Slashdot Mirror


OpenBSD's PF Developers Interview

An anonymous reader writes "ONLamp.com has published a very long interview with 6 OpenBSD's PF developers: Cedric Berger (cedric@), Can Erkin Acar (canacar@), Daniel Hartmeier (dharmei@), Henning Brauer (henning@), Mike Frantzen (frantzen@) and Ryan McBride (mcbride@). Start reading from the first half and continue with the second part."

110 comments

  1. Interview... BSD style by Anonymous Coward · · Score: 5, Funny

    Aside from the fact that netcraft said that all these people are dead, there is one thing that bugs me about this interview.

    Just like BSD, its all done in parallel!

    1. Re:Interview... BSD style by Anonymous Coward · · Score: -1, Offtopic

      yes they are dead. but rose from the dead with great power. it's harder to kill the undead. so beware! awoooooooo!

  2. PF ? by Aliencow · · Score: -1, Offtopic

    Post First ?

  3. OpenBSD? by Anonymous Coward · · Score: -1, Troll
  4. Snooze... by ObviousGuy · · Score: -1, Troll

    Halfway through I was expecting the interviewer to ask them what their favorite colors and favorite musicians were.

    Maybe he did ask. Did anyone make it through the second half?

    --
    I have been pwned because my /. password was too easy to guess.
    1. Re:Snooze... by Anonymous Coward · · Score: -1, Offtopic
      Most insightful interview question EVAR -

      Tabitha Soren of MTV News to Yassir Arafat-

      "So what do you do for fun?"


  5. Did they ask them... by Anonymous Coward · · Score: -1, Troll

    why pf.conf has to be so fucking cryptic?

    or why pfctl is such a poorly documented steaming pile?

    -Hector

    1. Re:Did they ask them... by Anonymous Coward · · Score: -1, Troll

      why pf.conf has to be so fucking cryptic?

      It's an idiot's test: real experts don't complain about it, only people who should be running Windows or MacOSX instead of opening their cake holes on Slashdot...

    2. Re:Did they ask them... by grub · · Score: 5, Informative


      pf.conf is cryptic? The manpage and demo files in /usr/share/pf are pretty handy. If you want cryptic shit, try using a Cisco PIX. I maintain 4 of them at work and they suck donkey-wang compared to PF & carp.

      --
      Trolling is a art,
    3. Re:Did they ask them... by Anonymous Coward · · Score: -1, Flamebait

      It's an idiot's test: real experts don't complain about it, only people who should be running Windows or MacOSX instead of opening their cake holes on Slashdot...

      That sort of elitism is exactly why the BSD and Linux communities are universally loathed.

    4. Re:Did they ask them... by Anonymous Coward · · Score: -1, Offtopic
      block in quick on slashdot from Hector to any;
      That wasn't very hard at all, now was it?

      ...

      Hello?

      ...

      Hm, guess he didn't really care.
  6. Incarcerate by Anonymous Coward · · Score: -1, Offtopic
    Sounds like a bunch of shady characters to me.

    How quick can be get them into the Iraqi prison system?

    Let me know ASAP

  7. Someone's gotta say it by Rosco+P.+Coltrane · · Score: -1, Funny

    Ryan McBride (mcbride@)

    Two McBrides involved in two different dead or dying OSes, surely it can't be a coincidence...

    --
    "A door is what a dog is perpetually on the wrong side of" - Ogden Nash
    1. Re:Someone's gotta say it by Anonymous Coward · · Score: 0

      2 Unices, too!

    2. Re:Someone's gotta say it by Anonymous Coward · · Score: 0

      > dead or dying OSes

      Presumably that was a joke. Otherwise you must be pretty damn ignorant.

    3. Re:Someone's gotta say it by Anonymous Coward · · Score: -1, Flamebait

      Presumably you're new here.

    4. Re:Someone's gotta say it by isorox · · Score: -1, Offtopic

      Yup, UNIXware is the next big thing!

    5. Re:Someone's gotta say it by Anonymous Coward · · Score: -1, Offtopic

      This should be modded down for being quite rude and insulting.

    6. Re:Someone's gotta say it by dipipanone · · Score: 1

      Hmm. Do you think that Ryan is a clean room implementation of Darl, or has another serious breach of SCO's intellectual property taken place?

      If I were Ryan, I'd take to the hills before David Boies slaps him with a five billion dollar lawsuit

    7. Re:Someone's gotta say it by Anonymous Coward · · Score: 0

      I'm sorry; I apologise for my comment. I just get irritated when people say bad things about OpenBSD.

      BSD is not dying!

    8. Re:Someone's gotta say it by Anonymous Coward · · Score: -1, Offtopic
      Fact: *BSD is dying.

    9. Re:Someone's gotta say it by charlos · · Score: -1, Flamebait

      You must really be an total idiot to say that OpenBSD is a dying OS. Please read and study more, and maybe you'll realize how much superios FreeBSD, OpenBSD nad NetBSD are over your little linux OS or Windows for that matter! charlos

    10. Re:Someone's gotta say it by Anonymous Coward · · Score: -1, Offtopic

      woooOOOSH

      goes the sound of the guys joke passing over your head.

      There really should be an option to filter out people with less than a certain number of comment, or late-series Slashdroids like you. Jesus, you teens are such a waste of free speech space...

    11. Re:Someone's gotta say it by Anonymous Coward · · Score: -1, Troll
      Thinks about this:
      Fact: *BSD is dying.
    12. Re:Someone's gotta say it by Anonymous Coward · · Score: -1, Flamebait

      OpenBSD is a rotting corpse that slashdot fanboys love to circlejerk over.

  8. Bah by Richard_at_work · · Score: -1, Redundant

    Start reading from the first half and continue with the second part.

    You must be new here, slashbots actually READING the article?! Having it in two parts just cements the fact that it wont get read :P

    1. Re:Bah by Erratio · · Score: 0, Offtopic

      I'd rather read the second half first, then the first half can be like a prequel.

      --
      I don't try to be right, I just try to make people think
    2. Re:Bah by Anonymous Coward · · Score: 2, Funny

      Ahh but this is a BSD article so the slashdot effect doesn't apply; the only people here will be people that actually care, and people who just want to flame about BSD dying. So the people in the first group (all 6 of them) actually will rtfa!

    3. Re:Bah by Erratio · · Score: 1

      Nothing more offtopic than responding to a line in the topic.

      --
      I don't try to be right, I just try to make people think
    4. Re:Bah by bro1 · · Score: 1

      I think you forgot the third group - random strangers (probably it's only me)

  9. Do NOT click on that link by Anonymous Coward · · Score: -1, Offtopic

    dickcream.com might sound innocent enough, but believe me, it ain't.

    Can't the /. editors do something about these stomach churning links?

  10. Not sure I understand the answer by Neil+Blender · · Score: -1, Troll

    Federico: How did you join OpenBSD?

    CB: BRAINS!!! I want to EAT YOUR BRAINS!!!

  11. So the world wants to know... by Anonymous Coward · · Score: -1

    What does PF mean?

    PF = Pink Floyd, naw.
    PF = Pirst fost, nope.

    So what gives?

    1. Re:So the world wants to know... by Anonymous Coward · · Score: 4, Informative

      Could you at least try finding it out yourself?
      PF is the Packet Filter in OpenBSD, kind of similar to iptables/ipchains in Linux.

    2. Re:So the world wants to know... by Anonymous Coward · · Score: 1, Interesting

      Packet filtering, you might think that would be mentioned in the summary... or the article. But then it wouldn't be Slashdot.

  12. NETCRAFT NOW CONFIRMS: *BSD IS DYING by Anonymous Coward · · Score: -1, Offtopic

    It is official; Netcraft confirms: *BSD is dying

    One more crippling bombshell hit the already beleaguered *BSD community when IDC confirmed that *BSD market share has dropped yet again, now down to less than a fraction of 1 percent of all servers. Coming on the heels of a recent Netcraft survey which plainly states that *BSD has lost more market share, this news serves to reinforce what we've known all along. *BSD is collapsing in complete disarray, as fittingly exemplified by failing dead last [samag.com] in the recent Sys Admin comprehensive networking test.

    You don't need to be a Kreskin [amdest.com] to predict *BSD's future. The hand writing is on the wall: *BSD faces a bleak future. In fact there won't be any future at all for *BSD because *BSD is dying. Things are looking very bad for *BSD. As many of us are already aware, *BSD continues to lose market share. Red ink flows like a river of blood.

    FreeBSD is the most endangered of them all, having lost 93% of its core developers. The sudden and unpleasant departures of long time FreeBSD developers Jordan Hubbard and Mike Smith only serve to underscore the point more clearly. There can no longer be any doubt: FreeBSD is dying.

    Let's keep to the facts and look at the numbers.

    OpenBSD leader Theo states that there are 7000 users of OpenBSD. How many users of NetBSD are there? Let's see. The number of OpenBSD versus NetBSD posts on Usenet is roughly in ratio of 5 to 1. Therefore there are about 7000/5 = 1400 NetBSD users. BSD/OS posts on Usenet are about half of the volume of NetBSD posts. Therefore there are about 700 users of BSD/OS. A recent article put FreeBSD at about 80 percent of the *BSD market. Therefore there are (7000+1400+700)*4 = 36400 FreeBSD users. This is consistent with the number of FreeBSD Usenet posts.

    Due to the troubles of Walnut Creek, abysmal sales and so on, FreeBSD went out of business and was taken over by BSDI who sell another troubled OS. Now BSDI is also dead, its corpse turned over to yet another charnel house.

    All major surveys show that *BSD has steadily declined in market share. *BSD is very sick and its long term survival prospects are very dim. If *BSD is to survive at all it will be among OS dilettante dbblers. *BSD continues to decay. Nothing short of a miracle could save it at this point in time. For all practical purposes, *BSD is dead.

    Fact: *BSD is dying

  13. Fact: *BSD is dying by Anonymous Coward · · Score: -1, Troll
    There is one thing we have to remember: *BSD is dying. Due to the troubles of Walnut Creek, abysmal sales and so on, FreeBSD went out of business and was taken over by BSDI who sold another troubled OS. Now BSDI too is out of business, and its corpse turned over to yet another charnel house.

    All major surveys show that *BSD has steadily declined in market share. *BSD is very sick and its long term survival prospects are very dim. If *BSD is to survive at all it will be among OS hobbyists, dabblers, and dilettantes. *BSD continues to decay, and nothing short of a miracle could save it at this point in time; for all practical purposes, *BSD is dead.

    1. Re:Fact: *BSD is dying by Anonymous Coward · · Score: -1, Flamebait

      yes bsd is dead, but now rose from the dead with great power. it's harder to kill the undead. so beware!

  14. the Failure of *BSD by Anonymous Coward · · Score: -1
    Why now? Why did *BSD fail? Once you get past the fact that *BSD is fragmented between a myriad of incompatible kernels, there is the historical record of failure and of failed operating systems. *BSD experienced moderate success about 15 years ago in academic circles. Since then it has been in steady decline. We all know *BSD keeps losing market share but why? Is it the problematic personalities of many of the key players? Or is it larger than their troubled personalities?

    The record is clear on one thing: no operating system has ever come back from the grave. Efforts to resuscitate *BSD are one step away from spiritualists wishing to communicate with the dead. As the situation grows more desperate for the adherents of this doomed OS, the sorrow takes hold. An unremitting gloom hangs like a death shroud over a once hopeful *BSD community. The hope is gone; a mournful nostalgia has settled in. Now is the end time for *BSD.

    1. Re:the Failure of *BSD by Anonymous Coward · · Score: -1, Flamebait

      You sound like a poor fucker who never managed to learn BSD.
      Stop wasting our bandwidth!

    2. Re:the Failure of *BSD by Anonymous Coward · · Score: -1, Flamebait

      It's because it has a shitty license that encourages exploitation.

      When any company can swoop in and take out the best parts without giving anything back why would you use something like bsd when you can find all the goodstuff in superior products without all the silly egos and nerd politics.

    3. Re:the Failure of *BSD by Anonymous Coward · · Score: -1, Flamebait

      Oh ya BSD is just soooo hard to learn...shea right.

      It's just another unix folks not nuclear physics stop acting like using it make you some kind of genius ok you little babies.

    4. Re:the Failure of *BSD by Anonymous Coward · · Score: -1, Offtopic

      they came back from the dead hahaha i see you trembling in fear. ignoring the fact that they are after you. awoooooo!

    5. Re:the Failure of *BSD by DashEvil · · Score: 1

      Isn't not liking a project because of the license it's under a `nerd politic'?

      --
      -If God wanted people to be better than me, he would have made them that way.
    6. Re:the Failure of *BSD by Anonymous Coward · · Score: -1, Troll

      I never said I didn't like it because of its license.

      I said BSD was a failure because it has a weak license that discourages corporations and others who use the code from contributing back.

      Nothing political about it, purely practical facts.

      Try some reading comprehension, genius.

    7. Re:the Failure of *BSD by DashEvil · · Score: 3, Insightful

      You never implicity stated that you disliked it, although you could hardly call a comment like "why would you use something like bsd when you can find all the goodstuff in superior products without all the silly egos and nerd politics." friendly.

      You disliking it was strongly implied, and then supported by you calling it a failure right now.

      Of course, you believe that it is the `weak' license that made it a `failure', but you clearly do not understand the goals of project.

      The Goal's of the BSD projects include making software that will be usable. Usable in any sense. If a commerical company incorperates 70% of OpenBSD into a project, it wouldn't change OpenBSD any. Since it doesn't change OpenBSD, you couldn't really consider it a failing point of the OS. Good code is now in wider circulation. This is one of the BSD goals. Now to call a project a failure because it is meeting a goal that you don't agree with, that is, I believe, a `nerd politic'.

      I personally don't care if code gets contributed back. They aren't after World Domination. They just want something that you apparently do not understand: Universally better software. I use Microsoft software, and I appreciate every bit of BSD code that has been incorperated into it.

      Anyway, I question on what grounds you actually deem it to be a failure. It is still developed, it still has a userbase. One that is, in fact, growing, despite the whining of all the trolls. I use it because I find it incredibly useful. Why do I use it instead of Linux? The question of the day for the trolls. Why would I use Linux instead of FreeBSD? You can answer that question for me if you want. I probably won't pay attention because I've looked at most of the Free Open Source OS's myself, did my research, and picked a winner. You banging on the table calling it a failure does not make it one.

      --
      -If God wanted people to be better than me, he would have made them that way.
  15. OpenBSD problems by Anonymous Coward · · Score: -1, Interesting
    I agree that FreeBSD is in deep trouble. And while FreeBSD is beset with its own internal strife, it is not the only BSD to be affected by this cancer. Just look at the problems plaguing OpenBSD.

    I read that T.Deraadt email thread when I first looked at OpenBSD, and my initial impression was that Theo had a real baaaaadddd attitude. I do know for a fact that a lot of the NetBSD folks were upset to see him leave and fork off his own version of the OS, and to lose him as a developer. But in reading his email he obviously has a problem with taking any criticism, and had no problem with jumping down someone's throat with a flamethrower and foul language. Denial, its not just a river in Egypt...

    Not that I wouldn't use OpenBSD, or any other operating system that met my technical needs, whatever the personality of the people involved. I've dealt with enough bad attitudes from commercial OS vendors in my years in the industry to be able to deal with it if I have to. It just seems that *BSD has an extra heaping helping of bad attitudes that make commercial vendors look like pikers.

    If you *really* read that email thread, you would see the attitude loud and clear. "We don't think that it helps anything for you to tell someone he's a f**khead when he's posting a message trying to help with the OS development." "F**K YOU, *I* want control of the source and if you don't like it I'll fork my own off!"

    That's my impression of it... He sounded like an immature little upset kid to me. The development of any of the O.S. OS's is a group effort, and having one person think they have all the answers and have to be the one in control is dead wrong. So, now he *has* control of his own fork of BSD, and lost the ability to maintain many of the various platform ports because he has no developers. Thus, the OpenBSD page says that for a VAX port, for instance, "support can be easily ported over from NetBSD". Why these problems are so prevalent under FreeBSD/OpenBSD/NetBSD remains something of a mystery. These systems seem to be self selective in their attraction to weirdos and big egos.

    The split had nothing to do with the quality of his coding work, and everything to do with his nasty attitude towards people... and NOT just the people of NetBSD Core, but other people who were just civilians trying to help out, or looking for help. No wonder BSD has lost.

    1. Re:OpenBSD problems by Anonymous Coward · · Score: 5, Interesting

      I've read the same thread myself, but I don't think Theo's temper is a problem for OpenBSD.
      Quite the contrary, actually.

      He has a project that's rock solid, and he doesn't want forks polluting OpenBSD's good reputation.
      I don't see why that's a problem. After all, OpenBSD is _his_ baby, and it's his call what to do with it.
      I'd probably do the same if I were in Theo's shoes.

    2. Re:OpenBSD problems by Anonymous Coward · · Score: -1, Flamebait

      I read that T.Deraadt email thread when I first looked at OpenBSD, and my initial impression was that Theo had a real baaaaadddd attitude.

      If Theo has a bad attitude then Linus must be a cu*t. I have read far worse from him (Linus) than Theo.

    3. Re:OpenBSD problems by burns210 · · Score: 2, Interesting

      yea, it is his 'baby' but it is released under and open license, why SHOULDN'T i be able to fork openbsd if i want? If Theo wants an unforkable OS, he shouldn't have started by forking netbsd in the first place!

    4. Re:OpenBSD problems by andkaha · · Score: 1

      why SHOULDN'T i be able to fork openbsd if i want?

      Sure, go ahead! That's what the MirBSD people did after all...

      --
      It's 11pm, do you know what your deamons are up to?
    5. Re:OpenBSD problems by mritunjai · · Score: 3, Informative

      Oh you can fork OpenBSD to your likeness, the only restriction is that you can't call your fork 'OpenBSD'... name it burnsBSD or whatever and you should be fine ;-)

      --
      - mritunjai
    6. Re:OpenBSD problems by CherniyVolk · · Score: 1, Interesting

      Oh you can fork OpenBSD to your likeness, the only restriction is that you can't call your fork 'OpenBSD'... name it burnsBSD or whatever and you should be fine ;-)

      In most cases, the fork should be named "BrokenBSD" by default.

    7. Re:OpenBSD problems by Anonymous Coward · · Score: -1, Offtopic

      I happen to know for a fact that Theo likes to fuck dead chickens.

    8. Re:OpenBSD problems by Anonymous Coward · · Score: -1, Flamebait

      In most cases, the fork should be named "BrokenBSD" by default.

      I'd vote for CorpseBSD, suitable for running the IT tasks for any morturary.

    9. Re:OpenBSD problems by CherniyVolk · · Score: 1

      Why was my post modded to troll?

      It was a compliment to OpenBSD. If you mess with
      it, you'll probably break it. Hence, some crack
      pot trying to branch his own BSD release should
      name it 'BrokenBSD'.

    10. Re:OpenBSD problems by Anonymous Coward · · Score: -1, Flamebait

      Because the few necrophiliac *BSD fanboy slashmods are raging faggots and can't stand the truth that *BSD is just so fucking dead.

  16. Fa1lzor5 by Anonymous Coward · · Score: -1, Offtopic

    Posts. Due 7o the

  17. Let's blame US soldiers when by Anonymous Coward · · Score: -1, Offtopic

    the prisons in Iraq are really being managed by private contractors, who are all GOP campaign contributors.

    American servicemen and women are being blamed in order to protect GOP politicos.

    Impeach and then convict Bush, Cheney, Rumsfeld.

  18. Shhh..... by Anonymous Coward · · Score: -1, Offtopic

    I see dead people...

    1. Re:Shhh..... by Anonymous Coward · · Score: -1, Flamebait

      he he he, shhh! be still. maybe the undead will hear you. they rose again from the dead with great power. so beware. now i see you trembling in fear (demonic laugh)

  19. PF can Filers By OS by zulux · · Score: 5, Interesting

    One of the coolers things 'bout PF, is that you can add another layer of security to your systems - if you know that you'll never use a Windows box to SSH into your OpenBSD server - you can specifically deny Windows from connecting with a simple PF rule.

    It's great of VPN stuff - all of my VPN equipment is OpenBSD - so I just don't allow any packets from any other OS. This mitigates any attack - now my attacker has to have and OpenBSD computer (or at least spoof one)

    --

    Moneyed corporations, non-working 'poor' and criminal prisoners are turning productive citizens into tax-slaves.

    1. Re:PF can Filers By OS by Anonymous Coward · · Score: 1, Interesting

      The OS fingerprinting really has limited usefulness, because it's so easy to fool it.

      Block external Windows clients? But I'm behind an OpenBSD firewall running pf myself, so connections from my Windows machine will look like OpenBSD. (synproxy ;)

      And what happens when Longhorn starts using a TCP/IP stack indistinguishable from OpenBSD? (not that that's likely...)

      What are the chances of someone attacking (let along successfully) an OpenBSD machine from Windows anyway? More likely they're on Linux or something else and have the ability to spoof any OS they want.

      You can't rely on it at all, and the rest of OpenBSD is secure enough that you don't really have to.

      I suppose you can use OS fingerprinting to enforce internal policy ("no Windows machines on out network"), since you really need 2 machines to evade that, but that's kinda silly.

  20. Go ahead and DO click on that link by Anonymous Coward · · Score: -1, Offtopic
    And just what were you expecting when you clicked on a "dickcream" link? Come on. You were expecting to see some queer action, weren't you? At least be a man and admit it.

    Look, I'm no queer but that troll link was damn funny. Complete with video and sound. Compared to the lemonparty and its kind, this was art.

  21. Developer laments: What Killed FreeBSD by Anonymous Coward · · Score: -1
    The End of FreeBSD

    [ed. note: in the following text, former FreeBSD developer Mike Smith gives his reasons for abandoning FreeBSD]

    When I stood for election to the FreeBSD core team nearly two years ago, many of you will recall that it was after a long series of debates during which I maintained that too much organisation, too many rules and too much formality would be a bad thing for the project.

    Today, as I read the latest discussions on the future of the FreeBSD project, I see the same problem; a few new faces and many of the old going over the same tired arguments and suggesting variations on the same worthless schemes. Frankly I'm sick of it.

    FreeBSD used to be fun. It used to be about doing things the right way. It used to be something that you could sink your teeth into when the mundane chores of programming for a living got you down. It was something cool and exciting; a way to spend your spare time on an endeavour you loved that was at the same time wholesome and worthwhile.

    It's not anymore. It's about bylaws and committees and reports and milestones, telling others what to do and doing what you're told. It's about who can rant the longest or shout the loudest or mislead the most people into a bloc in order to legitimise doing what they think is best. Individuals notwithstanding, the project as a whole has lost track of where it's going, and has instead become obsessed with process and mechanics.

    So I'm leaving core. I don't want to feel like I should be "doing something" about a project that has lost interest in having something done for it. I don't have the energy to fight what has clearly become a losing battle; I have a life to live and a job to keep, and I won't achieve any of the goals I personally consider worthwhile if I remain obligated to care for the project.

    Discussion

    I'm sure that I've offended some people already; I'm sure that by the time I'm done here, I'll have offended more. If you feel a need to play to the crowd in your replies rather than make a sincere effort to address the problems I'm discussing here, please do us the courtesy of playing your politics openly.

    From a technical perspective, the project faces a set of challenges that significantly outstrips our ability to deliver. Some of the resources that we need to address these challenges are tied up in the fruitless metadiscussions that have raged since we made the mistake of electing officers. Others have left in disgust, or been driven out by the culture of abuse and distraction that has grown up since then. More may well remain available to recruitment, but while the project is busy infighting our chances for successful outreach are sorely diminished.

    There's no simple solution to this. For the project to move forward, one or the other of the warring philosophies must win out; either the project returns to its laid-back roots and gets on with the work, or it transforms into a super-organised engineering project and executes a brilliant plan to deliver what, ultimately, we all know we want.

    Whatever path is chosen, whatever balance is struck, the choosing and the striking are the important parts. The current indecision and endless conflict are incompatible with any sort of progress.

    Trying to dissect the above is far beyond the scope of any parting shot, no matter how distended. All I can really ask of you all is to let go of the minutiae for a moment and take a look at the big picture. What is the ultimate goal here? How can we get there with as little overhead as possible? How would you like to be treated by your fellow travellers?

    Shouts

    To the Slashdot "BSD is dying" crowd - big deal. Death is part of the cycle; take a look at your soft, pallid bodies and consider that right this very moment, parts of you are dying. See? It's not so bad.

    To the bulk of the FreeBSD committerbase and the developer community at large - keep your eyes on the real goals.

    1. Re:Developer laments: What Killed FreeBSD by Anonymous Coward · · Score: -1, Offtopic

      Oops, wrong article. This is about OpenBSD.

  22. Wow by 222 · · Score: 1, Interesting

    I actually read the article, and although i can't tell you too much about what it means, i can tell you that these guys sound damn smart. I mean DAMN smart.

    1. Re:Wow by Moloch666 · · Score: 4, Insightful

      We are probably the only 2 people that read this article. I'm with you though. I'm currenly running all Gentoo switched from some use of FreeBSD. I'm seriously considering switching my firewall box to OpenBSD, the features sound awesome.

      --
      Understanding is a three-edged sword. -- Kosh Naranek
    2. Re:Wow by 0racle · · Score: 5, Interesting

      I personally have a lot of respect for the OpenBSD team, and the pf developers in particular, some time in the next week I'll be replacing my little Linksys with a OpenBSD pf firewall, and when I sat down to write the rules for it, it was amazing and appreciated how simple it is to write the rules, and that they're understandable at the same time. Comparing it to iptables that I saw once, the ease of writing the pf rules would have been enough for me to switch over. They also have that reputation thats not bad either.

      --
      "I use a Mac because I'm just better than you are."
  23. BSD IS DEAD/LINUX ADVOCACY by Anonymous Coward · · Score: -1, Troll

    Hello everyone!
    You may know me as the "troll" that posts the "BSD IS DEAD" and all of the "FACTS" to every BSD story on Slashdot. Many people wonder why I do it. The answer is that BSD is detrimental to the open source community.

    As a Linux advocate, I have taken upon myself the duty to convince Slashdot readers that BSD is dead and that Linux is the future. If BSD were to gain a bigger marketshare, corporations such as IBM, Oracle, and Sun may be distracted from their interest in Linux.

    If you know any BSD users, you must convince them to convert to Linux. These people are slowing down open source developement because developers are distracted from working on Linux programs to make them work with BSD. Imagine how great Gnome/KDE, Mozilla, and Apache would be if the developers didn't have to waste precious time writing code so that it would run on BSD. We need the entire open source community to get behind a single operating system so that developers can focus on achieving our goal, OS dominance.

    We can all agree that Microsoft has to go. We cannot allow any other proprietary operating system to take it's place. That narrows it down to the open source operating systems, of which the 2 major options are Linux and BSD. Since Linux already has the larger marketshare, we need to kill off BSD. Once we convert all the BSD developers to Linux, we will have a stronger army. We cannot survive when the open source community has to compete with itself.

    So what can you do to help? Easy. Find BSD users and developers and convince them to switch to Linux. Do so by any means necessary. You can start out being nice, but be persistent. Don't give up. In the end, they will thank you for enlightening them.

    After we destroy BSD, we will need to focus on a single Linux distribution, Fedora. The other Linux distributions are wasting time and causing confusion. We need everyone to focus on Fedora so that it can be made the best operating system ever!

    There can be only one open source operating system. Divided we fall. Together we shall rule.
    As a great man once said, "Let us never forget the duty, which we have taken upon ourselves."

    1. Re:BSD IS DEAD/LINUX ADVOCACY by Anonymous Coward · · Score: -1, Offtopic

      now i know you're not really a linux advocate. you're a lunatic wahahahahahaha.

    2. Re:BSD IS DEAD/LINUX ADVOCACY by Anonymous Coward · · Score: -1, Offtopic

      He's a sad, sad discrace to Open Source as a whole - especially Linux! Shows how little he knows and understands OSS.

  24. McBride@ ? by Ciderx · · Score: -1, Redundant

    Its happened! SCO has pwned OpenBSD!

  25. YOU FAIL IT. by Anonymous Coward · · Score: -1, Flamebait
  26. beg your pardon? by Anonymous Coward · · Score: -1, Offtopic

    they suck donkey-wang compared to PF & carp.

    I must misunderstand. It almost sounds like you speak of sucking on sweet donkey cock as though it were a bad thing...

    1. Re:beg your pardon? by Anonymous Coward · · Score: -1, Flamebait

      Compared to a Shetland Pony's cock, it is.

    2. Re:beg your pardon? by Anonymous Coward · · Score: -1, Offtopic

      Ever suck a dead moose's cock? It tastes just like *BSD.

  27. I read both pages, and.... by zogger · · Score: 1

    I tend to agree. After the first sentence I was lost, so they are either damn smart, or a great job of (que: jon lovitz) acttt-tinggg in the interview.

    I did like that os filtering idea.

  28. Re:NETCRAFT NOW CONFIRMS: *BSD IS DYING by Anonymous Coward · · Score: -1, Flamebait

    yes, bsd is died. but rose again from the dead with great power. it's harder to kill the undead. so beware!

  29. pf vs ipf vs ipfw vs iptables by ophix · · Score: 1

    i would really like to see a comparison between all of these packet filters with strength and weaknesses and maybe an example of the fliter scripts used for a few common scenerios.

    also maybe add in some ebtables+iptables stuff as well

    1. Re:pf vs ipf vs ipfw vs iptables by Homology · · Score: 4, Informative
      i would really like to see a comparison between all of these packet filters with strength and weaknesses and maybe an example of the fliter scripts used for a few common scenerios.

      For an example of setting up firewall for home or small office, have a look at the execellent PF User Guide> .

      Tired of sucky download performance when you max your upload on your ADSL connection? Well, PF solves that with packet queueing and prioritization.

    2. Re:pf vs ipf vs ipfw vs iptables by jimi1283 · · Score: 2, Interesting
      I can tell you, pf/ipf syntax is so easy when compared to iptables. And pf takes ipf even further by adding shortcuts to common tasks. For example, rather than setting up block rules to stop spoofing, you just do "antispoof for interface" and you're done :)

      I love OpenBSD for firewall/vpn duties... now if they'd just hurry the hell up and implement NAT-t for isakmpd i'd be a happy camper...

    3. Re:pf vs ipf vs ipfw vs iptables by Anonymous Coward · · Score: 4, Insightful

      I second that about altq, I have torrents, web browsing and streaming audio all going on my crappy cable modem (upstream sucks) and the day I setup the queueing it was like putting in a second broadband connection that didn't stall or drop out. Highly recommended.

    4. Re:pf vs ipf vs ipfw vs iptables by Anonymous Coward · · Score: -1, Troll

      *_g_o_a_t_s_e_x_*_g_o_a_t_s_e_x_*_g_o_a_t_s_e_x_*_
      g_______________________________________________g_ _
      o_/_____\_____________\____________/____\_______o_ _
      a|_______|_____________\__________|______|______a_ _
      t|_______`._____________|_________|_______:_____t_ _
      s`________|_____________|________\|_______|_____s_ _
      e_\_______|_/_______/__\\\___--___\\_______:____e_ _
      x__\______\/____--~~__________~--__|_\_____|____x_ _
      *___\______\_-~____________________~-_\____|____*_ _
      g____\______\_________.--------.______\|___|____g_ _
      o______\_____\______//_________(_(__>__\___|____o_ _
      a_______\___.__C____)_________(_(____>__|__/____a_ _
      t_______/\_|___C_____)/______\_(_____>__|_/_____t_ _
      s______/_/\|___C_____)__*BSD_|__(___>___/__\____s_ _
      e_____|___(____C_____)\______/__//__/_/_____\___e_ _
      x_____|____\__|_____\\_________//_(__/_______|__x_ _
      *____|_\____\____)___`----___--'_____________|__*_ _
      g____|__\______________\_______/____________/_|_g_ _
      o___|______________/____|_____|__\____________|_o_ _
      a___|_____________|____/_______\__\___________|_a_ _
      t___|__________/_/____|_________|__\___________|t_ _
      s___|_________/_/______\__/\___/____|__________|s_ _
      e__|_________/_/________|____|_______|_________|e_ _
      x__|__________|_________|____|_______|_________|x_ _
      *_g_o_a_t_s_e_x_*_g_o_a_t_s_e_x_*_g_o_a_t_s_e_x_*_


      Important Stuff: Please try to keep posts on topic. Try to reply to other people's comments instead of starting new threads. Read other people's messages before posting your own to avoid simply duplicating what has already been said. Use a clear subject that describes what your message is about. Offtopic, Inflammatory, Inappropriate, Illegal, or Offensive comments might be moderated. (You can read everything, even moderated posts, by adjusting your threshold on the User Preferences Page) If you want replies to your comments sent to you, consider logging in or creating an account.

      Important Stuff: Please try to keep posts on topic. Try to reply to other people's comments instead of starting new threads. Read other people's messages before posting your own to avoid simply duplicating what has already been said. Use a clear subject that describes what your message is about. Offtopic, Inflammatory, Inappropriate, Illegal, or Offensive comments might be moderated. (You can read everything, even moderated posts, by adjusting your threshold on the User Preferences Page) If you want replies to your comments sent to you, consider logging in or creating an account.

      Important Stuff: Please try to keep posts on topic. Try to reply to other people's comments instead of starting new threads. Read other people's messages before posting your own to avoid simply duplicating what has already been said. Use a clear subject that describes what your message is about. Offtopic, Inflammatory, Inappropriate, Illegal, or Offensive comments might be moderated. (You can read everything, even moderated posts, by adjusting your threshold on the User Preferences Page) If you want replies to your comments sent to you, consider logging in or creating an account.

  30. DeForest Kelley talks about BSD by Anonymous Coward · · Score: -1, Flamebait

    "It's dead, Jim."

    1. Re:DeForest Kelley talks about BSD by Anonymous Coward · · Score: -1, Offtopic

      DeForest Kelley said:

      "Oops I lied, Jim"

  31. I am Billy the Gates, THE CHAMPION! by Anonymous Coward · · Score: -1, Troll

    hah but still i'm not dead BWAHAHAHAHAHAHAHAHAHAHA! i am the champion of the world! BWAHAHAHAHAHAHAHA! you linux users are full of insecurities, full of flames. but still you can't match my beloved WINDOWS!!!! BWAHAHAHAHAHAHAHA!

  32. Elegy for *BSD by Anonymous Coward · · Score: -1, Flamebait

    Elegy For *BSD


    I am a *BSD user
    and I try hard to be brave
    That is a tall order
    *BSD's foot is in the grave.

    I tap at my toy keyboard
    and whistle a happy tune
    but keeping happy's so hard,
    *BSD died so soon.

    Each day I wake and softly sob
    Nightfall finds me crying
    Not only am I a zit faced slob
    but *BSD is dying.

    1. Re:Elegy for *BSD by Anonymous Coward · · Score: -1, Troll

      Elegy for You

      I saw you
      You cry and cry because BSD is dying
      But deep inside you cry
      Because you can't understand BSD

      Each day you are always spanked by your employer,
      Because you don't know how to use BSD
      And therefore you conclude BSD is dying,
      Because deep inside you can't understand it.
      Now you're job is dying.

      Don't worry friend, I'll pray for you
      So that one day, your brain will grow
      And that time you can now understand BSD
      And you'll said, Horray, now my brain rose back from the dead.
      With great power so others beware!

    2. Re:Elegy for *BSD by Anonymous Coward · · Score: -1, Offtopic

      Here's one for you:

      I saw you
      Sucking the cock of the dead corpse
      That is *BSD

      You felt so sorry for that lump
      That dead heap on the slab
      That is *BSD

      You still pretend it's alive
      Such potential for success but something rotting
      That is *BSD

      You deny yourself the truth
      You still pretend that usefulness exists
      That is *BSD

      Awake from your trance, you insensitive clod
      Realize that death is it
      Death extends beyond the one
      That is *BSD

    3. Re:Elegy for *BSD by Anonymous Coward · · Score: -1, Offtopic

      and here's for you:

      i saw you
      dying in great jealosy
      because you only know linux and not bsd
      and i know both.

      you deny yourself the truth
      that bsd rose from the dead
      because your brain can't just take it.

      you deny the fact that
      bsd is alive and kicking now
      because your brain can't match the great power of
      bsd

      i pity people like you my friend
      imagining and seeing one sucking cock of dead one
      that is not bsd my friend
      that is tux, sucking bill gate's cock
      stop using drugs my friend
      so you can't have many hallucinations.

      you can't even win over microsoft
      how can you win over bsd?
      even solaris kicks your a*s too

      don't pretend it is dead
      just because you can't understand it
      i advise to you my friend
      study harder so that one day
      your sleeping brain will be awaken.

      and also realize the fact
      that penguins are tasty snacks.

    4. Re:Elegy for *BSD by Anonymous Coward · · Score: -1, Offtopic

      HAHAHAHAHA!

    5. Re:Elegy for *BSD by Anonymous Coward · · Score: -1, Flamebait

      The pathetic, desparate retort of a fanatical necrophiliac *BSD luser. Sorry bitch, but your software is DEAD. IT'S FUCKING DEAD! Nobody beyond the sick realm of corpse-fucking criminals would use such a shitty operating system. Get your ass on Microsoft Windows and be useful, don't waste our time trying to convince anyone that the rotting smell is working code.

  33. it gives great insight into the bsd dev process by Anonymous Coward · · Score: -1, Offtopic

    nibble nibble munchkin. the M$FT is so big yes. it controls, controls all. the people they walk by i see their feet though my window. their feet swing by the bars on my window. pretty feet shiny shoes. swish swish. are they going to work? i WILL NOT go to work. M$FT is at work. M$FT controls the pretty feet people. controls their money their futures.

    i sit and rebuld my kernel. my CPU thrums. the kernel it is the key. we hack the linux yes good. 2.3, 2.4, 2.5, ...2.6!!!!!!!!! the M$FT it fears the linux. spreads lies. says the linux comes with no warranty. THE WARRANTY IT IS BAD! it goes into your pores. steals your power. the kernel is good. the kernel will rise and slay the M$FT. when the itching comes i think about the linux. it helps.

    i hack a driver for my dvd-rom. it does not work. i debug. it does not work. i delete the old source. and start again. i recompile. it does not work. on M$FT the dvd-rom is plug and play. that is how they get you. get behind your eyes. start the itching. so i hack the driver. i hack, we hack: we gnaw. gnaw at the ropes of slavery. the ropes of M$FT. pretty feet people, we will save you.

    the itching comes...

  34. pf also available for FreeBSD by FlightTest · · Score: 5, Informative

    pf has been available in ports for quite a while. Although it only works on the 5.x branch, I'm running it as my firewall on an old 166mhz Pentium.

    Personally, I find FreeBSD easier to deal with, but that's just me.

    --
    Merde, il pleut encore!
  35. AuthPF is neat too by myov · · Score: 4, Informative

    authpf allows you to authenticate remote users, and change the firewall rules. And it's all done by ssh'ing in with authpf as the user's shell.

    Useful if you want to hide services from the outside world (except for selected users), but you don't want the complexity of ssh tunnels/vpn. (ie: I want to give some people access to my ftp server but hide it from the rest of the world, and not give them vpn access to the whole network)

    --
    I use Macs to up my productivity, so up yours Microsoft!
  36. FreeBSD has pf(4) support too by mi · · Score: 1

    See the man-pages.

    --
    In Soviet Washington the swamp drains you.
  37. Thinking about tomorrow by Anonymous Coward · · Score: -1, Troll

    Problem is that *BSD is worse off than SCO. Most analysts agree that *BSD is dying. The same forces that are killing *BSD are the same ones that hurt SCO. My gut feeling that none of it can be helped. It is a convergence of events over the last few years that is beyond any individual's (or marketings') ability to influence. Some events in the course of history happen as the result of the irresistible pull of fate. The decline and fall of *BSD is just such an event in the history of technology.

  38. Dissemination is the goal by ^BR · · Score: 4, Informative

    Spreading technology, not ideology...

    Each time some BSD code is incorporated in a proprietary product the world is likely a better place, you don't want everyone and his dog coding an IP stack, if it was the case it would not be some unpatched windows boxes that would be used as attack launch points, the would be everything from your fridge to your car...

    BTW the license does not discourage anything, it just does not make it mandatory. Common sense makes contributing back a good thing, as maintaining a fork is likely more expensive that contributing back your valuable intellectual property would cost you.

    1. Re:Dissemination is the goal by Anonymous Coward · · Score: -1, Troll

      But BSD is dying so obviously you are quite wrong.

      BSD was relevent in the 90s but it's pretty much useless at this point.

    2. Re:Dissemination is the goal by Anonymous Coward · · Score: -1, Troll

      yes indeed, bsd is dead for the uninformed and ignorant.

  39. Hard Times for *BSD by Anonymous Coward · · Score: -1, Troll
    So why now? Why did *BSD fail? Once you get past the fact that *BSD is fragmented between a myriad of incompatible kernels, there is the historical record of failure and of failed operating systems. *BSD experienced moderate success about 15 years ago in academic circles. Since then it has been in steady decline. We all know *BSD keeps losing market share but why? Is it the problematic personalities of many of the key players? Or is it larger than their troubled personalities?

    The record is clear on one thing: no operating system has ever come back from the grave. Efforts to resuscitate *BSD are one step away from spiritualists wishing to communicate with the dead. As the situation grows more desperate for the adherents of this doomed OS, the sorrow takes hold. An unremitting gloom hangs like a death shroud over a once hopeful *BSD community. The hope is gone; a mournful nostalgia has settled in. Now is the end time for *BSD.

  40. It's impossible to create reliable BSD statistics! by trons · · Score: 5, Informative

    Don't you people understand... It is not possible for Netcraft to gather any statistical data on how many BSD machines are being used, simply because no one is *forced* to make their machine identify as a BSD machine! Quote from : "There are some, even large, companies that use BSD as routers, firewalls and even servers, without people noticing. That is a reason why no one can give current usage statistics for BSD, because no one is forced to say he is using BSD at all, or in which number." http://mirbsd.bsdadvocacy.org/?bsd-intro Drawing conclusions from statistical date without proper knowledge on the subject is Bad Practice..

  41. Re:It's impossible to create reliable BSD statisti by Anonymous Coward · · Score: 0

    heh this is slashdot. answer troll replies with troll replies too.

  42. So, what can XP users use... by RLiegh · · Score: 1

    ...until pf is ported to run on XP?

    1. Re:So, what can XP users use... by Anonymous Coward · · Score: 0

      /me rolls eyes

    2. Re:So, what can XP users use... by Brandybuck · · Score: 1

      Ummm... How about OpenBSD!

      --
      Don't blame me, I didn't vote for either of them!
  43. GNAA Free Zone by Anonymous Coward · · Score: -1, Troll
  44. TYPICAL *BSD FAGGOTRY, LOOK AT THE COMMENT MODS by Anonymous Coward · · Score: -1, Offtopic

    Only the non-pro-BSD comments are modded down, the others are not! WHAT FAGGOTRY!

  45. BSD is one dead bitch by Anonymous Coward · · Score: -1, Flamebait
    Theo says there are 7000 users of OpenBSD. How many users of NetBSD are there? Let's see. The number of OpenBSD versus NetBSD posts on Usenet is roughly in ratio of 5 to 1. Therefore there are about 7000/5 = 1400 NetBSD users. BSD/OS posts on Usenet are about half of the volume of NetBSD posts. Therefore there are about 700 users of BSD/OS. A recent article put put FreeBSD as about 80 percent of the BSD market. Therefore there are (7000+1400+700)*4 = 36400 FreeBSD users. This is consistent with the number of FreeBSD Usenet posts.

    Before FreeBSD was acquired by BSDI (due to the bankruptcy of Walnut Creek) sales were abysmal. Now BSDI itself is dead. Major marketing surveys show that BSD has steadily declined in market share. BSD is very sick and its long term survival prospects are very dim.

    If BSD is to survive at all it will be among hobbyist dilettante dabblers. The reasons behind the death of BSD are many and too sordid to describe in a short article. Suffice it to say, whatever the reasons, BSD is dead.