What every IT person needs to know about OpenBSD
bsdly.blogspot.com
bsdly.blogspot.com
Unixy goodness. Secure. Consistent. Excellent documentation. Makes a great firewall, vpn, and/or router.
Makes a great desktop as long as you can live within the open bsd package/port ecosystem, which includes much/most, but not all, open source / linux software [0], and choose compatible hardware, thinkpads when in doubt.
A handful of years into openbsd on a couple thinkpads and a vps and I'm very happy. I'm a tech guy who prioritizes simplicity, security, and minimizing surprises. More of a minimalist than I used to be. Openbsd documentation is fantastic [1]. I've had less upgrade problems over the years than with freebsd and linux systems I've run in the past. I've got scripts that configure everything on my systems, via shell commands and /etc files. Unlike a windows pc or an android phone I very much feel like this is MY computer.
Openbsd might not be for those who have to have their netflix drm or steam or adobe icloud stuff on the same pc they use as their general purpose personal computer. Depends on your priorities.
[0] http://ports.su/
On a fresh install I find myself always copying a couple dot files, editing a couple /etc files, etc., knowing there must be a better way. :)
#!/bin/sh
# TODO: install openbsd, from prepared usb or ethernet
# full disk encryption, openbsd.org/faq/faq14.html#softraid
# accept install defaults, including disk layout
# update operating system (if needed) and firmware
if [ "`syspatch -c`" ]; then syspatch; fi
fw_update
# update /etc/ntpd.conf, remove google entries
sed -i '/google/d' /etc/ntpd.conf
These scripts start as a lot of TODO entries that I'd have to manually follow when setting up a new pc. But over time I replace my TODO notes with actual shell code. Nothing wrong with having to manually do a few steps if you don't have time to automate everything. I never planned on trying to automate the bsd install to encrypted disk, for example. For quite a while mine seemed mostly manual, copy pasting shell commands for some of the steps. Now it's mostly automated, with a few manual callouts.It's easy to put the steps in order, and natural to configure the operating system before your home directory. I ended up splitting these into separate scripts, then eventually smaller component scripts in directories. So now I have a master ~/bin/setup/setup.sh script that autodetects the system (based on vps ip or laptop ethernet mac) and calls the correct componenant scripts, like pc/audio.sh, pc/pkg_add.sh, openbsd/etc_myname.sh, openbsd/etc_xenodm.sh, home/ dot_fvwmrc.sh, and so on. Each of these component shell scripts can update config files, enable daemons, copy things, etc. I made functions for some of these things. I can pass arguments to component scripts or set environment variables, for things like ip addresses and usernames. Minimally you need to be sure the automated scripts are idempotent, meaning you can run them repeatedly without harm. Things like trapping errors and testing in qmenu would be good. A lot of it is easy, copying in a file or appending to a file, running a chmod or rcctl command, etc.
It's nice to have this master copy of all my config. When I want to change something I edit the appropriate setup script then re-run it to push the change.
I wondered how linux stacked up, outside of the mentioned MAC capabilities, but the article was more focused on openbsd. How much does MAC buy if I don't notice that I've outgrown the granularity of normal file system permissions? I know that does often come up in environments with more users.
Do you think openbsd has worse security than normal linux? (not selinux)
My next planned security update is to attempt to separate apps that need network access from those that do not. I'm still brainstorming on how to best do this, maybe leveraging the ability of the pf firewall to allow/deny traffic by user account.
Android's surveillance is mostly in stock android and other derivatives, but not in AOSP; AOSP has no Play services. GrapheneOS is a downstream ROM that adds further hardening and privacy enhancements.
I view MAC as quite essential. On top of that, Clang on Linux supports sanitizers like CFI, safe-stack/shadow-call-stack, and a few others; check the Clang docs for more info.
Linux supports dm-verity which can help ensure the integrity of the base system, and can combine with UEFI Secure Boot for getting some of the way towards a fully verified boot.
I also don't know of a USBGuard- or kloak-equivalent for OpenBSD. USBGuard is essential for physical security regarding removable media, and kloak anonymizes keystroke input.
There is no OpenBSD web browser that's remotely secure; they all use Linux, macOS, and Windows sandboxing/hardening measures. I never enable JS in obsd; if I absolutely must, I run the browser in a VM and disable JIT.
My biggest easiest takeaway may be a reminder to remain portable, in case I want to switch to another os at some point.
btw, I'm with you on disabling javascript. I make exceptions for only a few sites, like banks, and duckduckgo. I pretty closely followed this guide [0] on configuring firefox, disabling all kinds of things like hw acceleration, wasm, fonts and javascript via ublock origin, etc.
[0] https://12bytes.org/articles/tech/firefox/firefoxgecko-confi...
Note that this will make you quite fingerprintable on sites with JS enabled. I'd rather split browsing across three browsers: one heavily neutered FF with the above prefs and my own personal customizations, one chromium (built properly with all mitigations, i.e. using is_official_build and not a distro package) for secure JS-enabled browsing (jitless and with all telemetry disabled/blocked, of course), and the Tor browser for anonymous browsing. Avoid ungoogled-chromium; its patches significantly weaken the browser's security by disabling component updates, and you'll have to build it yourself if you want all the exploit migigations included (since none of the available builds are built properly).
I'd avoid extensions if at all possible since they very heavily weaken the browser security model. Chromium lets you enable extensions on a per-site basis, which I find helpful. Extensions that inject content also make fingerprinting quite trivial: without any JS I can uniquely identify, e.g., a Canvas Fingerprinting Defender user by eyeballing a CSP report log against an access log, no JS needed.
I never heard of eBPF before. Is that like dtrace? I gather there was some working on adding that to bsd. I haven't missed not having either of those. Maybe more for lower level coding?
The simplicity, consistency, and documentation are a bigger deal to me. I realize needs and preferences vary.