How I would sell OpenBSD as a salesperson
dataswamp.org
dataswamp.org
Microsoft/google/meta really like OpenBSD, they throw large sums of cash at it and I think it's partly because of the licensing. [1] Windows itself takes a lot of security enhancements out of OpenBSD even before Linux catches on, and I also think OpenSSH with a permissive license has been a big factor in them including it in Windows now.
Also, you surely couldn't be using OpenBSD for performance-critical applications; I love OpenBSD, but it's incredibly slow, which makes it a complete nonstarter for most applications in that space.
And it's fast enough to do batch processing of serial transactions as well as serving a web app and networking
One of the reasons I know it is slower is due to security.
With the security mitigations OpenBSD chose to simply disable SMT. It is a less performant, but much simpler solution than the software mitigations that Linux and Windows implement.
https://www.phoronix.com/scan.php?page=news_item&px=OpenBSD-...
Do you know of any other reasons?
One famous case: About 15 years ago, someone made a patchset called HPN-SSH [1] for OpenSSH because:
> SSH implements a multiplexed connection protocol so a single TCP/IP connection can host multiple SSH sessions at the same time. This means that SSH also has to implement a flow control mechanism in order to make sure that the network connection isn't overwhelmed. Much like TCP/IP, it uses a receive buffer to indicate how much data the sender should be sending at any one point. The developers of OpenSSH had initially set this buffer size to 64KiloBytes.
This capped scp/sftp bandwidth on a 10ms link to about 50Mbps. At that time no OpenBSD developers would like to work on this because... they don't have >10Mbps NICs (or link? I don't remember) so they never feel the problem.
Of course the thing eventually got fixed, but much later.
Do not accept code that you know you won't be able to maintain or test.
In my experience I think the biggest bottleneck that I've found is filesystem performance. FFS (Fast File System) is pretty freakin slow, and you should really consider redundancy options in case one of the drives fails because its tolerance for recovery from failure isn't the best. It definitely isn't the most optimal or sometimes even viable solution for when you need performance on the filesystem to be high.
Given these things though chances are a lot lower that someone finds something filesystem-level which constitutes a way to hide malicious code or whatever (For example NTFS and hiding malware in Alternative Data Streams [1] or messing around with timestamps [2], or local privilege escalation in Linux's filesystem layer being a big vector for attack lately [3] - Hell even WSL mounting /mnt/c/ as chmod 777 which can wreck some real havok in something as basic as a few lines of python or ruby like stealing your browser session cookies [4] or just wrecking your windows install by deleting system32 like a bad prank from a decade ago [5])
[1] https://www.youtube.com/watch?v=S4MBzeni9Eo
[2] https://www.sciencedirect.com/science/article/pii/S266628172...
[3] https://blog.qualys.com/vulnerabilities-threat-research/2021...
[4] https://blog.lumen.com/windows-subsystem-for-linux-wsl-threa...
[5] https://memegenerator.net/img/instances/82246172/delete-syst...
They absolutely do not have any interest in any "security" matters in OpenBSD -- Microsoft Windows and Microsoft .NET are decades ahead of OpenBSD in terms of security.
> You may think OpenBSD slow performance could hit your productivity
> Maybe your favorite software is proprietary and will not be provided for OpenBSD, then your provider is entirely at fault...
Sales really isn't for everyone....lol
Also I haven't heard great things about their mailing list. Maybe this has changed, but they're in no shape to replace commercial quality technical support.
Anyone have a good resource to catch up?
In the meantime, I recommend my perspective to anyone who asks (nobody asks): separate the OS from the dev mailing list.
It's just not a very friendly list, or at least it wasn't in days of yore when OpenBSD was relevant.
You have to realize that a lot of BSD enthusiasts are people who have let "being a *BSD user" subsume their whole identity and there's a lot of "Linux is for noobs"-style elitism.
You do realize that a very _very_ large number of us here use OpenBSD code literally all day every day?
Who do you think wrote OpenSSH? Or do you remember Heartbleed, when everyone switched or thought about switching to LibreSSL?
Just because most of us don't run OpenBSD-the-OS very often doesn't mean we don't all frequently use it's code.
OpenBSD fans like to make a lot of hay about its vaunted security posture but in real-world use cases I have no doubt that properly configured and up to date FreeBSD, Linux or even Windows Server is just as secure as OpenBSD.
There are just vanishingly few reasons to use OpenBSD today.
The documentation does tend to be pretty good, but... honestly? I just don't find that to be a compelling reason to choose an operating system.
I do feel quality documentation makes a huge difference. Navigating the broken-links craziness of FreeBSD documentation was just such a frustrating experience. And even on a "first-class-supported" system at the time, they omitted a KEY (IMO) piece of information that resulted in me being unable to even run the OS until I did hours of research on OpenFirmware and realized the missing piece in the process. I could see from online discussions that most people had completely given up on FreeBSD at the same point I reached.
Ah well, for me, I don't notice any "warts" of any sort with OpenBSD, so whatever problems other people have just don't affect me or aren't relevant to my use case(s). Such is the case for any OS, I think ppl should use what works for them. No use discounting an OS completely just because it doesn't work for your purposes :)
wheeze Windows Server??!! This beggars belief.
I'll give you a hint. It's not BSD.
https://www.wearethemighty.com/mighty-history/worst-cyber-at...
Whereas openbsd people kept that attitude, the gnu+linux people went above and beyond to help newbies. Help not only in fixing their stuff, but also in growing and learning.
And I don’t buy the “secure by default” marketing stunt. At best you’d have to put that in the context of an OS that does a limited number of things, and does them poorly (questionable ux, poor performances). Gnu+linux is secure enough, particularly so if you compare that with the incredible amount of things it can do.
As someone using Debian, Ubuntu, OpenBSD, and other OSs regularly, what I'm experiencing is perhaps less "elitism" on the BSD side, and more of: "hey, we're also here, it would be nice if you could consider us sometimes". The BSDs traditionally have different ways of doing some things, which are equally as valid, but e.g. OpenSSH considers the needs of Linux users, and provides sandboxing through seccomp[1] (which NB is quite an achievement to get right, contrast with pledge[2]).
[1]: https://github.com/openssh/openssh-portable/blob/master/sand... [2]: https://github.com/openssh/openssh-portable/blob/master/sand...
Meanwhile e.g. on the systemd or GNOME side of things, projects tend to act not only as if Linux was the only platform in existence, but almost as if any alternative or adjacent technologies had no right to co-exist either: e.g. when GNOME told SDL2 developers to link against GTK to draw native window borders under Wayland[3]; or as systemd continues to swallow every traditionally discrete UNIX service, such as cron or syslog, and tries to shove DBus into the kernel. This is a stance that I'd expect from Apple (who are shipping an opinionated but highly polished and desirable product), not an open source community, where value emerges from collaboration.
[3]: https://gitlab.gnome.org/GNOME/mutter/-/issues/217
Of course there are plenty acts of both generosity and jackassery in all of these communities, however the picture you're trying to paint is a bit unfair.
Poettering hates everything that he hasn't touched. This is well-known and why anyone that cares about Linux and what it stands for should not use any OS that is infected by his projects.
Gnome 3 isn't worth the price of Systemd.
My experience is limited, but I really liked it. Didn't end up sticking with it for very familiar reasons - lack of http3, third party shitware that it's sometimes convenient to have for work, hardware support. But as a pure OS I thought it was miles above linux. Things fit together so well. And the docs! First time I'd ever read man pages so good that I took notes.
In an alternate reality, where Linux was an obscure OS and OpenBSD got all the love from third party vendors, driver writers, etc - the world would be a better place.
Could it be because NetApp builds products with it?
I did enjoy running it on my Lemote as a curiosity, but that port is dead now...my favourite part was the variety of arches it officially supported.
Again, as I stated in my comment, it's made for OpenBSD devs and that's fine - I hope they continue developing.
And if software, or hardware X is not supported, go do it, or get supported software/hardware instead.
"The bad news is that OpenBSD for the past 2 years has turned a loss of approximately $20K USD ($40K total). I don't think I need to explain in many words what that is doing to our beloved OS, and worse, our main systems architect. This is starting to seriously impede the development of OpenBSD and OpenSSH...
"What I want to point out what a lot of people don't seem to realize is that OpenSSH development is paid from the same pool of money as OpenBSD. OpenSSH is in use by millions around the world however the revenue stream just simply isn't there."
I will say FreeBSD is stellar with ZFS and XFS is very very stable these days - even btrfs functions as a decent ext4 replacement.
systemd can put your booting in an infinite loop instead, true progress.
Or, at the other end, systemd causing an infinite loop preventing shutdown.
Not to mention the pain in between.
If you just launch into a scripted speech rattling off features, I don't think you'll have much success. Are they having problems with GPL-licensed code? Why not FreeBSD, then? Maybe they have special security or compliance needs. Does OpenBSD solve those needs in a way that nothing else does?
I recently upgraded to a new router hw, which meant scrapping my old OpenBSD 6 and jumping straight to OpenBSD 7.1. One of the tasks was actually to renew all my old rules that had been hanging around from much older releases.
While doing this I noticed my old rules referenced lo as the loopback IF, but it's clearly called lo0.
Anyways, that was just one tiny detail. But I must say the rules did work out of box with 7.1, nat, port forwardings and openings all worked. All I did was set skip on lo so maybe it didn't matter so much. And maybe I can reference lo* with lo? Not sure.
Either way the handbook is what backs up point 1. Sure when you search for an issue in OpenBSD your search results are miniscule compared to Linux, but on the other hand there are no out of date guides or documentation sites, it's all in the handbook. The final say so for all things OpenBSD. That is definitely a strength. But I don't think you can say that OpenBSD is completely immutable.
You were using interface groups. The loopback interface, lo0 is a part of the lo interface group.
https://man.openbsd.org/ifconfig#group
When upgrading avoid long jumps, and always read the upgrade guides, they cover important changes between releases.
If someone has a keen eye for manipulation they might perceive this approach as deceptive though.
Still if instead of pushing a narrative you get the buyer to discover their fears within themselves I think this would be a good approach.
I guess like everything else the solution has to be tailored to the problem for maximum effect.
Change the name to FooCorp CyberBattle Platform Appliance, and put some sort of fancy front end or whatever.
Don’t sell benefits, sell what problems your product solves that the buyer has.
The sale person needs to talk to the Corp Legal IP team.
For example, during 6.8 to 6.9 upgrade, there was a major postgresql upgrade.
It is mentioned in the doc https://www.openbsd.org/faq/upgrade69.html (see Special packages at the bottom).
You're redirected to the package README with special instructions on how to setup and upgrade: https://github.com/openbsd/ports/blob/master/databases/postg...
Et voilà, everything is explained.
On debian, if I am not careful, I'll do an upgrade and risk breaking something during a db migration (I'm looking at you MySQL upgrades...).
Unless you deliver a working patch for the bug you found they're more likely to tell you to piss off.
A question? Lol, no we don't answer those here.
No mandatory access control, in the year 2022. Unimaginable. Only a fool would bet his business on this mess, and only a thief would take his money.
Does this count?
But it's a project for supporting the development of OpenBSD's hypervisor technology, not a production platform anyway.
Bro we dev this in Brasil nobody's going to nuke us here
I was using OpenBSD as a daily driver on my thinkpad for a year and a half. The motivations driving me to switch back to Linux were:
* slow -- can't use hyperthreading because of developers' security concerns with that technology.
* no Bluetooth support
* can't use Discord's electron app, meaning no screen share
* NTFS write support needs FUSE which is extremely slow. I worked around it by using exFAT which is fast
sysctl hw.smt=1Net/OpenBSD still mostly caters to the needs of hobbyists, I seldom see them in production (besides maybe network appliances).
Email me at aaronm04{at}iforgotmy.name if you want help.
The nice thing with Dockerfiles and the Docker registry is how quickly I get a reproducible, stateless, isolated environment for any large, proprietary or foreign app I may need, without resorting to a VM or polluting my system. All it takes is an Ubuntu or CentOS base, pull the apps and its dependencies, throw it away when I'm done while keeping a lean Alpine system underneath.
Jails would require me to set things from scratch each time I need a new app, even for a short while. It's just impractical.
I'm considering Nix as a potential alternative, but it doesn't work on the BSDs yet. If you know a way to run "modern workloads" in a KISS, convenient, Unix-y way, please let me know.
My "builds" are also reproducible. Why? I run the same build and deploy script each time. Wow.
For me this all is old wine in new pipes. Cold coffee. Registries.
Agree about NTFS-3g, it's next to useless. I've read somewhere that some optimizations are not enabled on OpenBSD.
Still, I like it and use it on my laptop and servers. I'm 100% in line with the first point of TFA : learning OpenBSD is a good investment, you feel that you steadily build up an coherent understanding of the system.
If the only issue with bt is sound, there are some usb dongles that are recognized as a sound card and do the bluetooth part outside of the OS. You have to trust the manufacturer though. If there are other requirements such as file sharing, they usually can be done easily another way.
I am not sure who and why would anyone using openbsd want to mount an ntfs filesystem on a regular basis to do large transfers.
IIRC the Discord webapp didn't have an option to share the screen. I only tried Firefox not Chrome.
> If the only issue with bt is sound, there are some usb dongles that are recognized as a sound card and do the bluetooth part outside of the OS. You have to trust the manufacturer though. If there are other requirements such as file sharing, they usually can be done easily another way.
True. I only have 2 USB ports on this laptop though, so it would have been an annoyance.
> I am not sure who and why would anyone using openbsd want to mount an ntfs filesystem on a regular basis to do large transfers.
My use case was copying video files to an NTFS flash drive. I'm not sure how common a problem it is for desktop/laptop users.
sysctl hw.smt=1https://dataswamp.org/~solene/2022-06-22-openbsd-selling-arg...
;)