Slashdot Mirror


OpenBSD, Reductionist Design

Duke of URL writes: "Sam Williams, of Upside Today has an article discussing OpenBSD's overall design philosophy, with good quotes from Theo de Raadt, the OpenBSD project leader. Williams also covers how the OpenBSD project goes about supporting their financial needs (by selling t-shirts, CDs, and posters) and briefly covers their lack of desire to receive venture capital despite offers. "

114 comments

  1. Re:Reductionist OS, reductionist user ... by Anonymous Coward · · Score: 1
    Pfff!! That's not a reductionist philosophy!

    I start fires by rubbing sticks together and I bathe in streams. I always wear the bare minimum (just enough so I won't get arrested). My productivity has increased since my switch from Open BDSM, and I've become more appealing to women!

  2. You read it wrong! by Anonymous Coward · · Score: 1

    did you READ??? they DO NOT WANT venture capital. NOT want.

    Read that last paragraph from the article again.

    1. Re:You read it wrong! by SirGeek · · Score: 1
      did you READ??? they DO NOT WANT venture capital. NOT want.

      Yes.. But based on all I have read, and from personal experience my take on it was

      Do Not Want = Know I can not get

      Sorry.. it is my opinion... such is life.

  3. Re:OpenBSD owns by Anonymous Coward · · Score: 1

    Main OS Advantages:

    Windows: Software & cutting edge driver hardware support.
    Linux: Growth.
    FreeBSD: maturity/stability
    OpenBSD: security


    Choose your OS based on needs.
    If you need games, get windows.
    If you need Unix qualities and app support, get Linux.
    If you need an OS that's tried and true, use FreeBSD.
    If you need security, get OpenBSD

    Note each OS has more qualities that listed here.
    Personally, I choose OpenBSD b/c I store mission-critical, ultra-sensitive data on my home PC, and I don't care if I have any applications.

  4. Re:all about marketing by Ranger+Rick · · Score: 1
    > It's not my choice, but the Market has decided
    > that's what it wants, and I have to respect
    > that.

    Wait a minute. You're in marketing, you should be perfectly positioned to know that most of the stuff marketing makes up is over-hyped and/or completely untrue. So why would you respect what the market decides is the defacto standard? :)

    :wq!

    --

    WWJD? JWRTFM!!!

  5. Re:OpenBSD's history by iota · · Score: 1

    While I can understand your trust issues, I have to disagree. What if Linus became an asshole? Would you stop using the Linux kernel? Theo may be rather tough at times, but thats just the way he is. If it bothers you, thats fine -- but it in no way affects the quality of OpenBSD.

    With OpenBSD's development model (all packages are audited and checked before being integrated properly with the system, as opposed to Linux, where all packages are thrown at the computer and put in little directories untill they work) the work of every developer, including Theo, is checked and audited by the other developers. 'OpenSource' software is the same way, you say? I don't see anyone checking the quality of a program before they make an RPM of it and drop it in their distributions CD. For example, just go throw in your latest RedHat CD and search for GNOME RPM's :)

    I trust Theo more than I trust a bunch of little, non-connected groups of penguin-shirt-wearing developers who preach Linux all the time. Linux is nice, and I'm no Linux basher - but I've yet to find a situation where Linux is the best choice to implement, instead of a BSD or other OS. Linux Firewall? No thanks, I like something secure, OpenBSD please! Linux Webserver? FreeBSD here I come. Of course, BSD's aren't as good as Linux is, because they aren't ever on ZDtv, and not in every national publication. Silly me, I forgot that the best software is the one thats got the most publicity, not the one that has the highest quality. Perhaps you forget August 24, 1995.

    jason

  6. Re:OpenBSD's history by iota · · Score: 1

    It was a big media event. People across the nation camped out to wait for copies of a great (heh) new piece of software that would forever lower the bar for software quality:

    Windows95 was released August 24th, 1995.

    :) jason

  7. Re:OpenBSD's history by iota · · Score: 1

    I run a quad CPU system on FreeBSD.
    I've never had a piece of quality hardware that was not supported out of the box by OpenBSD (or at least NetBSD).
    OpenBSD can binary emulate most of the other UNIX-alike's for the platform it runs on, including Linux.
    And I get all the support I could ever need from the newsgroups, the great man pages, and the FAQ.

    Any other arguments? :)

    jason

  8. well thought out, not just security by pixel+fairy · · Score: 1
    That default install is also set up out of the box with other stuff that just makes life easier, down to the little details. for example less is already installed and set as your pager. granted its easy to install and set less in any other OS, this is just an example. another is dhcp and apache already being there, and like other BSDs, ipfilter ready to go.


    so if you want to home firewall / NAT / router thats easy to set up and use, the default install gives you all that.


    my point here is that its also very well thought out for its other uses as well, and unlike netbsd, they are not afraid to break traditions if they think something is better. (they are not like slackware here, again, its just little things)


    even the installation is well thought out. almost all of it is just hitting enter for defaults except paritioning, which almost anyone doing this is going to have thier own preferences for anyway.


    i think the fact that most of us ftp install is because its so easy even if you have the CD.


    i still dont use it for alot of my work, it does lack some stuff that linux has. (like java-1.2)

  9. Re:More of Less! by The+Finn · · Score: 1
    Developing/studying systems that can be proved secure (buffer overflow wrapper where?)

    you could have runtime protection automatically inserted by the compiler, like stackguard but it'd probably be better in the long term to use languages that have strict bounds and type checking. (modula3?)

    --
    NetBSD: the cathedral vs the bizzare.
  10. Re:How do you convince PHB to use BSD? by freddie · · Score: 1

    I've been in the same situation you are alot of times. I haven't found a solution for the situation, as the company i'm working for has spent about 1/2 million on sun and oracle stuff (at least not windows), that could have done with one pc running linux and mysql, but here are

    a couple of ideas:

    1. Install the box, regardless of what anyone says. Once it's there they will probably use it.

    2. Work for another company, where geting things done is valued more than politics

    3. Install whatever equipment they want. You are a techie, and you are expected to like expensive equipment. Enjoy it and encourage them to buy more, remember it's not your money!

  11. Re:OpenBSD's history by aphr0 · · Score: 1

    Um. What happened August 24, 1995?

  12. Re:all about marketing by cymen · · Score: 1

    WTF... My bad apparently, this is not in reply to the comment it is attached to...

  13. Re:all about marketing by cymen · · Score: 1

    Wow! Just the right mix of "can this guy really be true" and "what a toker." Congrats on the hilarious post. Now I hope this gets moderated to "funny" (or whatever the humor category is) and not flame bait! Or maybe it is just my lack of sleep...

  14. Re:BSD is not secure! by cymen · · Score: 1

    While I'm no BSD zealot I think you took a few turns off the main road by accident with your example of Hotmail. The security holes were in Hotmail (the custom server software) not BSD.

  15. Re:all about marketing by PD · · Score: 1

    A truly cynical slashdot reader would walk down the street, and upon seeing two people in conversation, would wonder "who trolled who?"

    FOLKS! If I post something, and someone else responds to it, that does not necessarily mean that I trolled that other guy! There is a possibility that we are actually having a conversation!

    I ought to retell the story of the little boy who cried "troll" sometime...

  16. Re:Tired of people whining about OpenBSD CDROM Ima by kurowski · · Score: 1
    And DO buy the CDROMs, they help the project in so many ways...

    No! Don't buy the CD-ROMs just to support the project. Buy them if you need to. Otherwise just download the damn thing. If you want to support the project, just figure out the price of the CD, plus shipping, and donate it to the project. They get to keep the shipping expense, and there's one less worthless CD destined for some landfill.

    If you really want to own some physical thing that shows you support OpenBSD, then buy a T-shirt or two. You'll use it a hell of a lot more often than you would use a CD, and in the long run it's a bit more biodegradeable ;)

  17. Re:all about marketing by Yenya · · Score: 1
    Free/NetBSD have been around longer than Linux, but they didn't get the attention because they're more concerned with refining the code than writing press releases and speaking at conferences.

    I don't want to jump into an OS flamewar, but I have to correct the above statement. Both NetBSD and FreeBSD projects were founded later than Linux. The BSD UN*X has been there longer than Linux for sure. 386BSD and Linux are about the same age, but the FreeBSD/NetBSD projects as well as the OpenBSD project are younger than Linux.

    I think (no flames, please) the success of Linux should be attributed to its license and to its more open development model instead of speaking at the conferences and writing the press releases (Do you remember any press release by Linus except for the press releases for Linux 1.0, 1.2, 2.0 and 2.2?).

    -Yenya
    --

    --
    -Yenya
    --
    While Linux is larger than Emacs, at least Linux has the excuse that it has to be. --Linus
  18. Re:all about marketing by Lx · · Score: 1

    ok, the xml support maybe. I suppose that's not a bad idea, but I'm not a big fan of kernel modules. DirectX though, not a chance. There are efforts underway to make crossplatform versions of such things though, like SDL.

    -lx

  19. Re:all about marketing by Lx · · Score: 1

    You folks just don't get it, do you? BSD is NOT TRYING to gain more marketshare. You're thinking of Linux. BSD is concerned with making the best product possible - if lots of people use it, fine, if only a few do, fine. There is no need for market strategy, and this seems to be a hard concept for people to wrap their minds around. As for your 'monthly release cycle', we have a daily one. There are nightly snapshots, and you can always sync your source with the current versions.

    Furthermore, what kind of crack are your experts on? XML support in the kernel? What the hell for? That makes zero sense. And besides the fact that DirectX is a proprietary Microsoft standard, why exactly does UNIX need it?

    -lx

  20. Re:Linux is insecure. by JamesKPolk · · Score: 1

    security is a function of...

    1) how well designed certain OS features are

    2) how much time people are WILLING to poke at it

    Linux's announcement count benefits from 2, at least as much as 1. I'd say "same with Windows", but nobody has access to the code, to see if its kernel is written anything like a sensible kernel would be.

  21. why the sudden hike in 1999? by johnnnyboy · · Score: 1

    Looks like 1999 was a very bad year for linux and NT in general. Why the sudden kie compare to other years? I don't believe the numbers are accurate. Since when does netware and macos get so few security holes? I think the numbers are much higher for these lame systems.

    --
    "If a show of teeth is not enough, bite ... but bite hard!"
  22. Re:Question: Why so many versions ? by Clover_Kicker · · Score: 1

    >What is the difference between a version (BSD)
    >and a distro (Linux)?

    The various Linux distros all have the same Linux kernel (maybe different versions, but it's all the same kernel, more or less).

    Linux distros differ mostly in userland stuff, i.e. how the directories are laid out, init scripts, what utilities are bundled, packaging infrastructure, etc.

    The various BSDs have different kernels. They all started from the same codebase, but have diverged significantly since.

    Of course, the various BSD userland stuff has some differences as well.

  23. Re:No Capital ? Partial blame is Theo by Yakman · · Score: 1
    As an aside (and a vent) they (read Theo) aren't not listening to the community. The other BSD's (Free and Net) both are now releasing ISO images to download. When I wanted to do some comparisons of Free/Net/Open BSD's, I wanted to download the ISO's and burn CD's (at work, since at home I only had a 33.6K dial up). For Net and Free BSD's this was not a problem. When I got to OpenBSD, Nope.. No ISO. When I asked (in what I believe to be a polite manner) I was told basically to stick it that if I wanted a CD, I had to purchase it becuase creating an ISO would cause his sales on CD's to go to nothing (Really ? Tell this to RedHat, FreeBSD, NetBSD, etc.) Sorry, with opensource I try before I buy..

    I know it's still not as convenient, but all I did was download the packages directory and base directory for i386, and made my own damn bootable ISO :) Took about 2 hours of downloading, half an hour of burning, and magic. And because it's not for multi-platform like the OpenBSD CDs you buy I have the whole i386 package collection all on one CD. Bleh.

  24. Unbelievably... by gwolf · · Score: 1

    Few products with the word "open" in their names are Free (Stallman's definition) or even Open (Raymond's). OpenBSD is Open and Free.

  25. Re:OpenBSD's history by gwolf · · Score: 1

    Many people in this thread talk about Theo's harsh personality... I have a little doubt:

    Is RMS a nicer person than Theo?

    They both will rage about their positions and will not tolerate any other person's - But they both have done great things for all of us!

  26. Are you smoking crack??? by evilpete · · Score: 1

    A careless developer can make anything insecure whatever flavour OS it's running.

    AFAIK The hotmail problems were backdoors and mistakes written into the server side programming, not the system configuration.

    +++++

    --
    +++++
    The harder you look the less you see. That's what we're up against.
  27. Re:Moderation? by JatTDB · · Score: 1

    What, you want me to put my REAL email address on here? Yeah...right. I've managed to make my life nearly spam-free, and I plan to keep it that way.

    --
    "That's Tron. He fights for the Users."
  28. And windows by DarkMan · · Score: 1

    Windows 98

    Three days without a remote hole in any install!
    Uh, localhost hole?

  29. Re:big deal by NovaX · · Score: 1

    Lier. I found it in less then 30 seconds, and I didn't have to resort to doing a site search. I actually bothered to think.. heck, even less. I looked at the menu on the front page.

    From the faq (http://www.openbsd.com/faq/faq3.html#3.1.2)

    3.1.2 - Does OpenBSD provide an ISO image available for download?

    You can't. The official OpenBSD CD-ROM layout is copyright Theo de Raadt, as an incentive for people to buy the CD set. Note that only the layout is copyrighted, OpenBSD itself is free. Nothing precludes someone else to just grab OpenBSD and make their own CD.


    So basically, you really did pester him because your to lazy to do anything. Why else do you think BSD people get bad reps for not being polite to newbies? Think.

    --

    "Open Source?" - Press any key to continue
  30. Not new by superlame · · Score: 1

    This article didn't have anything new in it, but it was well written I thought, and interesting none the less.

    --
    -- Superlame http://catpro.dragonfire.net/joshua/
  31. Re:all about marketing by divec · · Score: 1

    Further similarity between OpenBSD and Judaism are that neither sets out to maximise it's "market share" and that it's a little difficult for an outsider to get accepted into the community. Linux must be equated to Christianity cos there are many many distros, some of which are almost identical. FreeBSD and Islam are both supposed to be updated versions of something which predates and sparked their "competitors" - although FreeBSD 4.0 is not regarded as "final" in at all the same way as Islam.

    --

    perl -e 'fork||print for split//,"hahahaha"'

  32. Re:OpenBSD's history by divec · · Score: 1
    How can an operating system have a philosophy?

    Never mistake an operating system for the lines of code which comprise its current version. The team developing the code are probably a more important part in the long run.


    Could an operating system have produced something as miraculous as the Holy Bible?

    I think the answer is either "Yes" or "No", depending on whether you believe the Bible to be the word of God or self-contradictory. But this ain't the place for that debate ;-). Anyway, I don't think the original poster was making that claim, he was just making a comparison. A parable if you like. Jesus never said we were actually seeds scattered on the ground. Similarly, the original poster never said that OSes actually were religions.

    --

    perl -e 'fork||print for split//,"hahahaha"'

  33. Re:How do you convince PHB to use BSD? by ptbrown · · Score: 1

    Quite the sticky situation. I've been fortunate enough to deal with many people who understood open source. And I'm male (which could be fortunate or unfortunate depending on how you look at it).

    So are they disregarding you because you're female, or because you use Linux? Maybe we should get OS preference included in non-discrimination laws.

    --
    Any sufficiently advanced civilization is indistinguishable from Gods.
  34. Re:LINUX IS DA BOMB !!!!! by mr · · Score: 1

    >TIMe Join LINUX

    Which Linux?

    Look at redhatisnotlinux.org. This site:
    1) claims to not be an anti-red-hat site.
    2) trying to get the world to see that linux is more than redhat

    Given one of the options is:
    >CompileFarm, for comercial entities to build binary distributions for ALL MAJOR Linux distributions.

    It looks like there is not ONE LINUX to join...but MANY Linuxes to pick from. So which Linux distro do you want us to do free work on?

    >WHy do we have soo many different unix variants.
    Answer this question: Why are there over 150 Linux versions?

    Given all the different distros, and the need for a special compile farm, it looks like Linux is more fragmented than the commerical Unix world ever was.

    --
    If it was said on slashdot, it MUST be true!
  35. Re:BSD is not secure! by mr · · Score: 1

    >At the moment BSD does not have enough support

    Really? I look at the ftp program in NT, Apple's Mac OS X, and even Linux, and find BSD code.

    Looks like plenty of people support the use of BSD in open AND closed source.

    >In a case like this BSD developers should either focus on releasing a better and more secure linux,
    And Linux NEEDS this help based on the money I make fixing Linux boxes that have been broken into. I hope it takes a long time to get around to fixing Linux...I *LIKE* making money off of Linux, and it only helps me install BSD....once these people get sick of Linux and being hit by script kiddies.

    --
    If it was said on slashdot, it MUST be true!
  36. Linux is insecure. by mr · · Score: 1

    According to securityfocus Linux is #2 for most announcements, with NT in the lead.

    Given the number of security announcements for Linux, exactly HOW is BSD less secure?

    Debian 2 2 29 5
    FreeBSD 4 2 18 6
    HP-UX 8 5 7 3
    IRIX 26 13 8 3
    Linux (aggr.) 10 23 84 30
    MacOS 0 1 5 0
    MacOS X Server 0 0 1 0
    NetBSD 1 4 10 3
    OpenBSD 1 2 4 2
    RedHat 5 10 38 17
    Solaris 24 31 34 6
    Windows 3.1x/95/98 1 1 46 11
    Windows NT 4 6 99 34

    --
    If it was said on slashdot, it MUST be true!
  37. Re:Not informative, just misleading. by niekze · · Score: 1

    Look at all the security sites....For example....RootShell.com what do they run? exactly.

    --


    Chaos, Mayhem, and Destruction: Not
  38. Re:How do you convince PHB to use BSD? by niekze · · Score: 1

    I installed OpenBSD over the phone for a friend and then ssh'ed into his box and had NAT setup (including dhcpd) in 15 minutes. All he had to do was plug the 1st nic into the cable modem, and the other into the hub. No need to install X or anything, just keep it small. BTW, I remember playing with RH 6.1 and i told it not to install KDE or GNOME (just use enlightenment duh) and it still installed GNOME. Stupid RH

    --


    Chaos, Mayhem, and Destruction: Not
  39. Re:all about marketing by Motor · · Score: 1

    I am a highly regarded professional marketer,

    -1 Troll. Aww come on. That was one of the funnier posts I've read recently. Miserable bastards - go and read it again.

    --
    We all know that crap is king
    Give us dirty laundry!
  40. Re:Question: Why so many versions ? by Imhmo · · Score: 1

    What is the difference between a version (BSD)
    and a distro (Linux)?

    Where is answerman?

  41. (OT) Your analogy is wrong... by -brazil- · · Score: 1
    ...as are most analogies.

    Who would that "charismatic leader" of chritianity be? Jesus? Islam wasn't even around back then. And Christianity has never eroded Judaism's "user base" not has Islam seriously affected that of Christianity. They all just spread out in different directions.

    Also, AFAIK there are presently more christians than muslims.

    --

    The illegal we do immediately. The unconstitutional takes a little longer.
    --Henry Kissinger

    1. Re:(OT) Your analogy is wrong... by zorba · · Score: 1

      Analogies are just that. Analogies. They cannot be expected to match circumstances exactly, but I think that this one fulfils its purpose admirably- illustrating the situation. You also have beautifully illustrated the situation, by the way, by being a hostile whiner.

      By the way, the "charismatic leader" that is referred to would probably be Emperor Constantine.
      And according to the Encyclopaedia Britannica, Christianity, 34%, Islam 18.4%. However Christianity hasn't expanded (percentage wise) in at least 100 years.
      Now get back on topic.

    2. Re:(OT) Your analogy is wrong... by pipacs · · Score: 1

      Was it a christian almanac or a muslim one?

  42. Re:all about marketing by -brazil- · · Score: 1

    Still, he *is* a troll. And getting lazy, too.

    --

    The illegal we do immediately. The unconstitutional takes a little longer.
    --Henry Kissinger

  43. Re:No Capital ? Partial blame is Theo by Fredbo · · Score: 1

    But what makes "Why is there no iso?" a stupid question?

  44. Re:big deal by SirGeek · · Score: 1
    Consider the first impression you've made: "I don't really feel like looking stuff up, I'll just pester someone else..."

    Umm... If you read my follow up, I stated I DID try and look up the answer.. but at the time when I did a search on the site for "ISO image" nothing showed up.. So I asked..

  45. Re:big deal by SirGeek · · Score: 1
    Lier. I found it in less then 30 seconds

    And.. If you read my OTHER messages.. You would have seen me say that it IS there now.. it wasn't when I originally was interested in the trying OpenBSD.

  46. Re:big deal by SirGeek · · Score: 1
    Do a ftp install then or make your own ISO image, its not that difficult. Show your support to the project by purchasing the cd. So your opinion of an OS is based on the the fact he doesn't like ISO images? Give me a break

    No.. Its NOT that he doesn't like ISO's.. Its the fact that his "logic" is flawed (Supply ISO Image = No CD Sales).. Sorry..

    As for FTP install.. On a 33.6K dialup ? I did it ONCE, only ONCE for a FreeBSD system (Version 2.2.5).. 5 hours to do an install is not what I want to do. (Bringing the computer to my place of employ to install isn't an acceptable option - unauthorized system on the network). I only wanted a CD so I could do the install from home on my own machine and at my own rate.
    Odds are that I would have purchased it (even if I DIDN'T use it, just as a sign of support) had I NOT been annoyed.

    Is it childish ? A little. Tough.. 1st impressions are REALLY important.

  47. Re:all about marketing by zorba · · Score: 1

    Actually, I believe it was a recursive troll. No serious flame contains the word "boobies".An excellent faux-flame response, and you leap into YHBTing.
    YHBRT. HAND. hahahahahahaha!

  48. make your own ISO by ArchieBunker · · Score: 1

    You burn linux and freebsd images, right? Well download the files you need and make your own image.

    --
    Only the State obtains its revenue by coercion. - Murray Rothbard
  49. big deal by ArchieBunker · · Score: 1

    Do a ftp install then or make your own ISO image, its not that difficult. Show your support to the project by purchasing the cd. So your opinion of an OS is based on the the fact he doesn't like ISO images? Give me a break.

    --
    Only the State obtains its revenue by coercion. - Murray Rothbard
    1. Re:big deal by Keith+Maniac · · Score: 1

      Is it childish ? A little. Tough.. 1st impressions are REALLY important.

      You're absolutely right.

      Consider the first impression you've made: "I don't really feel like looking stuff up, I'll just pester someone else..."

  50. Re:How do you convince PHB to use BSD? by luckykaa · · Score: 1

    Simple. Buy the CD. It then costs money, but not as much as another system.

    Make up something about the firewall boxes being more suitable for small businesses with no permanent technical support, (Or if that isn't likely to work, pick a type of company that the one you work for doesn't want to be like).

    You might be able to find some statistics that support your choice as well, but only use this approach if they actually ask for figures.

  51. Christianity HAS eroded the Jewish "user base" by ca1v1n · · Score: 1

    I don't know if you've ever studied European history, like say, in German and Russia, for example, in the first half of the 20th century, for example. Christianity has done to Judaism far worse than MS has ever done to any other OS or application company. The Holocaust and the brutal treatment under the rule of the Czars are just tiny examples of Christians doing evil to Jews. Christianity has gone far beyond mere FUD in its evils. It makes me ashamed at times to be associated with it.

    By the way, his analogy was actually very good. Yes, Jesus was a charismatic leader. Also, as far as Islam not being around at the time, you must have missed the reference to the BSD fork.

    Yes, it's true that most analogies are flawed, but that's because they're meant to approximate the situation in simpler terms. This doesn't make them wrong.

  52. Re:No Capital ? Partial blame is Theo by Keith+Maniac · · Score: 1

    When I got to OpenBSD, Nope.. No ISO. When I asked (in what I believe to be a polite manner) I was told basically to stick it that if I wanted a CD, I had to purchase it becuase creating an ISO would cause his sales on CD's to go to nothing (Really ? Tell this to RedHat, FreeBSD, NetBSD, etc.) Sorry, with opensource I try before I buy..

    I doubt the problem was your level of "politeness". The problem was that you are about the ten-thousandth person to ask "Where's the ISO?" They don't provide ISOs. Even a cursory glance through the mailing list would determine that. It's probably in the FAQ.

    The surest way to piss Theo (and a lot of other people) off is to ask the same question over and over again.

    In short, before anybody complains "Theo was a dick to me!", ask yourself "Did I actually attempt to find the answer myself, or just waste other people's time reasking a FAQ?"

  53. Re:No Capital ? Partial blame is Theo by Keith+Maniac · · Score: 1

    If you went to a company and their spokesperson was rude to you.. Would you EVER use that product ? Would you EVER reccomend that product ?

    Depends on the product. If the product suits your needs, then use it. Salesmen lie to me, and I consider that extremely rude. Theo has a short temper, but he and the other OpenBSD developers make a quality product. In many situations, I use it and recommend it. In others I don't. But his attitude has little to do with his product.

    I doubt Scott McNealy would be much more forgiving if I wandered into his office and said "What's, uh, the deal with this Solaris thing..." At best, he'll point me to a stack glossy literature...

    I still buy shit from Sun.

    Don't tell me his personality isn't a determent to the project. I talked with people who are "in" with Free/Net BSD's.. They said FreeBSD and NetBSD could probably actually merge into a common code base but they also said there is little chance in hell of ever merging with OpenBSD due to "personality conflicts"....

    Determent how? OpenBSD isn't about marketshare, or making money. Their expansion is based on one thing only: "Is our stuff better than theirs?"

    Would one big OpenFreeNetBSDi really be better? Why?

    And I actually DID try and find something about ISO images.. A search of their site (at that time) showed nothing.

    That's good, but there's still a few more places to check before yelling "Help" on the mailing lists. The archives are one of the best, just to make sure no one asked the same thing yesterday.

  54. Re:LINUX IS DA BOMB !!!!! by nomadic · · Score: 1

    So you're saying we should just shut the forks up? :)

    now that was just wrong...

  55. Re:No Capital ? Partial blame is Theo by lcrawford · · Score: 1

    umm, yes, I would, if the product was significantly better than the compititon. That, and i usually refrain from asking stupid questions.

  56. Re:OpenBSD as a firewall by eufaula · · Score: 1

    I have set up 2 OpenBSD firewalls with brconfig (bridging) and ipf. easy easy easy to do. one box is a p100 and the other is a p133, both with 64 meg ram, both b/t router (t1) and first switch on the network, and handle all of that traffic no problemo. Linux supports bridging but its not even close to being robust as the BSD version. Since it uses ipf, it supports a better form of chaining than linux as well.

  57. Re:all about marketing by Deeter · · Score: 1
    Well, my perception of the situation is that no one will be "left in the dust". The free unix user community is increasing in size, and even if it's 90% linux 10% *BSD, the BSD user community is still increasing in size, which means more developers, more opportunities for commercial growth etc.

    Moreover, I think that the market isn't really "getting" about open source yet is that there isn't the proprietary prisoner's dillema that exists in commercial OSes. Developing for Linux does not exclude OpenBSD. Both have their strengths and weaknesses, and because both are open, both can "borrow" the good ideas from each other.

    Also, open OS's promote a "toolbox" view of OS code. Because of the open development, you're not "stuck" using an OS that doesn't really meet your wants because it has one or two proprietary features you need. This means that running several differant OS's is okay, because the open nature makes them interoperable.

    --
    This Sig Intentionally left blank
  58. Re:Reductionist OS, reductionist user ... by unique123 · · Score: 1

    "simplify, simplify, simplify" - thoreau RISC chips, OpenBSD, gnu compiler... now that's tight!

  59. Re:all about marketing by BenjyFeen · · Score: 1
    Let's face it: The differences between Christianity, Judaism, and Islam are essentially related to marketing and distribution. As far as fundamental tenets and conceptual bases go, they're all at least as alike as NetBSD, OpenBSD, and Linux, but Christianity happened to have a charismatic leader at a critical point, and so gained a lot of market share and lots of support from government and industry. Now Islam has the greatest user base, and there are more Linux desktops than Jews in the world, and the reason isn't because of any substantive differences -- it's all about their marketing. Oy vey!

    Let's be clear: anyone who thinks dominance comes from having the best product should go sit on that stack of Betamax video tapes for a while until it sinks in.

    This is a call-to-arms for those looking to get into the game. For all those who complain that they're forever being overlooked: Stand on a fucking chair if you have to, and figure out what it takes to make more people like you and listen to what you say. And if you want to keep screaming and waving that bloody mallet and slavering and dripping gore on the linoleum and hollering "WHY WON'T ANYONE JOIN ME IN MY HOLY MISSION OF TRUTH?!", well, fine. You can go sit with the other cult members. The Christians and Muslims and Jews and Linux users may get criticized for being mainstream, but at least they're friendly and don't make such a mess. And, oh, by the way: they're 90% of your potential market, so you'd best treat them nice. (Me, I'm a Unitarian. We just drink coffee and pontificate.)

    Love,
    Benjy

    www.monkeybagel.com
    ---
    Benjy Feen
    http://www.monkeybagel.com
    ---

    --
    Benjy Feen
    http://www.monkeybagel.com
    ---
  60. Re:all about marketing by t0m+f00l · · Score: 1

    Jesus christ. Can you try staying on topic? OpenBSD to anti-religious fervor. Good job. -- This message would be in caps if it weren't for automated content filters.

  61. Re:all about marketing by t0m+f00l · · Score: 1

    I can cvsup and recompile the OS every couple of hours if I want.

  62. Re:all about marketing by t0m+f00l · · Score: 1

    CONGRATS. You have just been trolled. Have a bagel; you can slide it off my humungous shlong.

  63. Re:j00 4r3 4 phukk1n l4m3r, by krystal_blade · · Score: 1

    >> n0w 5hut th3 phukk up b3f0r3 1 k1ck j00r 455, f4gg0t. > What's scary is that I'm getting to where I can actually read this stuff as a stream, rather than having to decypher it one character at a time. Maybe I'm ready to tackle perl now. What's exceptionally scary about all of this is if you add all the numbers in that phrase together, (count 0's as tens) they come up to more than double the original posters I.Q. And they say monkeys can't do math well...

    --
    It will be easy to motivate our fellow man; there is hardly anything people treasure more than not being annihilated.
  64. Re:IT management, stress, and OpenBSD by Seraphin · · Score: 1

    ha ha
    80% of small businesses don't need SMP and can afford to make sure they don't pick unsupported hardware.
    Tell me about commercial support with linux...
    Apps used have (like samba) have the same support as with linux, as it is simply the same.
    Your point [d] betrays you as just an ideologic opensource hater and nothing else. Point [e] shows you're clueless. OpenBSD runs linux and Solaris binaries...

    You think that I propose OpenBSD as a valid alternative for anything and everything? You should learn to read!

  65. IT management, stress, and OpenBSD by Seraphin · · Score: 1
    There is one thing in which OpenBSD has the edge over EVERY other OS's in the world: the stress factor.
    I'm rookie, ok. Most of all, I'm availability conscious and rather the anxious type. I guess I'm not alone.
    Three days ago I gave OpenBSD a try. This OS is straight Unix. Configuration may be painfull at some stage, like disklabel creation. I guess more awaits me. I compiled Samba in, which is not audited and may suffer exploits and flaws. I'll certainly add other similar software in the future.
    Why bother then, some will argue?
    That's what is impressive with OpenBSD: network exploits, security holes, can only result of MY wrong doing. To my surprise, the thought is surprisingly conforting.
    The thing is, I know I may be adding vulnerabilities which each service I add, but as I add services, I can read the related doc, learning IN TIME about the security issue, and learn AT THE SAME TIME what countermeasure I have to take.
    I've added Samba, my next move is set the firewall accordingly.

    The relief is so great that the unix "unfriendliness" of the systems appears light in comparison: being carefull is feasible and will be fully rewarded.

    In summary:
    The stress factor is all important but often neglected, especially in business. But the hidden costs inccured are probably high. OpenBSD may help reduce these costs, as it gives the following adventages:

    • Less time spend closing hole(!), following bugtrack, upgrading faulty software, etc.
    • You spend more time setting up your server, but as a reward you get increased preemptive security, strong knowledge of your system and by derivation, a stronger ability to deal quickly and efficiently with incidents.
    • You are more confident, less subject to stress, so you think better.
    • Everything you learn is standard stuff, which will be usefull everywhere you go. Conversely, you stop cloggering your brain with lists of distribution dependent problems, exploits, holes...
    • You have more time to develop your system and educate users.
    • Your boss can boast to his peer (and competitors) when they go offline while he doesn't. That's what you want, right?
    • You live longer.


    More infos:
    - BSD Today: A step-by-step journal of installing OpenBSD
    - www.openbsd.org
    - OpenBSD Explained

    enjoy!

    Raph
  66. Re:OpenBSD owns by Anonymous Coward · · Score: 2

    I really don't think this is accurate; I know there were a number of local exploits in the past 6 months that affected all BSDs, including OpenBSD.

    most recent exploit: tricky procfs hole. of course, openbsd doesn't mount procfs by default.

    Now, this might just be a matter of hair-splitting; perhaps OpenBSD doesn't install any of the vulnerable BSD utils by default.

    that is correct.

    If that's the case, it's not a fair comparison, since RedHat has a number of different installation levels available.

    of course it's a fair comparison. the openbsd developers carefully check over all pieces of the operating system before including them by default. it's a measure that other vendors do not take. you may think that redhat provides a secure installation level, but do you really think that they read every piece of the linux kernel source, hunting for bugs? or even the small important utilities. this is where openbsd pulls ahead.

  67. Re:OpenBSD owns by Brian+Knotts · · Score: 2
    Two years without a localhost hole in the default install!

    I really don't think this is accurate; I know there were a number of local exploits in the past 6 months that affected all BSDs, including OpenBSD.

    Now, this might just be a matter of hair-splitting; perhaps OpenBSD doesn't install any of the vulnerable BSD utils by default.

    If that's the case, it's not a fair comparison, since RedHat has a number of different installation levels available.

    That said, I'd like to see things like LIDS incorporated into the Linux kernel, available for all to use. That would go a long way towards helping make Linux distributions more secure, if they'd at least turn on some of the openwall stuff (which has supposedly been incorporated into LIDS).

    --

  68. simple, show him what they really are. by pixel+fairy · · Score: 2
    many good little firewall boxes are usually bsd (or linux) based machines that cant be configured as much.


    Network Flight Recorder is one such device(not a firewall of course) that cant be configured at all. the openbsd box you want to install is the real deal and they have you there to make it do whatever is needed. i have yet to see a "real" router ping for lowest latency on different lines to determin which one to use for example. but a little perl on a bsd box did that trick nicely.


    you can also show them the messages from bugtraq, (a security vunerablilty / exploit mailing list if your not already on it) where sometimes, firewalls and little boxes come up. openbsd does not. almost any security site can help here. rootshell is another quick easy one.


    if they keep ignoring you, with your skills, maybe you should work elsewhere or just go to work take advantage of the free time and pay check your getting anyway.

    1. Re:simple, show him what they really are. by tweek · · Score: 2

      errr unless I'm mistaken (and I could be as the heat in India has fried my brain at this point) but isn't that what OSPF,BGP,EIGRP et al are for? The only problem with those is that you have to cooperate with your provider to set that up.

      --
      "Fighting the underpants gnomes since 1998!" "Bruce Schneier knows the state of schroedinger's cat"
  69. Re:Users should be assumed hostile by Frater+219 · · Score: 2
    The system must not accept foolishly easy passwords; it must enforce mixed-case with special characters.
    ... thereby causing the majority of newbies to keep their passwords written on Post-It Notes on their monitors, or else on index cards in their desk drawers. Especially if said newbies are secretaries, librarians, or Deans.
  70. Re:How do you convince PHB to use BSD? by Nathaniel · · Score: 2
    "I mean, you morons hired me to handle your technology, why oh why won't you listen?"

    Good question. Let them know that they are not letting you do your job. Let them know that they should either let you do the job, or expect you to find a different job, one where you get both responsibilities and the authority to make things happen.

    Alternatively, tell them how you're going to solve the problem, solve the problem that way, then tell them you've solved the problem.

    If it's a matter of not having an extra box to build a firewall with, pick up a used box yourself, or claim the old machine next time someone upgrades their desktop.

  71. Re:all about marketing by stripes · · Score: 2
    The Linux kernel isn't being developed for RedHat, or Caldera, or whatever.

    There are lots of people doing work on Linux for free. Some of that work is even off in userland where it will help some or all of the BSDs as well.

    There are people employed by Red Hat (and I expect others) that are payed to work on Red Hat. The folks that work for Red Hat Labs for example.

    Are there fewer BSD developers because of Linux, then?

    Sure. But Linux has done the work to get them. It's users were more excited. More intrested in recuriting others. More willing to try a new devlopment model. More willing to try a new bisness model. More willing to risk the goose that gave them their golden egg.

    So I dont get it. Yeah, Linux gets more press. But who the hell is doing Linux development for the press? And when did lack of press make a difference to bedroom coders?

    People doing it for the ego boost would be somewhat more intrested in who has the larger user base. People intrested in doing coding on an OS they can sell the boss may go for the one that has recieved more press. People tired of Windows coding may see the alternitave covered in the press and go for it.

    So, yeah, the press helps. And some people who use BSD are jelious of Linux's success. Some people who use BSD are delighted by Linuxes success. Some people who use BSD are happy to see BSD get a bit more press too. Some people who use BSD would rather keep it's eletest nature and not see so much press. I'm all of the above, in diffrent mesures as the days pass.

  72. Re:BSD is not secure! by LizardKing · · Score: 2

    But you've got to admit that the majority of Slashdot posters come across as clueless teenagers looking for a flamefest. I applaud the moderators for moderating that particular post down, as its author was clearly in the dark when it comes to the development of BSD and operating systems in general.

    As noted on the OpenBSD pages, there are a similar number of developers working on the core of OpenBSD as there are for Linux. Put simply, there just aren't that many coders out there who have the skills to work on a task like operating system development. Likewise, there is a threshold to how much of a large piece of software an individual can understand in its entirety. The Alan Cox's and Theo's of this world are pretty few and far between, but contrarily there are enough to sustain the development of Linux and the free BSD's.

    As for the original posters claim that developers should focus on Linux because it has a wider installed base than say FreeBSD, is to misunderstand the design goals of Linux. While OpenBSD concentrates on being stable and secure, while perhaps not state of the art, Linux aims to support as many peripherals as possible. This leads to experimental code in the kernel source tree, but a bigger chance that it will work on the latest hardware.

    Linux and OpenBSD have greatly differing design goals, and the original posters ignorance of them rightly deserved his post's critical moderation.

    Chris Wareham

  73. Re:BSD is not secure! by LizardKing · · Score: 2

    because he is ignorant to the facts his post should be moderated down and ignored right?

    When it comes across as flamebait, then yes.

    He or she obviously didn't even take the time to read the article which Slashdot was linking too, or else the nature of OpenBSD would have been apparent.

    It all comes down to whether you want Slashdot to descend into a morass of 'Frequently Asked Questions' (or frequently stated misconceptions as is more often the case). Personally I'd like a slightly more informed level of discourse on Slashdot - not the inane drivel I have to contend with on Usenet.

    At the same time the balance has to be right. I'd hate to see the level of pedantry and nit-picking that permeates comp.lang.c ... but this moderation struck me as spot on. The original poster didn't couch their message in terms of a question, but more like a blunt statement.


    Chris Wareham

  74. Re:Not informative, just misleading. by LizardKing · · Score: 2

    Hmmm, you obviously misread the intention of my post. You also used a rather poor analogy.

    Racecars don't have CD players. I can't make my car into a racecar by yanking out my CD player

    Bad analogy because I can strip down Linux and make a secure server. It may not be as reassuringly secure as OpenBSD, but given the disproportionate number of security holes in applications (as opposed to the kernel) then I'm content. The real analogy is to compare a rally car to a roadgoing version of the same model. The rally car has been finely honed for performance in much the same way OpenBSD is tweaked for security. The roadgoing version offers more features, but you may not need that added functionality. To carry the analogy to an extreme, OpenBSD is like making the rally car available to me - but I have to accept the possible limitations in functionality.

    By stating that a Linux user should strip down their install if they wish to be security conscious, I wasn't implying that they should give OpenBSD a miss. In fact, the main reason I stick with Linux is because I have considerably more experience with it than with OpenBSD. As I came from a SVR4 rather than BSD background that may be the reason why, (I find I have to 'relearn' things occasionally on BSD systems, while most Linux distros strike me as more SysV-ish).

    THe install base of Linux compared to OpenBSD does offer up the possibility that bugs are more quickly found in the former. However I find greater reassurance in OpenBSD's code audit than the possibility that bugs are reporte more readily for Linux systems. In this I assume you are in agreement.

    Chris Wareham

  75. Re:all about marketing by LizardKing · · Score: 2

    Some people who use BSD are delighted by Linuxes success

    An interesting point of view is the one I came across in a book on building firewalls with Linux and OpenBSD. Some in the BSD community look upon Linux with its bigger install base as an ideal testing ground for new software. This camp positively encourages development targeted at Linux at first, with the possibility of porting across to the BSD systems at a later date.

    There is a certain amount of the snobbery evident in this view. They see the Linux userbase as more tolerant of buggy software, with the obvious implication that the whole system is buggier. This is redolent of the complacency in the BSD community with regard to how their operating systems are perceived. Many potential users are put off by the condescending attitude that is more prevalent in BSD circles than in Linux ones.

    This attitude certainly put me off of using FreeBSD, especially as I found it a poor desktop system in comparison to the typical Linux distro. Thankfully, this seems to be changing as a number of people migrate to dual booting a BSD operating system alongside Linux, or switching altogether.

    Chris Wareham

  76. Re:How do you convince PHB to use BSD? by cymen · · Score: 2

    Perhaps it is time for the temporary-permanent OpenBSD box? Set it up for the "time being" and soon weeds will be growing up around the edges. Of course I'm in a slightly less PHB place so this might not be an option - but you could try it!

  77. Users should be assumed hostile by korpiq · · Score: 2


    If is passworded, the developer can do nothing about the user making their password their boyfriend's nickname, or putting it on a post-it note on their monitor.

    The system must not accept foolishly easy passwords; it must enforce mixed-case with special characters.

    There will always be first-time users, as well as human mistakes, and hot-headed if not straightforward evil intentions.

    I'm all for educating users, but it can not be the sole basis of security, can it?

    On the other hand, scaring lusers with love viruses is a great way to teach them about secure system. Or rather, less flawed ones.

    --

    I think, therefore thoughts exist. Ego is just an impression.
  78. passwords written on Post-It Notes by korpiq · · Score: 2


    Quite right indeed :) I should read what I answer to, perhaps?

    Then again, that is exactly the reason why you have to assume that the average user is hostile. User itself might not be, but those who see the password might be.

    Anyway, forcing it to be near random noise makes it less easy to be guessed without seeing that note.

    Post-It's should come with self-destruction enabled in case they get a password-resembling string written on them!

    --

    I think, therefore thoughts exist. Ego is just an impression.
  79. Minimalist is good by F2F · · Score: 2

    Just to add my "me too" post:

    Yes, minimalist is good when you want to get the job done.

    I couldn't be happier with openbsd at work -- it handles firewalling for the part of the network that needs to be hidden, it handles NAT for the windows boxen of the developers, it has 69 aliases on the external nic which handle web pages by portforwarding.. and all of this from a spiffy 486/66 box with 8 megs of ram...

    I can safely say that little or no other unixen can do that without desperately needing beefier hardware.

    Oh, and yes -- once configured as a silent firewall it could just be left there, without me having sleepless nights wandering when the new security hole will occur...

    And to top that off, you can almost daily find Theo in #openbsd @efnet and he *will* answer your questions, provided they are not extremely stupid (mine are sometimes :)...

    So, if you ever need a secure, silent workhorse that needs little or no tweaking to get working -- use openbsd :)

    flame on... :)

  80. OpenBSD as a firewall by zCyl · · Score: 2

    Does OpenBSD support a firewall that has a chainlike structure like linux's ipchains? People say that OpenBSD is more secure for a firewall, which I would gladly accept, but what I want to know is if you have a really complicated firewall setup, can OpenBSD keep up because it has a logarithm chainlike design, or is it a linear packet-matching design like other firewalls? I only ask because some commercial quality firewalls (including the pre-boxed ones) can get extremely poor performance when you start passing large amounts of traffic through a firewall with a large number of settings.

    Can someone familiar with OpenBSD internals provide an answer to this?

    1. Re:OpenBSD as a firewall by DoXaVG · · Score: 2

      OpenBSD utilizes IP Filter by Darren Reed. Home page: http://coombs.anu.edu.au/~avalon/ Read that for more details, the short is that yes, it supports rule chaining and IMHO is MUCH more powerful than IP Chains on linux. IP NAT (Masquerade) under linux is more developed however, so alot depends on what you're trying to do. From experience, the home user will be more suited to IP Chains (linux) than IP Filter (*BSD, Solaris, HP/UX...etc)

  81. Counter-Flame by extrasolar · · Score: 2

    Fuck off, Bastard.

  82. Re:Moderation? by JatTDB · · Score: 2

    WHY must there be so many different distributions of Linux?

    WHY are there so many SVR4 variants?

    Us UNIX geeks like to have variety, I suppose. Maybe it's not always in the best interests of solidarity and progress, but having the choices there is a nice feeling.

    --
    "That's Tron. He fights for the Users."
  83. Re:More of Less! by Cuthalion · · Score: 2

    Only if the software has no easily exploitable bugs is the uneducated user the primary flaw in security.

    It's not people leaving their passwords on Post-it (TM) notes that allows people to hack hundreds or thousands of boxes to do a DDOS attack with.

    --
    Trees can't go dancing
    So do them a big favor
    Pretend dancing stinks!
  84. blah by chriscappuccio · · Score: 2

    This article says "OpenBSD population 7000"

    7000 is an accurate number of CDs sold for OpenBSD 2.6, but not total!!!

  85. Re:More of Less! by WhyteRabbyt · · Score: 2

    Luser unsecurity hype is mostly unnecessary; software developers need to be more conscious.

    Bollocks. If is passworded, the developer can do nothing about the user making their password their boyfriend's nickname, or putting it on a post-it note on their monitor.

    The uneducated user is the primary flaw in security.

    Pax,

    White Rabbit +++ Divide by Cucumber Error ++

    --
    free experimental electronic music netlabel at www.viablehybrid.com
  86. Re:LINUX IS DA BOMB !!!!! by WhyteRabbyt · · Score: 2

    WHy do we have soo many different unix variants. Its time we got all the people stop wasting their time with so many different unices. Time to UNITE. TIMe Join LINUX...... Be a penguin or sit on a Window }:) UTS MOooooooS !

    So you're saying we should just shut the forks up? :)


    Pax,

    White Rabbit +++ Divide by Cucumber Error ++

    --
    free experimental electronic music netlabel at www.viablehybrid.com
  87. Re:How do you convince PHB to use BSD? by Rand+Race · · Score: 2
    Been there. I lobbied hard for an OpenBSD box for our firewall, but the PHB decided on a SonicWall. It was easy to setup and it seems to be working - Turned back a sub-seven the day after installation - , but I've sectioned off the accounting dept (Which unlike the rest of the network runs NT instead of MacOS and would have been vulnerable to the sub7) with an old Quadra running an OpenBSD firewall. So when and if we do get cracked I can point to the BSD box and say "They didn't get to accounting and if you dumbasses had listened to me they wouldn't have gotten in at all!". But in a little nicer way of course.

    --
    Insanity is the last line of defence for the master diplomat. But you have to lay the groundwork early.
  88. No Capital ? Partial blame is Theo by SirGeek · · Score: 2
    As it has been said dozens of times before, Theo is a good software developer. However his people skills are, well.. lets just say they are less than desirable for a spokes person.

    If Open BSD wants venture capitalists, they should get someone OTHER Theo to talk to them. He can have an attitude (as an example, think about things like the OpenSSH.ORG/COM Issue). If you take both sides statements with a grain of salt, It seems like the owner of OpenSSH.ORG was WILLING to make a deal (if OpenBSD/SSH would just add some links to OTHER open source security projects). But Theo copped a 'tude and sicked SlashDot on the owner of the OpenSSH.ORG domain (not a good PR thing).

    As an aside (and a vent) they (read Theo) aren't not listening to the community. The other BSD's (Free and Net) both are now releasing ISO images to download. When I wanted to do some comparisons of Free/Net/Open BSD's, I wanted to download the ISO's and burn CD's (at work, since at home I only had a 33.6K dial up). For Net and Free BSD's this was not a problem. When I got to OpenBSD, Nope.. No ISO. When I asked (in what I believe to be a polite manner) I was told basically to stick it that if I wanted a CD, I had to purchase it becuase creating an ISO would cause his sales on CD's to go to nothing (Really ? Tell this to RedHat, FreeBSD, NetBSD, etc.) Sorry, with opensource I try before I buy..

    Not good to annoy someone who helps plan server deployment at their company (and for their own company). So.. No OPEN BSD.. No Purchases (since I DO purchase open source software and CD's.. I have been buying FreeBSD since 2.2.5 and have 4 different Linux Distro's too).

    1. Re:No Capital ? Partial blame is Theo by SirGeek · · Score: 2
      In short, before anybody complains "Theo was a dick to me!", ask yourself "Did I actually attempt to find the answer myself, or just waste other people's time reasking a FAQ?" If you went to a company and their spokesperson was rude to you.. Would you EVER use that product ? Would you EVER reccomend that product ? I doubt it.. I know I wouldn't. That's GOT to hurt a company.. I know that I will probably NEVER use And I actually DID try and find something about ISO images.. A search of their site (at that time) showed nothing.

      All it would have taken is a page on their FAQ saying WHY they don't do ISO's (not that I think it is valid) would have made it simpler.

      NOTE: It is in the FAQ now...

      And I bet partial reason for NOT wanting VC's is because they KNOW due to personality conflicts the VC's would get pissed, leave and spread the word to not deal with these people..

      Don't tell me his personality isn't a determent to the project. I talked with people who are "in" with Free/Net BSD's.. They said FreeBSD and NetBSD could probably actually merge into a common code base but they also said there is little chance in hell of ever merging with OpenBSD due to "personality conflicts"....

    2. Re:No Capital ? Partial blame is Theo by SirGeek · · Score: 3
      Depends on the product. If the product suits your needs, then use it. Salesmen lie to me, and I consider that extremely rude. Theo has a short temper, but he and the other OpenBSD developers make a quality product. In many situations, I use it and recommend it. In others I don't. But his attitude has little to do with his product.

      But does the Salesman belittle you or tell you you are stupid if you don't buy the product ? I have HAD this happen at Best Buy (salestwit refused to ring up a $ 500 order because I didn't want a $ 40 extended service plan).

      No.. Theo's attitude doesn't affect the product.. It DOES affect perception of the company/project. If you go into a store to make a purchase and the manager tells you that you don't know anything, you will leave and not make any purchases there. Same would apply if the manager was calling someone else stupid or being rude.

      Perception is reality. If people perceve Theo to act childish, they in turn will have a bad perception of the project. I can understand the annoyance of an FAQ question, I try to NEVER ask an FAQ question. But it happens, sometimes the documentation is obscure or not 100 % clear, is it my fault if I can't totally understand something?

      Also the old addage of "you catch more flies with honey than you do vinigar" also applies (and don't remind me that "if you pull their wings off they'll eat whatever you give them" as that doesn't apply here *g*). If he doesn't "work and play well with others", Let him stick with what he is good at (software development). Let someone else with better people skills deal with the PR side of things.

  89. Minimalism by Animats · · Score: 2

    The thought of BSD, any version, as "minimalist" is pushing it. But compared to the shovelware that's sold as operating systems today, I suppose it makes sense. Still, compare QNX.

  90. Re:all about marketing by BenjyFeen · · Score: 2
    Lessee... where to start.

    "I'm quite tech-savvy". Understand that when someone says something like this, it's like a girl saying "I have gigantic boobies": not only is it faintly goofy-sounding, but the information being imparted will either be obvious to the observer or clearly untrue. In neither case is it an advantage to make the statement, and it can only hurt you if the observer disagrees.

    And since you call yourself an NT and VB \"guru\", and you're talking about UNIX, that makes you an A-cup girl in a prom dress, and let me tell you, honey, no amount of Kleenex is gonna help.

    I was going to argue some technical points, but I need another beer. Hang on.
    ---
    Benjy Feen
    http://www.monkeybagel.com
    ---

    --
    Benjy Feen
    http://www.monkeybagel.com
    ---
  91. only 7,000 OpenBSD users???? by Anonymous Coward · · Score: 3

    Hmm, no mention that 98% of OpenBSD users have downloaded the Os, or did a FTP install. (which works very nice) I think they could have mentioned that somewhere. I place that number MUCH higher than 7,000.

  92. Re:all about marketing by Anonymous Coward · · Score: 3
    For once a Slashdot poster makes sense.
    I am a highly regarded professional marketer, concentrating on the "tech-savvy" demographic. It has been proven time and time again, that there are 2 things that will get people to buy.

    1) sex

    2) fear

    Anyone with experience of the open source community (bearded, sandal wearing, grateful dead listening, socialistic, eliter-than-thou socipaths) will realise that sex is noth something they will understand in any meaningful way. Hence the marketing strategy must be all about FEAR. (or at the more 31337 would say P|-|334R.

    For BSD (Open, Net, Free, Whatever, they're all the same) to become popular and reach the dizzy heights that RedHat has achieved, it needs to change the marketing strategy.

    If I were in charge, I would instigate a Monthly release cycle. This way, the comfort and satisfaction a nerd gets from being "up to date" would be a short lived thing, and he would be constantly needing to upgrade to stay current. Even a moron can see the revenue streams here.

    Also, I would try and get the marketing story a bit more coherent. I mean, what DIFFERENTIATES *BSD from all its competitors (Linux, BeOs, Solaris) etc.

    I'm quite tech-savvy, being an NT and VB "guru" but I don't know operating systems. However the experts I've spoken with are clear, Free/Open/Net Bsd needs DirectX and XML support in the kernal, in order to compete with Windows, on a feature by feature comparision.

    I realise now that slashdot readers do not care for my insightful observations, however I continue to post them, as I personally am conviced of my expertise, and do not require it to be validated by a bunch of whining 16-year old Korn-listening skript kiddies, hell bent on destroying the music industry with their illegal "napster" protocols.

  93. Not informative, just misleading. by LizardKing · · Score: 3

    RedHat Linux has more security advisories, but that's a consequence of including so much software as part of the standard distribution. They also include lots of beta and recently developed code. OpenBSD in comparison only uses carefully audited code and older, well tried applications. The downside to the OpenBSD approach is that you only get a small set of tools with the standard disribution.

    So you should pick what you need from your Linux distribution, and don't install anything else. Or install OpenBSD if you want to. Just remember that a lot of free software is currently written with Linux as its primary target, so you may need to tweak it to get it going on OpenBSD.

    Comparing RedHat Linux to OpenBSD simply on the basis of how often security flaws are found in the entire distribution is misleading.

    (disclaimer: I happily use both RedHat Linux and OpenBSD, so I know the strengths and weaknesses of both)

    Chris Wareham

    1. Re:Not informative, just misleading. by stripes · · Score: 5
      So you should pick what you need from your Linux distribution, and don't install anything else. Or install OpenBSD if you want to. Just remember that a lot of free software is currently written with Linux as its primary target, so you may need to tweak it to get it going on OpenBSD.

      Now you have the misleading comparisin.

      The stripped down Linux will be just as sparse of features as OpenBSD (or more so if you do your job right). But who audited all that code for security holes? Who went over that code looking for buffer overuns? Who went back over that code looking for mis-uses of strncat?

      OpenBSD isn't secure because they don't ship much stuff. It is secure because they only ship stuff they have secured. That ends up being not much stuff because it is hard to secure things.

      Racecars don't have CD players. I can't make my car into a racecar by yanking out my CD player.

      Comparing RedHat Linux to OpenBSD simply on the basis of how often security flaws are found in the entire distribution is misleading.

      That I'll give you. RedHat has more users, and may be a more intresting target, so it may show more flaws. Except OpenBSD has made itself an extreamly tempting target by going "undefieted" so long, and being the chokepoint into more and more networks.

      Still looking at the raw numbers is not as cut and dried as it looks.

      disclaimer: I happily use both RedHat Linux and OpenBSD, so I know the strengths and weaknesses of both)

      Apparently not. Then again we all make mistakes.

  94. More of Less! by korpiq · · Score: 3
    Why We're Doomed to Failure, linked to from # (mandatory for roots?) discusses this as well.

    This is what I have been saying for a while now.

    There is a strong, growing need of
    • Moving all networked computers off Windows (will viruses eventually do this job?)
    • Securing all (restricted) networks with Open SSH
    • Developing/studying systems that can be proved secure (buffer overflow wrapper where?)
    • Packaging all software in a safe default installation.


    Luser unsecurity hype is mostly unnecessary; software developers need to be more conscious.

    @input = map {
    /^(\w+)$/ and $key=$1 and
    $cgi->param($key) =~ /^([\w\xA1-\xFF]*)$/ and
    ( $key, $1 );
    } $cgi->param(),
    --

    I think, therefore thoughts exist. Ego is just an impression.
  95. Re:j00 4r3 4 phukk1n l4m3r, by Black+Parrot · · Score: 3

    > n0w 5hut th3 phukk up b3f0r3 1 k1ck j00r 455, f4gg0t.

    What's scary is that I'm getting to where I can actually read this stuff as a stream, rather than having to decypher it one character at a time.

    Maybe I'm ready to tackle perl now.

    --

    --
    Sheesh, evil *and* a jerk. -- Jade
  96. plug the server... by DreamerFi · · Score: 3

    Then perhaps, although probably not, if he's a PHB, pointing him to GNATbox and/or www.dubbele.com will help - these are the 'plug it in' boxes he talks about, and they use BSD variants..

  97. all about marketing by ptbrown · · Score: 3

    Of course, it's because RedHat began treating Linux as a traditional product that must be "released" that has made it the investor's baby of open source. Free/NetBSD have been around longer than Linux, but they didn't get the attention because they're more concerned with refining the code than writing press releases and speaking at conferences.

    But then, it seems that a few BSD folks, like Theo, are doing the publicity thing; perhaps to try to avoid being left in the populist dust of Linux. I just hope it doesn't adversely affect the quality of the software.

    Not that Linux hasn't done wonders and that the high profile distros are doing anything "bad", of course. But I'd hate to see BSD suffer because everyone instantly associates open-source with Linux; and further associating Linux with Red Hat. I don't want to lose options because they're not as popular.

    --
    Any sufficiently advanced civilization is indistinguishable from Gods.
    1. Re:all about marketing by WhyteRabbyt · · Score: 5

      To be honest, I dont see how BSD would 'suffer because everyone instantly associates open-source with Linux'.

      I just dont understand that context of 'suffer'. The various flavours of BSD are being developed, much as the Linux kernel, without commercial or other constraints. The Linux kernel isn't being developed for RedHat, or Caldera, or whatever. Its being developed as a communal project, by people scratching a communal itch. And the developers of the BSDs are doing the same thing.

      Are there fewer BSD developers because of Linux, then? Maybe, although I'd reckon that there a lot more than there were (say) three years ago. Plus Linux apps tend to be fairly straightforward to get running on BSD systems, so its not as though all that Linux development gives Linux some kind of edge.

      So I dont get it. Yeah, Linux gets more press. But who the hell is doing Linux development for the press? And when did lack of press make a difference to bedroom coders?

      Pax,

      White Rabbit +++ Divide by Cucumber Error ++

      --
      free experimental electronic music netlabel at www.viablehybrid.com
  98. OpenBSD owns by niekze · · Score: 3

    OpenBSD:

    Three years without a remote hole in the default install!
    Two years without a localhost hole in the default install!

    RedHat:

    Three weeks without a remote hole in the default install!
    Two weeks without a localhost hole in the default install!

    Thats all im going to say.

    --


    Chaos, Mayhem, and Destruction: Not
  99. Reductionist OS, reductionist user ... by Anonymous Coward · · Score: 4

    The reductionist philosophy of OpenBSD has rubbed off on me as well. My dual boot machine contains RedHat Linux on one drive, and OpenBSD on the other. The Linux install is stripped down by most peoples standards, but includes all sorts of bells and whistles like GNOME, AbiWord, Mozilla, etc. all fastiduously kept uptodate with latest versions.

    Meanwhile, my OpenBSD install has the bare minimum - Blackbox WM, NEdit, DDD, Gimp and Communicator. The KISS philosophy that permeates OpenBSD really is infectious. The sparsity of a new OpenBSD install belies the extreme care that goes into what is there. The man pages are upto date and accurate, the tools are rock solid.

    I really, really recommend looking into OpenBSD for development boxes as well as it's usual server niche. My productivity has increased since the switch from Linux, as I get les of an urge to spend time compiling pre-release kernels and the latest GNOME tarballs. Instead I do that at home (hmmm, maybe I need to get out more ...).

  100. Regular release = faster package upgrading by joneshenry · · Score: 4

    I disagree with the interpretation of the UpsideToday article's "Like craft brewers, de Raadt and the OpenBSD development team prefer to let the software age a little, offering only two updates per year."

    Two updates per year at fairly predictable times is quite fast for operating systems. Also this contrasts with the philosophy of no guarantees whatsoever about when releases will be made, a philosophy that I believe has been demonstrated to result in the longest aged software, for no good reason.

    Looking at OpenBSD's current changelog, they are at least testing almost all of the important recently released software such as GCC's and Perl's.

    I think UpsideToday has it 180 degrees backwards. OpenBSD's fairly regular releases means that users will get inspected and verified packages faster than if they used another operating system where there is no set schedule. I think OpenBSD simply has better management in this respect because they have a disciplined schedule. They're releasing and updating at the fastest rate possible.

  101. Re:OpenBSD's history by JatTDB · · Score: 4

    I use OpenBSD not because I necessarily like or agree with everything Theo has done that may be controversial over the years. I use OpenBSD because, all things considered, it's a damn good OS. The developers work hard with a primary goal of producing the best code, not just code-that-works-and-supports-latest-doohickey.

    As I said in a previous OpenBSD thread, I don't care if the project lead eats children for breakfast and pushes old people out of wheelchairs for fun; if it works and I like it, I'll damn well use it.

    --
    "That's Tron. He fights for the Users."
  102. How do you convince PHB to use BSD? by Staciebeth · · Score: 4

    I've emailed the story link to my PHB, who asked me to recommend what to use for a firewall. I wrote a report that concluded OpenBSD -- it's free, an it's good. Now he keeps asking me about various little "firewall" boxes where you plug the server into one end and the internet into the other and hope for the best. Any ideas of how to explain "You would pay more money for a less good thing"?

    They've already tagged me as "that wierd linux girl" so every non-microsoft solution I suggest gets nodded at and then pretty much ignored. I mean, you morons hired me to handle your technology, why oh why won't you listen?

    Aarrrgh

  103. Tired of people whining about OpenBSD CDROM Images by Anonymous Coward · · Score: 5

    People always whine about OpenBSD not having official ISO images available online. Think about it: If you are on a slow modem connection to the Internet, would you rather download a 650MB ISO image, or a custom created 100MB image that's exactly what you need? I thought so...Here's how to do it:

    If you read the mkisofs man page, it's only a matter of setting up 2 options, one to point to the floppy disk image that you are going to boot from (for OpenBSD they are labeled *.fs, use cdrom26.fs for a CD) and then specify a _location_ destination for the boot.catalog.

    So just set up the mkisofs like you would for any other CD, then use -b cdrom.fs and -c boot.catalog and you'll be fine. (the *.fs file path is relative to the other files). It couldn't be simpler.

    Here's an example:

    mkisofs -b cdrom26.fs -c boot.catalog -L -R -o openbsd.iso /path/to/openbsd/distribution/files

    and cdrom26.fs is presumed to be at /path/to/openbsd/distribution/files/cdrom26.fs. (and yes there are other options, read the man page: http://www.openbsd.org's man page of mkisofs

    If people would quit complaining, they'd realize that it's BETTER this way, as you can create customized cdroms. I make -current CDROMs for x86 and put every package and licensed file on there. It's great...

    Oh and here's how you burn it:

    cdrecord -v speed=4 dev=/dev/cd0c driver=mmc_cdr openbsd.iso

    The cdrecord options are for either ATAPI or SCSI since we unified the driver in 2.6.

    Give 2.7 a try, it's wonderful!! And DO buy the CDROMs, they help the project in so many ways...

  104. Question: Why so many versions ? by Anonymous Coward · · Score: 5
    I have a serious question, why are there so many versions of BSD, NetBSD, FreeBSD, OpenBSD, BSDI, LameBSD, SecureBSD, WinBSD, etc etc

    Linux AFAIK only has one version, RedHat (although other version known as "distros" exist, they are not 100% Official, like RedHat is.

    The confusion about which BSD is the true "100% Official" BSD must be losing them users.

    RedHat's 100% official RedHat site is at RedHat