Earlier quoted context omitted.
I never claimed Linux was a Pinto. My point is, some things are just built well, and even if they're not used very often we can expect a certain level of quality, as opposed to saying that the only reason we don't see them stolen is because so few people drive them. Especially if they're used all the damn time, just not in places people see a lot. So some bugs will be found in OpenBSD. That's a given. However, it isn…
Yeah, I agree 100% :-) I guess what I'm saying is that it would make more sense to me if OpenBSD and Linux were both on the list. As you also mentioned, flaws existing in programs is inevitable, so unless the defect rate, normalized for usage, is significantly higher in one case, it's not good evidence for the quality or security of one over another.
EU study recommends OpenBSD
111–120 of 153 posts
Re: EU study recommends OpenBSD
#112Earlier quoted context omitted.
The problem is that de Raadt and crew have a much bigger priority: that OpenBSD's code proliferate and prevent any duplication of effort in creating secure programs. They've explicitly stated in the past that they consider proprietary use of their code to be a good thing (albeit it would be better if they'd push some money back to the OpenBSD crowd) because it prevents those companies from having to create yet anothe…
That's a perfectly reasonable priority! It's just that it possibly comes along with some disappointment, caused by people who don't contribute anything back (money, code, documentation or simply promoting the software).
Re: EU study recommends OpenBSD
#113Earlier quoted context omitted.
I primarily know about the projects listed at https://www.fokus.fraunhofer.de/809f10db25eddf3e/projects A personal observation is that, nowadays, gitlab seems to be preferred to github as part of a push to rely more on software developed inside the EU (guess it's an aftermath of the whole NSA story). PolicyCompass, for example, lives at https://github.com/policycompass Carneades lives at http://github.com/carneades M…
Never heard of them. Neglected PR?
I'd expect the upcoming (pan)"European Open Data Portal" to receive significantly more PR from the EU.
Re: EU study recommends OpenBSD
#114The EU also funds Minix 3 development, though that is more about reliability than security.
Re: EU study recommends OpenBSD
#115Earlier quoted context omitted.
And you can from proprietary licensed modifications? FSF recommendation is that you use the same license as the project which you are contributing to. If you use a BSD project, contribute your patches under BSD. If its GPL, contribute under GPL. If you combine work under BSD and GPL and write modifications, contribute back the modifications based on what code you are doing modification for. The proprietary way is to…
That's not the point. Let me rephrase that: - one of GPL's cool thing is that it prevents proprietary software from including GPL'd code without contributing back to the community - Because BSD is not as strict as GPL regarding license derivation, GPL says "BSD is bad, you're allowing proprietary software to use BSD code without giving back" - Some people take BSD code, modify it and distribute modifications under GP…
This is not an accurate description of what the GPL is shooting for, which has significant consequences on the things built up from this misunderstanding.
Re: EU study recommends OpenBSD
#116Earlier quoted context omitted.
>Nope—the great problem we face is that people would wrap the GPL around our code, and lock us out in the same way that these supposed companies would lock us out. Does he offer any examples of this happening ?
That comment came about because of a licensing spat with the atheros source code. http://undeadly.org/cgi?action=article&sid=20070913014315
http://thread.gmane.org/gmane.linux.kernel.wireless.general/...
Theo got very upset that the Linux devs practised 'full disclosure' over the violation and didn't contact OpenBSD privately (presumably he thinks customers who make use of OpenBSD should be fully informed about security threats that affect them, but not informed at all about legal threats that might put them at risk). He also tried to argue that the multiple commits over a period of time that contained copy and pasted GPL code was accidental, and got very upset when people suggested that one couldn't possibly accidentally copy specific portions of a GPL codebase and commit it to the repo multiple times. Theo also tried to argue that it wasn't a copyright violation since the code wasn't actually run-able (he knows full well that isn't how copyright law works).
The Linux developers response to that incident was also possibly partly motivated by earlier requests by some Linux developers for OpenBSD to dual licence portions of a different driver (i.e. also make it GPL). OpenBSD refused, for some of the reasons discussed already in this thread (they would likely receive GPL licensed changes that they would not be able to use). The strong reaction from the Linux devs was maybe to be expected after they had been told they couldn't use OpenBSD code, but then found OpenBSD had been stealing their code.
So there was a great big mess of egos and petty squabbling. I think a lot of that motivated the later copyright violations in the atheros drivers by the Linux developers that Theo is (rightly) complaining about above.
Re: EU study recommends OpenBSD
#117Earlier quoted context omitted.
More often than not, he wasn't referring to contributions in the FSF sense (i.e. people modifying code that they don't send back to the original authors). He simply meant that many of the institutions that run and use OpenBSD, which is available entirely for free, don't give anything in return - be it in the form of code, money, documentation or promotion. Another free license solves only a small proportion of this p…
Another free license solves only a small proportion of this problem. True, but with BSD I'm not sure you can view it as a problem to begin with since the license is explicitly designed to legally absolve the user of all obligation to do just that. If you desire monetary contributions be made, some kind of commercial license is the solution. If you desire modifications be contributed back, there are other licenses tha…
Asking people to consider it is the right thing to do. Switching license would defeat the entire point.
Re: EU study recommends OpenBSD
#118Earlier quoted context omitted.
Another free license solves only a small proportion of this problem. True, but with BSD I'm not sure you can view it as a problem to begin with since the license is explicitly designed to legally absolve the user of all obligation to do just that. If you desire monetary contributions be made, some kind of commercial license is the solution. If you desire modifications be contributed back, there are other licenses tha…
I think from the BSD point of view, contributing back is seen more of a weak social obligation than a legal one. You contribute back because it's a nice thing to do for those giving you free stuff, not because of section 6 paragraph 1 of some ten page legal document. Asking people to consider it is the right thing to do. Switching license would defeat the entire point.
I don't think that it is a coincidence that GPL led to Red Hat, a billion dollar support and services company, while BSD let to a multitude of hardware companies. The former is direct and the latter indirect profits of their respective software. The difference in worldview leads to different business ideas.
Re: EU study recommends OpenBSD
#119Theo De Raadt always complained that many of the institutions that run and use OpenBSD don't contribute back. Good to see the EU at least acknowledging that its something that they should explore. They probably use it and its features more than they realise. I suspect there is a strong political motive as well behind being "technologically independent" after the NSA mass surveillance revelations. I like the sound of…
> Theo De Raadt always complained that many of the institutions that run and use OpenBSD don't contribute back. Sounds like he needs a different license then.
GPL fans said the great problem we would face is that companies would take our BSD code, modify it, and not give back. Nope—the great problem we face is that people would wrap the GPL around our code, and lock us out in the same way that these supposed companies would lock us out. Just like the Linux community, we have many companies giving us code back, all the time. But once the code is GPL'd, we cannot get it back.
Re: EU study recommends OpenBSD
#120I love openBSD, it's implementation of certain things is slower (like networking), but it's so clean and well implemented. even if it doesnt' get to play with all the toys (like ZFS) it's what I'd love to default to for application servers/bastion server/firewalls etc; my only qualm with it currently is it's reliance of X11 for ports to work- I don't like install X11 libs on my servers wherever I can avoid it. :\
> my only qualm with it currently is it's reliance of X11 for ports to work- I don't like install X11 libs on my servers wherever I can avoid it. :\ Can you give a reference to this? I'm not doubting you, as I always install x11 anyway, I just didn't know this was still the case. I remember an issue with a lib in xbase.tgz a few years back that was required by lots of ports, but I thought they moved it to base.tgz. T…
http://www.openbsd.org/faq/faq15.html#NoFun (at the bottom of this section)