5 ms·
One bug found is a testament to the great diligence and culture around security of OpenBSD. Especially if you take into account the amount of resources they hav
by trashb 3mo ago
One bug found is a testament to the great diligence and culture around security of OpenBSD. Especially if you take into account the amount of resources they have been able to achieve this with.
- sunshine-o 3mo agoExactly, the entire AI industry has been trying to create an AI powered security arm race. I am not necessarily blaming them. Hard to know how much has been thrown into this but I would bet a lot. So far I have been very surprised we haven't been flooded by those type of announcements. If you look you will always find something and OpenBSD is the top price.
- cratermoon 3mo agoThey are throwing tokens at codebases and finding mostly vulnerabilities in cases that have not been worth the limited time and effort of the chronically underfunded and understaffed professional groups. There’d be a lot more value in the companies giving the money they spend on their synthetic text extruders to the organizations doing quality security research work.
- anuramat 3mo ago> they are ... finding ... vulnerabilities ... that have not been worth the time and effort ... that's kinda the entire point
- dTal 3mo agoThe point of the comment you are replying to is that it's also not worth the time and effort to use LLMs to find vulnerabilities, if "time and effort" can be measured with "money". If you factor in all the money spent on training, GPU data centers etc, it's not actually a financially efficient way to find bugs unless you profit from creating demand for LLMs. LLMs aren't cheaper than humans per unit work, yet. They're just massively deficit funded because capital thinks "AI" is going to reshape the world order, and wants in.
- anuramat 3mo ago> it's not actually a financially efficient way ... unless you profit from creating demand for LLMs well, they do? it's a win-win, you can't really criticise an AI lab for doing AI instead of straight up giving money to security researchers > If you factor in all the money spent on training why would I? it's not a cybersec-specific model
- dTal 3mo ago>you can't really criticise an AI lab for doing AI instead of straight up giving money to security researchers Sure I can, if they - or you - pretend "the entire point" is about useful security work rather than expensive loss-leading marketing and demand creation. We shouldn't look at this and think "wow AI is super useful for security". We should look and this and think "wow, there's a LOT of capital going into persuading us that AI is super useful for security". THAT is "the entire point".
- anuramat 3mo agosecurity researchers are using the free tokens that they get to do useful security work, AI labs are giving away free tokens to maximize their profits; is it really that hard to imagine that different parties might have different goals? > We shouldn't look at this and think you're gonna tell me what to think now?
- beanjuiceII 3mo agoone bug is all it takes
- Analemma_ 3mo agoLPEs do need to be fixed, but for most people it's not a threat model they need to worry about.
- dathinab 3mo agothis is a misconception yes, most company settings don't run untrusted code, and OpenBSD is mostly used for servers not employee devices but that doesn't mean LPEs aren't quite relevant, because they matter for pretty much everyone if combined with other vulnerabilities, like RCE, supply chain attack etc. and while RCE are becoming less common, supply chain attacks have been increasingly more common
- bell-cot 3mo agoIn theory. But real defenses are generally multi-layered. And in that context, a Swiss cheese slice with only one hole is still extremely valuable.
- JCattheATM 3mo agoWell, that's where OpenBSD falls short, it lacks facilities to really enforce defense in depth - even NetBSD has some better features in this regard.
- yjftsjthsd-h 3mo agoI don't think that's true? It runs most services as their own separate users, with pledge+unveil to limit what they can access even more. That's very much depth.
- bell-cot 3mo agoJust popped up, about pledge+unveil - https://news.ycombinator.com/item?id=48851765 https://news.ycombinator.com/item?id=48851765
- gnoack 3mo ago+1 It is also a testament to solid engineering and attention to good security practices in general. These still work, also against fancy new AI attackers. When sophisticated attacks become cheaper to run, maybe it will (finally) be cheaper to do more solid engineering instead of doing it quick and dirty and ending up in indefinite bug-squashing mode.
- VBprogrammer 3mo agoI suspect the easier option is to use AI to review your own code. The arms race between developers and attackers might even make some of the AI valuations come true.
- tiffanyh 3mo agoWhile I agree, OpenBSD also doesn't fully implement features/functionality. If your operating system only does 20% of what another operating system can do, it's easier for you to have 80% less bugs. That's not a knock, it's a design philosophy of OpenBSD (which is to do the minimal needed, and no more, in the most simplistic way).
- somat 3mo agoThat does not match my experience with obsd. It is not so much minimalism as they are not afraid to reinvent the wheel. A obsd install is full of services, more than most linux installs I have seen. For example you can imagine my disappointment when I discovered what a pain in the ass it is to get a pflow producer working on linux after doing the first one on openbsd.
- knorker 3mo agoI'd say it's true. They chose to not implement SMP until consumer CPUs surprised them by going multi thread. And obsd has no Bluetooth, right? A pretty big subsystem to drop because security.
- somat 3mo agoAnd as a counter example here you have openbsd "we are going to install a bgp daemon on every single device, because you never know when you may need one" I am not complaining, I like the feeling that I could single handedly rebuild the internet using only what is found in an openbsd base install. But wow, considering the size there is a lot in there. They definitely punch above their weight.
- knorker 3mo agoIt's not a counter example to give examples of what does exist. And it's not like the BGP daemon is on by default. That'd be dumb. You could equally say that any Ubuntu system has equally many steps to turn on a BGP daemon, starting with `apt install frr`. I sure hope openbsd's BGPd doesn't have any suid binaries. And if it doesn't, well that might just as well be a vacation photo instead of a binary for all the "code" it is. I agree that they're punching above their weight, but I would also say that they are falling more and more behind. 25 years ago they were more at par in what use cases they can address, and its performance. But now it's almost retro computing. And it's fine! If you really only need a bog standard webserver, or router/firewall, then that's the use case and it solves your problem. And solves the problem without baggage. I wouldn't use it for storage, though, since running a non-checksumming filesystem nowadays is a bit of a joke. (let's not get into btrfs. I acknowledge its history, but checksumming is not backups, and backups address the historical btrfs problems while not addressing at all the checksumming)