6 ms·
Is OpenBSD actually more secure than Linux? I have not been able to find any data to support this—only some vague opinions.
by maxall4 5mo ago
Is OpenBSD actually more secure than Linux? I have not been able to find any data to support this—only some vague opinions.
- deleted 5mo ago[deleted]
- doublerabbit 5mo ago"Is Secure" is subjective. I would be in favour to say that out of the box OpenBSD is more secure than Linux.
- nelsonic 5mo agoYou are correct; OpenBSD is secure by default. And it's not subjective at all. The homepage of https://www.openbsd.org https://www.openbsd.org proudly states "Only two remote holes in the default install, in a heck of a long time!" if they didn't have the evidence to support the statement, the internet would have forced them to remove it by now. ;-) Remote (exploitable) holes are the ones we all care about.
- bombcar 5mo agoThe key (and not saying it's bad, mind you) is that the default install has very few services installed, let alone running or open. So even if Debian and OpenBSD ship the exact same web server, but Debian has it defaulted installed and on, but OpenBSD does not, then a remote exploit won't count against OpenBSD.
- binkHN 5mo agoThere was a time when Linux distributions shipped lots of things on by default; OpenBSD bucked the trend and did not. This is less of an issue nowadays.
- Melatonic 5mo agoIsn't that a good thing for certain use cases ? If you are building an appliance type thing (say a storage or networking device) then you would want something minimalist you can add only the necessary services on. And arent those the types of devices the BSD (in general) are used for ? Less attack surface always equals less potential for bugs/flaws/exploits regardless of how good red teaming tools and workflows get. Now obviously for other use cases Linux could be a much better option.
- wahern 5mo agoAll OpenBSD services, including HTTP (httpd), SMTP (smtpd), and DNS (nsd, unbound, unwind), use privilege separation and sandbox themselves with pledge and either unveil or chroot. There's no extra configuration. And the developers dog-food these services; it's why they're in the base system. How many Linux services use seccomp? Or chroot, mount namespaces, or landlock? If they do at all, it's usually imposed externally by systemd or docker, in which case they usually run with overly broad permissions because there's no integration with the specific application code, thus the AF_ALG exploits in containers. On OpenBSD services continue to narrow their privileges after starting up so by the time an external request is serviced they have only minimal access to syscalls and the filesystem, often only read/write/send/recv syscalls, and if open is allowed only the specific files and directories needed to service requests. Typically even the network-facing daemon accepting TLS connections doesn't have access to the private key--you simply can't do that by running a vanilla service application in docker. Does OpenBSD have bugs? Of course. The question is, which environment has more trustworthy backstops? The Linux kernel provides all the facilities, but they're not used effectively, for many reasons.
- backscratches 5mo agoPeople would never lie on the internet.
- jjav 5mo ago> I would be in favour to say that out of the box OpenBSD is more secure than Linux. Also important to remember that diversity builds strength. Just as in biology, if all organisms are the same, they all succumb to the same virus. I have a multi-layered firewall approach where some are Linux, some are OpenBSD, some are commercial. They'll all have bugs, but unlikely they all have the same bug.
- tptacek 5mo agoNo. (It's fine!)
- nelsonic 5mo agoThe Data: Compare the number of CVE vulnerability trends over time between Linux: https://www.cvedetails.com/vendor/33 https://www.cvedetails.com/vendor/33 and OpenBSD: https://www.cvedetails.com/vendor/97 https://www.cvedetails.com/vendor/97 It's not even close! It's nearly two orders of magnitude higher for Linux. This isn't anecdotal or “vague opinion” CVEs are facts. You can ask the follow-up question: Why is that? And there are many reasons. It could just be that Linux having more users/eyes means more bugs are surfaced ... But you need to dig deeper to understand why OpenBSD is so much more secure, the core team of OpenBSD proactively reviews the security of other OSes and when they learn something, they rapidly implement the feature/fix in OpenBSD. Again, read: https://en.wikipedia.org/wiki/OpenBSD_security_features https://en.wikipedia.org/wiki/OpenBSD_security_features Many of the proactive security features OpenBSD has are not implemented by other OSes. And in the case of kernel-level Crypto, they won't ever be because US export restrictions.
- Tepix 5mo agoUS export restrictions? There are broad license exceptions since decades, so kernels like Linux are free distributable. Same would apply to OpenBSD.
- mghackerlady 5mo agowhich is canadian anyway
- tredre3 5mo ago> And there are many reasons. It could just be that Linux having more users/eyes means more bugs are surfaced You really brushed that one off, uh? The ratio of linux devices to openbsd is quite literally a million to one. The ratio of tech companies invested in linux to companies invested in openbsd is roughly 50,000 to 1. The ratio of professional security researchers paid to find flaws in Linux vs OpenBSD is harder to quantify at the moment, but I think we can guess a trend here. I can agree to a degree that OpenBSD takes security more seriously, and they have made very interesting design decisions to enforce their security model. But I entirely disagree that the number of "CVEs are facts" to back your opinion that it is superior.
- foofyter 5mo agomacOS is BSD roots on top of Darwin
- accrual 5mo agoWhile true it doesn't answer why OpenBSD is considered more secure by default than Linux. Despite its BSD roots, macOS has had its share of CVEs: https://www.cvedetails.com/version-list/49/70318/1/Apple-Macos.html https://www.cvedetails.com/version-list/49/70318/1/Apple-Mac...
- JdeBP 5mo agoThat's not specifically OpenBSD, though. The BSD world is not the monolith that it was back in the 1980s.
- avadodin 5mo agoTrue. No relevance to macOS and iOS. With due mention to FreeBSD's jails, BSD's security image developed mostly from OpenBSD which is said to have gained its security focus due to NetBSD being so insecure that the NetBSD folks were able to hack into DeRaadt's forked OpenBSD. Android's Bionic was based on or heavily influenced by OpenBSD's libc iirc, though.
- stackghost 5mo agoIt's not meaningfully more secure than e.g. Debian. Their claim to fame ("only two remote holes in the default install in X number of years") is definitionally only valid for the default install in its default configuration which means: no httpd, no smtpd, no unbound, etc. etc. etc. The default install isn't very useful, because it doesn't do a lot, and so "only two remote holes" or whatever isn't really saying much. For example: there are still CVEs popping up: https://nvd.nist.gov/vuln/detail/CVE-2024-11148 https://nvd.nist.gov/vuln/detail/CVE-2024-11148 Linux has more CVEs because it's orders of magnitude more popular. OpenBSD has appalling performance, and more or less nobody uses it, so there just isn't a large focus on auditing and fixing it. It's a great research project, but I would not run it on my personal devices. Not because it's "insecure" but because the putative security benefits do not merit the shockingly poor performance.
- Melatonic 5mo agoDon't most people use something FreeBSD based for production use ? I was under the impression OpenBSD was more used for testing and security research. For personal devices I'm not sure why anyone would run a BSD in the first place
- stackghost 5mo agoOpenBSD is absolutely a research OS and that's okay. My understanding is that Netflix used to use FreeBSD to serve video, but I read somewhere they're no longer using it. Not sure how true that is. Some game consoles like the Playstation run a modified FreeBSD as their OS.
- tolciho 5mo agoEasy to install and upgrade, sane defaults, good documentation, lack of waffleburgers of complexity, so I'm not sure why anyone wouldn't run OpenBSD in the first place. Granted I put Windows in the unusable bin and it's been there for decades now and sounds like it is getting worse, what passes for Mac OS X these days is not so good given that you have to disable some security thing to properly kill the annoying and disruptive notification system, among other annoyances still being fueded with, and I gave up on Linux after trying to support that waffleburger in production for a year or two.
- JCattheATM 5mo agoNo, not really. Linux has better options available and is significantly stronger when configured correctly. The OpenBSD approach ls largely based around eliminating bugs in the first place, but isn't as strong at limiting an attacker that successfully exploited a bug they missed or weren't responsible for.
- binkHN 5mo ago> when configured correctly. These are the operative words. With OpenBSD, you get this out of the box and everything just works. With other operating systems, you have to do a lot of the legwork that's already been done for you with OpenBSD and make sure you didn't break things with your configuration.
- JCattheATM 5mo ago> These are the operative words. These are words that when applied equally to Linux and OpenBSD, has Linux coming out ahead. > With OpenBSD, you get this out of the box and everything just works. With OpenBSD, out of the box you get a blank slate that really can't do anything, that you have to configure to do what you want, and currently can't be configured to be as secure as linux can be.
- tete 5mo agoSorry but that's simply not true. There are various cases where vulnerabilities didn't affect OpenBSD due to defense in-depth in OpenBSD. OpenBSD has a pretty long history of eg. limiting attacks through compile time mitigations while making them more usable for every day use compared to specialized "high security" Linux distributions. This can also be seen in patches of third party software (in the ports (packages) system) that often have patches so the code can live with these limitations. One example of such a mitigation is W^X. Implemented in OpenBSD in 2003, copied later by Windows, Linux and the other BSDs (incl. macOS). https://en.wikipedia.org/wiki/W%5EX https://en.wikipedia.org/wiki/W%5EX More recently of course pledge and unveil were also added. Also in 2003 OpenBSD was also the first mainstream (no research or test OS) that implemented strong ASLR that in 2005 was supported in Linux through third party patch sets. For a list, see here: https://www.openbsd.org/innovations.html https://www.openbsd.org/innovations.html Many things were later picked up by Linux distributions, kernel patchsets, compilers, etc.
- tete 5mo agoGiven from what Anthropic says with Mythos: Yes.
- thomashabets2 5mo agoI pointed plain old gpt 5.5 at openbsd and found plenty of bugs. Sent patches for two just in "find". Openbsd, like all other projects, needs a large scale LLM powered bug squash effort. My recent experience: https://blog.habets.se/2026/05/Everything-in-C-is-undefined-behavior.html https://blog.habets.se/2026/05/Everything-in-C-is-undefined-...
- tiffanyh 5mo ago> This was the most critical vulnerability we discovered in OpenBSD with Mythos Preview after a thousand runs through our scaffold. Across a thousand runs through our scaffold, the total cost was under $20,000 and found several dozen more findings. Anthropic did that for OpenBSD. https://red.anthropic.com/2026/mythos-preview/ https://red.anthropic.com/2026/mythos-preview/
- thomashabets2 5mo agoI know. I'm saying you don't even need Mythos to find bugs in OpenBSD. GPT 5.5 is SO much better than humans at finding these things. The fact that we don't even need Mythos, or $20k (I just pay $24/month and this was one of my MANY uses), to find bugs in OpenBSD shatters the dream that there exists any human who can write C properly with enough expertise, dedication, and time.
- jjav 5mo ago> (I just pay $24/month and this was one of my MANY uses), to find bugs in OpenBSD Bugs, or exploitable security vulnerabilities? If the latter, have you reported them all?
- thomashabets2 5mo ago