Live data from Hacker News

OpenBSD 6.2

openbsd.org

21–30 of 65 posts

Re: OpenBSD 6.2

#21
This is a draft of the release notes for a release which has not happened yet:

Released October 15, 2017

Broken links apparent in the doc as well.

Re: OpenBSD 6.2

#23

Off topic a bit, but anyone here use OpenBSD? I'd be interested in hearing why you use it, and what your experience has been like.

I tried... but it has no 802.11n support, from my understanding. That was a deal breaker for me.

Also, I was using an ancient CardBus ethernet adapter and it kept freezing up. Works fine on Linux. It's just unfortunate that all the things I tried had problems.

Linux just worked on the system I was using.

Re: OpenBSD 6.2

#24

Off topic a bit, but anyone here use OpenBSD? I'd be interested in hearing why you use it, and what your experience has been like.

Mail server, web server, CalDAV and CardDAV server, and development laptop. Never looked back.

Re: OpenBSD 6.2

#25
post #11

Earlier quoted context omitted.

>I've used it on my laptop. Primarily because it has had few vulnerabilities and is very stable. The OpenBSD propaganda works I see... Do you really think the tools you use like your web browser, mail client etc, have less vulnerabilities on OpenBSD than on any other BSD or linux distribution, please...

> Do you really think the tools you use like your web browser, mail client etc, have less vulnerabilities on OpenBSD... A reasonable question, but presumptuously and poorly framed, I think. Mitigation efforts like privilege separation[0] (for daemons), ASLR[1], SSP[2], and now KARL[3] are designed to make things systemically better. I'm personally a NetBSD person, and don't see that ending anytime soon, but I do appr…

All of those were developed on linux and linux distributions and were available on those before obsd...

Re: OpenBSD 6.2

#26

This is a draft of the release notes for a release which has not happened yet: Released October 15, 2017 Broken links apparent in the doc as well.

There's no bonus karma for waiting until the release is announced.

Re: OpenBSD 6.2

#27
post #10

Earlier quoted context omitted.

>I've used it on my laptop. Primarily because it has had few vulnerabilities and is very stable. The OpenBSD propaganda works I see... Do you really think the tools you use like your web browser, mail client etc, have less vulnerabilities on OpenBSD than on any other BSD or linux distribution, please...

> Do you really think the tools you use like your web browser, mail client etc, have less vulnerabilities on OpenBSD than on any other BSD or linux distribution, please... Yes. OpenBSD employs several mechanisms that improve the security of every application e.g. W^X and stack protector. See: https://www.openbsd.org/security.html

All of those are available on linux distributions, enabled by default.

Not only that, they were developed on linux distributions and available on them way before obsd.

Re: OpenBSD 6.2

#28

Earlier quoted context omitted.

>I've used it on my laptop. Primarily because it has had few vulnerabilities and is very stable. The OpenBSD propaganda works I see... Do you really think the tools you use like your web browser, mail client etc, have less vulnerabilities on OpenBSD than on any other BSD or linux distribution, please...

Actually "your web browser, mail client etc" do a lot of system calls to do networking et al, so yes, they do have less vulnerabilities than on Linux.

I don't think you know where the vast majority(95%+ ) of browser vulnerabilities are...

Re: OpenBSD 6.2

#29

Off topic a bit, but anyone here use OpenBSD? I'd be interested in hearing why you use it, and what your experience has been like.

Same as others below I use it as a firewall and have used OpenBSD since it was available for my Sparcstation IPC.

Don't get me wrong - my lab desktop at work is Fedora 26, my little lab boxes are mostly running Debian Stretch and I'm an RCHE current on things like SystemD who has a ton of RH boxes I support day in and day out. But OpenBSD is very old school UNIX in its simplicity; there is no cruft in the base OS because it's really built for a few specific purposes.

There are downsides to running OpenBSD; it didn't win any packet shifting races versus other BSDs last I looked, but it is (arguably) the most secure of the BSDs and for a firewall it is undeniably otherwise fit for purpose. Any old $100 refurbished PC from Microcenter and a couple of Intel NICs are all you need to build a whitebox firewall with lots of interesting knobs.

Every time I upgrade I literally throw all my configs to a USB stick, put in a new hard drive and do an install from scratch. Copying configs back and looking for changes between the distributions is the relatively painless work of a couple of hours and forces me to make sure nothing major has changed either in behavior of or the software packages themselves.

If there's any downside to OpenBSD it is that it isn't newbie friendly... I call it a full contact operating system because some of the list members can be abrupt to folks asking questions found in the FAQ.

Re: OpenBSD 6.2

#30
post #10

Earlier quoted context omitted.

> Do you really think the tools you use like your web browser, mail client etc, have less vulnerabilities on OpenBSD than on any other BSD or linux distribution, please... Yes. OpenBSD employs several mechanisms that improve the security of every application e.g. W^X and stack protector. See: https://www.openbsd.org/security.html

All of those are available on linux distributions, enabled by default. Not only that, they were developed on linux distributions and available on them way before obsd.

No, they are not.
Post reply on HN