Live data from Hacker News

HardenedBSD Feature Comparison with OpenBSD, FreeBSD, NetBSD

hardenedbsd.org

11–20 of 81 posts

Re: HardenedBSD Feature Comparison with OpenBSD, FreeBSD, NetBSD

#11
post #5

Read these claims with a pretty big asterisk. Implementation quality of HBSD features is often poor or very poor. https://www.fabiankeil.de/gehacktes/hardenedbsd/ is just one example. Specifically some of the changes made to "harden" the system are pretty dubious and introduce new bugs, possibly security relevant, that did not previously exist. No one runs or pen tests HBSD. It's even more niche than OpenBSD.

A positive scenario for forks is when the original project incorporates downstream changes that were positive. Could FreeBSD implement some of the security features identified by HardenedBSD?

Could implement some of the features (even if off by default), but probably not by using the HBSD diffs.

Re: HardenedBSD Feature Comparison with OpenBSD, FreeBSD, NetBSD

#12
post #9
post #6

Earlier quoted context omitted.

Self promotion / advertisement should always be read with a _big_ *. What should probably not be read with a _big_ * is their roadmap end: 2021... https://hardenedbsd.org/content/roadmap

With small projects, websites tend to be updated infrequently. On the other hand, there seem to have been 11 commits to the main project repo today: https://groups.google.com/a/hardenedbsd.org/g/src-commits-al...

These are all or mostly all just automated sync from upstream FreeBSD.

Re: HardenedBSD Feature Comparison with OpenBSD, FreeBSD, NetBSD

#13
That checklist is interesting. In what sense does OpenBSD have most of the base OS sandboxed? I'm kind of skeptical of that, but wondering if I missed something.

What any BSD needs to have a merit to a claim to security, in 2024, is some form of MAC. As long as there is no way to take away from having an all powerful root user (and pledge and unveil ain't it), then they have a long ways to go.

Re: HardenedBSD Feature Comparison with OpenBSD, FreeBSD, NetBSD

#14

That checklist is interesting. In what sense does OpenBSD have most of the base OS sandboxed? I'm kind of skeptical of that, but wondering if I missed something. What any BSD needs to have a merit to a claim to security, in 2024, is some form of MAC. As long as there is no way to take away from having an all powerful root user (and pledge and unveil ain't it), then they have a long ways to go.

> In what sense does OpenBSD have most of the base OS sandboxed?

They're talking about pledge. https://man.openbsd.org/pledge.2

Re: HardenedBSD Feature Comparison with OpenBSD, FreeBSD, NetBSD

#15

Earlier quoted context omitted.

I can just think of so many better things to do than to write online arguing which BSD implementations of features is better.

Write online how Linux distributions of features are better?

If anything, that's much more pointless. The biggest difference between linux distros is what package manager and init systems they use by default. BSDs develop and maintain their own kernels and userspace, so there are actual non-cosmetic differences between them.

Re: HardenedBSD Feature Comparison with OpenBSD, FreeBSD, NetBSD

#16
It's easy to invent a chart that only you can get a nearly perfect score on.

This does nothing to explain what any of these features are, what are "Boot hardening" and "sysctl hardening"?

At least OpenBSD's innovations page makes an attempt to explain new concepts and features that have been developed over the years, and people can make any comparisons for themselves.

https://www.openbsd.org/innovations.html

Re: HardenedBSD Feature Comparison with OpenBSD, FreeBSD, NetBSD

#17
post #14

That checklist is interesting. In what sense does OpenBSD have most of the base OS sandboxed? I'm kind of skeptical of that, but wondering if I missed something. What any BSD needs to have a merit to a claim to security, in 2024, is some form of MAC. As long as there is no way to take away from having an all powerful root user (and pledge and unveil ain't it), then they have a long ways to go.

> In what sense does OpenBSD have most of the base OS sandboxed? They're talking about pledge. https://man.openbsd.org/pledge.2

I thought that might be the case. So not actually sandboxing at all.

Re: HardenedBSD Feature Comparison with OpenBSD, FreeBSD, NetBSD

#18
post #14

Earlier quoted context omitted.

> In what sense does OpenBSD have most of the base OS sandboxed? They're talking about pledge. https://man.openbsd.org/pledge.2

I thought that might be the case. So not actually sandboxing at all.

What does Sandboxing™ give you that pledge+unveil doesn't?

Re: HardenedBSD Feature Comparison with OpenBSD, FreeBSD, NetBSD

#20
post #15

Earlier quoted context omitted.

Write online how Linux distributions of features are better?

If anything, that's much more pointless. The biggest difference between linux distros is what package manager and init systems they use by default. BSDs develop and maintain their own kernels and userspace, so there are actual non-cosmetic differences between them.

[deleted]
Post reply on HN