So, you may or may not know that, but you need FreeBSD and OpenBSD and they also need you! Every cent counts and so does every contributor, that helps the foundations keep their non-profit status. Also, you CAN be the change, if you specify what you'd like your donation to be used for (like more secure defaults for the OS).
FreeBSD – a lesson in poor defaults
31–40 of 72 posts
Re: FreeBSD – a lesson in poor defaults
#32I wonder how this compares to other unix systems, such as OpenBSD or various Linux Distros.
HardenedBSD ( https://hardenedbsd.org ) also. Which is a recent fork of FreeBSD that has a focus on security.
Re: FreeBSD – a lesson in poor defaults
#33As someone looking to move a cluster from ancient Debian, I was looking at either CentOS or FreeBSD but this looks not so nice..
Honestly, most of the concerns are rather superficial. You might want to try HardenedBSD instead of regular FreeBSD though, to get all the exploit mitigation stuff.
Re: FreeBSD – a lesson in poor defaults
#34Re: FreeBSD – a lesson in poor defaults
#35Earlier quoted context omitted.
Honestly, most of the concerns are rather superficial. You might want to try HardenedBSD instead of regular FreeBSD though, to get all the exploit mitigation stuff.
Don't do that. HardenedBSD is rather a one man project, who's patches have been reviewed and rejected by FreeBSD developers due to bad quality, poor design and lack of cooperation in bringing them to FreeBSD expected standards. It seems like a PR campaign from people who can write some C, but don't have much credibility in writing secure operating systems or production ready code. Beside the quality of the proposed s…
Re: FreeBSD – a lesson in poor defaults
#36While you're here, have you donated[0][1] yet? :) You may or may not be aware, but FreeBSD runs your movies on Netflix, your games on PlayStation and Nitendo Switch, your files on FreeNAS and ZFS, your friends on WhatsApp and OpenBSD runs everything else on OpenSSH. ;) So, you may or may not know that, but you need FreeBSD and OpenBSD and they also need you! Every cent counts and so does every contributor, that helps…
Re: FreeBSD – a lesson in poor defaults
#37As someone looking to move a cluster from ancient Debian, I was looking at either CentOS or FreeBSD but this looks not so nice..
Re: FreeBSD – a lesson in poor defaults
#38Earlier quoted context omitted.
HardenedBSD ( https://hardenedbsd.org ) also. Which is a recent fork of FreeBSD that has a focus on security.
Unfortunately, HardenedBSD is nothing more but a PR campaign from a one person who feels rejected due to poor code quality and bad reviews from FreeBSD developers who expect a bit more than just throwing random patches around and saying 'here, I fixed all these security problems with three lines of code'. I would recommend taking HardenedBSD and its announcements with a huge portion of salt.
Re: FreeBSD – a lesson in poor defaults
#39Earlier quoted context omitted.
Most new drives can do encryption in hardware with zero performance penalty using either the ATA password or Opal for NVMe. For those doing software/CPU encryption on the swap, or any other partition for the matter is simply wasteful and often slower.
Isn't on-drive encryption considered untrustworthy?
Re: FreeBSD – a lesson in poor defaults
#40Earlier quoted context omitted.
Honestly, most of the concerns are rather superficial. You might want to try HardenedBSD instead of regular FreeBSD though, to get all the exploit mitigation stuff.
Don't do that. HardenedBSD is rather a one man project, who's patches have been reviewed and rejected by FreeBSD developers due to bad quality, poor design and lack of cooperation in bringing them to FreeBSD expected standards. It seems like a PR campaign from people who can write some C, but don't have much credibility in writing secure operating systems or production ready code. Beside the quality of the proposed s…