Re: The Stunning Failure of OpenBSD

From: Jeff Cochran (jcochran@info.der-keiler.de)
Date: 07/18/02


From: jcochran at naplesgov dot com (Jeff Cochran)
Date: Thu, 18 Jul 2002 11:39:59 GMT


>When not attending classes at my community college to get my
>humanities degree, I work part-time at a printshop. Our Linux box
>there finally gave up the ghost. I'd heard that OpenBSD was incredibly
>secure so I talked my boss into putting that on as a replacement.

Bad move number one -- Recommending a product you've never used based
on things you've heard about it.

>I was even more shocked to learn that the ipchains rules we'd
>carefully setup on our Linux box would not work on OpenBSD!

Bad move number two -- Being shocked that you are confused when you
change software and assume it's identical the software you're familiar
with.

>Whatever the case, almost immediately our box was rooted. OpenBSD
>proved to be aptly named as the box was "open" to the entire world.

Bad move number three -- Using software you're unfamiliar with in a
production environment exposed to the internet.

>After spending a week trying to patch a leaky firewall, I gave up. I
>found an Mac SE/30 and put OSX on it. I then installed Norton Personal
>Firewall. That became our firewall and I'm proud to say that its been
>happily running for two weeks without a single incident. I find it
>funny that despite OpenBSD users arrogant claims of superiority, a
>humble SE/30, running an OS that's loosely based on OpenBSD, performed
>much better. Perhaps its another failing of open source versus
>commercial software. Whatever the case, its clear that OpenBSD has a
>long ways to go before it can be taken seriously.

Bad move number four -- Assuming that because *you* can't run
something it must be bad.

According to Apple's latest ad run, people are switching to Macs
because Windows is too hard for them. You seem to have done the same.
This is the only smart move you made, running what you need to get the
job done, instead of jumping into something you're unfamiliar with and
expecting it to magically solve your issues.

Jeff



Relevant Pages

  • Re: Which Linux OS best for beginner to setup as Web / Mail server / Internet sharer and firewall?
    ... >>I don't want to start a flame war, but in my experience OpenBSD is best ... >>boxes if you must run linux for applications. ... > linux inside the firewall? ... web server? ...
    (comp.os.linux.networking)
  • Re: Internet Sharing - Security
    ... Can you recommend the steps that I would need to take once I have ... OpenBSD 3.0 installed on my system. ... >>>inexpensive Linux 2.4.x firewall with Netfilter and ISC DHCP is fine. ...
    (comp.security.firewalls)
  • Re: Firewalls in a K-12
    ... on using Linux versus using OpenBSD for your firewall. ... I haven't found using OpenBSD much more difficult than using Linux ... The two arguments I would use against using Linux as a firewall are: ... point of making the default installations secure (although they are ...
    (Security-Basics)
  • Re: The Stunning Failure of OpenBSD
    ... To make the long story short, request your boss to spend about US$100 from ... his petty account to get any router + Firewall + NAT + QoS, ... to replace your Linux router. ... OpenBSD proved to be more ...
    (comp.os.linux.security)
  • Re: Home Security.
    ... features necessary for a firewall (packet filtering and/or proxying). ... security, I'd recommend OpenBSD. ... Another option to try is Linux. ...
    (Security-Basics)

Quantcast