paddy wrote:
> When I want a server I install a copy of OpenBSD. One hell of an
> operating system and the finest security software avaliable, IMHO. In
> addition, it takes some configuring to get up and running but the price
> is FREE or you can contribute to the development team by buying CD's for
> $45.
OpenBSD is a robust platform. I've maintained instances of it over the
years. Byte for byte, it's arguably more secure than most Linux
distributions *out of the box*. You rarely see a kernel exploit or
vulnerability in OpenBSD. Things like kernel-level PRNG is good to see,
especially in light of all the sequence-guessing exploits. It also seems
to have a better design and, for lack of a better term, "mission
statement" than Linux.
Now the buts:
It's a big debate whether a rigid design model or the almost chaotic
Linux development model is better....
As far as applications go, Linux and OpenBSD share much of the same code
so it's sort of a wash as far as user space security. For servers, the
SELinux extensions are really powerful. I worked at a firewall company
recently and they chose Linux over OpenBSD because of the MAC (mandatory
access control) features of SELinux *and* because the Linux TCP/IP stack
was better in most cases than OpenBSD's (in fact, some benchmarks place
OpenBSD *last* http://bulk.fefe.de/scalability/ ). Linux currently has
much better scalability (SMP support, e.g.) and this is really necessary
for higher end systems.
-----------------------------------------------------------------------
This list is provided as an unmoderated internet service by Networked
Knowledge Systems (NKS). Views and opinions expressed in messages
posted are those of the author and do not necessarily reflect the
official policy or position of NKS or any of its employees.
This archive was generated by hypermail 2.1.3 : Fri Aug 01 2014 - 19:22:14 EDT