I get it, preventing local privilege escalation on *NIX is hard, and I appreciate OpenBSD's focus and stance on security, v.s. say Linus's more laid-back attitude. And having arguably fewest of them is an achievement, even if it's not zero. Let's focus on making OpenBSD better and not belittling other's shortcomings.
[0] https://zh.wikipedia.org/zh/%E4%BA%94%E5%8D%81%E6%AD%A5%E7%A...
I have an OS I coded my self that no one has ever found a vulnerability on.
The answer is a bit of both.
Side note: I'm hugely grateful for all your work on OpenBSD.
www.tedunangst.com uses an invalid security certificate. The certificate is not trusted because the issuer certificate is unknown. The server might not be sending the appropriate intermediate certificates. An additional root certificate may need to be imported.
Error code: SEC_ERROR_UNKNOWN_ISSUER
And in Chrome:
Attackers might be trying to steal your information from www.tedunangst.com (for example, passwords, messages, or credit cards). NET::ERR_CERT_AUTHORITY_INVALID
- protected from alteration of the data in transit without either end's knowledge
and, IF you have a means to authenticate the owner of the certificate outside of the regular certificate signing process
- protection from impersonation of the other end of the connection
It's just a blog; I'm not submitting anything, but still it's an indicator that something fishy might be going on.
LetsEncrypt isn't perfect either. You've got to be cognizant of what details you are sharing over the connection, regardless of who signs the certificate.
[https://it.slashdot.org/story/17/03/25/2222246/over-14k-lets...]
> You've got to be cognizant of what details you are sharing over the connection, regardless of who signs the certificate.
So why not cut out the browser errors, for free? Somehow this vaguely feels like Don Quixote straining hard to hold onto the original definition of the term "hacker".
Props to this guy for sticking to his beliefs; I don't mean for this to be interpreted as saying anything should be changed.
> Yesterday, reading this page in plaintext was perfectly fine, but today, add some AES to the mix, and it’s a terrible menace, unfit for even casual viewing.
https://lobste.rs/s/wr1oh7/openbsd_changes_note_625#c_sh1obq