Could you explain whats bad about that comparison? Or point to an example of their "rudimentary grasp of C" ?
Could you explain whats bad about that comparison? Or point to an example of their "rudimentary grasp of C" ?
Can anyone point to a paper showing where HBSD successfully prevented an attack over FreeBSD?
So they generate a lot of noise. Instead of learning from the larger communities that are filled with extremely talented security people like Colin "cperciva" Percival, Robert Watson, Theo de Raadt, Maxime Villard, etc Shawn seems hellbent on being an exemplar of Dunning-Kruger effect. Unfortunately he is towing others along for the ride.
Anyway, even there, we can read : "ASLR aims to prevent an attacker from using previous knowledge of the address space to gain an advantage and execute malicious code. This has proven extremely effective in “raising the bar” of exploitation and is one of the most significant research challenges"
So, back to square one, why ASLR is obsolete? Its one of the main security features.
Recap: OPNsense uses HardenedBSD as base OS, which have ASLR, along with other BSDs. pfSense uses FreeBSD, which don't have ASLR/ASR.
These are context sensitive things that aren't learned by reading a comment thread, if you can't read that article and understand that it shows a multitude of exploits that bypass ASLR and that almost every exploit and contest includes or relies on existing ASLR bypass I don't really know what to tell you other than to keep reading and researching. The answers you seek are linked from TFA.
I expect you backing up your statement that ASLR is obsolete. So far all we have is a URL and advice to research ourselves.
What stops you from giving a direct answer? Hint: "ASLR is useless, because I can, for example, do this: ..."