"Secure by default" would be most meaningful IMO when describing a "fat" OS with services and such already enabled, and configured securely.
OpenBSD's "secure by default" is nice and useful so far as you can trust it's extremely unlikely someone will be able to nail you with a 0-day when you're doing your OS install and early setup, but that's the biggest part of that.
Not to say OpenBSD doesn't do other secure things. I'm just not impressed by their claim of "secure by default".
This is an unbelievably absurd statement. What do you mean it doesn't """do""" anything? I can boot up my openBSD desktop machine and write computer software, edit graphics, play media files, etc. Basically anything that you would want a computer to do.
Before that computer starts interacting with other computers over the network however, I generally have to ask it to. That's GOOD.
Some people will be okay playing uncompressed WAV and Sun AU files cat'ed to the audio device. Other people are going to want to play other audio formats.
This kind of reasoning is a bit reductionist. Sure, as long as my computer has a compiler and basic interfaces, I can "do anything that you would want a computer to do", given <x> amount of work on my part to re-implement the functionality I want.
Unless I want to write my own MP3 decoder, though, I'll need to install 3rd party software from ports.
> Before that computer starts interacting with other computers over the network however, I generally have to ask it to. That's GOOD.
Right, it is -- but most linux distributions also don't start a lot of network services. Linux has had a few more TCP/IP stack vulnerabilities than OpenBSD, but not many. And of course (mostly) Linux distros uses OpenBSD's SSH package.
Your empty Linux install and empty OpenBSD install will, from the network, appear mostly identical. And the bug in Firefox that pops a shell on your system likely won't be either Linux or OpenBSD's fault, but Firefox's.
While that is mostly true today, it certainly didn't used to be. Back when OpenBSD was really earning its security reputation, a default install of Red Hat would be rooted almost as soon as you connected it to the internet.
But if mg has a bug allowing malicious files to run code, then this won't increment the"remote holes in the default install"-claim, just to name an example.
If I go to the CVE database and search for "Windows 10" or "FreeBSD" then I might find 200 security holes of varying severity, and people will say "Windows 10 has had 200 security problems" Not all those problems will affect everyone, but this is the common-sense way most people would understand it.
But OpenBSD has a subtly different definition, and I think this subtly distinction is lost on many. I have nothing against OpenBSD and generally like it, but I always found this claim to be a bit misleading (even though it's technically correct). It's not a meaningless metric though; I remember installing Windows 2000 back in the day and it had malware before I could install the updates. But it is a very incomplete one.
It might not seem like a huge claim now, but it was actually extremely influential and operating systems now ship with inessential services turned off.
It’s technically correct, but a meaningless metric :P
OpenBSD doing NOTHING by default is exactly what I want. Somebody said that sshd starts by default, but actually it doesn't unless you specify that you want it to during installation.
When you finish an openBSD installation, you are presented with a fully functioning system that will boot up to a shell, which has a networking stack available, and will allow you to then install the things you want.
That's what I want a computer to do. I don't want it to start up the kitchen sink unless I ask it to.
True, but that does not have anything to do with the metric.
For example, see https://xkcd.com/641/ . Cereal being asbestos-free is definitely a good thing and "exactly what I want". Yet, people will complain about that advertisement.
Or "No vulnerabilities in the webservers turned on by default^1. Also, all default-enabled webservers are giraffes."
1: There are none, so this is true.
Adding 3rd party packages sure: you’ve left “default” behind, but ones installed by the OS? They count imho
This was a contrast to a fresh install of Windows which would get infected within minutes of being connected to the network (I'm assuming this is no longer true, but have never used windows).