Maybe this isn't the best place to ask this, but how does OpenBSD handle "real world" security these days? Last time I checked, OpenBSD was heavily audited, with emphasis on shipping a secure base system. The problem, to me, is that every running system in the world has many packages installed to make it useful as an e.g. server. What use is a secure base system if installable packages aren't audited to the same degree? Debian handles this by putting all packages (apart from universe) under the maintenance of the Debian Security Team. I would love to use OpenBSD, but want to make sure that the extra effort isn't spent with no real security advantage.