Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
notaplumber
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
61.
▲
by
notaplumber
6y ago
> Is this really appropriate for a core system component to have this many dependencies? Absolutely not. The entire OpenBSD base system can be built without an internet connection.
62.
▲
by
notaplumber
6y ago
BSD does not use GNU coreutils. Is it really unexpected that the developer of a BSD project might have been unaware at the time of a project attempting to replace it, or simply found it incompatible with the stated requirements-- POSIX comp
63.
▲
SerenityOS Update (April 2020)
(youtube.com)
3 points
by
notaplumber
6y ago
|
1 comments
64.
▲
by
notaplumber
6y ago
I have to believe given the sheer size of these communities, that the source code being available only helped to confirm what was already known. The panic seen here hearkens back to the days when companies made similar ridiculous security c
65.
▲
by
notaplumber
6y ago
What is up with the strange sensationalist claims in the article on and Twitter? Source code availability is not a prerequisite to people finding vulnerabilities or RCE exploits in games, there are many established games with open source ga
66.
▲
by
notaplumber
6y ago
I want one of these machines so bad. Would be an epic workstation, but the price tag is high. OpenBSD would mostly just work on these, as it already runs on the server boards. It even already has AMD graphics drivers ported to arm64, and a
67.
▲
by
notaplumber
6y ago
No. LibreSSL fork predates the issue, and has its own TLS 1.3 implementation. I'd expect the situation to be similar with Google's BoringSSL, but I don't how closely they track OpenSSL, if at all.
68.
▲
by
notaplumber
6y ago
Which is a bizarre statement, all ports development happens on the OpenBSD -current branch, which is effectively a rolling release for developers/users running snapshots. All of those projects that switched were simply expecting LibreS
69.
▲
by
notaplumber
6y ago
> Both SSH and SSL base on TLS. You are very mistaken. OpenSSH only uses OpenSSL (or LibreSSL) as an optional dependency for the libcrypto primitives (RSA/AES etc). NOT for libssl. The SSH protocol has nothing to do with either SSL
70.
▲
by
notaplumber
6y ago
No, LibreSSL is a fork of OpenSSL that predates this vulnerability, it even predates the OpenSSL 1.1.x API break (some compatibility has since been added), and has an entirely separate and new TLS 1.3 implementation. https://www.
71.
▲
by
notaplumber
6y ago
'mental' can often also mean 'crazy'.
72.
▲
by
notaplumber
6y ago
Thanks for the update!
73.
▲
by
notaplumber
6y ago
OpenBSD just released a portable version of their privsep rpki-client(8)* this week! https://www.rpki-client.org/ rpki-client 6.6p1 was released Apr 13, 2020: https://www.rpki-client.org/txt/rpki-client
74.
▲
by
notaplumber
7y ago
I sorta knew that. But it still feels weird for dollar amounts. As 25.000 looks a lot like 25.00 ($25 dollars, 0 cents).
75.
▲
by
notaplumber
7y ago
They mean USD $25,000 and not $25.
76.
▲
by
notaplumber
7y ago
I wish more people would have seen through this, but alas.. this is the real reason. Corporate pressure, agenda, not the best interest of the open source community. http://lists.llvm.org/pipermail/llvm-dev/2015-Oct
77.
▲
by
notaplumber
7y ago
> GCC is licensed under the GPL license. Clang uses a BSD license ... Looks like this hasn't been updated in a while. As of Clang 9.0 they migrated everything to the Apache 2.0 license, which is not nearly as permissive as BSD. Apac
78.
▲
by
notaplumber
7y ago
https://www.openbsd.org/sgi.html "The OpenBSD/sgi port was discontinued after the 6.5 release." That said, it was a very mature port and ran on many models, in 64-bit mode. The code remains in -current for no
79.
▲
by
notaplumber
7y ago
If a program needs arbitrary file-access late or "forever" then at least unveil(2) won't work, because that process needs arbitrary access. Sometimes a user policy can be enforced, i.e: documents must be in $HOME/Documen
80.
▲
by
notaplumber
7y ago
> OpenBSD-current users are not affected, www/mozilla-firefox update is already committed and will be available soon on the mirrors.
81.
▲
by
notaplumber
7y ago
In 2012, first release 5.3 in 2013. Added by Matthew Dempsky. It was used for the per-shared object stack protector cookie extended for the per-function cookies required for RETGUARD. https://github.com/openbsd/src/
82.
▲
by
notaplumber
7y ago
What it means. It's glib remark implying there was any difficulty.
83.
▲
by
notaplumber
7y ago
I'm sure they won't, if history tells us anything. It'll forever remain "liberated".
84.
▲
by
notaplumber
7y ago
Unless it's not immediately obvious-- there are no OpenBSD developers associated with this project, past or present. This isn't some splitting of existing communities. There was nothing "hard" about this fork, it's
85.
▲
by
notaplumber
7y ago
This isn't limited to C. If you run compiles as root, game over. fn main() { let shadow = include_str!("/etc/shadow"); println!("{}", shadow); } That's why OpenBSD ports c
86.
▲
OpenBSD U2F/Fido(4) Driver
(marc.info)
4 points
by
notaplumber
7y ago
|
0 comments
87.
▲
by
notaplumber
7y ago
Why OpenBSD/amd64 will not, and never has supported 32-bit binary compatibility on 64-bit. https://marc.info/?l=openbsd-misc&m=148926149318522
88.
▲
by
notaplumber
7y ago
It's a few threads above the OpenBSD one on oss-security, hardly obscure. https://www.openwall.com/lists/oss-security/2019/12/
89.
▲
by
notaplumber
7y ago
Yes, correct. smtpd is enabled on localhost for local users only. This is pretty common on most systems, AFAIK Debain uses exim4.
90.
▲
by
notaplumber
7y ago
No.
More ›