Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
aomix
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
91.
▲
Update on OpenBSD's kernel address randomized link (KARL)
(marc.info)
4 points
by
aomix
9y ago
|
0 comments
92.
▲
by
aomix
9y ago
Every few months I get caught up on these and secretly wish I worked with a testing infrastructure even a quarter as robust. Working on an emulator seems like the most finicky development work out there but the Dolphin group can hack withou
93.
▲
by
aomix
9y ago
I've fallen into doing something similar. I read the mailing lists regularly try to look over the source for something that gets a proposed patch. Because OpenBSD boils down their software to the essentials and tries to make their APIs
94.
▲
by
aomix
9y ago
I have nothing useful to add to this discussion. I just like that this idea is a core part of the TV show Person of Interest.
95.
▲
by
aomix
9y ago
I got so used to listening to a relative explain how IBM is run by incompetents that when that person retired I felt like we lost a family tradition.
96.
▲
by
aomix
9y ago
I still don't understand the strong reactions Soylent gets on either side. There's plenty to criticize and to like but reactions to it cluster around it being the end of the world or solution to all your problems. I'm a fan
97.
▲
by
aomix
10y ago
I've read the OpenBSD developers poke fun at Linux by saying the same thing. During the 2000/XP time frame security became a serious threat to Microsoft's market dominance. Since then Windows has kept up with the best securit
98.
▲
by
aomix
10y ago
To me it seems like Rust has an additional wrinkle with safe and unsafe code. A new Rust user needs to figure out both "How do I do this" and "Is this possible in safe code". The limits of safe code seems to be something
99.
▲
by
aomix
10y ago
But that is nearly a two sentence summary of the post. -The API changes are needed and good -The migration to 1.1 will be difficult The argument is just that it's not realistic for many OpenSSL users to drop 1.0 for a variety
100.
▲
by
aomix
10y ago
I do like it when security polices are compiled into the program and like it even better when they are impossible to disable. That way programs avoid getting out of sync with best security practices since they will start crashing for all us
101.
▲
by
aomix
10y ago
You can't beat Clonezilla for personal or small scale use. It's pretty basic compared to other tools but that also lets it be dead simple to use. I've migrated or restored so many systems with it I can't remember the las
102.
▲
by
aomix
10y ago
Well, to the best of my understanding. FreeBSD will generally have better performance while OpenBSD has the latest pf syntax and features. This is a source of animosity between the two projects that I don't fully understand. FreeBSD ha
103.
▲
by
aomix
10y ago
This summer I had a router running OpenBSD on the older apu1d and was seeing nearly 700mbps on iperf with a basic rule set. But I don't know how iperf relates to real world performance.
104.
▲
by
aomix
10y ago
That's really cool, thanks.
105.
▲
by
aomix
10y ago
That statement was comparing capsicum being applied to programs that were also pledged in around 2 lines of code. A few of the programs on the wiki as examples of capsicum applications originated from OpenBSD so they were primed and ready t
106.
▲
by
aomix
10y ago
That is probably the reason for the quick uptake of pledge in OpenBSD's tree. A lot of their software had already been restructured or rewritten for privilege separation. But looking at a few capsicum diffs in the FreeBSD codebase I&#x
107.
▲
by
aomix
10y ago
The testing infrastructure they've built up around the project is incredible.A handful of developers spent years building it out and now the entire project benefits immensely from it. It's the kind of thing developers fantasize ab
108.
▲
by
aomix
10y ago
DNS doesn't seem very well secured against determined attackers. But at the same time I almost never hear about attacks done via DNS spoofing. So I guess it harder to attack than I think.
109.
▲
by
aomix
10y ago
I've read other people make this point. There are a lot of TLS implementations out there but OpenSSL was so synonymous with SSL/TLS for so long that it became a fundamental building block. If an API could be established that lets
110.
▲
by
aomix
10y ago
I thought spamd passive aggressively insulting spammers and tarpitting their connections was a good effort at wasting their time. This is a big step up from that.
111.
▲
by
aomix
10y ago
Cool approach, you need to compromise two separate servers just to have a usable password database you could run tools against. A key compromise can be fixed quickly and a password compromise is useless without the key.
112.
▲
by
aomix
10y ago
There seem to be slightly fewer Lets Encrypt and ACME implementations than stars in the sky. Which is fantastic. Last week I read about a privsep/chroot/pledge'd (OpenBSD thing) C implementation https://kristaps.bs
113.
▲
by
aomix
10y ago
Yep, here's a brief overview of that from 2007 https://youtu.be/NJ9Jml0GBPk?t=1937 . SPARC64 is a favorite of this developer because it's some Alice in Wonderland stuff where up is down and left is right compared
114.
▲
by
aomix
10y ago
Making a diy router is a fun project if you're interested in the nitty gritty details of things like firewall rulesets and dns resolving. And in the end you're left with a powerful and flexible router.
115.
▲
by
aomix
10y ago
I'm reading over the diff and this is a very interesting 9 line changelog.
116.
▲
by
aomix
10y ago
I believe the router relies on a binary blob that lets EdgeOS (based on Vyatta which is based on Debian) offload routing to some specialized hardware. I run a OpenBSD router in a PC Engine Apu1d and it's more than fast enough. I can hi
117.
▲
by
aomix
10y ago
It's worth noting that hitting that performance relies on hardware acceleration not available on OpenBSD. I've read it can still manage ~100 mbps on OpenBSD which should be good enough for most people. But keep that in mind if you
118.
▲
by
aomix
10y ago
Pretty much any security measure in isolation can be bypassed. So you need to stack as many as are reasonable on top of each other to limit the attacker's toolkit. This change is basically free and makes certain things more difficult f
119.
▲
by
aomix
10y ago
Years ago there was a short lived VPN service that tried just that. Making sure their service was on non congested optimal routes to game servers. But it didn't really take off, I assume because of that reason. All they could offer was
120.
▲
by
aomix
10y ago
The OpenBSD devs were really enthusiastic about reallocarray as a way to catch some integer overflow issues like the OpenSSH issue.
More ›