Some OpenBSD features that aren't widely known
dataswamp.org
dataswamp.org
overall such a solid operating system. learning about it pays off quickly because they don't change things often, and your knowledge will be applicable for decades to come.
I also have this fear that Linux is gonna rot if Linus Torvalds dies or retires, so it's good to have a nice, clean alternative waiting in the wings.
between hdmi 2.1 and zfs he’s basically single-handedly reverted more useful, basic features and code than anyone else on the kernel team, all in the name of… DRM’ing symbols that have been “”mis-licensed”” for decades?
doesn’t really seem like a fight he had to pick, or anybody asked him to pick - the status quo was adequate for everyone involved (including users).
so why is that guy being in charge of Linux a good thing?
doesn’t seem that complex to not go around starting trouble when the status quo is stable and fine. Maybe Linux just appreciates boat-rockers more than the Unix world though - there are no Poetterings or GKHs eagerly churning everything in that part of the world.
BSD ++
openbsd has no blobs, only firmware, executable software that runs on the device chip. It still sucks, but there is a difference.
(Microcode, I guess, is one other category)
Linux, as it stands in terms of security, is an absolute joke. Historically we have Torvalds calling every security conscious user a master-debating monkey. And even more recently (few days ago) we got the LKML / CVE process debate - under which logic anything could technically become a security bug so we should drown ourselves in CVE because it isn't our job to think about whether something might be security relevant. This seems like a bad-faith argument from the Linux community - and I hope they lose it.
Docker ... is really just a bit of glorified buggy networking around namespaces/cgroups. I still remember the days when the docker documentation asked users to curl random sh&it into | sudo bash while talking about the security-benefits totally without blushing. Dockerhub has always been the petridish of choice for malware across critical infra and supply-chain attackers. Yet the community pretends Linux security is great while Windows security is terrible. That old meme was true 20 years ago. Today even Microsoft as shit as they are are miles ahead in terms of Linux security.
Linux is great in embedded domains because here nobody cares about security. What is left then is cloud infra which security-wise is a joke as we all know.
BSD understands that complexity is the enemy of security. And Linux essentially offloads any responsibility for the mess they create to the users. This is also because Linux still considers itself as just the Kernel. BSD has more control and is able to keep the entire system logically coherent (and secure). Linux security in comparison is best described by Grugq's slide nr. #35 of his "COMSEC beyond encryption" talk: https://grugq.github.io/presentations/COMSEC%20beyond%20encr...
man 8 accton (https://man.openbsd.org/accton.8)
man 8 sa (https://man.openbsd.org/sa.8)Vendors of RAID/SCSI/SATA controller are unable (and more often unwilling) to make it work in Linux ... together.