this post was submitted on 18 Feb 2024
47 points (79.7% liked)
Linux
48181 readers
1271 users here now
From Wikipedia, the free encyclopedia
Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).
Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word "Linux" in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.
Rules
- Posts must be relevant to operating systems running the Linux kernel. GNU/Linux or otherwise.
- No misinformation
- No NSFW content
- No hate speech, bigotry, etc
Related Communities
Community icon by Alpár-Etele Méder, licensed under CC BY 3.0
founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
I wouldn't recommend OpenBSD as it is fairly obscure compared to Linux. I've yet to see a real world example of how it is somehow better
They developed new system calls (pledge and unveil) which restrict they system calls and file access of programs (here's a good writeup by Andreas Kling after he added support in SerenityOS: https://awesomekling.github.io/pledge-and-unveil-in-SerenityOS/). As an example, the Firefox port for OpenBSD uses them to heavily restrict what random websites can do or get from your system.
Just one example since you've somehow yet to see any.
https://isopenbsdsecu.re/
I don't think much changed since then, but would love to be proven wrong.
Forgot to link a comment on that website: https://marc.info/?l=openbsd-misc&m=158908598913596&w=2
+1, but OpenBSD can enforce security (Linux have landlock, *san, ACL, MAC but cannot enforce them, while OpenBSD doesn't but can enforce pledge and unveil and even for some ports like chromium and firefox)
https://madaidans-insecurities.github.io/
But see Chimera Linux.
I heard of Chimera multiple times now, but everytime I look into it it doesn't seem to be more interesting and useful than say Alpine.
Do you have any write-ups about the security advantages of Chimera Linux?
I mean Chimera is using FreeBSD userland, and they expressed why GNU coreutils used by most distro have "problem". Since we are talking about BSD. (OpenBSD's userland is less in feature and it is cleaner)
(so that's bring an advantage in security lol)
Did you read it? The author is clearly biased against OpenBSD.
As an example, he dedicates quite a lot to talk about "ROP gadgets removal" (which is an ineffective mitigation employed by OpenBSD), however he also states:
When you consider the fact that some mitigations which were considered overkill were proven significant with time (for example, OpenBSD was completely unaffected by Spectre v1 and similar exploits since they disabled hyperthreading), statements like these make it clear to me that the author is biased.
Edit: This is not to say the website is deceptive, it's just that it doesn't provide a good analysis or comparison of the security of different systems IMO.