Linked by Thom Holwerda on Thu 1st Nov 2007 22:51 UTC, submitted by Earin
OpenBSD OpenBSD 4.2 has been released. "We are pleased to announce the official release of OpenBSD 4.2. This is our 22nd release on CD-ROM (and 23rd via FTP). We remain proud of OpenBSD's record of more than ten years with only two remote holes in the default install." Update: A what's new article at ONLamp.
Thread beginning with comment 282334
To read all comments associated with this story, please click here.
How?
by flanque on Thu 1st Nov 2007 23:43 UTC
flanque
Member since:
2005-12-15

"We remain proud of OpenBSD's record of more than ten years with only two remote holes in the default install."


How do they achieve this? Is it just very good practices and programming, or is it due to a lack of rich modern features?

RE: How?
by indiocolifa on Thu 1st Nov 2007 23:48 in reply to "How?"
indiocolifa Member since:
2006-06-20

Sorry, but please tell what "rich modern" features you expect that are related to security holes.

Edited 2007-11-01 23:49

Reply Parent Bookmark Score: 6

RE[2]: How?
by flanque on Fri 2nd Nov 2007 00:15 in reply to "RE: How?"
flanque Member since:
2005-12-15

You're misunderstanding. I don't know anything about OpenBSD. I don't know what's available for it.

I'm asking is this security record is due to them being very good at making the operating system, or if its due to there being less features than other operating systems.

It may be as feature rich as others, I just don't know, so that's why I'm asking.

Reply Parent Bookmark Score: 7

RE: How?
by anomie on Fri 2nd Nov 2007 00:10 in reply to "How?"
anomie Member since:
2007-02-26

Stringent code auditing and a genuine approach to secure design.

Like 'em or hate 'em (for their personalities), you have to respect their work.

Reply Parent Bookmark Score: 15

RE: How?
by paws on Fri 2nd Nov 2007 01:30 in reply to "How?"
paws Member since:
2007-05-28

The keyword here is 'default install'... a default OpenBSD install is really quite different to, say, a default Ubuntu Linux installation, or a default Windows Vista install..

I do love my OpenBSD though. It's just so clean..

Reply Parent Bookmark Score: 10

RE[2]: How?
by Doc Pain on Fri 2nd Nov 2007 01:49 in reply to "RE: How?"
Doc Pain Member since:
2006-10-08

"The keyword here is 'default install'... a default OpenBSD install is really quite different to, say, a default Ubuntu Linux installation, or a default Windows Vista install.. "

Please don't confuse OpenBSD (or FreeBSD, NetBSD) with a Linux distribution. OpenBSD is "just" an OS, nothing more. If you install it, you have installed an operating system, nothing more, nothing less. In most cases, you are required to install additional software for the purposes you want to use your system, maybe as a mail server, a web server, a rescue system, a development system, or an "all possible purposes one size fits all" desktop workstation. You decide what's going to be installed.

If you want a BSD OS bundled with additional software (in the way most Linux distributions are), you will have to use PC-BSD or DesktopBSD.

Reply Parent Bookmark Score: 2

RE: How?
by Hiawatha on Fri 2nd Nov 2007 06:16 in reply to "How?"
Hiawatha Member since:
2005-08-29

How do they achieve this? Is it just very good practices and programming, or is it due to a lack of rich modern features?


By simply denying a lot of security issues.

http://pwnie-awards.org/winners.html#lamestvendor

Reply Parent Bookmark Score: 1

RE[2]: How?
by purplemonk on Fri 2nd Nov 2007 11:11 in reply to "RE: How?"
purplemonk Member since:
2007-11-02

By simply denying a lot of security issues.

Looks like they accepted this one as a vulnerability at last:

http://www.techworld.com/security/news/index.cfm?newsID=8278&pagtyp...

Did they deny any other issues?

Reply Parent Bookmark Score: 4

RE[2]: How?
by Soulbender on Mon 5th Nov 2007 14:07 in reply to "RE: How?"
Soulbender Member since:
2005-08-18

Yeah, who you gonna trust? The companies who makes money and fame from hyping their bug findings or the guys who may not want to admit it?

Reply Parent Bookmark Score: 2