Why OpenBSD Is Important to Me
1–10 of 162 posts
Re: Why OpenBSD Is Important to Me
#2Also, why OpenBSD specifically, and not FreeBSD for example?
Re: Why OpenBSD Is Important to Me
#3I'm curious why the author says Linux is "insecure, anti-secure, and anti-privacy software" Can anyone explain this? Also, why OpenBSD specifically, and not FreeBSD for example?
As far as I'm concerned, it's good to have options and the OpenBSD developers have created software that I use daily (OpenSMTPd, SSH, PF, etc.) and for that, I'm thankful!
ps. I know that developing IPSEC backdoors is not easy by any means. But the subsequent Theo De Raadt answer, was that he can't tell if there are backdoors or not. That was my point.
Re: Why OpenBSD Is Important to Me
#4I'm curious why the author says Linux is "insecure, anti-secure, and anti-privacy software" Can anyone explain this? Also, why OpenBSD specifically, and not FreeBSD for example?
Re: Why OpenBSD Is Important to Me
#5I'm curious why the author says Linux is "insecure, anti-secure, and anti-privacy software" Can anyone explain this? Also, why OpenBSD specifically, and not FreeBSD for example?
That's not to say there aren't distros and contributors to Linux that care deeply about security--clearly there are. I just don't find the overall ecosystem nor the most popular distros nearly as focused on or as trustworthy on security and privacy. And as the stakes get higher with more of our lives going digital and more companies, states, and criminals trying to take advantage of that trend, I worry.
As for OpenBSD vs FreeBSD, I've had an easier time getting OpenBSD working on my hardware and OpenBSD seems to me more concerned with, focused on, and practically innovative on security--that is to say, they don't just introduce new security features that can be configured and used by someone smarter than me, the OpenBSD folks work hard to introduce new security tech that's on by default with no special knowledge required by the end user, i.e. pledge, W^X.
Re: Why OpenBSD Is Important to Me
#6I'm curious why the author says Linux is "insecure, anti-secure, and anti-privacy software" Can anyone explain this? Also, why OpenBSD specifically, and not FreeBSD for example?
the reason people say that Linux is insecure is probably because Linus' stances take a hard line, in that "you must understand what you're doing in order to make a patch".
The problem is, QA and auditing is only so good and doesn't always catch the people who really don't know what they're doing.. So Linus is openly hostile to people who do stupid things consistently in some sort of attempt to fend off the others who are doing silly things although perhaps not realising it.
That's my impression and it's based on nothing more than an outside perspective so I'm probably way off base, but Linus has certainly been quoted before as saying things like "anybody who pushes for security first is a masturbating monkey", avoiding integrating GRSec and PaX for aeons and it's usually left up to distro maintainers to cherry pick the bug fixes from the mainline kernel branch.
Re: Why OpenBSD Is Important to Me
#7Re: Why OpenBSD Is Important to Me
#8Of course software is never perfect, but it's nice to know the (small) subset of OpenBSD developers working on OpenSSH are still working on keeping the proverbial doors locked.
Re: Why OpenBSD Is Important to Me
#9Even if you don't run OpenBSD, you benefit from it.
Re: Why OpenBSD Is Important to Me
#10I'm curious why the author says Linux is "insecure, anti-secure, and anti-privacy software" Can anyone explain this? Also, why OpenBSD specifically, and not FreeBSD for example?
He may also be calling Linux insecure due to it being less uncompromisingly about security. Same could be said about FreeBSD--they aren't necessarily insecure, but they are not as explicitly focussed on that.
OpenBSD invests a great deal here. They have their own fork of Xorg (or was that XFree86?) that runs not as root. As far as I know that's unique amongst libre *nixen.
EDIT: this is what I get for starting a response, getting coffee and resuming my reply. We don't have to speculate what the author of is post intended, and his response is better than mine ;-)