OpenBSD will shut down if we do not have the funding to keep the lights on
marc.info
marc.info
There is "opinionated software" and then there is Theo being an intolerable, obnoxious, ego-maniac.
As such many people are going to see this and laugh and think "good riddance", and will be happy to see OpenBSD disappear.
That will only be enhanced by the fact the books are closed, the shortfall on the electric bill is inexplicably $20k, and nobody is prepared to explain the detail.
In essence rudeness + shady accounting practice != open source community that should feel a sense of entitlement from non-core users
It's a shame because the code (especially the crypto code) is really good. Seriously, go read it: I used to love reading the OpenBSD source, but I never contributed anything because Theo was such an absolute jerk.
I hope the guys who work on the crypto stuff at least either keep doing so elsewhere (Free- or Net-), or a new project without the need for $20k in electricity bills spins up to keep going.
I genuinely believe my non-tech friends and family have such a poor approach to security, because the people who have a good approach to developing security tools have such a poor approach towards my non-tech friends and family.
I use OpenSSH every fucking day.
I'll take the insults. And apologize to the idiots. And pitch in when I can.
Honestly, Theo can be an asshole, but often his temper is warranted when he's faced with idiocy, like when RMS was unapologetically trying to persuade the removal of all mentions of non-free packages in OpenBSD. (http://article.gmane.org/gmane.os.openbsd.misc/134850)
I know this is what RMS does, and actually I'm sympathetic with his views, but in that context it was bullshit. This is just one incident, who knows how much Theo has to deal with other people wasting his energy on non-issues, trivialities and misconceptions?
For what it's worth, he isn't any less of a dick than Linus. Yet Linus consistently earns hero praise and adulation, the criticism of his personality being secondary and written off as justified. So why isn't Theo's justified?
I don't know the full history of that thread, but it's not mentions of non-free packages that RMS was talking about - it was ports in OpenBSD that allowed people to easily install non-free packages.
Ah, found the original: http://marc.info/?l=openbsd-misc&m=119730630513821&w=2
And FWIW, I think Linus is a dick, too - but Linux has a much larger following, mainly due to reasons other than Linus.
Quick back-of-the-envelope: At $0.12/kWh, the shortfall is about 20kW of continuous power.
Do they have significant HVAC requirements? I don't think I see 20kW of iron in the two racks that get pictured.
On top of the electricity for the servers and for cooling, there is also maintenance: replacing ancient drives and other system components when they fail (which may require paying out the arse for some gear on eBay), fixing cooling equipment (ever replaced a dead AC unit in your house?), network maintenance and upgrades, internet connection, etc., etc. The list goes on and on. $20K seems reasonable to me. He's not asking for $20MM or even $200K, guys. He's not mining bitcoins. Please be reasonable.
It's requires 1/3 of a watt. For every watt of heat you need 1/3 of a watt of cooling. (For typical A/C's.)
Linus is a jerk towards experienced maintainers. Theo is a jerk towards everyone. There is a big difference.
I can't be bothered to look for it right now, but there was an email on lkml where an inexperienced contributor basically asked "should i just give up?" and Linus chipped in with quite a friendly manner and mentioned how important contributions from everyone were to the project.
Plenty of us have had positive interactions with Theo.
What do Theo and the project have to hide, exactly?
Really? Could you give me an example of that? Because from where I sit, as someone having been around the openbsd world for ~15 years, I don't see it. I see lots of people bitch about it, but never any examples of it actually happening. It is just something people seem to assume will be taken as gospel.
I offered help and enthusiasm for the project. He called me a lot of names and suggested OpenBSD wasn't for people who weren't like him.
That's just me. Fine, I'm a big guy, I can take it. But I then watched for months as he did the same to countless other individuals. Newb: "Hey, we could do 'X'" Theo: "No, go away, I hate you", is pretty much the tone.
Then there is the more public stuff. The stuff that is historic but a little larger.
He created OpenBSD because the NetBSD core ousted him for his attitude and demeanour towards other developers.
There is a whole section of his Wikipedia page dedicated to his "Outspokenness" which is a polite way of calling what is actually his "Obnoxiousness":
http://en.wikipedia.org/wiki/Theo_de_Raadt#Outspokenness
Nobody doubts he can write code, and that OpenBSD - and OpenSSH in particular - was a bonus to the open source World, but my point is that he and his inner circle are hostile to the rest of the community who aren't quite like them. It's a clique.
And cliques can't ask outsiders for help once they're established: they made up the rules, and they will live (and die), by those rules.
Theo had a choice: compromise, and be nice to people and understand other people's needs; or, don't compromise and be a bit of a jerk and piss people off but stay true to your own values.
He chose the latter. Fine. He should not be surprised that they are not running to their wallets when he needs $20k for electricity bills to continue running the project in that same way.
I'm not being rude about this, I'm being pragmatic. I don't particularly want to see OpenBSD die, but I can't see many people rushing to save it, and that's because the top hierarchy are perceived as - and are documented as regularly behaving as - complete jerks.
If Theo had been a little more temperate to more people, it's quite likely his $20k (and then some) would have been raised in under an hour. I know some FreeBSD guys have raised similar/larger amounts for smaller projects in the past within a day or two. How? By being nice people that other people want to support.
The mailing lists are all archived. Show me the link. The whole point was I hear bullshit stories all the time, but having been on the lists for over a decade, I know they are bullshit.
>but I can't see many people rushing to save it
Nobody cares what you can see. You just want some excuse to push your weird vendetta. Plenty of people are quite happy with openbsd, don't care about your imaginary problems, and have coughed up the $20k.
I only ever had a few email exchanges with Theo. One was a bug report and the other was a few questions for a project I did while studying, but he was friendly and helpful. Even if Theo had been a jerk, that doesn't change the fact that I've gotten a lot of value from OpenBSD in the past, without being asked for anything back, until now.
The closed books doesn't really bother me, I doubt that Theo or someone at the OpenBSD Foundation is going to run of to Cuba with the money. Maybe we should just accept that the people that they are asking for help are people like me who see a value proposition in: I give them €20 a month and OpenBSD doesn't go away. Only takes 1000 people like me to solve this and surely there has to be 1000 people in the world for who this is a great deal.
(I've interacted with Mr deRaadt once. He was perfectly lovely and helpful.)
Theo provides negative value. There are no circumstances (least of all extortion) that would make me give him money or aid of any sort.
> (I've interacted with Mr deRaadt once. He was perfectly lovely and helpful.)
Most of us will never know. His public attitude has ensured that.
It's not like we're talking about Wagner's antisemitism vs his music here!
They're more or less the same thing, one is how you see people you like, the other is how you see people that rub you the wrong way.
[scott_s@local ~] history | wc -l
500
[scott_s@local ~] history | grep ssh | wc -l
191
Donated.I don't think it's going too far to say that companies making heavy use of (i.e. profit from) OpenSSH are obligated to donate.
$ history | grep -c ssh
380
Donated.http://www.gnu.org/software/bash/manual/bashref.html#index-H...
you could also have a look at HIST_FIND_NO_DUPS and HIST_IGNORE_ALL_DUPS (more options at http://zsh.sourceforge.net/Doc/Release/Options.html )
If you still use bash, now is a good time to upgrade to zsh
I'm a zsh user but am surprised that you guys are still using sourceforge instead of github.
Sorry, couldn't resist.
[0]: https://www.crowdtilt.com/
[1]: http://www.crowdhoster.com/
[2]: https://www.crowdtilt.com/campaigns/please-help-the-internet...
For example [1], [2]
I encourage all to donate to our BSD friends. We all benefit from their work.
[1] https://www.freebsdfoundation.org [2] http://www.netbsd.org/donations/
They've raised almost 750k the last time that page was updated..
Does any Open Source license require monetary donations from companies using the code?
Sony and Apple and a lot of other companies using BSD licensed software DO give back -- in the form of code and employing developers to work the projects.
Sony, IIRC, employed some Japanese committers who were working on ACPI at one point.
https://https.openbsd.org/cgi-bin/order
Having just donated I would like to say that the man pages are wonderful. I like them so much that I have a oman alias and made a quick (and dirty) script to fetch them.
https://github.com/ninjin/ppod/tree/master/hck/openbsd_manpa...
Try them out when coding C or when writing portable shell-scripts, they are a blessing. There is also the official web interface:
Initial ask for help: http://marc.info/?l=openbsd-misc&m=138730448307723&w=2
How much it costs: http://marc.info/?l=openbsd-misc&m=138972987203440&w=2
Why old hardware platforms matter: http://marc.info/?l=openbsd-tech&m=138973312304511&w=2
Why not kickstarter: http://marc.info/?l=openbsd-tech&m=138973837906139&w=2
And most importantly, the donation link: http://www.openbsdfoundation.org/donations.html
Nevertheless, I donated $50 just for the excellent work they do on OpenSSH.
> Date: 2013-12-17 18:20:48
It just took a month to have this thread on HN (there were others).
> 20 thousand dollars in electrical expenses [annually?]and there's no way that overcoming those logistical reasons would be cheaper than $20,000? at all? okay, well then, I guess that limits your options doesn't it.
I can well imagine that there would be a lot of difficulty in moving an large eclectic collection of old machines into a modern data center, and that such an undertaking might be extremely expensive.
(I don't actually know what they currently pay)
If it wasn't for those three elements coming together, we wouldn't give a damn.
It's not a strangely large sum for what they need it for.
Anyone want to suggest we hold a bake sale?
It's funny to hear this sort of thing from someone trying to accrue $20k in donations. Yes, many people will give bad advice. No, you don't really get to complain about it when you are asking them for large sums of money.
If you can't turn it off, don't be donor facing.
Oh look, now they're asking for $40,000
"oh Look here's a poor idiot in the Mailing list that didn't become a UNIX expert before asking a question, let's flame the shit out of him."
Alright Let's collect some money. Wanna know why? fuck you it! It just needs to be this way. Wanna help or suggest a solution? fuck you unless it's a check.
How is this system not working?
"They probably are doing the right thing because they are who they are" isn't really a valid argument.
>Now, If you don't realize this is the reason we try to run on the older platforms, I am sorry but you have really not tried to stay in the loop of what makes OpenBSD a vibrant ecosystem. If you aren't in the loop regarding this, then your mail comes off pretty darn preachy.
>I really love how we keep getting advice. >Anyone want to suggest we hold a bake sale?
A simple no answer would do. Or maybe just the actual reason he runs the VAX.
Being nice to stupid people is as much of a skill as hacking up some kernel code.
What we can rely on it being is technologically awesome. What else can you say that about? If you try to change the culture of OpenBSD, assuming that's even possible, the quality will inevitably suffer.
Could you honestly say you'd prefer OpenBSD to be more like Ubuntu?
As for technically awesome, we are talking about a 'modern' OS that has poor support for multiple cores (servers will only have one core -theo), runs poorly inside a hypervisor and doesen't work as a hypervisor. An OS that does't support any of the newer types of file systems like zfs or btrfs. These things aren't strictly necessary, but that's kinda where things are headed in the server industry.
The code for the OpenBSD kernel is really clean and simple. It is well audited, but has half the security features of something like linux. This is a great approach if you don't stray to far from the kernel, but if it's not a firewall it might need a browser, java and or flash.
I think I am being realistic. It doesn't seem crazy that they could go on a fundraising binge, and get/hire some busines/PR/fundraising help that allows them to really meet their goals in the future. I'm not talking canonical money but you know 3-400k to power the servers and pay a couple people. That's a long term solution. We can all donate, and buy our disks but we'll be back here in a year.
I'd rephrase that as 'finding simple tasks peripheral to the main effort that would allow non-expert people to contribute time to the project without detracting from the main work'.
We wouldn't even need a very good one. I bet some kid still in school, studying PR, would do a better job than Theo.
The guy is infamous for being one of the most aggressive, sarcastic and trollish OSS developers out there. He's been like that for 20+ years, he's not going to change just because they are 20 grand short.
Part of the success OpenBSD has enjoyed is in fact due to this uncompromising attitude: Theo pushed hard against security-by-obscurity, binary blobs, undocumented proprietary hardware and poor development practices. With openSSH, they pretty much set the bar for security-related programs the wotld over.
At the same time, Theo's personality routinely drives away a lot of very capable developers and users, which limited the overall popularity OpenBSD could ever reach.
It would be nice if we could all work in an environment where we could be abrasive as we want and still get paid. But this is life and not many people have that opportunity.
If Theo want's to put up a fight about blobs and proprietary hardware, he should do that. Talking down to people who genuinely agree about his goals and are trying to help is really self destructive.
"If you chose to assert your ego in any number of ways, ``I am going to do it my way,'' you pay a small steady price throughout the whole of your professional career. And this, over a whole lifetime, adds up to an enormous amount of needless trouble."
"I am not saying you shouldn't make gestures of reform. I am saying that my study of able people is that they don't get themselves committed to that kind of warfare. They play it a little bit and drop it and get on with their work. "
If your code is wrong, I'll say it's wrong. I won't say you are an idiot, I won't make comments on your background and I won't judge you when I should be judging your arguments. I'll point what's wrong and why I think it's so and I'll welcome you if you prove me wrong and adjust my views accordingly.
Excessive abrasiveness is not a good trait for a community leader.
It's a shame people don't talk as much about his tireless dedication to an important but relatively small open source project. He really is one of the true open source heroes.
Attitudes like this are a big part of why I am far happier to run a for-profit business at near-breakeven than I am running a not-for-profit or cooperative enterprise.
$20K is... rather less than what my RHEL bill would be if I was using RHEL and not CentOS.
I mean, I'm a pretty small shop, and $20K is a lot of money for me (thus I'm using CentOS and not RHEL.) - but by the standards of a whole operating system? twenty grand is small potatoes. Hell, /my/ power bill is rather more than $20K a year.
> The OpenBSD project uses a lot of electricity for running the
> development and build machines. A number of logistical reasons
> prevents us from moving the machines to another location which might
> offer space/power for free, so let's not allow the conversation to go
> that way.
I don't understand this comment. If the choice came down to moving versus shutting down entirely, why is moving an unacceptable answer?Isn't he in a better position to decide what's unacceptable than you are?
That being said since OpenBSD is all about security maybe that's the reason they don't want to move the servers to some place where they won't be able to monitor physical access to the machines. That's pure speculation though.
It's not a big deal, and I don't expect him to go into detail. He just won't get a cent from me without elaborating, and that's OK. I'm not mad, and I understand he has mis-givings. I just don't think that answer is acceptable enough for me to donate, but that's my subjective opinion (and not everyone else's).
The more transparency you have in your discussion, the more supportive people will be.
I think that's total, obvious nonsense and if you need to be convinced, here's an exercise: consider how much money the average nonprofit would raise if people knew where all that money went.
Because every US nonprofit is required by law to do that. You can browse it all on line: http://foundationcenter.org/findfunders/990finder/
The web is bringing a lot of good transparency to nonprofits but there's still a lot of repugnant wastefulness and avarice that often isn't captured well by a 990 form. (publishing salaries is pretty huge, though)
I stand by my point that the more a person learns about the average charity the less they're going to want to donate... transparency doesn't magically lead to supportiveness. And wanting a project to account for every watt of electricity is just completely silly.
edit: transparency is a way for better charities to look good relative to poor ones, yes, but all things being equal, it's a negative for fundraising: as with business and government, a lot of what goes on in ANY organization is ugly to look at and is bound to turn some people off. (none of that is an argument against transparency itself, let's just not kid ourselves about its usefulness for raising money)
Transparency is critical.
I'm sure there are some people with unrealistic standards that would not donate at all. And I'm sure that there are plenty of organizations that take advantage of a lack of transparency to do dubious things. But the solution to that is more transparency. And more analysis of the transparent information, so that people can easily contextualize it.
Apparently, there isn't very much documentation/open accounting, and they aren't willing to discuss options to reduce the bill. That doesn't inspire confidence.
It is a lot of work for a small team to itemize and publish every expense, but some rough breakdown of monthly expenses that my donation would be going towards would really help.
OpenBSD releases quality software that all of us use EVERY SINGLE DAY as far as I'm concerned Theo can take the money and buy a yacht with it as long as they keep doing what they are doing.
Also keep in mind that a lot of contributors might not use OpenBSD, yet they might be interested in offering some small amount if they believe it's for a good cause and they know where that money is going.
So your feeling is similar to that toward a homeless dude? You'll give him a sandwich but not cash? If they're saying power is the shortfall, maybe we just need to buy them some solar panels or wind generators or something.
Of course, if an IBM/Apple/Google/etc offers space/power, it may be a less risky proposition.
It seems likely that they don't trust anyone else to have physical access to the machines for security reasons. Their threat model probably includes national governments.
My first "real" job was in the mid-90's; I was the first technical hire at a small Chicago ISP (EnterAct) that grew into a relatively large ISP (when I left, we were default-free peered to several tier-1 providers and had more POPs than I can name). It was great, and the team that started it --- two Big-5 accounting firm programmers --- was inspiring, particularly when it came to business strategy.
Anyways, very early on, EnterAct managed to maneuver into a reputation for premium customer support. We got that reputation by doing some concrete things differently than our competitors: we staffed an appropriate number of CSRs, trained them to be nice to customers, did a lot of gratuitous tech support for basic computer problems, and were flexible about resolving billing disputes. Sadly, a lot of those things were differentiators at the time. A couple years in and we were essentially able to hang "best customer support" on our list of features, and eventually we became the most popular ISP in Chicago largely based on that.
But something I came to notice pretty quickly: the things we were doing to earn that support reputation stopped being empirical differentiators pretty quickly. Our largest competitor, run by Karl Denninger, did us a continuing series of favors by pissing off their customers. But other large regional ISPs pretty quickly learned not to set fire to their customer base, and, by the end, I think our customer service was pretty much at par for the whole area; we were no longer truly different based on support. The reputation, however, never left.
That observation has stuck with me for my entire career. I think about it all the time. It's banal, I know: "early impressions count a lot", but there's a little more to it than that: you can weaponize an early impression by turning it into your market positioning and having some message discipline.
I left EnterAct for a job in Calgary with a company called Secure Networks (SNI), doing development and security research. For the year prior to leaving EnterAct, I had also been working with the OpenBSD project, mostly by writing all their security advisories, but also doing a bit of part-time security research. SNI operated the world's first commercial vulnerability research team, and had a very close relationship with Theo; we had a full time employee who had essentially led the first OpenBSD security audit. I went drinking with Theo many times, and vividly remember hanging out in his basement with Tim Newsham eating bad pizza and trying to find vulnerabilities in Daniel Bernstein's qmail (we found one that would work if integers were 128 bits, but ironically missed the LP64 bugs that Georgi Guninski found; it was 1997, though).
This is all a long prelude to a simple point, which is that I think OpenBSD's reputation for security works in a very similar way to how EnterAct's reputation worked. OpenBSD started doing something very different than FreeBSD, Linux, and (particularly) NetBSD: they did an OS-wide audit for vulnerabilities, and aggressively fixed apparent bugs whether or not we could demonstrate that they were exploitable. That was a great move. But it was so obviously great that pretty much everyone (with the possible exception of NetBSD) quickly adopted the practice.
Among security research insiders, OpenBSD's reputation became a little bit farcical. Not that OpenBSD was comically insecure --- it wasn't --- but that its reputation so far outstripped its actually differentiation. People found a bunch of vulnerabilities in OpenBSD and laughed as the claim at the top of the OpenBSD changed from "no vulnerabilities" to "no remotely exploitable vulnerabilities in the default install".
And at some point in the last 10 years, didn't OpenBSD's distro servers get owned up?
I'm sure the OpenBSD project would like its threat model to include NSA. But OpenBSD is not a meaningful ally in a contest between you and NSA. NSA wins that fight. OpenBSD's userland was much stronger than FreeBSD's in 1999, but I'm not sure I think their kernel is stronger in 2013, and that's probably what matters more.
Let me wind this bloviation up with a caveat: one thing a reputation for security gets you is a feed of talent that is interested in working on security problems. OpenBSD certainly got that. So for instance, OpenBSD's developers designed and built privilege-separated OpenSSH. There is a lot of good security work that has started inside the OpenBSD project, and I don't mean to talk any of that stuff down. I'd just be careful about taking the project's overall reputation to the bank, especially if you have serious adversaries.
Sorry for hanging this sprawling comment off your (simpler) point; I just don't want the root comment on the thread to be me talking down OpenBSD.
Well said.
Sorry for my slightly o/t comment.
Fortunately for me, I never had a CSR interaction with them. I used them until they augured in.
wgl@mcs.com
I think I started when it really was only Karl, was Dawn his first hire? Hmm, I probably still have the t-shirt as well.
ajm@mcs.com (or .net)
And that was my shortest email ever--11 characters complete.
Pretty sure that was a solaris box.
Back when I was in high school and I had a lot of free time and all that, the various incarnations of Linux were a delight. Even after that, I still went with it out of inertia and spent many evenings tweaking Gentoo.
I eventually just goddamn gave up. I got sick of every upgrade breaking something in my system and then especially got sick of deciding between figuring out how to use wpa_supplicant and installing NetworkManager which screws up my network settings as soon as I plug in the Ethernet cable while I'm still on my wireless. In a flight of rage I thought ok, I've had enough of this crap, and went the OpenBSD route.
Seriously, it has all the nice parts of Plan 9 while still actually being able to run all the tools I need. I still have Linux and Windows boxes for the odd tools that don't work on anything else (I do embedded systems for a living, and there's a lot of vendor lockdown there), but for my day-to-day workstation, I found nothing better.
When I got thrown in the deep end with Solaris, many years ago, I'd read the Solaris man page for the options, but first I'd read the OpenBSD man page to work out what the hell the command was for and why.
I don't know if this is common practice anymore...I don't remember the last time I saw a defective man page like this, but I still remember it with great anger. I love GNU, but I hate the kind of condescension it takes to try to force someone to use a different tool because you believe it to be superior to the standard tool (when it's really not; I find info pages to be obtuse to create, and difficult to read).
But we have other hypertext formats available. It'd be better if GNU started using some format that everybody already usees and knows how to write.
If you need a complex manual for a complex program, something is wrong.
I mean, the project wants to create an operating system that looks like UNIX, acts like UNIX, smells like UNIX, but from scratch with appropriate license that allows usage and access to source to anyone - so that the project doesn't get into legal trouble from whoever actually owns UNIX?
So drunk Stallman in 1981 says: "hik, let's call this, hik operhikating system GNU, hik, because it's not UNIX hik, but it sure looks like one, hik, but it's not, hik, but it kinda is hik, but it's not theirs hik it's everyone's hik". That's how I like to imagine it happened.
Now I no longer have anger management issues
The problem lies when you want to find something 1% of the time, and it's here that man pages become sprawling unindexed messes. For example, take a look at the man pages for perl or zsh: you'll have no chance finding anything, as those programs are so large that they need a wealth of documentation to go into them. At the same time, the info page for ls contains the things you rarely need to see such as exactly how things are sorted or the minute details of timestamp formatting. If this were all in the man page, you'd complain that you couldn't find anything in it.
1: My go-to example was always ifconfig, but linux's manpage for ip(8) really isn't that bad, as is actually the linux equivalent. Quality probably varies quite a bit based on the package that supplies the utility though, while OpenBSD's quality is fairly universal.
In 2009, our development team lost a whole 10 hours to a degraded Linux mdadm RAID1 that wouldn't rebuild due to an obscure error after a digger severed our power and internet connection. No internet access as power came up first so no access to online help. mdadm is buggy. Documentation sucks. Error messages suck. Only recourse was a full restore from tape which took a long time. This was the last straw after over a decade of dealing with this crap from network dropouts, laziness, half-arsed features, distro wars, politics and churn.
Some previous Unix experience in the late 1990s with OpenBSD on an old SparcStation 5 (the only thing that would run on that machine nicely) jumped into my mind on the way home. It had that warm, fuzzy, well-engineered, well-documented feeling about it, like an old HP RPN calculator. Got home, downloaded it and installed it on my laptop, replacing Ubuntu.
4 years down the line: one happy person with the same laptop running 5.4 still with that warm, fuzzy, well-engineered, well-documented feeling.
Not once has it let me down. Not for a minute in the 4000+ hours I've been using it. It just works.
Any bug numbers? I'm not seeing that on Debian Wheezy or CentOS.
But I have just ordered a CD set to try this OpenBSD to see what all the fuss is about and to learn something.
Yes, a cvs bug I believe. No kernel will protect you from bad user-mode code that really wants to execute everybody's shell script.
> Among security research insiders, OpenBSD's reputation became a little bit farcical.
I spent lots of time looking through the OpenBSD Kernel, togheter with FreeBSD and Linux kernel. It was my job for years, looking for vulns and writing exploits for them.
I still admire the OpenBSD Kernel for their simplicity and tidiness.
No comparision to FreeBSD kernel-side. FreeBSD kernel often have commits of several hundreds of KBs of mostly unaudited code. They still don't enable stack-protection today in 2014. It's a joke. My windows phone had stack protection in 2003.
No comparision to Linux either, the Linux kernel is so huge, so full of code that even if it's way more audited than FreeBSD, there are still vulns lurking everywhere and exploits for linux kernel came out almost monthly. Probably it's the reason it have so many security features, more than OpenBSD nowadays.
Windows, their kernel is a work of art. Microsoft only have to fire the guy that says "hey I got a great idea lets parse some random protocol inside the kernel"
But I disgress. OpenBSD is still very good. Very safe in the default install. It will protect your firefox from being owned by a NSA-sized enemy that really want to hack you? no. But the problem is in the browser, not in the kernel. Don't use a big browser. It's not in the default install :)
Missing entirely the point of the parent post. I can claim anything is secure if I seal it in enough concrete.
That may explain why unlike all other operative systems out there, OpenBSD distro gets smaller as time passes.
a) Shut down OpenBSD
b) Shut down Amiga support in OpenBSD
I mean, is it even a hard choice?
Besides, if there are many developers who like developing for Amiga, surely they would be able to find a replacement?
the fact is right now, OpenBSD will shut down if we do not have the funding to keep the lights on.
suggests the necessary $20k (cash) has not been forthcoming.
P.S. I understand it's not a threat in the sense of ransom etc, but the most correct word is not coming to my mind.
All three options exist, but the maintainers pretending that option b doesn't exist at this point in time increases the probability that option c will succeed.
If the pretense doesn't work, be very much assured that they will go with option b.
There are two important points that shouldn't be forgotten about aggressively pushing cross-platform: it retains developers and exposes bugs. There's a great deal of usefulness behind it, beyond simply making it obvious that the workstations we get today are shit.
I am not suggesting all legacy platforms need to be cut. I'm suggesting that it's possibly an acceptable risk, and also if a replacement UltraSPARC simply cannot be sourced, there can't be that many developers working on UltraSPARC anyway. (Just as an example)
It reminded me of a post-it I left in the company lab with a diagram for how to do proper gigabit cross-overs. I could still find it there five years later after they rearranged the lab several times.
Here's a link that does not require IEEEXplore access: http://www.scribd.com/doc/46141801/802-3ab-1999
- Is there a significant amount of people with high security standards and an interest in SGI workstation hardware?
- What about people who have high security standards and Sharp Zaurus hardware?
If these groups aren't as important, as say, ARM and x86 users, perhaps it could be worth dropping some of these platforms?
Personally, I do wish OpenBSD could somehow regain the popularity it once had and that support for modern hardware like 10GBE and scaling PF throughput w/ multi-core CPUs would improve. I don't know what it would take to bring people back.
If it's worse for the rest of the ecosystem, there's a point.
I'd be interested to hear whether or not this is the case from people closer to such a condition, though (ie: OpenBSD, NetBSD, ???).
This is like saying "I don't care if my arcade goes out of business, I'm going to keep the power hungry cabinets alive even though they only get used once every 3 years."
If there is an argument that maintaining this will somehow improve security overall and not just on ancient hardware then I would love to see it. But if the Devs working on it could care less of what the rest of us think, then maybe those Devs should pay their electricity bills to support their toy platforms because I could care less about what they think too ...
Then again, it's possible that emulation could surface other edge case issues. That's completely orthogonal to the value of non-emulated archaic architectures for this purpose, however.
Some of the architectures also have different endianess and incredibly complicated peripherals to the cost effective host machines as well meaning that it's actually more power efficient to run native. A headless 100MHz VAXstation for example draws less power than the equivalent host that would be required to provide a full, accurate emulation with peripherals. These aren't arcade machines.
Portability issues is where real hardware benefits. It's where you have battles of unusual register sizes, endianess, host/network order differences, different memory models and memory protection, different performance characteristics, different timings and different exploits.
Unless the emulation is 100% accurate, including timing, which is a really difficult thing to do (look at the effort MAME goes to), then the benefits over real hardware is moot.
Emulators are also expensive to write due to the above, have their own bugs and don't always recreate the bugs in the real hardware (which are sometimes exploitable).
Also, using emulated hardware could cut down the usage of the real pieces, which could then be better studied and preserved. Doing less builds on vintage hardware is, actually, a good idea.
Sounds good to me. Many times (actually most times) I have no need for a "desktop" metaphor on my screen in order to get things done. I actually get more done big jobs done faster without the desktop metaphor in the way.
"... the devs working on them probably could care less what the rest of us think."
That's what makes them so special.
Perhaps in the long run the most "powerful" and sought after computers will not be the ones with the latest chips, but the ones that the user has the most knowledge of and control over.
Can you imagine the old-timer reminiscing: "Remember when computers didn't have backdoors built-in?" or "Remember when you did not have to pay for a license to write programs for hardware you bought?"
"I really love how we keep getting advice. Anyone want to suggest we hold a bake sale?"
He clearly says things like "that's not up for discussion", "I'm not going into details", etc.
If anyone ever truly deserved the title BDFL...
What OpenBSD foundation really needs is a tactful and charismatic person to act as firewall and pf between Theo and the people with overflowing bank accounts, who are more accustomed to dealing with obsequious salesdroids than a person who is not only ten times smarter than their entire golf group put together, but also so aware of it that he cannot hide how much of a waste of time it is for him to suck up to any one of them, no matter how much he could use the cash.
Do you think Apple would have gone anywhere if Wozniak was the one talking to all the investors?
Not that I don't understand those feelings. I've spent enough time lurking on openbsd-misc to have seen Theo and friends be beastly. But never without some provocation. And one might wish better impulse control on any number of online personalities.
(And if you find this rude, note that I'm not involved with OpenBSD -- not even on the mailing list anymore -- so blame me, not 'the OpenBSD community'.)
On a regular basis, we find real and serious bugs which affect all
platforms, but they are incidentally made visible on one of the
platforms we run, following that they are fixed. It is a harsh
reality which static and dynamic analysis tools have not yet resolved.I think Theo could probably thin down the cluster and still be good but maybe I'm wrong and he'll show up with examples that require all of that hardware. That would be interesting because in our case we've sorted out the problems and rarely see things blow up on the RISC boxen.
http://www.openbsd.org/sgi.html http://www.openbsd.org/octeon.html http://www.openbsd.org/loongson.html
A mips32 port would also be very desirable for all those shitty little routers with their ancient Linux kernel, but sadly nobody is working on that at the moment.
So, should the network and firewall OS that many people claim OpenBSD is, slash its support for MIPS devices?
But OpenBSD could be testing on an embedded MIPS development device at any data center they want.
Sony Bravia EX series televisions are MIPS and Linux based for example.
MIPS SoC licensing is less expensive than ARM licensing at the smaller volumes inherent in low-end routers (.vs phones and tablets).
Change is hard, but I think it's worth a shot. And you never know maybe spending more time focused on real needs will create a better product from all the extra attention given to things that are work worthy.
And, the OpenBSD development team has contributed a lot to the software community, so it's extra frustrating not to get enough support back.
I'd expect that at some point it just stops being a fight you want to keep fighting.
Many of the machines do not have LOM. They have hardware failures instead. They hang because they get trashed building OpenBSD and ports pretty much 24/7. There is debugging and serial cables going on. Someone needs to push that NMI button and check the LEDs flicker like they should. Reboot them. Constantly update to the latest development version, making them panic quite a bit. Diagnose that. Installation procedure requires console access, monitor adapters, weird keyboards, ... They don't fit in racks properly. There are security concerns. Etc, etc.
It's wrong to think of the machine room as rack space than can be had for cheap somewhere else. It's much more like a lab (with the mad professor living on top, controlling the experiment).
I have donated to OpenBSD a number of times because I believe the project is of great value. In all cases where I used a release (for firewalls mostly) I purchased a CD set.
Link to relevant reddit comment thread: http://www.reddit.com/r/linux/comments/1vakm9/openbsd_develo...
8 year old image of one of the racks, is only grew since... http://www.openbsd.org/images/newrack.jpg
If they don't know at least numbers like that, there are some bigger issues.
You're expecting a medium to large size company to donate to you. Those companies have a moral and fiduciary duty to know what they are spending their money on. It seems odd that the "Open"BSD project doesn't feel the need to be open about the hardware they use!
My understanding is that 1000 CD-ROM sets will bring in the CA$20K needed
I get, from the comments, that: openSSH is great (sure, I can believe it) and Theo is an asshole but you should compromise and give them money anyway.
I don't get why a parallel operating system ought to continue existing, especially one that comes from the same legacy codebase as several others. I also don't get why, if openSSH is so good, the goal isn't to write a new SSH or fund openSSH separately and drop the rest that can't be supported. Why does the world needs OpenBSD instead of having the talent focused on making a smaller number (..Linux) better.
Certainly the answer might be 'because that's what the talent wants to work on' but that's not a good reason to fund it.
I have also gotten the impression, from limited observation, that there are real problems in the open source community with too many people doing the same thing and not working together, and with people being jerks (or just generally anti-social or at least not-highly-personable) and making it hard to get involved or care about otherwise important projects. I don't think supporting Theo, from what I've read here, helps that trend.
I know very little. Can someone fill me in?
OpenBSD being a full OS means that they need tools for everything. Occasionally, one of those tools will be superior to mainstream alternatives, thanks to the very strict practices of the project (which really sets the bar for any other project in the security field) -- OpenSSH being the most famous example. Even if their tools don't get adopted, a lot of their code and ideas do, benefitting the whole ecosystem.
Their practices also mean that a lot of the standard GNU userland is regularly audited with a degree of precision not found in more mainstream projects. The bugs they find will be fixed by everyone else, again benefitting everyone in the FLOSS world.
if you use CARP or OpenBGPd and have never bought a CD, you need to buy two ;p
What I don't get is where people - presumably people involved in information technology - conclude that $20k/year is a lot of money to spend on electricity. What utopia of free electricity for all are these people living in? Can I host a few servers there?
This is done routinely by both for-profit and non-profit organizations. In fact, it's done routinely by individuals like myself.
> What I don't get is where people - presumably people involved in information technology - conclude that $20k/year is a lot of money to spend on electricity.
Where I live, that would pay for the equivalent of 10-11 120-volt 20-amp circuits running at 80% capacity (per electrical code) 24/7. Some googling suggests Calgary rates are similar, which isn't surprising. We both get most of our power from hydro.
I wonder if any nonprofit, ever, has given a by-the-watt power accounting of the sort some of the people here are advocating
> Where I live, that would pay for the equivalent of 10-11 120-volt 20-amp circuits running at 80% capacity (per electrical code) 24/7.
aka several racks of equipment. My God, the audacity of OpenBSD developers, to ask for help powering this stuff!
Name them, link to the comments, and explain exactly what you mean by "by-the-watt power accounting", or you're just inventing strawmen.
> several racks of equipment
The extent of the evidence we have is that there are two racks: http://www.openbsd.org/images/rack2009.jpg
There are significant gaps in the racks, and ~16U are occupied by UPSs. The rest is a mix of fairly modern and legacy gear with a few external HDDs and a few 1U pieces of network gear. In a real datacenter, it would occupy perhaps 1.5 racks.
My arguments are backed by publicly-available evidence. Yours are backed by vague assertions by people who assuredly do not need you defending them. If they wish to convince anyone, they can release further evidence.
> My God, the audacity of OpenBSD developers, to ask for help powering this stuff!
Oh look, another strawman. Nobody believes requesting aid with an electric bill is unreasonable. It is the amount being requested that is shocking, and the extreme secrecy breeds suspicion.
I've never used OpenBSD except to tinker with it, and likely never will. But, I use OpenSSH hundreds of times a day (both in automated jobs and in the terminal). It is utterly necessary to me; likely necessary for all of us, really. So, while a company would have shed the extra weight and focused on its core product that users love years ago, OpenBSD keeps OpenSSH as a side effect. I guess I'm OK with that.
Maybe it's even necessary for OpenSSH developers to understand systems level programming at a level only OS developers can grasp, and maybe OpenSSH wouldn't be the absolute beast it is today without that kind of influence and widespread knowledge found in the OpenBSD team. I dunno. Whatever it is, I support the people and the things they do for me in OpenSSH even if I don't care much about OpenBSD.
Imagine being without ssh, then go donate. :)
On every* UNIX and UNIX-like OS ssh is OpenSSH. OpenSSH is why we don't telnet everywhere anymore.
*- Honestly, I don't know of anything that ships with something that is not OpenSSH.
Not that it's nearly as feature full as OpenSSH, nor as architected around security (process separation and all). But it's nice when you need a small sshd.
Personally, I've mostly used OpenSSH on desktop and servers and Dropbear on embedded/low-memory devices. I've also installed lsh-server out of curiosity once, but that was just to take a look, not for production use.
However, I believe, security- and featurewise, OpenSSH is probably a best option (unless device's really low on resources).
The only Unix systems I know of that don't use OpenSSH are embedded devices.
(note: I donated based on being OpenSSH user; I am not an OpenBSD user but I'm glad it exists)
Did you see any leaked powerpoint slides discussing MIPS r12k vulns, created in conjunction with SGI ? I didn't ...
"On a regular basis, we find real and serious bugs which affect all platforms, but they are incidentally made visible on one of the platforms we run, following that they are fixed. It is a harsh reality which static and dynamic analysis tools have not yet resolved. "
"Regarding shutting them down, there other social problems.
Yes, we remove about 10 of the architectures. We'd slowly lose the developers who like to work on those areas. They also work in other areas, but ... I suspect they would another BSD that supports them."
Keep in mind that OpenBSD is by the developers for the developers. That it's also useful for a lot of users is just a nice side effect, helpful for testing and funding.
It is until the developers can't afford to keep the lights on.
If OpenBSD isn't exaggerating about shutting down the project, then it seems reasonable to review their policy regarding old platforms and focus on what gives the most return.
If the answer is "NetBSD", let's consider that the expenses in 2012 for the NetBSD foundation were $6k [0].
Either they don't support the architectures the same way or they are spending the money in a smarter way.
[0] http://www.netbsd.org/foundation/reports/financial/2012.html
OpenBSD has a strict policy that supported architectures must be self hosted, tested, and built against HEAD constantly.
Theos answer: http://marc.info/?l=openbsd-tech&m=138973312304511&w=2
The fact this was submitted here and disappeared is kind of indicative of their problems.
Supporting them is important given their work on other projects, but it seems like outright dismissing alternatives to someone cutting them a check (e.g., moving the servers, etc.) is also probably limiting the help they're going to receive.
Right now I feel like linux is slowly eating all the market share, if it continues that way the BSDs will regress back to the lines of Hurd and Plan9.
Competition is always a good thing, even in the OSS world.
Linux is just a kernel. The problem is that outside the kernel there is perhaps already too much competition. E.g. there is glibc, eglibc, bionic, dietlibc, etc. There is SysV init, systemd, Upstart, OpenRC, etc. Then we have GNOME, KDE, Unity, Xfce, Cinnamon, and MATE.
For practically any component in a Linux system, except the kernel itself, there is already a lot of competition. The BSDs add four more, albeit incompatible (with Linux and each other), user lands.
I think the FLOSS world would profit from less fragmentation and more focus on making the good projects better. Of course, polishing existing work is not as much fun as writing your own ;).
That makes very little sense.
If I believed all the BSD forks had a chance to live long and prosper on their own I wouldn't be saying that, but right now it seems to me that none of them have any real long time chance to remain generic OS on par with Linux (except possibly FreeBSD but it's not even certain anymore). Linux just moves too fast these days.
> Competition is a good thing, so we should unite bit-parts that are in danger of being stomped out to ensure the dominant player still has competition in the future.
No, it would be getting rid of openbsd to try to prevent losing bsd.
I doubt you were truly unable to determine I was not talking about the Berkeley Software Distribution, but the family it spawned. Which leads me to conclude you are being obtuse. For... pleasure? I don't know.
Don't get me wrong, I love FreeBSD and use it for somethings, but they don't really take security very seriously. Theo just gave this lecture with examples http://tech.yandex.com/events/ruBSD/2013/talks/103/
The thing is they had their schisms for a reason, and inability to work together is kind of baked in, even if much of the code does in practice cross pollinate further downstream.
The other question is if it's possible to get the benefits of the strange old hardware support without the old school power consumption. I think many relative youngsters would be surprised by how thirsty some of those classic UNIX boxes were, and the hardware must be close to dead now. At some point the only remaining working SPARCstation will be used to build OpenBSD.
Revenue-wise, the best move would be for a shop like iXsystems, Pair or ByteMark to step up to cover costs. And, any shop that uses OpenSSH on a large scale should be able to pony up some cash to keep Open{SSH,BSD,CVS,{NTP,BGP,OSPF,SMTP,IKE}D} alive. For example, it would be nice to see OpenBSD on Amazon, and AWS might even be willing to fund kernel changes and more to accomplish that.
Finally: check out this handy script which makes it OpenBSD a whole lot easier to get started and complete common tasks. [1]
References:
a) Typing in a credit card number + billing address.
b)
- Signing up for an account at a Bitcoin exchange.
- Transferring money to them (by doing a?)
- Waiting for them to exchange it.
- Transferring it to the recipients' wallet (this one step is kinda-easy, I'll grant)
- Hoping the price of bitcoin holds stable-ish so that my bitcoins are still worth something when the recipient converts them back.
I personally am willing to risk 10 - 20% value to help establish a reasonable stability in BTC/USD exchanges. Once the exchange becomes more stable and nerdy people hold some amount of bitcoins the above problem is fixed, it's just that right now regulation and volitility are still a problem.
- Send Bitcoin from bank to recipients' wallet
The last point won't be an issue once Bitcoin stabilizes after its growth phase.
Replace a) with
- Fulfill an arbitrary number of legal requirements
- Sign up for an account at a bank
- Transfer money to the bank (by doing a?)
- Wait for the check/deposit to go through (hopefully neither you nor the bank fucked something up)
- Put it in your debit/credit account (this one step is kinda-easy, I'll grant)
The last thing about "Hoping the price holds stable" is irrelevant. The recipient can convert them immediately.
A fair comparison is the act of paying with your (funded) credit card versus paying with your (funded) Bitcoin wallet. I can say from experience that the Bitcoin wallet is significantly easier in a lot of cases (and also carries less of a risk of getting skimmed or having a payment database hacked or something).
Other organization provide all information for SEPA bank transfers on their donation page (e.g. http://www.osmfoundation.org/wiki/Donate/SEPA), while the OpenBSD donation page just provides an email address that you should contact if you want to donate via a simple, plain bank transfer. That's kind of discouraging.
Unfortunately, when I was using it, there weren't many interesting FLOSS projects to contribute to. Perhaps things have gotten better.
Either of those are two clicks (choice and confirmation) plus authentication which is identical to my in-app experience.
The biggest difference isn't about the process, but at what level a user has bought in to it - a payment shim from a particular provider or an ecosystem (Google / Apple).
I wonder how folks would react if Chrome / Safari started popping up a button to allow a seamless donation through Wallet/iTunes whenever a page presented a PayPal link or a CC form?
Amazon less so, but in my experience, almost nobody takes them.
theo was a visionary, and together with some other really brilliant folks (not counting myself as one of them) accomplished what people said no one could. since then he's been fine tuning that vision but has more or less kept it at around 2003. the world has changed, theo - and as a result the project - hasn't. so, the world caught up and users moved on.
Exploit Mitigation Techniques: an Update After 10 Years (by Theo) http://tech.yandex.com/events/ruBSD/2013/talks/103/
An OpenBSD talk by Michael Lucas https://www.youtube.com/watch?v=BXPV3vJF99k
Aside from OpenSSH, OpenBSD is not security relevant, and hasn't been for about a decade. So when they don't get the 20k, nothing of value is lost.
SSH alone, and all the utilities that use it... have made my work/life SOOOOOO much easier. That may sound silly, but when you don't have to search for some 3rd-party utility because what you need is built-in... it makes life easier.
I'm donating.
No BLOB is a very sane idea for example. I think we'd be further along if that was enforced stricter by other projects.
Even on cloudy days the new panels will produce energy.
The panels are usually warranted to produce at least a certain (80% on mine) percentage for a set period of time. (25 years on my 5 + year old PV arrays) so the other considerations would be a charge controller/charger, a voltage inverter (from DC to AC) cabling and batteries for storage.
Of all the items, the batteries will be the main recurring expense as they generally don't last as long as the PV panels. Depending on type of battery, and how heavily cycled they are, batteries can last for 10 years, with proper care and use.
A system which maintains a constantly higher amperage will last longer than a system that has been allowed to be exceedingly discharged. (no less than 80% of capacity)
In my area electricity sells for $0.49USD per KWH ergo solar is the logical solution.
The end result is a self reliant system, independent of the issues associated with distributed power sources, while increasing responsibility for the consumer.
I find the cost/benefit ratio to be in favor of under-funded consumers, especially in the long term.
I'm glad I read through the whole thread because by the time I got to the end of it I had changed my mind. In one e-mail to the list, Theo basically said (in effect) that a donation of $20 wasn't even worth it. (Granted, $20 isn't much in the grand scheme of things but I feel that it reasonable covers my use of OpenBSD.)
There are many people who think that Theo is the worst thing for the Project (because he's such an asshole). OTOH, however, there are many who think that the Project wouldn't exist if it weren't for Theo.
As you read the whole thread, I suppose you've also seen this quote?
Nicolai, and others,
I'd like to take the opportunity to thank all of those stepping up to the call for contributions. Every little bit helps.
See: http://marc.info/?l=openbsd-misc&m=138974990608900&w=2
Anyways, talk is cheap. Donate helps which as a lot of others here I just did. Thanks Theo!
I would rather have a non compromising, highly secure operating system available, with all the source code available for me to see (none of that binary blob business) than a mediocre operating system that was somewhat secure from a guy who was really chill.
Funding the OpenBSD project is not a decision about the personality of Theo, its a decision on the usefulness and and the quality of work that the OpenBSD community creates.
When I am setting up and configuring and relying on a server with OpenBSD, I could care less if Theo is eccentric or not. I am in awe of the technical brilliance of OpenBSD.
And yes I have donated and do donate to the project, and I encourage clients I have that are running on OpenBSD to do the same.
It's easy to just say "hur, they be stupid to port on vax/macppc/sparc/whatever". Do your homework.
Besides, with all their might, Google got pwned hard by NSA.
http://www.opensource.apple.com/source/xnu/xnu-2422.1.72/bsd...
My understanding is it has a reputation for being very secure, having thoroughly audited source code, and runs on lots of old and legacy hardware. It's also renown for having super thorough documentation. (see Zed's comment)
Judging by comments on this post, I think it is more a case of the maintainers and/or the foundation's management instead of loyalty or adoption of the OS. I believe HN also runs on OpenBSD too, if I'm not mistaken.
On FreeBSD.
That and the foundation's most important projects are probably OpenSSH (absolutely essential, main focus here) and OpenNTPD, rather than the OS itself.
when i make budgeting decisions (whether personal or in business), i start with the needs before going to the "nice to haves". for openbsd, i can't help but assume powering their various servers/systems is kiiind of a priority...
so what i want to know is: - the over all budget $ amount for 2014 - what was the cost of power in 2013 * how did you get to $20k for 2014? - which priorities are worth funding over power
my suspicion is that there's plenty of room for give and take here.
On another note, the readability of the font was a turn off for me. Fortunately, there is an option to view it in plain text. adding &q=raw at the end of the URL. http://marc.info/?l=openbsd-misc&m=138972987203440&w=2&q=raw
Why did I stop? Theo was such an ass about questions on "his" mailing lists that, well, there were friendlier communities out there.
OpenSSH, however, I use a lot so I could donate a few bucks for that.
EDIT: Here's the thing. I don't directly use OpenBSD, but they have influenced more than just UNIX for a long time.