<?xml version="1.0" encoding="utf-8" ?>
<rss version="2.0" xmlns:osnews="http://osnews.com/rss2#">
	<channel>
		<title>OSNews: </title>
		<link>http://www.osnews.com/story/21643/PF_Enabled_by_Default_in_OpenBSD-current</link>
		<description>Exploring the Future of Computing</description>
		<language>en-us</language>
		<copyright>Copyright 2001-2009, David Adams</copyright>
		<webMaster>adam+nospam@osnews.com</webMaster>
		<lastBuildDate>Mon, 30 Nov 2009 10:20:06 GMT</lastBuildDate>
		<image>
			<url>http://www.osnews.com/images/osnews.gif</url>
			<title>OSNews.com</title>
			<link>http://www.osnews.com</link>
		</image>
		<item>
			<title>Odd</title>
			<link>http://osnews.com/thread?367673</link>
			<guid isPermaLink="true">http://osnews.com/thread?367673</guid>
			<description>Considering OpenBSD always prided itself in being the most secure OS with it's default install (Mainly due to it rejecting everything and having all the services turned off) I find it very weird that it would enable PF to forward ALL incoming connections in by default.<br />
<br />
To me, it just seems very weird to go against something they've been doing for so long.</description>
			<pubDate>Tue, 09 Jun 2009 23:15:00 GMT</pubDate>
			<author>donotreply@osnews.com (Finchwizard)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Odd</title>
			<link>http://osnews.com/thread?367682</link>
			<guid isPermaLink="true">http://osnews.com/thread?367682</guid>
			<description>I think you're confusing having most services turned off with having pf on... turning on pf with the default install is new, they still leave most daemons off to have a 'secure by default' install. <br />
<br />
This doesn't mean they used to have pf enabled but blocking everything... that wasn't the case in the past<br />
<br />
They always have had the minimal services needed (meaning daemons aren't listening on ports), which they still do, but with the added benefit of pf being on but allowing all traffic except for the mentioned X tcp port</description>
			<pubDate>Wed, 10 Jun 2009 00:34:00 GMT</pubDate>
			<author>donotreply@osnews.com (flydpnkrtn)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>we don't need to block unavailable services</title>
			<link>http://osnews.com/thread?367683</link>
			<guid isPermaLink="true">http://osnews.com/thread?367683</guid>
			<description>Yes, services disabled/minimized by default means we don't have to block any unavailable services.</description>
			<pubDate>Wed, 10 Jun 2009 00:38:00 GMT</pubDate>
			<author>donotreply@osnews.com (hxizan)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Odd</title>
			<link>http://osnews.com/thread?368337</link>
			<guid isPermaLink="true">http://osnews.com/thread?368337</guid>
			<description>It isn't odd. As explained in FAQ:<br />
<br />
&quot;OpenBSD attempts to minimize the need for customization and tweaking. For the vast majority of users, OpenBSD &quot;Just Works&quot; on their hardware for their application. Not only is tweaking and customizing rarely needed, it is actively discouraged.&quot;<br />
<br />
<a href="http://www.openbsd.org/faq/faq1.html" rel="nofollow">http://www.openbsd.org/faq/faq1.html</a><br />
<br />
OpenBSD aims to be a general purpose OS, not only for servers, but for desktop or embedded systems too. Of course it can be a &quot;lot more secure&quot; than it is now, but this is not the point. You have to watch your mouth when you talk about what a &quot;secure&quot; OS is.</description>
			<pubDate>Fri, 12 Jun 2009 23:56:00 GMT</pubDate>
			<author>donotreply@osnews.com (dbolgheroni)</author>
			<category>Comments</category>
		</item>
	</channel>
</rss>
