Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 1 Jun 2001 15:21:05 -0700
From:      Kris Kennaway <kris@obsecurity.org>
To:        Steve Tremblett <sjt@cisco.com>
Cc:        Joel CARNAT <joel.carnat@noos.fr>, freebsd-stable@FreeBSD.ORG
Subject:   Re: Is OpenBSD safer than other BSDs ?
Message-ID:  <20010601152105.A89287@xor.obsecurity.org>
In-Reply-To: <20010601140605.M18959@sjt-u10.cisco.com>; from sjt@cisco.com on Fri, Jun 01, 2001 at 02:06:05PM -0400
References:  <20010601195419.3283ef01.joel.carnat@noos.fr> <20010601140605.M18959@sjt-u10.cisco.com>

next in thread | previous in thread | raw e-mail | index | archive | help

--HcAYCG3uE/tztfnV
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Fri, Jun 01, 2001 at 02:06:05PM -0400, Steve Tremblett wrote:
> +---- Joel CARNAT wrote:
> | 'lo folks  :-)
> |=20
> | I'm using OpenBSD as my home gateway and I was wondering :
> | is an OpenBSD box really safer than a FreeBSD one if your configure thi=
ngs (like inetd, ipf, ...) the same way ?
> |=20
> | if not, what's the point in using Open rather Free for a Gateway/Firewa=
ll/DNS cache/DHCPd ?
> |=20
>=20
> Much of the software is common across the BSDs, but a distinguishing
> feature of OpenBSD is the attention to detail in the comprehensive
> source code audit.  Then again, problems they find get implemented in
> other systems based on OpenBSD's suggestion...

And vice versa..it's not a one-way process (i.e. we've fixed quite a
few things in our source code audit which they missed the first time
around).

Personally, I don't think there are major security reasons to choose
one over the other.  If you look at the advisory history of FreeBSD
and OpenBSD over the past year or two, most of the serious problems
have been shared by OpenBSD; OpenBSD has had serious problems not
shared by FreeBSD; and FreeBSD has had serious problems not shared by
OpenBSD.

The "secure by default" thing isn't much of a difference any more; the
major practical difference is that OpenBSD has turned off a few more
inetd services than FreeBSD has.

FreeBSD's source code has been fairly well audited, and we've made a
lot of security fixes over the past few years, including fixes from
OpenBSD.

Bottom line is you should look at both systems and decide which you
like better.

Kris

--HcAYCG3uE/tztfnV
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (FreeBSD)
Comment: For info see http://www.gnupg.org

iD8DBQE7GBVQWry0BWjoQKURAiGBAKCoW+v7+da+9gHFeRWZsBVzt1IAmgCfTwHx
YzQeQZpgGcAeVK2mpoQMn5w=
=1d2v
-----END PGP SIGNATURE-----

--HcAYCG3uE/tztfnV--

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-stable" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20010601152105.A89287>