Live data from Hacker News

OpenBSD 5.6: What will be there

openbsd.org

81–83 of 83 posts

Re: OpenBSD 5.6: What will be there

#81
post #59

Earlier quoted context omitted.

That surprised me, too, because in 2013 I was installing from FTP. But mostly from habit. I'm hoping it's because they are going to be using HTTPS with pinned certs to ensure you are downloading from a proper mirror. But that's hope, not actual knowledge.

> HTTPS with pinned certs Is there an FTP equivalent of this?

There's FTP/S (and RFC-4217, and not SFTP), which uses an SSL session negotiated inside of an FTP session. I don't know if there's a client/server combo that supports pinning, but this much at least exists.

Frankly, if I was looking to implement this, I'd start with SFTP/SCP. FTP/S is, at best, a rarely implemented kludge.

Re: OpenBSD 5.6: What will be there

#82
post #11

Earlier quoted context omitted.

Off by default makes much sense given it is another vector to attack. If not needed then why be on and more likely to just use IPv4 over even touching IPv6.

Not just a vector of attack, it also causes performance and connectivity problems when misconfigured. As long as there is no critical mass for IPv6, it's not worth the headache. I know that if everyone had that attitude, IPv6 will never get critical mass, and that is exactly what I'm rooting for. I don't care for toasters with IP addresses.

I don't care for toasters with IP addresses.

Which means we'll have toasters sporting some proprietary, dumber-than-IPv6, less-functional-than-IPv6, less-secure-than-IPv6, IP address equivalent on the IoT. With DRM preventing you from toasting bread not approved by the vendor. Because there will come a point where buying a toaster without IoT enablement (in the future, toast marketing is nichy but profitable) will be about as easy as buying a 2014 production TV that doesn't sport cable hookups.

Tilt at those windmills...

Re: OpenBSD 5.6: What will be there

#83
post #82

Earlier quoted context omitted.

Not just a vector of attack, it also causes performance and connectivity problems when misconfigured. As long as there is no critical mass for IPv6, it's not worth the headache. I know that if everyone had that attitude, IPv6 will never get critical mass, and that is exactly what I'm rooting for. I don't care for toasters with IP addresses.

I don't care for toasters with IP addresses. Which means we'll have toasters sporting some proprietary, dumber-than-IPv6, less-functional-than-IPv6, less-secure-than-IPv6, IP address equivalent on the IoT. With DRM preventing you from toasting bread not approved by the vendor. Because there will come a point where buying a toaster without IoT enablement (in the future, toast marketing is nichy but profitable) will be…

No need for anything proprietary, IPv4 + NAT suffices. Solves the common problem of me accessing the toaster, and leaves the less common problem of remote toaster operation to some kind of tunnel. IoT and everything getting an IPv6 address are interesting ideas, I just doubt whether people care about it enough for it to pan out. If it's not really necessary, it's difficult to justify the cost of switching.
Post reply on HN