Live data from Hacker News

EU study recommends OpenBSD

undeadly.org

11–20 of 153 posts

Re: EU study recommends OpenBSD

#11
post #2

Theo De Raadt always complained that many of the institutions that run and use OpenBSD don't contribute back. Good to see the EU at least acknowledging that its something that they should explore. They probably use it and its features more than they realise. I suspect there is a strong political motive as well behind being "technologically independent" after the NSA mass surveillance revelations. I like the sound of…

"said the great problem we would face is that companies would take our BSD code, modify it, and not give back. − Nope. We have many companies giving us code back, all the time." - Theo De Raadt

Re: EU study recommends OpenBSD

#12
post #10

Didn't everyone recommend Linux and Mac OS back when vulnerabilities on these systems just hadn't been discovered (or possibly written) yet? Make OpenBSD popular, add a ton of devs, and attack value, and I'm pretty sure these problems will repeat themselves. I think the second study, which briefly names OpenBSD, does a good job of pointing out that technological changes alone are insufficient.

Yes, and a Brinks armored truck is just as vulnerable to carjackings as a Ford Pinto, we just don't know about the vulnerability because nobody drives them. People were saying the same things about Linux. In the late 1990s and early 2000s. By which time Linux had already become the de-facto go-to OS for web servers around the world. It was, in short, already a high-value target, and yet the apocalypse didn't occur.

Of course that's true. I'm just not convinced that OpenBSD : Linux :: Armored truck : Pinto.

In fact, the point of a good portion of the second study [1], p.17-25 is pointing out the flaws that have occurred in the Linux operating system and other existing technologies.

[1]http://www.europarl.europa.eu/RegData/etudes/STUD/2015/52740...

Re: EU study recommends OpenBSD

#13
post #4
post #2

Theo De Raadt always complained that many of the institutions that run and use OpenBSD don't contribute back. Good to see the EU at least acknowledging that its something that they should explore. They probably use it and its features more than they realise. I suspect there is a strong political motive as well behind being "technologically independent" after the NSA mass surveillance revelations. I like the sound of…

> Theo De Raadt always complained that many of the institutions that run and use OpenBSD don't contribute back. Sounds like he needs a different license then.

I don't think that would make them likely to contribute back, they'd just use something else. He'd rather have selfish people using good software than choosing to use something inferior.

Re: EU study recommends OpenBSD

#14
post #11
post #2

Theo De Raadt always complained that many of the institutions that run and use OpenBSD don't contribute back. Good to see the EU at least acknowledging that its something that they should explore. They probably use it and its features more than they realise. I suspect there is a strong political motive as well behind being "technologically independent" after the NSA mass surveillance revelations. I like the sound of…

"said the great problem we would face is that companies would take our BSD code, modify it, and not give back. − Nope. We have many companies giving us code back, all the time." - Theo De Raadt

If so, then the issue is they don't contribute money?

Re: EU study recommends OpenBSD

#15
post #3

The EU also funds Minix 3 development, though that is more about reliability than security.

The thing about security is that it touches everything.

Ease of use? If something's hard to use, it's easy to confuse people into doing insecure things. Security issue.

Unreliable? Security depends on predictable behavior, and failure modes are often unpredictable. Security issue.

Proprietary protocol? Even if it wasn't intentionally backdoored, you don't know its real attack surface, because you don't know all of the verbs it contains. Verbs imply actions, actions imply changes of state, changes of state imply the Dark Side... uh, security concerns. Security issue.

Performance? Even aside from timing attacks and simple DoSing, things often behave oddly when pushed to a limit, especially if that limit involves otherwise-hidden race conditions. Security issue.

Re: EU study recommends OpenBSD

#16
post #11
post #2

Theo De Raadt always complained that many of the institutions that run and use OpenBSD don't contribute back. Good to see the EU at least acknowledging that its something that they should explore. They probably use it and its features more than they realise. I suspect there is a strong political motive as well behind being "technologically independent" after the NSA mass surveillance revelations. I like the sound of…

"said the great problem we would face is that companies would take our BSD code, modify it, and not give back. − Nope. We have many companies giving us code back, all the time." - Theo De Raadt

You could have easily taken the full quote -- it's not quite the contradiction you're trying to make:

"GPL fans said the great problem we would face is that companies would take our BSD code, modify it, and not give back. Nope—the great problem we face is that people would wrap the GPL around our code, and lock us out in the same way that these supposed companies would lock us out. Just like the Linux community, we have many companies giving us code back, all the time. But once the code is GPL'd, we cannot get it back."

Re: EU study recommends OpenBSD

#17
post #2

Theo De Raadt always complained that many of the institutions that run and use OpenBSD don't contribute back. Good to see the EU at least acknowledging that its something that they should explore. They probably use it and its features more than they realise. I suspect there is a strong political motive as well behind being "technologically independent" after the NSA mass surveillance revelations. I like the sound of…

In general, the EU is _very_ strong on open source commitments. Almost all projects that I know of and some of which I'm working on funded as part of FP7 (Seventh Framework Programme) will eventually end up open-sourced.

Re: EU study recommends OpenBSD

#18
post #4
post #2

Theo De Raadt always complained that many of the institutions that run and use OpenBSD don't contribute back. Good to see the EU at least acknowledging that its something that they should explore. They probably use it and its features more than they realise. I suspect there is a strong political motive as well behind being "technologically independent" after the NSA mass surveillance revelations. I like the sound of…

> Theo De Raadt always complained that many of the institutions that run and use OpenBSD don't contribute back. Sounds like he needs a different license then.

I don't think any of the free/open licenses require users to contribute to the parent project. I don't think any even require that people distributing modified versions, send those modifications back upstream.

Re: EU study recommends OpenBSD

#19
post #17
post #2

Theo De Raadt always complained that many of the institutions that run and use OpenBSD don't contribute back. Good to see the EU at least acknowledging that its something that they should explore. They probably use it and its features more than they realise. I suspect there is a strong political motive as well behind being "technologically independent" after the NSA mass surveillance revelations. I like the sound of…

In general, the EU is _very_ strong on open source commitments. Almost all projects that I know of and some of which I'm working on funded as part of FP7 (Seventh Framework Programme) will eventually end up open-sourced.

Interesting! Could you elaborate some more and perhaps list a few projects, if you're allowed to?

Re: EU study recommends OpenBSD

#20
post #16
post #11

Earlier quoted context omitted.

"said the great problem we would face is that companies would take our BSD code, modify it, and not give back. − Nope. We have many companies giving us code back, all the time." - Theo De Raadt

You could have easily taken the full quote -- it's not quite the contradiction you're trying to make: "GPL fans said the great problem we would face is that companies would take our BSD code, modify it, and not give back. Nope—the great problem we face is that people would wrap the GPL around our code, and lock us out in the same way that these supposed companies would lock us out. Just like the Linux community, we h…

>Nope—the great problem we face is that people would wrap the GPL around our code, and lock us out in the same way that these supposed companies would lock us out.

Does he offer any examples of this happening ?

Post reply on HN