<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>app03</fireside:hostname>
    <fireside:genDate>Fri, 19 Jun 2026 09:00:48 +0000</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>BSD Now - Episodes Tagged with “Cryptography”</title>
    <link>https://www.bsdnow.tv/tags/cryptography</link>
    <pubDate>Wed, 26 Aug 2015 08:00:00 -0400</pubDate>
    <description>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros. The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day.</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>A weekly podcast and the place to B...SD</itunes:subtitle>
    <itunes:author>JT Pennington</itunes:author>
    <itunes:summary>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros. The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day.</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:keywords>berkeley,freebsd,openbsd,netbsd,dragonflybsd,trueos,trident,hardenedbsd,tutorial,howto,guide,bsd,interview</itunes:keywords>
    <itunes:owner>
      <itunes:name>JT Pennington</itunes:name>
      <itunes:email>feedback@bsdnow.tv</itunes:email>
    </itunes:owner>
<itunes:category text="News">
  <itunes:category text="Tech News"/>
</itunes:category>
<itunes:category text="Education">
  <itunes:category text="How To"/>
</itunes:category>
<item>
  <title>104: Beverly Hills 25519</title>
  <link>https://www.bsdnow.tv/104</link>
  <guid isPermaLink="false">0bc0c068-36fe-429f-b7f4-38ac01fb7f19</guid>
  <pubDate>Wed, 26 Aug 2015 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/0bc0c068-36fe-429f-b7f4-38ac01fb7f19.mp3" length="58136116" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>Coming up this week on the show, we'll be talking with Damien Miller of the OpenSSH team. Their 7.0 release has some major changes, including phasing out older crypto and changing one of the defaults that might surprise you.</itunes:subtitle>
  <itunes:duration>1:20:44</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;Coming up this week on the show, we'll be talking with Damien Miller of the OpenSSH team. Their 7.0 release has some major changes, including phasing out older crypto and changing one of the defaults that might surprise you.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"&gt;&lt;/a&gt;&lt;a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"&gt;&lt;img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.tedunangst.com/flak/post/OpenBSD-on-ERL" rel="nofollow noopener"&gt;EdgeRouter Lite, meet OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The ERL, much like the Raspberry Pi and a bunch of other cheap boards, is getting more and more popular as more things get ported to run on it &lt;/li&gt;
&lt;li&gt;We've covered installing NetBSD and FreeBSD on them before, but OpenBSD has gotten a lot better support for them as well now (including the onboard storage in 5.8)&lt;/li&gt;
&lt;li&gt;Ted Unangst got a hold of one recently and kindly wrote up some notes about installing and using OpenBSD on it&lt;/li&gt;
&lt;li&gt;He covers doing a network install, getting the (slightly strange) bootloader working with u-boot and some final notes about the hardware&lt;/li&gt;
&lt;li&gt;More discussion can be found &lt;a href="https://news.ycombinator.com/item?id=10079210" rel="nofollow noopener"&gt;on Hacker News&lt;/a&gt; and &lt;a href="https://www.reddit.com/r/openbsd/comments/3hgf2c" rel="nofollow noopener"&gt;various&lt;/a&gt; &lt;a href="https://www.marc.info/?t=143974140500001&amp;amp;r=1&amp;amp;w=2" rel="nofollow noopener"&gt;other&lt;/a&gt; &lt;a href="https://lobste.rs/s/acz9bu/openbsd_on_edgerouter_lite" rel="nofollow noopener"&gt;places&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;One thing to &lt;a href="https://www.marc.info/?l=openbsd-misc&amp;amp;m=143991822827285&amp;amp;w=2" rel="nofollow noopener"&gt;note&lt;/a&gt; about these devices: because of their MIPS64 processor, they'll have weaker ASLR than X86 CPUs (and no W&lt;sup&gt;X&lt;/sup&gt; at all)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.infoq.com/articles/freebsd-design-implementation-review" rel="nofollow noopener"&gt;Design and Implementation of the FreeBSD Operating System interview&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;For those who don't know, the "Design and Implementation of the FreeBSD Operating System" is a semi-recently-revived technical reference book for FreeBSD development&lt;/li&gt;
&lt;li&gt;InfoQ has a review of the book up for anyone who might be interested, but they also have an interview the authors&lt;/li&gt;
&lt;li&gt;"The book takes an approach to FreeBSD from inside out, starting with kernel services, then moving to process and memory management, I/O and devices, filesystems, IPC and network protocols, and finally system startup and shutdown. The book provides dense, technical information in a clear way, with lots of pseudo-code, diagrams, and tables to illustrate the main points."&lt;/li&gt;
&lt;li&gt;Aside from detailing a few of the chapters, the interview covers who the book's target audience is, some history of the project, long-term support, some of the newer features and some general OS development topics
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=144027474117290&amp;amp;w=2" rel="nofollow noopener"&gt;Path list parameter in OpenBSD tame&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We've mentioned OpenBSD's relatively new "&lt;a href="https://marc.info/?l=openbsd-tech&amp;amp;m=143725996614627&amp;amp;w=2" rel="nofollow noopener"&gt;tame&lt;/a&gt;" subsystem a couple times before: it's an easy-to-implement "self-containment" framework, allowing programs to have a reduced feature set mode with even less privileges&lt;/li&gt;
&lt;li&gt;One of the early concerns from users of other process containment tools was that tame was too broad in the way it separated disk access - you could either read/write files or not, nothing in between&lt;/li&gt;
&lt;li&gt;Now there's the option to create a whitelist of specific files and directories that your binary is allowed to access, giving a much finer-grained set of controls to developers&lt;/li&gt;
&lt;li&gt;The next step is to add tame restraints to the OpenBSD userland utilities, which should probably be done by 5.9&lt;/li&gt;
&lt;li&gt;More discussion can be found &lt;a href="https://www.reddit.com/r/openbsd/comments/3i2lk7" rel="nofollow noopener"&gt;on Reddit&lt;/a&gt; &lt;a href="https://news.ycombinator.com/item?id=10104886" rel="nofollow noopener"&gt;and Hacker News&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.freebsd.org/releases/10.2R/announce.html" rel="nofollow noopener"&gt;FreeBSD &amp;amp; PC-BSD 10.2-RELEASE&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The FreeBSD team has released the second minor version bump to the 10.x branch, including all the fixes from 10-STABLE since 10.1 came out&lt;/li&gt;
&lt;li&gt;The Linux compatibility layer has been updated to support CentOS 6, rather than the much older Fedora Core base used previously, and the DRM graphics code has been updated to match Linux 3.8.13&lt;/li&gt;
&lt;li&gt;New installations (and newly-upgraded systems) will use the quarterly binary package set, rather than the rolling release model that most people are used to&lt;/li&gt;
&lt;li&gt;A VXLAN driver was added, allowing you to create virtual LANs by encapsulating the ethernet frame in a UDP packet&lt;/li&gt;
&lt;li&gt;The bhyve codebase is much newer, enabling support for AMD CPUs with SVM and AMD-V extensions&lt;/li&gt;
&lt;li&gt;ARM and ARM64 code saw some fixes and improvements, including SMP support on a few specific boards and support for a few new boards&lt;/li&gt;
&lt;li&gt;The bootloader now supports entering your GELI passphrase before loading the kernel in full disk encryption setups&lt;/li&gt;
&lt;li&gt;In addition to assorted userland fixes and driver improvements, various third party tools in the base system were updated: resolvconf, ISC NTPd, netcat, file, unbound, OpenSSL, sendmail&lt;/li&gt;
&lt;li&gt;Check the &lt;a href="https://www.freebsd.org/releases/10.2R/relnotes.html" rel="nofollow noopener"&gt;full release notes&lt;/a&gt; for the rest of the details and changes&lt;/li&gt;
&lt;li&gt;PC-BSD also followed with &lt;a href="http://blog.pcbsd.org/2015/08/pc-bsd-10-2-release-now-available" rel="nofollow noopener"&gt;their 10.2-RELEASE&lt;/a&gt;, sporting a few more additional features
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Damien Miller - &lt;a href="mailto:djm@openbsd.org" rel="nofollow noopener"&gt;djm@openbsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/damienmiller" rel="nofollow noopener"&gt;@damienmiller&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;OpenSSH: phasing out broken crypto, default cipher changes&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://mail-index.netbsd.org/netbsd-advocacy/2015/08/22/msg000692.html" rel="nofollow noopener"&gt;NetBSD at Open Source Conference Shimane&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We weren't the only ones away at conferences last week - the Japanese NetBSD guys are always raiding one event or another&lt;/li&gt;
&lt;li&gt;This time they had NetBSD running on some Sony NWS devices (MIPS-based)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://en.wikipedia.org/wiki/JavaStation" rel="nofollow noopener"&gt;JavaStations&lt;/a&gt; were also on display - something we haven't ever seen before (made between 1996-2000)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.youtube.com/watch?v=-XF20nitI90" rel="nofollow noopener"&gt;BAFUG videos&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The Bay Area FreeBSD users group has been uploading some videos of their recent meetings&lt;/li&gt;
&lt;li&gt;Devin Teske hosts the first one, discussing adding GELI support to the bootloader, including some video demonstrations of how it works&lt;/li&gt;
&lt;li&gt;Shortly after beginning, Adrian Chadd takes over the conversation and they discuss various problems (and solutions) related to the bootloader - for example, how can we type encryption passwords with non-US keyboard layouts&lt;/li&gt;
&lt;li&gt;In &lt;a href="https://www.youtube.com/watch?v=49sPYHh473U" rel="nofollow noopener"&gt;a second video&lt;/a&gt;, Jordan Hubbard and Kip Macy introduce "NeXTBSD aka FreeBSD X"&lt;/li&gt;
&lt;li&gt;In it, they discuss their ideas of merging more Mac OS X features into FreeBSD (launchd to replace the init system, some APIs, etc)&lt;/li&gt;
&lt;li&gt;People should record presentations at their BSD users groups and send them to us
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://frankgroeneveld.nl/2015/08/16/configuring-l2tp-over-ipsec-on-openbsd-for-mac-os-x-clients" rel="nofollow noopener"&gt;L2TP over IPSEC on OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;If you've got an OpenBSD box and some Mac OS X clients that need secure communications, surprise: they can work together pretty well&lt;/li&gt;
&lt;li&gt;Using only the base tools in both operating systems, you can build a nice IPSEC setup for tunneling all your traffic&lt;/li&gt;
&lt;li&gt;This guide specifically covers L2TP, using npppd and pre-shared keys&lt;/li&gt;
&lt;li&gt;Server setup, client setup, firewall configuration and routing-related settings are all covered in detail
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.tubsta.com/2015/08/reliable-bare-metal-server-using-trueosfreebsd" rel="nofollow noopener"&gt;Reliable bare metal with TrueOS&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Imagine a server version of PC-BSD with some useful utilities preinstalled - that's basically TrueOS&lt;/li&gt;
&lt;li&gt;This article walks you through setting up a FreeBSD -CURRENT server (using TrueOS) to create a pretty solid backup solution&lt;/li&gt;
&lt;li&gt;Most importantly, he also covers how to keep everything redundant and deal with hard drives failing&lt;/li&gt;
&lt;li&gt;The author chose to go with the -CURRENT branch because of the delay between regular releases, and newer features not making their way to users as fast as he'd like&lt;/li&gt;
&lt;li&gt;Another factor is that there are no binary snapshots of FreeBSD -CURRENT that can be easily used for in-place upgrades, but with TrueOS (and some other BSDs) there are
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=144047868127049&amp;amp;w=2" rel="nofollow noopener"&gt;Kernel W&lt;sup&gt;X&lt;/sup&gt; on i386&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We mentioned some big W&lt;sup&gt;X&lt;/sup&gt; kernel changes in OpenBSD &lt;a href="https://www.marc.info/?l=openbsd-tech&amp;amp;m=142120787308107&amp;amp;w=2" rel="nofollow noopener"&gt;a while back&lt;/a&gt;, but the work was mainly for x86_64 CPU architecture (which makes sense; that's what most people run now)&lt;/li&gt;
&lt;li&gt;Mike Larkin is back again, and isn't leaving the people with older hardware out, committing similar kernel work into the i386 platform now as well&lt;/li&gt;
&lt;li&gt;Check out &lt;a href="http://www.bsdnow.tv/episodes/2015_05_13-exclusive_disjunction" rel="nofollow noopener"&gt;our interview with Mike&lt;/a&gt; for some more background info on memory protections like W&lt;sup&gt;X&lt;/sup&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2iGoeYMyb" rel="nofollow noopener"&gt;Markus writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21bIFfmUS" rel="nofollow noopener"&gt;Sean writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21Hjm8Tsa" rel="nofollow noopener"&gt;Theo writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, openssh, openssl, chacha20, chacha20-poly1305, aes, md5, hmac, cbc, gcm, cryptography, ed25519, curve25519, erl, edgerouter lite, tame, bafug</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Coming up this week on the show, we'll be talking with Damien Miller of the OpenSSH team. Their 7.0 release has some major changes, including phasing out older crypto and changing one of the defaults that might surprise you.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://www.tedunangst.com/flak/post/OpenBSD-on-ERL" rel="nofollow noopener">EdgeRouter Lite, meet OpenBSD</a></h3>

<ul>
<li>The ERL, much like the Raspberry Pi and a bunch of other cheap boards, is getting more and more popular as more things get ported to run on it </li>
<li>We've covered installing NetBSD and FreeBSD on them before, but OpenBSD has gotten a lot better support for them as well now (including the onboard storage in 5.8)</li>
<li>Ted Unangst got a hold of one recently and kindly wrote up some notes about installing and using OpenBSD on it</li>
<li>He covers doing a network install, getting the (slightly strange) bootloader working with u-boot and some final notes about the hardware</li>
<li>More discussion can be found <a href="https://news.ycombinator.com/item?id=10079210" rel="nofollow noopener">on Hacker News</a> and <a href="https://www.reddit.com/r/openbsd/comments/3hgf2c" rel="nofollow noopener">various</a> <a href="https://www.marc.info/?t=143974140500001&amp;r=1&amp;w=2" rel="nofollow noopener">other</a> <a href="https://lobste.rs/s/acz9bu/openbsd_on_edgerouter_lite" rel="nofollow noopener">places</a></li>
<li>One thing to <a href="https://www.marc.info/?l=openbsd-misc&amp;m=143991822827285&amp;w=2" rel="nofollow noopener">note</a> about these devices: because of their MIPS64 processor, they'll have weaker ASLR than X86 CPUs (and no W<sup>X</sup> at all)
***</li>
</ul>

<h3><a href="http://www.infoq.com/articles/freebsd-design-implementation-review" rel="nofollow noopener">Design and Implementation of the FreeBSD Operating System interview</a></h3>

<ul>
<li>For those who don't know, the "Design and Implementation of the FreeBSD Operating System" is a semi-recently-revived technical reference book for FreeBSD development</li>
<li>InfoQ has a review of the book up for anyone who might be interested, but they also have an interview the authors</li>
<li>"The book takes an approach to FreeBSD from inside out, starting with kernel services, then moving to process and memory management, I/O and devices, filesystems, IPC and network protocols, and finally system startup and shutdown. The book provides dense, technical information in a clear way, with lots of pseudo-code, diagrams, and tables to illustrate the main points."</li>
<li>Aside from detailing a few of the chapters, the interview covers who the book's target audience is, some history of the project, long-term support, some of the newer features and some general OS development topics
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144027474117290&amp;w=2" rel="nofollow noopener">Path list parameter in OpenBSD tame</a></h3>

<ul>
<li>We've mentioned OpenBSD's relatively new "<a href="https://marc.info/?l=openbsd-tech&amp;m=143725996614627&amp;w=2" rel="nofollow noopener">tame</a>" subsystem a couple times before: it's an easy-to-implement "self-containment" framework, allowing programs to have a reduced feature set mode with even less privileges</li>
<li>One of the early concerns from users of other process containment tools was that tame was too broad in the way it separated disk access - you could either read/write files or not, nothing in between</li>
<li>Now there's the option to create a whitelist of specific files and directories that your binary is allowed to access, giving a much finer-grained set of controls to developers</li>
<li>The next step is to add tame restraints to the OpenBSD userland utilities, which should probably be done by 5.9</li>
<li>More discussion can be found <a href="https://www.reddit.com/r/openbsd/comments/3i2lk7" rel="nofollow noopener">on Reddit</a> <a href="https://news.ycombinator.com/item?id=10104886" rel="nofollow noopener">and Hacker News</a>
***</li>
</ul>

<h3><a href="https://www.freebsd.org/releases/10.2R/announce.html" rel="nofollow noopener">FreeBSD &amp; PC-BSD 10.2-RELEASE</a></h3>

<ul>
<li>The FreeBSD team has released the second minor version bump to the 10.x branch, including all the fixes from 10-STABLE since 10.1 came out</li>
<li>The Linux compatibility layer has been updated to support CentOS 6, rather than the much older Fedora Core base used previously, and the DRM graphics code has been updated to match Linux 3.8.13</li>
<li>New installations (and newly-upgraded systems) will use the quarterly binary package set, rather than the rolling release model that most people are used to</li>
<li>A VXLAN driver was added, allowing you to create virtual LANs by encapsulating the ethernet frame in a UDP packet</li>
<li>The bhyve codebase is much newer, enabling support for AMD CPUs with SVM and AMD-V extensions</li>
<li>ARM and ARM64 code saw some fixes and improvements, including SMP support on a few specific boards and support for a few new boards</li>
<li>The bootloader now supports entering your GELI passphrase before loading the kernel in full disk encryption setups</li>
<li>In addition to assorted userland fixes and driver improvements, various third party tools in the base system were updated: resolvconf, ISC NTPd, netcat, file, unbound, OpenSSL, sendmail</li>
<li>Check the <a href="https://www.freebsd.org/releases/10.2R/relnotes.html" rel="nofollow noopener">full release notes</a> for the rest of the details and changes</li>
<li>PC-BSD also followed with <a href="http://blog.pcbsd.org/2015/08/pc-bsd-10-2-release-now-available" rel="nofollow noopener">their 10.2-RELEASE</a>, sporting a few more additional features
***</li>
</ul>

<h2>Interview - Damien Miller - <a href="mailto:djm@openbsd.org" rel="nofollow noopener">djm@openbsd.org</a> / <a href="https://twitter.com/damienmiller" rel="nofollow noopener">@damienmiller</a></h2>

<p>OpenSSH: phasing out broken crypto, default cipher changes</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://mail-index.netbsd.org/netbsd-advocacy/2015/08/22/msg000692.html" rel="nofollow noopener">NetBSD at Open Source Conference Shimane</a></h3>

<ul>
<li>We weren't the only ones away at conferences last week - the Japanese NetBSD guys are always raiding one event or another</li>
<li>This time they had NetBSD running on some Sony NWS devices (MIPS-based)</li>
<li><a href="https://en.wikipedia.org/wiki/JavaStation" rel="nofollow noopener">JavaStations</a> were also on display - something we haven't ever seen before (made between 1996-2000)
***</li>
</ul>

<h3><a href="https://www.youtube.com/watch?v=-XF20nitI90" rel="nofollow noopener">BAFUG videos</a></h3>

<ul>
<li>The Bay Area FreeBSD users group has been uploading some videos of their recent meetings</li>
<li>Devin Teske hosts the first one, discussing adding GELI support to the bootloader, including some video demonstrations of how it works</li>
<li>Shortly after beginning, Adrian Chadd takes over the conversation and they discuss various problems (and solutions) related to the bootloader - for example, how can we type encryption passwords with non-US keyboard layouts</li>
<li>In <a href="https://www.youtube.com/watch?v=49sPYHh473U" rel="nofollow noopener">a second video</a>, Jordan Hubbard and Kip Macy introduce "NeXTBSD aka FreeBSD X"</li>
<li>In it, they discuss their ideas of merging more Mac OS X features into FreeBSD (launchd to replace the init system, some APIs, etc)</li>
<li>People should record presentations at their BSD users groups and send them to us
***</li>
</ul>

<h3><a href="http://frankgroeneveld.nl/2015/08/16/configuring-l2tp-over-ipsec-on-openbsd-for-mac-os-x-clients" rel="nofollow noopener">L2TP over IPSEC on OpenBSD</a></h3>

<ul>
<li>If you've got an OpenBSD box and some Mac OS X clients that need secure communications, surprise: they can work together pretty well</li>
<li>Using only the base tools in both operating systems, you can build a nice IPSEC setup for tunneling all your traffic</li>
<li>This guide specifically covers L2TP, using npppd and pre-shared keys</li>
<li>Server setup, client setup, firewall configuration and routing-related settings are all covered in detail
***</li>
</ul>

<h3><a href="http://www.tubsta.com/2015/08/reliable-bare-metal-server-using-trueosfreebsd" rel="nofollow noopener">Reliable bare metal with TrueOS</a></h3>

<ul>
<li>Imagine a server version of PC-BSD with some useful utilities preinstalled - that's basically TrueOS</li>
<li>This article walks you through setting up a FreeBSD -CURRENT server (using TrueOS) to create a pretty solid backup solution</li>
<li>Most importantly, he also covers how to keep everything redundant and deal with hard drives failing</li>
<li>The author chose to go with the -CURRENT branch because of the delay between regular releases, and newer features not making their way to users as fast as he'd like</li>
<li>Another factor is that there are no binary snapshots of FreeBSD -CURRENT that can be easily used for in-place upgrades, but with TrueOS (and some other BSDs) there are
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144047868127049&amp;w=2" rel="nofollow noopener">Kernel W<sup>X</sup> on i386</a></h3>

<ul>
<li>We mentioned some big W<sup>X</sup> kernel changes in OpenBSD <a href="https://www.marc.info/?l=openbsd-tech&amp;m=142120787308107&amp;w=2" rel="nofollow noopener">a while back</a>, but the work was mainly for x86_64 CPU architecture (which makes sense; that's what most people run now)</li>
<li>Mike Larkin is back again, and isn't leaving the people with older hardware out, committing similar kernel work into the i386 platform now as well</li>
<li>Check out <a href="http://www.bsdnow.tv/episodes/2015_05_13-exclusive_disjunction" rel="nofollow noopener">our interview with Mike</a> for some more background info on memory protections like W<sup>X</sup>
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2iGoeYMyb" rel="nofollow noopener">Markus writes in</a></li>
<li><a href="http://slexy.org/view/s21bIFfmUS" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s21Hjm8Tsa" rel="nofollow noopener">Theo writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Coming up this week on the show, we'll be talking with Damien Miller of the OpenSSH team. Their 7.0 release has some major changes, including phasing out older crypto and changing one of the defaults that might surprise you.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://www.tedunangst.com/flak/post/OpenBSD-on-ERL" rel="nofollow noopener">EdgeRouter Lite, meet OpenBSD</a></h3>

<ul>
<li>The ERL, much like the Raspberry Pi and a bunch of other cheap boards, is getting more and more popular as more things get ported to run on it </li>
<li>We've covered installing NetBSD and FreeBSD on them before, but OpenBSD has gotten a lot better support for them as well now (including the onboard storage in 5.8)</li>
<li>Ted Unangst got a hold of one recently and kindly wrote up some notes about installing and using OpenBSD on it</li>
<li>He covers doing a network install, getting the (slightly strange) bootloader working with u-boot and some final notes about the hardware</li>
<li>More discussion can be found <a href="https://news.ycombinator.com/item?id=10079210" rel="nofollow noopener">on Hacker News</a> and <a href="https://www.reddit.com/r/openbsd/comments/3hgf2c" rel="nofollow noopener">various</a> <a href="https://www.marc.info/?t=143974140500001&amp;r=1&amp;w=2" rel="nofollow noopener">other</a> <a href="https://lobste.rs/s/acz9bu/openbsd_on_edgerouter_lite" rel="nofollow noopener">places</a></li>
<li>One thing to <a href="https://www.marc.info/?l=openbsd-misc&amp;m=143991822827285&amp;w=2" rel="nofollow noopener">note</a> about these devices: because of their MIPS64 processor, they'll have weaker ASLR than X86 CPUs (and no W<sup>X</sup> at all)
***</li>
</ul>

<h3><a href="http://www.infoq.com/articles/freebsd-design-implementation-review" rel="nofollow noopener">Design and Implementation of the FreeBSD Operating System interview</a></h3>

<ul>
<li>For those who don't know, the "Design and Implementation of the FreeBSD Operating System" is a semi-recently-revived technical reference book for FreeBSD development</li>
<li>InfoQ has a review of the book up for anyone who might be interested, but they also have an interview the authors</li>
<li>"The book takes an approach to FreeBSD from inside out, starting with kernel services, then moving to process and memory management, I/O and devices, filesystems, IPC and network protocols, and finally system startup and shutdown. The book provides dense, technical information in a clear way, with lots of pseudo-code, diagrams, and tables to illustrate the main points."</li>
<li>Aside from detailing a few of the chapters, the interview covers who the book's target audience is, some history of the project, long-term support, some of the newer features and some general OS development topics
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144027474117290&amp;w=2" rel="nofollow noopener">Path list parameter in OpenBSD tame</a></h3>

<ul>
<li>We've mentioned OpenBSD's relatively new "<a href="https://marc.info/?l=openbsd-tech&amp;m=143725996614627&amp;w=2" rel="nofollow noopener">tame</a>" subsystem a couple times before: it's an easy-to-implement "self-containment" framework, allowing programs to have a reduced feature set mode with even less privileges</li>
<li>One of the early concerns from users of other process containment tools was that tame was too broad in the way it separated disk access - you could either read/write files or not, nothing in between</li>
<li>Now there's the option to create a whitelist of specific files and directories that your binary is allowed to access, giving a much finer-grained set of controls to developers</li>
<li>The next step is to add tame restraints to the OpenBSD userland utilities, which should probably be done by 5.9</li>
<li>More discussion can be found <a href="https://www.reddit.com/r/openbsd/comments/3i2lk7" rel="nofollow noopener">on Reddit</a> <a href="https://news.ycombinator.com/item?id=10104886" rel="nofollow noopener">and Hacker News</a>
***</li>
</ul>

<h3><a href="https://www.freebsd.org/releases/10.2R/announce.html" rel="nofollow noopener">FreeBSD &amp; PC-BSD 10.2-RELEASE</a></h3>

<ul>
<li>The FreeBSD team has released the second minor version bump to the 10.x branch, including all the fixes from 10-STABLE since 10.1 came out</li>
<li>The Linux compatibility layer has been updated to support CentOS 6, rather than the much older Fedora Core base used previously, and the DRM graphics code has been updated to match Linux 3.8.13</li>
<li>New installations (and newly-upgraded systems) will use the quarterly binary package set, rather than the rolling release model that most people are used to</li>
<li>A VXLAN driver was added, allowing you to create virtual LANs by encapsulating the ethernet frame in a UDP packet</li>
<li>The bhyve codebase is much newer, enabling support for AMD CPUs with SVM and AMD-V extensions</li>
<li>ARM and ARM64 code saw some fixes and improvements, including SMP support on a few specific boards and support for a few new boards</li>
<li>The bootloader now supports entering your GELI passphrase before loading the kernel in full disk encryption setups</li>
<li>In addition to assorted userland fixes and driver improvements, various third party tools in the base system were updated: resolvconf, ISC NTPd, netcat, file, unbound, OpenSSL, sendmail</li>
<li>Check the <a href="https://www.freebsd.org/releases/10.2R/relnotes.html" rel="nofollow noopener">full release notes</a> for the rest of the details and changes</li>
<li>PC-BSD also followed with <a href="http://blog.pcbsd.org/2015/08/pc-bsd-10-2-release-now-available" rel="nofollow noopener">their 10.2-RELEASE</a>, sporting a few more additional features
***</li>
</ul>

<h2>Interview - Damien Miller - <a href="mailto:djm@openbsd.org" rel="nofollow noopener">djm@openbsd.org</a> / <a href="https://twitter.com/damienmiller" rel="nofollow noopener">@damienmiller</a></h2>

<p>OpenSSH: phasing out broken crypto, default cipher changes</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://mail-index.netbsd.org/netbsd-advocacy/2015/08/22/msg000692.html" rel="nofollow noopener">NetBSD at Open Source Conference Shimane</a></h3>

<ul>
<li>We weren't the only ones away at conferences last week - the Japanese NetBSD guys are always raiding one event or another</li>
<li>This time they had NetBSD running on some Sony NWS devices (MIPS-based)</li>
<li><a href="https://en.wikipedia.org/wiki/JavaStation" rel="nofollow noopener">JavaStations</a> were also on display - something we haven't ever seen before (made between 1996-2000)
***</li>
</ul>

<h3><a href="https://www.youtube.com/watch?v=-XF20nitI90" rel="nofollow noopener">BAFUG videos</a></h3>

<ul>
<li>The Bay Area FreeBSD users group has been uploading some videos of their recent meetings</li>
<li>Devin Teske hosts the first one, discussing adding GELI support to the bootloader, including some video demonstrations of how it works</li>
<li>Shortly after beginning, Adrian Chadd takes over the conversation and they discuss various problems (and solutions) related to the bootloader - for example, how can we type encryption passwords with non-US keyboard layouts</li>
<li>In <a href="https://www.youtube.com/watch?v=49sPYHh473U" rel="nofollow noopener">a second video</a>, Jordan Hubbard and Kip Macy introduce "NeXTBSD aka FreeBSD X"</li>
<li>In it, they discuss their ideas of merging more Mac OS X features into FreeBSD (launchd to replace the init system, some APIs, etc)</li>
<li>People should record presentations at their BSD users groups and send them to us
***</li>
</ul>

<h3><a href="http://frankgroeneveld.nl/2015/08/16/configuring-l2tp-over-ipsec-on-openbsd-for-mac-os-x-clients" rel="nofollow noopener">L2TP over IPSEC on OpenBSD</a></h3>

<ul>
<li>If you've got an OpenBSD box and some Mac OS X clients that need secure communications, surprise: they can work together pretty well</li>
<li>Using only the base tools in both operating systems, you can build a nice IPSEC setup for tunneling all your traffic</li>
<li>This guide specifically covers L2TP, using npppd and pre-shared keys</li>
<li>Server setup, client setup, firewall configuration and routing-related settings are all covered in detail
***</li>
</ul>

<h3><a href="http://www.tubsta.com/2015/08/reliable-bare-metal-server-using-trueosfreebsd" rel="nofollow noopener">Reliable bare metal with TrueOS</a></h3>

<ul>
<li>Imagine a server version of PC-BSD with some useful utilities preinstalled - that's basically TrueOS</li>
<li>This article walks you through setting up a FreeBSD -CURRENT server (using TrueOS) to create a pretty solid backup solution</li>
<li>Most importantly, he also covers how to keep everything redundant and deal with hard drives failing</li>
<li>The author chose to go with the -CURRENT branch because of the delay between regular releases, and newer features not making their way to users as fast as he'd like</li>
<li>Another factor is that there are no binary snapshots of FreeBSD -CURRENT that can be easily used for in-place upgrades, but with TrueOS (and some other BSDs) there are
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144047868127049&amp;w=2" rel="nofollow noopener">Kernel W<sup>X</sup> on i386</a></h3>

<ul>
<li>We mentioned some big W<sup>X</sup> kernel changes in OpenBSD <a href="https://www.marc.info/?l=openbsd-tech&amp;m=142120787308107&amp;w=2" rel="nofollow noopener">a while back</a>, but the work was mainly for x86_64 CPU architecture (which makes sense; that's what most people run now)</li>
<li>Mike Larkin is back again, and isn't leaving the people with older hardware out, committing similar kernel work into the i386 platform now as well</li>
<li>Check out <a href="http://www.bsdnow.tv/episodes/2015_05_13-exclusive_disjunction" rel="nofollow noopener">our interview with Mike</a> for some more background info on memory protections like W<sup>X</sup>
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2iGoeYMyb" rel="nofollow noopener">Markus writes in</a></li>
<li><a href="http://slexy.org/view/s21bIFfmUS" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s21Hjm8Tsa" rel="nofollow noopener">Theo writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>91: Vox Populi</title>
  <link>https://www.bsdnow.tv/91</link>
  <guid isPermaLink="false">fb5f8b6c-3786-48ec-b8ed-0e2d4d62f539</guid>
  <pubDate>Wed, 27 May 2015 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/fb5f8b6c-3786-48ec-b8ed-0e2d4d62f539.mp3" length="52090996" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This week on the show, we've got something pretty different. We went to a Linux convention and asked various people if they've ever tried BSD and what they know about it. Stay tuned for that, all this week's news and, of course, answers to your emails, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:12:20</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This week on the show, we've got something pretty different. We went to a Linux convention and asked various people if they've ever tried BSD and what they know about it. Stay tuned for that, all this week's news and, of course, answers to your emails, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"&gt;&lt;/a&gt;&lt;a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"&gt;&lt;img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.marc.info/?l=openbsd-tech&amp;amp;m=143247114716771&amp;amp;w=2" rel="nofollow noopener"&gt;LUKS in OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Last week, we were surprised to find out that DragonFlyBSD &lt;a href="http://leaf.dragonflybsd.org/cgi/web-man?command=cryptsetup&amp;amp;section=8" rel="nofollow noopener"&gt;has support&lt;/a&gt; for &lt;a href="https://en.wikipedia.org/wiki/Dm-crypt" rel="nofollow noopener"&gt;dm-crypt&lt;/a&gt;, sometimes referred to as LUKS (&lt;a href="https://en.wikipedia.org/wiki/Linux_Unified_Key_Setup" rel="nofollow noopener"&gt;Linux Unified Key Setup&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;It looks like they might not be the only BSD with support for it for much longer, as OpenBSD is currently reviewing a patch for it as well&lt;/li&gt;
&lt;li&gt;LUKS would presumably be an additional option in OpenBSD's &lt;a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man4/softraid.4" rel="nofollow noopener"&gt;softraid&lt;/a&gt; system, which already provides native disk encryption&lt;/li&gt;
&lt;li&gt;Support hasn't been officially committed yet, it's still going through testing, but the code is there if you want to try it out and report your findings&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;If enabled&lt;/strong&gt;, this might pave the way for the first (semi-)cross platform encryption scheme since the demise of TrueCrypt (and maybe other BSDs will get it too in time)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://lists.freebsd.org/pipermail/svn-src-head/2015-May/072255.html" rel="nofollow noopener"&gt;FreeBSD gets 64bit Linux emulation&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;For those who might be unfamiliar, FreeBSD has an &lt;a href="https://www.freebsd.org/doc/handbook/linuxemu.html" rel="nofollow noopener"&gt;emulation layer&lt;/a&gt; to run Linux-only binaries (as rare as they may be)&lt;/li&gt;
&lt;li&gt;The most common use case is for desktop users, enabling them to run proprietary applications like Adobe Flash or Skype&lt;/li&gt;
&lt;li&gt;Similar systems can also be found &lt;a href="https://www.netbsd.org/docs/guide/en/chap-linux.html" rel="nofollow noopener"&gt;in NetBSD&lt;/a&gt; &lt;a href="http://www.openbsd.org/faq/faq9.html#Interact" rel="nofollow noopener"&gt;and OpenBSD&lt;/a&gt; (though disabled by default on the latter)&lt;/li&gt;
&lt;li&gt;However, until now, it's only supported binaries compiled for the i386 architecture&lt;/li&gt;
&lt;li&gt;This new update, already committed to -CURRENT, will open some new possibilities that weren't previously possible&lt;/li&gt;
&lt;li&gt;Meanwhile, HardenedBSD considers &lt;a href="https://hardenedbsd.org/content/poll-linuxulator-removal" rel="nofollow noopener"&gt;removing the emulation layer&lt;/a&gt; entirely
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://mail-index.netbsd.org/netbsd-advocacy/2015/05/23/msg000686.html" rel="nofollow noopener"&gt;BSD at Open Source Conference 2015 Nagoya&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We've covered the Japanese NetBSD users group setting up lots of machines at various conferences in the past, but now they're expanding&lt;/li&gt;
&lt;li&gt;Their latest report includes many of the NetBSD things you'd expect, but also a couple OpenBSD machines&lt;/li&gt;
&lt;li&gt;Some of the NetBSD ones included a Power Mac G4, SHARP NetWalker, Cubieboard2 and the not-so-foreign Raspberry Pi&lt;/li&gt;
&lt;li&gt;One new addition of interest is the OMRON LUNA88k, running the &lt;a href="http://www.openbsd.org/luna88k.html" rel="nofollow noopener"&gt;luna88k&lt;/a&gt; port of OpenBSD&lt;/li&gt;
&lt;li&gt;There was even an old cell phone &lt;a href="https://twitter.com/tsutsuii/status/601458973338775553" rel="nofollow noopener"&gt;running Windows games&lt;/a&gt; on NetBSD&lt;/li&gt;
&lt;li&gt;Check the mailing list post for &lt;a href="https://pbs.twimg.com/media/CFrSmztWEAAS2uE.jpg" rel="nofollow noopener"&gt;some&lt;/a&gt; &lt;a href="http://image.movapic.com/pic/m_201505230541335560130d49213.jpeg" rel="nofollow noopener"&gt;links&lt;/a&gt; &lt;a href="http://image.movapic.com/pic/m_2015052305145455600ccea723a.jpeg" rel="nofollow noopener"&gt;to&lt;/a&gt; &lt;a href="https://pbs.twimg.com/media/CFjPv9_UEAA8iEx.jpg:large" rel="nofollow noopener"&gt;all&lt;/a&gt; &lt;a href="https://pbs.twimg.com/media/CD4k6ZUUMAA0tEM.jpg" rel="nofollow noopener"&gt;of&lt;/a&gt; &lt;a href="https://pbs.twimg.com/media/CFqn1GXUsAAFuro.jpg" rel="nofollow noopener"&gt;the&lt;/a&gt; &lt;a href="https://pbs.twimg.com/media/CFdIS2IUkAAZvjc.jpg" rel="nofollow noopener"&gt;nice&lt;/a&gt; &lt;a href="https://pbs.twimg.com/media/CFf5mToUIAAFrRU.jpg" rel="nofollow noopener"&gt;pictures&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.llvm.org/2015/05/openmp-support_22.html" rel="nofollow noopener"&gt;LLVM introduces OpenMP support&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;One of the things that has kept some people in the GCC camp is the lack of &lt;a href="https://en.wikipedia.org/wiki/OpenMP" rel="nofollow noopener"&gt;OpenMP&lt;/a&gt; support in LLVM&lt;/li&gt;
&lt;li&gt;According to the blog post, it "enables Clang users to harness full power of modern multi-core processors with vector units"&lt;/li&gt;
&lt;li&gt;With Clang being the default in FreeBSD, Bitrig and OS X, and with some other BSDs exploring the option of switching, the need for this potential speed boost was definitely there&lt;/li&gt;
&lt;li&gt;This could also open some doors for more BSD in the area of high performance computing, putting an end to the current Linux monopoly
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Eric, FSF, John, Jose, Kris and Stewart&lt;/h2&gt;

&lt;p&gt;Various "man on the street" style mini-interviews&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://gitlab.com/worr/libintl/blob/master/src/usr.bin/gettext/gettext.c" rel="nofollow noopener"&gt;BSD-licensed gettext replacement&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;If you've ever installed ports on any of the BSDs, you've probably had GNU's gettext pulled in as a dependency&lt;/li&gt;
&lt;li&gt;Wikipedia says "gettext is an internationalization and localization (i18n) system commonly used for writing multilingual programs on Unix-like computer operating systems"&lt;/li&gt;
&lt;li&gt;A new BSD-licensed rewrite has begun, with the initial version being for NetBSD (but it's likely to be portable)&lt;/li&gt;
&lt;li&gt;If you've got some coding skills, get involved with the project - the more freely-licensed replacements, the better
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://github.com/dspinellis/unix-history-repo" rel="nofollow noopener"&gt;Unix history git repo&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A git repository was recently created to show off some Unix source code history&lt;/li&gt;
&lt;li&gt;The repository contains 659 thousand commits and 2306 merges&lt;/li&gt;
&lt;li&gt;You can see early 386BSD commits all the way up to some of the more modern FreeBSD code&lt;/li&gt;
&lt;li&gt;If you want to browse through the &lt;em&gt;giant&lt;/em&gt; codebase, it can be a great history lesson
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.pcbsd.org/2015/05/hotfix-release-to-10-1-2-now-available/" rel="nofollow noopener"&gt;PCBSD 10.1.2 and Lumina updates&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We mentioned 10.1.1 being released last week (and all the cool features a couple weeks before) but now 10.1.2 is out&lt;/li&gt;
&lt;li&gt;This minor update contained a few hotfixes: RAID-Z installation, cache and log devices and the text-only installer in UEFI mode&lt;/li&gt;
&lt;li&gt;There's also a &lt;a href="http://blog.pcbsd.org/2015/05/lumina-desktop-status-updatefaq/" rel="nofollow noopener"&gt;new post&lt;/a&gt; on the PCBSD blog about Lumina, answering some frequently asked questions and giving a general status update
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s25h4Biwzq" rel="nofollow noopener"&gt;Jake writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2AF0bGmL6" rel="nofollow noopener"&gt;Van writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20Ie1USFD" rel="nofollow noopener"&gt;Anonymous writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20vBtoKqL" rel="nofollow noopener"&gt;Dominik writes in&lt;/a&gt; (&lt;a href="http://slexy.org/view/s20RjbIT5v" rel="nofollow noopener"&gt;text answer&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20USR3WzT" rel="nofollow noopener"&gt;Chris writes in&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Mailing List Gold&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://lists.mindrot.org/pipermail/openssh-unix-dev/2015-May/033945.html" rel="nofollow noopener"&gt;Death by chocolate&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, lfnw, linuxfest northwest, fsf, rms, hammer fs, nagoya, osc, dm-crypt, luks, cryptography, openmp, clang, llvm</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This week on the show, we've got something pretty different. We went to a Linux convention and asked various people if they've ever tried BSD and what they know about it. Stay tuned for that, all this week's news and, of course, answers to your emails, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.marc.info/?l=openbsd-tech&amp;m=143247114716771&amp;w=2" rel="nofollow noopener">LUKS in OpenBSD</a></h3>

<ul>
<li>Last week, we were surprised to find out that DragonFlyBSD <a href="http://leaf.dragonflybsd.org/cgi/web-man?command=cryptsetup&amp;section=8" rel="nofollow noopener">has support</a> for <a href="https://en.wikipedia.org/wiki/Dm-crypt" rel="nofollow noopener">dm-crypt</a>, sometimes referred to as LUKS (<a href="https://en.wikipedia.org/wiki/Linux_Unified_Key_Setup" rel="nofollow noopener">Linux Unified Key Setup</a>)</li>
<li>It looks like they might not be the only BSD with support for it for much longer, as OpenBSD is currently reviewing a patch for it as well</li>
<li>LUKS would presumably be an additional option in OpenBSD's <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man4/softraid.4" rel="nofollow noopener">softraid</a> system, which already provides native disk encryption</li>
<li>Support hasn't been officially committed yet, it's still going through testing, but the code is there if you want to try it out and report your findings</li>
<li><strong>If enabled</strong>, this might pave the way for the first (semi-)cross platform encryption scheme since the demise of TrueCrypt (and maybe other BSDs will get it too in time)
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/svn-src-head/2015-May/072255.html" rel="nofollow noopener">FreeBSD gets 64bit Linux emulation</a></h3>

<ul>
<li>For those who might be unfamiliar, FreeBSD has an <a href="https://www.freebsd.org/doc/handbook/linuxemu.html" rel="nofollow noopener">emulation layer</a> to run Linux-only binaries (as rare as they may be)</li>
<li>The most common use case is for desktop users, enabling them to run proprietary applications like Adobe Flash or Skype</li>
<li>Similar systems can also be found <a href="https://www.netbsd.org/docs/guide/en/chap-linux.html" rel="nofollow noopener">in NetBSD</a> <a href="http://www.openbsd.org/faq/faq9.html#Interact" rel="nofollow noopener">and OpenBSD</a> (though disabled by default on the latter)</li>
<li>However, until now, it's only supported binaries compiled for the i386 architecture</li>
<li>This new update, already committed to -CURRENT, will open some new possibilities that weren't previously possible</li>
<li>Meanwhile, HardenedBSD considers <a href="https://hardenedbsd.org/content/poll-linuxulator-removal" rel="nofollow noopener">removing the emulation layer</a> entirely
***</li>
</ul>

<h3><a href="https://mail-index.netbsd.org/netbsd-advocacy/2015/05/23/msg000686.html" rel="nofollow noopener">BSD at Open Source Conference 2015 Nagoya</a></h3>

<ul>
<li>We've covered the Japanese NetBSD users group setting up lots of machines at various conferences in the past, but now they're expanding</li>
<li>Their latest report includes many of the NetBSD things you'd expect, but also a couple OpenBSD machines</li>
<li>Some of the NetBSD ones included a Power Mac G4, SHARP NetWalker, Cubieboard2 and the not-so-foreign Raspberry Pi</li>
<li>One new addition of interest is the OMRON LUNA88k, running the <a href="http://www.openbsd.org/luna88k.html" rel="nofollow noopener">luna88k</a> port of OpenBSD</li>
<li>There was even an old cell phone <a href="https://twitter.com/tsutsuii/status/601458973338775553" rel="nofollow noopener">running Windows games</a> on NetBSD</li>
<li>Check the mailing list post for <a href="https://pbs.twimg.com/media/CFrSmztWEAAS2uE.jpg" rel="nofollow noopener">some</a> <a href="http://image.movapic.com/pic/m_201505230541335560130d49213.jpeg" rel="nofollow noopener">links</a> <a href="http://image.movapic.com/pic/m_2015052305145455600ccea723a.jpeg" rel="nofollow noopener">to</a> <a href="https://pbs.twimg.com/media/CFjPv9_UEAA8iEx.jpg:large" rel="nofollow noopener">all</a> <a href="https://pbs.twimg.com/media/CD4k6ZUUMAA0tEM.jpg" rel="nofollow noopener">of</a> <a href="https://pbs.twimg.com/media/CFqn1GXUsAAFuro.jpg" rel="nofollow noopener">the</a> <a href="https://pbs.twimg.com/media/CFdIS2IUkAAZvjc.jpg" rel="nofollow noopener">nice</a> <a href="https://pbs.twimg.com/media/CFf5mToUIAAFrRU.jpg" rel="nofollow noopener">pictures</a>
***</li>
</ul>

<h3><a href="http://blog.llvm.org/2015/05/openmp-support_22.html" rel="nofollow noopener">LLVM introduces OpenMP support</a></h3>

<ul>
<li>One of the things that has kept some people in the GCC camp is the lack of <a href="https://en.wikipedia.org/wiki/OpenMP" rel="nofollow noopener">OpenMP</a> support in LLVM</li>
<li>According to the blog post, it "enables Clang users to harness full power of modern multi-core processors with vector units"</li>
<li>With Clang being the default in FreeBSD, Bitrig and OS X, and with some other BSDs exploring the option of switching, the need for this potential speed boost was definitely there</li>
<li>This could also open some doors for more BSD in the area of high performance computing, putting an end to the current Linux monopoly
***</li>
</ul>

<h2>Interview - Eric, FSF, John, Jose, Kris and Stewart</h2>

<p>Various "man on the street" style mini-interviews</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://gitlab.com/worr/libintl/blob/master/src/usr.bin/gettext/gettext.c" rel="nofollow noopener">BSD-licensed gettext replacement</a></h3>

<ul>
<li>If you've ever installed ports on any of the BSDs, you've probably had GNU's gettext pulled in as a dependency</li>
<li>Wikipedia says "gettext is an internationalization and localization (i18n) system commonly used for writing multilingual programs on Unix-like computer operating systems"</li>
<li>A new BSD-licensed rewrite has begun, with the initial version being for NetBSD (but it's likely to be portable)</li>
<li>If you've got some coding skills, get involved with the project - the more freely-licensed replacements, the better
***</li>
</ul>

<h3><a href="https://github.com/dspinellis/unix-history-repo" rel="nofollow noopener">Unix history git repo</a></h3>

<ul>
<li>A git repository was recently created to show off some Unix source code history</li>
<li>The repository contains 659 thousand commits and 2306 merges</li>
<li>You can see early 386BSD commits all the way up to some of the more modern FreeBSD code</li>
<li>If you want to browse through the <em>giant</em> codebase, it can be a great history lesson
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2015/05/hotfix-release-to-10-1-2-now-available/" rel="nofollow noopener">PCBSD 10.1.2 and Lumina updates</a></h3>

<ul>
<li>We mentioned 10.1.1 being released last week (and all the cool features a couple weeks before) but now 10.1.2 is out</li>
<li>This minor update contained a few hotfixes: RAID-Z installation, cache and log devices and the text-only installer in UEFI mode</li>
<li>There's also a <a href="http://blog.pcbsd.org/2015/05/lumina-desktop-status-updatefaq/" rel="nofollow noopener">new post</a> on the PCBSD blog about Lumina, answering some frequently asked questions and giving a general status update
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s25h4Biwzq" rel="nofollow noopener">Jake writes in</a></li>
<li><a href="http://slexy.org/view/s2AF0bGmL6" rel="nofollow noopener">Van writes in</a></li>
<li><a href="http://slexy.org/view/s20Ie1USFD" rel="nofollow noopener">Anonymous writes in</a></li>
<li><a href="http://slexy.org/view/s20vBtoKqL" rel="nofollow noopener">Dominik writes in</a> (<a href="http://slexy.org/view/s20RjbIT5v" rel="nofollow noopener">text answer</a>)</li>
<li><a href="http://slexy.org/view/s20USR3WzT" rel="nofollow noopener">Chris writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://lists.mindrot.org/pipermail/openssh-unix-dev/2015-May/033945.html" rel="nofollow noopener">Death by chocolate</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This week on the show, we've got something pretty different. We went to a Linux convention and asked various people if they've ever tried BSD and what they know about it. Stay tuned for that, all this week's news and, of course, answers to your emails, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.marc.info/?l=openbsd-tech&amp;m=143247114716771&amp;w=2" rel="nofollow noopener">LUKS in OpenBSD</a></h3>

<ul>
<li>Last week, we were surprised to find out that DragonFlyBSD <a href="http://leaf.dragonflybsd.org/cgi/web-man?command=cryptsetup&amp;section=8" rel="nofollow noopener">has support</a> for <a href="https://en.wikipedia.org/wiki/Dm-crypt" rel="nofollow noopener">dm-crypt</a>, sometimes referred to as LUKS (<a href="https://en.wikipedia.org/wiki/Linux_Unified_Key_Setup" rel="nofollow noopener">Linux Unified Key Setup</a>)</li>
<li>It looks like they might not be the only BSD with support for it for much longer, as OpenBSD is currently reviewing a patch for it as well</li>
<li>LUKS would presumably be an additional option in OpenBSD's <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man4/softraid.4" rel="nofollow noopener">softraid</a> system, which already provides native disk encryption</li>
<li>Support hasn't been officially committed yet, it's still going through testing, but the code is there if you want to try it out and report your findings</li>
<li><strong>If enabled</strong>, this might pave the way for the first (semi-)cross platform encryption scheme since the demise of TrueCrypt (and maybe other BSDs will get it too in time)
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/svn-src-head/2015-May/072255.html" rel="nofollow noopener">FreeBSD gets 64bit Linux emulation</a></h3>

<ul>
<li>For those who might be unfamiliar, FreeBSD has an <a href="https://www.freebsd.org/doc/handbook/linuxemu.html" rel="nofollow noopener">emulation layer</a> to run Linux-only binaries (as rare as they may be)</li>
<li>The most common use case is for desktop users, enabling them to run proprietary applications like Adobe Flash or Skype</li>
<li>Similar systems can also be found <a href="https://www.netbsd.org/docs/guide/en/chap-linux.html" rel="nofollow noopener">in NetBSD</a> <a href="http://www.openbsd.org/faq/faq9.html#Interact" rel="nofollow noopener">and OpenBSD</a> (though disabled by default on the latter)</li>
<li>However, until now, it's only supported binaries compiled for the i386 architecture</li>
<li>This new update, already committed to -CURRENT, will open some new possibilities that weren't previously possible</li>
<li>Meanwhile, HardenedBSD considers <a href="https://hardenedbsd.org/content/poll-linuxulator-removal" rel="nofollow noopener">removing the emulation layer</a> entirely
***</li>
</ul>

<h3><a href="https://mail-index.netbsd.org/netbsd-advocacy/2015/05/23/msg000686.html" rel="nofollow noopener">BSD at Open Source Conference 2015 Nagoya</a></h3>

<ul>
<li>We've covered the Japanese NetBSD users group setting up lots of machines at various conferences in the past, but now they're expanding</li>
<li>Their latest report includes many of the NetBSD things you'd expect, but also a couple OpenBSD machines</li>
<li>Some of the NetBSD ones included a Power Mac G4, SHARP NetWalker, Cubieboard2 and the not-so-foreign Raspberry Pi</li>
<li>One new addition of interest is the OMRON LUNA88k, running the <a href="http://www.openbsd.org/luna88k.html" rel="nofollow noopener">luna88k</a> port of OpenBSD</li>
<li>There was even an old cell phone <a href="https://twitter.com/tsutsuii/status/601458973338775553" rel="nofollow noopener">running Windows games</a> on NetBSD</li>
<li>Check the mailing list post for <a href="https://pbs.twimg.com/media/CFrSmztWEAAS2uE.jpg" rel="nofollow noopener">some</a> <a href="http://image.movapic.com/pic/m_201505230541335560130d49213.jpeg" rel="nofollow noopener">links</a> <a href="http://image.movapic.com/pic/m_2015052305145455600ccea723a.jpeg" rel="nofollow noopener">to</a> <a href="https://pbs.twimg.com/media/CFjPv9_UEAA8iEx.jpg:large" rel="nofollow noopener">all</a> <a href="https://pbs.twimg.com/media/CD4k6ZUUMAA0tEM.jpg" rel="nofollow noopener">of</a> <a href="https://pbs.twimg.com/media/CFqn1GXUsAAFuro.jpg" rel="nofollow noopener">the</a> <a href="https://pbs.twimg.com/media/CFdIS2IUkAAZvjc.jpg" rel="nofollow noopener">nice</a> <a href="https://pbs.twimg.com/media/CFf5mToUIAAFrRU.jpg" rel="nofollow noopener">pictures</a>
***</li>
</ul>

<h3><a href="http://blog.llvm.org/2015/05/openmp-support_22.html" rel="nofollow noopener">LLVM introduces OpenMP support</a></h3>

<ul>
<li>One of the things that has kept some people in the GCC camp is the lack of <a href="https://en.wikipedia.org/wiki/OpenMP" rel="nofollow noopener">OpenMP</a> support in LLVM</li>
<li>According to the blog post, it "enables Clang users to harness full power of modern multi-core processors with vector units"</li>
<li>With Clang being the default in FreeBSD, Bitrig and OS X, and with some other BSDs exploring the option of switching, the need for this potential speed boost was definitely there</li>
<li>This could also open some doors for more BSD in the area of high performance computing, putting an end to the current Linux monopoly
***</li>
</ul>

<h2>Interview - Eric, FSF, John, Jose, Kris and Stewart</h2>

<p>Various "man on the street" style mini-interviews</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://gitlab.com/worr/libintl/blob/master/src/usr.bin/gettext/gettext.c" rel="nofollow noopener">BSD-licensed gettext replacement</a></h3>

<ul>
<li>If you've ever installed ports on any of the BSDs, you've probably had GNU's gettext pulled in as a dependency</li>
<li>Wikipedia says "gettext is an internationalization and localization (i18n) system commonly used for writing multilingual programs on Unix-like computer operating systems"</li>
<li>A new BSD-licensed rewrite has begun, with the initial version being for NetBSD (but it's likely to be portable)</li>
<li>If you've got some coding skills, get involved with the project - the more freely-licensed replacements, the better
***</li>
</ul>

<h3><a href="https://github.com/dspinellis/unix-history-repo" rel="nofollow noopener">Unix history git repo</a></h3>

<ul>
<li>A git repository was recently created to show off some Unix source code history</li>
<li>The repository contains 659 thousand commits and 2306 merges</li>
<li>You can see early 386BSD commits all the way up to some of the more modern FreeBSD code</li>
<li>If you want to browse through the <em>giant</em> codebase, it can be a great history lesson
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2015/05/hotfix-release-to-10-1-2-now-available/" rel="nofollow noopener">PCBSD 10.1.2 and Lumina updates</a></h3>

<ul>
<li>We mentioned 10.1.1 being released last week (and all the cool features a couple weeks before) but now 10.1.2 is out</li>
<li>This minor update contained a few hotfixes: RAID-Z installation, cache and log devices and the text-only installer in UEFI mode</li>
<li>There's also a <a href="http://blog.pcbsd.org/2015/05/lumina-desktop-status-updatefaq/" rel="nofollow noopener">new post</a> on the PCBSD blog about Lumina, answering some frequently asked questions and giving a general status update
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s25h4Biwzq" rel="nofollow noopener">Jake writes in</a></li>
<li><a href="http://slexy.org/view/s2AF0bGmL6" rel="nofollow noopener">Van writes in</a></li>
<li><a href="http://slexy.org/view/s20Ie1USFD" rel="nofollow noopener">Anonymous writes in</a></li>
<li><a href="http://slexy.org/view/s20vBtoKqL" rel="nofollow noopener">Dominik writes in</a> (<a href="http://slexy.org/view/s20RjbIT5v" rel="nofollow noopener">text answer</a>)</li>
<li><a href="http://slexy.org/view/s20USR3WzT" rel="nofollow noopener">Chris writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://lists.mindrot.org/pipermail/openssh-unix-dev/2015-May/033945.html" rel="nofollow noopener">Death by chocolate</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>73: Pipe Dreams</title>
  <link>https://www.bsdnow.tv/73</link>
  <guid isPermaLink="false">bca95163-7c0b-4440-902b-594ea8c61554</guid>
  <pubDate>Wed, 21 Jan 2015 08:00:00 -0500</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/bca95163-7c0b-4440-902b-594ea8c61554.mp3" length="65969428" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This week on the show we'll be chatting with David Maxwell, a former NetBSD security officer. He's got an interesting project called Pipecut that takes a whole new approach to the commandline. We've also got answers to viewer-submitted questions and all this week's headlines, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:31:37</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This week on the show we'll be chatting with David Maxwell, a former NetBSD security officer. He's got an interesting project called Pipecut that takes a whole new approach to the commandline. We've also got answers to viewer-submitted questions and all this week's headlines, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"&gt;&lt;/a&gt;&lt;a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"&gt;&lt;img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.freebsd.org/news/status/report-2014-10-2014-12.html" rel="nofollow noopener"&gt;FreeBSD quarterly status report&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The FreeBSD team has posted an updated on some of their activities between October and December of 2014&lt;/li&gt;
&lt;li&gt;They put a big focus on compatibility with other systems: the Linux emulation layer, &lt;a href="http://www.bsdnow.tv/tutorials/bhyve" rel="nofollow noopener"&gt;bhyve&lt;/a&gt;, WINE and Xen all got some nice improvements&lt;/li&gt;
&lt;li&gt;As always, the report has lots of updates from the various teams working on different parts of the OS and ports infrastructure&lt;/li&gt;
&lt;li&gt;The release engineering team got 10.1 out the door, the ports team shuffled a few members in and out and continued working on closing more PRs&lt;/li&gt;
&lt;li&gt;FreeBSD's forums underwent a huge change, and discussion about the new support model for release cycles continues (hopefully taking effect after 11.0 is released)&lt;/li&gt;
&lt;li&gt;Git was promoted from beta to an officially-supported version control system (Kris is happy)&lt;/li&gt;
&lt;li&gt;The core team is also assembling a new QA team to ensure better code quality in critical areas, such as security and release engineering, after getting a number of complaints&lt;/li&gt;
&lt;li&gt;Other notable entries include: lots of bhyve fixes, Clang/LLVM being updated to 3.5.0, ongoing work to the external toolchain, adding FreeBSD support to more "cloud" services, pkgng updates, work on SecureBoot, more ARM support and graphics stack improvements&lt;/li&gt;
&lt;li&gt;Check out the full report for all the details that we didn't cover
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://linux-audit.com/vulnerabilities-and-digital-signatures-for-openbsd-software-packages/" rel="nofollow noopener"&gt;OpenBSD package signature audit&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;"Linux Audit" is a website focused on auditing and hardening systems, as well as educating people about securing their boxes&lt;/li&gt;
&lt;li&gt;They recently did an article about OpenBSD, specifically their &lt;a href="http://www.bsdnow.tv/tutorials/ports-obsd" rel="nofollow noopener"&gt;ports and package system&lt;/a&gt; and signing infrastructure&lt;/li&gt;
&lt;li&gt;The author gives a little background on the difference between ports and binary packages, then goes through the technical details of how releases and packages are cryptographically signed&lt;/li&gt;
&lt;li&gt;Package signature formats and public key distribution methods are also touched on&lt;/li&gt;
&lt;li&gt;After some heckling, the author of the post said he plans to write more BSD security articles, so look forward to them in the future&lt;/li&gt;
&lt;li&gt;If you haven't seen &lt;a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener"&gt;our episode about signify&lt;/a&gt; with Ted Unangst, that would be a great one to check out after reading this
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://ask.slashdot.org/story/15/01/15/1547209/ask-slashdot-migrating-a-router-from-linux-to-bsd" rel="nofollow noopener"&gt;Replacing a Linux router with BSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;There was recently a Slashdot discussion about migrating a Linux-based router to a BSD-based one&lt;/li&gt;
&lt;li&gt;The poster begins with "I'm in the camp that doesn't trust systemd. You can discuss the technical merits of all init solutions all you want, but if I wanted to run Windows NT I'd run Windows NT, not Linux. So I've decided to migrate my homebrew router/firewall/samba server to one of the BSDs."&lt;/li&gt;
&lt;li&gt;A lot of people were quick to recommend &lt;a href="http://www.bsdnow.tv/episodes/2015_01_14-common_sense_approach" rel="nofollow noopener"&gt;OPNsense&lt;/a&gt; and pfSense, being that they're very easy to administer (requiring basically no BSD knowledge at all)&lt;/li&gt;
&lt;li&gt;Other commenters suggested a more hands-on approach, setting one up yourself with &lt;a href="http://blog.pcbsd.org/2015/01/using-trueos-as-a-ipfw-based-home-router/" rel="nofollow noopener"&gt;FreeBSD&lt;/a&gt; or &lt;a href="http://www.bsdnow.tv/tutorials/openbsd-router" rel="nofollow noopener"&gt;OpenBSD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;If you've been thinking about moving some routers over from Linux or other commercial solution, this might be a good discussion to read through&lt;/li&gt;
&lt;li&gt;Unfortunately, a lot of the comments are just Linux users bickering about systemd, so you'll have to wade through some of that to get to the good information
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://bsdxbsdx.blogspot.com/2015/01/switching-to-openssl-from-ports-in.html" rel="nofollow noopener"&gt;LibreSSL in FreeBSD and OPNsense&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A FreeBSD sysadmin has started documenting his experience replacing OpenSSL in the base system with the one from ports (and also experimenting with LibreSSL)&lt;/li&gt;
&lt;li&gt;The reasoning being that updates in base &lt;a href="http://www.openbsd.org/papers/eurobsdcon2014-libressl.html" rel="nofollow noopener"&gt;tend to lag behind&lt;/a&gt;, whereas the port can be updated for security very quickly&lt;/li&gt;
&lt;li&gt;OPNsense developers are &lt;a href="https://twitter.com/fitchitis/status/555625679614521345" rel="nofollow noopener"&gt;looking into&lt;/a&gt;  &lt;a href="http://forum.opnsense.org/index.php?topic=21.0" rel="nofollow noopener"&gt;switching away&lt;/a&gt; from OpenSSL to &lt;a href="http://www.bsdnow.tv/episodes/2014_07_30-liberating_ssl" rel="nofollow noopener"&gt;LibreSSL's portable version&lt;/a&gt;, for both their ports and base system, which would be a pretty huge differentiator for their project&lt;/li&gt;
&lt;li&gt;Some ports &lt;a href="https://bugs.freebsd.org/bugzilla/buglist.cgi?order=Importance&amp;amp;query_format=advanced&amp;amp;short_desc=libressl&amp;amp;short_desc_type=allwordssubstr" rel="nofollow noopener"&gt;still need fixing&lt;/a&gt; to be compatible though, particularly &lt;a href="https://github.com/opnsense/ports/commit/c15af648e9d5fcecf0ae666292e8f41c08979057" rel="nofollow noopener"&gt;a few&lt;/a&gt; &lt;a href="https://github.com/pyca/cryptography/issues/928" rel="nofollow noopener"&gt;python-related&lt;/a&gt; ones&lt;/li&gt;
&lt;li&gt;If you're a FreeBSD ports person, get involved and help squash some of the last remaining bugs&lt;/li&gt;
&lt;li&gt;A lot of the work has already been done &lt;a href="http://cvsweb.openbsd.org/cgi-bin/cvsweb/ports/" rel="nofollow noopener"&gt;in OpenBSD's ports tree&lt;/a&gt; - some patches just need to be adopted&lt;/li&gt;
&lt;li&gt;More and more upstream projects are incorporating LibreSSL patches in their code - let your favorite software vendor know that you're using it
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - David Maxwell - &lt;a href="mailto:david@netbsd.org" rel="nofollow noopener"&gt;david@netbsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/david_w_maxwell" rel="nofollow noopener"&gt;@david_w_maxwell&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://www.youtube.com/watch?v=CZHEZHK4jRc" rel="nofollow noopener"&gt;Pipecut&lt;/a&gt;, text processing, commandline wizardry&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://github.com/3ofcoins/jetpack" rel="nofollow noopener"&gt;Jetpack, a new jail container system&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A new project was launched to adapt FreeBSD jails to the "app container specification"&lt;/li&gt;
&lt;li&gt;While still pretty experimental in terms of the development phase, this might be something to show your Linux friends who are in love with docker&lt;/li&gt;
&lt;li&gt;It's a similar project to &lt;a href="https://github.com/pannon/iocage" rel="nofollow noopener"&gt;iocage&lt;/a&gt; or &lt;a href="https://github.com/ployground/bsdploy" rel="nofollow noopener"&gt;bsdploy&lt;/a&gt;, which we haven't talked a whole lot about&lt;/li&gt;
&lt;li&gt;There was also &lt;a href="https://news.ycombinator.com/item?id=8893630" rel="nofollow noopener"&gt;some discussion&lt;/a&gt; about it on Hacker News
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.reddit.com/r/BSD/comments/2szofc" rel="nofollow noopener"&gt;Separating base and package binaries&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;All of the main BSDs make a strong separation between the base system and third party software&lt;/li&gt;
&lt;li&gt;This is in contrast to Linux where there's no real concept of a "base system" - more recently, some distros have even merged all the binaries into a single directory&lt;/li&gt;
&lt;li&gt;A user asks the community about the BSD way of doing it, trying to find out the advantages and disadvantages of both hierarchies&lt;/li&gt;
&lt;li&gt;Read the comments for the full explanation, but having things separated really helps keep things organized
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://svnweb.freebsd.org/base?view=revision&amp;amp;revision=277487" rel="nofollow noopener"&gt;Updated i915kms driver for FreeBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;This update brings the FreeBSD code closer inline with the Linux code, to make it easier to update going forward&lt;/li&gt;
&lt;li&gt;It doesn't introduce Haswell support just yet, but was required before the Haswell bits can be added
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://zacbrown.org/2015/01/18/openbsd-as-a-desktop/" rel="nofollow noopener"&gt;Year of the OpenBSD desktop&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Here we have an article about using OpenBSD as a daily driver for regular desktop usage&lt;/li&gt;
&lt;li&gt;The author says he "ran fifty thousand different distributions, never being satisfied"&lt;/li&gt;
&lt;li&gt;After dealing with the problems of Linux and fragmentation, he eventually gave up and bought a Macbook&lt;/li&gt;
&lt;li&gt;He also used FreeBSD between versions 7 and 9, finding a "a mostly harmonious environment," but regressions lead him to give up on desktop *nix once again&lt;/li&gt;
&lt;li&gt;Starting with 2015, he's back and is using OpenBSD on a Thinkpad x201&lt;/li&gt;
&lt;li&gt;The rest of the article covers some of his configuration tweaks and gives an overall conclusion on his current setup&lt;/li&gt;
&lt;li&gt;He apparently used &lt;a href="http://www.bsdnow.tv/tutorials/the-desktop-obsd" rel="nofollow noopener"&gt;our desktop tutorial&lt;/a&gt; - thanks for watching!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://louwrentius.com/freebsd-101-unattended-install-over-pxe-http-no-nfs.html" rel="nofollow noopener"&gt;Unattended FreeBSD installation&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A new BSD user was looking to get some more experience, so he documented how to install FreeBSD over PXE&lt;/li&gt;
&lt;li&gt;His goal was to have a setup similar to Redhat's "kickstart" or &lt;a href="http://www.bsdnow.tv/tutorials/autoinstall" rel="nofollow noopener"&gt;OpenBSD's autoinstall&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The article shows you how to set up DHCP and TFTP, with no NFS share setup required&lt;/li&gt;
&lt;li&gt;He also gives a mention to mfsbsd, showing how you can customize its startup script to do most of the work for you
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20UsZjN4h" rel="nofollow noopener"&gt;Robert writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s219cMQz3U" rel="nofollow noopener"&gt;Sean writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2EkzMUMyb" rel="nofollow noopener"&gt;l33tname writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2nq6L6H1n" rel="nofollow noopener"&gt;Charlie writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21EGqUYLd" rel="nofollow noopener"&gt;Eric writes in&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Mailing List Gold&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=142159202606668&amp;amp;w=2" rel="nofollow noopener"&gt;Clowning around&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-ports/2015-January/097734.html" rel="nofollow noopener"&gt;Better than succeeding in this case&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, pipecut, david maxwell, commandline, shell, libressl, router, pf, cryptography, router, openssl, bhyve, digitalocean</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This week on the show we'll be chatting with David Maxwell, a former NetBSD security officer. He's got an interesting project called Pipecut that takes a whole new approach to the commandline. We've also got answers to viewer-submitted questions and all this week's headlines, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.freebsd.org/news/status/report-2014-10-2014-12.html" rel="nofollow noopener">FreeBSD quarterly status report</a></h3>

<ul>
<li>The FreeBSD team has posted an updated on some of their activities between October and December of 2014</li>
<li>They put a big focus on compatibility with other systems: the Linux emulation layer, <a href="http://www.bsdnow.tv/tutorials/bhyve" rel="nofollow noopener">bhyve</a>, WINE and Xen all got some nice improvements</li>
<li>As always, the report has lots of updates from the various teams working on different parts of the OS and ports infrastructure</li>
<li>The release engineering team got 10.1 out the door, the ports team shuffled a few members in and out and continued working on closing more PRs</li>
<li>FreeBSD's forums underwent a huge change, and discussion about the new support model for release cycles continues (hopefully taking effect after 11.0 is released)</li>
<li>Git was promoted from beta to an officially-supported version control system (Kris is happy)</li>
<li>The core team is also assembling a new QA team to ensure better code quality in critical areas, such as security and release engineering, after getting a number of complaints</li>
<li>Other notable entries include: lots of bhyve fixes, Clang/LLVM being updated to 3.5.0, ongoing work to the external toolchain, adding FreeBSD support to more "cloud" services, pkgng updates, work on SecureBoot, more ARM support and graphics stack improvements</li>
<li>Check out the full report for all the details that we didn't cover
***</li>
</ul>

<h3><a href="http://linux-audit.com/vulnerabilities-and-digital-signatures-for-openbsd-software-packages/" rel="nofollow noopener">OpenBSD package signature audit</a></h3>

<ul>
<li>"Linux Audit" is a website focused on auditing and hardening systems, as well as educating people about securing their boxes</li>
<li>They recently did an article about OpenBSD, specifically their <a href="http://www.bsdnow.tv/tutorials/ports-obsd" rel="nofollow noopener">ports and package system</a> and signing infrastructure</li>
<li>The author gives a little background on the difference between ports and binary packages, then goes through the technical details of how releases and packages are cryptographically signed</li>
<li>Package signature formats and public key distribution methods are also touched on</li>
<li>After some heckling, the author of the post said he plans to write more BSD security articles, so look forward to them in the future</li>
<li>If you haven't seen <a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener">our episode about signify</a> with Ted Unangst, that would be a great one to check out after reading this
***</li>
</ul>

<h3><a href="http://ask.slashdot.org/story/15/01/15/1547209/ask-slashdot-migrating-a-router-from-linux-to-bsd" rel="nofollow noopener">Replacing a Linux router with BSD</a></h3>

<ul>
<li>There was recently a Slashdot discussion about migrating a Linux-based router to a BSD-based one</li>
<li>The poster begins with "I'm in the camp that doesn't trust systemd. You can discuss the technical merits of all init solutions all you want, but if I wanted to run Windows NT I'd run Windows NT, not Linux. So I've decided to migrate my homebrew router/firewall/samba server to one of the BSDs."</li>
<li>A lot of people were quick to recommend <a href="http://www.bsdnow.tv/episodes/2015_01_14-common_sense_approach" rel="nofollow noopener">OPNsense</a> and pfSense, being that they're very easy to administer (requiring basically no BSD knowledge at all)</li>
<li>Other commenters suggested a more hands-on approach, setting one up yourself with <a href="http://blog.pcbsd.org/2015/01/using-trueos-as-a-ipfw-based-home-router/" rel="nofollow noopener">FreeBSD</a> or <a href="http://www.bsdnow.tv/tutorials/openbsd-router" rel="nofollow noopener">OpenBSD</a></li>
<li>If you've been thinking about moving some routers over from Linux or other commercial solution, this might be a good discussion to read through</li>
<li>Unfortunately, a lot of the comments are just Linux users bickering about systemd, so you'll have to wade through some of that to get to the good information
***</li>
</ul>

<h3><a href="http://bsdxbsdx.blogspot.com/2015/01/switching-to-openssl-from-ports-in.html" rel="nofollow noopener">LibreSSL in FreeBSD and OPNsense</a></h3>

<ul>
<li>A FreeBSD sysadmin has started documenting his experience replacing OpenSSL in the base system with the one from ports (and also experimenting with LibreSSL)</li>
<li>The reasoning being that updates in base <a href="http://www.openbsd.org/papers/eurobsdcon2014-libressl.html" rel="nofollow noopener">tend to lag behind</a>, whereas the port can be updated for security very quickly</li>
<li>OPNsense developers are <a href="https://twitter.com/fitchitis/status/555625679614521345" rel="nofollow noopener">looking into</a>  <a href="http://forum.opnsense.org/index.php?topic=21.0" rel="nofollow noopener">switching away</a> from OpenSSL to <a href="http://www.bsdnow.tv/episodes/2014_07_30-liberating_ssl" rel="nofollow noopener">LibreSSL's portable version</a>, for both their ports and base system, which would be a pretty huge differentiator for their project</li>
<li>Some ports <a href="https://bugs.freebsd.org/bugzilla/buglist.cgi?order=Importance&amp;query_format=advanced&amp;short_desc=libressl&amp;short_desc_type=allwordssubstr" rel="nofollow noopener">still need fixing</a> to be compatible though, particularly <a href="https://github.com/opnsense/ports/commit/c15af648e9d5fcecf0ae666292e8f41c08979057" rel="nofollow noopener">a few</a> <a href="https://github.com/pyca/cryptography/issues/928" rel="nofollow noopener">python-related</a> ones</li>
<li>If you're a FreeBSD ports person, get involved and help squash some of the last remaining bugs</li>
<li>A lot of the work has already been done <a href="http://cvsweb.openbsd.org/cgi-bin/cvsweb/ports/" rel="nofollow noopener">in OpenBSD's ports tree</a> - some patches just need to be adopted</li>
<li>More and more upstream projects are incorporating LibreSSL patches in their code - let your favorite software vendor know that you're using it
***</li>
</ul>

<h2>Interview - David Maxwell - <a href="mailto:david@netbsd.org" rel="nofollow noopener">david@netbsd.org</a> / <a href="https://twitter.com/david_w_maxwell" rel="nofollow noopener">@david_w_maxwell</a></h2>

<p><a href="https://www.youtube.com/watch?v=CZHEZHK4jRc" rel="nofollow noopener">Pipecut</a>, text processing, commandline wizardry</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://github.com/3ofcoins/jetpack" rel="nofollow noopener">Jetpack, a new jail container system</a></h3>

<ul>
<li>A new project was launched to adapt FreeBSD jails to the "app container specification"</li>
<li>While still pretty experimental in terms of the development phase, this might be something to show your Linux friends who are in love with docker</li>
<li>It's a similar project to <a href="https://github.com/pannon/iocage" rel="nofollow noopener">iocage</a> or <a href="https://github.com/ployground/bsdploy" rel="nofollow noopener">bsdploy</a>, which we haven't talked a whole lot about</li>
<li>There was also <a href="https://news.ycombinator.com/item?id=8893630" rel="nofollow noopener">some discussion</a> about it on Hacker News
***</li>
</ul>

<h3><a href="https://www.reddit.com/r/BSD/comments/2szofc" rel="nofollow noopener">Separating base and package binaries</a></h3>

<ul>
<li>All of the main BSDs make a strong separation between the base system and third party software</li>
<li>This is in contrast to Linux where there's no real concept of a "base system" - more recently, some distros have even merged all the binaries into a single directory</li>
<li>A user asks the community about the BSD way of doing it, trying to find out the advantages and disadvantages of both hierarchies</li>
<li>Read the comments for the full explanation, but having things separated really helps keep things organized
***</li>
</ul>

<h3><a href="https://svnweb.freebsd.org/base?view=revision&amp;revision=277487" rel="nofollow noopener">Updated i915kms driver for FreeBSD</a></h3>

<ul>
<li>This update brings the FreeBSD code closer inline with the Linux code, to make it easier to update going forward</li>
<li>It doesn't introduce Haswell support just yet, but was required before the Haswell bits can be added
***</li>
</ul>

<h3><a href="http://zacbrown.org/2015/01/18/openbsd-as-a-desktop/" rel="nofollow noopener">Year of the OpenBSD desktop</a></h3>

<ul>
<li>Here we have an article about using OpenBSD as a daily driver for regular desktop usage</li>
<li>The author says he "ran fifty thousand different distributions, never being satisfied"</li>
<li>After dealing with the problems of Linux and fragmentation, he eventually gave up and bought a Macbook</li>
<li>He also used FreeBSD between versions 7 and 9, finding a "a mostly harmonious environment," but regressions lead him to give up on desktop *nix once again</li>
<li>Starting with 2015, he's back and is using OpenBSD on a Thinkpad x201</li>
<li>The rest of the article covers some of his configuration tweaks and gives an overall conclusion on his current setup</li>
<li>He apparently used <a href="http://www.bsdnow.tv/tutorials/the-desktop-obsd" rel="nofollow noopener">our desktop tutorial</a> - thanks for watching!
***</li>
</ul>

<h3><a href="http://louwrentius.com/freebsd-101-unattended-install-over-pxe-http-no-nfs.html" rel="nofollow noopener">Unattended FreeBSD installation</a></h3>

<ul>
<li>A new BSD user was looking to get some more experience, so he documented how to install FreeBSD over PXE</li>
<li>His goal was to have a setup similar to Redhat's "kickstart" or <a href="http://www.bsdnow.tv/tutorials/autoinstall" rel="nofollow noopener">OpenBSD's autoinstall</a></li>
<li>The article shows you how to set up DHCP and TFTP, with no NFS share setup required</li>
<li>He also gives a mention to mfsbsd, showing how you can customize its startup script to do most of the work for you
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s20UsZjN4h" rel="nofollow noopener">Robert writes in</a></li>
<li><a href="http://slexy.org/view/s219cMQz3U" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s2EkzMUMyb" rel="nofollow noopener">l33tname writes in</a></li>
<li><a href="http://slexy.org/view/s2nq6L6H1n" rel="nofollow noopener">Charlie writes in</a></li>
<li><a href="http://slexy.org/view/s21EGqUYLd" rel="nofollow noopener">Eric writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=142159202606668&amp;w=2" rel="nofollow noopener">Clowning around</a></li>
<li><a href="https://lists.freebsd.org/pipermail/freebsd-ports/2015-January/097734.html" rel="nofollow noopener">Better than succeeding in this case</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This week on the show we'll be chatting with David Maxwell, a former NetBSD security officer. He's got an interesting project called Pipecut that takes a whole new approach to the commandline. We've also got answers to viewer-submitted questions and all this week's headlines, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.freebsd.org/news/status/report-2014-10-2014-12.html" rel="nofollow noopener">FreeBSD quarterly status report</a></h3>

<ul>
<li>The FreeBSD team has posted an updated on some of their activities between October and December of 2014</li>
<li>They put a big focus on compatibility with other systems: the Linux emulation layer, <a href="http://www.bsdnow.tv/tutorials/bhyve" rel="nofollow noopener">bhyve</a>, WINE and Xen all got some nice improvements</li>
<li>As always, the report has lots of updates from the various teams working on different parts of the OS and ports infrastructure</li>
<li>The release engineering team got 10.1 out the door, the ports team shuffled a few members in and out and continued working on closing more PRs</li>
<li>FreeBSD's forums underwent a huge change, and discussion about the new support model for release cycles continues (hopefully taking effect after 11.0 is released)</li>
<li>Git was promoted from beta to an officially-supported version control system (Kris is happy)</li>
<li>The core team is also assembling a new QA team to ensure better code quality in critical areas, such as security and release engineering, after getting a number of complaints</li>
<li>Other notable entries include: lots of bhyve fixes, Clang/LLVM being updated to 3.5.0, ongoing work to the external toolchain, adding FreeBSD support to more "cloud" services, pkgng updates, work on SecureBoot, more ARM support and graphics stack improvements</li>
<li>Check out the full report for all the details that we didn't cover
***</li>
</ul>

<h3><a href="http://linux-audit.com/vulnerabilities-and-digital-signatures-for-openbsd-software-packages/" rel="nofollow noopener">OpenBSD package signature audit</a></h3>

<ul>
<li>"Linux Audit" is a website focused on auditing and hardening systems, as well as educating people about securing their boxes</li>
<li>They recently did an article about OpenBSD, specifically their <a href="http://www.bsdnow.tv/tutorials/ports-obsd" rel="nofollow noopener">ports and package system</a> and signing infrastructure</li>
<li>The author gives a little background on the difference between ports and binary packages, then goes through the technical details of how releases and packages are cryptographically signed</li>
<li>Package signature formats and public key distribution methods are also touched on</li>
<li>After some heckling, the author of the post said he plans to write more BSD security articles, so look forward to them in the future</li>
<li>If you haven't seen <a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener">our episode about signify</a> with Ted Unangst, that would be a great one to check out after reading this
***</li>
</ul>

<h3><a href="http://ask.slashdot.org/story/15/01/15/1547209/ask-slashdot-migrating-a-router-from-linux-to-bsd" rel="nofollow noopener">Replacing a Linux router with BSD</a></h3>

<ul>
<li>There was recently a Slashdot discussion about migrating a Linux-based router to a BSD-based one</li>
<li>The poster begins with "I'm in the camp that doesn't trust systemd. You can discuss the technical merits of all init solutions all you want, but if I wanted to run Windows NT I'd run Windows NT, not Linux. So I've decided to migrate my homebrew router/firewall/samba server to one of the BSDs."</li>
<li>A lot of people were quick to recommend <a href="http://www.bsdnow.tv/episodes/2015_01_14-common_sense_approach" rel="nofollow noopener">OPNsense</a> and pfSense, being that they're very easy to administer (requiring basically no BSD knowledge at all)</li>
<li>Other commenters suggested a more hands-on approach, setting one up yourself with <a href="http://blog.pcbsd.org/2015/01/using-trueos-as-a-ipfw-based-home-router/" rel="nofollow noopener">FreeBSD</a> or <a href="http://www.bsdnow.tv/tutorials/openbsd-router" rel="nofollow noopener">OpenBSD</a></li>
<li>If you've been thinking about moving some routers over from Linux or other commercial solution, this might be a good discussion to read through</li>
<li>Unfortunately, a lot of the comments are just Linux users bickering about systemd, so you'll have to wade through some of that to get to the good information
***</li>
</ul>

<h3><a href="http://bsdxbsdx.blogspot.com/2015/01/switching-to-openssl-from-ports-in.html" rel="nofollow noopener">LibreSSL in FreeBSD and OPNsense</a></h3>

<ul>
<li>A FreeBSD sysadmin has started documenting his experience replacing OpenSSL in the base system with the one from ports (and also experimenting with LibreSSL)</li>
<li>The reasoning being that updates in base <a href="http://www.openbsd.org/papers/eurobsdcon2014-libressl.html" rel="nofollow noopener">tend to lag behind</a>, whereas the port can be updated for security very quickly</li>
<li>OPNsense developers are <a href="https://twitter.com/fitchitis/status/555625679614521345" rel="nofollow noopener">looking into</a>  <a href="http://forum.opnsense.org/index.php?topic=21.0" rel="nofollow noopener">switching away</a> from OpenSSL to <a href="http://www.bsdnow.tv/episodes/2014_07_30-liberating_ssl" rel="nofollow noopener">LibreSSL's portable version</a>, for both their ports and base system, which would be a pretty huge differentiator for their project</li>
<li>Some ports <a href="https://bugs.freebsd.org/bugzilla/buglist.cgi?order=Importance&amp;query_format=advanced&amp;short_desc=libressl&amp;short_desc_type=allwordssubstr" rel="nofollow noopener">still need fixing</a> to be compatible though, particularly <a href="https://github.com/opnsense/ports/commit/c15af648e9d5fcecf0ae666292e8f41c08979057" rel="nofollow noopener">a few</a> <a href="https://github.com/pyca/cryptography/issues/928" rel="nofollow noopener">python-related</a> ones</li>
<li>If you're a FreeBSD ports person, get involved and help squash some of the last remaining bugs</li>
<li>A lot of the work has already been done <a href="http://cvsweb.openbsd.org/cgi-bin/cvsweb/ports/" rel="nofollow noopener">in OpenBSD's ports tree</a> - some patches just need to be adopted</li>
<li>More and more upstream projects are incorporating LibreSSL patches in their code - let your favorite software vendor know that you're using it
***</li>
</ul>

<h2>Interview - David Maxwell - <a href="mailto:david@netbsd.org" rel="nofollow noopener">david@netbsd.org</a> / <a href="https://twitter.com/david_w_maxwell" rel="nofollow noopener">@david_w_maxwell</a></h2>

<p><a href="https://www.youtube.com/watch?v=CZHEZHK4jRc" rel="nofollow noopener">Pipecut</a>, text processing, commandline wizardry</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://github.com/3ofcoins/jetpack" rel="nofollow noopener">Jetpack, a new jail container system</a></h3>

<ul>
<li>A new project was launched to adapt FreeBSD jails to the "app container specification"</li>
<li>While still pretty experimental in terms of the development phase, this might be something to show your Linux friends who are in love with docker</li>
<li>It's a similar project to <a href="https://github.com/pannon/iocage" rel="nofollow noopener">iocage</a> or <a href="https://github.com/ployground/bsdploy" rel="nofollow noopener">bsdploy</a>, which we haven't talked a whole lot about</li>
<li>There was also <a href="https://news.ycombinator.com/item?id=8893630" rel="nofollow noopener">some discussion</a> about it on Hacker News
***</li>
</ul>

<h3><a href="https://www.reddit.com/r/BSD/comments/2szofc" rel="nofollow noopener">Separating base and package binaries</a></h3>

<ul>
<li>All of the main BSDs make a strong separation between the base system and third party software</li>
<li>This is in contrast to Linux where there's no real concept of a "base system" - more recently, some distros have even merged all the binaries into a single directory</li>
<li>A user asks the community about the BSD way of doing it, trying to find out the advantages and disadvantages of both hierarchies</li>
<li>Read the comments for the full explanation, but having things separated really helps keep things organized
***</li>
</ul>

<h3><a href="https://svnweb.freebsd.org/base?view=revision&amp;revision=277487" rel="nofollow noopener">Updated i915kms driver for FreeBSD</a></h3>

<ul>
<li>This update brings the FreeBSD code closer inline with the Linux code, to make it easier to update going forward</li>
<li>It doesn't introduce Haswell support just yet, but was required before the Haswell bits can be added
***</li>
</ul>

<h3><a href="http://zacbrown.org/2015/01/18/openbsd-as-a-desktop/" rel="nofollow noopener">Year of the OpenBSD desktop</a></h3>

<ul>
<li>Here we have an article about using OpenBSD as a daily driver for regular desktop usage</li>
<li>The author says he "ran fifty thousand different distributions, never being satisfied"</li>
<li>After dealing with the problems of Linux and fragmentation, he eventually gave up and bought a Macbook</li>
<li>He also used FreeBSD between versions 7 and 9, finding a "a mostly harmonious environment," but regressions lead him to give up on desktop *nix once again</li>
<li>Starting with 2015, he's back and is using OpenBSD on a Thinkpad x201</li>
<li>The rest of the article covers some of his configuration tweaks and gives an overall conclusion on his current setup</li>
<li>He apparently used <a href="http://www.bsdnow.tv/tutorials/the-desktop-obsd" rel="nofollow noopener">our desktop tutorial</a> - thanks for watching!
***</li>
</ul>

<h3><a href="http://louwrentius.com/freebsd-101-unattended-install-over-pxe-http-no-nfs.html" rel="nofollow noopener">Unattended FreeBSD installation</a></h3>

<ul>
<li>A new BSD user was looking to get some more experience, so he documented how to install FreeBSD over PXE</li>
<li>His goal was to have a setup similar to Redhat's "kickstart" or <a href="http://www.bsdnow.tv/tutorials/autoinstall" rel="nofollow noopener">OpenBSD's autoinstall</a></li>
<li>The article shows you how to set up DHCP and TFTP, with no NFS share setup required</li>
<li>He also gives a mention to mfsbsd, showing how you can customize its startup script to do most of the work for you
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s20UsZjN4h" rel="nofollow noopener">Robert writes in</a></li>
<li><a href="http://slexy.org/view/s219cMQz3U" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s2EkzMUMyb" rel="nofollow noopener">l33tname writes in</a></li>
<li><a href="http://slexy.org/view/s2nq6L6H1n" rel="nofollow noopener">Charlie writes in</a></li>
<li><a href="http://slexy.org/view/s21EGqUYLd" rel="nofollow noopener">Eric writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=142159202606668&amp;w=2" rel="nofollow noopener">Clowning around</a></li>
<li><a href="https://lists.freebsd.org/pipermail/freebsd-ports/2015-January/097734.html" rel="nofollow noopener">Better than succeeding in this case</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>47: DES Challenge IV</title>
  <link>https://www.bsdnow.tv/47</link>
  <guid isPermaLink="false">2c9f4e68-6474-41f9-ab80-bb40fbb76855</guid>
  <pubDate>Wed, 23 Jul 2014 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/2c9f4e68-6474-41f9-ab80-bb40fbb76855.mp3" length="66811828" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>Coming up this week on the show! We've got an interview with Dag-Erling Smørgrav, the current security officer of FreeBSD, to discuss what exactly being in such an important position is like. The latest news, answers to your emails and even some LibreSSL drama, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:32:47</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;Coming up this week on the show! We've got an interview with Dag-Erling Smørgrav, the current security officer of FreeBSD, to discuss what exactly being in such an important position is like. The latest news, answers to your emails and even some LibreSSL drama, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.openbsd.org/hackathons.html" rel="nofollow noopener"&gt;g2k14 hackathon reports&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Nearly 50 OpenBSD developers gathered in Ljubljana, Slovenia from July 8-14 for a hackathon&lt;/li&gt;
&lt;li&gt;Lots of work got done - in just the first two weeks of July, there were &lt;a href="http://marc.info/?l=openbsd-cvs&amp;amp;r=1&amp;amp;b=201407&amp;amp;w=2" rel="nofollow noopener"&gt;over 1000 commits&lt;/a&gt; to their CVS tree&lt;/li&gt;
&lt;li&gt;Some of the developers wrote in to document what they were up to at the event&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140713220618" rel="nofollow noopener"&gt;Bob Beck&lt;/a&gt; planned to work on kernel stuff, but then "LibreSSL happened" and he spent most of his time working on that&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140718072312" rel="nofollow noopener"&gt;Miod Vallat&lt;/a&gt; also tells about his LibreSSL experiences&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140718090456" rel="nofollow noopener"&gt;Brent Cook&lt;/a&gt;, a new developer, worked mainly on the portable version of LibreSSL (and we'll be interviewing him next week!)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140714094454" rel="nofollow noopener"&gt;Henning Brauer&lt;/a&gt; worked on VLAN bpf and various things related to IPv6 and network interfaces (and he still hates IPv6)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140714191912" rel="nofollow noopener"&gt;Martin Pieuchot&lt;/a&gt; fixed some bugs in the USB stack, softraid and misc other things&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140714202157" rel="nofollow noopener"&gt;Marc Espie&lt;/a&gt; improved the package code, enabling some speed ups, fixed some ports that broke with LibreSSL and some of the new changes and also did some work on ensuring snapshot consistency&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140715120259" rel="nofollow noopener"&gt;Martin Pelikan&lt;/a&gt; integrated read-only ext4 support&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140715094848" rel="nofollow noopener"&gt;Vadim Zhukov&lt;/a&gt; did lots of ports work, including working on KDE4&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140715212333" rel="nofollow noopener"&gt;Theo de Raadt&lt;/a&gt; created a new, more secure system call, "sendsyslog" and did a lot of work with /etc, sysmerge and the rc scripts&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140718134017" rel="nofollow noopener"&gt;Paul Irofti&lt;/a&gt; worked on the USB stack, specifically for the Octeon platform&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140719104939" rel="nofollow noopener"&gt;Sebastian Benoit&lt;/a&gt; worked on relayd filters and IPv6 code&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140719134058" rel="nofollow noopener"&gt;Jasper Lievisse Adriaanse&lt;/a&gt; did work with puppet, packages and the bootloader&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140719082410" rel="nofollow noopener"&gt;Jonathan Gray&lt;/a&gt; imported newer Mesa libraries and did a lot with Xenocara, including work in the installer for autodetection&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140721125235" rel="nofollow noopener"&gt;Stefan Sperling&lt;/a&gt; fixed a lot of issues with wireless drivers&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140721125020" rel="nofollow noopener"&gt;Florian Obser&lt;/a&gt; did many things related to IPv6&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140721090411" rel="nofollow noopener"&gt;Ingo Schwarze&lt;/a&gt; worked on mandoc, as usual, and also rewrote the openbsd.org man.cgi interface&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140722071413" rel="nofollow noopener"&gt;Ken Westerback&lt;/a&gt; hacked on dhclient and dhcpd, and also got dump working on 4k sector drives&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140723142224" rel="nofollow noopener"&gt;Matthieu Herrb&lt;/a&gt; worked on updating and modernizing parts of xenocara
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-questions/2014-July/259292.html" rel="nofollow noopener"&gt;FreeBSD pf discussion takes off&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Concerns from last week, about FreeBSD's packet filter being old and unmaintained, seemed to have finally sparked some conversation about the topic on the "questions" and "current" mailing lists (unfortunately people didn't always use reply-all so you have to cross-reference the two lists to follow the whole conversation sometimes)&lt;/li&gt;
&lt;li&gt;Straight from the SMP FreeBSD pf maintainer: "no one right now [is actively developing pf on FreeBSD]"&lt;/li&gt;
&lt;li&gt;Searching for documentation online for pf is troublesome because there are two incompatible syntaxes&lt;/li&gt;
&lt;li&gt;FreeBSD's pf man pages are lacking, and some of FreeBSD's documentation still links to OpenBSD's pages, which won't work anymore - possibly turning away would-be BSD converts because it's frustrating&lt;/li&gt;
&lt;li&gt;There's also the issue of importing patches from pfSense, but most of those still haven't been done either&lt;/li&gt;
&lt;li&gt;Lots of disagreement among developers vs. users...&lt;/li&gt;
&lt;li&gt;Many users are very vocal about wanting it updated, saying the syntax change is no big deal and is worth the benefits - developers aren't interested&lt;/li&gt;
&lt;li&gt;Henning Brauer, the main developer of pf on OpenBSD, has been very nice and offered to help the other BSDs get their pf fixed on multiple occasions&lt;/li&gt;
&lt;li&gt;Gleb Smirnoff, author of the FreeBSD-specific SMP patches, questions Henning's claims about OpenBSD's improved speed as "uncorroborated claims" (but neither side has provided any public benchmarks)&lt;/li&gt;
&lt;li&gt;Gleb had to abandon his work on FreeBSD's pf because funding ran out
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://linux.slashdot.org/story/14/07/16/1950235/libressl-prng-vulnerability-patched" rel="nofollow noopener"&gt;LibreSSL progress update&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;LibreSSL's first few portable releases have come out and they're making great progress, releasing 2.0.3 &lt;a href="http://marc.info/?l=openbsd-tech&amp;amp;m=140599450206255&amp;amp;w=2" rel="nofollow noopener"&gt;two days ago&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Lots of non-OpenBSD people are starting to contribute, sending in patches via the tech mailing list&lt;/li&gt;
&lt;li&gt;However, there has already been some drama... with Linux users&lt;/li&gt;
&lt;li&gt;There was a problem with Linux's PRNG, and LibreSSL was &lt;a href="https://twitter.com/MiodVallat/status/489122763610021888" rel="nofollow noopener"&gt;unforgiving&lt;/a&gt; of it, not making an effort to randomize something that could not provide real entropy&lt;/li&gt;
&lt;li&gt;This "problem" doesn't affect OpenBSD's native implementation, only the portable version&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.securityweek.com/openbsd-downplays-prng-vulnerability-libressl" rel="nofollow noopener"&gt;The developers&lt;/a&gt; decide to &lt;a href="http://www.tedunangst.com/flak/post/wrapping-pids-for-fun-and-profit" rel="nofollow noopener"&gt;weigh in&lt;/a&gt; to calm the misinformation and rage&lt;/li&gt;
&lt;li&gt;A fix was added in 2.0.2, and Linux may even &lt;a href="http://thread.gmane.org/gmane.linux.kernel.cryptoapi/11666" rel="nofollow noopener"&gt;get a new system call&lt;/a&gt; to handle this properly now - remember to say thanks, guys&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener"&gt;Ted Unangst&lt;/a&gt; has a &lt;a href="http://www.tedunangst.com/flak/post/this-is-why-software-sucks" rel="nofollow noopener"&gt;really good post&lt;/a&gt; about the whole situation, definitely check it out&lt;/li&gt;
&lt;li&gt;As a follow-up from last week, bapt says they're working on building the whole FreeBSD ports tree against LibreSSL, but lots of things still need some patching to work properly - if you're a port maintainer, please test your ports against it
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://mail-index.netbsd.org/current-users/2014/07/13/msg025234.html" rel="nofollow noopener"&gt;Preparation for NetBSD 7&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The release process for NetBSD 7.0 is finally underway&lt;/li&gt;
&lt;li&gt;The netbsd-7 CVS branch should be created around July 26th, which marks the start of the first beta period, which will be lasting until September&lt;/li&gt;
&lt;li&gt;If you run NetBSD, that'll be a great time to help test on as many platforms as you can (this is especially true on custom embedded applications)&lt;/li&gt;
&lt;li&gt;They're also looking for some help updating documentation and fixing any bugs that get reported&lt;/li&gt;
&lt;li&gt;Another formal announcement will be made when the beta binaries are up
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Dag-Erling Smørgrav - &lt;a href="mailto:des@freebsd.org" rel="nofollow noopener"&gt;des@freebsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/RealEvilDES" rel="nofollow noopener"&gt;@RealEvilDES&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The role of the FreeBSD Security Officer, recent ports features, various topics&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://blogs.freebsdish.org/portmgr/2014/07/18/bsdcan-2014-ports-and-packages-wg/" rel="nofollow noopener"&gt;BSDCan ports and packages WG&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Back at BSDCan this year, there was a special event for discussion of FreeBSD ports and packages&lt;/li&gt;
&lt;li&gt;Bapt talked about package building, poudriere and the systems the foundation funded for compiling packages&lt;/li&gt;
&lt;li&gt;There's also some detail about the signing infrastructure and different mirrors&lt;/li&gt;
&lt;li&gt;Ports people and source people need to talk more often about ABI breakage&lt;/li&gt;
&lt;li&gt;The post also includes information about pkg 1.3, the old pkg tools' EOL, the quarterly stable package sets and a lot more (it's a huge post!)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.ignoranthack.me/?p=212" rel="nofollow noopener"&gt;Cross-compiling ports with QEMU and poudriere&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;With recent QEMU features, you can basically chroot into a completely different architecture&lt;/li&gt;
&lt;li&gt;This article goes through the process of building ARMv6 packages on a normal X86 box&lt;/li&gt;
&lt;li&gt;Note though that this requires 10-STABLE or 11-CURRENT and an extra patch for QEMU right now&lt;/li&gt;
&lt;li&gt;The poudriere-devel port now has a "qemu user" option that will pull in all the requirements&lt;/li&gt;
&lt;li&gt;Hopefully this will pave the way for official pkgng packages on those lesser-used architectures
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blather.michaelwlucas.com/archives/2108" rel="nofollow noopener"&gt;Cloning FreeBSD with ZFS send&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;For a FreeBSD mail server that MWL runs, he wanted to have a way to easily restore the whole system if something were to happen&lt;/li&gt;
&lt;li&gt;This post shows his entire process in creating a mirror machine, using ZFS for everything&lt;/li&gt;
&lt;li&gt;The "zfs send" and "zfs snapshot" commands really come in handy for this&lt;/li&gt;
&lt;li&gt;He does the whole thing from a live CD, pretty impressive
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://thiagoperrotta.wordpress.com/2014/07/20/here-be-dragons-freebsd-overview-part-i/" rel="nofollow noopener"&gt;FreeBSD Overview series&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A new blog series we stumbled upon about a Linux user switching to BSD&lt;/li&gt;
&lt;li&gt;In part one, he gives a little background on being "done with Linux distros" and documents his initial experience getting and installing FreeBSD 10&lt;/li&gt;
&lt;li&gt;He was pleasantly surprised to be able to use ZFS without jumping through hoops and doing custom kernels&lt;/li&gt;
&lt;li&gt;Most of what he was used to on Linux was already in the default FreeBSD (except bash...)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://thiagoperrotta.wordpress.com/2014/07/21/here-be-packages-freebsd-overview-part-ii/" rel="nofollow noopener"&gt;Part two&lt;/a&gt; documents his experiences with pkgng and ports 
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s214FYbOKL" rel="nofollow noopener"&gt;Bostjan writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21cWLhzj4" rel="nofollow noopener"&gt;Rick writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21A4grtH0" rel="nofollow noopener"&gt;Clint writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s27fQHz8Se" rel="nofollow noopener"&gt;Esteban writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21QscO4Cr" rel="nofollow noopener"&gt;Ben writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://imgur.com/a/Ah444" rel="nofollow noopener"&gt;Matt sends in pictures of his FreeBSD CD collection&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, openssl, libressl, prng, linux, des, aes, encryption, cryptography, Dag-Erling Smørgrav, security, hackathon, pf, packet filter, firewall, smp, multithreading, ixsystems, tarsnap, bsdcan, cheri, zfs, qemu</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Coming up this week on the show! We've got an interview with Dag-Erling Smørgrav, the current security officer of FreeBSD, to discuss what exactly being in such an important position is like. The latest news, answers to your emails and even some LibreSSL drama, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://www.openbsd.org/hackathons.html" rel="nofollow noopener">g2k14 hackathon reports</a></h3>

<ul>
<li>Nearly 50 OpenBSD developers gathered in Ljubljana, Slovenia from July 8-14 for a hackathon</li>
<li>Lots of work got done - in just the first two weeks of July, there were <a href="http://marc.info/?l=openbsd-cvs&amp;r=1&amp;b=201407&amp;w=2" rel="nofollow noopener">over 1000 commits</a> to their CVS tree</li>
<li>Some of the developers wrote in to document what they were up to at the event</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140713220618" rel="nofollow noopener">Bob Beck</a> planned to work on kernel stuff, but then "LibreSSL happened" and he spent most of his time working on that</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140718072312" rel="nofollow noopener">Miod Vallat</a> also tells about his LibreSSL experiences</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140718090456" rel="nofollow noopener">Brent Cook</a>, a new developer, worked mainly on the portable version of LibreSSL (and we'll be interviewing him next week!)</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140714094454" rel="nofollow noopener">Henning Brauer</a> worked on VLAN bpf and various things related to IPv6 and network interfaces (and he still hates IPv6)</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140714191912" rel="nofollow noopener">Martin Pieuchot</a> fixed some bugs in the USB stack, softraid and misc other things</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140714202157" rel="nofollow noopener">Marc Espie</a> improved the package code, enabling some speed ups, fixed some ports that broke with LibreSSL and some of the new changes and also did some work on ensuring snapshot consistency</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140715120259" rel="nofollow noopener">Martin Pelikan</a> integrated read-only ext4 support</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140715094848" rel="nofollow noopener">Vadim Zhukov</a> did lots of ports work, including working on KDE4</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140715212333" rel="nofollow noopener">Theo de Raadt</a> created a new, more secure system call, "sendsyslog" and did a lot of work with /etc, sysmerge and the rc scripts</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140718134017" rel="nofollow noopener">Paul Irofti</a> worked on the USB stack, specifically for the Octeon platform</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140719104939" rel="nofollow noopener">Sebastian Benoit</a> worked on relayd filters and IPv6 code</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140719134058" rel="nofollow noopener">Jasper Lievisse Adriaanse</a> did work with puppet, packages and the bootloader</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140719082410" rel="nofollow noopener">Jonathan Gray</a> imported newer Mesa libraries and did a lot with Xenocara, including work in the installer for autodetection</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140721125235" rel="nofollow noopener">Stefan Sperling</a> fixed a lot of issues with wireless drivers</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140721125020" rel="nofollow noopener">Florian Obser</a> did many things related to IPv6</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140721090411" rel="nofollow noopener">Ingo Schwarze</a> worked on mandoc, as usual, and also rewrote the openbsd.org man.cgi interface</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140722071413" rel="nofollow noopener">Ken Westerback</a> hacked on dhclient and dhcpd, and also got dump working on 4k sector drives</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140723142224" rel="nofollow noopener">Matthieu Herrb</a> worked on updating and modernizing parts of xenocara
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-questions/2014-July/259292.html" rel="nofollow noopener">FreeBSD pf discussion takes off</a></h3>

<ul>
<li>Concerns from last week, about FreeBSD's packet filter being old and unmaintained, seemed to have finally sparked some conversation about the topic on the "questions" and "current" mailing lists (unfortunately people didn't always use reply-all so you have to cross-reference the two lists to follow the whole conversation sometimes)</li>
<li>Straight from the SMP FreeBSD pf maintainer: "no one right now [is actively developing pf on FreeBSD]"</li>
<li>Searching for documentation online for pf is troublesome because there are two incompatible syntaxes</li>
<li>FreeBSD's pf man pages are lacking, and some of FreeBSD's documentation still links to OpenBSD's pages, which won't work anymore - possibly turning away would-be BSD converts because it's frustrating</li>
<li>There's also the issue of importing patches from pfSense, but most of those still haven't been done either</li>
<li>Lots of disagreement among developers vs. users...</li>
<li>Many users are very vocal about wanting it updated, saying the syntax change is no big deal and is worth the benefits - developers aren't interested</li>
<li>Henning Brauer, the main developer of pf on OpenBSD, has been very nice and offered to help the other BSDs get their pf fixed on multiple occasions</li>
<li>Gleb Smirnoff, author of the FreeBSD-specific SMP patches, questions Henning's claims about OpenBSD's improved speed as "uncorroborated claims" (but neither side has provided any public benchmarks)</li>
<li>Gleb had to abandon his work on FreeBSD's pf because funding ran out
***</li>
</ul>

<h3><a href="http://linux.slashdot.org/story/14/07/16/1950235/libressl-prng-vulnerability-patched" rel="nofollow noopener">LibreSSL progress update</a></h3>

<ul>
<li>LibreSSL's first few portable releases have come out and they're making great progress, releasing 2.0.3 <a href="http://marc.info/?l=openbsd-tech&amp;m=140599450206255&amp;w=2" rel="nofollow noopener">two days ago</a></li>
<li>Lots of non-OpenBSD people are starting to contribute, sending in patches via the tech mailing list</li>
<li>However, there has already been some drama... with Linux users</li>
<li>There was a problem with Linux's PRNG, and LibreSSL was <a href="https://twitter.com/MiodVallat/status/489122763610021888" rel="nofollow noopener">unforgiving</a> of it, not making an effort to randomize something that could not provide real entropy</li>
<li>This "problem" doesn't affect OpenBSD's native implementation, only the portable version</li>
<li><a href="http://www.securityweek.com/openbsd-downplays-prng-vulnerability-libressl" rel="nofollow noopener">The developers</a> decide to <a href="http://www.tedunangst.com/flak/post/wrapping-pids-for-fun-and-profit" rel="nofollow noopener">weigh in</a> to calm the misinformation and rage</li>
<li>A fix was added in 2.0.2, and Linux may even <a href="http://thread.gmane.org/gmane.linux.kernel.cryptoapi/11666" rel="nofollow noopener">get a new system call</a> to handle this properly now - remember to say thanks, guys</li>
<li><a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener">Ted Unangst</a> has a <a href="http://www.tedunangst.com/flak/post/this-is-why-software-sucks" rel="nofollow noopener">really good post</a> about the whole situation, definitely check it out</li>
<li>As a follow-up from last week, bapt says they're working on building the whole FreeBSD ports tree against LibreSSL, but lots of things still need some patching to work properly - if you're a port maintainer, please test your ports against it
***</li>
</ul>

<h3><a href="http://mail-index.netbsd.org/current-users/2014/07/13/msg025234.html" rel="nofollow noopener">Preparation for NetBSD 7</a></h3>

<ul>
<li>The release process for NetBSD 7.0 is finally underway</li>
<li>The netbsd-7 CVS branch should be created around July 26th, which marks the start of the first beta period, which will be lasting until September</li>
<li>If you run NetBSD, that'll be a great time to help test on as many platforms as you can (this is especially true on custom embedded applications)</li>
<li>They're also looking for some help updating documentation and fixing any bugs that get reported</li>
<li>Another formal announcement will be made when the beta binaries are up
***</li>
</ul>

<h2>Interview - Dag-Erling Smørgrav - <a href="mailto:des@freebsd.org" rel="nofollow noopener">des@freebsd.org</a> / <a href="https://twitter.com/RealEvilDES" rel="nofollow noopener">@RealEvilDES</a></h2>

<p>The role of the FreeBSD Security Officer, recent ports features, various topics</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://blogs.freebsdish.org/portmgr/2014/07/18/bsdcan-2014-ports-and-packages-wg/" rel="nofollow noopener">BSDCan ports and packages WG</a></h3>

<ul>
<li>Back at BSDCan this year, there was a special event for discussion of FreeBSD ports and packages</li>
<li>Bapt talked about package building, poudriere and the systems the foundation funded for compiling packages</li>
<li>There's also some detail about the signing infrastructure and different mirrors</li>
<li>Ports people and source people need to talk more often about ABI breakage</li>
<li>The post also includes information about pkg 1.3, the old pkg tools' EOL, the quarterly stable package sets and a lot more (it's a huge post!)
***</li>
</ul>

<h3><a href="http://blog.ignoranthack.me/?p=212" rel="nofollow noopener">Cross-compiling ports with QEMU and poudriere</a></h3>

<ul>
<li>With recent QEMU features, you can basically chroot into a completely different architecture</li>
<li>This article goes through the process of building ARMv6 packages on a normal X86 box</li>
<li>Note though that this requires 10-STABLE or 11-CURRENT and an extra patch for QEMU right now</li>
<li>The poudriere-devel port now has a "qemu user" option that will pull in all the requirements</li>
<li>Hopefully this will pave the way for official pkgng packages on those lesser-used architectures
***</li>
</ul>

<h3><a href="http://blather.michaelwlucas.com/archives/2108" rel="nofollow noopener">Cloning FreeBSD with ZFS send</a></h3>

<ul>
<li>For a FreeBSD mail server that MWL runs, he wanted to have a way to easily restore the whole system if something were to happen</li>
<li>This post shows his entire process in creating a mirror machine, using ZFS for everything</li>
<li>The "zfs send" and "zfs snapshot" commands really come in handy for this</li>
<li>He does the whole thing from a live CD, pretty impressive
***</li>
</ul>

<h3><a href="http://thiagoperrotta.wordpress.com/2014/07/20/here-be-dragons-freebsd-overview-part-i/" rel="nofollow noopener">FreeBSD Overview series</a></h3>

<ul>
<li>A new blog series we stumbled upon about a Linux user switching to BSD</li>
<li>In part one, he gives a little background on being "done with Linux distros" and documents his initial experience getting and installing FreeBSD 10</li>
<li>He was pleasantly surprised to be able to use ZFS without jumping through hoops and doing custom kernels</li>
<li>Most of what he was used to on Linux was already in the default FreeBSD (except bash...)</li>
<li><a href="http://thiagoperrotta.wordpress.com/2014/07/21/here-be-packages-freebsd-overview-part-ii/" rel="nofollow noopener">Part two</a> documents his experiences with pkgng and ports 
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s214FYbOKL" rel="nofollow noopener">Bostjan writes in</a></li>
<li><a href="http://slexy.org/view/s21cWLhzj4" rel="nofollow noopener">Rick writes in</a></li>
<li><a href="http://slexy.org/view/s21A4grtH0" rel="nofollow noopener">Clint writes in</a></li>
<li><a href="http://slexy.org/view/s27fQHz8Se" rel="nofollow noopener">Esteban writes in</a></li>
<li><a href="http://slexy.org/view/s21QscO4Cr" rel="nofollow noopener">Ben writes in</a></li>
<li><a href="https://imgur.com/a/Ah444" rel="nofollow noopener">Matt sends in pictures of his FreeBSD CD collection</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Coming up this week on the show! We've got an interview with Dag-Erling Smørgrav, the current security officer of FreeBSD, to discuss what exactly being in such an important position is like. The latest news, answers to your emails and even some LibreSSL drama, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://www.openbsd.org/hackathons.html" rel="nofollow noopener">g2k14 hackathon reports</a></h3>

<ul>
<li>Nearly 50 OpenBSD developers gathered in Ljubljana, Slovenia from July 8-14 for a hackathon</li>
<li>Lots of work got done - in just the first two weeks of July, there were <a href="http://marc.info/?l=openbsd-cvs&amp;r=1&amp;b=201407&amp;w=2" rel="nofollow noopener">over 1000 commits</a> to their CVS tree</li>
<li>Some of the developers wrote in to document what they were up to at the event</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140713220618" rel="nofollow noopener">Bob Beck</a> planned to work on kernel stuff, but then "LibreSSL happened" and he spent most of his time working on that</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140718072312" rel="nofollow noopener">Miod Vallat</a> also tells about his LibreSSL experiences</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140718090456" rel="nofollow noopener">Brent Cook</a>, a new developer, worked mainly on the portable version of LibreSSL (and we'll be interviewing him next week!)</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140714094454" rel="nofollow noopener">Henning Brauer</a> worked on VLAN bpf and various things related to IPv6 and network interfaces (and he still hates IPv6)</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140714191912" rel="nofollow noopener">Martin Pieuchot</a> fixed some bugs in the USB stack, softraid and misc other things</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140714202157" rel="nofollow noopener">Marc Espie</a> improved the package code, enabling some speed ups, fixed some ports that broke with LibreSSL and some of the new changes and also did some work on ensuring snapshot consistency</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140715120259" rel="nofollow noopener">Martin Pelikan</a> integrated read-only ext4 support</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140715094848" rel="nofollow noopener">Vadim Zhukov</a> did lots of ports work, including working on KDE4</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140715212333" rel="nofollow noopener">Theo de Raadt</a> created a new, more secure system call, "sendsyslog" and did a lot of work with /etc, sysmerge and the rc scripts</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140718134017" rel="nofollow noopener">Paul Irofti</a> worked on the USB stack, specifically for the Octeon platform</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140719104939" rel="nofollow noopener">Sebastian Benoit</a> worked on relayd filters and IPv6 code</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140719134058" rel="nofollow noopener">Jasper Lievisse Adriaanse</a> did work with puppet, packages and the bootloader</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140719082410" rel="nofollow noopener">Jonathan Gray</a> imported newer Mesa libraries and did a lot with Xenocara, including work in the installer for autodetection</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140721125235" rel="nofollow noopener">Stefan Sperling</a> fixed a lot of issues with wireless drivers</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140721125020" rel="nofollow noopener">Florian Obser</a> did many things related to IPv6</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140721090411" rel="nofollow noopener">Ingo Schwarze</a> worked on mandoc, as usual, and also rewrote the openbsd.org man.cgi interface</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140722071413" rel="nofollow noopener">Ken Westerback</a> hacked on dhclient and dhcpd, and also got dump working on 4k sector drives</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140723142224" rel="nofollow noopener">Matthieu Herrb</a> worked on updating and modernizing parts of xenocara
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-questions/2014-July/259292.html" rel="nofollow noopener">FreeBSD pf discussion takes off</a></h3>

<ul>
<li>Concerns from last week, about FreeBSD's packet filter being old and unmaintained, seemed to have finally sparked some conversation about the topic on the "questions" and "current" mailing lists (unfortunately people didn't always use reply-all so you have to cross-reference the two lists to follow the whole conversation sometimes)</li>
<li>Straight from the SMP FreeBSD pf maintainer: "no one right now [is actively developing pf on FreeBSD]"</li>
<li>Searching for documentation online for pf is troublesome because there are two incompatible syntaxes</li>
<li>FreeBSD's pf man pages are lacking, and some of FreeBSD's documentation still links to OpenBSD's pages, which won't work anymore - possibly turning away would-be BSD converts because it's frustrating</li>
<li>There's also the issue of importing patches from pfSense, but most of those still haven't been done either</li>
<li>Lots of disagreement among developers vs. users...</li>
<li>Many users are very vocal about wanting it updated, saying the syntax change is no big deal and is worth the benefits - developers aren't interested</li>
<li>Henning Brauer, the main developer of pf on OpenBSD, has been very nice and offered to help the other BSDs get their pf fixed on multiple occasions</li>
<li>Gleb Smirnoff, author of the FreeBSD-specific SMP patches, questions Henning's claims about OpenBSD's improved speed as "uncorroborated claims" (but neither side has provided any public benchmarks)</li>
<li>Gleb had to abandon his work on FreeBSD's pf because funding ran out
***</li>
</ul>

<h3><a href="http://linux.slashdot.org/story/14/07/16/1950235/libressl-prng-vulnerability-patched" rel="nofollow noopener">LibreSSL progress update</a></h3>

<ul>
<li>LibreSSL's first few portable releases have come out and they're making great progress, releasing 2.0.3 <a href="http://marc.info/?l=openbsd-tech&amp;m=140599450206255&amp;w=2" rel="nofollow noopener">two days ago</a></li>
<li>Lots of non-OpenBSD people are starting to contribute, sending in patches via the tech mailing list</li>
<li>However, there has already been some drama... with Linux users</li>
<li>There was a problem with Linux's PRNG, and LibreSSL was <a href="https://twitter.com/MiodVallat/status/489122763610021888" rel="nofollow noopener">unforgiving</a> of it, not making an effort to randomize something that could not provide real entropy</li>
<li>This "problem" doesn't affect OpenBSD's native implementation, only the portable version</li>
<li><a href="http://www.securityweek.com/openbsd-downplays-prng-vulnerability-libressl" rel="nofollow noopener">The developers</a> decide to <a href="http://www.tedunangst.com/flak/post/wrapping-pids-for-fun-and-profit" rel="nofollow noopener">weigh in</a> to calm the misinformation and rage</li>
<li>A fix was added in 2.0.2, and Linux may even <a href="http://thread.gmane.org/gmane.linux.kernel.cryptoapi/11666" rel="nofollow noopener">get a new system call</a> to handle this properly now - remember to say thanks, guys</li>
<li><a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener">Ted Unangst</a> has a <a href="http://www.tedunangst.com/flak/post/this-is-why-software-sucks" rel="nofollow noopener">really good post</a> about the whole situation, definitely check it out</li>
<li>As a follow-up from last week, bapt says they're working on building the whole FreeBSD ports tree against LibreSSL, but lots of things still need some patching to work properly - if you're a port maintainer, please test your ports against it
***</li>
</ul>

<h3><a href="http://mail-index.netbsd.org/current-users/2014/07/13/msg025234.html" rel="nofollow noopener">Preparation for NetBSD 7</a></h3>

<ul>
<li>The release process for NetBSD 7.0 is finally underway</li>
<li>The netbsd-7 CVS branch should be created around July 26th, which marks the start of the first beta period, which will be lasting until September</li>
<li>If you run NetBSD, that'll be a great time to help test on as many platforms as you can (this is especially true on custom embedded applications)</li>
<li>They're also looking for some help updating documentation and fixing any bugs that get reported</li>
<li>Another formal announcement will be made when the beta binaries are up
***</li>
</ul>

<h2>Interview - Dag-Erling Smørgrav - <a href="mailto:des@freebsd.org" rel="nofollow noopener">des@freebsd.org</a> / <a href="https://twitter.com/RealEvilDES" rel="nofollow noopener">@RealEvilDES</a></h2>

<p>The role of the FreeBSD Security Officer, recent ports features, various topics</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://blogs.freebsdish.org/portmgr/2014/07/18/bsdcan-2014-ports-and-packages-wg/" rel="nofollow noopener">BSDCan ports and packages WG</a></h3>

<ul>
<li>Back at BSDCan this year, there was a special event for discussion of FreeBSD ports and packages</li>
<li>Bapt talked about package building, poudriere and the systems the foundation funded for compiling packages</li>
<li>There's also some detail about the signing infrastructure and different mirrors</li>
<li>Ports people and source people need to talk more often about ABI breakage</li>
<li>The post also includes information about pkg 1.3, the old pkg tools' EOL, the quarterly stable package sets and a lot more (it's a huge post!)
***</li>
</ul>

<h3><a href="http://blog.ignoranthack.me/?p=212" rel="nofollow noopener">Cross-compiling ports with QEMU and poudriere</a></h3>

<ul>
<li>With recent QEMU features, you can basically chroot into a completely different architecture</li>
<li>This article goes through the process of building ARMv6 packages on a normal X86 box</li>
<li>Note though that this requires 10-STABLE or 11-CURRENT and an extra patch for QEMU right now</li>
<li>The poudriere-devel port now has a "qemu user" option that will pull in all the requirements</li>
<li>Hopefully this will pave the way for official pkgng packages on those lesser-used architectures
***</li>
</ul>

<h3><a href="http://blather.michaelwlucas.com/archives/2108" rel="nofollow noopener">Cloning FreeBSD with ZFS send</a></h3>

<ul>
<li>For a FreeBSD mail server that MWL runs, he wanted to have a way to easily restore the whole system if something were to happen</li>
<li>This post shows his entire process in creating a mirror machine, using ZFS for everything</li>
<li>The "zfs send" and "zfs snapshot" commands really come in handy for this</li>
<li>He does the whole thing from a live CD, pretty impressive
***</li>
</ul>

<h3><a href="http://thiagoperrotta.wordpress.com/2014/07/20/here-be-dragons-freebsd-overview-part-i/" rel="nofollow noopener">FreeBSD Overview series</a></h3>

<ul>
<li>A new blog series we stumbled upon about a Linux user switching to BSD</li>
<li>In part one, he gives a little background on being "done with Linux distros" and documents his initial experience getting and installing FreeBSD 10</li>
<li>He was pleasantly surprised to be able to use ZFS without jumping through hoops and doing custom kernels</li>
<li>Most of what he was used to on Linux was already in the default FreeBSD (except bash...)</li>
<li><a href="http://thiagoperrotta.wordpress.com/2014/07/21/here-be-packages-freebsd-overview-part-ii/" rel="nofollow noopener">Part two</a> documents his experiences with pkgng and ports 
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s214FYbOKL" rel="nofollow noopener">Bostjan writes in</a></li>
<li><a href="http://slexy.org/view/s21cWLhzj4" rel="nofollow noopener">Rick writes in</a></li>
<li><a href="http://slexy.org/view/s21A4grtH0" rel="nofollow noopener">Clint writes in</a></li>
<li><a href="http://slexy.org/view/s27fQHz8Se" rel="nofollow noopener">Esteban writes in</a></li>
<li><a href="http://slexy.org/view/s21QscO4Cr" rel="nofollow noopener">Ben writes in</a></li>
<li><a href="https://imgur.com/a/Ah444" rel="nofollow noopener">Matt sends in pictures of his FreeBSD CD collection</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
