD and I would like to hear as well if any organization uses it for mission critical applications. [1] https://www.openbsd.org/innovations.html https://www.openbsd.org/innovations.html [2] https://en.wikipedia.org/wiki/W^X https://en.wikipedia.org/wiki/W^X
- brunoqc 3y agoWhat people use for hardware now that pcengines' apus are eol?
- t-3 3y agoI was recently looking at some Banana Pi boards, but I'm not sure if any of them other than the R1 will run OpenBSD. HardKernel's ODROID-H3 is tempting, but the cases are not great looking.
- miah_ 3y agoI've been using a NUC! My only "complaint" is that the model I'm using only has 1 built in NIC, had to add another via USB. It works very well.
- louwrentius 3y agoYou could use VLANs and ditch the extra USB NIC if you want.
- accrual 3y agoI ran such a topology for a while, aka "router on a stick". I had a two-port trunk link to a cheap Cisco small business switch, it worked great. It could also have been easily virtualized with a single virtual NIC, but I don't like virtualizing my router anymore, hah.
- unpixer 3y agoProtectil VP2420 here.
- saclark11 3y agoI'm curious to hear others' answers to this question as well. I've been looking into building my own OpenBSD based home router and so far thinking a Protectli Vault [1] would fit the bill. 1. https://protectli.com https://protectli.com
- blue1 3y ago
- user3939382 3y agoIMHO they really need a two-step release process for changes to pf.conf syntax. In the first step you get a warning when running the service about a deprecated syntax, then drop it. Over the last 20 years I’ve been bitten multiple times by changes to pf.conf which not only breaks your firewall, but invalidates entire published books on pf, countless articles, tutorials, etc. I read some quote from the BDFL once where he said something about breaking changes being good because you’re “in a better place” but I feel the BC breaks are too aggressive to rely on pf directly in anything but small commercial applications. If you want to to tinker and break your home network fine.
- petee 3y agoThis is why the upgrade guide says to actually read the changelog; they tell you the changes. I've only been bitten once, and it was because I didn't read first. >> Read through and understand this process before attempting it. For critical or physically remote machines, test it on an identical, local system first. >> Read configuration and syntax changes and the package upgrade instructions. There were several configuration changes and changes in packages that may require planning before starting the upgrade.
- tiffanyh 3y agoTypically you don't have breaking changes for a point release.
- accrual 3y agoFor OpenBSD at least, every release has equal weight and always increments by 0.1. There isn't a distinction between major and minor releases like other projects have. There are patches/errata, but those don't bump the version.
- petee 3y agoTheres a reason they call it an system upgrade, and not a patch or update. Blindly upgrading anything important without rtfm is just plain irresponsible, yet OP has used openbsd for 20 years and keeps making the same mistake over and over; typically you don't do that.
- proxysna 3y agoRelease image [1] is inspired by works of Louis Wain[2]. Name of the release image references one of his works[3]. [1] https://www.openbsd.org/images/ImHappyBecauseEveryoneLovesMe.jpg https://www.openbsd.org/images/ImHappyBecauseEveryoneLovesMe... [2] https://en.wikipedia.org/wiki/Louis_Wain https://en.wikipedia.org/wiki/Louis_Wain [3] https://arthive.com/artists/11470~Louis_Wain/works/466546~Im_happy_for_everyone_loves_me https://arthive.com/artists/11470~Louis_Wain/works/466546~Im...
- meristohm 3y agoI appreciate you pointing this out. While it's okay to "steal" art style towards developing one's own, it also feels great to attribute credit to the source of inspiration. None of us are anything without those who came before.
- proxysna 3y agoI don't think that they "stole" it. Just a nice tribute to the artist that also fits the theme. I am a fan of Louis Wain's work and just felt like sharing.
- wolf550e 3y agoWhy use an old version of ffmpeg? What is the use of ed25519 x509 TLS certs, which TLS clients support that and which CAs would sign that?
- merricksb 3y agoEarlier submission: https://news.ycombinator.com/item?id=37899319 https://news.ycombinator.com/item?id=37899319
- petee 3y agoWhy was this marked a dupe? Both were posted about the same time, but this one actually has upvotes and discussion...
- brynet 3y agoWhy is this marked [dupe]? This link is the official release page, and the most active discussion for it on HN today. Announcement mail: https://marc.info/?l=openbsd-announce&m=169746103423179&w=2 https://marc.info/?l=openbsd-announce&m=169746103423179&w=2
- accrual 3y agoI love how OpenBSD continues to support and fix issues on a wide variety of hardware. I personally run it on various machines, from Pentium MMX (1997), AMD K6-3 (1999), to modern machines. 486 support was dropped just a couple releases ago, and was supported longer than VAX. > Fix a bug in the handling of SCSI drives in the bootloader on the luna88k architecture. > Correct undefined behavior when using MS-DOS filesystems, fixes imported from FreeBSD. > On arm64, use the deep idle state available on Apple M1/M2 cores in the idle loop and for suspend, resulting in power savings. > Update AMD CPU microcode if a newer patch is available.