A quick look at __pledge_open(2) https://lobste.rs/s/sc5cbx #openbsd #security
https://dustri.org/b/a-quick-look-at-__pledge_open2.html
openbsd
I can't speak to the accuracy or "correctness" of the guy's instructions, but the way he opens the video is freaking hilarious.
https://inv.nadeko.net/watch?v=uTrOIPIx7pY
How to Install OpenBSD (2027 Edition)
Okay now, so who's got the *cajones* to send a mail to one of the #OpenBSD lists about #slop being included in base via tmux? ;) — #microblogging #MicroToot: 130 characters
https://github.com/macports/macports-ports/pull/30763
GitHub's Continuous Integration checks passed!
It's up to someone else with commit access to merge it.
For whatever reason? The rpki-client.org website main page hasn't been updated to reflect the release of 9.7 yet, but it's there on the mirrors (and I verified the tarball with signify) and an undeadly.org story was posted, so I am guessing I didn't really beat anything to the punch so much as the World Wide Web isn't a first class citizen contrasted with those toiling in the realms of securing routing protocols, as it should be.
#RPKI #rpkiclient #MacPorts #OpenBSD #OpenBGPD #BGP #OpenSource
A 27-Year-Old Authentication Bypass in OpenBSD's PPP Stack https://lobste.rs/s/suaa0r #openbsd #security #vibecoding
https://blog.argus-systems.ai/blog/openbsd-pap-27-year-auth-bypass.html
https://marc.info/?l=openbsd-ports&m=177652909703481&w=2
Good thing I've still my trusty #FreeBSD laptop.
Even more random redoing the sysupgrade -s and it passes straight away and upgrades. Does it boot the /bsd ? No it does not only boot.rd and boot.sp boot.
Please boost and thanks in advance.
Options: (choose one)
Advertisement: We are happy to welcome our new sponsor at #BoxyBSD: ST-Hosting.com
ST-Hosting.com stands for performance, stability, and pragmatic solutions and hosting like:
- LXC & KVM servers on AMD EPYC, Ryzen, Intel Xeon systems
- Fair pricing and direct support from Germany
- Hosting made in Germany
We’re excited to have https://st-hosting.com on board! You can immediately start to provision your BSD based boxes (like #FreeBSD, #OpenBSD, #NetBSD,...) at BoxyBSD in our new location in Germany, Nuremberg. Also, stay tuned for #Fosdem ;) Thanks a lot!
Heads up for Firefox users on #OpenBSD -current, landry@ the mozilla port maintainer has committed a new policy configuration file which changes some (annoying) default behaviour.
landry@ modified ports/www/mozilla-firefox/*: Install a policy configuration file
mostly taken from https://justthebrowser.com/firefox/, Disables:
Firefox Studies
Checking if firefox is the default browser
Sponsored stuff on the home page
GenAI features
PerplexityAI from the default search engines
in addition, frob GoToIntranetSiteForSingleWordEntryInAddressBar, which forces firefox to ask your dns first if you enter a single word in the address bar, useful to access local sites on your network instead of sending your internal dns entries to $searchengine.
cf https://mozilla.github.io/policy-templates/#gotointranetsiteforsinglewordentryinaddressbar
many knobs to frob, but those seem to be a decent baseline to fight against enshittification.
Kinda reminds me of that CCC talk on OpenBSD by that person who was like, super critical of OpenBSD, one of the security features (I don't remember which one and I really don't feel like re-watching that video on this slow WiFi just to be more precise with citations) he sort of hand waved away with something along the lines of: "maybe this is useful for some CTF competition, but not in the real world."
I mean, I dunno much about CTF competitions everywhere. At ToorCon 8, I sorta stood over jose's shoulder while he helped their CTF team get something to compile and for some reason, I ended up on that year's t-shirt, twice, as a result! ;) I also know some of the old DefCon CTF folks. obecian, of the Ghetto Hackers? Was an OpenBSD developer. Ghetto Hackers, having won CTFs in the past, I guess got to organize future CTFs or something?
OpenBSD was banned from CTFs IIRC, because it set the bar too high. In a Capture The Flag competition, you need hosts which are actually able to be exploited.
So, no, I don't think OpenBSD developers make security features, for CTF competitions, because at least, the last time I paid any attention to such things? OpenBSD was prohibited from being used in such things. That would be a lot of wasted development effort, for something from which no one would benefit.
As an aside, one of the two times (the first time I think? 2005?) that I ever ended up attending DefCon, I learned from Caezar how obecian got ingratiated into their group. Pretty hilarious story, but I would be retelling it with about two decades in between when I heard it and now, and doubtlessly would get some details incorrect. Not the thing to write about online so much as share in person anyway. ^_^
As an aside, didja see the Call For Papers for ToorCamp 2026?
https://talks.toorcon.net/toorcamp-2026/cfp
I dunno if I will have my life together enough to attend (it's late June, seems, dubious) but having attended ToorCamp in 2009 and having heard nothing but good things about it improving over the ensuring years? I am guessing it will be a good time!
#CTF #OpenBSD #ToorCamp #GhettoHackers
I've not mentioned in mailing lists yet as hoping someone shouts "Haha you Muppet! Fix it like this" 😜
Running #OpenBSD 7.8
DNS: #nsd (3 Master Zones), #DNSSEC & #DANE (RFC6698) + #unbound
Firewall: #pf with auto-fed tables (IPS-style), spambot-tarpitting & service rate limits.
Mail: #smtpd (Multi-domain, RFC8461/MTA-STS) + #rspamd (DKIM) + #dovecot (IMAPS-only).
Spam-Defense: #spamd with auto-SPF-walk (no more greylisting issues).
Web: #relayd (TLS-Terminator, HSTS, CSP) + #httpd (NIP-05, Autoconfig, security.txt).
Performance: Lightweight "Fail2Ban" via 1-liner shell script (No Python crap!).
#Nostr Relay in Rust building...
#SelfHosted #SysAdmin #Security #Privacy
Finally got around to updating my #OpenBSD router (new hardware) pairing it together with an #OpenWRT AP, funnelling everything through a separate #raspberrypi zero running #pihole
Bonus: my Raspberry Pi 400 is now setup with OpenBSD's httpd / relayd - ready to host all of my web projects locally!
That was sure a lot of buzz words...I'll gather my detailed thoughts and breakdown everything into a blog post soon 😄
Ladles and jellyspoons, @mischa and I are honoured to present, the one and only
#OpenBSD dot Amsterdam Fishtank
$ ssh puffy@fishtank.openbsd.amsterdam
or
$ ssh puffy@ft.obsda.ms
Because all statistics should be presented as whimsical ascii art.
Now go and book a VM with @OpenBSDAms so we can render more ascii fish.
, . , . ° , . , . , .
()< >() ()< >() ()< >() ()< >() ()< >()
` ' · ` 'o ` ' ` ' ` '
Audio on hp300
In the late 1980s, with the expansion of the Internet (even though it was not open to commercial activities yet) and the slowly increasing capabilities of workstations, some people started to imagine the unthinkable: that, some day, you may use your computer to record voice messages, send them over the Internet, and the recipient could listen to these messages on his own computer.
That was definitely sc
Installing #Slackware #Linux using #vmm on #OpenBSD. Got some help from this video on getting the console to display correctly in the terminal.
#RunBSD #BSD #virtualization
https://www.youtube.com/watch?v=sZnM-T6Os-s
Planning on using this as a practice Linux system for my Linux+ studies.
some days I wish upgrading #FreeBSD was as mindless as upgrading my #OpenBSD machines.
On OpenBSD, it's generally `sysupgrade`, let it do its thing, rebooting itself a couple times (entering my FDE passwords as necessary), and then a `pkg_add -u` to upgrade my packages. Sometimes a `sysmerge` if it can't do it automatically. But very much two (or three) idiot-proof commands with very little demand on this idiot's brain to recall where I am in the process.
While I like the automatic ZFS boot-environment snapshotting, FreeBSD requires me to know the next version-number I want to upgrade to (can't determine it or prompt me for viable options?), transcribe it as part of the upgrade command, then manually running `freebsd-update install` multiple times, rebooting manually multiple times between each, then `pkg update` and a `pkg upgrade` to update userspace. I'm sitting at a login…is this the first, second, or third reboot? I don't know, it was taking a while and I ended up wandering off to do something else.
This post brought to you by this morning's 14.3→14.4 FreeBSD upgrade 😆
🍵 

🐡 🚩